Author: admin

  • Legacy Systems, Modern Risks

    Legacy Systems, Modern Risks

    Introduction

    Mid-sized listed companies often continue to rely on the same legacy systems that once supported their early growth. Over time, however, these aging platforms become a burden. Excessive customizations and patchwork integrations accumulate into ‘tech bloat’, a complex tangle of outdated software and add-ons that slow the business down.

    One analysis noted that redundant systems could inflate operating costs by 20% and delay decision-making by 30% due to fragmented data. These hidden costs accumulate over time, eroding competitiveness.

    This article explores how legacy systems and ERP customizations constrain mid-sized firms drawing on examples from manufacturing and financial services, and why adopting nimble, easily orchestrated tools is the way forward. We also outline how companies can transition from legacy baggage to a future-proof tech stack.

    The Weight of Legacy: How Tech Bloat Occurs

    Tech bloat refers to the proliferation of redundant or antiquated technologies within an organization’s IT landscape. Companies in growth stage often over-customize their enterprise software to meet unique needs, especially when newer, scalable solutions seem unwarranted or too costly. Over years though, these ad-hoc adaptations create what is typically a clutter around the system.

    Common symptoms of tech bloat include outdated processes, redundant / overlapping applications or modules (often kept “just in case”) that duplicate functions, fragmented data and a company culture clinging to familiarity which only reinforces the cycle. Individually, each workaround or customization may have solved a short-term problem. But collectively, they begin to form a convoluted junction of systems that is hard to maintain or scale.

    For example, many mid-sized manufacturers still run on legacy ERP or production management systems implemented more than a decade ago. These might handle core functions like inventory or basic scheduling, but they struggle to support Industry 4.0 initiatives such as IoT-enabled machines, advanced analytics, or AI-driven automation.

    When legacy software can’t easily interface with sensors on the shop floor or can’t process the volume of real-time data modern equipment produces, it becomes a bottleneck.

    Data Quality and Integration Constraints

    A major pain point tied to legacy systems is poor data quality and integration. Older systems were not designed with modern data needs in mind. Information gets trapped in silos, and companies struggle to obtain a “single source of truth” across functions.

    Data might be incomplete, inconsistent, or not available in real time, undermining both strategic and day-to-day decisions. In fact, reliance on outdated legacy systems itself is listed as a common cause of data integrity problems. Older platforms often lack features to ensure data quality, and integrating them with modern applications can introduce inconsistencies. Analytics thus often remains unsupported due to quality constraints.

    Customizations layered on top of baseline systems further complicate data flows. Often, quick fixes or departmental databases are introduced to compensate for what the main ERP cannot do. For instance, finance might maintain a separate spreadsheet model because the legacy ERP’s reporting isn’t flexible enough, or a manufacturing plant might have a standalone quality tracking system not fully integrated with the core production software.

    These patches create data orchestration challenges and it becomes difficult to aggregate and reconcile information across the enterprise. Without large IT teams, such integration gaps are sometimes bridged with manual work, which introduces opportunities for inefficiencies.

    Many mid-sized banks and insurers grew on top of legacy core systems and have since layered on digital products without modernizing the core. This has led to situations of struggles of data integration which isn’t just an IT headache; but often a serious compliance liability.

    Migration of data from legacy systems is often a great challenge. Product design in legacy systems capture data in different formats that don’t support easy migration to the new systems.

    Industry-wide, banks lost an estimated $485.6 billion to fraud in 2023, much of it due to increasingly sophisticated schemes that exploit any lag in oversight. For mid-sized institutions with tight margins, such losses along with potential regulatory penalties for late reporting can be devastating. As a 2025 banking technology report highlights, outdated batch-based systems leave customers waiting for yesterday’s information and give fraud a head start – “a liability no mid-sized bank can afford in the instant economy”.

    From a risk management perspective, the key is to recognize tech bloat as an enterprise risk, not just an IT problem. It should be raised in risk registers and board discussions, the same way one would discuss financial, operational, or market risks. Once understood, the mitigation is to modernize and streamline the tech environment deliberately and proactively, before a crisis forces the issue.

