Rethinking risk management in the APAC region

Rethinking risk management in the APAC region

Security leaders must rethink the playbook in a region where legacy frameworks often fall short, writes Andreas Karki, Chief Operating Officer and Partner, Lares Risk Management International.

For many organisations, the Asia-Pacific (APAC) region is still viewed through an outdated lens: High-growth, emerging risk, manageable complexity.

In reality, the region has become one of the most demanding operating environments for security leaders responsible for managing risk across global operations.

It is no longer sufficient to extend frameworks into the region with minor adjustments. APAC has become a proving ground for whether those frameworks were ever fit for purpose.

Having supported multinational organisations across Southeast Asia, South Asia and the wider APAC region, one pattern is consistent: Risk management models are often inherited from headquarters, formally adopted and only partially adapted to local conditions. On paper, models appear robust.

On the ground, they frequently struggle to keep pace with the speed, diversity and ambiguity that define operations. For senior security leaders, this is not an academic challenge.

It is a leadership issue with direct implications for operational continuity, decision-making and organisational resilience.

APAC is not a single risk environment

One of the most common missteps is treating APAC as a unified operating context. It is anything but.

Within the same region, security leaders are expected to manage: Highly mature markets alongside developing and frontier economies; predictable regulatory environments alongside opaque or inconsistently enforced regimes; strong governance cultures alongside relationship-driven decision-making; stable political contexts alongside markets where regulatory, reputational and geopolitical factors intersect.

This diversity fundamentally alters how risk manifests. A model that works well in one market may quietly fail in another. In APAC, risk often does not present itself as a sudden incident.

More commonly, it appears as operational friction: Delays, informal workarounds, quiet non-compliance or reputational exposure that accumulates over time.

For security leaders, these are the risks that are hardest to capture in traditional assessments and the easiest to underestimate.

The gap between risk management and operational reality

Many global organisations operating in APAC have the foundations of risk management in place or are in the process of building them. Assessments are conducted, risk registers are developed and reporting lines to leadership exist to varying degrees.

The challenge is not intent or effort – it’s relevance. Too often, risk management remains a documentation exercise rather than a decision-enabling function. Assessments are completed, but outputs do not meaningfully influence how operations are designed, resources allocated or how leaders make trade-offs under pressure.

At the regional level, this gap is frequently bridged informally.

Country and site leaders rely on personal experience, local relationships and individual judgment to manage exposure. While this approach keeps operations moving, it also concentrates risk in people rather than systems.

When those individuals move on, organisational resilience moves with them. For senior security leaders, this represents a critical vulnerability. Effective risk management must be embedded into how the organisation operates, not carried quietly by a few capable individuals.

Trends reshaping operations

A range of trends are redefining how risk must be approached across the region.

Regulatory uncertainty remains a challenge. In many markets, laws and regulations exist, but interpretation and enforcement can vary significantly by jurisdiction, authority or sector.

Security leaders must plan for regulatory risk as a fluid operational factor rather than a fixed compliance requirement. Supply chain exposure has become increasingly visible.

Many organisations have optimised for efficiency and cost, only to discover that resilience was compromised in the process. In APAC, where supply chains are often regionally concentrated, disruptions can escalate rapidly across multiple markets.

Capability and talent gaps continue to affect security and risk functions.

While the region has strong local talent, experienced security leaders with cross-border, multi-market fluency remain scarce. This often results in over-reliance on a small number of trusted individuals, increasing key-person risk.

Tech adoption is accelerating faster than governance. Surveillance systems, risk platforms and monitoring tools are being deployed without always ensuring that policies, training and oversight evolve at the same pace. Tech alone does not reduce risk. Poorly governed technology can amplify it.

Crisis readiness also remains uneven. Many organisations have crisis plans, but fewer have tested them under realistic regional conditions. In APAC, crises rarely fit neatly into one category.

Regulatory, reputational, operational and political dimensions often collide.

Why traditional security models fall short

Traditional security models tend to underperform in APAC for number of reasons.

First, they remain overly centralised. Decision authority is retained at headquarters, while accountability for outcomes sits locally. This disconnect slows response and discourages proactive risk escalation.

Second, security is often positioned as a supporting function rather than a strategic partner.

Security leaders are brought into discussions after key decisions are made and then expected to manage the resulting risk without having shaped the decision itself.

Third, outsourcing is frequently treated as a substitute for leadership rather than a capability that requires governance. External providers play an important role in APAC, but without strong oversight and integration, accountability becomes fragmented. These challenges are rarely the result of poor intent.

They are the consequence of models designed for more predictable operating environments.

What effective risk management looks like in APAC

Organisations that manage risk effectively in the region tend to share common traits.

They empower regional leadership with genuine authority, not just responsibility. This includes influence over budgets, access to senior decision-makers and the ability to challenge assumptions constructively.

They integrate security, risk and resilience into a single operating mindset. Risk assessments are directly connected to business continuity planning, crisis response and operational decision-making.

They embed expertise where it is most needed, rather than defaulting to static structures or fragmented outsourcing. This provides flexibility while preserving governance and knowledge.

Most importantly, they treat risk management as a leadership discipline, not a compliance obligation. Security leaders are expected to understand the business, communicate risk in commercial terms and contribute meaningfully to strategic discussions.

A final reflection for security leaders

The APAC region is no longer a peripheral consideration in global risk discussions. For many organisations, it is where risk management maturity is tested most visibly.

For senior security leaders, the question is not whether existing frameworks can be extended into the region – the real question is whether those frameworks are adaptable enough to support decision-making in environments defined by speed, complexity and ambiguity.

Risk management in APAC demands regional fluency, operational credibility and the willingness to move beyond inherited playbooks. Those who do will not only protect their organisations but help build resilience that extends well beyond the region.

About the Author

Andreas is Chief Operating Officer and Partner at Lares Risk Management International, a global security and risk management consultancy supporting organisations across Europe, the Middle East, Africa and the Asia-Pacific region.

Based in Bangkok and living in Asia for more than seven years, he supports senior security leaders managing complex, multi-country operations across APAC and has helped build and grow the company’s regional offices in Thailand, Vietnam and India.

1-ISJ- Rethinking risk management in the APAC region
Andreas Karki, Chief Operating Officer and Partner,
Lares Risk Management International

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox