top of page

How Functional Silos Weaken Risk Identification and Escalation

  • Writer: Julien Haye
    Julien Haye
  • 5 days ago
  • 15 min read
Hero image for an Aevitium article on how functional silos weaken risk identification and escalation, featuring interconnected digital network graphics representing governance, enterprise risk management and information flow across an organisation.

In the previous article, Organisational Silos: The Hidden Cost of Fragmented Governance, I explored how functional specialisation strengthens organisations by improving expertise, accountability and operational oversight. I also examined how governance can become fragmented when information, decision-making and accountability remain confined within organisational boundaries.


This article builds on that foundation by examining how functional silos weaken risk identification and escalation.


Most organisations do not struggle to identify risks. They generate a constant flow of information through incidents, customer complaints, audit findings, operational monitoring, Key Risk Indicators (KRIs) and employee observations. The challenge is ensuring that these individual signals are connected to create enterprise awareness.


When information remains isolated within individual functions, emerging risks are often viewed as local issues rather than indicators of a wider organisational problem. Each team may understand its own responsibilities, yet no one develops a complete view of how risks, dependencies and emerging issues interact across the enterprise.


Effective governance addresses this challenge by ensuring information continues to move beyond the function where it originated. It connects insight, supports constructive challenge and enables leaders to make decisions based on a coherent understanding of enterprise risk rather than isolated functional perspectives.


Ultimately, risk identification is only the beginning. The quality of governance depends on how effectively organisations transform fragmented information into enterprise awareness.


Executive Takeaways


For readers scanning rather than reading in full, five governing insights frame the argument:

  1. Risk identification depends on connecting information across the organisation.

    Operational incidents, customer complaints, audit findings, regulatory observations, Key Risk Indicators (KRIs) and employee concerns all provide valuable insight into emerging risks. Effective governance ensures these signals are connected, enabling leaders to recognise enterprise-wide implications before issues escalate.

  2. Functional expertise strengthens governance when it is supported by organisational connectivity.

    Operations, Technology, Compliance, Risk and Internal Audit each contribute a different perspective on organisational risk. Governance brings these perspectives together, creating enterprise awareness that supports informed decision-making and coordinated action.

  3. Risk escalation is a governance capability that connects information with decision-making.

    Effective escalation ensures concerns continue moving beyond the function where they originated. Information is validated, shared, challenged and considered within its wider organisational context, allowing emerging risks to receive timely executive attention.

  4. Enterprise awareness strengthens decision quality and operational resilience.

    Boards and executive teams benefit from a connected view of organisational risk. Understanding how risks, dependencies and emerging issues interact enables earlier intervention, more effective governance and greater organisational resilience.

  5. Connected governance transforms information into organisational insight.

    As organisations become more complex, governance depends on the ability to connect information across organisational boundaries. This strengthens risk identification, supports effective escalation and enables leaders to make decisions with a clearer understanding of enterprise-wide risk.


Organisations Rarely Miss Every Warning


When a major organisational failure occurs, the immediate reaction is often:

"Nobody saw it coming."

In reality, that is rarely the case.


Most organisations generate a constant flow of information about emerging risks. Every day, warning signs appear across different parts of the organisation. For example:


  • Customer complaints reveal recurring issues.

  • Internal audits identify control weaknesses.

  • Operational teams notice unusual patterns.

  • Key Risk Indicators (KRIs) begin to deteriorate.

  • Near misses expose vulnerabilities before serious harm occurs.

  • Employees raise concerns about processes, behaviours or decisions.


Individually, these signals may seem routine or insignificant.


Together, they can reveal an emerging enterprise risk.


The challenge is not that warning signs are absent, but that they remain isolated within individual functions.


Operations may see one part of the picture. Compliance another. Technology identifies a different issue. Internal Audit reports separate findings. Each function performs its role effectively, yet no one connects the information to understand what it means for the organisation as a whole.


This builds on a theme explored in The Risk Within, where I examined how psychological safety influences whether people feel confident speaking up. Creating an environment where concerns can be raised openly remains fundamental to good governance.


However, speaking up is only the beginning.


Effective governance must also ensure that information continues to move across organisational boundaries. Warning signs need to be:


  • Shared across relevant functions.

