Roger Estall and I presented the Universal Decision-Making Method at RAW2020, drawing on our shared investigation, across decades, of decisions that produced poor outcomes or went significantly wrong.

Risk management myths are recurring misconceptions that mistake administrative tools for the thinking needed to make sound choices.

What RAW2020 revealed about failed decisions

What we found, consistently, was not that the wrong option had been chosen. It was that assumptions had gone unnamed and unmonitored. The person who made the call had relied on things being true without writing down what those things were. When one of them turned out to be false, the decision failed, and nobody could explain why, because nobody had recorded what it was resting on.

We examined decisions across mining, finance, aviation, and public health. The pattern did not vary by industry, by scale, or by the seniority of the people involved. A board approving a billion-dollar acquisition and a site manager approving a shift roster were making the same structural error: proceeding on premises they had never articulated. The acquisition failed because the board assumed regulatory approval in a foreign jurisdiction would follow the same timeline as domestic approval. The shift roster produced a fatigue-related incident because the manager assumed experienced workers would self-manage rest periods. Neither premise was written down. Neither was monitored. Both broke.

The method every Decider already uses

The Universal Decision-Making Method is not a new invention. It is a description of what everyone who decides already does, whether they are aware of it or not. A pilot deciding whether to divert. A board deciding whether to acquire. A family deciding whether to move. The steps are the same: state the purpose, name the opportunity, surface the assumptions, decide what level of certainty is sufficient, build monitoring into the decision before it leaves your desk.

The difference between those who decide well and those who do not is not intelligence, experience, or access to information. It is awareness and skill in applying the method. Those who decide poorly apply it without realising; those who decide well apply it on purpose. Roger Estall and I set out this distinction in Deciding, drawing on five decades of advisory work across industries and jurisdictions. My three-part conversation with Mark Siwik traces that career from the Flixborough explosion through the ISO working groups to the method itself.

Consider Captain Chesley Sullenberger, who landed US Airways Flight 1549 on the Hudson River in 208 seconds. He did not have all the facts. He could not know whether the engines could be restarted or whether he could reach an airport. What he did was apply the method at speed: identify the purpose (save the passengers), generate tentative options, test each against what he was taking as given, judge which gave him sufficient certainty of the desired outcome, and act. Proficient Deciders do not use a different method from everyone else. They use the same method with greater awareness and speed.

Why “risk management” myths persist

If the method is universal and intuitive, why has an entire industry grown up around the word “risk” rather than around better decisions? The answer is economic. Four groups sustain the belief system, each with strong self-interest. Insurers need to price premiums. Regulators need to demonstrate oversight. Academics need to publish. Consultants need to bill. Each group has legitimate reasons to study uncertainty. Not one of these groups sits beside a Decider who needs to commit to a course of action by Friday.

The result is an apparatus of registers, matrices, frameworks, and acronyms that sits beside the organisation's actual decisions without entering them. ISO 31000, COSO ERM, the IIA Three Lines Model: each proposes a structure. None asks the question that matters: what are you assuming, and how confident are you that it will hold?

Enron had Arthur Andersen praising its enterprise risk management. Boeing's 737 MAX program operated within a full framework of the same kind. Australia's Royal Commission into banking misconduct found that every major bank had risk committees, chief risk officers, and thorough reporting. The apparatus was fully assembled in each case. It was fully useless when it mattered most. Roger and I documented these failures not to score points against the profession but because they demonstrate a structural truth: cataloguing things that might go wrong is not the same as deciding what to do.

Why risk management is the wrong path

The word “risk” itself is part of the problem. Those responsible for decisions deserve a sharper instrument than a word nobody can define. It possesses dozens of formal definitions and no consistent meaning. The first ISO risk management standard contained 29 labels that relate to either ordinary words given a special meaning or to contrived expressions involving the word “risk.” Even the label “risk” is so ill-defined as to require five accompanying notes to its own definition, each of which either contradict or confuse. When the core term of a discipline cannot be defined, the discipline is not a discipline. It is a label in search of a subject.

The myths that sustain this apparatus are remarkably durable. That risk can be quantified on a five-by-five matrix. That a register reviewed quarterly constitutes governance. That a Chief Risk Officer position demonstrates organisational commitment to sound decisions. That compliance with a standard equals competence. Each myth persists because it serves someone's interest, and each compounds the decision fatigue already weighing on the people who actually decide, pulling their attention from the work that matters: stating what they are trying to achieve, naming what they are taking as given, and watching whether it holds.

The alternative

Help people apply the method they are already using, but apply it with awareness and skill.

An organisation that wants to improve its decisions does not need another framework or acronym. It needs its Deciders to do three things consistently. First, state the purpose of the decision and connect it to the broader purpose the organisation serves. Second, name what the decision rests on and sort each item by how much it matters and how confident they are it will hold. Third, build monitoring into the decision before it is finalised: specify what to watch, who watches it, and what triggers a revision.

No register. No heat map. No Three Lines Model. No annual risk appetite statement. Just the method, applied with the awareness and skill it deserves. Organisations that do this consistently will make better decisions than those burdened by the full apparatus of risk management mythology. The evidence of nearly fifty years supports that claim without qualification.

You could keep the risk management myth and never name what your next decision rests on.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.