Adopting a behavioural lens to strengthen resilience and enable better decisions

Risk management advisory

Businesswoman showing colleague data on a digital tablet while working in office

Financial institutions (FIs) operate in an increasingly complex and interconnected risk environment, amid growing regulatory expectations and stakeholder scrutiny. Robust risk governance, risk management frameworks and system of internal controls remain as critical as ever. In addition, organisations increasingly recognise that risk outcomes are ultimately shaped by human behaviours and decisions. Effective risk management therefore requires not only robust structures and processes, but also the capabilities to influence the contextual conditions that drive the desired risk behaviours and decision-making, risk-taking and organisational conduct.

In its 2017 publication, Enterprise risk management - Integrating with strategy and performance, the Committee of Sponsoring Organisations of the Treadway Commission (COSO) emphasises the importance of aligning risk, strategy and performance. Rather than managing risks in isolation, organisations should consider how risks may affect the achievement of strategic objectives and incorporate risk considerations into decision-making at all levels of the organisation. The publication further recognises that effective risk management extends beyond formal risk processes. In Principles 3, 4 and 20, COSO highlights the importance of defining the organisation's desired culture, demonstrating commitment to core values, and reporting on risk, culture and performance to facilitate informed decision-making and responsible risk-taking behaviours.

The importance of integrating risk and behavioural considerations into organisational decision-making has also been reinforced through COSO's 2026 publication, Corporate governance: Guiding principles for board oversight, developed in collaboration with PwC. In its Guiding Principles 5, 6 and 7, the publication emphasises the importance of aligning strategy, objectives and performance with the organisation's purpose, mission and values, while recognising the critical role that culture, conduct and tone at the top play in shaping decision-making and risk outcomes.

PwC's Global Risk Survey 2023 highlights that leading organisations are increasingly adopting a more strategic approach to risk management, recognising that risk decisions should be informed by the organisation's purpose, objectives and future vision. The survey further highlights that organisations with a human-led approach to risk management are better positioned to align risk management with business strategy, strengthen resilience and respond more effectively to opportunities and emerging risks. Effective risk management therefore requires not only robust risk governance, risk management frameworks and system of internal controls, but also an understanding of the human factors that influence risk-taking and organisational outcomes.

How PwC can help

Behaviourally-informed risk management

1. Controls optimisation
Adopt a behavioural-centric approach to optimise the system of internal controls by aligning controls to material risks and reframing the controls as behavioural drivers that nudges risk behaviours. Drawing on behavioural science and risk-based design principles, we can help organisations reduce control clutter, improve control effectiveness and enable more efficient, reduce execution drag and promote risk-intelligent decision-making.

2. Behavioural risk management
We can help FIs identify, assess and manage behavioural risks that may impede the achievement of organisational objectives. Drawing on behavioural decision science, governance and risk management principles, FIs can identify behavioural drivers, evaluate the effectiveness of culture and conduct frameworks, strengthen behavioural risk assessment methodologies, and implement monitoring mechanisms that provide insights into how behaviours influence risk and performance outcomes.

3. Fraud risk management
Drawing on behavioural decision science, we can help organisations supplement the Fraud Triangle by analysing how pressure, opportunity and rationalisation arise in the first instance, from organisational contextual conditions (such as incentives, deterrence measures, enablement and enforcement measures), leadership behaviours, social norms and mindsets towards fraudulent activities. We can help organisations identify fraud "hot spots" before incidents occur and design targeted behavioural interventions to manage fraud risk and strengthen organisational resilience against fraudulent activities.

Corporate governance effectiveness and risk management framework review

1. Independent review of risk management framework
Assess the adequacy and effectiveness of your Risk Management Framework through an independent review across nine key domains: Risk strategy and governance, risk appetite, risk leadership and accountability, risk identification and assessment, risk response, risk monitoring and reporting, risk tools and technologies, risk data, modelling and analytics, and resourcing and capabilities. Drawing on recognised frameworks such as COSO ERM, ISO 31000 and regulatory expectations, we identify enhancement opportunities and provide practical, prioritised recommendations to strengthen board oversight, risk-informed decision-making and organisational resilience.

