Overcoming Risk Management “Vibes”
Can a meditation on the alchemy of Foley artists shake the risk profession out of its “this feels right” mindset?
TL;DR: Flawed processes that “feel right” are prevalent within organisations, even when there is little evidence that they work. Risk management is not immune. Widely used risk tools and practices may be giving false comfort simply because they look and feel right.
Risk teams need strong decision analysis capabilities to challenge this kind of thinking: not just asking whether a proposal feels plausible, or can be falsified, but whether it is supported by clear logic, evidence, uncertainty analysis, and (wherever possible) quantification.
As a profession, risk also needs to get into the habit of testing its own methods. If a risk tool or process cannot show that it improves decision-making, we should change our approach.
The views and opinions expressed on this account are my own and do not reflect the official policy or position of my employer. Any content provided is for informational purposes only and should not be considered or relied upon as professional advice.

Organisations and senior business leaders report relying on their "gut", instincts and personal experience for 40%-80% decisions, based on multiple studies. Research also supports the idea that the management systems - the set of rules, plans, and steps that a group or business uses to enable decision-making - are themselves often introduced with on a similar basis. Thinking about the Foley artist profession can give us an insight into why "this feels right" management can be so prevalent, and yet so invisible.
Foley artists: a hidden profession
Foley artists are sound magicians. Named after Jack Foley, an early pioneer of the craft, they create the soundscape of film and television. Their work gives scenes texture, weight and realism, helping the audience believe what they see. A dropped cardboard box becomes a heavy block when paired with a loud, deep thud.
In fiction
Foley artists can turn the mundane into the fantastical: a hammered metal cable becomes a laser gun; an elephant’s shriek played backwards turns into a TIE fighter; the slowed sound of a crushed car is now the roar of a T Rex; dog food sucked from a can is the uncanny sound of the T-1000 squeezing through metal bars.
They are so good that most viewers never notice how much sound is added after filming. Foley artists specialise in making things "feel right". They recreate sounds we think we know: doors slamming, floorboards creaking, people kissing. Over time, some of these invented sounds become part of how we think the world really sounds. Bullets do not “ping” [i]. Snow rarely crunches. Swords are silently drawn from leather scabbards. Guns do not cock loudly. Breaking bones sound far less, well, moist.
In nature documentaries
Nature documentaries rely on Foley work too. In retrospect, this can’t be too much of a surprise. Cameras can zoom from long distances and go underwater. Microphones need to be close to the sound, surrounded by air, and protected from background noise. In the now standard nature doc “making of” featurette, the rugged cameraman sitting eyes-deep in a putrid swamp is not accompanied by a baggy-t-shirt-and-joggers boom operator.
As in fiction, the documentary Foley artist has two main jobs. The first is to recreate sounds that are real but were not captured[ii]: animals walking, chewing or breathing, for example. Wing beats are made by flapping gloves. A fish splash is a hand swishing through water. Animal cries are taken from sound libraries.
The second job is stranger: to invent sounds that do not really exist. Television abhors silence, so moving things must have a sound. Silent snakes slither audibly. Insects can be heard as they stretch, walk and spin webs. Foley artists have even created sounds for a bear opening its eye and blinking[iii].
In live sports
If that blows your mind (watermelon or pomegranate are industry standard for exploding brains), then just wait for live sports. Sports audio usually falls into four broad categories:
Authentic sound that represents what spectators hear, but with dampened crowd noise (think football, rugby and tennis).
Authentic sound that represents what competitors hear, such as diving, where viewers hear sound from above and below the water, or curling, where team members are miked up.
Authentic enhanced sounds that are only experienced by the broadcast audience, such as an amplified dartboard or microphones placed between an archer and their target to capture the arrow whistling through the air. [iv]
Synthetic sounds recreating what microphones could not capture, or that may not exist at all. A horse race is accompanied by a slowed-down buffalo charge. The sound of oars slicing the water are taken from a sound library, cleaned up and layered onto a boat race. Skiing sounds are manufactured.
So What?!
Foley work is invisible because it “feels right”. It does not break the illusion that sound and image are connected, and so we don’t question it. Even when it should be obvious that sounds could not have been recorded we accept it as the truth. We may even resist losing sounds we discover are fake – the sound of a bullet ricocheting – because we have come to expect them.
