← Back to catalog

Executive Intelligence™

Executive Risk Intelligence™

Detecting Emerging Risk Before It Becomes Failure

Every serious failure was detectable before it was visible.

Read emerging failure while it is still cheap to act on.

10 modules · 28 lessons
$995$1,495
Sign in to buy

Secure checkout via Stripe. Full refund within 14 days if you've completed under 10% of the course.

What you'll learn

  • Audit what your risk register contains against what has actually gone wrong, and recognize the class of failure enumeration cannot reach.
  • Measure the detectability window on real incidents, and treat widening that interval as the objective rather than improving prediction.
  • Recognize precursors despite arriving in a vocabulary different from the failure they precede.
  • Read failures in other organizations as free data about your own exposure.
  • Detect drift in conditions where nothing has gone wrong and no line has been crossed.
  • Measure remaining margin rather than compliance with a limit, and recognize why a strong record accelerates its erosion.
  • Convert near misses from closed successes into the most informative data the business produces.
  • Build a near-miss channel that survives contact with the organization's incentives.
  • Identify where exposure genuinely concentrates, and which apparently independent risks move together.
  • Choose indicators that lead rather than confirm, and place sensing inside cadence that already exists.
  • Make a risk that has not happened discussable, and agree thresholds before the case arrives rather than arguing them when it does.
  • Redesign a recurring review to look forward and hold items that have no owner.

The problem this solves

Build the Capability to See a Failure Forming While It Is Still Cheap to Stop

Read the account of almost any serious organizational failure and the same sentence appears.

The signs were there.

It is usually true, and it is almost always unfair. The signs were there in the way a word is there in a page of text you have not been told to look for: present, legible, and unremarkable among everything else present and legible. The people who later look negligent were not ignoring a warning. They were reading a stream of ordinary operational detail in which the warning was one item, indistinguishable at the time from a hundred others that led nowhere.

This is the problem the program addresses, and it is a problem of detection rather than of diligence. Organizations are already competent at managing risks they have named. They maintain registers, assign owners, set appetites, and review them on a cadence. That machinery works, and it works precisely to the extent that the risk was correctly identified in advance. The failures that damage enterprises are rarely drawn from the register. They emerge from the interaction of conditions that were each individually acceptable, each owned by a different person, and each entirely defensible when examined alone.

Executive Risk Intelligence™ develops the faculty of reading emergence. It begins with an uncomfortable audit of what your register actually contains against what has actually gone wrong, and it establishes the quantity that governs everything after: not the probability of a failure, which you usually cannot know, but the detectability window, the interval between the moment a condition becomes detectable and the moment it becomes consequential. Widening that interval is the whole of early warning. Almost every practice in this program is a way of noticing sooner rather than a way of predicting better.

From there the program works through the structures by which failures actually form. Precursors arrive in a vocabulary different from the failure itself, which is why they are not recognized as precursors. Margin erodes without any event occurring, so an organization that has crossed no line can still have consumed everything that was keeping it away from one, and a strong track record accelerates this rather than protecting against it. Near misses, the richest early-warning data most businesses hold, are closed as successes and discarded, because a problem that did not happen leaves nothing to investigate. Exposures that appear independent move together, and concentration rarely sits where the organizational chart implies.

The second half is construction. You will build a sensing capability, which is a different thing from a reporting obligation and behaves differently under pressure, choosing indicators that lead rather than confirm and placing them inside cadence that already exists. You will address the asymmetry that suppresses early warning in every organization: being right too early is indistinguishable from being wrong, and is punished the same way, which is why thresholds have to be agreed before the case arrives rather than argued when it does. And you will redesign a recurring review so that it looks forward and can hold an item that has no owner because it is not yet anyone's problem.

