Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Risk culture assessment showing leadership, communication, accountability and incentives around a risk management program

Risk Culture Guide 2026: Assess and Improve It

Risk culture is the set of shared values, beliefs and behaviors that determine how people in an organization notice risk, talk about it and act on it. It explains why two companies with identical policies, registers and committees can behave very differently when something goes wrong. In one, problems are raised early and dealt with. In the other, they are hidden until they become crises.

This guide explains what risk culture is, why it matters to enterprise risk management, how to assess it, which indicators reveal it, and practical steps to improve it. It is aimed at risk managers, compliance leads and executives who want more than a register and a policy.

What risk culture is

A widely used description comes from the Institute of Risk Management, which defines risk culture as the values, beliefs, knowledge, attitudes and understanding about risk shared by a group of people with a common purpose. In practice it is visible in small decisions: whether a manager welcomes bad news, whether a salesperson reports a customer complaint that might be a symptom, whether an engineer speaks up about a shortcut, and whether leaders reward results at any cost or results achieved the right way.

The COSO Enterprise Risk Management framework places culture in its governance and culture component, which includes exercising board oversight, establishing operating structures, defining the desired culture, demonstrating commitment to core values and attracting, developing and retaining capable individuals. You can read the framework overview on the COSO ERM guidance page. Our guide to the COSO ERM principles explains where culture sits among them.

Why risk culture matters

Processes cannot cover every situation. Most risk decisions are made by individuals without a committee looking on, and culture guides those decisions. Supervisors of financial institutions have emphasized this for years. After the financial crisis, the Financial Stability Board published guidance on supervisory interaction with financial institutions on risk culture, precisely because weak culture was seen as a root cause of failures that formal controls did not prevent. The same applies outside finance: safety events, data breaches and product failures often trace back to warning signs that were known and not acted on.

A strong culture does not mean avoiding risk. It means taking risk knowingly, with the right people involved, inside the limits the organization has set. Our guide to risk appetite shows how those limits are defined.

Elements of a healthy risk culture

ElementWhat it looks likeWarning sign
Leadership behaviorLeaders discuss risk openly and ask about it in decisionsRisk mentioned only in audit season
Speaking upStaff raise concerns and are thankedPeople fear blame for reporting problems
AccountabilityRisk owners named and held responsibleRisks owned by a committee, no individual
IncentivesRewards balance results and conductTargets reward volume with no regard to risk
CompetencePeople understand the risks in their rolesRisk seen as the risk team’s job
LearningIncidents lead to changesThe same incidents repeat

How to assess risk culture

You cannot audit risk culture the way you audit a control, but you can look at it from several angles and compare them. Use more than one method, since each has blind spots.

  1. Surveys. Short anonymous questions on speaking up, trust in leadership, clarity of accountability and perceived pressure. Compare results across units and over time.
  2. Interviews and focus groups. Ask open questions about recent decisions, near misses and how bad news travels.
  3. Behavioral indicators. Look at data that reflects actual behavior, such as the number and timing of incident reports, the age of open audit actions and the take-up of training.
  4. Decision reviews. Examine a sample of significant decisions to see whether risk was considered, who was involved and what was recorded.
  5. Observation. Sit in on committees and reviews and note how risk is discussed.

Indicators that tell you something

Useful indicators include reporting rates, since a very low number of incident reports usually means under-reporting, not a safe organization. Other measures are time from event to escalation, share of risk owners who have updated their entries on time, percent of audit actions closed on time, staff survey results on willingness to speak up, use of the whistleblowing channel and repeat incidents. Pair them with the kind of thresholds described in our guide to KRI thresholds. Do not treat any single figure as proof, since each has explanations, but look at patterns across units and over time.

Building tone from the top and the middle

Leaders set the tone with what they do, not what they say. When executives ask about risk in strategic decisions, accept bad news calmly, and admit their own mistakes, others follow. Middle managers are equally important, because most employees judge culture by their direct manager. Equip managers to respond well when someone raises a concern, and hold them accountable for how their teams behave.

Include risk in objectives and reviews. If performance pay rewards revenue only, the message is clear. Add conduct and risk measures to scorecards and give them real weight, and make sure that those who raise legitimate concerns are protected from retaliation.

Making risk management part of everyday work

Culture improves when risk practices are simple and useful to the people doing the work. Keep templates short, embed risk questions in project gates and planning, provide quick guidance and make it easy to log an issue. Show people what happened to what they reported, since nothing kills reporting faster than silence. Our guide to the enterprise risk register shows how to keep the record usable, and the risk management policy can set out expectations for all staff.

Linking culture findings to reporting

Report the results of your assessment to the board alongside other risk information, with trends, hot spots and actions. Combine it with the portfolio view described in our guide to risk aggregation, so that leaders see where cultural weaknesses coincide with high exposure. A unit that scores poorly on speaking up and also holds a large concentration of risk deserves attention first.

Culture in different parts of the organization

Culture is rarely uniform. A trading floor, a research laboratory and a customer service center each develop their own norms, and a group-wide statement will land differently in each. Assess by unit, then compare. Look particularly at places under pressure, such as teams with aggressive targets, recent reorganizations or high turnover, because pressure is when shortcuts are tempting and people are least likely to speak up. Also look at new acquisitions, where the acquired business may have very different habits.

Where units differ, avoid the temptation to rank and shame. Ask what the stronger units do differently and what supports them, and share those practices. Involve local leaders in designing the response, since changes they help design are more likely to last.

A short worked example

A manufacturer notices that few near-miss reports come from one plant even though incidents there are similar to others. A short survey shows that supervisors there tend to ask who is to blame before asking what happened. Leadership responds with three steps: training for supervisors on responding to reports, a rule that the first question is what can we learn, and a monthly summary of changes made because of reports. Within a year the plant’s reporting rate rises to the group average and the number of serious incidents falls. The lesson recorded is that the change came from how managers responded, not from new procedures.

Common mistakes when working on culture

Organizations treat culture as a communications campaign, rely on a single annual survey, blame individuals for system problems, ignore incentives, leave middle management out and never report results to the board. Another mistake is confusing a quiet risk register with a healthy culture. Silence can mean people have stopped bothering. Track behaviors and outcomes, act visibly on what you learn and repeat the assessment at regular intervals.

Building an assessment on a solid base

Culture work sits on top of a sound risk process. If you need a structure for that base, the Enterprise Risk Assessment Report and Workbook provides a structured assessment, scoring and register that can carry your culture indicators alongside other risk information. Whatever you use, treat it as something to measure, discuss and improve, not as a slogan.

Risk culture FAQ

What is risk culture?

It is the shared values, beliefs and behaviors that shape how people in an organization identify, discuss and respond to risk, visible in everyday decisions.

Can risk culture be measured?

Not directly, but you can combine surveys, interviews, behavioral indicators such as reporting rates and decision reviews to build a reliable picture and track it over time.

Who is responsible for it?

Leadership owns it. The board sets expectations, executives model behavior, managers reinforce it daily and the risk function measures and supports, but it cannot own culture alone.

What is a good sign of a healthy risk culture?

People raise concerns early, near misses are reported, bad news travels quickly, incidents lead to changes and leaders respond with curiosity instead of blame.

How often should it be assessed?

Assess it at least annually, and after major events or organizational change, using the same methods so that results can be compared across periods.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.