Emergency services work under demanding conditions. In an operation, clear roles, well-rehearsed procedures and reliable information are what count. Decisions have to be taken quickly, responsibilities assigned unambiguously and measures implemented consistently.
At tactical and strategic management level, reality sometimes still looks different: risks are kept in Excel lists, assessments recorded in Word documents and information spread across various storage locations.
That works – as long as structures stay manageable. But as soon as several departments, owners and decision-making levels are involved, it becomes harder to know the current status at any time and to steer developments traceably.
This is precisely where digital risk management can make a decisive difference. fortControl transfers proven principles from day-to-day operations to the governance level: clear responsibilities, a shared information base, defined processes and traceable decisions.
In this interview, Rolf Wagner explains why emergency services in particular can benefit.
Rolf, why is structured risk management especially important for emergency services?
Emergency services are used to assessing risks professionally and taking decisions under time pressure. That professionalism should also be reflected at tactical and strategic level.
There it concerns, for example, organisational risks, personnel dependencies, information security, critical infrastructure, availability or the question of which measures have to be prioritised.
The challenge is not so much that these risks are unknown. What is often missing is a shared structure in which they are assessed consistently, assigned to owners and tracked over a longer period.
Digital risk management creates exactly that basis. Everyone involved works with the same current view of risks, assessments and measures. This turns risk management from a periodic documentation task into a continuous management process.
But don’t Excel and Word work for that too?
Of course they work – and for simple overviews they can be perfectly adequate.
It becomes more difficult when several people work on one risk or different management levels are involved. Questions quickly arise: which version is current? Who changed the assessment? Why was a risk reassessed? Which measure was decided? Who is responsible for it? By when does it have to be implemented? And was it actually completed?
This information can also be managed with classic documents. The administrative effort, however, grows with every additional interface and every further participant.
The problem is therefore not Excel or Word. The problem arises when individual documents are supposed to represent an organisation-wide management process.
What does fortControl do differently?
One important difference is structured and collaborative review processes.
Take a risk assessment as an example: several risk owners first review the risks assigned to them and update their evaluations. The assessments are then consolidated and checked. At a further management level, evaluation or approval takes place.
fortControl can map such multi-stage procedures digitally. Responsibilities are defined, processing status is visible and feedback is documented traceably. Instead of exchanging assessments by email and merging them manually afterwards, a shared process emerges.
This brings together three things that are decisive in risk management: accountability, traceability and currency.
What does that look like in practice?
All the roles involved access the same information base. Subject matter owners see the risks relevant to them. Risk owners can review and develop assessments. Managers receive a consolidated overview of the current risk situation and the measures derived from it.
Changes are documented traceably. This removes the need to work in parallel on different versions of a file. Information does not have to be gathered and transferred manually on an ongoing basis.
Instead, a shared view emerges of:
- current risks and their assessment
- responsible people
- ongoing and planned measures
- processing and approval status
- changes compared with earlier assessments
This shared view is decisive for management in particular. Because risks do not just have to be recorded. They have to be understood, prioritised and managed.
Can you call that a digital situation picture?
To a certain extent yes – but with one important difference from the operational situation picture of a deployment. In risk management it is about a management situation picture at governance level.
It shows, for example: where are the biggest risks right now? Which of them are changing? Where have measures been initiated? Where are there delays? Which risks have been consciously accepted? And which topics require a management decision?
Decision-makers thus do not simply receive a long list of risks, but a structured basis for discussion and decisions. For me that is one of the most important advantages of digitalisation.
Many emergency services have processes that have grown historically. Does everything have to be rebuilt for fortControl?
No. In my view that would also be the wrong approach.
Emergency services have established management structures, responsibilities and procedures. These have often grown over years and exist for good reasons. Digitalisation should therefore not mean replacing working processes with a rigid standard system.
fortControl makes it possible to map existing structures and processes and develop them step by step. Responsibilities, review processes and reporting lines can be designed to fit the individual organisation. The platform supports the process – not the other way round.
At the same time, digitalisation offers the chance to question procedures that have grown historically: where are there unnecessary media breaks? Where is information recorded more than once? Where are clear responsibilities missing? And which steps can be simplified?
This creates not just a digital copy of the previous process, but in the best case a better process.
What role does collaboration play?
A very large one. Risk management is not the task of a single risk manager.
Expertise is distributed across the organisation. An IT risk is judged differently from a personnel, logistical or operational risk. At the same time, an overarching view has to emerge in the end. That is precisely why different roles have to be able to work together.
fortControl creates a shared working basis for this. Instead of collecting individual evaluations afterwards, participants can work on assessments, comments and measures within a structured process.
That not only improves efficiency. It also raises the quality of the discussion, because it becomes traceable who assessed a risk in which way and on what basis decisions were taken.
What does that mean for managers?
Above all: more overview. Managers do not need every detail of an individual risk. They have to be able to recognise where action is required.
Which risks are particularly high? Which are developing negatively? Where are measures overdue? Where is a decision needed? And where can risks be consciously accepted?
Dashboards and structured analyses help to condense this information. That is how risk management genuinely becomes a management instrument – and not a collection of documents that are mainly updated for the next review meeting.
Does digitalisation automatically mean better risk management?
No. A poor procedure does not automatically become good just because it is mapped digitally.
The decisive questions remain the same: are the relevant risks known? Who bears responsibility? Are assessment criteria traceable? Who decides on risk treatment? Are measures actually implemented? And is it checked regularly whether the situation has changed?
A digital tool can structure these processes, simplify them and make them more transparent. Responsibility for good risk management, however, remains with the organisation and its leadership. That is exactly why it is important not to see technology as an end in itself.
Where do you see the greatest added value of fortControl?
For me it lies in turning many individual contributions into a shared management process.
Risks are not just documented, they are actively worked on. Measures are not recorded somewhere, they are assigned to owners and tracked. Decisions do not disappear into meeting minutes, they stay connected to the respective risk.
Over time this produces a traceable development. You see not only where the organisation stands today, but also how risks have changed and which decisions were taken in response. That creates transparency and commitment.
From risk register to management instrument
In their daily operations, emergency services demonstrate every day how important clear procedures, defined responsibilities and a shared information base are. The same principles are decisive in tactical and strategic risk management too.
Digitalisation can help to bring isolated documents and point-in-time assessments together into a continuous process.
- 1 Identify risks Relevant risks from all departments are recorded systematically instead of being stored separately.
- 2 Assess Uniform criteria make evaluations comparable and traceable.
- 3 Clarify responsibilities Every risk and every measure has a responsible person.
- 4 Implement measures Agreed measures are tracked with a due date and a status.
- 5 Track changes History and versioning show how the risk situation has developed.
- 6 Take decisions Management receives a condensed basis for prioritisation and leadership decisions.
The steps do not run once, but as a continuous management process.
fortControl creates a shared platform for this and supports emergency services in steering risk management traceably, collaboratively and continuously.
This turns an administrative task into what risk management should actually be: an active management instrument.