Why Value Creation and Risk Management Today is 2 Sides of the Same Strategy in All Companies
- Morten Efferbach
- Aug 6
- 7 min read
When AI is so strategic and fails so often when trying to create value and revenue growth, the management of the risks associated with AI - and how you manage them - becomes equally strategic

Every leadership team I meet this autumn is working on the same three things: a sharper go-to-market motion, tighter execution, a better product strategy. Good. Those are the right things to work on, whether the company has 20 employees or 20,000. But I keep coming back to a question that none of the strategy decks answer: what happens to all of that value if the leadership team and the board are not actually ready to catch what goes wrong on the way there?
This is not a rhetorical worry, and it is not a large-company problem. It is the central finding behind Decision Readiness, the book I have spent the last year writing, and it is the reason I think 2026 is the year boards - of any size - stop treating risk oversight and value creation as two different processes, and start treating them as one strategy with two sides.
The spending is real. The returns mostly aren't.
Start with the number every leadership team and board is currently living with: artificial intelligence. Worldwide enterprise spend on AI is heading toward two and a half trillion dollars by the end of this year. That is not a rounding error in anyone's budget. And the return on it is, for most companies, disappointing in a very specific and well-documented way.
MIT's research on enterprise generative-AI pilots found that roughly 95 per cent showed no measurable effect on profit or loss. RAND puts the share of AI projects failing to deliver their intended business value above 80 per cent - so four out of five, more or less exactly what you may have heard quoted. McKinsey's most recent global survey finds a similar pattern from a different angle: 88 per cent of organisations now use AI somewhere in the business, but only around a third see any impact on EBIT at all. Three independent research houses, three different methodologies, the same uncomfortable shape.
What is striking is not the failure rate itself. It is where the failure actually comes from. It is very rarely the technology. The models do what models do. The pattern that repeats - across RAND's review of more than two thousand enterprise AI initiatives, across the case studies I document in the book - is organisational: a project launched without a defined business problem, without a named executive owner, without a measurable outcome agreed before the money was spent. Klarna's much-discussed customer service rollout is the clean example. The AI handled simple, standardised interactions well. What no one had modelled was the cost of being wrong on the complex ones - and within a year the company was rehiring, at a cost that by its own account exceeded the savings the project was meant to deliver.
That is not a technology failure. That is a decision that was never properly readied before it was made - and it is exactly why the risk side of AI cannot be delegated to IT or treated as a footnote to the growth case. If AI is strategic enough to bet the company's growth on, managing the risk of it failing is strategic enough to belong on the same page, not a separate one. That is true whether the board in question sits over a family firm, a mid-sized exporter or a listed multinational - the size of the company changes the size of the bet, not the logic.
Risk and growth have been sitting in two different rooms
Here is the pattern I keep seeing in boardrooms, and it is one of the arguments I spend a full chapter on in the book: most boards run two separate conversations under two separate names. The audit or risk committee asks, in careful and structured detail, what could go wrong. The strategy conversation - where it exists as more than an annual afternoon - asks, in much looser and more optimistic language, what the company should do next. Different room, different tone, often a different point on the agenda entirely.
There is no good structural reason for that split. The same directors, the same duty of care, applies to a decision to enter a new market as to a decision to accept a given level of cyber exposure. What differs is not the board's competence. It is habit. Risk decisions get real discipline. Growth decisions, by convention rather than by design, mostly do not.
This is not a pattern confined to AI, and it is not just my reading of the boardroom.
COSO, the body that sets the reference standard for enterprise risk management, published new research in May 2026 built on a global survey of risk leaders and executive interviews: 98 per cent believe risk management should play a more strategic role in decision-making, yet only 7 per cent say it is actually fully integrated into strategy decisions today, and more than half still describe their programme as primarily a compliance function. Deloitte's own global survey of C-suite and board respondents found the same shape from a different angle - nearly nine in ten organisations agree that risk management should be about creating value, not just avoiding loss, but fewer than one in five are taking sufficient action on it. As one insurance-group chief executive put it in that same research, strategy and risk are two sides of the same coin. The agreement is almost universal. The follow-through almost never arrives.
