We are particularly delighted to feature an exclusive interview with Stephen Sidebottom, Chair of the Institute of Risk Management (IRM), to mark the release of his new book, Fundamentals of People Risk Management. In our conversation, Stephen shares insights from his extensive experience in risk, leadership and human resources, and discusses why people risk deserves a more prominent place in boardroom discussions. His book provides practical frameworks for understanding how behaviour, culture, ethics and decision-making influence organisational success and resilience, offering timely guidance for risk professionals seeking to integrate people risk into enterprise-wide risk management approaches.
What inspired you to write Fundamentals of People Risk Management, and why do you believe now is the right time for organisations to focus more seriously on people risk?
The book has grown quite naturally out of the overlap between two parts of my professional working life. I spent many years leading global HR functions and working with leaders on managing the human reality of organisations. I have also become increasingly involved in the world of risk, where there is a strong thinking discipline about uncertainty, exposure, control, and long-term resilience.
These two worlds often look at the same organisation and the same event but don’t always join the dots to create an holistic interpretation of what is going on. HR can see much of the lived reality of work and understands people management processes. Risk sees the formal architecture of governance and control but often has an underdeveloped view of the connection between the human system and enterprise risk.
The book doesn’t argue that organisations have ignored people related risks. On the contrary, they already recognise many of the visible manifestations of these risks. Things like fraud, misconduct, capability gaps, concentration risks, well-being concerns, and cultural failures are familiar to us from many examples across sectors.
But in practice it seems to me they are often managed as operational issues through process controls, compliance mechanisms or event responses, or sometimes as abstractions with general statements of intent.
Of course, these responses are often useful. Fraud prevention controls are necessary, as are things like conduct standards, clear incentives, and accountability. Well-being requires significant attention to health, safety and workplace design. But the approach to people risk here asks a different question, an upstream question, about the conditions in the human system that make people risk consequences more or less likely.
This is rooted in my belief that a well calibrated human system creates sustainable long-term value for organisations. Financial soundness, commercial relevance, and competitive positioning are essential, but they are not sustained in isolation. Sustainable performance also depends on the extent to which the organisation can build and maintain trust, competence, belonging, well-being, and learn and renew itself.
As to “why now?”, organisations are operating in conditions where human systems are under increasing pressure. Technology is changing work significantly, trust in institutions is weak, and external demands and pressures are rising. These forces are reshaping what organisations need from the people who work in them. and what those people in turn need from their organisations. Given this context, people risk cannot be treated as a set of HR issues or operational incidents – it has to be understood as part of enterprise risk management in support of long-term resilience.
Drawing on your experience in risk management, what were some of the biggest challenges you faced when translating complex people risk concept into a practical guide for readers?
Human systems are complex open systems, so there was a real challenge in working out how to approach this in a way that was relatively straightforward to navigate and allowed readers to work out what they were going to do. The biggest challenge was perhaps to accept that there is no single answer or formula that can be applied. It’s not as straightforward as simply offering a model or checklist.
The book is, however, rooted in a relatively simple argument. People risk starts upstream, in the conditions that shape how people think, decide, and act. It is a property of systems, not individual behaviour. Organisations therefore need to move from events and symptoms to underlying conditions and system design in the way they think about understanding and managing their people risks.
It is also essential to understand organisational context. Every organisation has its own purpose, priorities, history, strategy, pressures and vulnerabilities. So, the practical question rapidly becomes not “what is the universal answer to people risk?”, but “how does this organisation create value through its human system and where is that value vulnerable?”
That is why the book offers a framework, or a landscape of issues, rather than a formula. The framework links inputs with outcomes. The inputs are those areas where organisations can act, and the outcomes describe the human conditions that show whether the system is working well. These outcomes are not simply aspirations or sentiment measures but instead markers of long-term organisational health.
Inputs are the areas where leaders, HR professionals, and risk practitioners should intervene. For example, if trust is deteriorating, the answer is not to measure trust more elegantly. The task is to understand what leadership, cultural, work design, or external conditions are causing it to deteriorate in the first place. If there are problems of competence, the question should not be only whether training exists, but whether the organisation’s strategy, operating model, and knowledge systems are aligned.
This is where the second line perspective of the book becomes so important – the risk oversight that challenges, monitors, and tests whether risk is being managed effectively. HR owns many people processes, but people risk is broader than HR process effectiveness. The book tries to give HR, risk professionals, and leaders a shared way of seeing how risk exposure is created and transmitted through the human system.
Were there any particular case studies, experiences or conversations that significantly shaped the direction and content of the book?
When I began the project, I expected to spend more time drawing specific lessons from interviews with managers, HR leaders and risk professionals. Those conversations were valuable in shaping the overall direction, but I realised that the most interesting part was not usually the individual initiative they described, but how they were thinking about their organisation as a system. That shifted the book away from cataloguing good practice and more towards helping readers develop a way of seeing the system in which they are operating. In a complex organisation interventions only make sense in context. Identifying high impact interventions require a real understanding of timing, trust, leadership attention, and readiness for change. The same actions or interventions that can be catalytic in one setting could be performative in another.
Public case studies therefore become important because they allow us to step back and ask different questions. Not “who failed?” but “what did the system make more likely?”, “what was being reinforced?”, “what was being ignored?”. Rather than offering a new diagnosis these case studies offer opportunities to consider how those same issues might play out in other organisations and to recognise that organisations can reach a state where they are no longer able to see and understand the dynamics within their own human system.