That matters for organisations, and for risk management teams because organisations often substitute "this feels right" for "this is supported by evidence". The fact that they feel so right makes them hard to spot and challenge, leading to poor decisions, blind spots, and false assurance.”[v]
“This feels right” in organisations
Managers often rely on tradition, anecdotes, intuition, benchmarking and fashionable management ideas rather than evidence to support decision-making[vi]. This creates decision processes based on beliefs that feel “right" but may not be supported by much proof.
Ideology
Management beliefs can be hard to shift when they are rooted in personal experience, ideology, industry norms, or culture. These beliefs become even harder to challenge when they are built into regulation, either directly or because they are the easiest way to evidence compliance.
Ideology is one of the biggest barriers to evidence-based management. People can become so attached to their theories that they struggle to accept evidence that challenges them. Managers are not immune to this effect: they may become more or less sceptical of an idea depending on whether it fits their existing worldview.
In a previous post, I explored how ideology becomes more influential when there is less data to support a decision. The best way to reduce this risk is to be clear about two things: what problem are we trying to solve, and what evidence would show that a proposed solution works?
Implementing management systems
Management systems - the set of rules, plans, and steps that a group or business uses to reach its goals - are often introduced with limited evidence that they actually work. Research suggests they are often copied from systems leaders have seen before, recommended by consultants, or copied from companies that appear successful.
This creates a common problem. Organisations copy the visible parts of another company’s system without understanding the culture, context or logic that made those practices work. They may also copy practices that are not well matched to their own environment.
The key questions are simple: “Why does a given practice enhance performance? And what is the logic that links it to bottom-line results? If you can’t explain the underlying theory, you are likely engaging in superstitious learning, and you may be copying something irrelevant or even damaging – or only copying part (perhaps the worst part) of the practice.”[iv]
Implications for decision-making
When senior leaders have to rely on subjective judgement it can push them towards a “this feels right” test rather than an evidence-based one. It also makes it easier to miss limitations or flaws in the decision-making process.
The test becomes “does this explanation feel plausible?” rather than “how confident are we that this explanation is correct?” Without objective analysis and challenge, a complex but well-evidenced explanation can lose out to a simpler story that feels acceptable and is easier to defend politically.
What does this mean for risk teams?
This creates a challenge for risk teams. It is difficult to challenge a business that makes decisions, sets strategy or implements management systems on the basis of what feels right. Risk teams therefore need to strengthen their role in decision analysis and strategic challenge. Many risk issues are not isolated failures; they are symptoms of weak decision-making, which is more likely when it is based off "this feels right" thinking.
Applying the “this feels right” test to risk management
The more uncomfortable question is what happens when we apply the same lens to risk functions themselves: our tools, our approach to business engagement, our assessments, and our reporting. How much of what we do survives because it feels right? How much would survive objective, evidence-based scrutiny?
Risk appetite
The standard approach to risk appetite frameworks may be an example of copying visible practices without fully understanding why they appeared to work. After the 2008 financial crisis, regulators noticed that firms with risk appetites tended to perform better than those without. This helped turn risk appetite into a regulatory expectation across most areas of the business.
But was the conclusion justified? Did those firms perform better because they had risk appetite statements? Or did they perform better because their boards were already having disciplined, quantitative conversations about their most material risks, and used risk appetite only where it helped the firm to better manage those risks? In that version of the story, risk appetite was a symptom of better risk management, not the cause.
In financial services, it now “feels right” to create risk appetites for almost every risk type, whether or not they improve decision-making, support delegation or help the business make good trade-offs. This can, paradoxically, lead to worse risk management, as risks with poorly designed risk appetites end up facing less scrutiny due to the false assurance the appetite framework provides.
Risk matrices
Tony Cox’s research[vii] is highly critical of the risk matrices many teams use for scoring and ranking risks. He demonstrates that they:
Have poor resolution, meaning very different risks can receive the same rating.
Can give higher qualitative ratings to risks that are actually smaller in quantitative terms.
Can support poor allocation of resources when used to prioritise risk mitigation options.
Can produce ambiguous inputs and outputs, especially when scoring depends on subjective judgement that is not consistent across subject matter experts.
Can result in ambiguous inputs and outputs that are not replicable across subject matter experts.
Risk matrices also encourage organisations to focus on one probability, or a small number of probabilities. This conflicts with how risk owners usually manage uncertainty. Cox concluded that “These limitations suggest that risk matrices should be used with caution, and only with careful explanations of embedded judgements.”
So why do we keep using them? Because they feel right. They are familiar. Other companies use them. They are cheap and easy to explain. Regulators and stakeholders expect them. None of these is a strong argument that they improve decisions.
