This is a conceptual paper that aims to (1) discuss how risk identification outcomes differ between Risk Management 1 (RM1) and Risk Management 2 (RM2) and (2) describe the potential consequences of these different outcomes on the organization at different management levels. This research challenges the traditional thinking that risk management is confined to the financial and operational aspects of the organization. It presents risk management as a strategic and value-adding process that contributes to organizational safety and which should be considered as an inseparable part of corporate strategy.
A literature review was conducted to explain the differences between RM1 and RM2 and how risk identification outcomes are likely to differ according to the overall risk management scheme adopted within an organization. The research approach is based on extensive review of the existing academic literature, as well as practitioner opinions, and reports and information produced by organizations outside of traditional academic publishing channels, underpinned by theoretical and practical reasoning. Non-academic sources were tested using the CRAAP criteria for quality and reliability purposes.
RM1 and RM2 are two different forms of risk management. Therefore, the outcomes of the risk identification process will differ accordingly. In other words, the nature of the risk management scheme adopted within an organization guides the outcomes of risk identification. The findings of this paper serve as theoretically derived propositions, expert reflections, professional recommendations and conceptual insights rather than definitive findings.
Senior executives need to be aware of the form of risk management adopted, and whether they follow RM1 or RM2 in their organizations. This is significant as it describes how different risk management arrangements may produce different risk identification outcomes. Risk management has commonly been presented as a “process” in the literature but less often discussed as a corporate philosophy that can influence other areas of business.
Based on the literature review, it was found that research on RM1 and RM2 is scarce and is limited to a few online discussions posted on some web forums and accordingly, this is the first structured study that discusses how risk identification outcomes may vary between RM1 and RM2.
1. Introduction
Today, organizations across all business sectors are exposed to countless risks that need to be managed carefully. Risk management is therefore key for survival in dynamic business environments. Arthur et al. (2025) found that in many small- and medium-sized enterprises (SMEs), the responsibility of conducting risk management still falls on owning managers, and the extent to which risk management principles are embedded depends on their own perception of vulnerabilities and attitudes toward risk taking. Accordingly, risk management activities are still intuitive, lacking formal and structured framing.
Recently, two distinct forms of risk management named Risk Management 1 (RM1) and Risk Management 2 (RM2) have been acknowledged in the literature. Risk identification is a part of the risk management process. It is a field of research that continues to evolve as long as new risks continue to emerge and new corporate/management practices continue to evolve. Risk identification has been selected as a subject of investigation in this research because it is the first and foremost step in the risk management process and which lays the foundation for the success of the whole process. Failure to identify risks properly leads to serious financial and/or non-financial ramifications.
This conceptual paper aims to (1) discuss how risk identification outcomes differ between RM1 and RM2 and (2) describe the potential consequences of these different outcomes on the organization at different management levels. More specifically, this research attempts to answer the question on how risk identification can produce more useful outcomes that can better serve the objectives of the organization in view of the risk management philosophy being adopted.
2. Literature review
2.1 Risk Management 1 vs Risk Management 2
Two distinct forms of risk management named Risk Management 1 (RM1) and Risk Management 2 (RM2) have recently been acknowledged in the literature. According to Sidorenko (2019a) and Risk-Academy (2018), RM1 is centered on satisfying external stakeholders, whereas RM2 focuses on decision making and decision support inside the organization. Therefore, RM1 and RM2 are fundamentally different.
RM1 and RM2 are not yet common/prevalent acronyms in the literature. The following sections of the literature review and discussion are based on extensive review of published research, as well as practitioner opinions, and reports and information produced by organizations outside of traditional academic publishing channels.
Scanning the literature shows that no structured research has yet been published – in academic journals specifically – that investigates the short-term and long-term implications of adopting RM1 or RM2 on the organization, except for Sidorenko (2019b). According to Ponder (2018), RM1 is “the form of risk management that most of us are familiar with”, in other words, this is the risk management approach many organizations still adopt today. Oreshile et al. (2025) and Vij (2019) referred indirectly to RM1 as “traditional risk management”. The aim of this approach is to build a risk management framework for the organization and to create a risk register that covers as much aspects of the business as possible. It also focuses on the regular updating of the risk reports and risk information, as well as the use of key risk indicators. RM2 however extends the scope of RM1 practices by drawing more attention on how the elements of the risk management framework are aligned and integrated with the existing policies and procedures. It takes into account how different management decisions may require different risk analysis techniques and different criteria for treating risks – an aspect that is less emphasized in traditional risk registers. RM2 also stresses the fact that decision makers need risk information not only updated but also put into context, next to performance information and reports, and that risk indicators need to be integrated with performance management cycle(s). More importantly, RM2 calls for a comprehensive understanding of the company's risk profile and risk universe for the purpose of supporting the decision-making process. Therefore, and according to RM2 advocates, RM2 is superior to RM1 and has an overarching influence that surpasses typical practices (Risk-Academy, 2024).
