Edition 1 · Published 16 September 2026

Global Risk Culture Standard

The open standard that turns risk management into culture, across organisations, supply chains and the machines now inside the decision.

What is GRCS?

Measure what your organisation does, not what it says

Most risk culture assessments measure how an organisation would like to think. GRCS measures how it actually behaves. How long warning takes to travel, whether a decision has a named owner, whether an override was correct, whether a supplier disclosed early, and whether anything changed after the last failure.

It is assessed on evidence, not opinion. Every level of every pillar names the artefact or observed behaviour that demonstrates it. If a level cannot be evidenced, it cannot be claimed.

Why “Global”
Risk no longer stays inside the organisation that creates it. It travels through suppliers, platforms, logistics partners and data services, and it travels faster than it is absorbed. An organisation can have a genuinely mature internal risk culture and still be wholly exposed through the culture of others. GRCS assesses your organisation, including your capability in relation to your suppliers and your machines. It does not assess or certify them.

Why now
Artificial intelligence has moved from changing how work is done to changing who, or what, is deciding. The characteristic failure is not model error. It is unchallenged reliance on a plausible machine output that nobody in the room fully understood. At the same time, risk culture has become an examinable regulatory object in multiple jurisdictions, and boards are now being asked to evidence cultural claims they previously only asserted.

Where GRCS fits
GRCS sits alongside ISO 31000, COSO ERM and quantitative models such as FAIR, not in place of them. Those frameworks handle quantification, control effectiveness and capital allocation. GRCS addresses the human and organisational layer that decides whether any of that apparatus works in practice.

Contracts secure compensation after a disruption. Culture determines whether you get the phone call three weeks before it.

Who it's for

Boards and governing bodies

Who need to evidence cultural claims, not just assert them, and who are accountable for the statement of governance intent every assessment begins with.

Risk, assurance and compliance leaders

Who are ready to move beyond checkbox governance to evidence that holds up under supervisory scrutiny.

Executives and operational leaders

Who own decisions that now run through suppliers, platforms and machine systems, and need accountability to stay clear when they do.

HR, people and organisational development professionals

Who shape the incentives, psychological safety and capability that determine whether warning travels or stays silent.
The architecture

Seven pillars score capability. Three decide whether it can be trusted.

GRCS keeps the ten-pillar design and five-level maturity ladder of its predecessor, but restructures what the pillars do. Seven core pillars are scored from Level 1 (Ad Hoc) to Level 5 (Sustainably High-Performing). Three conditioning pillars are rated Strong, Adequate or Weak and applied as a discount on the whole result, because ethics, transparency and sustained capability determine whether the other seven readings can be believed.

Core Pillars
Leadership, Governance and Decision Authority

Where authority actually sits, so accountability can be located before it matters.

Risk Intelligence and Early Detection

Reading changing conditions early enough for the reading to be useful.

Decision Quality and Evidence Use

Setting the standard of evidence a decision must meet, and holding it under pressure.

Risk Appetite Translation and Enforcement.

Turning appetite from a statement into a constraint that can decline a decision.

Human–Machine Decision Integrity

Keeping accountability, verification and competence intact as decisions are delegated to machines.

Extended Enterprise and Supply Chain Culture

Whether your own conduct invites or suppresses warning from the network you depend on.

Adaptive Elasticity and Presilience®

The capacity to operate degraded, adapt at the edge, and emerge better positioned.

Conditioning pillars

Ethics, Incentives and Legitimacy

Whether concealment is the rational individual choice.

Transparency, Escalation and Psychological Safety

Whether information travels intact. A Weak rating here caps the reported score.

Capability, Learning and Change

Sustaining the whole system and closing the loop from outcome back to practice.

Score well everywhere else but fail on transparency, and GRCS tells you the truth: nothing else in your profile can be trusted. That’s not a harsher assessment. It’s an honest one.

How to use the standard

Four documents. One assessment method.

GRCS is an open standard, free to download, use, adapt and cite with attribution. Edition 1 is published as a suite:

The Standard. The full benchmarks for all ten pillars, with Characteristics, Consequences and Evidence at every level, the scoring method, governance intent and regulatory alignment, and the assessment methodology.

User Guide. How to run an assessment in seven steps, in the order you’ll actually need them: who does what, the evidence pack, choosing your assessment mode, and the five mistakes that defeat an assessment.

Representing Maturity. How an assessment becomes a number, what that number can and cannot carry, and how to present it to a board without misleading anyone.

Transition Checklist. Every change from ORCS v8 to GRCS Edition 1, what it means, and what to do if you hold an ORCS baseline.

The assessment in brief

Record the board’s statement of governance intent. Declare the assessment mode: self, facilitated or independent. Assemble evidence against each pillar. Run the five behavioural and documentary instruments, starting with warning-time reconstruction. Rate each pillar, apply the structural rules, and report all four figures with the evidence relied on. Then decide what you’ll do differently, which is the only reason to have done any of it.

