Risk and Resilience

Slow-Onset Risks Fail When Organisations Treat Them as Events

How leaders can govern chronic risks that accumulate quietly, become normalised and escape attention until consequences are difficult to reverse.

EraNorth Insights · 9 min read

Chronic conditions need control systems, not occasional reactions.

Organisations are generally better at responding to visible incidents than to deterioration.

A machine stops, a customer complains, a cyber system goes offline or a safety event occurs. The signal is clear. Escalation begins. People gather. Action follows.

Slow-onset risk behaves differently.

Exposure accumulates. Maintenance backlog grows. Technical debt spreads. Quality drifts. A supplier becomes progressively more critical. Workforce fatigue rises. Cyber controls age. Dust remains in the air between obvious outbreaks.

Nothing appears urgent enough on any single day.

That is precisely why the risk can become strategic.

The Strategic Context

Zuo, Rameezdeen, Hagger, Zhou and Ding's 2017 study of dust control on construction sites examined the behaviour of managers responsible for environmental protection.

The study is valuable because dust is a classic slow-onset condition. It can arise from recurring construction activities and weather, while important health consequences may emerge over time rather than immediately.

Interviewees varied markedly in how they interpreted the risk. Some recognised serious consequences. Others saw dust largely as irritation or discomfort. The authors found a tendency to treat dust outbreaks as discrete events associated with particular work or weather rather than as an ongoing site condition requiring continuous monitoring and control.

That distinction is larger than dust.

It is the difference between incident management and condition management.

What Leaders Commonly Misread

The first misread is believing that absence of an incident means the control is working.

Slow-onset risks often have weak feedback. The organisation can operate for long periods without an obvious loss event while exposure accumulates.

The second is over-relying on visual evidence.

In the study, many sites did not undertake regular monitoring unless specifically required, while visual inspection was one of the reported approaches. Yet slow-onset hazards are often dangerous precisely because human senses are poor measuring instruments for cumulative exposure.

The third is assuming that policy presence equals operational control. Large firms may have environmental or project-management plans, but risk depends on what is detected, measured, acted upon and reviewed in practice.

The fourth is applying one control without examining its secondary consequences. Water suppression was the dominant dust-control method reported in the study. The authors highlighted a dilemma: water itself is an environmentally sensitive resource, particularly under dry conditions when dust is likely to be problematic.

A control can solve one variable while worsening another.

Reframing the Issue

Slow-onset risks should be managed as states of the system, not only as events.

An event asks:

"What happened?"

A condition asks:

"What is the system becoming?"

This changes governance.

For a condition, management needs:

  • a defined normal range;
  • leading indicators;
  • monitoring frequency;
  • thresholds for intervention;
  • ownership of trends;
  • cumulative exposure logic;
  • periodic challenge of the control method.

The system must detect deterioration before the consequence creates its own signal.

Normalisation Is a Risk Mechanism

When people operate around a condition every day, familiarity can reduce perceived urgency.

Minor vibration becomes "how the machine runs."

A workaround becomes "how the process works."

Repeated overtime becomes "what delivery requires."

A backlog becomes "normal workload."

Dust becomes "part of the site."

This is normalisation, and it can be reinforced by the absence of immediate consequences.

The organisation may even reinterpret tolerance as evidence of safety: "We have done it this way for years."

That logic is particularly weak for cumulative risks because the delay between exposure and consequence is exactly what makes informal learning unreliable.

Monitoring Is a Leadership Choice

The dust study reported that 59% of the monitoring responses involved no regular monitoring unless specifically required. That finding is context-specific and should not be generalised to all construction sites, but the governance lesson is strong.

If monitoring occurs only after a trigger from a client, regulator, public complaint or visible event, the organisation is operating reactively.

Monitoring frequency reveals what management actually treats as controllable.

Leaders should therefore ask: which material risks in our enterprise are currently governed mainly through lagging indicators?

Examples may include:

  • corrosion discovered during failure inspection;
  • cyber weaknesses discovered after attempted exploitation;
  • supplier fragility discovered after missed delivery;
  • cultural deterioration discovered after turnover increases;
  • quality drift discovered through customer claims;
  • project overload discovered after milestones slip.

For each, earlier state information may be available.

Controls Interact

Water suppression in the source study demonstrates a broader systems principle.

