Edition 1 · Published 16 September 2026
Global Risk Culture Standard
The open standard that turns risk management into culture, across organisations, supply chains and the machines now inside the decision.
Measure what your organisation does, not what it says
Most risk culture assessments measure how an organisation would like to think. GRCS measures how it actually behaves. How long warning takes to travel, whether a decision has a named owner, whether an override was correct, whether a supplier disclosed early, and whether anything changed after the last failure.
It is assessed on evidence, not opinion. Every level of every pillar names the artefact or observed behaviour that demonstrates it. If a level cannot be evidenced, it cannot be claimed.
Why “Global”
Risk no longer stays inside the organisation that creates it. It travels through suppliers, platforms, logistics partners and data services, and it travels faster than it is absorbed. An organisation can have a genuinely mature internal risk culture and still be wholly exposed through the culture of others. GRCS assesses your organisation, including your capability in relation to your suppliers and your machines. It does not assess or certify them.
Why now
Artificial intelligence has moved from changing how work is done to changing who, or what, is deciding. The characteristic failure is not model error. It is unchallenged reliance on a plausible machine output that nobody in the room fully understood. At the same time, risk culture has become an examinable regulatory object in multiple jurisdictions, and boards are now being asked to evidence cultural claims they previously only asserted.
Where GRCS fits
GRCS sits alongside ISO 31000, COSO ERM and quantitative models such as FAIR, not in place of them. Those frameworks handle quantification, control effectiveness and capital allocation. GRCS addresses the human and organisational layer that decides whether any of that apparatus works in practice.
Contracts secure compensation after a disruption. Culture determines whether you get the phone call three weeks before it.
Boards and governing bodies
Risk, assurance and compliance leaders
Executives and operational leaders
HR, people and organisational development professionals
Seven pillars score capability. Three decide whether it can be trusted.
GRCS keeps the ten-pillar design and five-level maturity ladder of its predecessor, but restructures what the pillars do. Seven core pillars are scored from Level 1 (Ad Hoc) to Level 5 (Sustainably High-Performing). Three conditioning pillars are rated Strong, Adequate or Weak and applied as a discount on the whole result, because ethics, transparency and sustained capability determine whether the other seven readings can be believed.
Core Pillars
Leadership, Governance and Decision Authority
Where authority actually sits, so accountability can be located before it matters.
Risk Intelligence and Early Detection
Reading changing conditions early enough for the reading to be useful.
Decision Quality and Evidence Use
Setting the standard of evidence a decision must meet, and holding it under pressure.
Risk Appetite Translation and Enforcement.
Turning appetite from a statement into a constraint that can decline a decision.
Human–Machine Decision Integrity
Keeping accountability, verification and competence intact as decisions are delegated to machines.
Extended Enterprise and Supply Chain Culture
Whether your own conduct invites or suppresses warning from the network you depend on.
Adaptive Elasticity and Presilience®
The capacity to operate degraded, adapt at the edge, and emerge better positioned.
Conditioning pillars
Ethics, Incentives and Legitimacy
Whether concealment is the rational individual choice.
Transparency, Escalation and Psychological Safety
Whether information travels intact. A Weak rating here caps the reported score.
Capability, Learning and Change
Sustaining the whole system and closing the loop from outcome back to practice.
Score well everywhere else but fail on transparency, and GRCS tells you the truth: nothing else in your profile can be trusted. That’s not a harsher assessment. It’s an honest one.
How to use the standard
Four documents. One assessment method.
GRCS is an open standard, free to download, use, adapt and cite with attribution. Edition 1 is published as a suite:
The Standard. The full benchmarks for all ten pillars, with Characteristics, Consequences and Evidence at every level, the scoring method, governance intent and regulatory alignment, and the assessment methodology.
User Guide. How to run an assessment in seven steps, in the order you’ll actually need them: who does what, the evidence pack, choosing your assessment mode, and the five mistakes that defeat an assessment.
