AI and Geopolitics Strain Risk Management

Almost two-thirds of audit leaders are finding it harder to identify potential risks before they have a material impact on their organisations, according to Gartner findings reported at the Gartner Enterprise Risk, Audit and Compliance Conference. The survey found that 64% of audit leaders are facing greater difficulty in identifying risks early.

The findings point to a growing challenge for traditional risk-management frameworks. Organisations are simultaneously dealing with the adoption of artificial intelligence, new operating models, changing regulation and geopolitical uncertainty. According to Gartner analysts, the combination is placing increasing pressure on established governance, controls and risk-management practices.

However, the problem is not simply a lack of risk information. Gartner argues that providing business leaders with more policies, risk reports and oversight does not necessarily translate into better risk decisions.

Only around 30% of business-unit leaders surveyed said their ability to manage risks was influenced by insights and findings received from audit, compliance and risk-management teams. This suggests a significant gap between the information produced by assurance functions and the ability of operating teams to act on it.

From Risk Information to Risk Action

The findings highlight the importance of strengthening risk ownership within business functions.

Audit, risk and compliance teams traditionally provide assurance, identify control weaknesses and communicate emerging risks. But organisations increasingly need business managers themselves to understand their responsibilities and make informed risk decisions during day-to-day operations.

Gartner describes this as a confidence and capability gap. Business leaders may receive detailed risk insights but still lack the practical knowledge needed to translate those insights into action.

The proposed response is therefore not simply to expand the size of assurance functions. Instead, organisations should find scalable ways to build risk-management capability directly within business workflows.

This could include embedding guidance and decision-support tools into existing processes, providing assurance coaching at the point where decisions are made and establishing repeatable collaboration between business teams and assurance functions.

AI Could Support Risk Decisions

Artificial intelligence is also identified as a potential tool for closing this capability gap.

AI systems can help translate specialist knowledge and process guidance into practical support for business users. They could assist employees in completing risk-management tasks, identify relevant control requirements or allow users to test their reasoning against established audit, risk and compliance knowledge.

This creates an interesting shift in the role of AI within risk management. Rather than using AI only to identify risks, organisations can potentially use it to help employees make better decisions about risks within their own areas of responsibility.

However, such applications would still require appropriate governance, particularly where AI-generated recommendations influence material business decisions.

A Broader View of Organisational Risk

The findings also reinforce the importance of closer collaboration between audit, risk and compliance functions.

Each function sees different aspects of the organisation’s risk profile. Combining their observations can provide business leaders with a more complete picture of emerging threats and control weaknesses.

The broader challenge is therefore not simply increasing the volume of risk oversight. It is improving the organisation’s ability to manage risk through thousands of operational decisions made every day.

For banks, insurers and other financial institutions, this is particularly relevant as AI adoption, regulatory requirements, cyber threats, third-party dependencies and geopolitical developments increasingly intersect.

The Gartner findings suggest that effective risk management will require a stronger emphasis on capability building, decision support and risk ownership within business functions.

The objective is not for assurance teams to manage every risk themselves. Instead, they need to help the wider organisation develop the knowledge, tools and confidence required to make risk-aware decisions consistently.

Want to deepen your expertise beyond today’s news?

Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.

Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.

#Riskmanagementnews

author avatar
RMA INDIA

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.