Human Risk
Most organizations govern their systems and their facilities. Almost none govern the people they trust.
A large share of events that surface as cyber or physical failures begin as human ones. The privileged insider. The executive hired without verification. The succession nobody planned. The automated hiring tool nobody audited. Apogee governs the human layer with the same rigor applied to the other two.
The six areas we govern
Each can be engaged as an assessment, a strategy, a governance design, or a sustained program: the same four services that structure every Apogee engagement.
Executive due diligence & verification
Before an organization hands someone its authority, its credentials deserve more than a résumé read-back. We verify executives to an investigative standard (history, claims, exposure, and conflicts) before the trust is extended, not after it is abused.
Vetting program governance
Background checks are a moment; vetting is a program. We design and govern the screening architecture: what is checked, how often, for which roles, and what happens when something surfaces mid-tenure.
Insider threat
The person with the badge and the credentials is the exposure no perimeter addresses. Program design that detects, deters, and manages insider risk without turning the workplace into a surveillance state.
Leadership & succession risk
The succession nobody planned is a risk event with a long fuse. We assess key-person exposure, continuity of decision authority, and the bench behind the org chart, and govern the plan that closes the gap.
Workforce & personnel assurance
Assurance that the workforce you have is the workforce you think you have: role-based trust levels, access aligned to duty, and the personnel controls that keep both true as people move and roles change.
AI hiring governance
Automated hiring tools make consequential decisions about people at scale, and most have never been audited by anyone accountable for the outcome. We govern the models, the vendors, and the decisions they are allowed to make.
Due diligence to an investigative standard, not a screening-vendor standard.
This domain carries a credential no cybersecurity firm can imitate: the firm's founder is a retired FBI senior executive, and its investigative capability is real. Executive due diligence conducted by people who have run actual investigations reads differently (because it is different). The questions are sharper, the verification is deeper, and the judgment behind the findings has answered for consequences before.
The boundary, stated plainly
This is a governance and assurance discipline. Within the risk domains, we do not fill roles.
We assess, verify, and govern the people function. The firm conducts talent placement only for public sector entities requiring program management or technology focused roles, through its public sector practice under its own engagement terms. The two are never blended: an assurance finding is never a pretext for a placement fee, and a placement mandate never grades the program it hires into.
Common questions
What is human capital risk governance?
Human capital risk governance addresses the people layer of enterprise risk: executive due diligence and verification, vetting program design, insider threat programs, leadership and succession risk, workforce assurance, and AI hiring governance. A large share of events that surface as cyber or physical failures begin as human ones, and Apogee governs this domain with the same rigor applied to the other two.
How is executive due diligence different from a standard background check?
Background checks are a moment; Apogee conducts due diligence to an investigative standard. The firm's founder is a retired FBI senior executive, and the investigative capability is real. Executive due diligence here covers history, credential claims, exposure, and conflicts, conducted by people who have run actual investigations, not screening vendors working from a checklist.
Does the human risk practice overlap with talent placement?
No. This is a governance and assurance discipline; it does not fill roles. The firm conducts talent placement only for public sector entities requiring program management or technology focused roles, through its public sector practice under its own engagement terms. The two are never blended: an assurance finding is never a pretext for a placement fee, and a placement mandate never grades the program it hires into.
Ready to take a unified view of enterprise risk?
Schedule a conversation with M.K. Palmore to explore how Apogee Global RMS can serve your organization.
Schedule a Consultation