Across eight modules these assemble into your Emerging Risk Sensing Architecture: a precursor map, a drift and margin audit, a near-miss channel, a concentration and coupling map, an indicator set, pre-agreed thresholds, a forward review agenda, and a 90-day build plan for the part of the business you are accountable for. Two optional overlays extend the core, one for regulated and safety-critical environments where precursor data is already mandated and still unread, and one for exposure held by suppliers, portfolio companies, and third parties you cannot instrument directly.

This is the fifth and final program in the faculty line, and it holds a deliberate boundary. Monitoring an assumption you have already named, through tripwires and trigger bands, belongs to Executive Organizational Intelligence™, and this program extends those instruments rather than restating them. Putting a number on a risk once it is explicit, through probability, calibration, and reference classes, belongs to Executive Decision Intelligence™. What sits here is the interval before either is possible: the period when a condition is forming, has no name, appears on no register, and is visible only as something slightly unusual that nobody has any reason to raise.

The outcome is not a longer register.

It is a shorter distance between the moment something starts going wrong and the moment you know.

Who this is for

Three ways in

For yourself

Executives who hold a risk register that has never once predicted the thing that actually happened.

$995

For a cohort

Risk, assurance and L&D functions moving the organization from recording risk to sensing it.

Thirty minutes, no obligation, to work out whether this is the right program before you put anyone through it.

Book a call

For your company

Groups whose operating footprint is concentrated, coupled or correlated in ways the register does not show.

Volume pricing, invoicing and a written proposal. Buying seats directly is on the card above.

Request a proposal

Request a proposal

Tell us roughly what you need and we will send a written proposal. You do not need an account.

We use these details to prepare and send your proposal. Nothing else.

The method

Executive Risk Intelligence™ on the Control Loop

A faculty program teaches the whole executive control loop rather than a sequence, so its modules return to the same steps from different angles. The width of each arc is how much of the program sits there.

Executive Risk Intelligence™ on the Control Loop: the course's modules placed on the six-step control loop.

Curriculum

10 modules · 28 lessons

  • The Risks That Materialize Are Rarely the Ones You Listed10 minPreview
  • Enumeration Against Emergence11 min
  • What a Register Is Actually Good For10 min

Includes: Quiz · Self-assessment · Field assignment · Worksheet

A taste: your free preview

The Risks That Materialize Are Rarely the Ones You Listed

Free previewThe Risks That Materialize Are Rarely the Ones You Listed10 minReading

Every serious failure produces the observation that the signs were there. It is usually true and almost always unfair, and understanding why is where this program starts.

The Founding Principle: A failure large enough to matter has almost always been detectable for longer than it was visible.

Detectable and visible are different words, and the distance between them is the subject of this program. Nothing here rests on predicting better. It rests on shortening that distance.

Introduction

Read the post-mortem of almost any serious organizational failure and you will find the same sentence, phrased slightly differently each time.

The signs were there.

It is usually accurate. It is also, in most cases, deeply unfair, and the unfairness is worth taking seriously rather than dismissing as hindsight bias. The signs were there in the way a particular word is there on a page of text you have not been told to look for: present, legible, and entirely unremarkable among the several hundred other things that are also present and legible.

The people who look negligent in the retelling were not ignoring a warning. They were reading a continuous stream of ordinary operational detail in which the warning was one item, indistinguishable at the time from a great many similar items that led nowhere. Retrospect supplies the one thing they did not have, which is the knowledge of which item mattered. Every account written afterward is written by someone who already knows the answer, and that knowledge cannot be unlearned by the person writing.

This program is built on taking that difficulty seriously. If the problem were carelessness, the answer would be attention. It is not carelessness, so the answer has to be structural.

The Register Works, Within Its Boundary

Start by giving the existing machinery its due, because the argument that follows is not that risk management is broken.

Most organizations of any size maintain a risk register. Risks are identified, scored on likelihood and impact, assigned an owner, given a treatment, and reviewed on a cadence. Appetite is stated. Escalation thresholds exist. In a well-run business this apparatus is genuinely functional, and it works with a precision that is easy to underestimate.