  • Challenged to understand their significance.

  • Connected with related information.

  • Escalated to the appropriate decision-makers.


Only then can local observations become enterprise awareness. Without that connectivity, organisations can identify multiple risks without recognising the pattern they collectively reveal.


Many significant organisational failures do not happen because risks were invisible.


They happen because the organisation never connected what it already knew.


From Organisational Silos to Fragmented Risk Awareness


In the previous article, I explored how organisational silos naturally develop as organisations grow. Functional specialisation brings deeper expertise, stronger oversight and clearer accountability. Finance, Operations, Technology, Compliance, Risk and Internal Audit all play essential roles in managing increasingly complex organisations.


Specialisation acts as a strength, though it creates a critical gap when functions focus on individual responsibilities at the expense of an enterprise-wide view.


Every function owns part of the picture.


For example:

  • Operations manages operational risks and incidents.

  • Technology monitors system performance, resilience and cyber threats.

  • Compliance oversees regulatory obligations and policy adherence.

  • Risk monitors Key Risk Indicators (KRIs), risk appetite and emerging risks.

  • Internal Audit provides independent assurance over governance and controls.


Each function reports through its own governance processes, using its own metrics, reporting cycles and priorities. Individually, these activities are both necessary and valuable.


Collectively, however, they can create fragmented risk awareness.

Fragmented risk awareness occurs when information remains within functional boundaries, preventing the organisation from recognising how individual risks, incidents and emerging issues interact across the enterprise.


Each function may have strong local visibility, yet the organisation lacks enterprise awareness. This explains why organisations can appear well governed while still being surprised by significant events.


The issue was not simply how individual functions managed risk. It was that governance did not connect information to reveal its enterprise-wide implications. This is one of the reasons Integrated Risk Management has become increasingly important.


Its purpose is not simply to consolidate risk reporting. It is to:

  • Connect information across organisational boundaries.

  • Identify dependencies between functions, processes and third parties.

  • Provide an enterprise view of risk rather than isolated functional perspectives.

  • Support better decision-making through connected governance.

Ultimately, individual functions own the activities.


The enterprise owns the consequences.


Figure 1. From Local Visibility to Enterprise Blind Spots. A vertical governance flow diagram illustrating how strong visibility within individual business functions can unintentionally create enterprise blind spots. The diagram progresses from Local Visibility, where functions have strong insight into their own activities, to Functional Awareness, where information remains confined within departmental boundaries, and finally to Enterprise Blind Spot, where no single function recognises how risks, issues and dependencies connect across the organisation. The visual concludes with the message: "Strong local visibility does not guarantee enterprise awareness." The infographic uses Aevitium branding in black, white, grey and gold and includes the company logo, copyright notice and disclaimer.

Why Risk Information Stops Moving


Organisations generate vast amounts of information about emerging risks every day. Operational incidents, customer complaints, audit findings, Key Risk Indicators (KRIs), regulatory observations and technology alerts all contribute valuable insight into the organisation's risk profile.


Generating information is rarely the problem. Connecting it is.


As organisations grow, governance naturally becomes more distributed. Individual functions establish their own reporting processes, governance forums and management information to support their responsibilities. This is both necessary and appropriate.


The challenge arises when these governance arrangements operate effectively within functions but remain only loosely connected across the enterprise.

Over time, information becomes fragmented.


Risks are managed in different parts of the organisation using different governance arrangements:


  • Ownership is distributed across specialist functions.

  • Incidents are investigated using different methodologies.

  • Key Risk Indicators (KRIs) are measured against different thresholds.

  • Reporting follows separate governance cycles and committee structures.

  • Technology platforms store information in different systems.

  • Taxonomies describe similar issues using different terminology.

  • Business priorities compete for management attention.


None of these arrangements are inherently flawed.


Together, however, they make it increasingly difficult to connect information across organisational boundaries.


This is where many organisations begin to lose enterprise awareness. A technology incident may initially appear to be a local operational issue. Customer complaints may be reviewed separately by a service team. Internal Audit may identify governance weaknesses. Compliance may observe an emerging regulatory concern.


Viewed independently, each issue appears manageable.


Viewed together, they may reveal a much broader enterprise risk.

