As institutional narratives increasingly diverge from objective realities, Chief Risk Officers must transition from ERM overseers to architects of ground truth.
For decades, enterprise risk management (ERM) operated on a foundational, often unstated assumption: While the future is uncertain, the present is knowable and somewhat predictable. Risk professionals relied on data from government agencies, legislative bodies, and the judiciary as stable baseline truths. If a government agency published an inflation or unemployment metric, a legislative committee released a staff report, or a court ruled on legal precedent, corporate risk models treated these inputs as ground truths.
In 2026, that assumption is not one corporate leaders can afford. We are operating in what philosophers and political theorists classify as a "post-truth" era, where institutional narratives may be manufactured to satisfy ideological alignments rather than empirical facts. From regulatory rollbacks shaped by corporate lobbying to high courts favoring personal interpretations over long-standing judicial precedents, federal institutions have drifted toward narrative construction.
Brenda Boultwood
This is not a partisan critique; it is a profound operational hazard. As Hannah Arendt warned in her seminal work on truth and politics, the danger of modern institutional distortion is not merely that a specific lie is told, but that the shared sense by which we perceive reality is actively degraded. For the CRO and Chief Executive Officer committed to long-term organizational sustainability, this environment requires an epistemological upgrade. Risk managers can no longer just be data consumers; they must become architects of truth.
To survive this era, ERM must ground itself in what Italian philosopher Maurizio Ferraris calls "New Realism" and the concept of unamendability. Ferraris argues that regardless of our internal filters, linguistic frames, or political desires, reality exists as an objective truth. A government may declare a supply chain secure or the crypto asset class stable, but the physical and economic reality will remain unamendable. If your risk models are built on institutional narrative rather than objective truth, reality will eventually break your organization.
ERM Framework Under Epistemic Siege
To manage risk when institutional data inputs are compromised, leadership must systematically re-engineer the four core pillars of traditional enterprise risk management.
Risk Identification: Piercing the Ideological Frame
Traditional risk identification relies heavily on scanning the external environment for legislative, regulatory, and geopolitical shifts. However, in a post-truth environment, the language used by external authorities is often heavily wrapped in what cognitive linguist George Lakoff calls "frames," or metaphors designed to dictate what the audience accepts as true.
When a legislative body or an administration labels a policy initiative, the title frequently obscures the underlying operational impact. Risk identification must move past these "hot" metaphors and look directly at the mechanics of the policy.
If an administration frames a trade restriction or an environmental policy through the lens of national security or economic liberation, the risk manager must strip away the narrative. The identification process must ask, What are the raw physical realities of this policy on our supply lines, inputs, and capital requirements, regardless of how the policy is branded?
Risk Assessment: Epistemology vs. Ontology
The core failure of modern risk assessment is the confusion between epistemology, or what we think we know based on reports, and ontology, what actually exists and in some form is the basis for our risk taxonomy. When a high court discards decades of precedent based on subjective interpretations, the legal risk assessment cannot simply adjust the compliance risk framework. It must assess the structural stability of the legal environment itself.
In this context, the philosopher Harry Frankfurt’s distinction between a liar and a "bullshitter" becomes a vital diagnostic tool for risk assessment. A liar knows the truth and attempts to hide it; a bullshitter simply does not care about the truth, focusing entirely on the immediate utility of the claim.
When assessing institutional guidance, risk managers must evaluate whether the data coming from public sources is based on empirical evidence or institutional bullshit designed for political consumption. If an agency alters its reporting metrics to show a politically favorable outcome, the risk assessor must discount that data and seek commercial sources to devise approaches to independent verification.
Risk Measurement and Analysis: Activating the Scientific Attitude
Risk measurement requires clean data, but digital algorithms and institutional capture have turned data into a product designed to feed tribal passions rather than Aristotelian logic. Political theorist Ignas Kalpokas notes that social media algorithms have commoditized information to satisfy emotional biases. This pollution quickly bleeds into corporate data feeds, market sentiment analysis, and economic forecasting models, reflecting “vibes.”
To counteract this, risk analysis must adopt what philosopher Lee McIntyre calls the "scientific attitude," a ruthless commitment to data integrity and a willingness to hold models accountable to empirical results, even when those results contradict corporate or political custom. Risk managers must aggressively stress-test models against worst-case "realist" scenarios. If the organization’s financial models assume the stability of an institutional data point, the risk analysis team must build parallel models that assume that benchmark is artificially inflated or politically manipulated.
Risk Reporting: Moving from Coherence to Correspondence
Corporate risk reporting often falls into the "neutrality trap." To avoid appearing political or confrontational, internal risk reports frequently present conflicting narratives with equal weight, often balancing hard empirical data against institutional rhetoric. This represents a reliance on a "coherence" theory of truth where an explanation fits neatly within a comfort zone.
Effective risk reporting in a post-truth world must demand a "correspondence" theory of truth. We must ask, Does the internal assessment match the external, unamendable world? Risk reports delivered to the board and CEO must be blunt, clear, and stripped of mitigating rationale. If an administrative policy is fundamentally unworkable or built on false premises, the risk report must state that directly, providing the leadership team with a clear baseline for strategic decision-making.
