Regulatory change and emerging risk top compliance concerns
,

Regulatory change and emerging risk top compliance concerns

Compliance functions and risk managers said that their top strategic priorities over the coming 18 months are keeping abreast of regulatory changes and mitigating emerging risk, according to Thomson Reuters. Half of respondents to the survey underpinning the report said they had noticed a recent shift in their organisations from viewing compliance as a tick-box exercise…

Compliance functions and risk managers said that their top strategic priorities over the coming 18 months are keeping abreast of regulatory changes and mitigating emerging risk, according to Thomson Reuters.

Half of respondents to the survey underpinning the report said they had noticed a recent shift in their organisations from viewing compliance as a tick-box exercise to regarding it more as a strategic activity.

Strategic perspective

“In the past, companies’ risk and compliance functions have often been dismissed as cost

centres intent on stifling innovation and opportunity,” the report said. “However, the dynamics of corporate leadership are shifting, and these teams are now increasingly considered strategic partners to the business, fundamental to supporting stability, improving efficiency, and maximizing growth.”

The survey found that most organisations had about 15 people dedicated to risk and compliance, but this number had increased in recent years as businesses seek to cut costs by insourcing those activities. In fact, 63 per cent said more risk and compliance work has been

insourced at their organisations over the past 2 years: 39 per cent said they are insourcing more of that work every year.

ESG evolution

A key driver for these changes has been the rise in regulation around Environmental, Social and Governance reporting, the report said. Over half of respondents (57 per cent) said that had resulted in compliance roles becoming more specialised and had increased the use of more advanced technologies.

But there is still work to be done. Almost four in ten organisations said they had not clearly defined ESG, according to a report in the Harvard Law School Forum this summer. A significant minority (17 per cent) of organisations said they did not know who was responsible for ESG in their businesses.

“Whereas a company’s status as public or private was significantly correlated with whether the company had clearly defined ESG, that characteristic does not appear relevant to who oversees ESG,” the report said. “Indeed, the survey indicated that private companies were as likely as public companies to have an ESG officer.”





← Previous

Cyber risk tops threats to financial system
Cyber risk is the leading systemic risk for the financial sector, according to the most…






Next →

Government focuses on understanding AI’s future
The UK government has called for better understanding of artificial intelligence (AI) to balance the…

7 OCTOBER 2026

Key elements of a mature programme risk capability

Hosted by Vinay Shrivastava. Vinay's presentation will cover lessons he has learned over the course of his career. These insights will be shared using the principles of ISO31000 risk management.

Find out more

8 OCTOBER 2026

Pre-deployment agentic risk management

Delivered by Adam Grainger, the outcome of this session is to be able to support an agentic implementation with effective pre-deployment risk identification and mitigation.

Find out more

14 OCTOBER 2026

AI Transforming Enterprise Risk Management Activities

Risk management has changed considerably over the years, with new frameworks, standards and expectations shaping the way organisations manage risk. However, many of the day-to-day activities within Enterprise Risk Management (ERM) functions have remained much the same.

Find out more

Advertisement