    Transitioning to a Future-Proof Tech Stack – Key Pillars

    The good news is that today there are more options than ever to right-size a tech stack for scalability, flexibility, and integration. A “future-proof” tech stack for a mid-sized firm would typically have the following characteristics:

    A. Modular Architecture

    Instead of one monolithic system doing most things, the stack is composed of smaller, specialized applications or services that can be connected. This could mean using a core ERP for finance and inventory, but a separate best-of-breed system for, say, CRM or e-commerce, with seamless integration between them. The benefit is greater flexibility to upgrade or swap out one component without a full upheaval and usually better functional depth in each area.

    B. Ease of Integration

    A nimble tech stack is one where data can flow readily across systems. Modern tools achieve this with API-driven designs and integration middleware. The ability to orchestrate workflows that span multiple applications would be crucial. For example, an order entry in the CRM should automatically create a demand signal in the manufacturing system and an invoice in the finance system, without manual intervention.

    Scalability and Cloud Infrastructure: To enable ease of scale, many mid-sized enterprises are migrating from on-premises servers to cloud-based solutions. Cloud infrastructure (whether public cloud or private/hybrid clouds) offers on-demand scalability to can ramp up capacity during peak periods or as the business grows, without having to overhaul hardware. Cloud-based SaaS applications also relieve the burden of software patching and upgrades, as the vendor handles that. New market entrants often go cloud-native from the start, building on scalable platforms to “avoid vendor lock-in and technical bloat”

    C. Security and Compliance by Design

    Modern systems tend to have stronger security frameworks and compliance features out-of-the-box. A good tech stack will include up-to-date identity and access management, encryption of data in transit and at rest, audit logging, and compliance modules for relevant regulations (be it GDPR for data privacy or SOX controls for financial systems).

    Today’s products also have external stakeholder portals that allow for limited access but enable the consolidation of data from all sources in one place such as a customer portal, Vendor Portal or a Partner Portal.

    Leading practices to ensure clinical transition

    Transitioning from legacy to future oriented systems is a journey that involves careful planning and execution. Here are some leading practices for mid-sized firms embarking on this journey:

    1. Audit and Rationalize

    Start with a ruthless audit of your current IT landscape. Inventory all systems, custom scripts, and data stores. Identify which ones are redundant, outdated, or low-value. It’s common to find multiple tools performing similar functions (for example, two reporting tools being used by different departments).

    Evaluate which systems are truly critical vs. which could be phased out or consolidated. This process often uncovers “quick wins,” such as shutting down an old server or eliminating duplicate software licenses to save cost. More importantly, it gives you a map of dependencies highlighting where fragile integrations might break during modernization.

    An independent technology assessment explores the audit of inventory and provides a comprehensive priority order and roadmap for implementation.

    2. Prioritize Incremental Modernization

    Prioritize areas where modernization yields the highest benefit and manageable risk. This could mean decoupling a piece of the monolith into a microservice or selecting one function (say, CRM or HR management) to migrate to a modern SaaS first.

    By adopting microservices or a two-speed architecture, you can gradually migrate workloads to newer systems while keeping the business running on the old system in parallel.

    Many companies start with less critical modules as pilots, learn from those migrations, and then tackle core systems. Re-architect in steps by carving out modules from the legacy core and rebuilding them.

    3. Strengthen Data Foundation

    As part of the transition, invest in data cleansing and integration early. It’s futile to implement a shiny new platform on top of dirty or siloed data. Growing firms should consider setting up a central data repository or using data integration tools to pull together key information from legacy systems.

    This could run in parallel to legacy systems initially, for example, building a cloud data warehouse that aggregates data from the old ERP, CRM, and other sources. Such a project not only improves reporting in the short term, but also prepares the ground for new systems (which can plug into the centralized data store).

