top of page

Is moving to more predictive risks and having standards realistic?

4 hours ago
2 min read
Does our risk tech all speak the same language?
Does our risk tech all speak the same language?

As needs move to predictive risks, how can that be better articulated?


I've had many conversations in recent times on how there is a real need to shift from reactive risk to a more proactive and predictive risk ecosystem. Over the past year, much of the intel industry's efforts are often built around webinars and documents (often long PDF reads). Now you can transcribe webinars and utilise documents to use AI to do the deeper analysis for you ... but is that really enough pinning you hopes that AI will find the areas for focus and actually do anything about them.


So, seeing so many advisories, forecasts, risk registers (whether public or private sector focused) it makes me think there is a real need to either standardise around this ... or at least have a framework that takes this data and makes it easier for platforms (and AI) to ingest and provide some analysis and guidance around.


Advisories

These can range from very wide geopolitical situations aimed at security leadership, either describing the situation in a particular geography or specific advice on an upcoming event ... to very personalised instructions for individuals living or travelling in those areas with dos/don'ts, medical advice etc. The challenge is whether these need articulating in a consistent way or not, it is more about whom they are aimed at. Often these would impact planning around shorter term goals, such as daily business operations and travel policy.


Forecasts

Whether these are short, mid or long-term projections of the future, somewhat similar to wider scale advisory information these lean more towards possibilities and more strategic decision making. Whether they focus on the upcoming year or the next decade, articulating a forecast is a little more tricky as the more distant you look, the probabilities may become more vague. Building a model for this across all of your intel would really help organisations plan better.


Risk Registers

Love them or hate them, all organisations need in some form to identify threats, analyse their potential impact and formulate some form of mitigation to accept, reduce or prevent them. Again, no standards exist in this area, even though many countries, cities and regions provide risk registers, they are often PDF documents. There are many ERM platforms that will build the register for you, but are you response platforms plugged into these?


Let me know your thoughts on where you are seeing any moves towards common frameworks or approaches. We now have so many platforms that manage risk from identification, to response and audits ... we need some form of continuity to how risk is articulated and processed.


Comments


© 2025-26 by Evo Strategy.

Powered and secured by Wix

Follow Us:

  • LinkedIn
bottom of page