← sunnyray.com
The Sunny Ray Show · Episode Page

Turning Risk Into a Number the CFO Can Actually Use

Gary Bierc · Founder & CEO, Aperitisoft · 38:58
watch on youtube ↗

What we talked about.

Gary Bierc, founder and CEO of Aperitisoft, joins Sunny Ray to explain how enterprise risk management drifted from a performance tool into a compliance checkbox, and how his company is pulling it back. Bierc pioneered enterprise risk management in the late 1990s while at Moore Business Forms, later founding rPM3 Solutions LLC in 2002 and patenting a method called ARQ, Aggregate Risk Quantification, in 2010. Aperitisoft, born from a 2015 consulting engagement, ingests general ledger data to calculate a company's live cost of risk in dollar terms instead of red, yellow, green heat maps. Bierc argues that regulations like Sarbanes-Oxley, Dodd-Frank, and Basel II made risk part of corporate vocabulary but locked it into a compliance mindset rather than a strategic one. He shares how Boeing became his first customer, why marketing should be viewed as a tool for managing demand risk, and how framing risk as dollars, not colors, finally earns CFOs and boards' attention. The conversation closes with a personal story about how information and control shape true risk, using both an anvil parable and the film National Treasure as metaphors.

Gary Bierc explains why he built patented software that turns enterprise risk into real general ledger dollars, not color-coded heat maps.

The questions, and the answers.

What are you building at Aperitisoft, and what problem are you solving?

Enterprise risk management has fallen into being a compliance exercise instead of connecting risk to performance in dollar terms. At Aperitisoft we built patented software that ingests general ledger data to quantify your actual cost of risk on an enterprise scale, both predictively and historically. We're the only company doing that. It finally gives boards and the C-suite a real answer to what a red, yellow, green heat map actually means to the bottom line.

You've been building this since 2002. What kept the company alive through eras that killed most others?

I started as a consultant evangelizing enterprise risk management, but the market wasn't ready. In 2010 I patented ARQ, Aggregate Risk Quantification, and renamed the company rPM3 Solutions LLC. A 2015 consulting engagement pushed us to build software differently from typical GRC systems, and that's where Aperitisoft was born. The whole architecture is purpose built around the actual enterprise risk process, which lets us do things traditional systems simply cannot.

Can you give us the origin story, the version you'd tell over a drink?

I was pioneering enterprise risk at Moore Business Forms when it got taken over by a KKR type group, so I took my ball and left. About a year into a sabbatical, I got a call from Boeing's newly appointed director of ERM. He'd followed my work and said if I ever went into business for myself, he'd be my first customer. That's literally how I got started.

What did enterprise risk management look like in 2002, and what genuinely changed versus what only appeared to change?

Almost nobody was doing enterprise risk management then, mostly financial services and maybe energy. I was one of the first to bring it into manufacturing, so I was truly evangelizing. Since then, Sarbanes-Oxley put risk into the vocabulary of accountants and auditors, and frameworks like COSO and ISO 31000 emerged internationally. The problem is those frameworks built in a compliance orientation rather than a performance driven one, though that's finally starting to change.

You've watched several hype cycles pass through your category. Which one did the most damage to how buyers think about risk?

Sarbanes-Oxley got the word risk into everyone's vocabulary, but Dodd-Frank after the 08-09 crash really forced the compliance problem into place. Internationally, Basel II did something similar. It helped awareness but hurt because it narrowed what was expected, so risk departments became focused on complying with regulators instead of connecting risk to performance. Boards now know the words, but they're checking a box rather than trying to be the best.

Why has the industry been so committed to color-coded heat maps for so long?

It's what the systems available at the time allowed. Predictive risk modeling needs Monte Carlo simulation with an easy methodology, and most companies never had that sophistication. So the thinking became, if I list my risks and put color coding on it, I satisfy an auditor and move on. But heat maps never connect to your earning sensitivity or what would happen to your balance sheet if a risk fully played out.

Monte Carlo simulation isn't new. What's actually patented in ARQ, and what does it let a customer do that they couldn't before?

ARQ is a business method for looking at the general ledger and determining which accounts belong to cost of risk versus core business cost. The default assumption is that everything is core business unless you can prove it's actually managing a risk. Marketing, for example, isn't really producing sales, it's managing product demand risk. Once you separate those buckets properly, how you allocate resources changes completely.

When a risk becomes a dollar figure on the general ledger, who in the organization suddenly cares who maybe didn't before?

The CFO takes it far more seriously, and so does the CEO. Suddenly they're seeing that their earnings forecast for the year carries real uncertainty, maybe to the tune of half of what was told to investors. That gets immediate attention, because now the conversation becomes about how we mitigate this and make a real difference, not just acknowledging a color on a chart.

Enterprise Risk ManagementRisk QuantificationCFO & Board StrategyCompliance vs PerformanceARQ PatentEntrepreneurship Origin Story

Gary Bierc

Founder & CEO, Aperitisoft

Building something daring? Sunny talks to founders like this every day. Fifteen minutes to see if your story belongs on the stage.

Claim your pre-interview
Built with help from AI. We use AI tools to research, draft, and assemble pages like this one. A human reviews everything, but if something looks off, tell us and we will fix it fast.