    Ensuring data integrity and consistency will make the eventual cut-over to new applications much smoother. Additionally, define data governance practices so that as new systems come online, they adhere to common data standards and quality checks.

    4. Foster a Culture of Change and Upskilling

    One often underestimated aspect of modernization is the human factor. Employees comfortable with legacy tools may resist the change or fear that new systems will complicate their jobs.

    This could be tackled by communicating the vision for the new system, involving end-users in design and testing, and providing robust training. Organizations could also consider encouraging a culture that rewards innovation, perhaps by running internal hackathons or pilot programs to get teams excited about new ways of working.

    At the same time, an aspect to consider is addressing the skills gap. Need to upskill staff or hire new talent fluent in modern architectures could be imperative. Bringing in a “digital native” leader or two can also help drive the transformation from within. A robust change management framework aids such transitions in a holistic manner.

    By following these steps, growing companies can navigate the modernization journey in a controlled, risk-aware manner. The key is to view tech stack improvement as an ongoing program rather than a one-off project. The external environment, from cyber threats to compliance requirements will continue evolving, so building an adaptable technology core is itself a risk management strategy.

    Conclusion

    Whether it’s adopting a modular ERP approach, leveraging cloud services, or deploying integration platforms, mid-sized firms have pathways to shed legacy detritus and become more data-driven and responsive. The transition needs to be handled with care though. With incremental steps, solid change management, and an eye on risk mitigation it is very much achievable.

    Those that act decisively now, auditing their systems and steadily modernizing, will not only reduce the risks of today but also position themselves to capture the opportunities of tomorrow. The time to break free from the constraints of legacy tech bloat is now. Future growth and resilience depend on it.

    Sources:

    • Graham, Paul (2025). Beyond Technical Debt: Overcoming The Burden of Legacy Systems (LinkedIn).
    • backbase.com Pleiter, Jouk (2023). Legacy banking tech is a dead-end. Here’s why progressive modernization is the way forward. (Backbase Blog).
    • erpadvisorsgroup.com ERP Advisors Group (2023). ERP Implementation Case Study Series: Mid-Sized Food & Beverage Companies.
    • ibm.com IBM (2023). Data Integrity Issues: Examples, Impact, and 5 Preventive Measures.
    • whatfix.com Whatfix (2025). 9 Critical Digital Transformation Challenges to Overcome.
    • online.flippingbook.com TKO Miller (2024). Packaging Industry Report – Year-End 2024.
    • lumenalta.com Lumenalta (2025). Real-time data is no longer optional for mid-market banks.
    • simplelegal.com SimpleLegal (2022). Why legacy tech is a legal risk management nightmare.
    • sikich.com Sikich (2025). Why Acting Now Matters: Overcoming the Risks of Legacy Systems.
    • priority-software.com Priority Software (2022). Postmodern ERP for Old-School Manufacturers.
  • Think Again: The Power of Knowing What You Don’t Know

    Think Again: The Power of Knowing What You Don’t Know

    Duration: 6 – 7 hours.

    Writing Style: Witty, fast-paced, with pop culture, business anecdotes and behavioural science references.


    What is the Main Hook of the Book ?

    The central hook is the underlying theme that intelligence is not the ability to think, it is the ability to rethink. He redefines success which is not about having all the answers but about having the humility to question what we think we know, the curiosity to explore alternatives, and the agility to change our minds without losing credibility.

    Standout feature: The chapter-end “Actions for Impact” toolkits that are quick guides that turn insights into habits for individuals, teams, and organisations.


    Premise / Core Idea

    The book is structured broadly across three themes:

    • Rethinking at the individual level
    • Encouraging others to rethink
    • Building cultures and systems of rethinking

    The book brings forth a lens on the following themes:

    Building Personas – The book is built around a core idea that cognitive flexibility – our ability to rethink, unlearn, and revise our opinions, is more critical to long-term success than knowledge or confidence. Grant outlines four mental personas that define how we engage with disagreement:

    • The Preacher – Tries to convince others of what they already believe
    • The Prosecutor – Tries to prove others wrong
    • The Politician – Tries to win favour and stay likeable
    • The Scientist – Seeks truth, revises beliefs based on evidence

    Think Again is a call to operate more like scientists allowing always questioning, always open, always iterating.

