Why cross-category risks slip through corporate risk management
We deal with risk the way we deal with most messy things, by sorting it into tidy categories. The ones that should worry us most are those that refuse to stay in any of them.
FUTURE PROOF – BLOG BY FUTURES PLATFORM
The corporate risks that don’t fit in one box
Most of us picture GPS as the little blue dot that finds us on a map. It does so much more than that. The same satellite signals stamp the precise time on every card payment, keep power grids in step, and hold planes and cargo ships on their routes.
In 2024, according to the International Air Transport Association, reports of GPS “spoofing”, where a counterfeit signal convinces a receiver it is somewhere it isn’t, rose by about 500 per cent on the year before. Most of it was spillover from conflict zones rather than anything aimed at a particular company.
The more tightly our systems are wired together, the less any single risk stays in its own lane. And that’s why a serious disruption to satellite timing doesn’t arrive as one clean type of event. It becomes a technology problem, a security problem, a geopolitical problem and a logistics problem all at once, tearing through systems that different teams watch separately and almost no one watches together.
Get a comprehensive picture of emerging corporate risks
Futures Platform’s Future of Corporate Risk 2026 report maps 33 emerging risks across five domains.
When a risk arrives before it has a name
Some risks are not just hard to file. They turn up before there is any file to put them in. Think of the money that rushed into corporate AI on the promise of fast, easy efficiency. A 2025 study from MIT’s Project NANDA found that 95% of organisations had seen no measurable return, and the researchers pinned that less on weak technology than on how badly the tools fit the way people actually work. The spending had been treated as a tech decision and measured by tech numbers. What went wrong was mostly about workflow, judgement and oversight, and none of that had a natural home on anyone’s list of risks until the bill landed.
Foresight teams keep a working vocabulary for developments at this stage, before they settle into a clear trend that shows up in the numbers. A weak signal is the faint, early flicker that might grow into something serious or might fade to nothing, still too shapeless to name and too shapeless to own. A wild card is a long shot, unlikely to land but violent enough to rearrange an entire industry if it does.
It doesn’t always make sense to guard against these the way you would a trend you can already measure. But it pays off to keep them in view, and above all to trace where they could lead. One failure rarely stays put. A single stretch of corrupted GPS signal nudges a cargo ship off course, which backs up a port, which empties a factory’s shelves of parts, which then misses a carmaker’s quarter. The first event is a technology story. The last is a financial one. Nobody filed them under the same heading, and that is exactly how a small, odd signal becomes a loss no one saw coming.
Who owns the space between the categories?
So the useful question is not whether every category is covered. On most registers, they are. The real question is what happens to the threats that will not sit in just one, and whether the tools a risk team relies on are built to hold them or to gently take them apart. Most of those tools, through no fault of the people using them, do the second thing.
It is nobody’s failing in particular. The forms we fill in offer single headings, so a risk that spans five of them gets written down under one, then managed, from that point on, as something smaller than it is. Which is why the threats most likely to catch us off guard often look so unremarkable. They are rarely the biggest item on the register, or the least likely. More often they are simply the ones filed under a single word because the form had room for only one.
Spotting them doesn’t necessarily require a bigger budget or a drastic organisational change. It only asks for a habit, and a slightly different kind of attention: reading the gaps between the columns as closely as the columns themselves, because that is usually where the next real surprise is already sitting, waiting for someone to give it a name.
The full Future of Corporate Risk 2026 report examines five domains — geopolitical, digital, climate, organisational, and financial — drawing on current market intelligence and longer-horizon trends to trace where each is heading and what it means for corporate strategy.
The most dangerous corporate risks cross categories and slip through the register. Why they stay invisible, and the habit that helps you spot them early.