Thinking that they have addressed all the risks that they have identified.
My first reaction was to put the risk managers at Baring Brothers up for this award for the Nick Leeson debacle.
Telling the Programme Director that he and his senior management team were the single biggest risk.
Pretty catastrophic for my tenure on that programme :-)
From my personal experience the most catastrophic error a Risk Manager can make is to ignore the warning signs and not take appropriate action just because it would upset business status quo and would cast the RM as a non-team player and a political outcast.
The under-estimation of human stupidity!
Owning the management of risk, rather than the business process owners.
Cowing under to management pressure to ignore warning signs or omitting Risks
Allowing comprises to Risks already identified to make leadership look good or dodge a bullet
ignoring 'people risk'