Escalation is triggered by the size of a single risk and justified by a portfolio-offsetting argument the same body of doctrine refutes, which leaves the governing body structurally blind to the accumulation that doctrine itself calls most dangerous.
Two things are true of every escalation threshold, and they pull against each other. The first is that it is necessary. A governing body that sees every exposure sees none of them clearly, and an enterprise that escalates everything teaches its delivery leaders that nothing is theirs. Setting a size at which a risk must travel upward is how a board becomes selective on purpose rather than by accident.
The second is that the threshold has exactly one criterion: the magnitude of a single risk considered on its own. Cost band, schedule band or severity rating, the test is applied item by item, and what fails to reach it does not travel. Those items were not weighed at board level and found immaterial; they were never weighed there at all, and the governing body holds no instrument that would tell it how many there are, what they share, or what they sum to.
Between these two truths sits a justification most enterprises adopted without examining. Tolerances widen as they move up the structure, and the reason routinely given is a portfolio effect: a holder of wider authority manages a broader spread of exposures and can accept more in any one place because the others will offset it. That is not a claim about nerve but about statistical structure, holding only under conditions the same body of governance teaching denies elsewhere in its own pages. Offsetting requires exposures that do not move together and estimates as likely to be generous as mean. The discipline's own instruction is that neither applies: delivery risks are positively correlated more often than not, independence is the standing default and is optimistic, and estimates are shaded by what the estimator needs accepted.
The consequence is precise. The escalation rule reports upward the class of risk least likely to destroy an enterprise, because a single large exposure is visible, owned and already funded with somebody's attention. It is silent about the class most likely to: many individually moderate exposures driven by two or three common causes and capable of arriving in the same fortnight. The board leaves the meeting believing it has seen the risk position. It has seen a residue, and no procedure in the system can report the difference.
The Strategic Context
Consider a hypothetical protected-cropping business running forty hectares of glass, growing tomatoes and capsicum for a small set of supermarket buyers. Its register is well kept. Heating and carbon dioxide dosing run off a gas contract; electricity is generated on site and sold back when spot prices allow; labour is seasonal and partly visa-dependent. Pest control is biological, which works until a temperature excursion breaks the predator-prey balance, and water is recycled, so a pathogen in the loop reaches every bay.
Every line is rated moderate, none crosses the board escalation band, and the delivery leadership is right that none alone should. Yet a fortnight of unusual heat raises the cooling load, suppresses fruit set, cuts picker productivity, accelerates pest pressure and coincides with the summer spot-price spike that swings the energy position hard. Five moderate lines move at once because they are not five bets. They are one bet on one climate, one crop cycle and one energy contract, written on five rows.
The shape is not agricultural. Wherever an enterprise concentrates on a small number of physical, commercial or human dependencies, the register decomposes that concentration into modest entries and the escalation rule declines to report any of them. The decomposition is honest; the reporting rule is what fails, because it selects on the largest member of a set while the enterprise is exposed to the sum.
The window matters as much as the size. An accumulation absorbed comfortably across a year is fatal inside a six-week harvest, and no escalation band contains a time term at all.
What Boards Misread About Their Own Threshold
The first misreading is that a quiet escalation report means a quiet risk position. It means only that no single item was large. Silence from a filter is not information about what the filter excluded.
The second is more consequential. Boards read a wider tolerance at their own level as a statement about their capacity to absorb loss. It is not. The width is earned by diversification, not by balance-sheet depth or seniority. A board that has never asked which exposures make up the offsetting portfolio holds an authority granted on a condition it has never verified, and likely false in a concentrated enterprise.
The third is that a ranked list of the largest exposures describes the exposure. It describes the tail's upper edge, and says nothing about how many items sit just below it, how many drivers they share, or whether they move as one. This article takes the number on each line as given and asks only what the threshold does with it; whether a figure produced by multiplying probability against impact is a defensible basis for ranking anything is argued in [Related article: An Expected Value in a Ranking's Clothes] and is not settled here.
Reframing the Issue
Escalation is usually described as a reporting rule. It is more useful to treat it as a sampling design.
A design that selects the maximum of a set answers one question excellently and another not at all. It answers: what is the largest single thing that could go wrong here? It cannot answer: what is this enterprise exposed to? The second is what a governing body is accountable for, and no care in applying the first rule produces it: the information required was discarded before the report was assembled.
Read that way, the remedy is not a debate about where to set the band; lowering it enlarges the sample of maxima without fixing a selection problem. What is needed is a second instrument that samples on the sum, running on the population the first declines.
One caution on scope. What follows assumes exposures rated within a single delivery unit on a single scale. An enterprise adding ratings across several units faces a prior arithmetic problem, because the words on those scales are not the same number; that belongs to [Related article: Three Scales, One Word] and nothing here resolves it.
What the Threshold Cannot See
An offset has two preconditions
For a portfolio to absorb an over-run in one place, two conditions must hold. The exposures must not move together, so that when one goes badly the others are not. And the central estimate of each must be as likely to be beaten as missed, so the favourable half of the distribution exists to be drawn on. Both are assumed silently whenever a delegation schedule grants a wider band to a higher level.
