The Framework

IRIS

A strategic risk intelligence framework built for synthesis, not just risk detection and reporting, for organizations whose risks don't respect the boundaries between security, operations, and enterprise risk.

Start Here

IRIS: One-Page Overview

The framework's two mandates, its theoretical foundation, and where it sits relative to the enterprise risk register, on a single page.

Go Deeper

The IRIS Practitioner's Guide

The full IRIS methodology, refined as the framework continues to develop. Inside: ten core sections, plus appendices covering the interview process, an analyst scorecard, a glossary, six composite case studies, common challenges to implementation, and the framework's theoretical foundation.

Flagship

Executive Leader Edition

For decision-makers with budget authority: the full methodology, staffing architecture, and all six composite case studies.

$199
Buy →

Risk Domain Leader and No-Authority Practitioner editions are in development. Additional editions to follow.

The Problem

Most risk registers only catch what's already been named.

Across the risk domains, the languages aren't the same, the platforms in use are different, and performance metrics and risk assessment methodologies are different. And yet everything gets catalogued in a register and considered managed. But what about what isn't named?

A transboundary risk, per Blondin & Boin's framework for transboundary crisis cooperation, is one whose defining characteristic is its potential to cross functional, institutional, and policy boundaries in a way that cannot be fully assessed, owned, or resolved by any one risk domain: security, legal, financial, geopolitical, operational, or otherwise. The risk's cause, its consequences, or its path to escalation cross the boundaries that separate how those domains define, measure, and report risk. The deciding factor is not which domain the risk originates in. It's whether the risk's trajectory outpaces the institutional capacity of any single owner to see it, define it, or act on it in time.

Cross-domain risk synthesis, visualized

The Shadow Layer

At the core of IRIS are two functions: discovering undetected or unexplored cross-domain risks that don't fit neatly into existing categories, and auditing existing register entries for misdefinition, not just staleness.

Led by a team of interdisciplinary professionals with relevant domain experience, the IRIS functional layer operates beneath the formal risk register. This layer draws on a boundary framework (transfer, translate, transform) to move risk signal across the divides that typically separate security, risk, and operational teams.

Prof. Paul Carlile
Academic Grounding
"IRIS represents a rare and welcome application of rigorous boundary-crossing theory to real-world enterprise risk intelligence practice. Jay has identified the key insight: mistaking a pragmatic boundary for a syntactic one is costly, but mistaking a syntactic boundary for a pragmatic one can be fatal to an organization. IRIS translates that diagnostic power into the hard, sustained work of building the organizational architecture to address it."
Prof. Paul Carlile
Senior Associate Dean, Research & Innovation, Boston University Questrom School of Business
In Practice

Synthesis, not just detection.

IRIS sits downstream of an organization's existing intake and domain-level triage, synthesizing across domains after they've each done their risk assessment and reporting, so nothing that crosses a boundary gets lost in the handoff.

Discovery

Surface the unnamed

Cross-domain risks that don't fit any single team's register.

Audit

Test what's already there

Register entries checked for misdefinition, not just age.

Translation

Cross the boundary

Signal carried across the syntactic, semantic, and pragmatic divides between teams.

Free Reading

The IRIS essays.

Standalone essays on the framework and where risk intelligence is headed. Free to download, no signup required.

Part 1 of 3

Enterprise Risk Was Built Within a Constraint That's Lifting

Why enterprise risk integration has stalled for a generation, and the structural constraint behind it. Download →

Part 2 of 3

One Constraint Lifts. Another Endures.

AI is closing the old constraint, but a deeper one, organizational architecture, remains. Download →

PDF · Free · Part 3 of 3

What It Takes to Lift the Enduring Constraint

What the new synthesis function must be capable of, and what the organization has to provide. Download →

More essays and regular writing on the Resources page.

Want to see IRIS applied to your organization?

Book a short call. No pitch, just a conversation.

Book on Calendly →