Since the energy markets liberalisation at the beginning of the 1990s in Europe, electricity monopolies have gone through a profound evolution process. From an industrial organisation point of view, they lost their monopoly on their historical business, but gained the capacity to develop in any sector. Companies went public and had to upgrade their financial risk management process to international standards and implement modern risk management concepts and reporting processes (VaR, EaR...). Even though important evolutions have been accomplished, we argue here that the long-term risk management process of utility companies has not yet reached its full maturity and is still facing two main challenges. The first one concerns the time consistency of long-term and mid-term risk management processes. We show that consistencies issues are coming from the different classical financial parameters carrying information on firms' risk aversion (cost of capital and short-term risk limits) and the concepts inherited from the monopoly period, like the loss of load value, that are still involved in the utility company decision-making process. The second challenge concerns the need for quantitative models to assess their business model. With the deregulation, utilities have to address the question of their boundaries. Although intuition can provide insights on the benefits of some firm structures like vertical integration, only sound and tractable quantitative models can bring answers to the optimality of different possible firm structures.