Earlier quoted context omitted.
Re-reading this, I realize it’s needlessly wordy. To condense my point, you can simply ask, “what risk is this process trying to mitigate?” If the answer is “none”, it validates your point that the process is needless and the claim about risk is proved false. But most responses will be able to articulate what the risk is, whether it’s relevant to your position or to someone else.
> But most responses will be able to articulate what the risk is, whether it’s relevant to your position or to someone else. Not my experience at all. Most responses to the question as phrased would be "huh?" I would claim that most processes are not born of an intent to mitigate risk; in my experience there's rarely an intent at all, people cargo-cult the idea that they should have processes without understanding wh…
I’ve certainly worked in organizations that continued processes out of sheer inertia of “this is the way we’ve always done it.” While someone may have inherited a process and continued using it without understanding why, if you reach back to the initiator they will have a risk they were trying to mitigate. Even if their predecessors are oblivious. Again, I would chalk this up to a failure of leadership to explain the “why” when passing it off rather than a failure of process.
Even in instances where people copy processes just because they are emulating a different org, that original organization had a risk they were mitigating. Blindly following suit like an automaton says more about the person pushing it than the validity of the original intent.
A process can certainly outgrow its intent. If I am prescribed medicine and blindly continue taking that medicine after I’m well, it doesn’t mean the there was no original, valid intent. The risk profile changed; the process did not update keep inline with that changed risk profile.