Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Emerging risk identification funnel from horizon scanning to risk register

Emerging Risk Identification: A Practical Process 2026

Emerging risk identification is the discipline of spotting threats before they are big enough to appear in the risk register. Most registers are built from past events and known exposures. They tell you what has already gone wrong, or what the team can already imagine. By the time a new technology, regulation, conflict or social shift has produced a loss, it is too late to prepare cheaply.

This guide sets out a practical process for emerging risk identification: how it differs from the normal risk process, where to look, how to triage signals, how to use scenarios and how to report the results to leaders.

What makes a risk emerging

An emerging risk is a developing or evolving threat whose likelihood, impact or timing is uncertain and that is not yet fully understood or captured in the risk register. It may be new, such as a technology that did not exist before, or an existing risk changing character, such as a supply route shifting because of geopolitical events. The defining features are uncertainty and time: the risk may take years to mature, and by then the options to respond will be narrower.

ISO 31000:2018 describes risk management as dynamic, recognising that risks can emerge, change or disappear as internal and external contexts change, and it calls for continual monitoring and review. Emerging risk identification puts that principle into practice. Our guide to running a risk assessment workshop covers the routine process, and this article covers the forward-looking side.

How emerging risk identification differs from routine assessment

AspectRoutine risk assessmentEmerging risk identification
Time horizonUp to a year or twoThree to ten years
DataHistory, incidents, controlsWeak signals, expert judgment, trends
OutputRated risks with treatmentsWatch list, scenarios and early warnings
RatingsLikelihood and impact scoresRelevance, velocity and uncertainty
OwnerProcess or risk ownerRisk function with executive sponsor

Sources for horizon scanning

Good emerging risk identification draws on several kinds of source, because no single one gives the full picture.

  • Global outlooks. The World Economic Forum publishes an annual Global Risks Report that surveys experts on near- and long-term risks, a useful prompt list.
  • Regulators and standard setters. Consultations, discussion papers and speeches often signal new rules years ahead.
  • Industry bodies and peers. Trade associations, benchmarking and incident sharing groups.
  • Insurers and reinsurers. Their research on losses and trends.
  • Technology and science. Research publications, vendor roadmaps and patents.
  • Internal voices. Front-line staff, customers, sales and procurement often notice changes first.
  • News and geopolitical analysis. Conflicts, trade measures and social movements.

A repeatable process for emerging risk identification

1. Collect signals

Assign people to scan defined sources on a regular schedule and log signals in a common place. Ask business units to submit signals through a short form. Capture what was observed, the source, the date and why it may matter.

2. Triage

Not every signal deserves attention. Screen them against criteria such as relevance to your strategy and operations, potential impact, speed at which the risk could develop, the degree of uncertainty and the time left to respond. Group related signals into themes, such as climate transition, generative AI, supply chain fragmentation or workforce change.

3. Analyse selected themes

For each priority theme, develop a short paper: what is happening, how it could affect the organisation, which objectives and processes are exposed, what is known and unknown and what early indicators to watch. Involve experts inside and outside the organisation.

4. Test with scenarios

Scenarios turn uncertainty into something discussable. Write two or three plausible stories of how the theme might play out, including a severe but plausible one, and ask how the organisation would fare. Consider the effect on strategy, capital, operations and reputation. Scenarios do not predict; they test resilience and reveal what to prepare.

5. Decide the response

For each theme, choose one of a few outcomes: monitor with defined indicators, prepare contingency options, invest in capability, or move it into the main risk register with a treatment. Assign an owner and a review date. Themes that are not moved to the register still need a home.

Early warning indicators

Every watched theme should have indicators that would tell you it is becoming urgent: a regulatory proposal moving to formal consultation, a competitor launching a new product, a price crossing a threshold, a supplier showing stress. Set trigger levels in advance and agree what happens when one is reached. Our guides to KRI reporting and KRI thresholds describe how indicators and thresholds work in practice.

