Reading the Room Before It's a Finding: A Diagnostic for Governance That Reads Signals

A diagnostic for risk and governance leaders: can your function read a weak signal before it becomes a finding?

In April 2005 a rapid commuter train near Osaka took a 70 km/h curve at 116, derailed into an apartment building. One hundred and seven people died. That failure, told in full in the original article “The Station that Knew: On Governance that Cannot Read Signals,” was not a failure of information. It was a failure to read it. JR West had formal risk functions, reporting and governance. What it lacked was the ability to read the weak signals its own people and systems were already producing. The pattern is not particular to railways: Wells Fargo's account-opening figures told the same story for years before the bank acted on them as one.

Most organisations' risk reporting talks about emerging risk. This generally covers horizon scanning and early indicators, and sits on top of a governance function focused on reading and managing the familiar categories: financial, operational and compliance. These are mature disciplines. The ability to read weak signals, patterns below the threshold of action but too persistent to be dismissed as noise, receives less attention.

This piece is a diagnostic. It asks three questions about your own function, to test whether that gap exists. Each one makes visible a choice you have probably already made without noticing.

1) When someone sees a weak signal, does it have somewhere to go that is not the machinery built for findings?

In the years before the Amagasaki derailment, drivers on the line kept noticing things: timetables that left no margin, near-misses they quietly absorbed. The information existed. It simply had nowhere to go that would treat it as anything other than a driver's failing. In your organisation, where does that kind of report go?

For many, it is ingested into the same machinery which handles confirmed problems. Weak signals, often several at once, none conclusive alone, are asked for evidence they do not have, measured against a rubric which assumes the problem has already happened, and closed when they cannot meet those standards. The function was simply not designed to hold a hunch, or a yet-unvalidated pattern, long enough to determine whether it is real.

The harder challenge is not building this capability but protecting it: keeping it from being rolled into the existing machinery, where it will be held to the wrong standard and quietly blunted. It is a discipline before it is a department. But it still needs an owner, and in a regulated firm that owner is an accountable individual who already exists; it does not require a new one.

This is not only a matter of better indicators. A good key risk indicator suite catches a great deal – but an indicator only tells you about a risk someone already decided was worth watching. Weak signals are the other kind. JR West's method for grasping incidents was to wait for crew to report them, rather than to mine the data its own recorders already held. There was more in those records than anyone was reading. No one had been given the job. A metric without an owner is not a control. It is a record kept for the inquiry.

The test: ask to see the route a pattern-level concern actually took last quarter – where it was raised, where it went, where it sits now. If the only route runs through the process built for confirmed breaches, a weak signal has nowhere to go but the machinery built to close it.

2) What happens to the person who raises a concern that turns out to be wrong?

Consider the position of someone who notices something early. The pattern is real to them but not yet provable. If they raise it and they are right, there may be quiet credit once the thing has confirmed itself. If they raise it and they are wrong, the cost is immediate and personal: the time they took from colleagues, the meeting they called, the senior attention they spent on something that came to nothing. The reward is back-loaded and uncertain. The cost is front-loaded and sure. A rational person doing that arithmetic waits until the pattern is strong enough to survive challenge – by which point it is no longer an early signal but a confirmed finding, and the window has closed.

The function does not lose its early warning to bad people or bad culture. It loses it to ordinary people responding sensibly to the incentives around them.

Aviation faced a sharper version of this problem and solved it. Since 1976, US aviation staff report near-misses not to the regulator that can ground or fine them, but to NASA, which cannot. NASA strips out the identifying detail, finds the patterns across thousands of such reports, and passes the hazards to those who can act on them. Because the receiver has no stake in the reporter's fate, and because filing itself earns limited protection from the regulator, the reporting is honest, and the near-misses surface while they can still be acted upon.

A corporation cannot build a NASA. There is no neutral, stake-free receiver inside a company. But it can create distance: whoever receives a weak signal should have no hand in judging the person who raised it.

