A shipowner does not register his vessel in Panama because he intends to sail there. He registers it there because the flag decides who has to answer when something goes wrong, and he has selected a flag that will not. Most rules, processes and organisational structures work the same way: they are designed to move responsibility away from the point where the decision is taken, and the consequence flows downhill until it reaches someone with no rule left to hide behind. That person did not decide anything. That person pays.

A ship’s flag tells you who will answer when something breaks

Under international maritime law, the flag state carries the legal duty to inspect a vessel, certify its safety, and enforce labour standards on board. That is the entire point of registration. A ship is a piece of territory that moves, and the flag decides whose law travels with it.

So the owner picks the territory. He can live in Piraeus, run the technical management from Cyprus, register the hull in Monrovia, and crew it from Manila. Nothing about that is illegal. Each link is compliant with its own frame. The International Transport Workers’ Federation, which has been documenting this arrangement for decades, describes a flag of convenience vessel simply as one flying the flag of a country other than the country of ownership, and points at the reason: cheap registration fees, low or no taxes, and the freedom to recruit the cheapest labour available.

What the owner buys is not a port. It is a gap. The state whose flag flies at the stern has neither the inspectorate nor the incentive to look closely at a fleet it will never see. The owner has bought distance between his decision and its consequences.

The industry knows this precisely enough to have built instruments around it. The Paris Memorandum of Understanding on Port State Control exists because flag states cannot be trusted to police their own registers, so the ports do it instead. Its annual performance lists rank flags on three years of inspection and detention data and sort them into a White, Grey and Black list. In the 2025 lists, forty flags sit on the White list, nineteen on the Grey, ten on the Black. The Black list is the list of flags whose ships are detained most often relative to how often they are inspected.

Read that structure again, because it is the interesting part. An entire international apparatus had to be invented to compensate for the fact that the party formally responsible has arranged not to be. Nobody in that apparatus is naive about it. The compensating mechanism is treated as normal infrastructure.

And when a ship is finally abandoned in a foreign port, which the ITF documents regularly, the crew on board discovers what the arrangement was actually for. There is an owner in one country, a manager in another, a registry in a third, and a crew agency in a fourth. Every one of them followed its own frame. The unpaid wages, the food running out, the months without repatriation: those are entirely real, and they belong to nobody.

Moral hazard is a design outcome, not a moral failing

The economics of this were formalised more than sixty years ago, and the formalisation is more useful than the outrage. In 1963, Kenneth Arrow examined how insurance changes the behaviour of the insured, drawing on a term already circulating in insurance practice: the effect of coverage on incentive. Once a party is shielded from the cost of an outcome, that party’s care in avoiding the outcome drops. Not because the party is dishonest. Because the price signal has been cut.

The word “hazard” carries a moral tone that misleads people. It sounds like an accusation of bad faith. It is not. It is a statement about geometry. If you separate the person who takes a decision from the person who absorbs its consequence, the decision degrades. Reliably. Regardless of character.

The principal-agent literature that grew out of that period describes the same geometry from the other side: whenever one party acts on behalf of another whose interests differ, and the acting party knows things the other does not, the acting party’s rational move is to optimise for what will be observed rather than for what actually matters. A process that is auditable will beat a process that is effective, every time, if only the audit is checked.

Put those two together and you have the mechanism this whole essay is about. A rule can be written to achieve its stated purpose. A rule can also be written to produce evidence that its stated purpose was pursued. The second is cheaper, faster to demonstrate, and defensible in front of a regulator, an insurer or a court. Organisations are not stupid. They pick the second more often than they admit, and they rarely pick it consciously enough to feel dishonest about it.

Organised irresponsibility describes what mature structures produce on purpose

Ulrich Beck gave this its sharpest name. Writing on the risk society, most famously in Risikogesellschaft (1986, published in English as Risk Society in 1992) and then in Gegengifte: die organisierte Unverantwortlichkeit (1988), he argued that modern institutions have become extremely good at generating hazards while simultaneously generating the procedural conditions under which nobody can be held accountable for them. Organised irresponsibility: the phrase does the work.

