Is the Board Governing the Future or Reviewing the Past?

Boards receive more risk information than ever.

Risk dashboards track current exposures. Committee papers explain incidents and control weaknesses. Audit reports identify findings. Key risk indicators show movements against thresholds. Emerging-risk exercises consider what may be coming next.

All are important. Boards cannot govern effectively without understanding what has happened, what is happening now and whether existing controls are working. But there is another question worth asking: does that information arrive early enough to influence what happens next?

A risk report can be accurate, comprehensive and well governed while still being largely retrospective. By the time an emerging threat has become a recognised risk category, moved sufficiently to change a key risk indicator or generated an incident serious enough to reach the board, many of the decisions that shaped the organisation’s exposure may already have been made.

That matters when geopolitical developments can quickly alter markets and supply chains, technological capabilities advance faster than many governance cycles, and changes in operating conditions can reshape established risk assumptions well before formal indicators show a breach.

Boards therefore need a good account of the current risk position, but they also need some sense of when that position is becoming less reliable.

The rear-view mirror still matters

There is a reason governance relies heavily on historical information.
Realised events provide evidence. Losses can be quantified. Control failures can be investigated. Trends can be compared. Audit findings can be validated. Management actions can be tracked.

Emerging risks are less accommodating. Evidence may be incomplete, probability difficult to estimate and expert views divided. Some anticipated threats will never materialise, while developments that initially appear peripheral can become important very quickly.

That makes caution appropriate. Boards should not replace evidence with speculation.
The real challenge is to combine what is known about the organisation today with credible signs that the conditions around it are beginning to shift.

Consider a business service that depends on external technology providers, specialist staff and stable transaction volumes. Current reporting may show acceptable supplier performance, stable incident volumes and controls operating within tolerance.

Now suppose one provider is becoming more strategically important, experienced staff are leaving, volumes are rising, and the threat environment is changing.

Any one of those developments may be manageable. Together, they may alter the assumptions on which the existing risk assessment depends.

Governance needs to recognise that change before an incident confirms it.

Annual horizon scanning can become an administrative exercise

Most established risk functions already have some form of emerging-risk or horizon-scanning process.

The weakness is often not the absence of foresight, but what happens to it once it has been identified.

An annual exercise may flag geopolitical developments, regulatory change, artificial intelligence, cyber threats or shifts in customer behaviour. The resulting list can be thoughtful and well researched.

Yet the value of governance lies in what follows. Which assumptions might those developments unsettle? Which existing risks could they amplify? Which decisions should management revisit?

A geopolitical development, for example, may affect supplier availability, sanctions exposure, cyber activity, market conditions or the ability to operate in particular jurisdictions. AI may change data risk, model risk, third-party exposure, workforce capability or operational resilience.

Treating each issue simply as an emerging-risk theme can obscure how it interacts with exposures the organisation already has.

This is where horizon scanning can become disconnected from ERM. One process looks outward for developments. Another reports the established risk universe. Strategy and investment decisions may sit elsewhere again.

Individually, each process can be sound. The problem comes when insight moves between them too slowly, or not at all.

Foresight only becomes useful when it changes the quality or timing of a decision.

Weak signals rarely arrive with a risk label

Future risk is difficult to govern partly because early signals are often ambiguous.

A rise in control exceptions may be temporary. Higher employee turnover may have no material risk consequence. A supplier’s performance may deteriorate and recover. A regulatory proposal may change substantially before implementation.

Boards cannot respond to every movement. What deserves attention is the point at which several developments begin to form a pattern.

Suppose customer complaints are rising in one process. At the same time, manual overrides are increasing, a supporting technology platform is undergoing significant change, and the responsible team is experiencing unusually high turnover.

Each indicator may have its own explanation. Seen together, however, they may suggest that the operating environment around the process is changing faster than its controls and governance.

Traditional reporting can make that difficult to see. Incidents may sit in one report, controls in another, suppliers elsewhere, audit findings on another agenda and external intelligence within an emerging-risk process.

The task is to interpret the relationships between those signals, without turning every weak movement into a prediction.

What matters is recognising when the combination is strong enough to justify attention before a formal threshold has been crossed.

Risk categories can anchor thinking to yesterday’s problems

Risk taxonomies are necessary. Without consistent categories, firms would struggle to aggregate exposures, allocate ownership or report coherently.

They can also shape what an organisation notices.

Once a risk is defined, measured and assigned, governance naturally becomes better at monitoring it in its recognised form. New developments are then interpreted through that structure.

At times, however, the important change is taking place across the structure rather than within one category.

A technology development can affect operational processes, customer outcomes and third-party exposure simultaneously. A geopolitical shock may create cyber, market, supplier and regulatory consequences at the same time. A strategic decision to automate a process may alter exposure to data quality, workforce capability and resilience together.

