Rather than acting as a defensive barrier, an integrated, cross-functional risk strategy gives organisations the operational confidence to accelerate through overlapping global crises.
Key Insights
- Global crises no longer strike in isolation; they create compounding threats that cascade across borders and industries.
- Traditional, siloed risk management fails in this environment because rigid departmental boundaries blind businesses to the interconnected chain reactions that cause enterprise-wide breakdown.
- To build enterprise resilience, companies must adopt a decentralised risk culture that empowers rapid decision-making and turns risk from an obstacle into a strategic advantage.
The era of standalone crisis is over. Over the past six years, markets have absorbed back-to-back shocks driven by “inflation, tariffs, wars, and a pandemic “, as Andy Romanis, Chief Risk Officer at Olam Food Ingredients (ofi), observed.
Because these threats ripple across global operations, siloed departmental responses guarantee failure. Navigating this cumulative volatility demands holistic thinking from a modern polycrisis enterprise.
This operational shift took centre stage during the Institute of Enterprise Risk Practitioners (IERP®) Global Conference 2026, where Andy explored the topic on a panel moderated by Tony Chin, Former Bank Chairman and Board Advisor.
Featuring Norliwati A Wahab, Group Chief Risk Officer at PETRONAS, and Loshani Ravindranath, Managing Director & Regional Head of Risk Control Unit, Group Consumer Banking at CIMB Bank, the session mapped how dismantling traditional boundaries builds enterprise resilience.
The Rise of the Polycrisis Enterprise
A polycrisis occurs when multiple, seemingly unrelated threats collide to create a widespread disruption far greater than the sum of its parts.
As a result, companies no longer face disruptions one at a time. They now must navigate overlapping volatility, where geopolitical tension, economic instability, and supply chain bottlenecks all interact at once.
Surviving this environment requires a fundamental shift in perspective. Historically, businesses viewed risk management as a defensive, compliance-driven hurdle designed only to prevent worst-case scenarios. However, building enterprise resilience means reframing risk from a restrictive hurdle into a strategic enabler for long-term growth.
Norliwati captured this shift using a straightforward automotive analogy. “Having brakes in your car allows you to brake when there’s an emergency, but it gives you the confidence to drive as fast as you want,” she explained.
In this sense, robust risk management functions like a high-performance braking system. It does not exist to slow the organisation down or limit its potential; it provides the essential protection needed to accelerate safely.
When leadership teams know they have reliable mechanisms to absorb multiplying shocks, they gain the operational clarity to pursue ambitious value creation, even in an unpredictable world.
How Converging Risks Fracture Operations
While value creation is the ultimate goal, the reality on the ground is that a standalone incident quickly triggers a domino effect across supply chains, financial markets, and corporate reputations. When threats surface, they rapidly cross borders and industries to amplify existing vulnerabilities.
Andy illustrated this reality by detailing how geopolitical tensions sever established trade routes. Using the shipment of coffee as an example, the ofi’s Chief Risk Officer noted how avoiding the Red Sea drastically alters logistics.
“What was typically a 25-day voyage from Ho Chi Minh to Antwerp is now a 40-day voyage if you have to go around the Cape,” he explained. Geopolitical risk in the Middle East has also disrupted aviation: airlines have been avoiding Iranian airspace since March, meaning that some of the air corridors particularly along the northern coast of Turkiye are very congested.
These physical delays inevitably trigger secondary operational hurdles. As logistical routes shift, firms face immediate administrative friction. For example, Andy noted that alongside physical rerouting, companies must navigate complex insurance negotiations, in some cases having to secure specific pre-approvals.
Moving beyond logistical hurdles, Norliwati emphasised that converging threats force businesses to assess exposure across multiple fronts. Plus, supply chain shocks are the beginning; a polycrisis enterprise must instantly evaluate the knock-on impact on its people, environmental assets, and corporate reputation on the ground.
Why Siloed Enterprise Risk Management Fails
Traditional risk registers often treat threats separately, giving organisations a false sense of security. When departments operate behind rigid walls, they remain blind to the interconnected ripple effects that actually cause large-scale breakdown.
Loshani detailed how a single geopolitical event ripples through a financial institution’s internal departments. She observed that converging risks behave like a tsunami, arriving in successive waves that multiply across different business functions.
She traced the trajectory of an oil supply constraint to show exactly how this unfolds:
- Macroeconomic shift: A sudden supply shock drives up inflation and interest rates.
- Commercial strain: Household affordability drops, instantly compressing profit margins for SMEs and creating direct credit risk.
- Internal friction: This financial strain triggers heightened collections activity and attracts intense regulatory scrutiny.
- Reputational damage: Left unchecked, the compounding fallout ultimately destroys consumer trust.
Standalone defences prove useless against threats that jump seamlessly from department to department. A fragmented approach invites failure when modern crises demand unified, cross-functional visibility to survive.
Building Resilience in Enterprise Risk Management
Moving beyond reactive defence requires companies to map out the knock-on effects of overlapping threats long before they strike. This proactive shift represents the evolution of enterprise risk management.
Tony explained that the contemporary Chief Risk Officer functions less as a traditional gatekeeper and more as a strategic prioritiser. “The CRO to me, as a CEO, is a chief risk filter because their role is to assess all the risks… and escalate the big ones to the top,” he observed.
For this filter to operate effectively during an overlapping crisis, a business must cultivate a decentralised risk culture that empowers rapid decision-making on the ground.
Loshani detailed how financial institutions relentlessly over-prepare for worst-case scenarios to safeguard operations. However, she emphasised that rigorous planning remains insufficient without strategic delegation.
She noted that organisations must actively embed empowerment into their culture, building mechanisms to ensure decisions made by frontline teams carry the exact same weight as those executed by senior leaders.
This decentralisation eliminates critical operational bottlenecks, giving the enterprise the structural agility needed to respond instantly when overlapping risks finally strike.
Turning Converging Risk Into a Competitive Advantage
When risk management functions as a proactive, decentralised strategy rather than a restrictive constraint, an organisation can anticipate how distinct threats interact before they materialise.
Committing to enterprise resilience transforms profound volatility into a distinct competitive advantage. An empowered, cross-departmental risk culture stops an organisation from merely defending against the next shock and enable it to confidently step forward as a highly adaptable polycrisis enterprise






