    Consultant Takeaway: Use the “Scientist Mindset” when engaging with client assumptions. Replace “This is the solution” with “Let’s test this hypothesis.” Clients respect confidence, but they trust curiosity and co-creation more.

    Power of Rethinking – Grant explores how subject-matter experts fall prey to overconfidence bias and confirmation bias. Rethinking isn’t natura, but it’s learnable. There is focus on the Dunning-Kruger Effect where he states that people with low ability overestimate themselves and how in contrary, the impostor syndrome, in moderation, can be healthy, it motivates humility and lifelong learning.

    Consultant Takeaway:

    • Building cognitive humility into the problem defining phases.
    • Using alternate scenario planning, and encouraging team members to play the role of  “devil’s advocate” roles early in strategy or transformation work.
    • Encourage teams to own both what they know and what they don’t.
    • Use “confidence intervals” in forecasts to express uncertainty honestly.

    The Joy of Being Wrong – People often fear being wrong because it threatens their identity. But rethinking can be joyful if we see it as learning, not losing.

    Consultant Takeaway:

    • Create space for clients to admit when legacy thinking no longer serves them.
    • Use “nonlinear learning” sessions in long-term projects to surface pivots or find new insights without judgment.

    The Good Fight Club – Constructive conflict (task conflict) strengthens teams when managed well. Grant distinguishes healthy disagreement from toxic arguments. Challenging each other makes teams smarter and work towards more productive outcomes.

    Consultant Takeaway: In cross-functional strategy work, establish ground rules for productive dissent. Use debate rituals (“one team argues for; one against”) to de-personalize disagreement and improve decisions

    Dancing with Foes – Grant encourages persuading sceptics or opponents with not with facts, but with curiosity, listening, and small concessions. He encourages asking questions that lead others to examine their own thinking.

    Consultant Takeaway:

    When facing resistance from client stakeholders (especially in transformation or change), shift the pattern of questioning to ask: “What would make this idea more workable for you?”

    Establishing Empathy – Grants suggests a more empathetic approach towards clients and other key stakeholders within or external to the organisation. Shared identity unlocks mutual understanding.

    Consultant Takeaway:

    In silos (e.g., finance vs. sales), frame problems as “our shared challenge,” not “their issue.” Use empathy-building exercises to soften resistance during operating model redesigns.

    Mild Mannerisms – In order to support change and promote growth, the book showcases how when persuading others, it’s better to start small and let them come to their own conclusions. The key is not present overwhelming evidence.

    Consultant Takeaway:

    • People don’t resist change; they resist being changed.
    • Use “laddering” in client presentations. Start with their pain points, validate them, and then introduce rethinking gradually.
    • Avoid information overload or lecturing.

    Art of Conversation – Think Again warrants the need for emotional listening and creating an ecosystem of and psychological safety because in the end, it’s not just facts that will change minds.. Emotion and effective listening, matter and hold equal ground.

    Consultant Takeaway:

    • When discussing risk, compliance, or culture gaps; listen more than you speak.
    • Say: “I hear you. What makes this issue important to you?”
    • Lead with trust before data.

    Rewriting the Source Code – Grant firmly establishes the concept of rethinking that needs to be  built into education and professional development. He emphasises the need to teach people how to think, not just what to think. Organizational rethinking requires systems and habits. Grant explores companies that build “challenge networks,” encourage dissent, and reward curiosity.

    Consultant Takeaway: Infuse consulting engagements with “learning loops.” Don’t just deliver a model, teach how to challenge it, adapt it, and sustain it.

    Escaping Tunnel Vision – Success can breed overconfidence. Even high-performers must question their assumptions.