Due to the scarcity of the academic literature and published research on RM1 and RM2, the two concepts are not yet fully intelligible to a wide set of scholars and practitioners in the field of risk management. Therefore, it becomes critical to clarify more explicitly what is original about RM1 and RM2 in relation to research on enterprise risk management (ERM) and the ISO 31000 of Risk Management, which clearly steers the existing literature of risk management.
Oreshile et al. (2025) implicitly pointed to the concept of RM2 in their discussion on ERM; a concept that replaces the traditional “silo-based” risk management practices, which are often subject to individual and functional limitations/biases and other atypical intervening factors, with a purpose-driven and structured framework of risk management that aims to reduce information asymmetry and provide extensive data on the firm's risk profile. Based on a test sample of 112 US companies, the findings by Gordon et al. (2009) provided strong evidence on a positive correlation between ERM and firm performance (Mishra et al., 2019).
Having said that, there is no definitive evidence which confirms that ERM and RM2 are two identical concepts. RM2 is tailored more specifically toward achieving the goals of the organization by integrating/incorporating risk information and analysis directly into day-to-day business choices. Stated differently, ERM is the overarching discipline that aims to manage corporate-wide risks that affect the achievement of business objectives, whereas RM2 is a more specific, internally-focused risk methodology that is designed to guide and inform business decisions. Hussain (2026) made a crucial observation by stating that compliance-based approaches to ERM need to be revisited in order to transform the process into a dynamic strategic capability that enables far-sighted decisions which better underpin organizational resilience. Accordingly, the following theoretical proposition can be assumed:
Managerial recommendation 1: It is advised that organizations today combine RM2 with ERM rather than choosing between them.
Sidorenko (2019b) presented a number of practical steps to implement RM2. The author argued that these steps are likely to increase chances of success and facilitate the integration of risk management into decision-making, processes and culture of the organization. The author stated that: “implementing RM2 may not work so accurately every time, and some decision makers may still ignore risks no matter what we do, but following these steps won the best ERM implementation award”, stressing the fact that RM2 can be more easily implemented after following these steps as a guide for implementation.
The steps needed for implementing RM2 presented by Sidorenko (2019b) intersect with the ISO 31000 in some areas especially the “Principles”. Four “Principles” overlap between RM2 and the ISO 31000 namely Integration (Integrated), Dynamic, Best available information and the Human and cultural factors; meaning that risk management should be an integral part of all organizational activities and core processes, a dynamic process, a process that is based on the best available information, and a process that is aligned and compatible with the culture of the organization (i.e. takes into consideration that culture significantly influences all aspects of risk management at every level). The primary distinction between RM2 and the ISO 31000 however is that RM2 is a practical, internal decision-making methodology, whereas the ISO 31000 is a standard (universally accepted), principles-based framework for designing an overarching risk management “system” for the “entire” organization. Accordingly, the following theoretical proposition can also be assumed:
Managerial recommendation 2: It is advised that organizations today combine RM2 with the ISO 31000 rather than choosing between them.
The discussion above indicates that RM2 is value-adding, i.e. aims to create or add value to the organization, whereas RM1 aims to provide evidence on existing measures, procedures and risk reports for the satisfaction of external stakeholders primarily without necessarily demonstrating how these measures, procedures and documentation are integrated or incorporated into core business activities and practices; a perspective that is less likely to add/create value or serve the internal operations. Therefore, it can be argued that RM1 aims mainly to preserve/maintain existing value. This raises many questions about how practically RM1 can transform the strategic position of the organization into a more advanced future position that matches the dynamics of the business environment(s) (i.e. contributes to the achievement of the vision of the organization and its future objectives) and if RM1 aims to maintain a predefined level of risk appetite or risk-taking operations as long as external stakeholders are satisfied. Table 1 summarizes the key differences between RM1 and RM2.