And the evidence for this sits inside the same data set I use for the AI numbers above. Private-equity-backed boards are, on the record, the best-governed boards there are - they spend markedly more of their meeting time on strategy and value creation than their peers. And on the one growth lever nearly every one of them is now under pressure to pull, artificial intelligence, they fail at almost exactly the rate everyone else does.
General discipline about value creation does not automatically produce domain-specific discipline about a particular bet. The first layer of governance is necessary. It is not sufficient.
What private equity actually does differently - and why it transfers
The part of this that I find genuinely useful, rather than just cautionary, is what the better-performing private equity operators do instead. It is not a cleverer strategy. It is a small number of named initiatives, each with a named owner, a quantified target, a budget, and a pre-agreed willingness to kill it if it is not delivering - reviewed at every board meeting, not once a year. McKinsey's own analysis of the buyout industry shows the operators built around exactly this discipline outperforming their peers by two to three points of IRR, and the gap widens precisely in the difficult years, when undisciplined optimism is most tempting.
None of that is proprietary to private equity. It is a governance structure - ownership, quantification, standing review, the courage to stop - and any board can install it. Most simply have never had a sponsor insisting on it.
This is where I think the ‘risk versus growth’ framing quietly misleads boards. The same six questions I build into every domain in the book - what is the exposure, what should we be asking that a confident deck doesn't already answer, have we rehearsed how this could go wrong, what is our appetite before we call it, who by name owns this decision, and how will we actually know if it's working - do not belong more naturally to a cyber threat than to a market entry. They are simply what a prepared board asks before it commits real resources to an uncertain outcome. A board that has already built the habit for its principal risks does not need to build it again from nothing for its growth bets. It only has to point the same instrument in a different direction.
Why this matters more, not less, now that answers are cheap
There is a deeper shift underneath all of this, and it is the one the book opens with. For most of the history of the company, a good answer was the scarce and expensive thing - the analysis, the modelling, the careful report. AI is making that abundant and nearly free. Work that used to take a team a month now takes an afternoon.
When the answer stops being scarce, the value does not disappear. It moves - to the question that gets asked before the analysis even begins, to the judgement required to weigh an answer the data cannot settle on its own, and to the willingness to act on that judgement when it is uncomfortable. None of that can be bought off the shelf, and none of it shows up in a productivity dashboard. It is the work of a prepared leadership team and a prepared board, and it is fast becoming the rarest and most valuable thing a company has.
The practical takeaway
If your leadership team is investing real energy in go-to-market, execution and product strategy this year - and it should be - the honest next question is not ‘is our strategy good enough.’ It is: if this bet goes wrong, or if the exposure we are not watching crystallises at the same time, does our board actually know what it will do, who owns the call, and what ‘success’ was agreed to look like before the money went out the door? If the answer is no, the value creation work is being built without a foundation underneath it, and the record - Klarna, the Nordic AI investment gap, the wider pattern RAND and MIT document - suggests that foundation gets tested sooner than most leadership teams expect.
None of this scales with headcount. A twenty-person exporter making its first serious AI bet needs the same six questions answered as a listed group with an AI committee - it simply needs to answer them in an afternoon rather than a quarter. Decision readiness is not a large-company discipline that smaller companies grow into eventually. It is a habit of asking, before the money moves, that costs almost nothing to install and a great deal to have skipped.
This is the argument at the centre of Decision Readiness, and it is the discipline the eight Decision Readiness Workbooks were built to make practical for boards - of any size - that do not have a private equity sponsor standing over them insisting on it. If it is useful to talk through where your own board's second layer currently stands, I would be glad to have that conversation.
Morten Efferbach is the founder of Leadership Capital Group and the author of Decision Readiness: From Good Governance to Governance 2.0, based on the findings of the Global Board Survey 2026.




Comments