Risk theatre and risk culture look nearly identical from outside an institution — both produce committee minutes, risk registers, and board reporting packs. The difference only becomes visible when something actually goes wrong, and by then, distinguishing them is no longer an academic exercise.
Risk theatre is a control that exists because a policy document says it should, monitored by a committee that meets on schedule and notes the relevant paper, with no individual who could describe, specifically, how they'd know if the control were quietly failing. Risk culture is the same nominal control, but owned by someone who can answer that question immediately, because they've actually thought about it recently, not just when the annual review came around.
The gap between the two rarely shows up in documentation review, which is precisely why theatre persists undetected for years. A risk register entry reads identically whether it describes a genuinely monitored control or a dormant one — the difference lives entirely in whether a specific person is actually paying attention, and that's not something a document can certify.
I test for this directly in engagements by asking a control's named owner, without notice, to describe what they did last month to actually exercise oversight. Genuine risk culture produces a specific, immediate answer. Risk theatre produces a pause, followed by a general description of the policy rather than a specific recent action.
Institutions serious about closing this gap need to build that same unannounced question into their own internal review cycle — because the moment a genuine incident occurs, that's exactly the question a regulator, a journalist, or a board member is going to ask, and 'the policy exists' will not be an adequate answer.