,

How to manage risk and resilience using the 5 capitals model 

Most organizations still run risk management and resilience planning as separate functions. A 5 capitals model shows why treating them as one builds real business resilience.  Key takeaways for this risk and resilience guide   Introduction: flipping the risk management coin  A few years ago, one UK firm made a small, telling change. Its risk and…

Corey Avatar

Most organizations still run risk management and resilience planning as separate functions. A 5 capitals model shows why treating them as one builds real business resilience. 

Key takeaways for this risk and resilience guide  

  • Risk management and resilience planning are too often run as separate functions, often sitting in different departments, covering much of the same ground without talking to each other. 
  • “Resilience” earns a warmer boardroom reception than “risk”. Framing the same work around outcomes people want, rather than threats they fear, changes how leaders engage with it. 
  • A 5 capitals model, people, reputational, operational, financial and environmental, forces an organization to name the essential outcome each capital cannot afford to lose. 
  • Resilience regulation started in financial services, but NIS2 and the UK’s governance code show the same expectation now reaches critical sectors right across the economy. 
  • Building genuine business resilience starts by naming those essential outcomes now, not by waiting for a regulator to force you. 

Introduction: flipping the risk management coin 

A few years ago, one UK firm made a small, telling change. Its risk and assurance department kept the same people, the same mandate and the same reporting lines. All that changed was the name on the door: assurance became resilience. Almost overnight, work that had struggled for attention started getting it. Another organization went further, folding its entire ESG program into what it now calls its strategic resilience program. (Risk is our Business podcast, episode 24

Neither firm changed what it does. Both changed how the business hears it. 

The gap between what risk management actually is and how well it gets heard is often reflected in organizational structures: enterprise risk typically reports through legal, finance or internal audit, while business continuity and crisis management, the resilience side of the same equation, usually sit in IT or another department entirely, running as a separate function but covering much of the same ground. The two rarely speak to each other. 

Emma Price, a risk and resilience specialist with close to 25 years’ experience across financial and non-financial sectors and now a partner at the governance consultancy BRAVE, has a simple way of describing the fix. Risk and resilience, she argues, are “two sides of the same coin”. Treat them as one discipline, built around a small number of “capitals” an organization can’t afford to lose, and the result is much more useful. Rather than a long list of things that could go wrong, you have a short list of outcomes worth protecting … and a much clearer basis for board-level decisions. 

This matters well beyond banks and insurers. Resilience regulation may have started in financial services, but today it reaches across every sector from healthcare to utilities. 

Why “resilience” earns a better hearing than “risk” 

Ask most risk professionals why their work is hard, and sooner or later they mention a hearing problem, not a thinking problem. The analysis is sound. The audience switches off. 

As GRC analyst Michael Rasmussen puts it: 

“Risk is a scary word. Who wants to own risk? They pass it around like a hot potato. But you put that resilience word next to it. What business process owner or business manager or executive doesn’t want to be resilient?” 

Michael Rasmussen, GRC Analyst & Pundit, GRC 20/20 Research 

Price’s own client conversations support this

“Risk still carries a bit of a stigma with the fun police, the Department of No, whatever you want to call it. Resilience just feels a lot more proactive.” 

The distinction is more than cosmetic. A team framed around avoiding downside spends its political capital defending a veto. A team framed around protecting outcomes the business already values gets invited into the conversation before, not after, the decision is made. 

That reframing has institutional backing. McKinsey’s resilience research, surveying more than 250 private-sector leaders across industries and regions, found:  

  • 84% feel underprepared for future disruptions,  

The report argues that resilience “must become a core strategic priority rather than a reactive afterthought.” 

Deloitte’s analysis of the risk-resilience relationship makes a related point from a different angle: risk and resilience teams often work with closely related concepts, appetite and impact tolerance, likelihood and plausibility, without a shared vocabulary to connect them. 

Both studies point to the same fix: stop running risk and resilience as separate functions translating for each other, and start running them as one. 

The 5 capitals of resilience and the “essential outcomes” test 

In a research report, The Five Capitals of Organizational Resilience, Deloitte argues the need to build resilience across 5 “capitals” that comprise the ecosystem in which organizations operate

  1. People – the way the organization supports its own people, fostering creativity, instilling and instituting cultural norms, conduct and behavior. 
  1. Reputational – responsiveness to external perceptions, building brand capital, maintaining a foundation of trust and dependability.  
  1. Operational – how the organization uses its non-financial resources to withstand or adapt to shocks and stresses. 
  1. Financial – an organization’s ability to withstand events that impact its liquidity, income or assets.  
  1. Environmental – how the organization operates within the natural world (sustainability, climate change, etc.).  

For each capital, the exercise asks a single, deceptively hard question: what is the essential outcome or objective this capital exists to deliver, the thing the organization absolutely cannot afford to lose, whatever the cause of disruption? 

The clearest explanation of that question comes from a 2021 paper commissioned jointly by the UK’s National Preparedness Commission, Cranfield University and Deloitte. It borrows a line from the marketing theorist Theodore Levitt:  

“People don’t want to buy a quarter-inch drill. They want a quarter-inch hole.” 