The book uses examples such as the Post Office Horizon scandal, Boeing, Wells Fargo, and the Metropolitan Police to explore how people risk manifests in different places and over time. These organisations are all very different, but major failures often emerge from familiar patterns such as discounting weak risk indicators, making challenge costly, distorting judgement through incentives, and mistaking activity for control.
The IRM people risk survey also shaped book. Respondents recognised people risk as strategically important, but repeatedly described the problem in terms of conditions rather than individual traits. Conditions such as overload, ambiguity, conflicting expectations, hierarchy, and blurred ownership. That reinforced in my mind the need for a framework that starts upstream with the conditions that produce behaviour, rather than downstream with the risk event.
How do you see the relationship between organisational culture, leadership and enterprise risk evolving over the next few years?
I think culture will become much more central to enterprise risk, but only if we also become much more precise about what we mean by it and clear about how we manage it.
In the book culture is not treated as a general organisational atmosphere. Instead, it is defined as what most people do most of the time. From a risk perspective, culture is an essential part of the control environment and should be managed as such. This is because culture either amplifies or dampens weak risk signals, it either accelerates or holds back organisational learning, and it either reinforces or undermines leadership intent. This means culture can become a powerful source of resilience, or a vector of harm. The difference depends on whether leaders see the system clearly and act with discipline to manage it.
In my experience this is where many organisations struggle. They can recognise issues such as conduct risk, ethical risk, and cultural risk, but they often try to manage them through values statements, behavioural expectations, or compliance processes. Those things may be a necessary part of the control environment, but they are not enough. Decision discipline, challenge, ethical behaviour and candour cannot simply be mandated, they have to be created instead through the conditions people experience every day.
Leaders collectively shape what the organisation notice and acts on, what it tolerates, and when and how it learns. If leaders say one thing but reward another, the organisation learns from the reward. If challenge is invited but then punished, the organisation learns from the punishment. The formal message may matter, but the lived signal matters more.
Over the next few years, I expect more mature organisations to stop treating culture as a survey topic and start treating it as a living risk control surface. This means understanding how patterns of behaviour affect the organisation’s ability to govern itself well, to learn from events, and perform in a sustainable way. Organisations that already do this well connect leadership, culture and work design to value creation, reputation, and trust outside the organisation. The book describes how this works through the people risk value chain showing the way behaviour inside the organisation translates into value, performance and stakeholder trust outside it.
What are some of the most common mistakes organisations make when trying to manage people related risks, and how can risk professionals begin to address them more effectively?
Organisations don’t ignore people related risks. They do however frequently make the mistake of managing the manifestations of this risk in isolation.
Conduct risk is a good example. It is often managed through things like behavioural standards, incentives, customer duty obligations, conflict management and accountability mechanisms. Again, those are all important. But if the organisation only manages conduct at the level of process or individual behaviour, it may miss some of the deeper conditions that shape that conduct in the first place. The risk may lie in those conditions – decision discipline, ethical climate, leadership signals, workload, power, status, and whether people can challenge what is happening around them.
The same is true of concerns such as well-being, capability, and concentration risk. An organisation can treat each of these as a distinct operational issue, but together they also tell us something about the sustainability of the human system. A stressed system narrows judgement and decision quality. Fragile capability weakens resilience. A concentration of knowledge or authority creates dependency.
The role of risk professionals is to help shift the conversation from incident to system. This means asking not only “what happened?” but “what made this more likely, and where else might the same conditions exist?’ They can also help organisations become more deliberate and disciplined about weak signals. The challenge is not simply to collect more data. The task is to understand which signals matter because they connect to the organisation’s purpose, strategy, and most important sources of value creation. That’s where the second line has a particularly important role. It can help test whether people related exposures are being identified, owned, challenged, and assured as part of enterprise risk, rather than treated as isolated HR, conduct, or operational matters.
What do you hope readers, particularly risk professionals, board members and business leaders, will take away from the book and apply within their own organisations?
I hope that readers take away the idea that people risk is not just about preventing people from doing bad things. It’s much more importantly about understanding how organisations create value through human systems, and where that value is vulnerable.
For risk professionals, I hope the book gives them away into a territory that can sometimes feel difficult to handle. Culture, leadership, and behaviour may appear less tangible than financial or operational risks, but they often determine whether controls work at all.
For HR leaders, I hope it offers a stronger connection between their work and enterprise risk and value creation. HR often holds many of the signals that matter, but those signals are too easily reported as activity or sentiment rather than interpreted as evidence about the long-term health of the system.
For boards and business leaders, I hope the book encourages a more disciplined and inquisitive conversation about the organisation they are creating. What is the system they have built teaching people to do? What does it really reward? What does it ignore in practice? Where does it learn quickly, and where does it defend itself against uncomfortable information?
The book frames these questions through the relationship between inputs and outcomes. The inputs are the domains under management influence: leadership, culture, capability, work design and external context. The outcomes are the states that indicate whether the human system is resilient: trust, competence, inclusion and belonging, well-being, and learning and renewal. When one of these outcomes weakens, it is a signal that the underlying input needs attention.
I think this is important for sustainability and preparedness. Organisations rightly spend a lot of time understanding their competitive environment, horizon risks, geopolitical exposure, supply chains and regulatory change. My argument is that the human system is just as fundamental to resilience. It determines the extent to which the organisation can see clearly, decide well, respond quickly, and retain the trust it needs to operate.
That, for me, is the heart of people risk management. It’s not so much a response to failure or a better way of reporting HR activity. Instead, it’s a way of seeing, learning, and shaping the human system through which long term business value is created.
This website uses cookies to ensure you get the best experience on our website.
Read our Privacy Statement & Cookie Policy