The word that matters there is “organised”. Not “accidental”. Not “emergent”. The dilution of responsibility is an output of the system working as designed, and the system is often improved in that direction over time. Every incident produces a new procedure. Every new procedure adds a documented step, a sign-off, a delegated control. The chain lengthens. The audit trail thickens. And the number of people who could actually be held to answer for an outcome goes down, not up.

This is why “we have a process for that” is such a durable sentence in corporate life. It is not a description of capability. It is a claim about liability, and it is usually true.

Here is the part that should bother a chief executive. The same maturity curve that makes a large organisation reliable also makes it a very efficient exporter of risk. Its counterparties are almost always smaller, less lawyered, and less able to say no. So the risk moves outward, to suppliers, subcontractors, partners, franchisees, and eventually to individual employees on the last rung. Each transfer is documented. Each transfer is agreed. None of it looks like coercion, because at every step somebody signed.

A case: the secure process that secured nothing

I want to reconstruct one case in detail, anonymised, because the abstraction only becomes useful when you can see the machinery turning.

A mid-sized company works with one of the very largest names on the French market. Being in that supply chain is commercially significant. It changes what other buyers think, it stabilises the order book, and it justifies hiring. The relationship is asymmetric in every dimension that matters: revenue concentration, legal capacity, and who can walk away.

The work requires the smaller company to hand over genuinely sensitive material. Commercial terms. Unit pricing and the reasoning behind it. Technical architecture. An honest inventory of what the company can and cannot do, which is the single most exploitable document any business produces about itself.

The large group has a secure document process. This is not a fiction and not a shortcut. It is written down, it is referenced in the contract, it has an internal owner, it appears in the group’s compliance reporting, and it has been signed off by people whose job title contains the word security. It has an official-looking external platform in front of it, operated by a third party with a public-sector flavour, which does a great deal of work on the perception side.

The process, executed as designed, does the following. The supplier uploads the document to the platform. The platform applies a watermark. The watermarked PDF is then attached to an email and sent onward to whoever inside the group needs it.

That is the whole control.

A watermark encrypts nothing. It restricts nothing. It expires nothing. It cannot be revoked once the file is out. It does exactly one thing, and it does it well: it writes the supplier’s identity onto every page. And the email carrying the file lands in an unknown number of mailboxes, on devices nobody has enumerated, subject to retention rules the supplier has never been shown, forwarded onward by people acting in good faith with no idea what the file is worth.

Anyone with a security background sees this instantly. Which raises the real question: how does a process like this survive inside an organisation that employs competent security people?

It survives because it is not a security control. It is a liability instrument, and as a liability instrument it is excellent.

Follow the incentives. Procurement needs a documented process in order to close the contract. Compliance needs a control it can name in a report. Legal needs the process referenced in the agreement so that the group’s obligation is defined and bounded. The internal auditor needs something checkable, and “was the platform used” is checkable in a way that “was the file actually protected” is not. The security team may well have flagged it, but the security team does not own procurement’s contract template, and the finding sits in a backlog behind things with owners.

None of these people is acting in bad faith. Each is optimising for what is observed in their function. The result of all that local rationality is a process whose real function is to establish that a procedure existed and was followed.

Now run the failure.

Eighteen months in, the file surfaces where it should not be. Maybe a laptop, maybe a departing employee, maybe an unrelated breach at a fourth party, maybe a forward to a consultant who also works for a competitor. The vector barely matters. What matters is what each side is holding when the music stops.

The group is holding a documented process, an audit trail showing it was followed, a contract clause defining its obligation narrowly, and a watermark that names the source of the leaked document. Its exposure is procedural and it is covered. Internally, this will be handled as an incident, closed with an action item, and possibly used to justify one more step in the process.

The smaller company is holding something else. Its pricing logic is now readable by anyone who wants to undercut it, and pricing logic is far more damaging than a price, because it tells a competitor where the floor is and why. Its honest inventory of weaknesses is now available to be quoted back at it in the next competitive situation. Its commercial terms with this group become the reference point every other large buyer will demand to match. And in the next negotiation with the group itself, its margin is no longer private information.

