Risk 360

From Risk Registers to “Attack Mode”: Mr. Anand Mahindra’s Uncertainty Philosophy and the Modern Enterprise Risk Management Outlook

Getting India Risk Ready

For generations, business leaders were taught that uncertainty was something to endure. Markets would eventually recover, geopolitical tensions would ease, supply chains would stabilise, and economic cycles would return to normal. The role of management was largely to navigate these temporary disruptions until predictability returned.

That philosophy no longer reflects reality.

In Mahindra Group’s FY26 Annual Report1, Chairman Anand Mahindra and Group CEO & Managing Director Dr. Anish Shah articulate a view that is both refreshingly simple and strategically profound: uncertainty is no longer cyclical—it is structural. It is not an occasional disturbance to business. It has become a permanent feature of the business environment. Consequently, organisations cannot afford to wait for certainty before making bold decisions. Instead, they must learn to be comfortable with uncertainty itself.

This perspective represents far more than a statement about the current economy. It reflects a modern Enterprise Risk Management (ERM) philosophy—one that every boardroom, executive team and risk professional should understand.

The world has fundamentally changed. Organisations today are operating in an environment where geopolitical tensions reshape global supply chains overnight, artificial intelligence disrupts entire industries in months rather than decades, cyberattacks evolve faster than defensive technologies, climate events increasingly affect operations and insurance costs, and regulatory expectations continue to expand across jurisdictions. These are no longer isolated risks that appear occasionally on a risk register. They are interconnected forces that influence the strategic decision making process within an organisation.

In such an environment, the traditional approach to risk management begins to lose relevance. Historically, risk management was often viewed as a defensive function. Risk professionals were expected to identify what could go wrong, prepare risk mitigation plans, ensure compliance and prevent losses. Success was frequently measured by the absence of incidents.

While those responsibilities remain important, they are no longer sufficient.

Modern Enterprise Risk Management has evolved considerably over the last decade. Today, its purpose extends beyond protecting organisations from downside events. It exists to improve decision-making under uncertainty. It helps organisations allocate resources more intelligently, identify emerging opportunities earlier than competitors, understand interconnected risks, strengthen resilience and ultimately create long-term value.

This is precisely why Anand Mahindra’s remarks deserve attention from the global risk management community.

Perhaps the most striking phrase in his message is the call for organisations to move into “Attack Mode.” Borrowed from Formula E racing, Attack Mode allows drivers to access an additional burst of power—but only at carefully chosen moments during a race. It is not activated continuously, nor is it used recklessly. Success depends entirely on timing, preparation and judgement.

The same principle applies in business.

Attack Mode is not about taking greater risks. It is about taking better-informed risks.

There is an important distinction.

Organisations often make the mistake of equating risk-taking with recklessness. In reality, the most successful organisations are rarely reckless. Instead, they invest heavily in understanding uncertainty before making decisive moves. They develop multiple future scenarios, analyse potential outcomes, strengthen operational resilience, preserve financial flexibility and establish clear early warning indicators. Once these foundations are in place, they move quickly when opportunities emerge.

That is exactly what mature Enterprise Risk Management seeks to achieve.

The greatest competitive advantage during periods of disruption often belongs not to the largest organisations, but to those capable of making confident decisions while others remain hesitant.

History repeatedly demonstrates this pattern. Many of today’s global market leaders strengthened their positions during financial crises, technological disruptions or periods of geopolitical instability. While competitors focused solely on surviving uncertainty, these organisations invested, innovated and expanded. They understood that uncertainty creates opportunities alongside threats.

This dual perspective sits at the heart of modern ERM.

Traditional risk registers often present uncertainty almost entirely in negative terms. They catalogue operational failures, cyber incidents, regulatory breaches, financial risks and supply chain risks. These remain important considerations, but they represent only half of the picture.

Every uncertainty also creates possibility.

A technological risk may threaten existing business models while simultaneously creating entirely new markets. Regulatory changes may increase compliance obligations but also eliminate weaker competitors. Economic slowdowns may reduce short-term revenues while creating opportunities for strategic acquisitions, talent acquisition or long-term investment.