David Denyer and Mike Sutliff, ‘Resilience Reimagined: A Practical Guide for Organisations’, National Preparedness Commission, Cranfield University and Deloitte 

Applied to resilience, the point is that the asset, the drill, is rarely what matters. The outcome it produces is what matters. If the drill breaks, the organization’s job is to find another way to make the hole, not to mourn the drill. 

Put into practice, an essential outcome reads less like a risk register entry and more like a promise.  

For the financial capital, it might be the ability to meet payroll and settle supplier invoices through a 30-day disruption, regardless of the cause. For the people capital, it might be keeping frontline and customer-facing staff safe and paid, whatever else in the business has gone wrong. For the reputational capital, it is usually the ability to keep the trust of customers and regulators who were already loyal before the disruption began, rather than simply managing the immediate headlines. 

“The five capitals model gives a CFO and a plant manager the same vocabulary. That’s the reason it works better than a risk register: everyone in the room can see what they’re actually protecting and why.”

Paul Cadwallader, GRC Strategy Director, CoreStream GRC 

Naming those outcomes in advance changes how a business behaves under pressure. Instead of asking, mid-crisis, what could go wrong next, teams already know what they are protecting, and can focus every decision on defending it, as they’re clearly tied back to business objectives. 

Resilience regulation now reaches every sector 

Having started in financial services, where the EU’s Digital Operational Resilience Act (DORA) and Australia’s Prudential Standard CPS 230 now set detailed rules for ICT risk, testing and third-party oversight, resilience regulation now reaches across critical sectors well beyond banking and insurance. 

The EU’s NIS2 directive extends cybersecurity and resilience obligations to around 18 sectors, energy, healthcare, water, waste, transport, manufacturing of critical products, digital infrastructure, postal services, space and public administration among them.  

Provision 29 of the UK Corporate Governance Code, which applies to every premium-listed company regardless of sector, already requires directors to explain the risk-management and internal-control systems that support the business’s ongoing viability. 

In the US, the picture is more fragmented though the direction is equally clear. “Sound Practices to Strengthen Operational Resilience,” issued jointly by the Fed, OCC and FDIC targets the largest US banks while the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA, due to be finalized in September 2026) requires covered entities across critical infrastructure sectors to report significant cyber incidents to CISA within 72 hours and ransomware payments within 24 hours. At the same time, the SEC’s 2023 cybersecurity disclosure rules require every US public company, regardless of sector, to describe board oversight of cybersecurity risk in its 10-K and to disclose material incidents within 4 business days. 

Whatever the regulation, whichever the country, a hospital trust, a water utility or a mid-market manufacturer has no less need than a bank to know its essential outcomes. 

Resilience beyond financial services 

The five capitals model works across all sectors.  

A manufacturer’s operational capital is rarely about a single production line; it is about the ability to keep making product when one supplier, one machine or one site goes down.  

A hospital trust’s people capital has nothing to do with a compliance filing; it is about patient and staff safety holding through whatever has disrupted normal operations.  

A utility’s environmental capital is not a sustainability report; it is the grid’s ability to stay up through the extreme weather events becoming less exceptional every year.  

A retailer’s reputational capital is the trust that survives a supply chain failure or a data incident with customers still willing to shop there afterwards. 

None of these organizations needs DORA, CPS 230 or NIS2 to tell them this work matters. But the recent regulatory wave provides risk and resilience teams with impetus along with a well-tested vocabulary to borrow – 5 capitals, essential outcomes, tolerance for disruption – rather than inventing their own from nothing. 

Stop starting with risk and focus on what you cannot afford to lose 

Naming essential outcomes is the starting discipline. Using them to make decisions, every week rather than once a year, is where most organizations still fall short. 

At Gartner’s Enterprise Risk, Audit and Compliance Conference, held in North America this September, Gartner’s Nancy Queally described the shift in ambition:  

“The future of GRC is not about managing more risk. It is about helping the organization achieve its objectives in the face of risk.” 

Nancy Queally, Managing Vice President. Advisory, Gartner 

Gartner’s own research, presented at the same event (and described in the recent key takeaway blog), found that: 

  • Only 33% of business leaders can translate risk insight into concrete action, even as… 
  • 64% of boards agree their organization should be taking on more risk, not less. 

Insight, in other words, is rarely the bottleneck. Application is. 

This is the gap that CoreStream GRC and the governance consultancy BRAVE aim to close with Objectives@Risk™. 

Objectives@Risk™ begins with an organization’s objectives and essential outcomes, then connects them to critical obligations, risks and risk appetite, scenarios, dependencies, controls, assurance and performance outcomes. Carolyn Clarke, BRAVE’s founder, describes the problem it addresses in terms any board will recognize: 

“Experience has demonstrated directors struggle to see the wood for the trees. Information is fragmented and disconnected from the reality of discussions in the boardroom and c-suite. Risk, at best, becomes a discussion of potential hazards, rather than a meaningful conversation about how to deliver on objectives and priorities.” 

