This site is part of the Informa Connect Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 3099067.

Risk Management
search
CRO

15 things risk leaders learnt from [The new CRO agenda: Untangling risk in an AI-driven world]

Posted by on 01 October 2026
Share this article

How are AI, evolving regulation, and geopolitical uncertainty redefining the modern CRO agenda? Kirsty Hart, Global Head of Risk and Compliance at Archer, examines how organisations are connecting risk across the enterprise to improve decision-making, strengthen resilience and prepare for what's next.


1. Risks don't live in silos

AI, operational resilience, third-party risk, regulation, and geopolitics all converge on the same services, processes, and decisions. Managing them as completely separate categories creates a false sense that the risks themselves are separate.

2. The CRO role is evolving in three ways:

  • Hindsight to foresight: Move beyond periodic RCSAs to scenario analysis and emerging threat signals.
  • Gatekeeper to orchestrator: Embed risk into decisions while options are still being considered, not as a sign-off at the end.
  • Risk reducer to value protector: Fewer findings doesn't automatically mean safer. Enable the organisation to take risks within agreed thresholds.

3. AI governance must treat AI as a business capability, not a tech implementation

Discovery and classification of AI systems come first; that classification determines the regulatory route, controls, and oversight required. Proportionate governance routes let low-risk use cases move efficiently while resources focus on high-risk ones.

4. Static AI approval isn't enough

An AI model approved today can change behaviour within days. Continuous runtime monitoring and human oversight are essential.

5. Operational resilience starts with the business outcome, not the system

Identify the important business service, apply a disruption tolerance, map dependencies (people, process, tech, third parties), run severe-but-plausible scenario tests, and define response choices, including vendor exit strategies.

6. Third-party risk must look beyond the direct vendor

Map fourth-party and fifth-party dependencies. Multiple vendors may share the same underlying provider, creating hidden industry concentration risk. Exit clauses tell you legal rights, not operational feasibility.

7. Vendor reassessment should be event-driven, not just annual

Material changes in vendor service, data access, or AI usage should trigger ad hoc reassessment. Don't wait for the next review cycle.

8. Regulatory change management requires full traceability

A changed obligation should trace through to impacted services, controls that need changing, internal owners, and evidence of implementation. Until you can evidence all four, regulatory change isn't complete.

9. Geopolitical risk needs to move from headlines to decisions

Map signals (sanctions, trade controls, instability) to actual organisational exposure, define trigger points that require a decision, and give management options: reduce, hedge, hold capital, or accept.

10. A single failure propagates fast

An AI fraud monitoring glitch can impact customers, retailers, support teams, and vendors within minutes, requiring answers that only a connected risk view can provide.

11. Balance central consistency with federated accountability

Centralise risk appetite, taxonomies, standards, and regulatory interpretation. Federate execution and domain-specific control ownership to business areas. This reinforces the three lines of defence model.

12. Board reporting should reduce cognitive load, not add to it

Start with the outcome at risk, explain scale and velocity of exposure, and always include a management recommendation. A red risk without a decision is just an observation.

13. Integrated GRC is the enabling architecture

It creates a common evidence chain connecting incidents to obligations, third parties to controls. AI can organise, but accountability stays with humans.

14. Start small and build organically

Pick one critical service, map it end-to-end (risks, obligations, applications, vendors, controls), identify gaps, run tabletop exercises, then expand quarter by quarter. Don't try to connect everything at once.

15. If investing in one thing next year, invest in connected risk capabilities

Great analytics on disconnected data sets gives no insight. Connected risk underpins both effective AI governance and meaningful risk analytics.


Discover more and connect with the largest, most senior community of financial risk managers at RiskMinds this November.


Share this article

Sign up for Risk Management email updates

keyboard_arrow_down