Representing Maturity. How an assessment becomes a number, what that number can and cannot carry, and how to present it to a board without misleading anyone.
Transition Checklist. Every change from ORCS v8 to GRCS Edition 1, what it means, and what to do if you hold an ORCS baseline.
The assessment in brief
Record the board’s statement of governance intent. Declare the assessment mode: self, facilitated or independent. Assemble evidence against each pillar. Run the five behavioural and documentary instruments, starting with warning-time reconstruction. Rate each pillar, apply the structural rules, and report all four figures with the evidence relied on. Then decide what you’ll do differently, which is the only reason to have done any of it.
Already using ORCS?
From ORCS to GRCS
GRCS Edition 1 supersedes the Organisational Risk Culture Standard, versions 1 to 8. It is a re-architecture, not a renaming. The ten-pillar design, the five-level ladder and the paired characteristics-and-consequences format carry forward. What changes is how the pillars are structured, what counts as evidence, and how the result is calculated.
The most important changes: an Evidence column now applies to every level of every pillar; ethics and transparency become conditioning pillars that gate the score; Extended Enterprise and Supply Chain Culture is new; Human–Machine Decision Integrity has been substantially rewritten; framework alignment moves out of the pillar set; and survey-based assessment is replaced by five behavioural and documentary instruments.
If you hold an ORCS v8 baseline, don’t compare results directly. Use the concordance in Annex A of the Standard and the Transition Checklist, and state which movements reflect changed performance and which reflect changed architecture. A different number after transition usually reflects a more honest measurement, not a worse culture.
Supporting Organisations
The following organisations endorse and support the Global Risk Culture Standard, Edition 1:
Peer review panel — GRCS Edition 1, Round 1
With thanks to the reviewers who provided independent, critical review of Edition 1 during Round 1 (August to September 2026).
Lineage: ORCS v8 endorsement and peer review
The organisations and reviewers below endorsed and reviewed ORCS version 8 (2025), the predecessor to this Edition. They are acknowledged here for provenance; this should not be read as endorsement of GRCS Edition 1 or of any change introduced in it.
Peer review panel — ORCS v8
What reviewers said about ORCS v8
These testimonials were given for ORCS version 8, the predecessor Standard, and are shown for lineage.
Dr. Jennifer L. Schneider, CIH
Todd Tucker
Chief Randy R. Bruegman
Jessica Minion
Our Risk Culture Experts
The Global Risk Culture Standard, Edition 1, is authored by Dr Gavriel Schneider, with Dr Paul Johnston, Christopher Stitt and Jack Jones as supporting authors, reflecting their contribution to the Edition 1 architecture and to what is new in it.
Dr Gav Schneider
GRCS references and builds upon the Organisational Risk Culture Standard, version 8 (2025), authored by Dr Gavriel Schneider, Dr Paul Johnston, Christopher Stitt, Jack Jones and Amanda Barber, which remains separately available on this site.
Citation
How to cite: Schneider, G., with Johnston, P., Stitt, C., & Jones, J. (2026). Global Risk Culture Standard, Edition 1. riskculture.org.
Be part of the conversation
ORCS | A Global Community for Risk Culture
Our LinkedIn group is where practitioners discuss how the Standard is being understood, applied, tested and debated in real organisations. It’s also the formal channel for practice-based comment on GRCS: contributions are considered by the GRCS Technical Committee at each review.
Join to share how you’re applying GRCS, compare notes on the transition from ORCS, and work through the hard parts, from evidencing Pillar 6 to assessing machine-informed decisions.
Practical writing on risk culture, evidence and the changing risk landscape.
Read through some of the writings that our experts have recently published and equip yourself further with practical knowledge on risk culture.
This article was written for ORCS v8, the predecessor to GRCS Edition 1.
Upcoming events
GRCS Edition 1 briefings and practitioner sessions will be listed here. Join the LinkedIn group to hear first.




























