Foresight and resilience

Foresight, Connected Risks and Organizational Resilience

Resilience is built before disruption. It connects weak signals and causal paths with the critical outcomes, tolerances, authority and response options that must be ready when normal conditions fail.

Preparedness

Protect critical outcomes before disruption begins.

Resilience connects tolerances, dependencies, authority and tested alternatives so the organization can adapt when normal assumptions fail.

Emerging risk

From insight to foresight to action

Foresight before hindsight

Historical data is necessary but insufficient. Major disruptions often begin as weak signals that appear unrelated until their transmission paths become visible.

Signals may emerge across regulation, markets, customers, operations, technology, geopolitics and social expectations. Individually they can look immaterial. Together they may change a strategic assumption, accelerate customer behavior, increase liquidity pressure or expose an operational dependency. Foresight is the discipline of connecting those signals before urgency removes choice.

This requires causal reasoning, not disconnected storytelling. A scenario should explain the direction of relationships, the time lag, the assumptions and the point at which an effect becomes material. It should distinguish a root driver from a symptom and reconcile the narrative with financial and operational measures.

Risk categories remain useful for ownership and measurement, but material events rarely stay within one category. A market movement can create liquidity pressure, customer action, operational strain and a hurried management decision. A regulatory change can alter product economics, capital, systems, behavior and reputation at the same time. The most dangerous exposure may be the combination of risks assessed separately.

Regulatory change as a strategic issue

Regulatory change should not begin as a document or system implementation exercise. Changes in solvency, accounting, governance, customer protection or capital can alter strategy, product economics, asset allocation, data, operating models, management incentives and customer outcomes.

The first question is therefore: which management decisions will this change alter? Once the strategic and economic implications are understood, the organization can translate them into policy, process, system and reporting requirements. Technical compliance without strategic interpretation is an incomplete implementation.

Anticipate

Scan signals, test assumptions and identify plausible changes before the threat becomes obvious.

Integrate

Connect causal paths across strategy, customers, operations, finance, capital and reputation.

Activate

Convert insight into thresholds, decision options, accountable actions and escalation.

Organizational resilience

Protect critical outcomes

Resilience is built before disruption

Resilience is the ability to anticipate, adapt and continue delivering critical outcomes when normal assumptions, resources or processes no longer hold.

The starting point is the outcome or service that must be protected. Which customers, obligations or public interests depend on it? What level and duration of disruption can be tolerated? Which people, technology, facilities, data, funding and third parties are necessary? This outcome view exposes dependencies that functional continuity plans can miss.

Business continuity plans are necessary but not sufficient. A resilient organization knows the trade offs that become acceptable in stress, who has authority to make them and which alternative arrangements are genuinely ready. It also has communication discipline, financial capacity and management actions that have been tested rather than merely documented.

Resilience improves through learning. Incidents, near misses, exercises and control failures should update assumptions, tolerances, dependencies and response arrangements. Recovery is not complete when service resumes. It is complete when the organization understands why the disruption propagated and changes the system accordingly.

Critical outcome test

Priority

Which outcome must be protected first, and why?

Tolerance

How much disruption can customers and obligations bear?

Dependency

Which internal and external resources make it possible?

Authority

Who can make trade offs when normal governance is too slow?

Alternative

What tested arrangement works when the primary path fails?

Risk culture is how people think before acting

Risk culture is visible in daily choices: whether people test assumptions, raise bad news early, own exceptions and welcome challenge before commitment. Its strength is not measured by the frequency of risk terminology. It is measured by whether people act differently because they understand the uncertainty and consequence.

A healthy culture asks what could go sideways, which assumption may be wrong, who may be affected, what evidence supports the decision and what should cause reconsideration. It treats escalation as responsible behavior rather than disloyalty and protects dissent long enough for a concern to be examined on its merits.

“Culture becomes visible at the moment a person decides whether to surface an uncomfortable fact or let the organization continue with a comfortable assumption.”

Applicability

Across multiple industries

The framework travels. The context changes.

The approach applies wherever leaders allocate resources, accept uncertainty, maintain controls and protect important outcomes.

Cross industry applicability should not mean forcing every organization into one risk taxonomy. It means beginning with the same disciplines: clarify the objective, identify uncertainty, trace consequences, compare options, test capacity, set conditions and assign action. Industry knowledge then determines what matters within each discipline.

01

Financial services

Capital, solvency, liquidity, asset and liability management, product economics, conduct and regulatory change.

Can the strategy remain viable when market, behavior, liquidity and capital stresses occur together?
02

Diversified groups

Corporate parenting, delegation, shared services, concentration, portfolio choices, acquisitions and integration.

Do governance rights, risk ownership and group support match the exposures created across the portfolio?
03

Technology and digital

Cyber risk, third parties, data, artificial intelligence, service reliability, model governance and rapid change.

Which critical outcomes depend on technology, and what human decision remains accountable when automation fails?
04

Infrastructure and public services

Continuity of essential services, long dated assets, public accountability, safety, mandate and financial capacity.

Which services must continue, within what tolerance, and who has authority when normal procedures are too slow?
05

Consumer and operating companies

Customers, supply chains, quality, pricing, working capital, conduct, operational control and brand trust.

How could an operational weakness transmit into customer harm, financial loss and a wider loss of confidence?