A local control can create resource use, cost, secondary hazards or operational constraints elsewhere.

In manufacturing, increasing inspection may improve defect detection but reduce flow and conceal process capability problems.

In cybersecurity, aggressive access restrictions may reduce one risk while encouraging employees to develop unauthorised workarounds.

In project governance, additional approvals may reduce decision risk while increasing schedule delay and informal bypass behaviour.

Controls should therefore be evaluated as a portfolio, not independently.

The objective is not maximum control. It is a stable risk state at acceptable total cost and consequence.

Decision Framework

ERANORTH proposes a six-part chronic-risk review.

1. Condition definition

Describe the state being controlled.

Avoid defining the risk only through the eventual event. "Catastrophic bearing failure" is an event. "Progressive bearing degradation beyond defined vibration and temperature limits" is a condition.

2. Exposure pathway

Explain how the condition accumulates or worsens.

What creates it? How quickly can it change? Who or what is exposed?

3. Detectability

Identify which indicators appear before material harm.

Use instrumentation where human observation is unreliable.

4. Threshold and trend

Define both absolute thresholds and deteriorating trends.

A value within limits can still warrant action if the trend is moving rapidly in the wrong direction.

5. Control interaction

Test resource consumption, side effects and behavioural consequences of each control.

6. Ownership

Assign responsibility for the condition between incidents.

If accountability activates only after an event, chronic risk has no true owner.

From Strategy to Execution

Immediate action: identify five material risks that can worsen without producing an immediate incident. Review whether each has a leading indicator and explicit monitoring frequency.

Medium-term capability building: integrate condition monitoring into operating routines. Combine technical data with behavioural observation. Make trend review part of management cadence rather than an exceptional audit activity.

Long-term strategic positioning: design systems that fail visibly before they fail dangerously. Invest in sensing, preventive maintenance, transparent escalation and organisational norms that treat weak signals as useful information rather than operational inconvenience.

For project-based organisations, this includes transferring risk knowledge across temporary teams. A condition should not become "new" every time a project starts.

The Behavioural Layer

The source study used the Norm Activation Model to examine awareness of consequences and responsibility.

Its practical implication is important: technical controls depend partly on whether managers perceive the consequence as serious and accept responsibility for acting.

This does not justify replacing engineering control with awareness campaigns. It means technical systems and behavioural systems interact.

A well-designed control that managers regard as low priority may be inconsistently applied. A highly motivated manager without adequate equipment or monitoring cannot compensate indefinitely.

Leadership needs both capability and responsibility.

Related article: Behaviour Change Must Be Designed for the Behaviour You Need

Signals to Monitor

Watch for:

  • risks described only through incidents rather than condition states;
  • recurring "minor" deviations that never trigger root-cause work;
  • absence of regular monitoring unless externally required;
  • heavy reliance on visual inspection for poorly visible hazards;
  • controls that create significant secondary resource or safety problems;
  • repeated short-term workarounds;
  • schedule pressure routinely overriding preventive activity;
  • risk reviews dominated by lagging metrics;
  • different sites interpreting the same condition very differently.

A dangerous phrase is: "It has never caused a problem before."

For slow-onset risk, history without measurement may reveal tolerance, not control.

Questions for the Leadership Team

  1. Which of our most material risks can deteriorate for months before producing an obvious incident?
  2. What leading indicators tell us what those systems are becoming?
  3. Which conditions are monitored only because a regulator, customer or auditor requires it?
  4. Where are we relying on visual judgement when measurement is available?
  5. Which controls create meaningful secondary risks, costs or resource burdens?
  6. Who owns each chronic condition between incidents and projects?
  7. What has become normal in our operations that would concern an informed outsider?

Closing Perspective

Risk management should not wait for the system to announce failure.

The deeper discipline is to recognise states of deterioration while there is still room to act cheaply, safely and reversibly.

Slow-onset risks become dangerous when familiarity turns them into background noise and governance activates only after a visible event.

Leaders should manage the condition before the condition becomes the incident.

Source basis: This article is an original ERANORTH synthesis principally informed by Jian Zuo, Raufdeen Rameezdeen, Matthew Hagger, Zhihua Zhou and Zhikun Ding (2017), Dust pollution control on construction sites: Awareness and self-responsibility of managers, Journal of Cleaner Production, 166, 312–320.


About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.