None of this is whistleblowing, and the distinction matters. Most jurisdictions already mandate a protected channel for disclosable conduct: whistleblower regimes, mandated by statute across the UK, US, EU and Australia, and by listing rules and corporate codes in parts of Asia. They exist for a specific and serious category: wrongdoing, breaches, danger to the public. A weak signal rarely starts as any of those. The statutory regime was not built for weak signals, and routing early patterns through it either inflates them into allegations they are not, or sees them thrown out without further investigation. The channel this piece describes sits alongside the whistleblower regime, not inside it, and does the work the statute was never meant to do. None of this diverts a genuine disclosure from the protected channel. That route must remain.

The design question is narrower than it looks. Three things have to hold. The act of raising a concern must be insulated, as far as anything can be, from the individual's performance review. The judgement to raise it must be recognised on its own terms, not only when it turns out to be right. And the record must not score people for being wrong: investigated and closed is honest; false positive presumes a correct answer existed at the time, which for a weak signal it did not.

The obvious objection is that this licenses crying wolf. It does not, because what it protects is the substance of an honest concern that did not pan out, and nothing more. Fabrication, bad faith, raising a flag to damage a rival: these are different matters, handled as they always were. The line between bad faith and honest-but-wrong will always be governed by professional judgement, usually made in hindsight, often by the same people the protection is meant to hold at arm's length. No structure removes that judgement entirely. What a good one does is raise the bar for treating a wrong concern as misconduct, and put the decision somewhere other than the desk of the manager whose work was questioned. The protection is for honest judgement. It was never meant to cover everyone.

The test: find someone who raised a concern in the last two years that came to nothing, and ask whether they would do it again. Their answer is the state of your architecture, whatever the policy says.

3) Can your function see a pattern forming between reporting cycles?

Governance runs on a calendar. This is appropriate for deliberate decisions, which should be made with evidence and at a measured pace. It is poorly suited to a pattern that forms in the six weeks between two meetings and is eight weeks old by the time anyone whose job it is to act on it is in the room.

Reading signals in real time does not mean replacing the calendar. It means having something alongside it: a standing point at which the current pattern landscape is reviewed at higher frequency than the board cycle, an agreed authority to pull a developing concern forward to the risk committee chair ahead of the next scheduled slot when it crosses a threshold, and a sharper setting during periods of known strain, such as a restructure, an integration, or a leadership change – when the signals matter most and the organisation is least inclined to look.

This costs something, and the cost is worth naming. It is senior attention, the scarcest thing a governance function spends, and the discipline to keep the exercise from slumping into one more status meeting that reviews what is already known. For an organisation in a high-consequence sector, that cost is smaller than the failure it guards against. For others it is a real trade-off, honestly made. The point is not that every function should build it, but that a leader should know whether theirs has.

The test: ask when the function last brought a concern to the board off-cycle, on the strength of a pattern rather than a finding. If the answer is never, the function runs on the calendar alone, which may be the right design, but should be a decision rather than a default.

What the three questions have in common

None of these is, in the first instance, a question about culture. Not because culture does not matter, but because culture is downstream. It forms in response to the structure around it. That is the argument the original piece makes at length. The enforced system, not the stated one, is what shapes how people actually behave. Structure comes first. It does not remove the human judgement at the centre of all this, but it shapes and constrains it – and it is the part a leader can actually decide: how the function is built, what it is allowed to hold, who is protected, and when it is permitted to look. You cannot mandate a culture into being. You can build the structure it forms inside. Most of the time, that structure is the thing no one chose to examine.

Answering all three questions honestly means going and looking: pulling the actual escalation cases, asking the people who raised them, finding out what happened to those people afterwards. The going-and-looking is the diagnostic. The answers are usually less comfortable than the policy would suggest.

Governance is not, in the end, what is written in the framework. It is what happens to the person who notices something before the system does.

Comments

All posts loaded No posts found VIEW ALL Read more Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS No posts found Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS CONTENT IS LOCKED STEP 1: Share to a social network STEP 2: Click the link on your social network Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy Table of Content