RM1 vs RM2
| Risk Management 1 | Risk Management 2 |
|---|---|
| Most commonly adopted across various business sectors (until today) | Is still less widely intelligible and adopted. It has not yet gained mainstream popularity, general consensus or large-scale use |
| This is the “Traditional” form of Risk Management | Has all-embracing influence on the organization that transcends typical risk management practices |
| Aims at creating a detailed risk register for the organization | Draws more attention on how the elements and outcomes of the risk register are aligned and integrated with the existing policies, practices and procedures |
| Provides regular updating of risk reports and information | Stresses the fact that decision makers need risk information not only updated but also put into context, next to performance information and performance reports |
| Warrants the use of key risk indicators (KRIs) | Risk indicators need not only to be used but also to be integrated with performance management cycle(s) and matched with other key performance indicators (KPIs) |
| Provides evidence on existing measures and risk reports for the satisfaction of external stakeholders and auditors primarily | It considers how different management decisions may require different risk analysis techniques and different criteria for treating risks not only for the satisfaction of stakeholders, but mainly for supporting internal decision making |
| Preserves/maintains corporate value | Aims to create and add value to the business (i.e. value-creating and value-adding process) |
| Maintains a certain level of risk appetite or risk-taking operations, as long as external stakeholders are content or satisfied | Calls for comprehensive and deep understanding of the company's risk profile and risk universe, which profoundly reflects on the company's risk appetite |
| Compliance-driven approach | Decision-support approach |
| Procedural/systematic | Human-centered |
| Methodical | Fosters innovative thinking |
| Primary audience is external, including mainly: auditors, regulators, board and credit agencies | Primary audience is internal, including mainly: decision-makers, project managers and executives |
| Risk Management 1 | Risk Management 2 |
|---|---|
| Most commonly adopted across various business sectors (until today) | Is still less widely intelligible and adopted. It has not yet gained mainstream popularity, general consensus or large-scale use |
| This is the “Traditional” form of Risk Management | Has all-embracing influence on the organization that transcends typical risk management practices |
| Aims at creating a detailed risk register for the organization | Draws more attention on how the elements and outcomes of the risk register are aligned and integrated with the existing policies, practices and procedures |
| Provides regular updating of risk reports and information | Stresses the fact that decision makers need risk information not only updated but also put into context, next to performance information and performance reports |
| Warrants the use of key risk indicators (KRIs) | Risk indicators need not only to be used but also to be integrated with performance management cycle(s) and matched with other key performance indicators (KPIs) |
| Provides evidence on existing measures and risk reports for the satisfaction of external stakeholders and auditors primarily | It considers how different management decisions may require different risk analysis techniques and different criteria for treating risks not only for the satisfaction of stakeholders, but mainly for supporting internal decision making |
| Preserves/maintains corporate value | Aims to create and add value to the business (i.e. value-creating and value-adding process) |
| Maintains a certain level of risk appetite or risk-taking operations, as long as external stakeholders are content or satisfied | Calls for comprehensive and deep understanding of the company's risk profile and risk universe, which profoundly reflects on the company's risk appetite |
| Compliance-driven approach | Decision-support approach |
| Procedural/systematic | Human-centered |
| Methodical | Fosters innovative thinking |
| Primary audience is external, including mainly: auditors, regulators, board and credit agencies | Primary audience is internal, including mainly: decision-makers, project managers and executives |
In addition, Table 2 clarifies areas of convergence, divergence and overlap between RM1 and RM2, and traditional risk management, ERM and the ISO 31000.
Areas of convergence, divergence and overlap between RM1 and RM2, and traditional risk management, ERM and the ISO31000
| Traditional risk management | ERM | ISO31000 | |
|---|---|---|---|
| RM1 | High convergence | Diverge in purpose and consequently a wide set of practices | Diverge – mainly in structure and methodology |
| RM2 | Diverge in purpose and consequently a wide set of practices | High convergence | Overlap in scope and a number of “Principles” |
| Traditional risk management | ERM | ISO31000 | |
|---|---|---|---|
| RM1 | High convergence | Diverge in purpose and consequently a wide set of practices | Diverge – mainly in structure and methodology |
| RM2 | Diverge in purpose and consequently a wide set of practices | High convergence | Overlap in scope and a number of “Principles” |
2.2 Risk identification
The term “risk” has been defined in several ways in the literature. For the purpose of this research, it is defined as “the effect of uncertainty on organizational objectives” (ISO 31000:2018). Organizations need to identify risks in order to lessen their impacts and/or probability of occurrence. Risk identification is the first step in the risk management process and which determines the success of all subsequent stages (Kountur and Sari, 2023; Kmec, 2011; Tchankova, 2002). George (2020) noted that managers sometimes do not spend enough time identifying risks, rather they dedicate more time introducing extra risk mitigation measures unaware that unidentified risks cannot be mitigated.
At an operational level, effective risk identification protects the organization from the adverse consequences of business disruptions associated with daily operations. At a department level, accurate risk identification enables business-unit-level managers to develop the most appropriate strategies for response and mitigation for their business areas (Shahsavari et al., 2024). Successful risk identification also contributes positively to top management by reducing the effects of uncertainty on the strategic and future goals of the organization.
