In my 25+ years working in risk management, I have come to embrace a personal motto: simplicity is not the opposite of sophistication; simplicity is the relentless pursuit of understanding. Today, in an era defined by AI-driven uncertainty, that principle matters more than ever. Complexity is everywhere, but clarity is a choice.

Artificial intelligence is rapidly finding its way into the operating systems of business. It is shaping decisions, redesigning workflows, automating tasks, creating content, coordinating activities and, increasingly, acting on behalf of humans rather than merely responding to their instructions. For executives, the important question is no longer whether AI matters. It is how to manage a technology that appears to evolve faster than the frameworks used to govern it.

The defining feature of this moment is uncertainty. New capabilities create new possibilities, but they also create new dependencies, new failure points and new forms of complexity. The instinctive response inside organisations is often to add more structure: more governance, more procedures, more controls, more dashboards and more committees. Some of these may be necessary. Yet the first response to complexity should not always be more complexity. It should be understanding.

Risk management begins with understanding. Many people associate it with mitigation, compliance, reporting or control. These are all important, but they come later. Before one can mitigate a risk, one must understand it. Before one can control a system, one must understand how it behaves. Without understanding, control is only an illusion dressed up as process.

This is where simplicity becomes more than an aesthetic preference. It becomes a discipline. Many years ago, a skipper I knew used to tell me that the fastest boats were often the ones with the emptiest hulls. At first, I assumed he was talking about weight. He was not. His point was that every additional item on board represented another thing to monitor, maintain, secure, repair or worry about. A simpler boat was easier to understand, and therefore easier to control.

That lesson has stayed with me. The value of simplicity is not that it makes systems smaller. The value of simplicity is that it reduces the resources required to understand them. Imagine two boxes. One contains two objects. The other contains ten thousand. The first can be understood almost completely. The second requires time, attention, classification, memory and perhaps a system of its own merely to know what it contains. The difference is not philosophical. It is practical. Understanding consumes resources.

Human attention is finite. So are time, expertise, capital and cognitive capacity. Every additional process, dependency, exception, variable or moving part consumes part of that capacity. Complexity is therefore not inherently bad, but it is never free. It should be treated like any other scarce resource: used only when its value justifies its cost.

This is the practical meaning of less is more. It does not mean eliminating sophistication. It means reducing a system to the minimum level of complexity required by its context. If the context does not justify the complexity, the system should be trimmed. Not for elegance. For control. The fewer unnecessary parts one has to understand, the more deeply one can understand the parts that matter.

From this perspective, risk management becomes a discipline of probabilities. Its purpose is not to eliminate uncertainty, which is impossible, but to improve the odds. In my own work, I have found it useful to distinguish between two broad categories of factors. Some variables are within one's control. They can be shaped, limited, governed, simplified and managed. The target with these variables is to understand them so well, and control them so effectively, that the probability of the desired outcome approaches certainty.

Other variables sit outside direct control. Markets move, technologies evolve, competitors act, regulations change and human behaviour remains difficult to predict. These factors cannot be commanded. They can only be studied, monitored and understood. The objective is to reduce the probability of surprise, particularly the low-probability, high-impact events that live in the tail of the distribution.

Good risk management therefore rests on a simple chain of logic: understanding creates control; control improves probability; probability shapes outcomes. Simplicity matters because it protects the first link in that chain. It makes understanding possible without exhausting the resources needed to act on that understanding.

This matters greatly in the age of AI. Many organisations approach AI as a technology problem, asking what models to buy, which platforms to deploy or what use cases to prioritise. These are legitimate questions, but they are not sufficient. A better starting point is more basic: do we understand the system we are introducing? Do we understand where it creates value, where it creates dependency, where human judgment remains essential and where uncertainty still resides?

The question becomes more urgent as AI becomes more agentic. We are moving from systems that answer questions to systems that plan, coordinate, execute and interact with other systems. In that world, AI behaves less like passive software and more like a participant in a broader operating environment. The risk is not merely that a tool produces an imperfect output. The risk is that interconnected actions begin to compound in ways the organisation does not fully understand.

The temptation, again, will be to respond with complexity. More rules, more procedures, more approval layers and more monitoring may appear to create safety. Sometimes they will. But every new control also becomes part of the system it seeks to control. It must itself be understood, maintained and governed. Before adding a layer of complexity, leaders should ask a harder question: does this increase understanding? If it does not, it may be increasing risk rather than reducing it.

This is why simplicity may become a competitive advantage in the AI era. Simple systems are not necessarily primitive. They are systems whose essential variables are visible, whose dependencies are known and whose behaviour can be understood with the resources available. Such systems are easier to control, easier to audit, easier to explain and easier to improve.

The organisations that succeed in the age of AI may not be those with the most sophisticated architectures or the largest number of automated processes. They may be those that keep their systems simple enough to understand them at their best. For if understanding is the foundation of control, and control is the foundation of risk management, then simplicity is not a retreat from sophistication. It is the condition that makes sophistication usable.

AI will continue to introduce uncertainty. That is unavoidable. The task of leadership is not to remove uncertainty from the world, but to avoid adding unnecessary uncertainty of one's own. In the end, risk management is not the art of predicting the future. It is the discipline of positioning oneself so that the future is more likely to unfold in one's favour.