Trust

0
0
Hire Risk Expert
You agree to our Terms and Conditions of Use, PDPA & Privacy Policy and Cookies Policy

Trust

When Anything Can Be Created, Copied or Manipulated, How Do We Know What to Trust?

Trust has always mattered. We trust people, businesses, institutions, documents, photographs, identities, reviews and information every day. And we trust often without consciously thinking about it. 

One of my pet peeves that I have is that people trust people simply because of their status in life, or because they are Professionals! This is another story for another day but sufficient to know that to me, one of the biggest measurable whether 'something' or 'someone' can be be trusted is how long the person has been doing it, and/or how long the history. 

We can't deny that something important is changing, and in mind-blowing ways!

A.I. can create convincing text, voices, photographs and videos. A fake identity can look genuine. A convincing expert may not be an expert at all. Reviews can be manufactured. False information can travel around the world before the truth catches up. And increasingly, we may interact with A.I. without even knowing whether there is a human on the other side.

This creates a very different question for individuals and organisations:

How do we know what (or whom) to believe?

Fortunately for us, most of us are not that expert in creating deepfakes yet. I mean come on! You can tell an A.I. Avatar from the real me right?

But yes with these massive leaps in A.I. technology, we feel that Trust deserves its own section on our website.

How Does Trust Relate to the Pillars of Risk Management?

Trust connects strongly with the established Pillars of Risk Management, particularly Cyber Risk, Governance & Compliance, Third-Party Risk, Enterprise Risk, Technology Risk and Risk Assessment.

If somebody impersonates a senior executive using a deepfake, there may be a Cyber Risk. If a third-party supplier provides inaccurate or misleading information, there may be Third-Party Risk. If an organisation makes claims that cannot be substantiated, there may be Governance & Compliance implications. If damaged trust affects customers, investors, employees or business relationships, it can become an Enterprise Risk.

Trust can also affect Operational Resilience and Business Continuity. During a crisis, people need to know which information is genuine, which instructions to follow and who is authorised to communicate.

But trust is also bigger than the traditional risk pillars.

Risk Management frameworks can help us identify threats and introduce controls. They cannot completely answer the human question:

“Do I believe you?”

Trust ultimately exists between people, organisations, information and the systems we increasingly depend upon. I am only saying about Trust existing between people. I find people a bit odd nowadays, some not exhibiting expected behaviour at all. Have you also observed the same? 

Trust Is Becoming Harder to Assume

For much of the digital era, we learnt to question suspicious emails, unfamiliar links and unusual requests.

The next challenge is more difficult because the suspicious thing may no longer look suspicious.

A voice may sound exactly like someone we know. A video may appear authentic. An email may be perfectly written. A website may look professional. An online profile may appear credible. An A.I.-generated explanation may sound authoritative even when the underlying information is wrong.

The problem therefore moves beyond simply spotting something that looks fake.

We increasingly need to ask:

How was this verified? Where did it come from? Who is really behind it? Can I confirm it somewhere else?

Verification may increasingly become part of everyday risk thinking.

A.I. Changes the Economics of Trust

This is one reason Trust is separate from A.I. & Risk on this website.

The A.I. & Risk section asks how we manage and govern A.I. itself. Trust asks what happens to society, organisations and individuals when technology makes convincing content and identities much easier to create.

A.I. did not invent misinformation, impersonation, fraud or damaged reputations.

What it changes is the speed, scale and ease with which convincing material can potentially be produced.

Deepfakes are an obvious example. But the wider issue includes synthetic voices, fake experts, fabricated evidence, manipulated content, false reviews and A.I.-generated information that may be repeatedly copied until nobody knows where it originally came from.

The risk is not simply that false information exists.

The deeper risk is that genuine information may also become harder to trust.

Reputation Can Take Years to Build and Minutes to Challenge

Trust and reputation are closely connected, but they are not exactly the same.

A business builds reputation through what it repeatedly does, and in how how it treats customers, responds to problems, delivers its promises and behaves when things go wrong.

But reputation now exists in an information environment that the business does not completely control.

A misleading post, fabricated image, fake review or false allegation can travel quickly. An organisation may find itself responding publicly before it has even established what happened.

This is why reputation risk increasingly overlaps with information integrity, verification, crisis communication and misinformation management.

The question is no longer only:

“How do we protect our reputation?”

It is also:

“How do we establish what is true quickly enough to respond well?”

Misinformation and Disinformation Are Not the Same Thing

Not every piece of false information is deliberately created to deceive.