This is why effective governance is about more than oversight.


Oversight ensures that individual functions discharge their responsibilities.

Connected governance ensures that information continues to move between those functions so that emerging risks, hidden dependencies and recurring patterns can be recognised before they become organisational failures.


The difference is significant:

  • Oversight monitors individual functions.

  • Connected governance connects organisational insight.

  • Enterprise awareness enables informed decision-making.


Good governance does not simply create reporting.


It creates organisational awareness.

Without that connectivity, organisations can become highly effective at managing individual risks while remaining surprisingly ineffective at recognising enterprise risk.


Case Study - Equifax: When Information Exists but Enterprise Awareness Does Not


The 2017 Equifax data breach is often described as a cybersecurity failure. In reality, it also illustrates how fragmented governance can weaken organisational awareness.


A critical software vulnerability had already been identified, and a security patch was available. Technology teams understood the vulnerability. Cybersecurity teams monitored the emerging threat. Patch management teams were responsible for deploying the update, while management relied on governance reporting to provide assurance that critical risks were being addressed.


The challenge was not the absence of information, but that governance failed to provide a connected view of remediation, accountability, and enterprise risk.

Information remained fragmented across operational processes, technology functions and management reporting. As a result, senior leaders received assurance that did not fully reflect the organisation's true level of exposure.


The vulnerability remained unaddressed, allowing attackers to compromise the personal information of approximately 147 million individuals. The consequences extended far beyond technology, resulting in regulatory investigations, significant financial penalties, executive departures and lasting reputational damage.


The breach demonstrated that operational resilience depends as much on governance and information connectivity as it does on technical controls.

Key lesson

Enterprise awareness requires more than individual functions managing risk effectively. It requires governance that connects information, validates assurance and provides leaders with a complete view of enterprise exposure before decisions are made.

Risk Escalation Is More Than Speaking Up


Effective risk escalation often begins with someone recognising that something is not quite right. An employee questions an unusual transaction. A manager notices a recurring operational issue. A technology team identifies an emerging vulnerability. A customer complaint highlights an unexpected pattern. Someone decides the issue deserves attention and raises it.



Without it, organisations lose one of their most valuable sources of early warning.


However, speaking up is only the first step.


For information to influence organisational outcomes, it must continue moving beyond the individual or team that first identified the issue. It needs to be:


  • Understood within its local context.

  • Validated against available evidence.

  • Connected with related information from across the organisation.

  • Escalated to the appropriate decision-makers.

  • Translated into timely decisions and meaningful action.


This progression is often overlooked.


Figure 2. From Speaking Up to Action. A five-stage governance flow illustrating how an identified concern becomes an organisational response. The process begins with Speaking Up, where an individual or team raises a concern. It progresses to Risk Escalation, where information is assessed and routed through appropriate governance channels, followed by Enterprise Awareness, where related risks, dependencies and patterns are connected across the organisation. This enables Decision, where leaders evaluate the complete picture and determine an appropriate response, before concluding with Action, where decisions are implemented, monitored and translated into organisational improvement. The visual reinforces the message: "Speaking up starts the journey. Connected governance completes it." The infographic uses Aevitium branding in black, grey, white and gold and includes the company logo, copyright notice and disclaimer.

Many organisations invest significant effort in encouraging people to raise concerns. Psychological safety, whistleblowing arrangements and speak-up programmes all play an important role in creating an open culture.


Yet relatively little attention is given to what happens next.


Once concerns have been raised:

  • Does the information move across organisational boundaries?

  • Is it connected with other emerging issues?

  • Does it reach people with the authority and context to make informed decisions?

  • Or does it remain within the function where it originated?


This is where governance becomes critical.


Effective risk escalation is not simply about moving information upwards through management layers. It is about ensuring information moves across the organisation, enabling local concerns to become enterprise awareness.


This reinforces a point explored in my earlier article, Why Risks Fail to Escalate. Many organisations assume escalation breaks down because people choose not to speak up. While culture and psychological safety remain fundamental, governance plays an equally important role.


Information can fail to influence decisions even when people do exactly what they are expected to do.


Good governance does not stop at encouraging people to raise concerns.


