Monday Morning Quarterbacking
Aug 26, 2026
Everybody Saw It Coming. So Why Did Nobody Stop It?
There is a particularly frustrating sentence that seems to appear after almost every major failure:
“There were warning signs.”
Of course there were.
After the project collapses, the fraud is discovered, the cyberattack occurs, the vendor fails, or the budget explodes, suddenly everyone becomes Sherlock Holmes.
"Well, looking back..."
"There had been some concerns..."
"We knew the schedule was getting tight..."
"There were a few unusual transactions..."
"People had mentioned the vendor was difficult..."
"We thought someone was looking into it..."
And there it is.
We thought someone was looking into it.
Possibly six of the most dangerous words in governance.
Because sometimes organizations don't fail because nobody saw the problem.
They fail because everybody saw a little piece of it, and everybody assumed somebody else owned it.
The Warning Sign Isn't Always Flashing Red
We tend to imagine warning signs as enormous flashing lights:
🚨 FRAUD ABOUT TO OCCUR
🚨 PROJECT ABOUT TO FAIL
🚨 VENDOR ABOUT TO COLLAPSE
Wouldn't risk management be easier if that were how it worked?
Unfortunately, warning signs are usually much less dramatic.
The monthly report arrives two days late.
Then four.
Then someone stops producing it altogether.
A project milestone slips.
The explanation sounds reasonable.
Another slips.
There's another reasonable explanation.
A vendor invoice doesn't quite match the supporting documentation.
Someone promises to correct it next month.
An employee raises a concern.
Management says they will "keep an eye on it."
Nothing individually seems serious enough to pull the emergency brake.
But risk rarely arrives as one enormous event.
Sometimes it arrives as a collection of little things we keep explaining away.
When Does a Red Flag Become Red Enough?
This is one of the hardest questions in risk management.
Organizations cannot investigate every anomaly.
Auditors cannot audit every concern.
Project managers cannot escalate every delay.
Executives cannot personally examine every operational hiccup.
If everything is urgent, nothing is urgent.
But the opposite is equally dangerous.
If every warning sign can be individually explained, we may never stand back far enough to see the pattern.
Imagine this:
A project is 8% behind schedule.
Not ideal, but recoverable.
Costs are 6% over forecast.
Again, uncomfortable but manageable.
Three key people have left.
That's unfortunate.
The primary contractor has submitted significantly more change orders than expected.
There's probably an explanation.
Quality defects are increasing.
The team is investigating.
Individually?
Perhaps manageable.
Together?
We need to talk.
That is the difference between monitoring individual risks and understanding the story those risks are beginning to tell.
Risk Has a Habit of Living Between Departments
Here's where things get particularly interesting.
Finance sees the increasing invoices.
Procurement sees the vendor disputes.
Project Management sees the schedule delays.
HR sees the turnover.
IT sees unusual system activity.
Internal Audit sees control weaknesses.
Legal sees contract disputes.
Each function may be doing its job perfectly well.
But who is looking across all of them?
Because the organization doesn't experience risk in neat departmental boxes.
The project doesn't care which department owns the problem.
Neither does the fraudster.
Neither does the cybercriminal.
And your supplier certainly doesn't reorganize its financial difficulties according to your corporate reporting structure.
Sometimes the most important risk information exists between the boxes on the organization chart.
The Three Most Dangerous Owners of Risk
Ask who owns a particular issue and occasionally you'll meet three mysterious individuals.
Somebody.
Anybody.
And my personal favorite...
Everybody.
"Somebody is handling it."
"Anybody can raise the concern."
"Everybody knows about it."
None of those answers tells me who is actually accountable.
Good governance doesn't simply identify risks.
It identifies:
Who owns the risk?
Who monitors it?
Who has authority to act?
When must it be escalated?
And who needs to know?
Without those answers, a beautifully designed risk framework can become little more than expensive wallpaper.
Escalation Shouldn't Require an Act of Courage
Another problem occurs when people do recognize the warning signs but hesitate to raise them.
Why?
Because escalation sometimes feels like admitting failure.
The project manager doesn't want to tell executives the project is slipping.
The vendor manager doesn't want to admit the supplier relationship is deteriorating.
The employee doesn't want to be labelled "difficult."
The auditor doesn't want to sound alarmist.
The executive doesn't want to take something to the Audit Committee until they have all the answers.
So everyone waits for certainty.
Unfortunately, by the time certainty arrives, the problem may have arrived with it.
Organizations need cultures where saying:
"Something doesn't look right yet, and I think we should look closer"
is considered good management, not panic.
You don't need to know the building is burning down before you're allowed to mention that you smell smoke.
Connect the Dots Before They Become a Picture
Yesterday we talked about asking:
What changed?
Today, let's add another question:
What happens when we connect those changes?
One unusual invoice might mean nothing.
One project delay might mean nothing.
One employee resignation might mean nothing.
One customer complaint might mean nothing.
But sometimes several seemingly unrelated signals form a pattern.
And that is where good auditors, risk professionals, project managers and leaders earn their keep.
Not because they can predict the future.
But because they are willing to look beyond the individual event and ask:
"Is this trying to tell us something?"
Your Challenge for Today
Take one significant project, vendor, process or risk in your organization.
Don't start with the risk register.
Instead, ask the people involved:
What has changed recently?
What are you slightly worried about?
What keeps happening that shouldn't?
What are we explaining away?
Who owns the next action?
And perhaps the most revealing question of all:
What does everyone know that nobody is talking about?
That conversation might teach you considerably more than another hour staring at a heat map.
Because strong risk management isn't simply about identifying red flags.
It's about recognizing when several little red flags have quietly started waving at the same time.
Learn. Question. Connect. Grow.
At LG3, we want learning to travel beyond the classroom and into the conversations that change how organizations work.
Keep asking better questions. Keep connecting the dots. Keep looking beyond your own little box on the organization chart.
And most importantly, never assume somebody is handling it.
Learn and Grow with LG3.
What is the most overlooked warning sign you've seen before a project, process or relationship went wrong?
Stay connected with news and updates!
Join our mailing list to receive the latest news and updates from our team.
Don't worry, your information will not be shared.
We hate SPAM. We will never sell your information, for any reason.