How to Identify and Manage Emerging Risks
A framework and practical guide for moving from scattered early evidence to clear risk hypotheses, priorities, and strategic action.
- Format
- Practical guide
- Framework
- Seven building blocks
- Use
- Executive and risk teams
- Access
- Public

Why analyze emerging risks?
Most organizations have no shortage of risk information. The real challenge is identifying which developments could materially affect the organization before those developments become obvious.
Is a new regulation an isolated policy announcement or the beginning of a structural change? Is an unusual incident evidence of an emerging risk or simply noise? Which weak signals deserve executive attention, and which should remain on a watchlist?
A robust emerging-risk process turns scattered information into actionable foresight. It helps an organization detect change earlier, uncover interdependencies, and prepare before uncertainty becomes disruption.
Traditional risk management is strongest when risks are familiar, measurable, and supported by historical data. Emerging risks rarely offer those advantages. They may involve:
- Limited or contradictory evidence
- Unclear probabilities
- New combinations of familiar risks
- Long-term consequences
- Rapidly changing exposure
- Controls that have not yet been tested
- Dependencies that cross organizational boundaries
An emerging-risk analysis helps answer three questions:
- What is changing?
- How could it affect our objectives?
- What should we do before the outcome becomes clear?
The emerging-risk framework
A comprehensive emerging-risk assessment can be structured around seven building blocks. Each block answers a distinct question while preserving the evidence chain from source to decision.
- 01Scope and ObjectivesDefine the system, horizon, and decisions before starting the scan.
- 02Current Risk BaselineUnderstand the existing system before deciding what is genuinely new.
- 03Horizon ScanningSearch systematically for early evidence of meaningful change.
- 04Signal AnalysisSeparate fact from inference, then cluster signals into meaningful patterns.
- 05Emerging Risk FormulationTranslate a pattern of change into a credible pathway to consequence.
- 06Assessment and PrioritizationDecide which risks to watch, investigate, prepare for, or act on.
- 07Response and MonitoringTurn emerging-risk analysis into accountable action and continuous learning.
Sources → scan hits → signals → patterns → emerging risks → strategic responses
Scope and Objectives
Define the system, horizon, and decisions before starting the scan.

What it is
This step defines the subject, boundaries, time horizon, and intended use of the analysis.
Without a clear scope, horizon scanning can become an unlimited collection of interesting information with little strategic relevance.
How to do it
Start by writing a focal question:
What emerging changes could materially affect [objectives or system] within [scope] by [year], and how should [organization] prepare?
Then define:
- Objectives: What is the organization trying to achieve or protect?
- Domain: Which activities, services, or systems are included?
- Geography: Is the analysis global, regional, or country-specific?
- Time horizon: How far into the future are you looking?
- Decisions: Who will use the analysis and for what?
- Exclusions: What will not be covered?
Use three time horizons where appropriate:
- H1: Current system and immediate pressures
- H2: Transition and emerging alternatives
- H3: Structural transformation
Current Risk Baseline
Understand the existing system before deciding what is genuinely new.

What it is
The baseline describes how the system currently works and which risks, assumptions, and controls are already recognized.
Its purpose is to distinguish genuinely emerging change from familiar risks and current operational problems.
How to do it
Review:
- Existing risk registers
- Strategic plans
- Business models
- Critical processes and assets
- Historical incidents
- Current controls
- Key dependencies
- Known trends
- Existing risk appetite
- Management assumptions
Identify the assumptions supporting the current strategy. Examples include:
- Critical suppliers will remain available.
- Regulation will remain broadly stable.
- Customers will continue behaving similarly.
- Key technologies will remain economically viable.
- Skilled employees will remain available.
- Insurance will remain affordable.
These assumptions later become scanning targets.
Horizon Scanning
Search systematically for early evidence of meaningful change.

What it is
Horizon scanning is the systematic search for early evidence of developments that could create future threats, opportunities, or strategic surprises.
It is broader than reading the news. It includes identifying, collecting, and interpreting signals across multiple sources and domains.
The University of Houston summarizes the process as Find → Collect → Analyze.
How to do it
Begin with two complementary scanning modes:
Directed scanning
Search for developments related to known objectives, dependencies, and assumptions. For example:
- Could regulation change?
- Are new substitutes appearing?
- Is supplier concentration increasing?
- Are customer behaviours shifting?
- Are existing controls becoming less effective?
Exploratory scanning
Search outside the current risk taxonomy and immediate industry. Explore:
- Adjacent sectors
- Emerging technologies
- Social movements
- New business models
- Scientific research
- Geopolitical developments
- Environmental change
- Changing values and behaviours
Use STEEP to maintain broad coverage: social, technological, economic, environmental, and political.
Where to scan
Use a balanced source portfolio:
- Government and regulatory publications
- Scientific research and patents
- Corporate filings and procurement notices
- Investment activity and incident reports
- Industry publications and reputable news
- Job advertisements and specialist newsletters
- Startups, pilot projects, online communities, and edge sources
Search for change words such as:
pilotprototypefirstunexpectedfailurebanlawsuitshortageinvestmentprocurementpatentnew regulationbacklashrecord increasedeclineSignal Analysis
Separate fact from inference, then cluster signals into meaningful patterns.