    Consultant Takeaway:

    • In high-growth clients, beware of “success trap thinking.”
    • Encourage scenario reviews: What assumptions would kill this model if they changed tomorrow?

    Abandoning Best Practices – Best practices are often frozen thinking. The best leaders ask: What’s our “next practice”?

    Consultant Takeaway: While building the target operating model or revenue design work, challenge the best practices. Ask: “What worked last year and why might it fail next year?”


    Application

    As a young consulting firm, our credibility is built, not just on what we know, but on how we think. Think Again isn’t just relevant; it’s foundational to how we want to shape our work and our voice.

    Here’s where it intersects with our journey:

    • In Risk Advisory – The hardest part of risk management isn’t designing controls; it’s overcoming overconfidence and confirmation bias. Grant’s tools help us reframe risk culture not as a checklist but as a way of thinking. Example: In a risk audit for a mid-sized financial services client, we asked business heads to list what they feared most vs. what they thought would never happen. It became a mirror, 90% of their risk events had roots in the “never will happen” zone.
    • In Finance Transformation – Legacy assumptions drive process design, budgeting, and forecasting. Grant champions a concept called “pre-mortems” to challenge those assumptions and invite rethinking. Example: While reworking a client’s zero-based budgeting framework, we asked, “If you had to start this business unit today, would you structure it this way?” The result: two outdated cost centres merged into one agile shared service.
    • In Revenue Strategy – Rethinking helps us build smarter go-to-market plans. It helps us challenge “This is how we’ve always sold,” and shifts the conversation to “What if we were wrong about what the customer wants?” Example: One B2B firm had been investing heavily in demos and roadshows. Post-rethink, it was uncovered that most qualified leads were coming from technical webinars. That led to a revenue reallocation that increased marketing ROI by 40%.

    Challenger Thoughts

    • More depth on emotional triggers – While Grant talks a lot about cognitive habits, he underplays the emotional toll of changing long-held beliefs. More consideration on how does one manage status, vulnerability, or shame would be helpful.
    • There could be more frameworks that provide  guidance on how to build “rethinking” into recurring rituals such as boardrooms, investment committees, or cross-functional project teams.

    Conclusion

    Think Again isn’t a leadership book, a change book, or a productivity book, it’s a thinking book. It gives you the tools to unlearn, reframe, and become more agile, not in your actions, but in your beliefs.

    What resonated deeply with us was:

    • Good consultants don’t always have the best ideas, they ask the best questions. This book validates that and sharpens how we show up: not as Preachers with a fixed model, but as Scientists who learn through inquiry.
    • Disagreement isn’t dangerous; it’s the source code for better ideas.
    • Build curiosity and instead of disagreeing, try to understand what led them to that view. It creates psychological safety and better decision quality.

    Rethinking isn’t weakness. It’s wisdom. And for those of us building businesses, and shaping new models; it’s the most powerful skill we can cultivate.

    Margin Notes Rating Category: Reference Shelf

  • The ESG Mirage: Why Integration Falters & What True Governance Demands

    The ESG Mirage: Why Integration Falters & What True Governance Demands


    Background

    ESG has officially entered the mid-market boardroom. Sustainability sections now feature prominently in annual reports. Mid-sized companies display framework badges with pride such as GRI, TCFD, and SASB, and fill pages with metrics, values, and diagrams tracing their impact across the value chain.

    What many mid-sized firms have built however, is ESG optics, not ESG integration. ESG continues to largely operate as a standalone disclosure compliance driven function, decoupled from Enterprise Risk Management (ERM), and operational decision making.

    The cost of this structural disconnect is rising. Investors are demanding alignment between ESG strategy and business outcomes. Operational incidents are increasingly linked to blind spots that ESG frameworks were supposed to surface but didn’t.