It works, however, on one condition: that the risk was correctly identified in advance. Everything downstream of identification, the scoring, the ownership, the treatment, the review, is machinery for managing a named thing. None of it is machinery for finding an unnamed one. The register is an inventory, and an inventory tells you about its contents.

That is not a defect. An inventory that also detected items it did not contain would be a different instrument. The difficulty arises when an organization holds a register, reviews it diligently, and concludes from the diligence that it is watching its risks. It is watching the risks it has listed, which is a smaller and differently shaped set.

The Retrospective Test

There is a single exercise that settles this question inside any specific business, and it tends to end the argument faster than any general claim.

Take the last five to ten events that actually cost your organization something material. Losses, write-offs, failed programmes, regulatory findings, lost customers, safety events, whatever "material" means in your business. For each, ask three questions in order.

Was it on the register? Not whether something adjacent to it was on the register. Whether the specific condition that occurred was there.

Was it on the register in a form that would have prompted action? This is the question that does the work. A great many failures are technically foreshadowed by a register entry so general that it could not have prompted anything. "Supply chain disruption" is on almost every register in the world and has never told anyone to do anything on a Tuesday.

Did anyone escalate it before it happened? And if they did, what happened to the escalation?

In most organizations the honest answer to the second question, across a set of ten events, is one or two. Occasionally none. This is not a finding about the quality of your risk function, and the exercise is worth running with that stated up front, because otherwise the risk function will experience it as an audit and the answers will get worse. It is a finding about what the instrument is for.

Why the Ones That Get Listed Are Not the Ones That Happen

Three mechanisms select the contents of a register, and none of them selects for what is about to go wrong.

Availability. Registers are populated from what people can readily imagine, and imagination is anchored to what has already happened, to this business or to a competitor recently enough to be discussed. A risk that has never occurred anywhere in the sector is very difficult to place on a list, and the failures that damage enterprises most are disproportionately drawn from exactly that category.

Ownership. A register entry requires an owner, and an owner requires the risk to sit inside somebody's remit. Conditions that form between remits are structurally hard to enter, because the first question asked of a proposed entry is whose it is. A risk that belongs to nobody in particular is a risk that gets left off the list, and Module 5 will show that this is where a large share of serious exposure actually lives.

Defensibility. Entries have to survive review by people who will ask why they are there. This selects for risks that are easy to justify, which means risks that are conventional, and conventional risks are the ones every comparable organization is also watching. The register converges on the consensus set, and the consensus set is well defended precisely because everyone is watching it.

A register is an inventory of the risks you have already imagined. The ones that damage you are drawn from a different population, and the selection mechanisms guarantee it.

The commercial version of this and the operational version look identical in structure. A business whose register lists customer concentration, currency exposure, and key-person risk is describing a conventional set. The loss, when it comes, arrives through a pricing concession granted to retain one account, which interacts with a covenant nobody was reading against that account's payment behaviour. In a regulated operation, the register lists equipment failure, supplier quality, and competence. The event arrives through a temporary process deviation that was individually approved, repeated, and never aggregated. In both cases every component was known to somebody, and the combination was on no list.

Where This Program Sits

Two boundaries define what this course will and will not teach, and both matter from the first lesson.

This program does not teach you to monitor an assumption you have already named. That instrument exists and it belongs to Executive Organizational Intelligence™, which ships the Assumption Register, tripwires, and Trigger Bands. Those are the correct tools for a risk you have identified and want to watch. This program will cite them, extend them, and never restate them. The distinction to hold: a tripwire cannot be set on an assumption nobody has made.

This program does not teach you to put a number on a risk. Probability, calibration, reference classes, and the value of information belong to Executive Decision Intelligence™. Those apply once a risk is explicit enough to be a stated question. This course is concerned with the period before that, when a condition is forming, has no name, and is visible only as something faintly unusual that nobody has any particular reason to mention.

