Rewiring enterprise risk management

Aerial view of a goup working
  • August 2026

Enterprise Risk Management (ERM) came about to bring understanding to uncertainty. Its foundations still matter: organisations need to make difficult decisions with risk in mind, give leadership visibility of the highest-priority risks that could most affect success, and ensure that the controls underpinning those risks are understood and effective. But those foundations are no longer enough.

As uncertainty shifts from exception to expectation, this should be ERM’s moment. Yet in many organisations, executives and CROs struggle to define its value. Too often, ERM relies too heavily on a process-led, backward-looking view of uncertainty: risks are classified, reviewed on a cycle and reported through established governance, often after decisions have already been made. Instead of being dynamic and decision-focused, ERM is too often siloed, static and process-driven. The result is a critical gap between where risk is created through decisions and where risk is reviewed. That gap also exists because risks move across functions, expose hidden dependencies and combine in ways that formal categories rarely capture.

It is clear that ERM is at a crossroads.

ERM is not obsolete, but it is under-imagined. Its next stage of value will come from moving beyond process as the main measure of effectiveness to rewiring ERM around the decisions that shape the organisation’s exposure.

In this article, we outline three big shifts to help rewire ERM, along with a few practices leaders will need to leave behind.

Start with decisions

Risk emerges through the choices organisations make, from strategic bets to everyday operational decisions. But those choices rarely happen in a single moment. They are made through conversations, assumptions and informal judgement long before they appear in a governance or investment committee pack.

That creates a timing problem. Many organisations still review risks after strategies have been set, programmes have started and commitments have already been made. The real test is whether ERM is present in the formal and informal moments where choices are being made, rather than reporting on risks after the fact.

A rewired ERM model would look further upstream. It would ask where important decisions are actually made “in the wild”, what assumptions are being carried forward, and where challenge would be most useful before momentum becomes difficult to reverse. That applies not only to major strategic choices, but also to the controls, routines and processes through which thousands of decisions are made every day. Used well, this can help risk teams improve the quality of those decisions before outcomes are locked in.

This is not about making risk a brake on the organisation but about helping leaders make better choices while there is still time to act.

The measure of ERM’s value needs to be reframed. The question is not only whether risks have been discussed, captured and actioned, but whether better decisions are being made because risk expertise is present at the right point, in the right form.

Three steps to map decisions ‘in the wild’
 

  • Follow the decision, not the process. Pick one or two important decisions and trace how they actually develop: through formal governance, informal conversations, assumptions and early commitments. Compare what happens in practice with what the organisation says should happen.
  • Find the real decision points. Identify where judgement is actually exercised: who is involved, what options are considered, what assumptions are carried forward, and where challenge enters - or fails to enter - the process. Pay attention to recurring decisions embedded in routines as well as major one-off choices.
  • Get close enough to see the pressures. Spend time with the teams making the decisions. Observe the constraints, incentives and trade-offs they face, and ask what upcoming decisions matter most. The aim is to understand before intervening, then identify where risk input could improve the decision while there is still time to change course.

Prepare for how disruption really moves

The second shift is to rewire ERM for interconnected preparedness.

Risk categories create structure and accountability, but they can also make disruption look more orderly than it is. Few critical risks stay in one lane for long. In fact, they can defy organisational structures altogether. A cyber incident, for example, may begin as a technology issue but quickly become an operational, customer or regulatory challenge. A single event can expose dependencies that may not be visible in a traditional taxonomy.

ERM therefore needs to ask a more practical question: what must keep working for the organisation to remain viable under stress?

That is where the idea of the ‘Minimum Viable Company’ becomes useful. At its simplest, this means defining the smallest set of services, processes, functions and dependencies that must be sustained to keep the organisation viable during a crisis. Rather than trying to predict every possible disruption, ERM can help build a clearer view of what the organisation depends on when conditions deteriorate. This creates a different lens through which to prioritise the risks and scenarios that matter most.

The specifics will vary. Some organisations will need to focus on critical technology, while others may need stronger fallback processes or clearer escalation routes. But the principle is the same: understand critical dependencies, stress-test vulnerabilities and practise responses before disruption exposes them.

Preparedness is not pessimism but a source of confidence. It moves ERM beyond the impossible task of predicting the next crisis and towards a clearer understanding of what the organisation must protect, preserve and restore when several things go wrong at once.

Using Minimum Viable Company as an additional lens for ERM

One way to put this into practice is to use Minimum Viable Company (MVC) as a management prioritisation tool. Because risks are interdependent, MVC helps leaders focus scarce attention, investment and resilience capacity on the capabilities and dependencies that matter most, rather than treating risks as neat, isolated categories - disruptions do not care about organisational structures. PwC has applied the same logic at national scale through the concept of a ‘Minimum Viable UK’, looking across critical national infrastructure and the interdependencies required to keep essential economic and civic activity functioning through severe disruption. See Connecting for continuity in a crisis.