    This article examines the widening gap between ESG reporting and ESG risk integration in mid-sized firms. When it refers to ESG risks, it points to a broad but tangible spectrum of exposures. These include climate transition shocks, biodiversity loss, labour rights violations, greenwashing, data breaches, supply chain vulnerabilities, and governance failures. These are not theoretical risks. They show up as project delays, litigation, regulatory penalties, capital constraints, and reputational damage. For mid-sized firms, exposure is growing, but the ability to anticipate, measure, and mitigate ESG risks often falls short. This article explores that disconnect and lays out a blueprint for embedding ESG into the core of ERM, where it belongs.


    Where Integration Breaks: Key Vulnerabilities


    a. Scattered Ownership, Hollow Oversight

    • This diffusion is often a legacy of how ESG has evolved in resource constrained settings. Without dedicated teams, ESG has tended to land where bandwidth exists at a point in time, not where strategic alignment lies.
    • Ask who is accountable, and the answers are often unclear  or contradictory. CSR may manage community initiatives, risk taking on climate, legal handling disclosures, and HR overseeing diversity. Responsibilities are thus scatteredwith little coordination between units.
    • When issues emerge, responses are disjointed. A vendor may face human rights violations or a site may breach environmental norms, but coordination falters. In such moments, governance gaps surface.
    • The result is symbolic oversight where updates are shared, dashboards reviewed, but material risks go unchallenged. What looks like oversight proves to be a reporting theatre. ESG exists, but it does not lead.

    b. Disconnection from Enterprise Risk Management (ERM)

    • Scan a typical risk register of a mid-sized company and you will likely find familiar entries: operational, credit, cyber,  reputational or regulatory risks. But sustainability exposures such as water scarcity, human rights violations, or climate transition risk areoften missing. This omission reflects a deeper structural misalignment. ESG risks are not just underreported, they are mismanaged.A major Indian outsourcing firm was recently embroiled in controversy after labour and data protection lapses surfaced. Global clients were drawn into the cross-border implications, revealing how ESG vulnerabilities within third-party ecosystems can escalate into legal, operational, and reputational crises when not integrated into enterprise risk frameworks.
    • ESG and risk teams usually operate on separate tracks, guided by different templates, language, and reporting cycles. There is limited dialogue, shared metrics, and few common touchpoints in governance. The consequences are tangible. Risks that are not integrated do not get assessed, tracked, or mitigated.
    • Decisions on capital deployment, supplier onboarding, or market entry move forward without proper accounting of ESG exposure. And when ESG risks crystallize, whether through forced labour allegations or carbon price shocks, they hit as surprises, not scenarios planned for. The fallout is reputational, financial, and at times regulatory.

    c. Short-Term Fixes, Long-Term Blind Spots

    • ESG risk management in many mid-sized firms still remains reactive. Environmental near misses, whistleblower alerts, or supplier violations are resolved in isolation. They are treated as incidents to close, not signals of operational risk.
    • These events rarely trigger cross-functional reviews or governance reform. They are often viewed through conventional lenses like outsourcing, reputational, or compliance risk, rather than as ESG issues warranting systemic attention.
    • Most incident platforms are not equipped to tag and escalate ESG-related risks across risk taxonomies or internal audit programs. As a result, these incidents are captured but not translated into lasting controls or reforms. ESG concerns remain excluded from the formal risk universe, leaving gaps in ownership, escalation, and consequence management.
    • The problem is not that patterns go unnoticed. It is that they are seen, logged, and filed away without institutional learning. With no feedback loop between ESG events and core GRC systems, the organisation remains in a state of incident-by-incident reaction. The absence of structural course correction keeps ESG risk in the background, never part of the firm’s control spine.

