Breadcrumb

  • Home
  • Subramanian: The Unifying Risk Mindset Map

Search form

Main navigation

  • Home

Subramanian: The Unifying Risk Mindset Map

Thursday, 4 December, 2025 - 08:27

Diversity in risk management approaches isn't a sign of weakness or incompleteness. Instead, it reflects the complex, varied nature of risk itself, which demands tailored solutions for different organisational needs, cultures, and objectives. This plurality is a strength says, Shankar Subramanian .

Based on the core principles of leading frameworks and my analysis of the search results, the most effective approach is not to adopt a single "best" framework, but to build a context-driven, integrated, and holistic practice. The goal is to move from a rigid, checklist-driven model to a dynamic strategic capability.

To help you understand the landscape, here is a comparison of the three main "schools of thought" on risk and the two leading frameworks for structuring your approach.

The Three Schools of Thought on Risk :

Your question touches on a fundamental philosophical debate in the field. Different organisations align with one of these three mindsets.

1. The Negative Lens School

· Core Belief: Risk is inherently a threat, danger or hazard.

· Focus: Exclusively on preventing or minimising negative outcomes and losses.

· Implication: Management is defensive and protective. While it safeguards assets, this view can lead to a culture of risk aversion and missed opportunities.

2. The Duality School

· Core Belief: Risk includes both threats and opportunities (uncertainties with positive effects).

· Focus: Managing downsides while proactively identifying and exploiting potential upsides.

· Implication: Management is balanced. It aligns with modern standards like ISO 31000 which explicitly includes opportunities in its process. The challenge is overcoming the natural human tendency to focus more on threats.

3. The Embedded Uncertainty School

· Core Belief: Risk isn't a separate category; it is the fundamental uncertainty inherent in all decision-making and operations.

· Focus: Integrating consideration of uncertainty seamlessly into "doing the job" at all levels.

· Implication: Management is holistic and cultural. This is the most mature perspective where intelligent risk-taking becomes a source of innovation and competitive advantage.

The Frameworks: ISO 31000 vs. COSO ERM :

To operationalise any of these mindsets, organisations often turn to structured frameworks. The two most prominent are ISO 31000 and COSO ERM. They are not competing standards but serve different, often complementary, purposes.

ISO 31000: The Universal Principles :

· Origin: International Organisation for Standardisation (global).

· Core Philosophy: A principles-based, flexible guideline for managing risk of any type.

· Key Strength: Its universal adaptability. It provides a common language and a process (establish context, identify, analyse, evaluate, treat, monitor) that can be integrated into any existing organisational process.

· Best For: Organisations seeking a foundational, flexible approach to build or benchmark their risk culture, especially in international or non-financial contexts.

COSO ERM: The Strategic & Governance Framework:

· Origin: Committee of Sponsoring Organisations of the Treadway Commission (U.S.-based).

· Core Philosophy: Integrating risk management with strategy-setting, performance, and corporate governance.

· Key Strength: Strong governance and strategic alignment. Its structured "cube" model clearly links strategy, objectives, and performance, making it highly effective for internal control and board-level oversight.

· Best For: Organisations, particularly in regulated or financial sectors, that need to tightly align risk with strategy and demonstrate robust governance to stakeholders.

Shankar Subramanian can be contacted via LinkedIn, where this article was first published at https://www.linkedin.com/in/shankar-subramanian-/

 Comparative Summary :

· Approach: ISO is principle-led and process-focused; COSO is component-led and strategy-focused.

· Flexibility: ISO is highly adaptable; COSO is more structured.

· Integration: ISO integrates with other management systems; COSO integrates with strategy and performance.

The Complete and Effective Approach: A Hybrid, Dynamic Model :

No single school or framework is universally "complete." The most effective approach synthesises the strengths of multiple perspectives into a living practice. Based on the principles in the search results, here are the hallmarks of a complete risk management approach:

1. Move from Siloed to Enterprise-Wide (ERM)

Abandon the traditional, reactive model of managing risks in departmental silos (e.g., just IT or finance). Adopt an Enterprise Risk Management (ERM) perspective that provides a holistic, coordinated view of how risks interact across the entire organisation to affect strategic objectives.

2. Balance Quantitative and Qualitative Analysis

Use both lenses for a complete picture.

