This website uses cookies

Read our Privacy policy and Terms of use for more information.

The Escalation Operating System

Welcome to Issue 21 of Beyond the Lines.

There’s a moment in organisations that tells me more about risk culture than any policy, training deck, or heatmap ever will.

Someone raises something small, early, and slightly uncomfortable.
Not a crisis. Not a scandal. Just a risk signal.

And then the room does the pause.

You can almost see the internal calculations running.

Is this going to be welcomed, or weaponised
Will this turn into blame, or into a decision
Will I be supported, or quietly marked down for being “difficult”

That pause is the culture.

So this week is not about getting people to “speak up more”.
It’s about engineering escalation so it feels normal. Routine. Boring, in the best way.

Because boring escalation creates faster decisions, fewer late surprises, less “everyone knew”, and better evidence without anyone doing the Friday afternoon screenshot hunt.

And as you read, if you want a quick mirror of how your environment stacks up on the pillars we’re using this month, my free Risk Culture Scorecard gives you a personalised PDF report:

Right. Let’s build the operating system.

The four pillars we’re using this week

Challenge Safety
Clarity of Accountability
Tone in Action
Learning from Misses

Most organisations treat these like values.

I treat them like mechanics.

Not posters.
Not slogans.
Mechanics you can install.

Here’s the uncomfortable truth I see in practice.

People do not avoid escalation because they lack integrity.
They avoid escalation because escalation is often designed to feel like social risk.

So the fix is not motivation.
It’s design.

The Escalation Operating System

I want to give you a single framework you can use with your team that is bigger than any one post.

Four components. One page. Installable in weeks, not months.

  1. Escalation Path

  2. Leader Response

  3. Decision Discipline

  4. Learning Loop

If any one of these is weak, escalation becomes a drama.
If all four are strong, escalation becomes routine.

Let’s walk through each with tools you can actually lift and use.

1. Escalation Path

When escalation feels “career limiting”, it’s usually because the path is vague.

Vague path creates two bad behaviours.

People keep it local for too long.
Or they over escalate because nobody knows the normal route.

The practical fix is to publish rungs with timeboxes.
Not a complex flowchart.
Just clarity on what happens next.

Here is the “rungs” model I use. Adapt the language to your organisation, but keep the logic.

Rung 1

Early signal
Something feels off, but it is not proven yet
Escalate to your manager the same day
Goal
Surface early, do not wait for perfect evidence

Rung 2

Confirmed issue
A control failed or a breach is likely
Escalate the same day to the accountable owner
Goal
Contain the risk and name an owner for the fix

Rung 3

Cross team risk
More than one team is involved or ownership is unclear
Escalate within 24 hours to the decision maker
Goal
Clarify decision rights and remove blockers

Rung 4

Material exposure
Potential for significant financial, regulatory, safety, or reputation impact
Escalate immediately for senior visibility, decision within 24 hours
Goal
Get sponsorship, resource the response, and decide quickly

Rung 5

Red event
Major incident, external breach, regulator involvement, or severe impact
Immediate crisis route with executive and board visibility as needed
Goal
Stabilise first, communicate clearly, capture decisions as you go

The key is this.

If you want Challenge Safety, you cannot make escalation dependent on bravery.
You make it dependent on triggers and routes.

Practical upgrade you can install this week
Pick one area where issues age quietly.
Write down the rungs and who owns each rung.
Then publish it to the team as an operating note.

2. Leader Response

This is Tone in Action in its purest form.

Most organisations say they want early escalation.
Then leaders respond like early escalation is an inconvenience.

The moment someone raises a risk, leaders tend to do one of three things.

They interrogate the person
They interrogate the past
They perform frustration to show control

All three create silence.

Instead, you want a response that does two jobs at once.

It protects the person raising the signal.
It moves the team towards a decision.

Here is the “response card” I coach leaders to use. It is deliberately simple.

Thank you for raising it early
What is the specific risk
What decision are you asking for
What do you need from me today
When will you update me

You do not need leaders to be perfect.
You need leaders to be consistent.

If you lead people, make this your one behavioural goal for the week.
Respond to the first risk raised with calm structure, not emotion.

That is how you train culture without announcing you are training culture.

3. Decision Discipline

Most escalation drama is actually a decision vacuum.

People escalate.
Everyone discusses.
Nobody decides.
Then the risk just sits there, quietly ageing, until it becomes expensive.

Decision discipline fixes that, and it also fixes evidence.

Because evidence is not something you create at the end.
It is the trail of clear decisions, owners, and proof points.

Here’s the decision log I use in practice. Five fields only.

1. Decision needed
2. Options
3. Recommendation
4. Decision made
5. Owner and date

Then add the line that makes it a risk culture tool, not a governance template.

What risk are we accepting, mitigating, or transferring
And for how long

That last part matters more than people think.

A lot of organisations do not accept risk.
They drift into it, because there is no time boundary and no revisit.

If you implement nothing else this week, implement this.

No decision is “agreed” until it is logged.
No action is “closed” until a proof point exists.

That is Clarity of Accountability without the theatre.

4. Learning Loop

Learning from Misses is the pillar most organisations say they value, and quietly punish.

People learn fast when learning is safe.
People hide when learning becomes blame.

So the learning loop needs to be light. Routine. Expected.

