Navigating Complexity in Large-Scale Projects: Beyond the Risk Register
- John Al Khateeb

- Jul 22
- 6 min read
Updated: 2 days ago
In complex projects, the most valuable signals are often those that a risk register cannot capture. These signals include the persistent tensions between roles, disciplines, and priorities that reveal how the project is evolving. Effective risk management remains essential; a risk is an uncertain event that one works to prevent or mitigate. The discipline of identifying, assessing, and treating risk is foundational. INMAA Advisory's approach builds on this foundation while adding a distinctive layer. In complex environments, the risk register captures what can be named, but complexity also produces conditions that resist naming. Understanding these conditions requires a different lens.
This article outlines three significant shifts that this lens involves: from risk to vulnerability, from divided accountability to collective sensemaking, and from managing complexity to sensing it.
Complex Projects as Human Activity Systems
A complex project is not merely a machine with clean, separable dependencies. It is a complex adaptive human activity system, comprising suppliers, competitors, government entities, customers, and subcontractors, all interdependent. The distinction between interdependence and dependence is crucial. Dependence is linear; one part relies on another, and one can trace the line. In contrast, interdependence is mutual and often circular, producing behaviors that no single part can explain independently. The whole is greater than the sum of its parts.
This is why complexity resists the reductive habit of breaking a system into pieces, managing each piece, and assuming that the whole is thereby managed. In an interdependent system, the behaviors that matter reside in the interactions, not the components. Two forms of complexity are worth distinguishing here: organized complexity, which has a structure that one can model, and disorganized complexity, which embodies genuine VUCA conditions—volatility, uncertainty, complexity, and ambiguity.
From Risk to Vulnerability
Risk, as conventionally practiced, is allocatable. One names a threat, assigns an owner, attaches a treatment, and records it. This property is precisely why risk management integrates so seamlessly into process and compliance. Under pressure, process can quietly override leadership, decision-making, and accountability. The risk register becomes something to fall back on rather than a prompt for decisive action.
Vulnerability, however, behaves differently. It exists in the interdependence between parts of the system, not within any single part, and is often invisible from any one vantage point. A capability delivered on budget but unable to integrate is not a risk sitting in anyone's register; it is a vulnerability residing in the space between parties, each of whom sees only their portion. One cannot allocate accountability for a vulnerability in the same way one allocates a risk, as recognizing it requires multiple perspectives.
David Hillson's well-known definition—risk is uncertainty that matters—serves as a useful anchor here and is worth extending. What matters, and to whom, is not predetermined. It depends on the worldview from which the project is being observed. Two roles examining the same program may disagree about what matters precisely because they hold different, legitimate, partial views. This disagreement is not noise to be resolved; it is valuable information.
Accountability Cannot Be Divided
Conventional governance seeks clear roles and explicit decision rights. In stable conditions, this clarity prevents the ambiguity and conflict common in multi-stakeholder environments. However, there is a limit to how far accountability for complexity can be partitioned. Each role in a complex project possesses a different worldview: the delivery function perceives one reality, while the oversight function perceives another. Each view is real yet incomplete. Predictability relies on understanding, and understanding always occurs within a specific domain or area of concern. Losing the whole-system view does not merely result in missing information; it alters what is possible to understand.
This is where the distinction between multidisciplinary and interdisciplinary work becomes practical rather than academic. Multidisciplinary efforts run disciplines side by side, each in its lane, with outputs assembled at the end. Interdisciplinary efforts integrate these disciplines, allowing insights to form in the overlap between fields rather than within any one of them. Complex project governance requires the latter. The vulnerabilities that matter emerge between disciplines and roles, meaning that the mechanism for surfacing them is not a clearer division of labor but genuine sensemaking—the disciplined act of bringing together partial worldviews.
In this context, accountability does not dissolve into collective vagueness. Instead, it concentrates. It shifts from the boxes on a responsibility chart to the quality of the forum where different worldviews converge and make sense of what each is observing. Boundaries determine the scope and scale of concern. Drawing them too tightly around a single role causes the signal to fall outside the frame. The governance task is to set these boundaries deliberately and to create a forum where partial views can converge.
From Control to Clarity
The instinct in the face of complexity is to seek greater control—more reporting, tighter processes, and quicker resolution of open questions. In a complex adaptive system, this instinct often removes the very signals that leadership most needs. Persistent tensions between legitimate priorities—control versus flexibility, speed versus assurance, sovereignty versus interoperability—are not failures of governance to be engineered away. They are emergent properties of the system, carrying diagnostic information about how the project's complexity is shifting. If one collapses a tension too early by choosing a side, one loses the early warning it provides.
A more useful posture involves shifting from control to clarity and focus. This approach does not aim to command the system into predictability but rather pursues shared understanding across its various worldviews. It also fosters resilience to absorb what cannot be predicted. Resilience here is not merely a contingency line item; it is the capacity to adapt as conditions change, embedded in how the project is governed rather than added on afterward.
A newer pressure sharpens all of this. As AI systems begin to generate governance signals faster than human forums can process them, the binding constraint shifts. It is no longer about detection; organizations increasingly receive more signals than they can act upon. The constraint becomes the organization’s capacity to make sense of and decide on what it is already receiving. Governance that meets on a fixed monthly rhythm cannot effectively govern a picture that changes weekly. Aligning the tempo of decision-making with the tempo of risks—and vulnerabilities—is rapidly becoming the practical edge of governance maturity.
Sensing Complexity in Practice
Sensing complexity means treating it as a condition to be read rather than a problem to be controlled. In practice, this involves establishing a project's complexity profile early, monitoring persistent tensions as leading indicators, setting system boundaries deliberately, and building resilience to absorb what cannot be predicted. This approach contrasts with reliance on modeling tools suited to stable, organized conditions.
Frequently Asked Questions
What is the difference between a risk and a vulnerability in complex projects?
A risk is an uncertain event that can be named, assigned an owner, and mitigated—it fits within a register. A vulnerability, on the other hand, is a structural condition that exists in the interdependence between parts of a system. It is often invisible from any single vantage point and cannot be allocated to one role. INMAA treats both as necessary: risk management remains foundational, while vulnerability identification requires collective sensemaking across worldviews.
Why can't accountability for risk simply be divided between roles?
Accountability for named risks can be divided and should be. However, in a complex adaptive human activity system, each role holds a partial worldview. The vulnerabilities that matter appear in the interactions between roles rather than within any single role. Accountability for those cannot be partitioned; it concentrates in the quality of the forum where different perspectives meet and make sense of what each is observing.
How does INMAA read governance tensions?
INMAA treats a tension as a persistent, paradoxical force—such as control versus flexibility or speed versus assurance—that cannot be permanently resolved. These tensions carry information about a project's shifting complexity. Rather than collapsing tensions into the risk register, INMAA reads them as signals for adaptation. Best-practice risk management and tension-informed decision-making work together, not in opposition.
What does "sensing complexity" mean in practice?
Sensing complexity involves establishing a project's complexity profile early, monitoring persistent tensions as leading indicators, setting system boundaries deliberately, and building resilience to absorb what cannot be predicted. This approach emphasizes understanding complexity as a condition to be read rather than a problem to be controlled.
By adopting these strategies, organizations can navigate the complexities of large-scale projects more effectively, ensuring that they are better equipped to manage the inherent uncertainties and achieve successful outcomes.




Comments