Strategy and Foresight

When an Industry Agrees on One Framework, It Goes Blind Together

Every firm improving its risk practice by adopting the same method raises the sector's average standard and correlates its errors. Assurance is where the correlation lands first.

EraNorth Insights · 30 Aug 2026 · 14 min read

Convergence on a single risk framework across an industry correlates the sector's blind spot, and the effect reaches the assurance function first, because the auditor is drawn from the same body, trained on the same templates and assessed against the same maturity model as the audited.

Every firm in a sector can improve its risk management, verifiably and simultaneously, and leave the sector more exposed than before. This is not a paradox of measurement; it follows from how the improvement is achieved. Firms improve by adopting the method the professional bodies, certifying institutes, consultancies and regulators have converged upon. Each adoption raises that firm's floor. Each also narrows the range of questions asked across the whole population of firms.

Any portfolio manager recognises the shape. A portfolio of individually excellent positions that are all the same position is not a good portfolio; what matters is not the quality of each holding but the correlation between them. Applied to risk practice, the question is not how good your method is, but how much of the sector's total capacity for noticing it represents — and what sits outside it.

The counterintuitive part is where the correlation lands first. Not in the operating business, where executives look, but in assurance — the function constituted specifically to catch what the business missed. Convergence compounds fastest there, because the assurance provider is drawn from the same professional population as the assured, trained on the same templates, certified by the same body, assessed against the same maturity model. Independence has been achieved with respect to the entity, not with respect to the method — and the method determines what gets seen.

This is not speculation. It is visible in the discipline's own teaching, which carries both halves of the contradiction without joining them. That material requires risk audits to be performed by someone outside the project — in practice, another practitioner from the same office. It also names institutional isomorphism — organisations within a field converging on common structures, identified by Paul DiMaggio and Walter Powell — as a mechanism that degrades the capacity to perceive risks specific to a situation, listing standardised templates and shared professional training among its channels. Both statements appear; neither is read against the other. A field holding both has not noticed that its independence requirement is defined against the wrong thing.

The Strategic Context

Convergence in risk method has been treated as a straightforward good for three decades, and the case is real: common language reduces transaction costs between counterparties, common process makes capability portable, and common structure lets a regulator supervise a hundred entities with one framework rather than a hundred.

What was never priced is the correlation this creates in what the population fails to consider. A method is not only a way of examining; it is a boundary around what counts as examinable. Standard risk architecture handles discrete, nameable events carrying a likelihood, a consequence and an owner. Exposures that are not events — a slow shift in a customer base, an inherited assumption nobody has re-derived, a change in what a contract term is understood to mean — have no home in that structure. They are not judged unlikely; they are never raised, in any firm, because the instrument has no field for them. A comparable gap governs what individuals may commit the enterprise to owe as distinct from what they may approve, which [Related article: What May They Cost You?] examines and this article leaves there, being concerned only with what a converged sector cannot see.

Take commercial property insurance underwriting as a hypothetical illustration. Carriers in such a market run the same peril catalogue and accumulation categories, use the same few modelling suppliers, and hire underwriters trained at each other's firms. Each position is defensible on its own terms. The market's aggregate exposure to anything the shared catalogue does not name — a change in construction practice, a drift in occupancy mix, a reinterpretation of a standard policy term — is undiversified across the whole market, and no participant can surface it, because all run the instrument that omits it.

What Leaders Commonly Misread

The first misreading is that this argues against standards. It does not. Abandoning a common framework would sacrifice comparability, supervisory efficiency and workforce mobility for a benefit realised only in rare events. The argument is that a converged sector needs a deliberately maintained minority position, not a different majority one.

The second is that internal audit or external review already provides the corrective. Both are governed by the convergence. Its remit, working papers, sampling logic and maturity rating derive from the same standards estate as the process it examines. It will reliably detect non-compliance. It has no instrument for detecting the framework's omissions, because a gap does not present as a finding. It presents as a clean report.

The third is that diversity of standards constitutes diversity of method. Sectors comfort themselves that several frameworks circulate and firms may choose between them. The discipline's own comparative material makes this hard to sustain: it presents multiple named methodologies as genuine alternatives while conceding, in the same discussion, that they share one process spine and differ principally in terminology, emphasis and depth. Choosing between instruments that ask the same questions in different words is branding, not methodological diversity — though the precise degree of shared architecture across the major published standards [FACT CHECK REQUIRED] is ERANORTH's reading rather than a sourced finding.

Reframing the Issue

The useful reframing treats method concentration as a portfolio exposure: what share of our capacity to notice sits in one instrument, and what is our position if that instrument is wrong in a way we cannot see from inside it?

Three things follow. Method concentration has a measurable proxy — the provenance of the people who assess risk and the templates they use. It has a hedge — divergent capability, deliberately retained and held in reserve rather than deployed everywhere. And it has a budgetable cost, because retaining a divergent method is inefficient by construction, and the inefficiency is the price of the cover.

This also reframes independence. Independence of interest — no stake, no reporting line, no prior involvement — is necessary and well governed; independence of formation is neither required nor measured anywhere. The first protects against a reviewer who does not want to see, the second against one who cannot.

Where Convergence Reaches Assurance First

Independence is defined against the entity, not the field

Every assurance regime the discipline has produced specifies independence relative to the thing reviewed: not on the project, not in the reporting line, not previously involved. Applied consistently, that yields a reviewer from the next office or a firm in the same market — same certification, same categories, same maturity model. The independence obtained is real and addresses a real failure mode. It is simply orthogonal to that of a converged method, which requires a reviewer whose formation differs, not whose desk does.

