A strategic risk intelligence framework built for synthesis, not just risk detection and reporting, for organizations whose risks don't respect the boundaries between security, operations, and enterprise risk.
The framework's two mandates, its theoretical foundation, and where it sits relative to the enterprise risk register, on a single page.
The full IRIS methodology, refined as the framework continues to develop. Inside: ten core sections, plus appendices covering the interview process, an analyst scorecard, a glossary, six composite case studies, common challenges to implementation, and the framework's theoretical foundation.
For decision-makers with budget authority: the full methodology, staffing architecture, and all six composite case studies.
Risk Domain Leader and No-Authority Practitioner editions are in development. Additional editions to follow.
Across the risk domains, the languages aren't the same, the platforms in use are different, and performance metrics and risk assessment methodologies are different. And yet everything gets catalogued in a register and considered managed. But what about what isn't named?
A transboundary risk, per Blondin & Boin's framework for transboundary crisis cooperation, is one whose defining characteristic is its potential to cross functional, institutional, and policy boundaries in a way that cannot be fully assessed, owned, or resolved by any one risk domain: security, legal, financial, geopolitical, operational, or otherwise. The risk's cause, its consequences, or its path to escalation cross the boundaries that separate how those domains define, measure, and report risk. The deciding factor is not which domain the risk originates in. It's whether the risk's trajectory outpaces the institutional capacity of any single owner to see it, define it, or act on it in time.
At the core of IRIS are two functions: discovering undetected or unexplored cross-domain risks that don't fit neatly into existing categories, and auditing existing register entries for misdefinition, not just staleness.
Led by a team of interdisciplinary professionals with relevant domain experience, the IRIS functional layer operates beneath the formal risk register. This layer draws on a boundary framework (transfer, translate, transform) to move risk signal across the divides that typically separate security, risk, and operational teams.
"IRIS represents a rare and welcome application of rigorous boundary-crossing theory to real-world enterprise risk intelligence practice. Jay has identified the key insight: mistaking a pragmatic boundary for a syntactic one is costly, but mistaking a syntactic boundary for a pragmatic one can be fatal to an organization. IRIS translates that diagnostic power into the hard, sustained work of building the organizational architecture to address it."
IRIS sits downstream of an organization's existing intake and domain-level triage, synthesizing across domains after they've each done their risk assessment and reporting, so nothing that crosses a boundary gets lost in the handoff.
Cross-domain risks that don't fit any single team's register.
Register entries checked for misdefinition, not just age.
Signal carried across the syntactic, semantic, and pragmatic divides between teams.
Standalone essays on the framework and where risk intelligence is headed. Free to download, no signup required.
Why enterprise risk integration has stalled for a generation, and the structural constraint behind it. Download →
AI is closing the old constraint, but a deeper one, organizational architecture, remains. Download →
What the new synthesis function must be capable of, and what the organization has to provide. Download →
More essays and regular writing on the Resources page.
Book a short call. No pitch, just a conversation.