Why Risk Productivity Now Matter

Banks’ second lines of defense (2LOD) are facing an expanding mandate: beyond traditional credit and market risk, they must now oversee third-party risk, climate and ESG, cyberthreats, data risk, and evolving regulatory expectations across jurisdictions. Despite this heavier load, overall risk headcount and budgets have remained broadly stable, forcing chief risk officers (CROs) to seek productivity gains rather than simply adding resources.

McKinsey’s latest Global Risk Productivity Benchmark shows that risk organizations are reshaping how they allocate people, where they invest in technology, and how they design operating models to build a more strategic, AI-ready risk function.

Theme 1: Risk Resources And Leadership Are Rebalancing

The survey of more than 40 global and regional banks (average balance sheet around 1.1 trillion dollars, including 15 G‑SIBs) reveals broad stability in overall risk resources: median risk FTE “intensity” as a share of total bank headcount is slightly lower than in prior surveys, and costs have also remained steady. At the same time, variability between low- and high-intensity banks is shrinking, as institutions with previously lean risk teams add capacity and those with heavier setups streamline.

Within that stable envelope, there is a marked reallocation of risk talent. FTEs in credit risk have declined by about 7 percent annually between 2020 and 2023, driven by automation and greater first line of defense (1LOD) ownership of transaction-level decisions, while headcount in market risk and operational risk has risen by roughly 3 percent and 11 percent per year, respectively. Risk leaders increasingly see themselves as enablers of AI and automation, trying to boost productivity without eroding core capabilities or human judgment.

Theme 2: The Risk Operating Model Is Being Refined

CROs are adjusting operating models to cope with a heavier burden and rapid technology change, often without extra resources. One major shift is closer collaboration with the first line and a stronger push to embed risk ownership where risks originate: businesses are expected to run better risk and control assessments, monitor key risk indicators, and use automated decision engines for credit and collections, while the 2LOD focuses on portfolio-level oversight.

At the same time, enterprise risk management (ERM) budgets have grown by about 10 percent, with additional spending on nonfinancial risk oversight, climate and ESG, and strategic risk, reflecting a push toward holistic resilience. Retail credit risk has become more automated, reducing time spent in 2LOD and freeing resources for wholesale credit and faster-growing areas like credit modeling and analytics, where FTEs have expanded by roughly 10 percent a year since 2020. Market risk teams are also shifting: data collection and exploitation are up more than 10 percent annually, even as modeling and P&L calculations decline modestly, underscoring a focus on automation and data-driven oversight.

Theme 3: Regulation Is Tougher, More Nuanced, And More Demanding

Supervisory expectations are tightening, especially in Europe, where regulators have raised the bar on climate risk management and are enforcing principles like BCBS 239 on risk data aggregation and reporting. New rules such as the EU’s Digital Operational Resilience Act (DORA) and the Fundamental Review of the Trading Book are shaping operational and market risk practices, and in some cases supervisors have pressed large banks to increase risk FTEs.pwc+1

Operational risk capital requirements have risen—by about 15 percent in Europe between late 2022 and late 2024—reflecting Basel IV changes and national interventions like the Monetary Authority of Singapore’s capital multipliers after major incidents. Regulators are also demanding more transparency and agility: banks must be able to run ad hoc stress tests, drill down to obligor or product level, reconcile with finance, and provide auditable, explainable outputs on short notice, pushing them toward agile data pipelines, reusable scenarios, and more advanced reporting centers.

Theme 4: Technology And AI Are Moving From PowerPoint To Production

Technology is becoming central to risk productivity, with many CROs wanting to be early leaders in digital risk and AI, not followers. By mid‑2024, the majority of surveyed banks had at least piloted data analytics and “traditional” AI in risk use cases, especially in reporting, data management, credit decisioning, and pricing, and about 70 percent had run proofs of concept in AI-driven credit. Leadership‑aspirant institutions are testing AI across more risk dimensions and use cases; others are experimenting with generative AI to capture quick wins.

Despite headcount reductions in some areas, credit risk still accounts for about 1.2 percent of total bank FTEs and around 45 percent of risk FTEs, making AI applications in credit modeling and automated workflows a top priority. Risk functions are investing serious time and people: some allocate 100–200 hours per year per leader to digital and analytics topics, and a significant share employ dozens of FTEs focused on technology and data. Yet three blockers consistently slow deployment—poor data quality, privacy and security concerns, and misuse risks—highlighting the need for strong data governance and clear AI-use frameworks.

Theme 5: Mutualization, Location Strategy, And Agentic AI

To meet rising expectations without increasing size, banks are mutualizing and industrializing risk activities. Shared-service centers and centers of excellence are increasingly used for model risk management, analytics hubs, reporting, and change/IT functions, sometimes including specialized centers for AI and machine learning model oversight. About a third of surveyed banks operate sizable international hubs for risk, with offshored and nearshored resources representing roughly one‑fifth of risk FTEs on average; offshoring is most prevalent in model risk, change, and IT-related risk services.

Credit risk and regulatory relations remain more local, but AI’s rapid progress is prompting some banks to consider skipping traditional mutualization or offshoring steps and instead moving directly to agentic AI workflows as a new efficiency paradigm. In parallel, risk organizations are streamlining internal structures to reduce fragmentation and complex spans of control, balancing specialization by risk type, business line, geography, and enterprise functions while keeping the model agile and aligned with business needs.

Productivity As The New Differentiator

The survey’s overarching message is that risk productivity and effectiveness, not headcount, will define success. Leading risk organizations are clarifying mandates and three-lines-of-defense responsibilities; creating granular transparency on cost and capacity; simplifying and automating high-volume work; embedding AI and automation under risk-owned governance; and building coherent structures with centers of excellence and shared services to support clear resource reallocation and talent strategies.

The shift from risk to resilience remains central: CROs must implement AI at scale, develop cross-risk analytical capabilities, standardize infrastructure for responsible AI, and cultivate talent that blends traditional risk expertise with digital-native skills. The key question, as McKinsey frames it, is whether CROs will proactively drive this transformation—becoming enablers of performance and resilience—or simply react to mounting pressures.

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these