Risk identification is fundamental for all types and sizes of organizations (Letens et al., 2008). Even SMEs and new start-ups need to invest in risk identification despite their limited resources. These companies need risk identification especially at the early stages of their lifecycles and prior to launching their new products or services in order to safely manage to grow and maintain their customers on the long run. They also need to identify potential risks early enough in order to avoid unexpected market conditions (Riepl et al., 2024). In this context, Glowka et al. (2024) added that risk identification is tightly linked to risk perception, a concept necessary for understanding risk-taking behavior and managing uncertainty. They argued that over the past three decades, the complexity and uncertainty in business environments have been increasing, prompting a deeper exploration into risk-taking behaviors.
Risk identification should be consistent and relevant to the organization. According to Williams (2017), taking a haphazard approach to risk identification by including irrelevant risks will have unwanted consequences. An adequate understanding of the organization and its business environment in this regards should guarantee a more relevant risk identification process tailored specifically to the needs of the organization (ISO 31000:2018; Lundqvist, 2014; Tchankova, 2002). Risk identification should therefore be an ongoing process especially within those business sectors which are characterized by high speed of operations and super connectedness, such as the logistics, supply chain and distribution management (Shahsavari et al., 2024).
In order to perform risk identification comprehensively, input from all business units is recommended due to the fact that these units are fully aware of their own business threats and challenges. Engaging a wider set of external stakeholders in risk identification also provides broader perspective and better insight, and unveils risks that might not be clear to detect at early stages. It will also ensure that no significant risk goes unnoticed. Accordingly, Kountur and Sari (2023) proposed a business process approach to risk identification where risks are identified unit by unit starting from the lowest level of management until all business units/areas are covered. Nonetheless, Morales (2024) argued that risk identification should not necessarily be complex.
3. Methodology
This is a conceptual paper. In this paper, the researcher conducted an extensive literature review in order to investigate a core question that is: “how can risk identification produce useful outcomes that better serve the goal of the organization in view of the risk management philosophy being adopted?” Overall, the research approach is based on careful review and selection of relevant literature underpinned by theoretical and practical reasoning.
RM1 and RM2 are not yet common/prevalent acronyms in the literature. Despite the scarcity of structured scholarly research on RM1 and RM2, the researcher attempted to make use of almost all published material including commentaries, blogs, webinars, online discussion platforms and forums, and senior executives' opinions, as well as research relating to the field of risk management in general published between the period (2019–2026) in order to capture a full understanding of the differences between RM1 and RM2 and how they affect risk identification outcomes. These resources were used for theory-building purposes. Accordingly, key consequences on the organization, as well as a range of theoretical and practical implications have been identified and discussed which contribute positively to the existing research in the field of risk management. Figure 1 shows the steps of the research methodology that were considered in this paper.
The flowchart begins with Step 1, which involves scanning the existing literature for structured research relating to RM1 and RM2. No structured research was found, except for Sidorenko, A. (2019b). Step 2 involves scanning online resources and grey literature relating to RM1 and RM2. Step 3 uses the CRAAP framework to assess the quality of all non-academic sources of information selected. Step 4 scans the extant academic literature relating to the field of Enterprise Risk Management in general. Step 5 develops the literature review based on the information obtained in the previous steps and published research relating to the field of Risk Management. Step 6 supports the literature review with theoretical and practical reasoning and insights from practitioners in the field.Research methodology. Source: Author's own work
The flowchart begins with Step 1, which involves scanning the existing literature for structured research relating to RM1 and RM2. No structured research was found, except for Sidorenko, A. (2019b). Step 2 involves scanning online resources and grey literature relating to RM1 and RM2. Step 3 uses the CRAAP framework to assess the quality of all non-academic sources of information selected. Step 4 scans the extant academic literature relating to the field of Enterprise Risk Management in general. Step 5 develops the literature review based on the information obtained in the previous steps and published research relating to the field of Risk Management. Step 6 supports the literature review with theoretical and practical reasoning and insights from practitioners in the field.Research methodology. Source: Author's own work
A pre-determined standard for deciding which academic sources will be included in this research was carefully considered based mainly on recency, inclusion and exclusion criteria, and source credibility and indexing. Accordingly, the academic sources/references that have been used to build the theoretical foundation of this research were obtained from major journal databases/ publishing platforms, including Emerald and Taylor and Francis primarily. The research focused on the most up-to-date journal articles available in the existing literature in order to capture a clear and recent view of risk management practices adopted in organizations from different sectors for the purpose of providing conceptual basis for future practices that can serve various sectors. Research focusing primarily on modern enterprise risk management was therefore considered. Earlier research focusing on ad hoc risk management practices, individual mechanisms and responses, risk generated by atypical human behavior or corporate practices, or context-specific risk management criteria was therefore excluded. The researcher carefully selected the keywords during the process of searching for the relevant material/references. Keywords included risk identification, enterprise risk management, risk-informed decision making and ISO 31000. This careful selection enabled the researcher to draw the implications and conclusions based on valid academic discourse instead of assuming these implications and conclusions subjectively. Non-academic resources were assessed using the CRAAP test framework. This technique helps to check for currency, relevance, authority, accuracy and purpose of the sources of information and published material in order to provide reliable selection experience and criteria.
