When risk becomes a business partner
A conversation with Adrianna Fabijanska, CEO & Founder of Meridian Risk Intelligence, on what it really takes for business and risk to work as partners, and why the best decisions often come from understanding each other better.

When risk becomes a business partner


When Risk Becomes a Business Partner

I have known Adrianna Fabijanska for quite a few years now.

One of the things I have always valued about her is her curiosity. She is one of the sharpest people I know in her field, but she is also constantly asking what is changing, why it matters and whether the way we think about something still holds.

Over the years, we have discussed compliance, markets, tokenisation, emerging technologies and broader questions where the right answer is not immediately obvious.

Adrianna is now CEO & Founder of Meridian Risk Intelligence Ltd, after a career spanning financial crime compliance, global advisory, assurance and risk. She was most recently Global Head of Financial Crime Compliance - Investment Banking and Global MLRO for Investment Banking at ING, a global systemically important bank. Earlier, she held senior international compliance roles, led regulatory remediation and transformation programmes and served as a regulator, including sitting on the supervisory boards of strategic entities in energy and markets infrastructure.

Today, Meridian Risk Intelligence Ltd advises asset managers, banks and other financial institutions at the intersection of compliance risk and emerging risks. Its work includes the design and delivery of financial crime and compliance enhancement programmes, digital and crypto assets, AI and geopolitics.

My own perspective is shaped by 15 years in business development across different products, markets and complex situations. That experience has left me with a fairly simple belief: when business and risk are genuinely aligned, there is very little that cannot at least be explored.

With Adrianna now building Meridian Risk Intelligence Ltd and experiencing the commercial side more directly, it felt like a natural moment to bring those two perspectives together around one key question: when does risk become a business partner?

What does being a business partner actually mean?

We use the term business partner rather easily.

My best experiences with risk have never been about getting an easy yes. They have been about someone willing to understand what the business is trying to achieve before reaching a conclusion.

So I asked Adrianna where she sees the difference between assessing an opportunity and helping shape one.

“The difference is timing and intent. Assessment happens once a proposition already exists: the structure is chosen and expectations have already been set. The risk role at that point is close to binary.

Shaping happens earlier, while the problem is still open. That is where a risk professional can influence the structure, the controls that are designed in rather than bolted on, and the information needed before commitment rather than after.

But early involvement does not mean co-ownership of the commercial outcome. The second line, and the MLRO above all, carries an independent judgement that must survive the relationship intact.

For me, the principle is simple: risk can be fully invested in helping the business find a good answer, and entirely uninvested in whether that answer is yes. That is what makes the partnership credible.”

That distinction matters. Partnership is not about making risk more likely to say yes. It is about making its perspective useful without weakening the independence that gives it value.

Should risk get closer to the commercial context?

If timing is the first part of the equation, proximity is the next. Once risk is involved, how close should it get to the underlying commercial context?

I have seen how easily nuance disappears as information moves from one person to another. A situation described second-hand is rarely quite the same as hearing the context directly.

So I asked Adrianna whether proximity actually improves risk judgement, and where the boundary should sit.

“Very much so. Poor risk decisions are often caused not by poor judgement but by poor information. Commercial context can pass through several layers, and important nuance can disappear before it reaches risk.

Hearing the context directly allows me to ask the questions that matter and to hear how they are answered. Hesitation, over-explanation and precision each tell you something a written summary cannot.

Risk functions talk a great deal about wanting a seat at the table. The less-discussed truth is that you also need a business that wants risk there - as a matter of governance, not goodwill.

At the same time, proximity must never become advocacy. Risk is there to listen, question and form a view, not to become the commercial champion. Risk attends and challenges; business owns and decides.

Closer, yes. Captured, never.”

That is the balance: better information without blurred accountability.

What happens when there is no playbook?

That balance becomes harder when the subject itself is new.

This becomes particularly interesting in areas where the answer is not obvious. Tokenisation is one example. Digital assets and AI give us plenty more to discuss.

New markets and technologies rarely arrive with years of precedent behind them. That creates opportunity, but also uncertainty.

Adrianna starts by questioning the word new itself.

“I begin by refusing to treat ‘new’ as a risk category. ‘New’ describes the market, not the risk. Strip away the novelty and most of the underlying questions are familiar: who is the counterparty, where does value come from and go, who controls it, and can we evidence what is happening?

The next step is separating what is genuinely unknown from what is merely uncomfortable. Uncertainty that can be reduced through more information, expertise or a bounded pilot is a reason to keep working. Risk that cannot be reduced, contained or monitored is a reason to stop.

I use three tests: can I explain the risk and its mitigation to a regulator in plain language? Would we detect it going wrong ourselves? And is the residual risk within an appetite the board has actually approved?

If those tests hold, uncertainty becomes a design brief. If they do not, the answer may be not yet, which is very different from no.

Intellectual honesty about uncertainty is itself a control.”

I like that idea because it reaches beyond compliance. Uncertainty does not automatically mean stopping. Sometimes the better response is to define what remains unknown, what can be reduced and what would need to be true before moving forward.