The question therefore changes from “How do we avoid uncertainty?” to “How do we position ourselves to benefit from it?”

That subtle shift fundamentally transforms the role of Enterprise Risk Management.

If uncertain risks become permanent, organisations cannot simply rely on crisis management capabilities that activate after something goes wrong. Instead, resilience must become embedded into everyday operations, strategic planning and organisational culture.

Resilience today is no longer limited to business continuity plans stored on a shelf or annual crisis simulations conducted to satisfy regulatory requirements. It has become an organisational capability that enables businesses to absorb shocks, tackle organisational risks, adapt rapidly and continue creating value despite changing circumstances.

This requires a very different organisational mindset.

Strategic planning can no longer depend upon a single forecast. Leadership teams must routinely evaluate multiple plausible futures. Investment decisions must consider geopolitical risks alongside financial metrics. Technology strategies must include governance considerations. Supply chains must prioritise resilience as much as efficiency. Human capital strategies must recognise that future workforce risks extend far beyond recruitment and retention.

Enterprise Risk Management increasingly serves as the discipline that connects all these conversations.

Its role is becoming less about documenting risks and more about enabling strategic confidence.

This evolution also changes expectations from board of directors.

For many years, board discussions surrounding risk primarily focused on reviewing historical performance and ensuring regulatory compliance. Increasingly, however, boards are expected to carry out board risk management and oversee future uncertainty rather than simply analyse past events.

Questions such as “What assumptions underpin our strategy?”, “What external developments could invalidate those assumptions?” and “Where might disruption create opportunities for growth?” are becoming central to effective governance.

Boards that continue viewing ERM solely as a compliance exercise risk overlooking its greatest strategic contribution.

Equally important is recognising that risk management is no longer confined to the risk department.

One of the defining characteristics of mature ERM is the recognition that every business function contributes to organisational resilience. Finance manages capital uncertainty. Procurement manages supplier uncertainty. Technology teams manage cyber risks. Human Resources addresses workforce uncertainty. Marketing protects reputation. Legal teams deal with compliance risks and navigate regulatory uncertainty. Product development anticipates market shifts.

In other words, the first line of defence has become the organisation’s largest and most important source of risk intelligence.

This requires employees across functions to think differently—not merely completing operational tasks but continuously recognising changing risks and emerging opportunities within their respective domains.

As organisations adopt artificial intelligence at scale, this integrated approach becomes even more critical.

Artificial intelligence undoubtedly offers unprecedented opportunities for efficiency, productivity and innovation. However, it simultaneously introduces artificial intelligence risks and new governance challenges involving data quality, algorithmic bias, cybersecurity, regulatory expectations, intellectual property and ethical decision-making.

Technology alone cannot manage these complexities.

They require governance.

They require oversight.

Most importantly, they require AI Risk Management and Enterprise Risk Management.

Perhaps the most significant lesson emerging from Mahindra’s philosophy is cultural rather than procedural.

Many organisations unintentionally reward excessive caution. Employees become reluctant to escalate concerns. Innovation slows because people fear failure more than missed opportunity. Decision-making becomes increasingly bureaucratic. Over time, the organisation becomes highly efficient at preserving the past but poorly equipped to shape the future.

A strong risk culture produces the opposite effect.

People speak up early when they identify emerging risks. Teams challenge assumptions constructively. Leaders encourage informed experimentation rather than blind optimism or excessive conservatism. Near misses become learning opportunities rather than sources of blame. Risk discussions become strategic conversations instead of compliance exercises.

This cultural shift ultimately determines whether uncertainty becomes a source of competitive disadvantage or competitive strength.

The coming decade is unlikely to reward organisations that simply wait for conditions to stabilise. If anything, the pace of disruption is expected to accelerate. Artificial intelligence will continue reshaping industries, geopolitical dynamics will remain fluid, climate adaptation will demand new investments, cyber threats will become increasingly sophisticated, and stakeholder expectations around governance and sustainability will continue to evolve.