    d. ESG as Policy, not Practice

    • Many mid-sized firms have made substaintial progress in formalising ESG commitments, issuing environmental policies, supplier codes of conduct, and diversity statements. On paper, the structure appears sound but in practice, ESG often remains disconnected from core governance and risk processes.
    • In GRC terms, ESG policies are frequently documented but not operationalised. They may not inform procurement thresholds, risk assessments, or investment decisions. First and second-line functions often lack clarity on ownership, escalation, or how ESG ties into day-to-day decision-making. Without mapped controls, training protocols, and integration into assurance cycles, these policies function more as signals of intent than tools of control.
    • Compouding the complexity is proliferation of various frameworks leading to disclosure misalignment. Many organizations struggle to reconcile overlapping or divergent expectations, resulting in fragmented reporting and diluted strategic focus.
    • This gap is not always a result of indifference. Competing compliance pressures and resource constraints can slow down implementation. Without intentional follow-through, even the most well-designed policies fall short of delivering meaningful risk mitigation. ESG maturity must be measured not by the presence of documents, but by the presence of systems that activate them when it matters.

    e. When ESG Goals and Rewards Don’t Align

    • In many mid-sized firms, ESG targets exist on paper but lack execution in practice. Sustainability teams may be commended for reporting achievements, yet the broader organization remains focused on financial KPIs that often conflict with ESG goals. Cost pressures get passed down the value chain leading to corner-cutting, while accelerated timelines increase the likelihood of environmental or safety incidents.
    • A key barrier is the weak integration of ESG into performance architecture. Where ESG metrics appear in bonus scorecards, they are often peripheral, vaguely defined, or outweighed by short-term financial goals. This imbalance is particularly visible at senior levels, where ESG objectives are seldom treated with the same urgency as revenue or margin targets.
    • The result is a misalignment between declared priorities and actual behaviour. Employees learn to focus on what is measured and rewarded. When ESG is not embedded in those levers, it struggles to influence decisions in a meaningful way, not because intent is lacking, but because the system is not built to support it.

    f. Over-indexing on Reporting Tools, Underinvesting in Control Maturity

    • Across the mid-market, ESG dashboards and disclosure software are on the rise. Companies invest in sleek platforms that automate surveys, generate visual reports, and populate sustainability portals with curated metrics. Even though ESG data may feed disclosure reports, but it often bypasses the systems that govern enterprise control like incident management, RCSA, and third-party audits. The result is a disconnect where core risk systems remain unchanged, limiting the shift from insight to action.
    • Compounding this issue is the poor quality of ESG data generated by many reporting systems. Inconsistent methodologies, unverifiable metrics, and outdated sources often result in low-confidence inputs. When such flawed data becomes the basis for business decisions, it not only undermines credibility but exposes firms to material risk misjudgments.
    • A large European asset manager came under investigation in 2022 after national regulators launched a raid based on allegations of greenwashing. Although its ESG disclosures were extensive, internal records and control reviews indicated that several funds were marketed as ESG aligned without sufficient substantiation. The optics of compliance had obscured the absence of effective governance. The result was regulatory backlash, investor exits, and significant reputational damage.
    • The more firms over index on optics without reinforcing the control layer beneath, the more exposed they become to ESG failures, reputational damage, and regulatory sanctions that reporting alone cannot defend against.
    • Bridging the ESG gap requires more than software fixes or better disclosures. It calls for a reset in how companies assign ownership, integrate ESG into risk frameworks, and translate accountability into daily decisions. The blueprint that follows outlines practical steps mid-sized firms can take to move ESG from narrative to control reality, one that holds up under scrutiny and improves performance from the inside out.

    Embedding ESG within ERM Framework – A blueprint


    a. Governance & Strategy

    • Clarify ESG Ownership: Assign ESG accountability at the board and CxO levels. Establish cross-functional steering committees that include leaders from risk, operations, sustainability, legal, and procurement. Make roles explicit. When responsibility is shared without clarity, it leads to inaction.
    • Link ESG KPIs to Leadership Appraisals: Incorporate progress on ESG metrics into formal executive performance reviews. Tie variable compensation to tangible ESG outcomes, not just the completion of disclosure requirements.
    • Scrutinize ESG Trade Offs: Institutionalize ESG risk and benefit analysis in capital allocation, procurement, and growth decisions. All major investments should be assessed for ESG exposure by the relevant committees before approval.
    • Align with Risk Appetite and Code of Conduct: Embed ESG criteria within the organization’s stated risk appetite. Clearly define what levels of trade off between short term gains and long term risks to reputation, compliance, or sustainability are acceptable and what are not.