2. Review of COSO 2026 corporate governance: Guiding principles for board oversight
Assess whether the Board's governance structures, oversight processes and information flow effectively support enterprise risk management and organisational decision-making. Drawing on the 12 guiding principles, we evaluate how the Board and its committees oversee risk appetite, risk management, internal control, monitoring and assurance activities, and whether these support the organisation's strategy, objectives and resilience. In addition, we assess whether management’s monitoring and assurance activities provide the board with a coherent view of risk management, internal control effectiveness, and risk culture, enabling effective oversight of strategy, performance and organisational resilience.

Enterprise risk management (ERM) advisory

1. Assess ERM maturity
Assess the effectiveness and maturity of your current ERM capabilities against leading practices and recognised frameworks such as COSO ERM and ISO 31000. We identify key strengths, improvement opportunities and practical actions to enhance the effectiveness of your ERM programme.

2. Design or enhance ERM frameworks
Design or enhance your ERM framework to align with your strategy, operating model and regulatory expectations. This includes the development of policies, governance structures, methodologies and risk management processes tailored to your organisation.

3. Operationalise ERM
Implement practical risk management processes and tools that bring ERM frameworks to life across the organisation. We help organisations develop risk taxonomies, risk registers, risk appetite frameworks, key risk indicators (KRIs) and reporting mechanisms that enable consistent risk assessment, monitoring and oversight across the enterprise.

4. Identify emerging risks
Identify, assess and monitor emerging risks through structured horizon scanning, leveraging on our in-house risk radar. By combining industry insights, peer benchmarks and external risk intelligence with internal stakeholder perspectives, organisations can better understand developing risks and opportunities and incorporate them into strategic decision-making.

5. Develop and embed ERM capabilities
Develop organisational risk management capabilities through tailored ERM training and practical guidance. We help organisations embed ERM into day-to-day operations and decision-making, reinforcing understanding of risk appetite, risk assessment methodologies, KRIs and reporting requirements, while building the knowledge and ownership required to sustain risk management practices over the long term.

Why PwC

Deep understanding of leading behaviourally-informed ERM practices

PwC has played a significant role in the development of globally recognised risk management frameworks and thought leadership. As contributors to the COSO enterprise risk management – Integrating with strategy and performance framework and collaborators on COSO's corporate governance: Guiding principles for board oversight, we bring deep insights into leading practices in behaviourally-informed risk management, governance, culture and organisational decision-making.

Proven methodologies and proprietary accelerators

Our approach is underpinned by PwC's proprietary toolkit, including:

  1. Our maturity assessment framework – designed to help our clients understand their current-state maturity and define a roadmap for a desired future state;
  2. Our culture management framework – which outlines the key capabilities for organisations to establish an interconnected ecosystem for behavioural risk management; and
  3. Risk radar – a visualisation and reporting tool that presents emerging risks and opportunities, based on industry-specific developments.

These accelerators enable organisations to assess their current-state capabilities, identify improvement opportunities and gain deeper insights into emerging risks and opportunities.

Practical implementation experience across financial services

We have extensive experience supporting FIs in enhancing ERM frameworks, governance arrangements, risk appetite frameworks, KRIs, risk registers, monitoring capabilities, and behavioural risk management practices. Our focus is not only on designing frameworks, but also on helping organisations operationalise and embed risk management practices and behaviours that support informed decision-making and sustainable outcomes.

Speak to our specialists

Explore how your organisation can improve decision-making and respond more effectively to emerging threats via behaviourally-informed risk management.

Follow us

Required fields are marked with an asterisk(*)

Your personal information will be handled in accordance with our Privacy Statement. You can update your communication preferences at any time by clicking the unsubscribe link in a PwC email or by submitting a request as outlined in our Privacy Statement.

Contact us

Alywin Teh

Alywin Teh

Financial Services Risk Leader, PwC Singapore

Tel: +65 9627 7018

Hide