A New Risk Landscape

Organizations are facing a risk environment that is more volatile, interconnected, and fast-moving than at any point in recent decades. Geopolitics, cyberthreats, trade tensions, and rapid digitalization mean that risk leaders are now central to strategic decision-making, not just compliance.

In this context, “good” risk management is no longer static, document-heavy, or backward-looking. It must be dynamic, tech-enabled, and capable of supporting real-time decisions across the enterprise.

Five Global Forces Reshaping Risk

Five structural forces that are redefining how risk functions must operate:

  • Geopolitical flux as the new normal: The global uncertainty index is vastly higher than 20 years ago, with ripple effects across supply chains, capital flows, cyber activity, and domestic policy. This demands more dynamic scenario planning, stress testing, and forward-looking risk frameworks that can adapt quickly.
  • Technological progress and AI: Digitalization and AI are transforming customer journeys, fraud and cyber risk, and contagion dynamics, requiring near-real-time data, new metrics for nonfinancial risks, and updated risk appetite frameworks.
  • Interconnected risks: Economic, operational, cyber, and strategic risks increasingly share common drivers, making siloed risk types obsolete. Risk functions must manage these as integrated portfolios through enterprise risk management and cross-functional teams.
  • Shifting competitive landscape: Nonbank financial institutions now hold a large share of global financial assets, complicating counterparty risk and oversight. Digital assets add new risk types, especially around AML, third-party dependencies, and operational resilience.
  • Regulatory fragmentation: After years of relative alignment, regulations are diverging across jurisdictions, raising complexity for multinational institutions. In many areas, internal risk appetite will become more binding than external rules, especially where regulations lag technology.

What Stays The Same In Risk Management

Despite profound change, some foundational elements remain central:

  • Three lines of defense (3LOD): The model continues to be essential, especially the second line’s role in standards, oversight, and accountability, even as technology allows the first line to take on more risk tasks.
  • Risk frameworks and appetite: A clear risk management framework and risk appetite statement remain the anchors for governance and culture. They must, however, become more granular and embedded into “controls by design.”
  • From risk to resilience: Stakeholders expect institutions not only to manage risk but to demonstrate financial and operational resilience. Cross-risk scenario analysis and simplification of processes, data, and systems become key enablers.

What Will Change: Towards Continuous, AI-Driven Risk

How risk will evolve in an AI-defined future:

  • Dynamic risk appetite and simulations: Institutions will run continuous synthetic simulations (macroeconomic shocks, climate events, cyberattacks) and potentially operate digital twins of balance sheets and critical operations to test resilience before major decisions.
  • Continuous real-time monitoring: Periodic, sample-based assurance will give way to always-on portfolio monitoring using shared data across all lines of defense. This approach, already common in market, liquidity, and cyber risk, will extend to credit and nonfinancial risks.
  • Integrated risk profiling: Financial, nonfinancial, and strategic risks will be analyzed together, focusing on root causes—human and infrastructural. Agile, squad-based models will replace rigid silos, with analytics-savvy specialists working alongside domain experts.
  • Hybrid human–AI workforce: Routine tasks (exposure monitoring, scoring, fraud detection) will be heavily automated by multiagent systems, while humans provide oversight, ethical judgment, and orthogonal thinking.
  • New human roles: Future risk managers will be valued for subject-matter depth and critical, independent thinking rather than process administration. Training will shift toward scenario- and simulation-based learning to prepare people as “humans in the loop.”

Reimagining The Risk Function

Instead of rebuilding risk from scratch, we argue for evolutionary transformation anchored in three organizational components:

  • Strategic nerve center: A central intelligence unit that sets risk appetite and limits, identifies emerging risks, runs scenarios, and synthesizes insights for leadership. This unit is staffed by cross-functional, strategic thinkers and tightly linked to an analytics center of excellence.
  • Domain-specific pods: Risk pods organized by risk types or critical domains (e.g., legal entities), staffed by senior experts who apply judgment to exceptional cases while bots handle most operational tasks.
  • Analytics center of excellence (COE): A shared engine room that continuously analyzes data, monitors thresholds, and powers fully digitized reporting and self-service analytics. This COE brings together multiagent systems and human analysts.

This structure supports differentiated career paths: strategic leaders in the nerve center, deep specialists in the pods, and data/AI talent in the COE, with rotations to encourage cross-pollination.

What CROs Need To Do Now

The authors close with four practical imperatives for chief risk officers:

  • Invest in upskilling: CROs and their teams must deepen their understanding of AI, its applications, and its risks to avoid becoming bottlenecks and instead act as enablers of transformation.
  • Strengthen cross-cutting capabilities: Build or enhance enterprise risk management and risk-agnostic monitoring capabilities that can connect risks across types and support faster, coordinated responses.
  • Ensure responsible, transparent AI: Design governance for AI use cases, including approval frameworks, continuous monitoring, documentation, and ethical guidelines that balance speed with safety and regulatory expectations.
  • Evolve talent strategy: Hire and develop data scientists, modelers, engineers, and AI specialists alongside traditional risk experts, and redesign career paths and performance systems accordingly.

McKinsey’s prior work on CRO archetypes—protector, architect, and business accelerator—underlines that the best risk leaders know when to shift modes, balancing prudence with innovation. In a rapidly changing environment, CROs have a unique opportunity to shape risk functions that not only protect value but also enable growth.

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these