The Missing Layer in Modern Governance: Human Capital Risk
GRC, ERM and ESG have converged. The one risk that runs through all of them is still managed by gut feeling.
Walk into any board meeting today and you'll hear the same vocabulary: GRC, ERM, ESG, the SDGs, resilience, accountability. Ten years ago these lived in separate departments, with separate owners, separate tools and separate reports. Today regulators, investors and auditors expect one connected view of how an organization identifies, governs and reports its risks.
Look closely at that connected view, though, and you'll find a gap right in the middle of it.
We have mature frameworks for financial risk, operational risk, cyber risk and climate risk. But the risk that sits underneath almost all of them, how people perceive, decide and behave, is still handled through annual training, hotlines, background checks and instinct.
That gap is human capital risk. In 2026 it is the least measured and most consequential risk on the register.
Every framework comes back to people
GRC assumes that people understand the rules and follow them. Policies are only as strong as the perception of the people expected to apply them.
ERM asks organizations to identify and prioritize their material risks. Yet in most risk registers, "people risk" is a single line item, while fraud, safety breaches, data leaks and misconduct are logged as separate events, as if they didn't share a human root cause.
ESG has two letters that are fundamentally about people. The S covers workforce, safety, wellbeing and conduct. The G covers integrity, ethics and accountability. Investors and reporting standards increasingly expect organizations to show how they manage these, not just describe them.
The SDGs make it explicit. SDG 8 calls for decent, safe work. SDG 16 calls for strong, accountable institutions and a substantial reduction in corruption and bribery. Neither can be delivered by technology that watches systems while ignoring the people inside them.
The common thread is behavioral risk: the gap between what an organization's policies say and how its people actually perceive and act on them.
Disclosure without measurement is just narrative
Most organizations can produce a well-written ESG or governance report. Far fewer can answer basic questions behind it:
Which roles carry the highest integrity exposure, and why?
Do employees in sensitive positions actually recognize a conflict of interest when they see one?
Where are people aware of a problem but choosing to stay silent?
Has our risk picture changed since we hired these people?
Without data, human capital governance becomes a statement of intent. With the right data, it becomes a managed, auditable process.
Behavioral risk: perception, not verdicts
At Logical Commander, we approach this differently from the tools most people associate with "integrity testing."
We don't produce verdicts. We don't label people guilty or innocent. We reveal perception.
Consider four employees connected to the same issue. One believes they acted correctly. One saw something and stayed silent. One is unsure whether a rule was broken. One doesn't recognize that a violation happened at all.
A traditional approach treats them as a single problem. Good governance treats them as four: one needs clarification, one needs a safe channel to speak, one needs training, one may need escalation. That's the difference between policing people and governing risk.
Severity is context-aware too. The same behavior carries different weight for a driver in logistics, a finance director in banking, or a procurement officer in a regulated tender. Risk prioritization that ignores role and industry produces noise. Context produces decisions.
From candidate to long-tenured employee
Human capital risk isn't a one-time event at the hiring gate. It evolves.
Candidates. Hiring is the cheapest point at which to manage risk. Understanding how a candidate for a sensitive role perceives integrity, compliance and safety scenarios gives HR and security teams insight that CVs, interviews and background checks can't provide.
Periodic assessments. People change. Roles change, pressures change, financial and personal circumstances change, and access to money, data and decision-making grows. A risk picture taken at hiring and never updated isn't a risk picture. Periodic, proportionate assessments keep it current, the same way any other material risk is reviewed on a cycle.
Post-incident. When something does go wrong, understanding who perceived what lets organizations investigate fairly and prevent recurrence, rather than turning a review into a witch hunt.
The US question: why most companies avoid this, and why they no longer have to
For US employers, the conversation about integrity assessment usually ends at four letters: EPPA.
The Employee Polygraph Protection Act sharply restricts private employers from using lie-detection methods in hiring and employment decisions. Understandably, legal teams treat anything resembling a polygraph as a liability, and many organizations simply leave this entire risk category unmanaged.
Logical Commander was designed from the ground up with this in mind. Our platform does not perform lie detection, does not render verdicts of truthfulness, does not conduct covert surveillance, and does not store biometric identifiers. It operates transparently, with the people involved, and leaves every decision with humans.
The result is that US organizations can assess candidates and run periodic assessments for employees in sensitive roles within a framework built to align with EPPA, without the legal exposure that polygraph-style tools carry. The same privacy-first design supports organizations operating under GDPR and other data-protection regimes across the 47+ countries where our technology is deployed.
From insight to governance
Insight only matters if it reaches the people who govern. That's why our assessments feed into E-Commander, a centralized platform that brings Human Risk Intelligence together with governance, ERM and GRC.
HR, compliance, security, legal and risk teams work from one framework covering more than 90 risk topics, with shared policies, clear ownership, prioritization and an audit trail. The board gets what it has been asking for: a single, defensible view of where human risk sits and how it is being managed.
Governance that can see people
The organizations that lead in the next decade won't be the ones with the most controls. They'll be the ones that understand the people operating those controls, ethically, proportionately and early.
Cyber protects your systems. Biometrics confirm identity. ERM, GRC and ESG define what good governance looks like. Human capital risk intelligence is the layer that makes all of them work in practice.
Where does human capital risk sit in your organization's governance framework today: on the risk register, in the ESG report, or nowhere yet?
%20(2)_edited.png)

