In general, many businesses have no formal policy on risk management. The few that have, view the risk management function in isolation from general business processes. This means that everyone does their job without concern as to what risks the business is getting exposed to. It is up to the risk manager to figure out any mitigation needed.