And this program runs the house method. Every PIOL Executive Academy program follows the same six-step loop, named here so you meet it knowingly rather than by accident:

The PIOL Executive Control Loop: Detect, Diagnose, Decide, Intervene, Evidence, Embed.

Modules 2 and 4 are Detect. Modules 1, 3, and 5 are Diagnose. Module 7 is Decide. Module 6 is Evidence. Module 8 is Intervene and Embed.

Executive Reflection

There is a reason this material is uncomfortable for capable executives specifically, and it is worth naming before the discomfort gets attributed to something else.

Competence at managing named risk is genuinely valuable and it is also self-reinforcing in a way that narrows attention. An executive who runs a disciplined register, reviews it seriously, closes actions, and can evidence all of it to a board is doing something demonstrably better than an executive who does not. The apparatus produces evidence of control, that evidence is real, and it is examined regularly by people whose approval matters.

What it does not produce is any signal about its own coverage. A register cannot report the risks it omits, because the omission is exactly the absence of the entry. So the diligence generates confidence that is well founded with respect to the listed set and says nothing whatever about the unlisted one, and there is no mechanism by which the difference becomes apparent until something arrives from outside the list.

The disciplined position is not to trust the register less. It is to stop reading its completeness as evidence of coverage, and to build a second capability whose job is the part the register was never built for.

Executive Exercise: The Register Reality Test

Allow about two hours, and run it yourself rather than delegating it to the risk function. The finding is for you.

Step one. List the last five to ten events that cost your organization something material. Use finance's numbers where they exist. Include events that were contained, since a contained event is still an event that was not anticipated.

Step two. For each, answer the three questions: was the specific condition on the register, was it there in a form that would have prompted action, and did anyone escalate before it happened.

Step three. For every event that was not on the register in an actionable form, establish one thing: was it knowable? Not knowable by you, but knowable by anyone in the organization. In almost every case the answer is yes, and the people who knew will be identifiable. Write down who they were and what they saw.

Step four. For each of those people, answer why what they saw did not travel. Options include that they did not recognize it as significant, that they had nowhere obvious to put it, that raising it carried a cost, or that they raised it and nothing happened. Record which, without correcting anyone.

The output is your Register Reality Audit, the first deliverable of the course, and the baseline every later module is designed against. Step three is the one that matters. It establishes whether your problem is that the information does not exist, which is a genuinely hard problem, or that the information exists and does not travel, which is the far more common case and the one the remaining modules address.

Key Insight

A risk register is machinery for managing named risk, and every part of it downstream of identification presumes the identification was correct. It cannot report its own omissions, because an omission is the absence of an entry, so diligent review produces confidence about the listed set and no information at all about the unlisted one. Three mechanisms select register contents, availability, ownership, and defensibility, and none selects for what is about to go wrong. The failures that damage enterprises are drawn from a different population than the one the register describes.

Key Takeaways

The observation that the signs were there is usually accurate and usually unfair, because the signs were present and legible among a great many other present and legible things, and only retrospect supplies the knowledge of which one mattered. The retrospective test that settles this in any specific business is whether the last five to ten material events were on the register in a form that would have prompted action, and in most organizations the honest answer across ten events is one or two. Availability anchors registers to what has already happened somewhere; the ownership requirement excludes conditions forming between remits; and the defensibility requirement converges every register onto the same conventional set that all comparable organizations are already watching. The distinction that separates this program from the flagship's instruments is that a tripwire cannot be set on an assumption nobody has made, and the distinction from Decision Intelligence is that this program covers the period before a risk is explicit enough to carry a number.

PIOL Principle #1: A register is an inventory of the risks you have already imagined, and it cannot report what it omits; the failures that reach you are drawn from a different population.

Want the rest of the course? Sign in or create an account, then enroll.

Ready to start?

$995 for full lifetime access. Full refund within 14 days if you've completed under 10% of the course.