Is “no” sometimes where the interesting work starts?

Of course, sometimes the answer is still no. Not every opportunity should happen.

But there is an important difference between we can’t do this and we can’t do it this way. The second leaves room to understand whether the problem is the opportunity itself or the way it has been designed.

That does not mean risk should become the architect of the solution.

“The moment risk starts redesigning the transaction, risk becomes its author, and nobody can independently challenge their own design.

Risk can define the concern and the outcome that needs to be achieved; the business owns the redesign. Risk can say what would need to be true, not how the proposition should be structured.

Some decisions also have to remain outside the commercial conversation altogether, particularly around suspicious activity reporting, certain exit and sanctions decisions, and the handling of law-enforcement or regulatory enquiries. A partnership, however strong, cannot become a channel through which those decisions are influenced. In my own MLRO roles those decisions sat outside any commercial relationship, including the ones I valued most, and that is exactly how it should be.

Those safeguards do not undermine partnership. They are what allow it to exist, because independence has to be protected by design rather than by personality.

The same principle applies when business and risk disagree. Both sides should arrive with reasons rather than positions, and the challenge should be directed at the proposition rather than the person. Quiet compromise is where independence dies.

And independence does not mean assuming risk is always right. I have been wrong. A partner who tells me that a control I have proposed makes no operational sense is doing me a favour.”

That last point matters. Good partnership does not eliminate disagreement. It makes disagreement useful.

What should business development understand better about risk?

If business expects that kind of partnership from risk, the expectation has to work in both directions.

So what should those of us in business development understand better?

“First, when risk says no, it is rarely only about one specific case. Risk is also thinking about what would need to be explained to a regulator, a court, a correspondent bank or a board if things go wrong.

Second, the downside is asymmetric. A hundred good decisions earn little visible recognition; one bad decision can cost a licence, a relationship or a reputation built over decades.

Third, information delivered late is itself a risk. Bring the ambiguous facts early and unpolished. I would rather hear in week one that something looks odd than discover it in week eight once expectations have already been created.

And documentation matters. It is the memory of the decision and protects the business at least as much as it protects risk. Written compliance is not operating compliance, but operating judgement that was never written down does not exist when it is tested.”

That is probably the most practical lesson for the business side. Our instinct can be to bring something forward once it looks sufficiently developed. But the uncomfortable or unclear parts may be exactly what need to surface first.

What changes when you sit in both worlds?

This is where Meridian Risk Intelligence Ltd makes the discussion particularly interesting.

Adrianna is now building relationships and making commercial decisions herself, while bringing years of experience looking at complex questions through a risk lens.

So has being closer to the commercial side changed her view?

“Reinforced, but with a sharper edge. Building Meridian Risk Intelligence Ltd, I now feel the weight of a pipeline, the cost of a delayed decision and the pull of a commercial opportunity - and a sharper appreciation of why the second line’s independence must be structural rather than personal, so that it never depends on who is in the room. That has given me a far deeper respect for what business development colleagues carry.

It has also made me more convinced, not less, that independent risk thinking can be a commercial asset rather than an overhead. What organisations need is someone who understands the business well enough to say no in a way that opens a different door.

For me, that comes back to mutual literacy: risk that understands commerce, and business that understands risk.

That literacy has to work both ways. Just as business needs to understand risk, the risk function needs to understand how the business makes money, how its products work and what it is trying to achieve. That is what allows risk to challenge in a language the business can act on.

Looking back, the independence required by the roles I held did not constrain partnership. It was what made it possible, because the business could trust that my yes meant something.

But above all, it takes people. Partnership is not a framework or a governance chart. It is a relationship built through many conversations, some of them awkward, over years.”

Where does that leave us?

What strikes me after this conversation is how little of it is really about compliance in the narrow sense. It is about whether two different perspectives can meet early enough, and understand each other well enough, for the difference between them to become useful.

Timing matters. Boundaries matter. And partnership has to work both ways.

That is why Adrianna’s idea of mutual literacy resonates with me. Business and risk do not need to think alike. They need to understand each other well enough to challenge each other intelligently.

Looking across 15 years, I can think of many situations, across different firms and markets, where a risk partner who thinks the way Adrianna does would have made the decision better. Not because the answer would have been easier, but because the thinking around it would have been.

That, to me, is the real value of a strong risk partner. They do not remove the complexity or guarantee the answer you want. They make the thinking around it better.

Find your risk partner early, and earn the right to keep them close.

A note on scope and independence. This conversation is about how business development and risk work together as a matter of general professional practice. It does not draw on or comment on any specific transaction, client, counterparty, escalation, suspicious activity report, exit decision, sanctions matter or regulatory engagement either of us has worked on. The MLRO role carries its own independent responsibilities, protected by governance rather than relationships, and nothing in this article should be read as suggesting that this independence can be influenced by proximity to the business. The views expressed are personal and do not represent any current or former employer or organisation.

Intelligence, investigations and the wider MLRO remit raise a distinct set of questions, which the authors may return to separately.

Leave a Reply

Your email address will not be published. Required fields are marked *