Anthropomorphism is a term that refers to attributing human characteristics to non-human entities, such as objects, animals, or deities.
Many risks are dealt with in abstract terms - a few examples of things people have told me (in “speech marks”), or I’ve read, from the past week:
- “Fraud is a secondary issue for our business.”
- A cyber attack cost M&S (a UK retailer) £300m in profits and wiped £1bn of value.
- “On large infrastructure projects, there is a risk of political interference.”
- “The security situation in DRC is dynamic.”
- “No third parties show up on sanctions lists.”
There is nothing wrong with each of these statements. But they’re passive. They give a false sense of either distance or fatalism (it’s out of our hands). But if we make these risks human, might it help manage them? Here’s how I did or might respond to each statement.
- “Fraudsters will typically target businesses like yours here, here, and here.” In this instance, it was a renewable energy power producer, so we could use examples from past work around misappropriation (panels, inverters, copper wiring), contractors inflating invoices (ghost employees, to substitute inferior parts), and improper write-off/disposal (e.g., claiming a panel is damaged to scrap it and resell to the parallel market).
- A hacker group known to target retailers “pretended to be an employee and tricked IT staff into changing passwords to get into the company’s system.” The ‘hack’ is irrelevant; human decision-making, cuts to risk prevention teams, and social engineering left employees underqualified and unprepared.
- “Projects X, Y, and Z were targeted by politicians A & B, why?” We then discussed trends, including regions, particularly contentious politicians, poor planning, and a lack of stakeholder engagement, among other issues.
- The eastern part of DRC is again descending into outright conflict - why, who, what (modus operandi, targets, etc.)? From that, what can or should you do, now, next week?
- “Which third-parties? Why?” Expand the conversation to consider how we should determine third-party risks (what they do for you, where, with whom, and how), to move beyond simply listing names in OFAC and assuming that affords protection.
It can be a little unsettling to consider our organisations as targets, victims, and perpetrators of potential wrongdoing. But hiding behind generalisms achieves nothing. Managing risk in decision-making and human-centric systems requires us to name who is involved, how, and why. It’s challenging to manage risk in any other way.
Treating risk as an abstract concept is like walking an invisible dog. You might tell people, “I’m managing risk!” but until you put a collar and a name on it, you’re just holding an empty leash and hoping nobody notices.
What are your pet names for real risks?
AI why?
So, some AI models seek to blackmail their masters as they’re deleted. SkyNet begins. While others are more persuasive than humans in arguments.
Despite this, we’re testing three primary use-cases for AI. Which would you be comfortable trying or testing?
- Triage tools - dynamic risk assessments (e.g., third-party risk) that sift all the things you could worry about related to a given third-party (including investee) into those you should prioritise.
- Training - developing a “how-to” platform has long been an ambition. Imagine asking the AI, “I’m an SME in France in healthcare, guide me through setting up a risk-based framework.” The AI would use the triage above and then suggest the tools, templates, and modules to guide you through the process (with regular human-led clinics and one-on-one calls when you get started).
- Document diagnostics - uploading disclosure from a third party (including an investee), setting benchmark parameters, and obtaining a heatmap report that identifies weak spots and suggests an action plan for improvement.
Which one(s) would you pay for? How much?
