Insights
- Assurance can no longer be periodic. Regulatory change hit about 550 developments a day in 2024, and breach costs hit a record $5.0 million in 2026, higher still for financial services at $6.3 million.
- Three structural gaps hold institutions back. Fragmented risk visibility, inadequate third- and fourth-party oversight, and unclear governance prevent boards from receiving a reliable, enterprise-wide view of risk.
- Third-party risk is the most urgent pressure point. Lean teams, manual processes, limited vendor coverage, and poor visibility into shared dependencies leave institutions exposed to vendor-related incidents and operational disruption. Fourth-party risk is a blind spot by design.
- AI cuts both ways. It's fueling the threat, with AI-enabled breaches up 56%, while also being the clearest fix, though adoption is outrunning governance.
- The fix is a phased capability, and the market is already funding it. A four-phase roadmap lets institutions build incrementally, and Gartner expects legal and compliance tech spend to double by 2027.
The pressure pushing risk assurance into the boardroom
Financial institutions were hit with 550 regulatory developments every day in 2024, up three times from 2022. Meanwhile, the regulatory backdrop keeps compounding. The European Banking Authority identified Digital Operational Resilience Act (DORA) implementation, information and communication technology (ICT) risk management, and third-party risk oversight as priorities in its work program for 2026. One survey found that 65% of general counsel and compliance officers rank regulatory change as their top risk today, ahead of tariffs and other business concerns.
Breach economics make the case even stronger. IBM found the global average cost rose 12% to a record $5 million, driven by higher detection, escalation, and lost business costs. The financial services domain was hit hardest: Average breach cost reached $6.3 million, 26% above the global average. AI is now a named driver of that cost. The research also shows that one in four malicious breaches was AI-enabled, and financial services and energy were among the most targeted sectors by these AI-driven attacks.
The boardroom is also paying attention: Nearly 36% of North American chief financial officers (CFOs) named enterprise risk management a priority for 2026, and managing data-related privacy and cybersecurity risk remains one of the top priorities for CFOs.
Risk assurance, the process of confirming that risks are identified, controlled, and reported reliably, is being pulled toward continuous, data-enabled delivery because periodic, manual assurance cannot keep pace with the risk and regulatory environment institutions now operate in.
Where traditional risk assurance breaks down
Three connected gaps leave institutions unable to keep up with the growing pace of risk:
- A visibility gap: Risk data is locked in spreadsheets or legacy governance, risk, and compliance (GRC) tools, with no real-time visibility. Risk, controls, and assurance teams work in silos, and the board receives conflicting information from different functions. Risk appetite statements exist on paper, but don't translate into operational risk tolerances or key risk indicator (KRI) thresholds that management actually acts on. McKinsey found that the average risk maturity score across industries sits at just 2.6 out of 4.0, with 42% saying their IT and GRC systems need improvement, and 15% saying they are absent or lagging entirely.
- A third-party and operational exposure gap: Vendor and supply chain risk is largely unmonitored. A commonly cited resourcing benchmark is one dedicated third-party risk staff member per 100 vendors, yet a Ncontracts survey found 73% of financial institutions run third-party risk teams with two or fewer full-time staff even while overseeing 300 or more vendors. Whistic's 2025 TPRM Impact Report found enterprises added an average of three full-time employees over the year, yet 94% still lack the time or resources to assess all the vendors they'd like to, and third-party breaches kept rising even as headcount and spending grew. The consequence shows up directly in outcomes, with 49% of institutions reporting a vendor-related cyber incident. The real gap is that most institutions are still running lean teams against largely manual processes, leaving coverage gaps that automation is well placed to close. This gap is now visible at the top: third-party risk was ranked as the second most concerning risk category.
Fourth-party risk, or the risk from a vendor's own vendors, is invisible. Anothe Ncontracts survey found 26% of financial institutions do not assess fourth-party risk at all. And concentration risk, or the risk of multiple vendors relying on one provider, is not quantified or managed because institutions assess each vendor on its own rather than mapping shared dependencies. At the same time, institutions are often unable to identify important business services, define impact tolerances, or prove they can stay within them under severe disruption. The UK’s financial regulator, the Financial Conduct Authority, observed that many institutions would struggle to remain within impact tolerance for severe scenarios, such as a cyberattack or an outage at a third-party provider. Cyberthreats are evolving faster than control frameworks, and technology and operational risk remains disconnected from the enterprise risk view. - A governance gap: Frameworks exist, but ownership is fragmented across technology, operations, security, compliance, procurement, and internal audit. This is compounded by weak underlying data quality. KPMG found regulatory compliance and cyber risks are now the top two drivers of third-party strategy, at 48% and 37% respectively, yet only one in five institutions rates its third-party data quality as high.