What it is
Signal analysis converts raw sources into structured observations about change.
An article is a scan hit. The change it may indicate is the signal.
How to do it
For each scan hit, separate three elements:
- Observed fact: What does the source establish?
- Interpretation: What change might this indicate?
- Implication: Why could that change matter?
Example
- Observed fact
- A regulator launches a consultation on algorithmic accountability.
- Signal
- Governments are beginning to treat algorithmic decisions as a distinct regulatory category.
- Potential implication
- Organizations may face new audit, explanation, and appeal requirements for automated decisions.
Capture each signal using a standard card:
- Title, observed evidence, interpretation, source, and date
- Actors, geography, STEEP category, and time horizon
- Evidence maturity, related signals, and counterevidence
- Analyst decision
Next, group related signals into clusters. A cluster might contain regulatory consultations, new professional roles, litigation, technology failures, and corporate-governance changes.
Together, these may reveal a broader driver such as:
Increasing accountability for automated decisions
Emerging Risk Formulation
Translate a pattern of change into a credible pathway to consequence.

What it is
This step translates a pattern of change into a risk that could affect objectives.
A trend is not automatically a risk. It becomes a risk when there is a credible pathway from the change to an organizational consequence.
How to do it
Use this risk-statement formula:
Because of [driver or changing condition], there is a possibility that [uncertain event or development] will affect [objective], resulting in [consequences] within [time horizon].
Example
Because organizations increasingly depend on a small number of shared digital-infrastructure providers, a provider failure, cyber incident, or regulatory restriction could disrupt several critical services simultaneously, undermining operational continuity and compliance within three to seven years.
Then map the causal pathway:
- Driver
- Changing exposure
- Potential event
- Direct consequence
- Cascading effects
- Objective affected
Map relationships such as:
- Depends on
- Causes
- Amplifies
- Constrains
- Enables
- Substitutes for
- Mitigates
- Is exposed to
Assessment and Prioritization
Decide which risks to watch, investigate, prepare for, or act on.

What it is
This step determines which emerging risks deserve monitoring, investigation, preparation, or immediate action.
Emerging risks should not be assessed using false precision. Their probabilities are often poorly understood, but their potential consequences and preparation requirements can still be evaluated.
How to do it
Assess each risk across several dimensions:
- Strategic relevance, potential impact, reach, and persistence
- Reversibility, velocity, and time to impact
- Preparation lead time and interconnectedness
- Exposure trajectory and control maturity
- Evidence confidence
Keep evidence confidence separate from potential impact.
Low evidence confidence, high potential impact, and a long preparation lead time.
That combination may justify investigation and no-regret preparation even though its likelihood cannot yet be estimated reliably.
| Evidence confidence | Lower potential impact | Higher potential impact |
|---|---|---|
| Lower | Watch | Investigate and preserve options |
| Higher | Monitor or manage routinely | Prepare or act |
Response and Monitoring
Turn emerging-risk analysis into accountable action and continuous learning.

What it is
The final step converts emerging-risk analysis into decisions, preparation, and continuous learning.
The aim is not always to eliminate the risk. It may be to understand it, monitor it, preserve options, or increase resilience.
How to do it
Assign one of six management postures:
- Watch: Retain the signal and monitor developments.
- Investigate: Reduce important knowledge gaps.
- Prepare: Take no-regret actions and preserve options.
- Act: Implement controls because exposure is accelerating.
- Transfer to ERM: Move the risk into conventional management once it becomes sufficiently familiar.
- Retire: Remove risks that are invalidated, irrelevant, or fully absorbed elsewhere.
Possible responses include:
- Additional research and expert interviews
- Scenario exercises and pilot programmes
- Dependency diversification and alternative suppliers
- Contractual flexibility and workforce development
- Business-continuity improvements and new insurance arrangements
- Decision triggers and contingency plans
Define indicators at three levels:
- Leading indicators: Patents, research, policy proposals, and pilots
- Development indicators: Adoption, investment, procurement, and geographic spread
- Materialization indicators: Incidents, losses, litigation, and service disruption
For each indicator, define:
- Data source
- Owner
- Review frequency
- Threshold
- Required action
Scale the evidence. Strengthen the judgment.
AI can streamline the most labor-intensive parts of the framework, but human judgment remains essential where context, materiality, accountability, and decisions converge.

AI for scale and connection
- Monitoring large source sets
- Extracting events and claims
- Translating sources
- Removing duplicates
- Drafting signal cards
- Clustering related signals
- Finding counterevidence
- Mapping relationships
- Identifying coverage gaps
- Monitoring indicators
Humans for judgment and action
- Defining the focal question
- Determining strategic relevance
- Validating causal relationships
- Assessing materiality
- Applying risk appetite
- Selecting responses
- Accepting accountability
AI for collection, structure, and connection; humans for context, judgment, and action.
The “so what?”
The framework is valuable only when it changes a decision, strengthens preparedness, or preserves a strategic option. Its discipline comes from making every step inspectable: what was observed, what was inferred, how the risk could travel, what merits attention, and which evidence should trigger action.