Already using ORCS?
From ORCS to GRCS

GRCS Edition 1 supersedes the Organisational Risk Culture Standard, versions 1 to 8. It is a re-architecture, not a renaming. The ten-pillar design, the five-level ladder and the paired characteristics-and-consequences format carry forward. What changes is how the pillars are structured, what counts as evidence, and how the result is calculated.

The most important changes: an Evidence column now applies to every level of every pillar; ethics and transparency become conditioning pillars that gate the score; Extended Enterprise and Supply Chain Culture is new; Human–Machine Decision Integrity has been substantially rewritten; framework alignment moves out of the pillar set; and survey-based assessment is replaced by five behavioural and documentary instruments.

If you hold an ORCS v8 baseline, don’t compare results directly. Use the concordance in Annex A of the Standard and the Transition Checklist, and state which movements reflect changed performance and which reflect changed architecture. A different number after transition usually reflects a more honest measurement, not a worse culture.

Endorsements

Supporting Organisations

The following organisations endorse and support the Global Risk Culture Standard, Edition 1:

Peer review panel — GRCS Edition 1, Round 1

With thanks to the reviewers who provided independent, critical review of Edition 1 during Round 1 (August to September 2026).

Lisa R Young

Senior Metrics Engineer, Netflix

Dr Pranit Anand

Senior Lecturer in Cyber Security Management and Education, UNSW

Maman Ibrahim

Founder, DiamondSoul & Creator, The Decision Layer

Dr Jolene Morse

Ringleader, Riskywomen

Dr Bob Mark

Managing Partner, Black Diamond

Yohanes Jeffry Johary

President & Managing Director, OCS Indonesia

Dr Fayadh Alenezi

Associate Professor, Al Jouf University

Dave Cohen

Chief Executive Officer, Risk 2 Solution Group

Neil Farber, MD, PhD

Inventor, Action Board

Lineage: ORCS v8 endorsement and peer review

The organisations and reviewers below endorsed and reviewed ORCS version 8 (2025), the predecessor to this Edition. They are acknowledged here for provenance; this should not be read as endorsement of GRCS Edition 1 or of any change introduced in it.

Peer review panel — ORCS v8

Lord Toby Harris

Chair, National Prepareness Committee

Tim McCreight

CEO & Founder, TaleCraft Security

Dr Jolene Morse

Ringleader, Riskywomen

Dr Jen Schneider

Professor, Rochester Institute of Technology

Todd Tucker

Managing Director, The FAIR Institute

Lisa Young

Senior Metrics Engineer, Netflix

Bob Mark

Manging Partner, Black Diamond

Becky Lane

Founder, Brick Lane Consulting

Dave Cohen

Deputy CEO, Risk 2 Solution

Don Morron

Founder, HighlandTech

Darrel Waurio

Staff, Risk Expert, Walmart Global Tech

Dr Fayadh Alanezi

Associate Professor, Al Jouf University

Michael Gips

Managing Director, Kroll

Simon Levy

CEO, Risk Management Institute of Australasia

Sandi Davies

CEO, International Foundation for Protection Officers

Jason Brown

CEO, Former Chair Technical Comimittee TC262 Risk Management

What reviewers said about ORCS v8

These testimonials were given for ORCS version 8, the predecessor Standard, and are shown for lineage.

The Authors

Our Risk Culture Experts

The Global Risk Culture Standard, Edition 1, is authored by Dr Gavriel Schneider, with Dr Paul Johnston, Christopher Stitt and Jack Jones as supporting authors, reflecting their contribution to the Edition 1 architecture and to what is new in it.

Dr Gav Schneider_Headshot

Dr Gav Schneider

Author, GRCS Edition 1 ·Group Managing Director and Chair of the Board, Risk 2 Solution Group
Version 2

Jack Jones

Supporting author · Risk Management Executive
Paul Johnston_Headshot

Dr Paul Johnston

Supporting author · Behavioural Scientist & Risk Management Specialist
Christopher Stitt_Headshot

Christopher Stitt

Supporting author · Founder and CEO, CrisisLead

GRCS references and builds upon the Organisational Risk Culture Standard, version 8 (2025), authored by Dr Gavriel Schneider, Dr Paul Johnston, Christopher Stitt, Jack Jones and Amanda Barber, which remains separately available on this site.

Citation

How to cite: Schneider, G., with Johnston, P., Stitt, C., & Jones, J. (2026). Global Risk Culture Standard, Edition 1. riskculture.org.

Be part of the conversation

ORCS | A Global Community for Risk Culture

Our LinkedIn group is where practitioners discuss how the Standard is being understood, applied, tested and debated in real organisations. It’s also the formal channel for practice-based comment on GRCS: contributions are considered by the GRCS Technical Committee at each review.

Join to share how you’re applying GRCS, compare notes on the transition from ORCS, and work through the hard parts, from evidencing Pillar 6 to assessing machine-informed decisions.

From the authors

Practical writing on risk culture, evidence and the changing risk landscape.

Read through some of the writings that our experts have recently published and equip yourself further with practical knowledge on risk culture.

Upcoming events

GRCS Edition 1 briefings and practitioner sessions will be listed here. Join the LinkedIn group to hear first.