Questions to stress-test your MVC:

  • What outcomes must you continue to maintain during a catastrophic disruption like a cyber attack?
  •  What is your Business-As-Usual process that fulfils this outcome?
  • What dependencies does the outcome rely on – people, third parties, tech / data, facilities?
  • Are there any existing workarounds or 'resilience solutions' to achieve this outcome during a catastrophic disruption? If not, what resilience solutions should be designed?
  • How long can we tolerate disruption; how quickly must we recover our critical services?
  • Have we tested or exercised our resilience solutions under real stress?

Incorporate AI to sharpen human judgement

The third shift is to rewire ERM to be human-led and AI-amplified.

The opportunity is not to make the existing risk machine faster. Automation may create efficiency, but it does not improve judgement. The more important question is how AI can extend the reach and imagination of risk teams.

Used well, AI can help detect weak signals, test assumptions and explore scenarios at pace. It can reveal patterns that traditional reporting may miss and help leaders ask better questions under uncertainty.

But ERM should remain human-led. The most important risk judgements involve ambiguity, complexity and behaviour under pressure. AI can expand the field of view, but people still need to interpret what matters and decide where to intervene.

The aim should therefore be to use AI to amplify judgement, not create the illusion of automated certainty. AI can make risk teams more curious and responsive, but it cannot replace the human skill of challenging assumptions at the right moment.

Human-led, AI-amplified
 

AI can add value by analysing large datasets at pace and helping risk teams spot weak signals and anomalies: points in the data, trends or assumptions that do not quite make sense. Teams are also using AI to rapidly generate risk scenarios to explore how different conditions could affect a decision in close to real-time. But the value comes from what people do next: risk professionals use their judgement and expertise to investigate those prompts, connect them to business context and uncover hidden assumptions, dependencies or emerging risks that might otherwise remain unseen. Not every signal will matter, but used this way, AI helps build a fuller picture of uncertainty and strengthens human judgement rather than replacing it.

Let go of outdated concepts

As risk teams evolve, they also need to let go of outdated concepts and slogans.

One distraction is the idea that “risk is opportunity”. Organisations do, of course, take risks to create value. But most senior leaders still use risk in its practical sense: the ‘bad things’ that could happen and affect performance. Trying to reframe the word itself can make the task of bringing people along harder, not easier. Risk functions do not need to become substitute commercial teams to prove their relevance. Their distinctive contribution is to make opportunity more robust by testing assumptions, clarifying downside and helping leaders understand what is being staked. In short, effective ERM teams help leaders and organisations see things they otherwise would not, at moments that matter.

Another is putting “risk-based” in front of every activity. Risk-based planning, risk-based prioritisation and risk-based decision-making may all have value, but the language can become self-referential. The aim is not to make the organisation speak risk’s language, but to help the organisation make better choices.

A third is broad talk of “risk culture.” Culture matters, but the phrase can be too vague to act on, and expecting a small risk function to change entire organisational cultures - because most organisations have more than one - is unrealistic.

More useful is a focus on specific behaviours. Do leaders invite challenge early enough? Are weak signals escalated? Are assumptions tested while there is still time to change course? ERM becomes more practical when it moves from abstract culture change to targeted behavioural intervention. And when risk functions do that, something powerful happens: attitudes start to shift in ways that broad “risk culture” programmes could never achieve.

A more useful role for risk

Rewiring ERM does not mean abandoning discipline, governance or control. It means aiming them at a more valuable purpose.

The future risk function should be more outward-looking, more collaborative and more closely connected to the decisions that shape the organisation’s exposure. It should help leaders understand uncertainty before choices are locked in, build preparedness around the capabilities and dependencies that matter most, and use AI to strengthen rather than replace human judgement.

That is a demanding agenda but a necessary one. It recognises what many risk leaders already know: the current model is under strain. It also gives them a constructive direction, not to reject ERM but to reimagine its role.

The organisations that do this well will not simply manage risks more efficiently. They will make better decisions while there is still time to act, respond with greater confidence under pressure and build resilience around how risk actually moves, not how formal categories suggest it should.

Contact us

Callum Bright

Callum Bright

Director - Enterprise Risk Management, PwC United Kingdom

Tel: +44 (0)7802 659019

Ben Cattaneo

Ben Cattaneo

Senior Manager, Risk and Resilience, PwC United Kingdom

Tel: +44 (0)7483 420185

Follow us