Not a 90 minute retrospective only when something goes wrong.
A weekly cadence that catches the weak signals.

Here is the simplest loop I have seen consistently reduce late surprises.

A weekly 10 minute escalation reset.

New signals
Stuck actions
Trigger check
Decisions and proof points

That’s it.

If you do this weekly, you are training the organisation to treat escalation as normal work.

And you get a bonus … evidence improves without chasing, because the decisions and actions are visible in the flow.

If you want to pressure test whether your environment actually supports this kind of operating system, use the Scorecard as a mirror rather than a label.

Risk culture is becoming auditable, and that is a good thing

Last week I asked the Beyond the Lines community what you want more of in this newsletter, and a great question came in from Herman about emerging risk culture standards. Thank you, Herman.

Here’s my take, in practical terms, with one caveat. This is my interpretation of where the profession is heading, based on what the standards are signalling and what I see working in organisations.

The direction of travel is towards culture being treated less like a story, and more like evidence. Not evidence in the sense of “a perfect spreadsheet”. Evidence in the sense of observable behaviours, decisions, and interpersonal dynamics you can actually assess.

What the IIA is signalling

The IIA’s Organizational Behavior Topical Requirement frames organisational behaviour as the human side of risk, made up of observable actions, decisions, and interpersonal dynamics.

Topical Requirements are mandatory for assurance engagements when the topic is in scope, so this is not just a nice to have. It is a nudge towards more consistent expectations on how we audit behaviour related risks.

My interpretation of what that means for us as practitioners is simple.

If we keep treating risk culture as vibes, we will keep getting vague results.
If we treat behaviour as auditable, we can build repeatable methods and stronger conclusions.

What ORCS is signalling

ORCS, the Organisational Risk Culture Standard (ORCS) developed out of Australia, is another signal. It treats risk culture as something you can benchmark using structured, evidence based elements, rather than opinion. ORCS is being championed heavily through the Australian and New Zealand risk ecosystem.

My interpretation is that ORCS is part of a broader move to give organisations a clearer yardstick. Not just “do we have a good culture”, but “what does good look like, and how do we know”.

What this means for the industry

If these signals continue, a few shifts are likely.

Risk culture work becomes more operational.
Less campaigns and posters. More routines and decision points.

Audit scope gets more specific.
Not “culture review”. More “escalation behaviour”, “decision discipline”, “speak up response”, “learning loop”.

Evidence gets closer to the work.
Teams chat escalation. Decision logs. Action ageing. Repeated overrides. How leaders respond in the moment.

Skills broaden.
More interviewing, observation, behavioural indicators, and triangulation. Less over reliance on policies and training completion.

Second line and internal audit get a shared language.
Not to duplicate, but to align on what “good” looks like and where ownership sits.

How to make culture auditable without making it bureaucratic

Here’s the practical translation. If you want culture to be auditable, you need to design for it.

Challenge Safety
Do people have a safe, normal route to raise risk early
Evidence to look for
Escalation ladder, clear triggers, leader response scripts, examples of early signals being welcomed and acted on

Clarity of Accountability
Does ownership exist in reality, not just in a tracker
Evidence to look for
Decision rights, one named owner per outcome, dates, proof points, closure standards

Tone in Action
What happens in the first 60 seconds when someone raises a risk
Evidence to look for
Language leaders use, patterns of defensiveness or curiosity, whether messengers get supported, whether issues move or stall

Learning from Misses
Do you learn, or do you explain
Evidence to look for
Post incident actions that change workflows, repeated issues analysis, measurable improvement in time to decision, fewer repeats

This is exactly why I built the Risk Culture Scorecard in the first place. It is a starting point to move the conversation from abstract to specific. Use it as a mirror, not a label.

And if you want the deeper implementation pack, I’m building the full Risk Culture Audit Framework tool next. That will include practical testing approaches, evidence prompts, and templates you can actually run. If you want optional early access when it releases in early Feb, the waitlist is here.

The Escalation Audit, 20 minutes

This is implementation grade. Do it once and you will see your real constraints immediately.

Set a timer.
Do it with one leader and one delivery owner.

Step 1
Pick one late surprise from the last 90 days.

Step 2
Write the timeline in five bullet lines only.

When the first signal appeared
Who noticed
Who they told
When a decision was made
When it became urgent

Step 3
Name the failure mode. Pick one.

Escalation path unclear
Leader response created fear
Decision rights unclear
Ownership unclear after the meeting
Evidence expectations were unrealistic
Learning loop did not exist

Step 4
Install one operating fix for four weeks only.

Publish the rungs and timeboxes
Use the leader response card
Start the five field decision log
Apply one owner, one date, one proof point
Run the weekly 10 minute reset

Step 5
Track one metric.

Time from first signal to first decision

If that time reduces, your culture is improving.
Not because people are nicer.
Because the system is working.

Community ask

If this issue was useful, I would be very grateful if you would you share it with your colleagues, the ones who also deal with escalation, repeat surprises, or decision friction.

They can subscribe here:
https://beyondthelines.beehiiv.com/

And if you want me to cover something specific, hit reply and tell me the topic.
I’m building this with practitioners, not for them.

Thanks again for helping me on the journey to building the highest-value community in the audit, risk and controls space globally.

Have a great week ahead.

Best,

Keep Reading