    b. Risk Integration & Controls

    • Embed ESG in a Risk Based Framework: Integrate ESG into enterprise-wide risk identification, assessment, and escalation processes. Focus on what is material and purpose driven, ensuring ESG risks are treated with the same discipline as financial or operational exposures.
    • Expand the Risk Taxonomy and Assign Ownership: Update enterprise risk taxonomies to include exposures such as climate disruption, labour rights, data governance, and supply chain integrity. Ensure every function maps its relevant ESG risks into the central register with defined controls, owners, and mitigation plans.
    • Establish ESG-Linked Key Risk Indicators: Monitor leading signals such as supplier code violations, whistleblower reports, or environmental breaches. Set thresholds that trigger escalation through existing governance channels to avoid fragmented oversight.

    c. People & Accountability

    • Build Practical ESG Fluency Across Functions: Move beyond theoretical training. Equip operations, finance, procurement, and HR teams with role-specific ESG guidance that informs day-to-day decisions, trade offs, and escalation procedures.
    • Distribute Responsibility Across the Front Line: ESG ownership should not rest solely with sustainability or reporting teams. Link ESG responsibilities to operational roles, with measurable targets tied to control implementation, risk mitigation, and incident reporting.
    • Enforce Structured Escalation for ESG Breaches: Treat ESG failures with the same urgency as financial or operational breakdowns. Supplier violations, environmental incidents, or workplace grievances must trigger a formal response, including remediation steps and governance review.

    d. Data, Reporting & Technology

    • Integrate ESG into Risk and Control Systems: Move ESG from static reports to live data streams embedded in incident management tools, RCSA processes, and third party risk platforms. Ensure ESG risks and breaches inform how the organisation governs and responds in real time.
    • Design ESG Data for Actionability: Prioritise usability over volume. Enable procurement teams to flag supplier risks, operations to monitor environmental exposure, and risk committees to evaluate trade offs. Insight, not collection, is the objective.
    • Test Control Implementation, Not Just Documentation: Go beyond policy checklists. Monitor if ESG controls are actually followed, assess how they perform under pressure, and use internal audits to uncover weak links and emerging issues.
    • Use Technology to Scale Discipline, Not Bypass It: Leverage tools to centralise ESG data, trigger alerts, and map exposure. Technology should support control ownership and follow through, not replace it.

    Care should be take however when introducing ESG scoring systems powered by AI. When underlying data or algorithms carry historical bias, AI tools can amplify discrimination, skew assessments. Organizations must exercise caution and ensure AI tools are explainable, monitored, and contextually validated.


    Conclusion – Transitioning From Blueprint to Benchmark

    Embedding ESG into GRC needs more than intent. It requires ongoing assessment. The indicators below offer a practical way to evaluate how ESG risk is being integrated across key decision-making processes. They reflect whether ESG is influencing governance, operations, and risk management in a consistent and structured manner.

    These metrics go beyond compliance. When used thoughtfully, they provide insight into how ESG is shaping internal behaviours, influencing leadership decisions, and guiding procurement and oversight. Tracking trends across these indicators can help firms identify where integration is working and where it needs reinforcement.

    External certifications can play a supporting role, provided they are used to validate embedded practices rather than serve as stand-ins for them. When done right, they help demonstrate that ESG is being taken seriously in practice, not just on paper.

    For mid-sized companies at the ESG inflection point, the question is no longer about ticking the disclosure box. It is about control. True resilience comes from whether ESG risks are embedded into governance, operational controls, and decision-making frameworks.

    This is a structural shift requiring clear ownership, alignment with enterprise risk, and readiness to adapt. Real resilience comes from how ESG informs how a company governs itself, manages risk, and drives accountability.

    The real shift lies in moving from “Are we ESG-compliant?” to “Is ESG risk embedded in the way we govern, decide, and operate?”