4. Rationale and discussion
According to Sanchez-Cazorla et al. (2016), risk identification outcomes act as a guide for steering the organization toward a safer trajectory during the different stages of its lifecycle. The outcomes of risk identification serve as inventory of all potential risks associated with the organization's activities and business operations (Aouati et al., 2017). This inventory has to remain up-to-date as long as the organization evolves. Risk identification outcomes are therefore of supreme significance not only because they uncover business exposures to potential hazards but also because they act as input to the following stages of the risk management process, including risk assessment, analysis and treatment. Gao et al. (2024) argued that different factors can affect the nature of the outcomes of the risk identification process and cause unintended bias toward irrelevant areas or issues of lower concern to the organization. For instance, the outcomes of risk identification may be significantly influenced by individual or personal views or perceptions, especially from those who have long expertise in risk management, and since expertise is typically stored in the mind/memory of people- rather than being physically stored in a corporate database – it can be lost when those employees leave or retire.
Risk identification should not therefore be considered a stand-alone process or conducted in isolation from the overall context of the organization. Hassall and Lant (2023) argued that understanding the basis of sociotechnical risk management is necessary for risk identification. Stated differently, the nature of risk management adopted within the organization and risk identification are closely correlated. Sweeting (2017) also argued that risk identification should be performed as part of a well-defined larger risk management framework. Therefore, the choice between RM1 and RM2 is expected to make a substantial difference. In this context, it should be noted that any organization has the freedom/right to choose any form of risk management that matches its line of business and operations.
Bearing the aforementioned discussion in mind, if an organization adopts RM1, then risk identification outcomes are expected to be in line with this form of risk management, i.e. driven toward satisfying external stakeholders; meaning that it is highly likely these outcomes will be shaped according to RM1 arrangements and scope. Accordingly, it becomes necessary to understand what external stakeholders expect from the business and to address their concerns. External stakeholders are entities outside the firm who have various interests in the corporation. They are affected by the operations of the organization and benefit when it prospers or are subject to loss when it declines or fails to achieve its business objectives (Awa et al., 2024). External stakeholders typically share a bundle of concerns relating primarily to the financial performance of the company and its success in the marketplace. Risk identification outcomes under RM1 typically highlights these concerns with little/no freedom to express broader corporate issues outside this confined domain.
On the other hand, if an organization adopts RM2, then risk identification outcomes are also expected to be in line with this form of risk management, i.e. focus on efficiency of decision making and decision support systems; meaning that it is highly likely these outcomes will be shaped according to RM2 arrangements and scope. Ting et al. (2009) mentioned that risk management should be considered as a decision-making process. For instance, a company may choose to leverage its analytics and modeling techniques in order to provide a more detailed picture about its risk profile thus enabling senior management to make more effective and prudent decisions. Subsequently, the outcomes of the risk identification process under RM2 are expected to establish what has been described in the literature as “risk-informed” decision making, a process that better serves today's organizations which operate in highly dynamic and unpredictable business environments (Vasconcelos et al., 2023; Thieme et al., 2021; Birkmann et al., 2020; Ersdal and Aven, 2008). Risk-informed decision making uses risk identification outcomes in conjunction with other risk information to lead to more complete, transparent and informed decisions at all levels within the organization. Overall, it can be argued, with more confidence, that risk identification outcomes under RM2 have the potential to openly address a wider range of business issues which can bring additional benefits to the organization.
In view of that, the outcomes of risk identification under RM1 vs RM2 are also expected to be different in terms of objectivity and transparency. Objectivity in this context is a measure of the level to which these outcomes may be influenced by predefined/predetermined factor(s), and transparency is a measure of how open and honest the organization is in disclosing correct data to the concerned parties (also known as risk reporting) (Malafronte and Pereira, 2021). Under RM1, transparency and objectivity levels are expected to be lower when compared to RM2. Under RM1, satisfying external stakeholders is considered a predefined/predetermined factor and therefore risk identification outcomes will be confined to this domain primarily. As a result, levels of transparency are expected to decline too due to the fact that risk identification does not act as a proactive process that identifies newly evolving and emerging risks broadly and openly, which in turn reduces the amount of accurate data that should be disclosed to stakeholders. As indicated by the ISO 31000:2018, this approach to risk identification is insufficient as the organization needs to identify risks whether their sources are under its control or not.