The same doctrine withdraws both
A discipline that contradicts itself on a point of structure is telling the reader something reliable about that point. The instruction that a wider portfolio permits a wider tolerance sits, in the same body of teaching, alongside three others: that assuming independence between delivery risks is the standard simplification and is wrong in the optimistic direction; that estimates are distorted by what the estimator wants accepted; and that several individually manageable exposures can converge and exceed the sum of their separate impacts, unwarned of by a register that assessed each one independently. ERANORTH's contention is that this is the discipline's central unresolved conflict, not an editorial oversight.
The population that never crosses the line
If exposures are positively correlated, the offsetting effect does not fade gently. It reverses. Correlated moderate items reinforce rather than cancel, and the aggregate exceeds what an independent model predicts by a margin that grows with the number sharing the driver. The sub-threshold population is not the safe remainder. In a concentrated enterprise it is the principal exposure, and the reporting rule defines it as the part not reported.
Bandwidth is the constraint the threshold does not price
Escalation bands are denominated in money, time or severity. The binding constraint when several exposures arrive together is none of those: it is the number of consequential decisions a small group can take well in one window.
A hypothetical superannuation fund administrator makes this plain. A member-data migration, an insurer transition, a new product tier, elevated attrition in operations and a change to a unit-pricing control are five moderate rows sharing one senior bench and one release window. Money is not what runs out. Judgement is, and the register has no column for it.
This article concerns items that never cross the line. What becomes of one that crosses it and later leaves the escalation report, whether because it was treated or because the tolerance moved beneath it, and why only one of those leaves a record, is the subject of [Related article: Treated, or Tolerated?] and is not examined here.
Decision Framework
The accumulation test runs monthly on the population the escalation rule excludes. It needs no new data and no change to the existing bands, only a standing agenda item and someone able to act on the output.
| Test | Runs on | Fires when | Consequence |
|---|---|---|---|
| 1. Common-cause grouping | exposures below the escalation line | three or more trace to one driver | the driver becomes a named cluster with one owner |
| 2. Cluster sizing | each named cluster | members' impacts, summed, with no probability discount | the cluster escalates at the band its sum reaches |
| 3. Same-window convergence | each named cluster | three or more members can materialise in one reporting period | escalate one level irrespective of size |
| 4. Offset warrant | any tolerance wider than the one below it | the holder cannot name the offsetting exposures and their different drivers | the tolerance reverts to the narrower band |
Three points of discipline make this work rather than decorate a pack.
Group by driver, not by owner. The glasshouse register groups by function, which is precisely why its concentration is invisible; grouped by weather, energy contract and labour supply, three clusters appear and two are large.
Apply no probability discount at step two. The cluster exists because one driver is assumed to move its members together, and discounting each separately reimposes the independence assumption the test was built to remove.
Treat step four as a burden of proof, not a discussion. The holder of the wider band names the offsetting exposures in writing or loses the width.
From Strategy to Execution
Immediately. Extract the sub-threshold population for one delivery unit and count it. Group it by driver rather than by owner, identify every driver carrying three or more items, size the largest cluster by summed impact, and take that number to the next governance meeting alongside the escalation report. The contrast between the two documents is the argument.
Over the next two quarters. Add the accumulation test to the terms of reference of the body that already receives escalations, making it an obligation rather than an initiative. Require the offset warrant at every delegation boundary and record the answers. Make driver, not function, the primary grouping axis in the register, and run the same-window test against the real operating calendar: a harvest, a commissioning sequence, a release train.
Over the longer horizon. Stop treating delegated tolerance as a fixed property of a role. Treat it as a claim about the exposures beneath it, reviewed whenever their structure changes. An enterprise that concentrates on fewer suppliers, sites or platforms has narrowed its offsetting portfolio, and its delegation schedule should narrow with it. Very few schedules move at all.
Signals to Monitor
Watch the population beneath the line, not the items above it. A rising count of exposures sitting just inside the band, particularly where one estimator produced several, indicates a threshold being managed rather than met. A falling ratio of distinct drivers to total exposures indicates concentration, whatever the row count suggests.
Watch the arrival pattern. Escalations reaching the board singly and at intervals suggest an uncorrelated position; escalations arriving in bursts within one period suggest the population beneath was already moving as one, and the first arrivals were only the first to become visible.
Watch for one driver appearing in several registers under different wording, the usual form concentration takes. And treat a year in which the accumulation test escalated no cluster at all as evidence that the test is not being run.
Questions for the Leadership Team
- How many exposures sit below our escalation line, and what do their impacts total undiscounted for probability?
- How many distinct drivers account for that population, and which three carry the largest number of dependent exposures?
- When our tolerance was set wider than the level below, which exposures were named as the offset, and who confirmed they have different drivers?
- Over the last four reporting periods, did escalations reach us singly or in clusters, and did anyone examine the pattern?
- Which sub-threshold exposures could materialise inside our next critical operating window, and is one person expected to handle all of them?
- What would have to be true of the correlation between our exposures for our delegation schedule to be sound, and when was it last tested?
Closing Perspective
Exhortation will not help, because the people preparing the report are following the rule correctly. What can change is the standing of the offsetting claim. At present it is an inheritance: written into delegation schedules, repeated in governance frameworks, never once evidenced. Every executive holding a band wider than the one beneath them holds an authority granted on a condition nobody has been asked to demonstrate. The accumulation test is a way of asking.
The responsibility that leaves is specific. A governing body still receiving only its largest exposures has decided, whether or not it has said so, that it will learn about its concentrated positions when they arrive rather than before. That is a legitimate choice for an enterprise to make deliberately. It is not one that should be made by the default settings of a reporting template.
About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.