Building the right team and habits

The process depends on curiosity more than on tools. Form a small cross-functional group with people from strategy, operations, technology, legal, finance and sustainability, and rotate a few members each year so the group does not settle into one viewpoint. Encourage dissent, and make it safe to raise a signal that turns out to be wrong. A culture that punishes false alarms will produce silence.

Give the group a fixed rhythm. A monthly signal review of an hour, a quarterly theme session and an annual scenario exercise are enough for most organisations. Keep a log of themes and what happened to them, including those retired, so that you learn how often your early judgments were right and where blind spots lie.

Using external experts

Invite outside experts such as academics, regulators, insurers or industry analysts to challenge assumptions once or twice a year. They see patterns across many organisations and are less committed to your internal view. Brief them well, ask specific questions and record what changed as a result.

Linking themes to strategy

Tie each priority theme to a strategic objective and a named executive, and ask in every strategy review which themes could change the assumptions behind the plan. This is where the process delivers its value: not in the list, but in decisions taken earlier and with more options.

Governance and ownership

Emerging risks cut across functions, so the risk function typically coordinates the process, while an executive sponsor ensures leaders take part. Review the watch list at least twice a year at the risk committee, and bring one or two themes in depth to the board each cycle. Link the output to strategy and planning; if emerging risks never change a plan, the process is ornamental. Record the process in your enterprise risk register arrangements and connect it with your risk appetite discussions.

A hypothetical example of emerging risk identification

The following is a hypothetical example invented for illustration. A regional food distributor runs a quarterly scan. Signals include a regulatory consultation on packaging waste, a competitor’s trial of autonomous delivery vans, reports of rising heat-related crop failures in a key sourcing region and staff comments that drivers are leaving for logistics gig platforms. Triage groups these into four themes and rates the heat and sourcing theme as highly relevant and fast-moving.

The team writes a paper and a scenario: two consecutive poor harvests raise prices by 30 per cent for a core product, with supply gaps. The exercise shows the distributor relies on a single region for that product. The risk committee agrees to qualify a second supplier region, set price and yield indicators and add a concentration item to the main register. The packaging theme stays on the watch list with a trigger tied to the consultation outcome.

Common mistakes in emerging risk identification

Common weaknesses include one annual workshop with no follow-up, lists of buzzwords with no analysis, treating emerging risks as ordinary risks with likelihood scores, no owners, no indicators, no link to strategy, reliance on a single source, ignoring the front line, overreacting to every headline and never retiring themes. Another is limiting the scan to the industry’s own risks, when disruption often arrives from outside it.

Reporting emerging risks to leaders

Keep reports short. A one-page view listing themes, why each matters, the time horizon, current status, key indicators and the decision needed is more useful than a long catalogue. Use visuals such as a radar of themes by velocity and impact. Provide a few concrete questions for leaders, such as whether to invest in a capability or take a position. Update the view quarterly and highlight what changed since last time.

Templates for emerging risk identification

A consistent report format captures signals, themes, scenarios and responses in the same way each cycle. The Enterprise Risk Assessment Report and Workbook provides a report and workbook for documenting enterprise risks and their treatment. Whichever tool you use, keep the layout stable so leaders can see how themes develop.

Emerging risk identification FAQ

What is an emerging risk?

A developing or changing threat whose likelihood, impact or timing is uncertain and which is not yet fully captured in the risk register.

How often should we scan?

Continuously for signals, with a formal review at least quarterly and a deeper session once or twice a year.

How do we rate emerging risks?

Use relevance, potential impact, velocity and uncertainty rather than precise likelihood scores, and revisit as evidence grows.

When does an emerging risk join the register?

When it becomes concrete enough to assess and treat, for example when indicators trigger, exposure is confirmed or a decision is needed.

Who should be involved?

The risk function, an executive sponsor, business unit leaders, front-line staff and outside experts who can challenge internal views.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.