Based on the discussion above, a number of key implications on the organization can be anticipated as a result of adopting RM1 or RM2. The following section discusses these implications in more detail. In principle, these implications are expected to apply to all organizations, yet the extent to which these implications are influential may vary between different organizations and sectors. It should be noted that the implications presented next stem logically from the above rationale/reasoning specifically for those organizations which are in favor of carrying out a transformation process from RM1 to RM2. It should also be noted that the implications discussed below do not provide an exhaustive list of what there is, rather, section 5 aims to discuss the most expected or noticeable implications.
5. Consequences on the organization/implications
5.1 Pure and speculative risk identification
First, under RM2, risk identification aims to identify the range of pure risks an organization is exposed to, as well as the factors that can be exploited in order to improve the position of the organization in its market place and the industry (also known as speculative risks). This has been highlighted by the Australian Department of Finance which stated that: “the aim of risk identification is to develop a comprehensive and tailored list of future events which could be uncertain, but are likely to have an impact (either positively or negatively) on the achievement of the objectives- these are the risks” (Comcover's series of Risk Management Sheets, 2016). According to Rejda and McNamara (2021), speculative risk is uncertainty about an event that could produce either a profit or a loss, such as a business venture or a gambling transaction. Powers (2006) also described speculative risks as those expected to unfold negative or positive outcomes. Downey (2022) further explains by stating that because almost all projects or investments involve some degree of speculative risk, and because the organization may sometimes have no clear idea whether the investment will succeed or not, it has to identify both, pure and speculative risks. Speculative risks are therefore taken into consideration by the organization not as a result of random selection or uncontrollable circumstances but as a conscious decision. This can be considered value-adding as it helps the organization better develop its strategic foresight both on the short term and on the long run. Under RM1 however, risk identification seeks to identify pure risks primarily and the range of events that may bring negative consequences paying less attention to the value that can be obtained from identifying speculative risk.
5.2 Methods of risk identification
Second, as the organization's operations progress over time, new risks are likely to emerge and these may have composite or unfamiliar nature. This is referred to as “risk evolution” (Zhou et al., 2025). As a result of the evolving nature of risk, a multimethod approach to risk identification may prove to be more effective and compatible. According to Sweeting (2017) and Dinu (2015), there are several quantitative and qualitative risk identification techniques, and under certain circumstances, where risk has a dynamic or complex nature, a combination of these techniques can be used. Shahsavari et al. (2024) and Fan and Stevenson (2018) stated that risk identification can also be performed in collaboration with business partners in case multiple firms work closely together or when they form business partnerships over extended supply chains. Under RM2, all risk identification techniques can be considered, quantitative and qualitative, as long as this serves and supports the decision-making process. This was emphasized by Ponder (2018) who stated that under RM2 settings, a wider range of risk identification techniques can be applied and links between these different methods can also be established in order to provide more accurate, reliable and comprehensive outcomes that feed the decision-making process. On the other hand, RM1 relies heavily on quantitative methods and ratios for risk identification that cover primarily the financial aspect of the organization as external stakeholders typically find it easier to interpret. This sometimes proves to be inadequate especially when identifying non-financial risks and is likely to produce redundant quantitative and numerical results.
5.3 Organizational resilience
Third, it follows logically from the above discussion that levels of organizational resilience are likely to vary according to the range of risk identification techniques being used. Resilient organizations are those able to undertake and maintain positive changes under challenging conditions. They are capable of “bouncing back” following major incidents, restore their normal operations swiftly and maintain a desirable level of functioning (Sawalha, 2015). Higher levels of resilience rely on the capacity of the organization to identify risks comprehensively (Ampratwum et al., 2024). The fact that RM2 fosters the use of a wider set of risk identification techniques results in improved levels of organizational resilience. Indeed, George (2020) argued that some risks may have obvious causes and therefore can be easily identified, whereas other risks may require more detailed rounds of investigation using a variety of methods to identify. In this context, Ravulakollu et al. (2018) have introduced what they referred to as “Risk-based Resilience Assessment” (RBRA) by which they could estimate levels of resilience more accurately based on data obtained from risk identification. More broadly, in the socio-ecological context, the concept of resilience has been addressed both as a system's ability to quickly return to its pre-shock equilibrium and as a system's capacity to absorb disturbances and make the necessary adjustments while maintaining its core functions – potentially considering a new equilibrium status. Resilience is also central to fostering innovation and adaptation, particularly in response to the rapid digital transformation and global technological advancements (Capoani et al., 2025). Paeffgen et al. (2024) also argued that organizational resilience should be assessed differently using different attributes or features depending on the context of the organization, which can only be more effectively achieved under RM2 arrangements/settings.