None of that appears as a line item. There is no invoice for it. The chief executive of the smaller company will feel it as a slow deterioration in win rates and negotiating position over the following two years, and will attribute it to market conditions, because that is the only explanation available without the document in hand.

The recourse is close to nil. Not because the law is unfair, but because the process was followed. The obligation was defined and met. The supplier accepted the process at contract signature, at a moment when refusing it would have meant not signing at all, and when nobody in the room framed it as accepting a transfer of risk. It was framed as security. It said security on the label. It had a platform.

That is what a flag of convenience looks like when it is made of paper. The group registered the handling of your most sensitive material under a regime that cannot hold it responsible, and it did so while telling you, accurately, that the regime existed and was documented.

The cost always lands on whoever is furthest from the decision

In every version of this pattern, the party that pays is the one with the least power to have shaped the rule. No coincidence there. Risk moves along the path of least resistance, and resistance is a function of power, so the selection mechanism does the work on its own.

The crew on the abandoned ship did not pick the registry. The supplier did not draft the document process. The apprentice put in charge of a critical technical subject, because the contractor who used to hold it was judged too expensive, did not decide to concentrate a company’s survival into the hands of its least experienced person. In each case the decision was taken several levels above, by someone whose exposure to the outcome had already been engineered away.

And the person who ends up carrying it is almost always grateful at first. That detail is worth sitting with. The apprentice is pleased to be trusted with something real. The supplier is pleased to be in the supply chain. Consent is present at every step, which is exactly why the arrangement is stable and why it does not read as abuse from the inside.

For a chief executive, the uncomfortable half of this is that the same logic runs in both directions. You inherit transferred risk from regulators, from large customers, from vendors whose terms you accepted because you needed the deal. You also transfer it: onto an underpowered hire on a subject nobody in your company understands, onto a supplier whose liability cap is smaller than the damage they could cause you, onto an internal process that documents an approval instead of producing a judgement. You will pay for the second kind later, and you will pay for it as an operational surprise rather than as a decision you remember making.

Cargo ship at the edge of a port

Read a rule by asking who wrote it

There is one question that cuts through all of it, and it is not a technical question. Who wrote this rule, and what would happen to them if it failed?

If the answer is “nothing”, you are not looking at a protection. You are looking at a transfer, and you are standing at the receiving end of it. That holds for a supplier’s security process, for a large customer’s subcontracting clauses, for an insurance exclusion, for an internal approval workflow, and for the training certificate nobody in the building could act on.

The repair is unglamorous and it is not more process. It is naming. Take the decisions in your organisation that would genuinely hurt if they went wrong, and put a person’s name against each one, not a committee, not a vendor, not a procedure. Then take the rules imposed on you from outside and mark, for each, who is exposed if it fails. What remains unnamed after that exercise is the list of risks you are carrying without knowing it.

Doing this does not make an organisation safer on its own. It makes the exposure visible, which is the only condition under which a leader is actually deciding rather than discovering. The alternative is to keep sailing under a flag somebody else chose, and to find out what it was worth on the day it matters.

Sources

FAQ

What is moral hazard, and why does it matter for how organizations write internal processes?

Moral hazard, a term Kenneth Arrow formalized in 1963 for insurance, describes how a party’s care in avoiding a bad outcome drops once it’s shielded from that outcome’s cost — not through dishonesty, but because the price signal has been cut. When you separate the person who takes a decision from the person who absorbs its consequence, the decision degrades reliably, regardless of anyone’s character. This is why a process can be genuinely well-documented and still fail to protect anyone: it was built to produce evidence of compliance, not the outcome it claims to secure.

How do you tell whether a rule is actually protecting you or just transferring risk onto you?

Ask who wrote the rule and what would happen to them if it failed. If the answer is ‘nothing,’ you’re not looking at a protection — you’re standing at the receiving end of a transfer. This applies to a supplier’s security process, a large customer’s subcontracting clause, an insurance exclusion, or an internal approval workflow. The fix is naming: attach a specific person’s name to every decision that would genuinely hurt if it went wrong, and mark who is exposed on every rule imposed on you from outside.