Managing Risk in a Post-Truth Environment: Some Examples
The consequences of failing to independently verify institutional and corporate narratives are already shaping global markets.
Case 1: The Nvidia-Huawei Information Failure
A stark example of the dangers of narrative-driven decision-making occurred when Nvidia provided reports to the administration regarding rival Huawei’s technological capabilities. Seeking to protect its market share and render export control policies less restrictive, Nvidia emphasized a corporate narrative of competition from foreign state-backed capabilities.
The administration, prioritizing immediate decisions over empirical verification, accepted these corporate assertions without gathering rigorous, independent intelligence. By basing sweeping federal export restrictions on an unverified, self-serving corporate narrative, the administration failed to apply a strict correspondence test to the data, resulting in adversary access to sophisticated U.S. chips.
Case 2: The Boeing Safety Narrative vs. Engineering Reality
For years, aerospace giant Boeing substituted an internal compliance narrative, or a coherence model of truth, for physical engineering safety tolerances, an unamendable ontological reality. Corporate leadership and regulatory oversight teams increasingly relied on checked boxes regarding aircraft safety and manufacturing quality. Because the internal culture penalized those who pointed out the gap between the corporate narrative and safety thresholds, the system failed to create awareness of safety concerns. Ultimately, physical component failures forced a massive operational and financial meltdown, proving that corporate vocabulary cannot override structural mechanics.
Case 3: The 2025 Synthetic Information Energy Flash Crash
In late 2025, automated commodity trading systems at CME suffered a massive crash due to a single point of failure in a data center cooling system. The regulatory bodies were slow to issue verifications, and algorithmic models, programmed for real-time information, failed. Organizations that survived the crash were those whose ERM frameworks required physical correspondence and supply-line confirmation before executing risk-mitigation protocols. The episode demonstrated the importance of resiliency for highly centralized digital infrastructure.
Paradoxes of Post-Truth Risk Management
As CROs navigate this corrupted information landscape, they must manage three structural paradoxes inherent to the post-truth corporate environment.
1. The Paradox of Consensus: To build an effective risk culture, organizations strive for consensus and alignment. However, in a post-truth world, seeking total alignment can inadvertently manufacture an internal echo chamber that mirrors external tribalism. If the risk team prioritizes social solidarity over friction, they will fail to challenge the prevailing institutional or corporate narrative. The solution is for risk leaders to channel philosopher Jürgen Habermas by intentionally constructing an “ideal speech situation,” a corporate culture where whistleblowers and analysts can present uncomfortable, unamendable facts without fear of coercion or professional retaliation.
2. The Paradox of Pragmatism: Philosophers like William James argued that truth is "what works" because of its utility. In business, a pragmatic approach means adapting to the regulatory and political landscape to maintain short-term profitability. The paradox is that acting on what works in the short term, such as endorsing an administration’s flawed economic narrative to gain a regulatory favor, could create catastrophic long-term exposure. The solution is to allow corporate strategy to adapt to political realities, but ensure the risk management models remain ruthlessly realistic, recognizing that short-term political utility cannot prevent a structural rupture when the unamendable facts finally assert themselves.
3. The Paradox of Transparency: In response to heightened volatility, organizations often demand more reporting, more disclosures, and more compliance documentation. The paradox is that more paperwork does not produce more truth. It frequently produces more noise. In Frankfurt’s terms, excessive compliance reporting often degenerates into corporate bullshit with documents written purely to satisfy a bureaucratic metric rather than to convey accurate operational realities.
The solution is to reduce the volume of reporting and drastically increase the density of empirical verification, forcing teams to defend the data integrity of their metrics rather than the volume of their outputs.
Parting Thoughts
Operating an enterprise in a post-truth world requires corporate leaders to abandon the comforting assumption that public institutions are reliable custodians of factual reality. When the state, the legislature, and the courts treat truth as a flexible tool for power and ideological consistency, the corporation must become its own anchor.
Chief Risk Officers cannot prevent the broader cultural and institutional epistemic meltdown, but they can insulate their organizations from it. By embracing a new realism, enforcing the scientific attitude, and demanding that internal risk reporting correspond strictly to unamendable physical and economic data, risk managers fulfill their highest calling. They cease to be passive consumers of external narratives and become the definitive architects of organizational ground truth.
Brenda Boultwood is the Distinguished Visiting Professor, Admiral Crowe Chair, in the Economics Department at the United States Naval Academy. The views expressed in this article are her own and should not be attributed to the United States Naval Academy or the U.S. Department of Defense.
She is the former Director of the Office of Risk Management at the International Monetary Fund. She has previously served as a board member at both the Committee of Chief Risk Officers (CCRO) and GARP, and is also the former senior vice president and chief risk officer at Constellation Energy. She held a variety of business, risk management, and compliance roles at JPMorgan Chase and Bank One.
Topics: Enterprise
Brenda Boultwood