5.4 Corporate culture and strategy settings
Fourth, RM2 promotes a safety culture across the organization where almost everyone has a role to play in the risk management process including risk identification. RM2 is as much about embracing a safety culture as it is about process. Vredenburgh (2002) defined safety culture as developing a norm through which employees become extra vigilant of the risks in their workplace and the surrounding environments. Connecting risk management and culture helps to build a risk management program that can be better aligned not only with daily operations but also with strategy at corporate and business-unit levels (Grima et al., 2025). Indeed, this unified risk, culture and strategy approach has a greater influence and value to offer to the organization than traditional risk management frameworks often offered by RM1. For instance, Hassall and Lant (2023) argued that risk identification is key to sustainable competitive advantage which lies at the heart of the strategic aspect of the organization. Also in their study conducted in the Kumasi Metropolis in Ghana, Arthur et al. (2025) concluded that risk management is a vital component of strategic management, especially for SMEs. Under RM1 however, risk identification outcomes tend to have greater external focus drawing less attention to the internal benefits that can be obtained. Nowadays, it is becoming more evident that failing to explicitly account for risk when formulating corporate strategies is a shortfall, weakness and incompetence. A safety culture enables the organization to prepare for “unknown unknowns”; a type of risk that is less predictable and which sometimes poses existential threats to the organization (Young, 2022).
5.5 Vulnerability assessment
Fifth, under RM2, business vulnerabilities are being identified too as part of the risk identification process; those weaknesses in business operations which are likely to render the organization susceptible to crises or failures in case they are mismanaged or neglected (e.g. loose points, weak linkages, incompatible system components, inconsistencies in procedures, network vulnerabilities or weak access points). Organizational vulnerability can be viewed as the opposite side of resilience. These vulnerabilities could be rooted in the human or the technical aspects of the organization (i.e. factors that exist or are inherent within the organization). Chipangura et al. (2024) further explained that these vulnerabilities are usually generated through the accumulation or convergence of unmanaged or mismanaged processes. Vulnerabilities are different from risks, yet they have the potential to negatively affect the achievement of the goals of the organization as much as risks do. This in-depth understanding of organizational vulnerabilities could be partially or often totally overlooked under RM1. Vulnerability assessment does not only help organizations fix these weak points but also transform vulnerabilities into capacities; an approach that aims to improve the strategic position of the organization in the future, both internally and in the industry.
5.6 The business environment
Sixth, as today's organizations operate in highly dynamic business environments, also described in the literature as volatile, uncertain, complex and ambiguous (VUCA business environments), there is an increasing need for taking prompt and immediate decisions, on a daily basis, relating to almost all aspects of business operations and transactions. Accordingly, conducting risk identification for the purpose of satisfying external stakeholders only is certainly lacking. Factors, such as wars and social unrest, political conflicts and trade sanctions adversely affect global business environments too which also pose many threats and challenges. In this context, Kristóf and Virág (2025) added that implicit risk factors during times of uncertainty and crises differ from those factors identified in previous research conducted in stable external business environments. These conditions urge senior executives to expand their risk identification scope beyond the conventional boundaries aiming at underpinning the decision-making process. One of the core attributes of RM2 is that it fosters the continuous alignment between the risk identification outcomes and decision-making not only during times of comfort and stability but also during times of crises when risk factors are manifold.
5.7 Management levels involved/under consideration
Another expected consequence of adopting RM1 on risk identification is that risk owners are likely to focus primarily on the operational and middle management risks, whereas risk owners under RM2 work more closely and openly with senior management as long as decision-making is involved. However, the fact that all management levels within the organization are inseparable fosters the adoption of RM2. Accordingly, those organizations which have a long established RM1 culture could be advised to reconsider their approach to risk management in order to encompass a wider range of risks that have the potential to affect the achievement of the strategic goals and future projections.
Table 3 distinguishes between conceptually plausible implications, propositions yet to be tested and implications that are supported by the literature. Table 3 underpins the reliability of the abovementioned implications in terms of their nature and provides clear guidance for future extended research in the field.
Comparison between conceptually plausible implications, propositions yet to be tested and implications that are supported by the literature
| Conceptually plausible implications | Implications yet to be tested | Implications supported by the literature |
|---|---|---|
| 5.1 Inclusion of pure and speculative risk identification | 5.3 Levels of organizational resilience | 5.2 Methods of risk identification used |
| 5.6 Alignment with the business environment | 5.4 Compatibility with the corporate culture and strategy settings | 5.5 Inclusion of vulnerability assessments |
| 5.7 Management levels involved/under consideration |
| Conceptually plausible implications | Implications yet to be tested | Implications supported by the literature |
|---|---|---|
| 5.1 Inclusion of pure and speculative risk identification | 5.3 Levels of organizational resilience | 5.2 Methods of risk identification used |
| 5.6 Alignment with the business environment | 5.4 Compatibility with the corporate culture and strategy settings | 5.5 Inclusion of vulnerability assessments |
The possibility of combining/merging different RM1 and RM2 practices in varying percentages | 5.7 Management levels involved/under consideration |
6. Conclusion
RM1 and RM2 are two distinct risk management philosophies. Each has its own characteristics and scope and thus implications on the organization. Organizations are free to choose the form of risk management they prefer and the more suitable for their corporate settings, nevertheless, in order to be more practically aligned with today's dynamic global business environment(s) and build the foundations for sustainable resilience, the choice between the two should be judicious as it will certainly protect the organization from unnecessary setbacks and guide its future toward better chances of survival. Taking into consideration that RM2 reflects the most up-to-date evolution of risk thinking (Sidorenko, 2019b), RM2 is likely to match the needs and requirements of today's global business environments more effectively.