It ensures those concerns continue to move until they become informed decisions and meaningful action.


Why KRIs Can Create a False Sense of Assurance


Key Risk Indicators (KRIs) are an essential component of effective governance. They help organisations monitor performance, identify emerging trends and provide early warning when risk levels begin to change. Used well, they support informed decision-making.


However, most KRIs are designed around organisational structures rather than enterprise interactions. Each function monitors the indicators that reflect its own responsibilities. For example:


  • Technology monitors system availability, cyber events and technology resilience.

  • Operations tracks processing errors, service performance and operational incidents.

  • Compliance measures regulatory breaches, policy exceptions and compliance obligations.

  • Customer teams monitor complaints, customer outcomes and service quality.


This is entirely appropriate. The challenge is that enterprise risks rarely develop within a single function.


They develop where functions, processes and dependencies interact.

As a result, organisations may receive reassuring reports across multiple governance forums:


  • Technology remains within tolerance.

  • Operational performance is stable.

  • Compliance indicators show no significant concerns.

  • Customer complaints remain low.


Individually, every function appears healthy.


Yet the organisation may still face a significant enterprise risk.


A critical dependency between systems, suppliers or business processes may be deteriorating without appearing in any individual KRI. No single function owns the complete picture, and no individual indicator reveals how risks are combining across organisational boundaries.


This is why Integrated Risk Management is about more than consolidating dashboards.


Its purpose is to connect information, dependencies and governance so that leaders understand not only how individual functions are performing, but also how those functions interact to influence enterprise risk.

Good KRIs remain essential.


They provide valuable insight into the health of individual functions.


However, good KRIs do not automatically create good governance.

Good KRIs provide functional assurance. Good governance provides enterprise assurance.


This infographic highlights the gap between functional assurance and enterprise assurance, showing how individual performance dashboards can mask critical risks. It contrasts functional dashboards showing "green" indicators with a more nuanced enterprise view that reveals potential threats through interdependencies and critical dependencies impacting overall business outcomes.

Near Misses: Organisational Learning Before Failure


Every organisation experiences near misses. A control prevents an error before it affects customers. An operational issue is identified before it disrupts a critical business service. A cyber attack is contained before systems are compromised.

A supplier experiences disruption, but contingency arrangements prevent a wider impact.Because the immediate consequences are limited, these events are often viewed as successes rather than learning opportunities.


In reality, near misses provide some of the richest sources of organisational learning.


They often reveal:

  • Weak controls before failures occur.

  • Hidden dependencies between systems, processes and third parties.

  • Behavioural patterns that influence decision-making under pressure.

  • Governance weaknesses that are not visible during normal operations.


The challenge is that organisational learning often stops where the event occurred. Operations improve a process. Technology strengthens a control. Compliance updates a policy. Each function learns from its own experience, yet the wider organisation may never recognise that similar vulnerabilities exist elsewhere.


This is another consequence of fragmented governance.


Without mechanisms to connect learning across organisational boundaries, near misses remain local improvements rather than enterprise learning. The immediate issue is resolved, but the organisation misses an opportunity to strengthen resilience more broadly.


This is closely linked to both risk culture and psychological safety.

Psychological safety encourages people to report mistakes, concerns and near misses without fear of blame. A positive risk culture reinforces openness, constructive challenge and continuous improvement.


However, culture alone is not enough.


Governance must ensure that learning continues to move across the organisation. Lessons identified within one function should inform decisions across the enterprise, particularly where similar risks, dependencies or governance weaknesses exist.


Mature organisations do not simply ask: Has the issue been resolved?


They also ask:


Where else could this happen, and what does it tell us about the organisation as a whole?


That question transforms a near miss from a local operational event into enterprise learning.


Why Decision Quality Depends on Connected Information


Every significant organisational decision is only as good as the information on which it is based. Boards and executive teams are often judged by the quality of their decisions, particularly during periods of uncertainty or crisis. Yet decisions rarely fail because leaders lack experience, judgement or commitment.


More often, they fail because decision-makers never receive a complete picture of what the organisation already knows.


This is where connected governance becomes critical.


High-quality decisions depend on more than accurate reporting. They require information that is:

  • Complete, bringing together relevant information from across the organisation.