Carolyn Clarke, Founder, BRAVE 

Price frames the shift in similar terms:  

“The conversation has shifted from identifying risks to navigating uncertainty… organizations don’t need another static list of risks. They need clarity on the outcomes they must deliver, the objectives that matter most.” 

Emma Price, Partner, BRAVE 

That thinking aligns with CoreStream GRC’s work on value-based GRC: that the point of a GRC program is not the length of its risk register but its confidence in the organization’s ability to hit its objectives.  

“Value-based GRC empowers an organization to achieve the right objectives with confidence.” 

Paul Cadwallader, GRC Strategy Director, CoreStream GRC  

5 capitals, essential outcomes and Objectives@Risk™ all point to the same underlying discipline: stop starting with the risk, and start with what the organization cannot afford to lose. It is a different lens on the same interconnection problem we explored in our recent look at how cascading risk catches organizations out. There, the fix was mapping how risks depend on each other; here, it is naming the outcomes that connection is ultimately protecting. 

Conclusion: it’s time to rebrand risk with resiliency 

The firm that renamed its risk department didn’t solve resilience by changing a sign. What it did was remove a barrier that had nothing to do with the work and everything to do with how the work was heard. 

The harder job, the one that actually builds resilience, is naming the essential outcomes across people, reputational, operational, financial and environmental capitals, then connecting those outcomes to the risks, controls and decisions that protect them, continuously rather than once a year. That work shouldn’t wait for DORA, CPS 230, NIS2 or CIRCIA to arrive in your sector. It starts with a conversation your board can have this quarter. 

If you would like help having that conversation, CoreStream GRC offers a one-hour, bespoke workshop with GRC Strategy Director Paul Cadwallader and your enterprise risk and compliance team, covering practical steps to connect your organization’s objectives, risks and resilience into one confident view.  

Frequently asked questions about risk and resilience 

What’s the difference between risk management and resilience?  

Risk management identifies and assesses threats across the whole business, usually reported upward periodically. Resilience narrows that lens to five capitals (people, reputational, operational, financial and environmental) and asks what essential outcome each one must deliver through disruption. Run together, they support faster, more focused decisions than either discipline manages alone. 

What are the “five capitals” of resilience?  

Deloitte’s organizational resilience research names five: people, reputational, operational, financial and environmental capital. Each represents a category of value an organization depends on, and the exercise is naming the specific outcome within each one that must survive a disruption, whatever form that disruption takes. 

Does my organization need to worry about DORA or CPS 230 if it isn’t a regulated financial firm?  

Not directly; both apply only to financial entities, in the EU and Australia respectively. But the EU’s NIS2 directive already extends similar obligations to around 18 sectors, including energy, healthcare, manufacturing and water, and the underlying discipline, naming essential outcomes before a regulator asks, applies to any organization. 

What’s the difference between DORA and NIS2?  

DORA is financial-services specific, covering roughly 20 types of EU financial entities and their technology providers. NIS2 is broader, covering around 18 sectors across energy, health, transport, manufacturing, water and public administration. Both address operational resilience, but NIS2 reaches far beyond banking and insurance. 

What is Objectives@Risk™? 

Objectives@Risk™ is a joint offering from CoreStream GRC and governance advisory firm BRAVE. It provides a practical framework that links governance strategy with day-to-day execution, helping leaders navigate uncertainty with confidence by connecting governance, risk, resilience, and performance around the outcomes that drive success. 

What is meant by “essential outcomes” in resilience planning?  

An essential outcome is the specific result a capital must keep delivering through a disruption, not the asset or process that normally delivers it. As the UK’s National Preparedness Commission’s 2021 paper puts it, borrowing from Theodore Levitt: customers don’t want a quarter-inch drill, they want a quarter-inch hole. 

  • How to manage risk and resilience using the 5 capitals model 

    How to manage risk and resilience using the 5 capitals model 

    Most organizations still run risk management and resilience planning as separate functions. A 5 capitals model shows why treating them as one builds real business resilience.  Key takeaways for this risk and resilience guide   Introduction: flipping the risk management coin  A few years ago, one UK firm made a small, telling change. Its risk and…

  • From risk management to business outcomes: what Gartner’s GRC insights mean for risk leaders 

    From risk management to business outcomes: what Gartner’s GRC insights mean for risk leaders 

    Risk leaders do not need more information. They need more of the right context.  That was one of the clearest themes we took from the 2026, North American, Gartner’s Enterprise Risk, Audit and Compliance Conference. Across sessions the conversation repeatedly came back to a bigger question: how can GRC help organizations make better decisions and…

  • The future of risk, cybersecurity, and due diligence: Key insights from CoreStream GRC’s upcoming industry panels 

    The future of risk, cybersecurity, and due diligence: Key insights from CoreStream GRC’s upcoming industry panels 

    If there is one theme that has emerged from CoreStream GRC’s news and insights coverage throughout 2026, it’s this: Risk is becoming more interconnected, more technology-driven, and more business-critical than ever before.  As preparations begin for Risk Expo Europe 2026 and XapienXchange London 2026, many of the questions dominating boardrooms today are the same issues CoreStream GRC has been tracking throughout the year:   The result…