People working in more stable business environments on the other hand often seek steady performance, avoid market volatility, are less concerned about the changes taking place in their external business environments and tend to have a risk-averse attitude. Those people are likely to handle stress more effectively because of the predictable nature of their workplace which normally minimizes surprises. They are also process-driven and rely on proven methodologies over experimenting with unproven strategies. In such cases, and under such circumstances, RM1 could still be a valid and feasible choice rather than delving into new or more demanding risk management philosophies.
Since the findings of this research (implications on organizations) are analytical (i.e. logically and theoretically derived), it should be noted that the conclusions of this paper represent/provide conceptual insights rather than providing definitive results/arguments.
Risk management is a value-adding process. The absence of the risk component renders a corporate strategy less capable of handling future challenges which compromises the overall safety and security profile of the organization. The choice of the corporate approach to risk management is therefore of paramount significance. According to some recent studies, strategy and risk management should be viewed from an integrated perspective.
RM1 and RM2 are not yet prevalent/common acronyms in the extant literature. More research is highly and promptly recommended to investigate the impacts of adopting RM1 vs RM2 on the organization and its business operations at all management levels. RM1 and RM2 are fundamentally different and moving from RM1 to RM2 requires significant changes to be made within the organization. RM2 aims at establishing a risk-based or risk-informed decision-making system capable of supporting many aspects of the organization, while RM1's primary focus is to satisfy and meet the expectations of external stakeholders by providing documented evidence on existing risk procedures and protocols which is appealing to external auditors too who are also considered part of the larger network of external stakeholders. It is equally important to note that an organization may change its risk management scheme/philosophy throughout its lifetime according to what better meets its interests or supports the achievement of its objectives. The choice between RM1 and RM2 will not impact the risk management department only but also will affect other areas of business.
In many cases, managers do not spend enough time identifying risks, rather they dedicate more time introducing extra risk mitigation measures unaware that unidentified risks cannot be mitigated. Risk identification is an area that is significantly influenced by the choice between RM1 and RM2 and therefore the outcomes of risk identification are expected to vary accordingly. Risk identification sheds light on the factors surrounding an organization which determines the future projection of the organization based on the changing or evolving nature of these factors at micro- and macro-levels. Therefore, and according to the form of risk management adopted within an organization, risk identification can be as narrow as identifying typical short-term/daily business interruptions or as broad as addressing the whole range of threats and challenges affecting the organization and the achievement of its business objectives. Risk identification can also be as simple as using one method to identify risks or as intricate as using a combination of multiple qualitative and/or quantitative methods. However, advanced decision-making requires using a variety of risk identification techniques.
Further potential consequences have been discussed in this research pertaining to risk identification outcomes under RM1 and RM2. These relate mainly to speculative risk, risk identification techniques used by an organization, levels of organizational resilience, safety culture, vulnerability identification and decision making.
It should also be stressed that our choice of the form of risk management requires a change in traditional patterns of thinking and management practices. Risk management is not a complementary or optional process, rather it is fundamental to the organization. A final remark that is worthy to mention in this regard is that some views propose that a combination of RM1 and RM2 practices is also feasible and can be adopted at varying percentages in an attempt to gain the benefits of both (Sidorenko, 2019a; Risk-Academy, 2018). For instance, an organization may decide to adopt 60% RM1 and 40% RM2 or the opposite. One way of approaching this perspective is by aligning/blending those activities/practices from RM1 and RM2 that have common purposes or common expected outcomes on the organization, for instance, both RM1 and RM2 are supposed to provide basis for organizational protection and long term survival in dynamic business environments. Core values that aim at achieving this can be combined. Also, it can be argued that since both, RM1 and RM2, aim at collecting relevant data about the range/types of risks facing the organization, a unified repository that combines input from both processes (in different percentages) can be implemented for the aim of improving the organization's awareness of potential risk factors. Yet, this approach still requires thorough and methodical investigation to validate its practicality and whether it can equally be applied across organizations from different sectors and business areas consistently. Future research should also focus on describing other potential consequences resulting from adopting RM1 and RM2 on other specific areas of business and management practices.