If each function considers only the implications within its own category, every individual component may be identified while the overall shift in exposure remains less visible.

This is where ERM earns its place. It should help senior leaders see when external change is altering existing exposure and when several movements, taken together, warrant a different decision or level of attention.

The answer is rarely to invent another category. More often, it is to recognise that the existing categories no longer tell the whole story.

Scenario assessment should test decisions

Scenario assessment can help boards move beyond a single expected future, but its value depends on what happens after the scenario has been described.

A detailed scenario about geopolitical fragmentation, a major technology disruption or an AI-enabled cyber event may generate a useful discussion. The stronger test is whether it exposes assumptions that management is relying on.

What happens to an important service if a key provider becomes unavailable while internal teams are already managing another disruption?

Which strategic plans depend on continued access to particular markets, data, infrastructure or specialist skills?

Which controls would come under pressure if transaction volumes, attack speeds or regulatory demands changed significantly?

These are not exercises in prediction. They are ways of testing whether current decisions remain sensible across a credible range of conditions.

A useful scenario may strengthen confidence in the existing strategy. It may also reveal that an apparently acceptable risk position depends on assumptions that have never been tested under pressure.

Either outcome gives the board something useful to govern.

External intelligence needs an internal destination

Firms have access to substantial external information: regulatory publications, geopolitical analysis, loss events, peer experience, threat intelligence, market data and industry research.

The harder part is deciding what any of it means internally.

An external loss event becomes more useful when management tests whether the same conditions exist within its own organisation. A regulatory development matters when the firm understands which activities, controls and accountabilities it could affect. Peer experience has value when it challenges assumptions behind an internal assessment.

Information becomes intelligence when it changes the understanding of exposure or informs a decision.

That means horizon scanning cannot end with circulation of an emerging-risk report. Relevant developments need a route into risk assessment, scenario analysis, control monitoring, assurance and strategic decision-making.

For the board, the more telling question is not simply what management is watching, but what management has reconsidered because of what it has seen.

The timing of the challenge

Good governance is often judged by the quality of challenge around a decision.
Timing deserves just as much attention.

A risk function can produce excellent analysis and still have limited influence if it enters the process after the strategic direction has effectively been settled.

The same applies to boards. By the time a major investment, supplier relationship, market entry or technology programme reaches final approval, substantial resources and senior sponsorship may already be committed. Challenge remains possible, but changing direction is harder.

Future-oriented governance therefore depends partly on when risk intelligence enters decision-making.

Risk functions need enough proximity to strategic change to identify assumptions while they can still be tested. Boards need visibility of material uncertainty before choices become difficult to reverse.

That does not mean risk should obstruct experimentation or demand certainty before management acts. In a fast-changing environment, waiting for complete information may itself create risk.

What matters is the quality of the commitment being made.

Management should be able to explain what it believes, what evidence supports that belief, what could prove it wrong and which signals would cause the organisation to reconsider.

At that point, foresight stops being a separate exercise and becomes part of decision discipline.

What should the board expect to see?

A more future-oriented risk conversation does not necessarily require a larger board pack. It may require a different emphasis within it.

Alongside current exposures and realised events, boards need enough information to understand where important assumptions are changing, which external developments could materially alter existing risks and where early combinations of evidence deserve attention.

Useful questions include:

  • Which assumptions behind our strategy or risk appetite have become less certain?
  • What external developments could materially change several of our existing risks at the same time?
  • Where are early movements appearing in incidents, control exceptions, complaints or supplier performance before formal thresholds are breached?
  • What have we learned from significant external events or peer experience, and have we tested whether similar conditions exist here?
  • Which scenarios would make our current controls, recovery plans or risk assessments unreliable?
  • Is risk intelligence reaching decision-makers early enough to influence commitments before they become difficult to reverse?

The answers matter more than the creation of another foresight dashboard.

Governing uncertainty without pretending to predict it

Boards cannot govern only through the rear-view mirror. Nor can they govern through prediction.

The task is more demanding than either.

They need reliable evidence about what has happened, a current view of how the organisation is operating and enough foresight to recognise when the assumptions connecting today’s position to tomorrow’s decisions are becoming less dependable.

Incidents and losses provide lessons from the past. Control and performance information show how the organisation is operating now. Horizon scanning, external intelligence and scenarios help test what could change next.

The question is whether those different forms of evidence come together soon enough to matter.

For GRAC functions, good risk reporting should therefore be judged by more than whether the board has been accurately informed. It should also be judged by whether the information arrived early enough to influence a decision.

A board can be exceptionally well informed about risks that have already become visible.

The harder governance test is whether it can recognise when the conditions for the next material risk are beginning to form.

Stay up to date with the latest stories from the world of governance, risk, audit and compliance >>>

Facebook
Twitter
LinkedIn