Misinformation generally refers to false or inaccurate information that may be shared without an intention to mislead. Disinformation involves deliberate deception.

For an organisation trying to respond, that distinction can matter.

A confused customer repeating something incorrect may require a very different response from somebody deliberately impersonating the organisation or manufacturing false information.

This is why understanding the source, intention, reach and potential consequence of false information becomes part of assessing the risk.

Trust Is Also About What We Do When Something Goes Wrong

No organisation can guarantee that nothing will ever go wrong.

Mistakes happen. Systems fail. People make poor decisions. Information can be incorrect.

Trust is therefore not built only by preventing problems.

It is also shaped by how we respond when problems occur.

Do we acknowledge what happened? Do we communicate clearly? Do we correct inaccurate information? Do we explain what is known and what remains uncertain? Do we take responsibility where appropriate? Do our actions match what we say?

This brings us into crisis communication, transparency and rebuilding trust.

Sometimes the response to a problem becomes almost as important to trust as the original problem itself.

What We Will Explore in Trust

We have divided Trust into eight areas.

Trust Risk explores what happens when customers, employees, investors or other stakeholders no longer believe or rely upon an organisation.

Reputation Risk looks at how actions, events and information can affect how an organisation is perceived.

Misinformation & Disinformation examines inaccurate information, deliberate manipulation and how organisations can understand and respond to both.

Deepfakes looks specifically at synthetic or manipulated media and the growing problems of impersonation, authenticity, verification and fraud.

Information Integrity asks whether information is accurate, reliable, traceable and fit to be relied upon.

Crisis Communication considers how organisations communicate when events are moving quickly and reliable information matters most.

Rebuilding Trust looks at what happens after confidence has been damaged and what organisations can realistically do to restore it.

Digital Identity explores a question that may become increasingly important: in a digital world, how do we establish that somebody/something is really who or what it claims to be?

Across these areas, we will also explore authenticity, verification, transparency, fake experts, institutional trust and the emerging idea of trust architecture as well as the systems and processes we use to establish confidence rather than simply assuming it.

From “Trust Me” to “Verify Me”

Perhaps one of the biggest changes ahead is that trust may increasingly require evidence.

For individuals, that may mean checking the source before sharing something.

For businesses, it may mean creating clearer verification processes for unusual instructions, payments or requests.

For leaders, it may mean recognising that a familiar voice or face is no longer necessarily proof of identity.

For organisations, it may mean being able to demonstrate where important information came from and how it was verified.

And for all of us, it may mean becoming comfortable saying:

“Before I act on this, how do I know it is real?”

That is not about becoming suspicious of everything.

It is about adapting our methods of trust to an environment in which authenticity can no longer always be judged by appearance alone.

Trust Cannot Be Controlled Completely

There is another reason Trust is different from many conventional risks.

An organisation can introduce controls, but it cannot order people to trust it.

Trust is earned through behaviour, consistency, competence, communication and experience. It can be strengthened. It can be damaged. And once damaged, rebuilding it may take time.

That makes trust difficult to put neatly into a risk matrix.

Yet its consequences can be very real: customers leave, employees disengage, partners reconsider relationships, investors become concerned and people stop believing what an organisation says.

For risk management, therefore, the challenge is not to control trust.

It is to understand what creates it, what threatens it, what evidence supports it and what we can do when it begins to disappear.

Questions We Will Be Exploring

Throughout Trust, we will explore questions including:

  • What Is Trust Risk?

  • How Do Companies Lose Trust?

  • How Do You Rebuild Trust After Something Goes Wrong?

  • What Is Reputation Risk?

  • How Do You Know If Information Is Real?

  • How Can You Spot a Deepfake?

  • What Are the Business Risks of Deepfakes?

  • What Is Misinformation Risk?

  • Misinformation vs Disinformation: What's the Difference?

  • How Does A.I. Affect Trust?

  • Can You Trust A.I.-Generated Content?

  • How Do I Verify What A.I. Tells Me?

  • What Is Information Integrity?

  • How Do Fake Reviews Affect Trust?

  • Can We Trust Online Identity Anymore?

  • What Happens When Nobody Knows What Is Real?

  • How Should Businesses Respond to False Information?

  • How Do You Communicate During a Crisis?

  • Why Is Transparency Important?

  • How Much Should We Trust an A.I. Agent?

In a world where almost anything can look convincing, trust may increasingly depend not on what looks real, but on what we can verify.