A denser map of disclosed risks
In September 2026, Swiss Re Institute and the London School of Economics reported that the number of connections among risks disclosed by 91 Fortune 100 companies was 24% higher than in 2019. Their joint analysis places artificial intelligence and supply chains among the most important points where different risks meet. This is a measure of connections found in corporate disclosures, not a measured 24% increase in losses or in the probability of a systemic crisis.
The researchers also found that the share of companies reporting AI and new-technology risks increased by about 30% over the period. They describe paths that connect digital systems, financial markets, natural hazards and political or social disruption. A local shock can have broad effects when many organisations depend on the same provider or infrastructure.
Why diversification may be misleading
A multinational can distribute subsidiaries across countries and still share a single cloud environment, payroll provider, medical administrator, payment network or critical logistics route. Insurers and captives can likewise write apparently unrelated exposures that respond to one outage. The group’s financial statements may show geographic and line-of-business diversification while its operational dependencies remain concentrated.
This requires a different exposure exercise. Risk teams should start with a critical service or supplier, map the entities and benefits arrangements that rely on it, identify substitute providers and estimate how long the group could operate without it. The relevant loss may extend beyond property damage to business interruption, delayed claims, employee access to care and reputational costs. The same exercise should test a physical event affecting shared digital infrastructure.
Insurance and captive implications
For insurers and reinsurers, accumulation should be examined across policies and products rather than inside a single coverage silo. Cyber, property, contingent business interruption, liability and employee-benefits assistance may all be implicated by one incident. Coverage triggers, aggregation clauses, exclusions, waiting periods and policyholder mitigation duties can determine whether separate policies respond as expected. Scenario analysis should reflect those interactions before the group relies on assumed diversification.
A captive can consolidate claims and exposure data across subsidiaries, retain predictable layers and clarify which losses the group is deliberately financing itself. It does not remove a common dependency. Its board should see the group’s exposure to the same suppliers, geographic clusters and model providers across retained and reinsured layers, as well as the operational recovery assumptions supporting its capital assessment. An independent non-executive director should ask management and the actuary to challenge correlated scenarios and explain any gap between operational resilience and risk-transfer assumptions.
A practical board test
Select two material dependencies and run a joint exercise with procurement, IT, HR, risk, insurers and the captive. For each, ask what fails first, what employee populations are affected, when cash is needed, and which policy or retention responds. Record the weakest contractual or data link and an owner for remediation. Repeat the test after a change in provider or major acquisition.
The study does not predict the next shock. It supplies a question for boards: how much of the apparent spread of risk rests on the same service or response mechanism? That question connects continuity planning with insurance design and capital allocation.
The framework can be applied to a benefits pooling network: ask whether a single network administrator, insurer or provider controls data, claim routing or settlement across many countries. The scenario should include a prolonged outage and a simultaneous surge of queries from employees. The network should identify which local carriers can continue paying claims, what information headquarters can retrieve independently and where an alternative servicing arrangement has already been contracted. For reinsurance, this same exercise can reveal whether several cedants share a service provider even when their insured populations do not overlap. The resulting common exposure should appear in counterparty and accumulation reports, with explicit uncertainty where data are missing. These are proposed governance tests based on the research, not examples of failures documented in the study.
Sources
Swiss Re Institute and LSE, The age of interconnected risks, September 2026
Source: 2026-09-26_GBV_Systemic_Risks_Swiss_Re_LSE.docx
