While businesses have managed risks for centuries, the traditional approach to risk management has been to assign risk oversight responsibilities to certain business functions, such as legal or IT, where risks are managed in isolation by that function.