· Quantitative Analysis: Use data, statistics, and financial models for measurable risks (e.g., market, credit). It's precise but data-hungry and time-consuming.

· Qualitative Analysis: Rely on expert judgment and experience for complex, intangible, or emerging risks (e.g., reputational, regulatory). It's faster and captures nuance but can be subjective.

3. Integrate Frameworks, Don't Just Choose One

The most resilient organisations often use ISO 31000 as their foundational philosophy and overarching process, leveraging its flexibility and common language. They then apply the COSO ERM structure to ensure strong governance, strategic alignment, and integration with internal controls. This hybrid model is explicitly recognised as a best practice.

4. Focus on Implementation & Culture Over Compliance

The greatest challenge isn't selecting a framework, but implementing it in a way that changes behaviour. 

Success depends on:

· Leadership & Tone at the Top: Active board and C-suite sponsorship is non-negotiable.

· Breaking Down Silos: Establish clear governance to ensure communication and data flow across departments.

· Building a Risk-Aware Culture: Move from a compliance checklist to a culture where considering risk and opportunity is part of everyday decision-making.

How to Build Your Accepted Approach :

To turn this insight into an accepted and implemented approach in your organisation, follow these steps:

1. Assess Your Current State: Identify which "school of thought" dominates your culture. Is risk only seen as a negative? Recognise your starting point.

2. Define Your "Why": Clarify if your primary driver is regulatory compliance, strategic resilience, innovation, or all three. This will guide your framework emphasis.

3. Propose the Hybrid Model: Advocate for using ISO 31000's principles as your core methodology, strengthened by COSO ERM's governance components for strategic alignment.

4. Start with a pilot: Don't attempt a full-scale rollout. Apply the integrated approach to a single strategic project or business unit to demonstrate value, learn lessons, and build credibility.

5. Measure and Communicate Value: Report on how risk management has protected value, saved resources, or identified new opportunities—not just on how many risks were logged.

In essence, the existence of multiple schools and frameworks is a testament to the maturity of the risk management discipline. The complete approach is context-aware, intelligently hybridized, and culturally embedded, transforming risk management from a defensive protocol into a core capability for strategic success.

To help you evaluate what your organisation needs most, consider which of these starting points best describes your situation?

· We need a common language and basic process to get everyone on the same page.

· Our board and regulators are demanding better risk governance and reporting.

· We want to use risk management proactively to drive innovation and competitive strategy. 

 


Republished with permission


 

About this section

Opinion pieces or "Op-Eds" are the home-made bombs of the publishing world. So long as they meet editorial standards, are not intentionally offensive with a view to causing hurt or insult and are relevant to our field of endeavour, we will look at submissions.

We like contentious, we like contrarian views. We don't like pretty much any -ism . We recognise that Opinion pieces are one person's view and are not balanced (if they are balanced and reach a reasoned conclusion, they are probably more suited to the Articles section). We do not like acronyms and buzzwords.

Op-Eds are the author's personal views and do not necessarily represent the views of World Money Laundering Report or its publishers.

To submit an Opinion piece, please complete the Contact form.

Footer menu

  • Weekly Digest (opens in new tab)
  • Images attribution (opens in new tab)
  • Corporate, privacy, intellectual property and access (opens in new tab)
  • Advertising and Recommendations (opens in new tab)
  • Promote your business (opens in new tab)
  • Enquiries (opens in new tab)


 

BOT AND SCRAPER ACCESS DENIED

 


 

Built with Drupal     |     Hosted by Siteground     |     Template by Alaa Haddad     

Design by Vortex Centrum Limited    |     Some services provided by Google Workspace    

Posters and other merch by ProjectLXX   |   Privacy and security services by Surfshark and Firetrust. 


Nothing in this website is intended to be or shall be taken as legal advice. 

You should always seek advice from a practitioner experienced in this area. 


Everything on this website is copyright Nigel Morris-Cotterill and/or Vortex Centrum Limited for itself or one of its business units. No downloading, printing or other means of replicating or reusing is permitted. In particular, all bot access is denied and all scraping of content will result in the legal action set forth in the terms and conditions in this site. For legal, cookies and privacy see vortexcentrum.com.

Copyright 1999- © 2026 Vortex Centrum Limited - All rights reserved. Bot access denied.