  • Connected, revealing how individual risks, incidents and dependencies influence one another.

  • Timely, ensuring emerging concerns reach decision-makers before options become limited.

  • Constructively challenged, enabling assumptions to be tested and alternative perspectives to be considered.


When these conditions exist, leaders are better equipped to understand uncertainty, evaluate trade-offs and make informed decisions. When they do not, decision quality inevitably suffers.


The consequences are rarely immediate. Leaders may believe they are making well-informed decisions because every governance report appears reassuring. However, if information remains fragmented across functions, committees or reporting structures, decisions are based on partial visibility rather than enterprise understanding.


This reinforces a theme explored in my article Leading Through Uncertainty. In complex organisations, uncertainty cannot be eliminated. The objective is not to predict every disruption but to preserve the quality of decisions as conditions continue to evolve.


Good governance plays a fundamental role in achieving that objective.


Its purpose is not simply to provide oversight or assurance. It is to ensure that information continues to move across organisational boundaries, enabling leaders to see emerging patterns, understand interconnected risks and make decisions based on enterprise awareness rather than isolated functional perspectives.


Ultimately, poor decisions often reflect fragmented governance rather than poor leadership.


Decision quality is rarely determined in the boardroom. It is determined by how effectively governance connects information long before a decision is made.


Operational Resilience Starts Long Before a Crisis


When organisations think about operational resilience, attention often focuses on incident response, crisis management and business continuity.

These capabilities are essential.


However, true operational resilience begins long before a crisis occurs.

It begins with an organisation's ability to recognise weak signals, connect emerging information and intervene before isolated issues develop into significant operational events.


Resilient organisations rarely succeed because they respond more effectively after disruption has occurred.


They succeed because they identify and address vulnerabilities while there is still time to act. This progression reflects how resilience is built in practice:

  • Weak signal identifies an early indication that something may be changing.

  • Near miss exposes a vulnerability before significant harm occurs.

  • Risk escalation ensures concerns move beyond the originating function.

  • Enterprise awareness connects information across organisational boundaries.

  • Decision enables leaders to understand the wider implications.

  • Intervention addresses root causes before they become major incidents.

  • Operational resilience is strengthened through continuous learning and adaptation.


Figure 4. From Weak Signals to Operational Resilience. A vertical process infographic illustrating how organisations build operational resilience through connected governance and early intervention. The seven-stage pathway progresses from Weak Signal, where an early indication of change is identified, to Near Miss, exposing a vulnerability before harm occurs; Risk Escalation, where concerns move beyond the originating function; Enterprise Awareness, where information is connected across organisational boundaries; Decision, where leaders assess enterprise-wide implications; Intervention, where action addresses root causes; and finally Operational Resilience, where the organisation becomes stronger, more adaptive and better prepared for future disruption. A highlighted footer states: "Operational resilience is built long before disruption occurs." The infographic uses Aevitium's corporate branding with a black, white, grey and gold colour palette and includes the Aevitium logo, copyright notice and professional disclaimer.

Every stage depends on connected governance.


If weak signals remain isolated, near misses are treated as local events or information fails to move across organisational boundaries, organisations lose the opportunity to intervene early. By the time a crisis becomes visible, many of the opportunities to prevent it have already passed.


This reinforces an important principle:


Operational resilience is not created during a crisis. It is created by the quality of governance that exists beforehand.


Ultimately, operational resilience is not a single capability.


It is the outcome of effective governance, connected information and informed decision-making working together over time.


The most resilient organisations are not those that recover fastest.

They are those that recognise emerging risks early enough to prevent many crises from occurring in the first place.


Five Questions Directors Should Ask About Risk Identification and Escalation


1. How do we know emerging risks are connected across the organisation rather than managed in isolation?

Risks rarely develop within a single function. Directors should seek assurance that management can identify relationships between operational, technology, compliance, customer and strategic risks, enabling the organisation to recognise emerging enterprise risks before they escalate.

2. What mechanisms ensure information continues to move beyond the team that first identifies a concern?

Identifying a risk is only the first step. Boards should understand how concerns are validated, shared across organisational boundaries, escalated through appropriate governance channels and translated into informed decisions and timely action.