Claiming to have zero risk appetite
Many organisations respond to extreme downside risks by saying they have “no” or “zero” risk appetite. This "feels right”, or at least it “feels wrong” to admit that the organisation operates in a way that could allow the bad thing to happen, however remote the possibility. But unless the organisation can take actions that make the risk physically impossible, “no appetite” is an expression of hope rather than appetite.
I do not want to die in a plane crash, but if I choose to fly, I clearly accept some level of exposure. Organisations need the same honesty. If they refuse to acknowledge real exposure, they may avoid necessary conversations on the appropriateness of the strategy, or the effectiveness of the control framework.
Risk scoring as an expression of “fairness” rather than “risk”
Risk scoring often involves subjective judgement. But those judgements are coloured (pun intended) by what “feels right”.
Scores can quickly move to amber or red for underperforming business areas with little justification. This happens because stakeholders often confuse poor performance with poor risk management, even though performance and risk are different concepts. The reverse can also happen: an adverse risk score for a team with a reputation for good delivery is more likely to face scrutiny.
There is also often a demand for fairness. Risk scores are expected to reflect effort and delivery, rather than uncertainty. Internal failures are amplified through risk scoring, whereas material shifts in the risk environment driven by external changes are downplayed. How many InfoSec risk scores have moved in response to the new external risks created by the latest round of AI model releases? A focus on fairness and performance in risk scoring anchors risk assessments to a historic understanding of the business and limits a firm's ability to respond to emerging threats and a changing understanding of the risk environment.
Oversimplifying risk tools
Effective risk management depends on clear communication and actionable insight. That is uncontroversial and well supported by evidence. But the idea can drift into a damaging simplification: that every formal risk tool must be transparent to the business, owned by the business, and easily understood by all stakeholders. This can limit the complexity of risk tools and analysis, and so limit their usefulness. I am convinced the evidence from organisational psychology research does not support a simplified risk toolset . In fact, that concern is one reason I started this blog.
So What?!
Risk teams need to build stronger decision analysis norms and capabilities. We need to challenge flabby “this feels right” thinking in the business, especially where it shapes strategy, management systems and major decisions.
This is hard. Decisions that are made with intuition are difficult to spot and even harder to change. Think how long you have watched nature documentaries with completely manufactured soundscapes without noticing, because they “felt right”.
Risk functions also need to apply the same standard to themselves. As a discipline, we should test the business benefit of our tools and methods. If a process cannot show that it improves decisions, clarifies accountability, supports better trade-offs or provides meaningful assurance, we should be willing to redesign it or let it go.
How do we do this?
A useful first step comes from Oxford’s Centre for Evidence-Based Medicine: frame the situation as a clear, answerable question. Once the question is clear, it is much easier to decide what evidence is relevant to support the decision and determine how success should be judged.
Evidence-based management requires leaders to put aside belief, habit and conventional wisdom — the dangerous half-truths that organisations often rely on — and focus instead on the facts needed to make better decisions. This does not mean waiting for perfect evidence. Businesses often need to act quickly, and evidence is often incomplete. But decisions can still be designed so they can be tested, refined or abandoned as new evidence emerges.
When risk teams challenge decisions, they should ask five questions: was the decision framed as a clear question; what evidence supports the answer; could quantification have improved the decision-process; has sufficient uncertainty analysis been undertaken; and how will the outcome be validated later? If those steps are missing, there is a good chance that “this feels right” thinking has filled the gap. Risk teams should apply the same discipline to their own work: why are we introducing this process or tool, what decision or assurance need does it serve, and how will we know whether it has worked?
I hope this blog sparks ideas and discussion. If you found it interesting, please share or connect with me on LinkedIn to contribute or provide feedback!
[ii] https://www.northumbria.ac.uk/about-us/news-events/news/expert-comment-the-animal-sounds-in-nature-documentaries/
[iii] https://www.businessinsider.com/how-foley-sound-effects-are-made-for-nature-documentaries-2020-12
[iv] 99% invisible podcast: sound of sports
[v] Evidence-Based Management, Pfeffer & Sutton, January 2026, Harvard Business Review
[vi] Pfeffer & Sutton (2006) Hard Facts, Dangerous Half-Truths, and Total Nonsense
[vii] Cox, L.A. (2009). Limitations of Risk Assessment Using Risk Matrices. In: Risk Analysis of Complex and Uncertain Systems. International Series in Operations Research & Management Science, vol 129. Springer, Boston, MA. https://doi.org/10.1007/978-0-387-89014-2_4



Comments