By Appbay Technologies
Naming the risk is the easy part. Proving it’s actively monitored is the governance obligation that follows.
A UAE bank recently set a five-year target to double net profit to AED 20 billion – and, in the same period, formally added “strategy” and “people” risk to its principal risk framework. That’s a deliberate governance move. But a newly named risk category with no established monitoring process is exactly the kind of gap an auditor or regulator finds before the bank does – especially one sitting directly beside a specific, dated, board-visible target.
The Priority: A Trackable Target, Paired With a Newly Named Risk
Setting a specific, dated profit target is a clear and reasonable ambition for any bank pursuing accelerated growth. Doubling net profit within a fixed five-year window is inherently trackable – and inherently exposes any year that falls behind pace. Naming “strategy risk” as a formal category in the same period raises the stakes further: the bank now has to demonstrate that category is actively monitored, not just acknowledged.
That’s fair scrutiny, but it creates a real operational question: is progress against the target being tracked continuously, or reconstructed reactively each time the board asks?
The Hidden Problem: A Risk Category Without a Monitoring Process
Here’s where the operational gap actually shows up, inside a bank that just formalized strategy risk as a principal category:
New category, no established process – “strategy risk” is new to the framework; the bank likely doesn’t yet have the same auditable monitoring rigor it has for credit or market risk. Reactive reporting – the strategy office can report where things stand when asked, but doesn’t yet have a standing, always-current view. Skepticism as the default – a five-year target invites year-by-year scrutiny, and a newly named risk category with nothing visible behind it invites more. Early warning, caught late – without continuous tracking, the first sign of the plan slipping is often the same moment the board finds out.
Why does this exist? Formally naming “strategy risk” means the bank now has to demonstrate active, ongoing monitoring – not just acknowledgment. That’s a new governance obligation the bank created for itself, and most risk functions aren’t yet built to meet it continuously.
Why This Matters Now
The category was named. Now the board wants to see it monitored with the same rigor as every other principal risk.
A newly formalized risk category next to a dated, specific target raises a question that isn’t rhetorical:
“Is strategy risk actually being tracked against the plan – or is this a label with nothing behind it yet?”
For the CRO or Head of Strategy, this plays out as a live governance problem, measured against evidence that usually only gets assembled once a year:
Milestone-to-target tracking – is progress against the AED 20 billion goal visible continuously, or only reconstructed at review time? Time-to-deviation-detection – would the bank catch the plan slipping months in, or only discover it at the next strategy update? Board reporting parity – does strategy risk get the same audit trail and reporting cadence as credit or market risk, or a lighter touch?
Naming the risk isn’t the problem. Proving, continuously, that it’s monitored is.
An Honest Look at the Fit
This is a genuine partial fit, not a clean product match. Appbay’s core strength is in regulated operational workflows – AML, KYC, lending – and strategic execution monitoring is a different application of that same orchestration pattern, not a repurposed product out of the box.
Where there’s a genuine, if partial, fit: our ComplianceIQ Regulatory Radar (SLA tracking, owner assignment) and Multi-Perspective Document Insight Copilot (stakeholder-specific reporting) both transfer core capability directly – track against plan, flag deviation, assign an owner, report to different audiences.
Here’s what that would actually involve, in principle:
- Strategic Milestone/KPI Data Ingestion Progress against the five-year target brought into one continuously updated view, rather than assembled fresh for each strategy review.
- AI-Driven Trend and Deviation Analysis Flagging where the plan is drifting off pace, not just confirming the headline number at year-end.
- Human Strategy-Office Review Every flagged deviation reviewed and interpreted by a person – the same judgment call the strategy office would make anyway, with continuous evidence behind it.
- Appian-Orchestrated Escalation and Audit Trail One governed workflow producing continuous evidence and a defensible audit trail, not a year-end reconstruction exercise.
- Board Reporting Dashboard Strategy risk reported with the same parity and rigor as every other principal risk category.
- An 8-12 week proof of concept, scoped to one strategic milestone tracked against the five-year target, is a reasonable way to start that conversation.
This Pattern Isn’t Unique to One Bank
Any institution pairing an ambitious, dated growth target with a newly formalized execution-risk category will face the same board question, review after review: is it monitored, or just named? The banks getting ahead of this aren’t waiting for the next annual cycle to find out – they’re building the continuous evidence trail before the gap gets flagged for them.
Let’s Compare Notes
We’re working with banks across the GCC formalizing strategy and execution risk alongside ambitious growth targets – same challenge, building the monitoring to match the framework. If your organization is facing a similar governance gap, we’d welcome the conversation.
Send us a message – this one’s genuinely about comparing notes, not a pitch.