Against this backdrop, Anand Mahindra’s message carries significance far beyond the Mahindra Group.

It captures a broader transformation in management thinking—one that aligns remarkably well with the evolution of Enterprise Risk Management itself.

The future will not belong to organisations that eliminate business uncertainty. That is impossible.

Nor will it belong to organisations that simply become more risk-averse.

Instead, it will belong to organisations that develop the capability to understand strategic risks and uncertainty better than their competitors, make faster and better-informed decisions, build resilience into every function, and recognise that every period of disruption contains the seeds of future growth.

Ultimately, this is the true purpose of modern Enterprise Risk Management. It is not about building thicker risk registers or producing more dashboards. It is about giving leaders the confidence to act when certainty is absent.

In many ways, Anand Mahindra’s call to move into “Attack Mode” is not a departure from Enterprise Risk Management at all. It is one of its most contemporary and compelling expressions—a reminder that in today’s world, the greater challenge may not be uncertainty itself, but waiting for it to disappear.

The author confirms that this article is original and has not been copied, reproduced, or derived from another author’s work, except for appropriately cited third-party references used for research purposes.

Citations

1 https://www.mahindra.com/annual-report-FY2026/

FAQS

1.What is modern Enterprise Risk Management? 

  • Enterprise Risk Management (ERM) is “an integrated and joined up approach to managing all areas of risk across an organisation and its extended networks.”  
  • This means that ERM goes much beyond the traditional financial risk approach and covers study of the entire Risk Universe. 
  • Strategic planning can no longer depend upon a single forecast. Leadership teams must routinely evaluate multiple plausible futures. Investment decisions must consider geopolitical developments alongside financial metrics. Technology strategies must include governance considerations. Supply chains must prioritise resilience as much as efficiency. Human capital strategies must recognise that future workforce risks extend far beyond recruitment and retention.
  • Enterprise Risk Management increasingly serves as the discipline that connects all these conversations.
  • Its role is becoming less about documenting risks and more about enabling strategic confidence.
  • One of the defining characteristics of mature ERM is the recognition that every business function contributes to organisational resilience. 

2. How does Enterprise Risk Management help organisations manage uncertainty? 

  • Modern Enterprise Risk Management has evolved considerably over the last decade. Today, its purpose extends beyond protecting organisations from downside events. 
  • It exists to improve decision-making under uncertainty. 
  • It helps organisations allocate resources more intelligently, identify emerging opportunities earlier than competitors, understand interconnected risks, strengthen resilience and ultimately create long-term value.

3. How can businesses make better decisions under uncertainty? 

  • Organisations cannot afford to wait for certainty before making bold decisions. Instead, they must learn to be comfortable with uncertainty itself.
  • This perspective reflects a modern Enterprise Risk Management (ERM) philosophy—one that every boardroom, executive team and risk professional should understand.
  • Modern Enterprise Risk Management helps organisations allocate resources more intelligently, identify emerging opportunities earlier than competitors, understand interconnected risks, strengthen resilience and ultimately create long-term value.
  • Organisations often make the mistake of equating risk-taking with recklessness. The most successful organisations invest heavily in understanding uncertainty before making decisive moves. They develop multiple future scenarios, analyse potential outcomes, strengthen operational resilience, preserve financial flexibility and establish clear early warning indicators. Once these foundations are in place, they move quickly when opportunities emerge.
  • If uncertainty has become permanent, organisations cannot simply rely on crisis management capabilities that activate after something goes wrong. Instead, resilience must become embedded into everyday operations, strategic planning and organisational culture.
  • The future will not belong to organisations that eliminate uncertainty. That is impossible. Instead, it will belong to organisations that develop the capability to understand uncertainty better than their competitors, make faster and better-informed decisions, build resilience into every function, and recognise that every period of disruption contains the seeds of future growth.

You may also like

Leave a reply

Your email address will not be published. Required fields are marked *

More in Risk 360