3. Does our governance provide enterprise awareness or simply functional reporting?

Committee papers and Key Risk Indicators (KRIs) often provide valuable insight into individual functions. Directors should consider whether governance also enables them to understand how risks, dependencies and emerging issues interact across the organisation, rather than reviewing them as separate reports.

4. How do we know our assurance reflects operational reality?

Positive reporting does not always indicate that enterprise risks are well understood. Boards should ask how management validates that governance information is complete, consistent and sufficiently connected to provide an accurate view of organisational exposure, particularly where multiple functions share responsibility.

5. Are we identifying weak signals early enough to strengthen operational resilience?

Operational resilience begins long before a crisis. Directors should seek evidence that weak signals, near misses and recurring issues are analysed collectively, enabling the organisation to intervene early, strengthen resilience and improve decision-making before significant disruption occurs.

Conclusion


Organisations rarely struggle to identify risks.


They struggle to connect what they already know.


Throughout this article, we have seen that warning signs often exist across different parts of the organisation. Customer complaints, operational incidents, audit findings, emerging technology issues and regulatory concerns can all provide valuable insight. Individually, they appear manageable. Together, they can reveal a significant enterprise risk.


The difference lies in governance connectivity.


Effective governance does more than allocate responsibilities or produce management information. It enables information, challenge, accountability and organisational learning to move across functional boundaries, transforming local observations into enterprise awareness.


This, in turn, strengthens decision quality. Leaders gain a more complete understanding of emerging risks, hidden dependencies and the wider implications of strategic choices. It also enables organisations to intervene earlier, learn continuously and build operational resilience before disruption occurs.


Ultimately, risk identification is rarely the greatest organisational weakness. Enterprise awareness is.


Organisations that connect information effectively are better equipped to make informed decisions, adapt to uncertainty and respond confidently to an increasingly complex and interconnected risk landscape.


The organisations that thrive are not those that identify the most risks. They are those that connect information early enough to make better decisions before risks become crises.


About the Author: Julien Haye


Managing Director of Aevitium LTD and former Chief Risk Officer with over 26 years of experience in global financial services and non-profit organisations. Known for his pragmatic, people-first approach, Julien specialises in transforming risk and compliance into strategic enablers. He is the author of The Risk Within: Cultivating Psychological Safety for Strategic Decision-Making and hosts the RiskMasters podcast, where he shares insights from risk leaders and change makers.


 

Frequently Asked Questions


What is the difference between risk identification and risk escalation?

Risk identification is the process of recognising potential threats, vulnerabilities or emerging issues that could affect organisational objectives. Risk escalation is the governance process that ensures significant risks are communicated to the appropriate decision-makers in a timely manner. Effective governance connects these activities, ensuring important information moves beyond the originating team and receives appropriate oversight.


Why do organisations struggle to identify enterprise risks?

Enterprise risks often emerge through the interaction of multiple functions, systems, third parties and business processes. Individual teams may identify risks within their own areas, but fragmented governance can make it difficult to recognise how those risks combine to create wider organisational exposure. Connected governance helps create a holistic view of enterprise risk.


How can boards improve the quality of risk reporting?

Boards should encourage reporting that explains relationships between risks rather than reviewing individual metrics in isolation. Effective board reporting highlights emerging trends, interdependencies, root causes and potential strategic implications, enabling directors to understand the organisation's overall risk profile and make more informed decisions.


What role does organisational culture play in risk escalation?

A strong risk culture encourages employees to raise concerns early, share information openly and challenge decisions constructively. Psychological safety, leadership behaviours and clear escalation processes all influence whether emerging risks are communicated before they become significant operational or strategic issues.


How does connected governance support operational resilience?

Connected governance enables organisations to recognise emerging issues before they develop into major disruptions. By bringing together information from different functions, leaders gain greater visibility of operational dependencies, allowing earlier intervention, more effective decision-making and stronger organisational resilience.


How can organisations reduce the impact of functional silos?

Organisations do not need to remove specialist functions to reduce silos. Instead, they should strengthen governance by improving information sharing, aligning reporting, clarifying accountability, encouraging cross-functional collaboration and creating governance forums that support enterprise-wide decision-making.


 
 
bottom of page