The template is the transmission mechanism

Convergence travels less through mandates than through artefacts: the register template, the breakdown structure, the scoring scale, the workshop prompt list. Each is adopted because it saves time and satisfies reviewers, and each carries a settled theory of what a risk is. Once the same artefacts are in use across a sector, the population's identification capacity has been shaped by a handful of documents nobody in any single firm is positioned to challenge — questioning a template every peer uses reads as eccentricity, not diligence.

The maturity model closes the loop

The final mechanism is evaluative. Where a sector's maturity model defines advanced practice as fuller adherence to the common framework, a firm maintaining a divergent method scores worse than one that does not. The instrument meant to measure risk capability penalises the only capability protecting against its own blind spot. Whether a maturity rating should attach to an individual or an organisation is a separate question owned by Article 26. What matters here is that convergence becomes self-reinforcing the moment it is graded.

Two adjacent problems sit outside this article. Convergence also produces a shared control estate nobody in the sector retires, whose compounding cost belongs to [Related article: Who Retires a Control?]. And within a single enterprise the register is distorted long before any sector effect applies, because it doubles as an input to individual appraisal — an incompatibility owned by [Related article: Honest Instrument, or Performance Input?], while this article deals only with what a whole sector cannot see.

Decision Framework

The instrument is the divergent-method reserve: a deliberately maintained, budgeted minority of the enterprise's risk work conducted by a method that is not the sector's dominant one. It is governed as a reserve — sized, owned, tested and reported — not run as a pilot.

Sizing rule. Set a floor: a proportion of material exposure re-examined each year by a divergent method, or a fixed number of the enterprise's largest decisions. A floor is required because a reserve without one is the first thing cut in a cost cycle.

Divergence test. A method qualifies only if it differs on at least two of three axes: unit of analysis (narrative scenario or failure-mode reasoning rather than a discrete-event register); source of judgement (people whose formation lies outside the sector's dominant certification); and primary question (what would have to be true for this to fail, rather than what could go wrong). A method differing only in vocabulary fails.

Reviewer provenance rule. At least one reviewer per cycle must have been trained outside the sector's dominant framework. Record provenance explicitly: certifying body, formative sector, years inside the industry. Provenance is auditable; independence of mind is not.

The nil-return trigger. If a divergent review returns nothing absent from the dominant register, treat that as evidence the review was not divergent — not that the register is complete. Two consecutive nil returns require replacing the method or the reviewer, and the trigger belongs in the terms of reference before the first review runs.

Placement rule. Point the reserve at exposures where the sector's collective experience is thinnest, not where its stated exposure is largest. New product forms, counterparty types, materials, regulatory interpretations and recent acquisitions are where a shared framework is least likely to hold a category — and where its absence is least likely to be noticed.

Consider professional archaeology and heritage consulting as a second hypothetical case. Almost every practitioner trained in one of a few departments, works to shared assessment guidance, and reviews peers' work as a condition of consent. Individual assessments are competent. What the framework has no category for — the cumulative effect of many small approvals, or whether archive and curation capacity exists for what is recovered — is invisible to every participant at once, and the peer reviewer checking the work comes from the same handful of firms.

From Strategy to Execution

Immediate. Map provenance. For everyone who assesses or assures risk, record where they were trained and under which framework. If a single certification lineage accounts for most of that population, you have measured your method concentration — usually a higher number than the executive expects.

Medium-term. Stand up the reserve with a named owner, a budget line, and terms of reference containing the divergence test and the nil-return trigger. Point it at one recently acquired or recently created exposure. Report its findings to the board separately from the main risk report: consolidating them into the standard format re-imposes the categories the reserve exists to escape.

Long-term. Make provenance diversity a standing criterion in recruitment for risk and assurance roles, and require external providers to disclose the formation of the individuals assigned, not the credentials of the firm. Where your sector maintains a maturity model, argue for divergent capability to be recognised within it: a sector grading only conformity will keep producing correlated blindness however well individual firms perform.

Signals to Monitor

Watch the agreement rate between internal and external review. Sustained high agreement is usually read as assurance quality; in a converged sector it is better read as evidence that both parties run the same instrument. Watch, too, how many register entries would appear on a generic template for your industry: a register a competitor could have written describes the sector's shared model rather than your enterprise.

Watch the origin of findings. If they consistently concern compliance with the framework rather than exposures it cannot accommodate, assurance is operating inside the boundary it was created to test. And after any sector-wide loss, ask how many participants held it on a register beforehand: a low count across a whole market is not evidence the event was unforeseeable, but a measurement of correlation.

Questions for the Leadership Team

  1. Of the people who identify, assess or assure risk for us, what proportion were trained under the same framework, and which certifications does that population hold?
  2. Which of our material exposures currently has no category in the framework we use, and who would have raised it had it fitted?
  3. When our external assurance provider last examined us, what was the professional formation of the individuals assigned — not the firm's credentials, but theirs?
  4. In the last three loss events in our sector, how many participants carried the exposure on a register before it materialised, and what does that tell us about the method rather than the events?
  5. What would it cost annually to maintain a divergent review capability, and against which specific exposures would we place it first?
  6. Does our sector's maturity model reward or penalise retention of a method that differs from the standard, and what has that done to our own investment decisions?

Closing Perspective

Method concentration is the one exposure a risk function cannot detect using its own instrument, which is why it survives every cycle of improvement the sector runs. Each round of standardisation raises the average and tightens the correlation, and the second effect is never entered anywhere as a cost.

The decision this leaves is specific and uncomfortable. Maintaining a divergent method is measurably inefficient: scored down by the maturity model, questioned in benchmarking, hard to defend in a cost review, because its value is realised only when the consensus method is wrong. An enterprise that funds only what its sector's framework recognises as good practice has, by that decision, adopted the sector's blind spot as its own — with no paper anywhere recording that a choice was made.


About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.