These three gaps are structural, not transient, which is why boards need institutions to build sustained risk-assurance capabilities.
A phased path to continuous risk assurance
Institutions that treat risk assurance as a one-time compliance exercise will consistently be outpaced by the increasing pace and volume of threats. They must build assurance as a continuous, data-enabled, and increasingly AI-augmented capability, spanning the full risk life cycle from identification and appetite-setting through testing of controls to real-time monitoring and reporting to the board.
Each institution should follow a structured framework fit assessment, evaluating industry, regulatory exposure, risk appetite, and current maturity, before an architecture is recommended. This maturity path runs across four phases:
- Phase 1 - Assess and design: Here, institutions carry out a maturity assessment, select the right framework, run a gap analysis, and design the roadmap.
- Phase 2 - Build and implement: This stage involves deploying the framework, designing policies and procedures, setting up the GRC platform, and building team capability.
- Phase 3 - Operate and optimize: The focus shifts to continuous monitoring, AI integration, KRI refinement, and board reporting.
- Phase 4 - Innovate and scale: Institutions move on to predictive analytics, enterprise scaling, regulatory technology integration, and building a center of excellence.
AI adoption is accelerating fast enough to change what "continuous" looks like: Gartner’s 2026 survey of audit professionals found 93% report some level of AI use, though only 38% have an actual AI strategy, and current use still concentrates on isolated tasks rather than broader audit activities. But adoption is outrunning control. Banks also have low confidence in their AI controls, with only 18% saying they are confident they could pass an independent audit of those controls, at the same time as financial services sits among the sectors most targeted by AI-driven attacks. The European Central Bank made the governance implication explicit, stating that banks need clear accountability for AI-driven decisions, effective oversight, and robust governance.
AI's greatest near-term value in assurance is the elimination of manual, low-value effort, freeing risk professionals to focus on interpretation, challenge, and decision-making, while giving boards a real-time view of risk rather than a backward-looking one. The defensive upside is worth quantifying for the board too: institutions making extensive use of AI and automation in security saved close to $1.9 million per breach compared to those using none.
Third-party risk deserves particular focus given its regulatory profile under DORA and CPS 230 (Australia’s version of DORA) and its outsized contribution to breach exposure. A full life cycle view covers identification and scoping, due diligence, onboarding and contracting, ongoing monitoring, and exit and offboarding. This must be underpinned by a risk classification framework, controls assurance coverage across cyber, data, operational, and financial risk, and visibility into concentration and fourth-party risk. EY found that the number of nth-party vendors monitored increased by 20% year over year, and 64% of institutions now validate their vendors' own third-party risk programs rather than relying on a single point-in-time assessment.
The impact of AI on third-party risk management is particularly visible, where the gap between traditional practice and what is now possible is widest. For example:
- Vendor screening used to mean manually completing a questionnaire over several weeks per vendor; AI now auto populates those questionnaires from public filings, prior responses, and news, and flags gaps instantly.
- Risk scoring used to happen once a year or on a periodic cycle; machine learning models now score vendors daily using financial signals, cyberthreat feeds, news sentiment, and regulatory actions.
- Controls monitoring used to mean a point-in-time audit; it is now always-on, tracking vendor security posture through application programming interface integrations, dark web feeds, and certificate monitoring.
- And fourth-party and concentration risk, once largely unmapped, can now be traced by AI, which maps shared infrastructure and common sub-processors across the vendor population and quantifies concentration.
Four steps to build continuous assurance
The winning approach to close the above-mentioned gaps combines the following four key elements:
- Conduct a framework fit assessment to baseline current maturity against industry and regulatory context. With average risk maturity sitting at just 2.6 out of 4.0 for industries in general, most institutions will find they are earlier on the curve than assumed.
- Prioritize the pain point causing the most immediate board or regulatory pressure. This is likely to be a third-party risk or operational resilience, given third-party risk now ranks as the second most concerning risk category among peer institutions.
- Identify quick-win opportunities for continuous controls monitoring or AI-enabled risk assessment to demonstrate value early, following the same path institutions moving from point-in-time to continuous vendor validation have already taken.
- Build a phased roadmap (assess and design, build and implement, operate and optimize, innovate and scale) rather than a single large-scale transformation. Institutions building the investment case have a strong data point to cite: Gartner forecasts that legal, risk, and compliance functions will double their technology spend by 2027, showing that the wider market is already moving in this direction. The AI-specific piece of that spend is growing even faster: Gartner projects spending on AI governance platforms will reach $492 million in 2026 and surpass $1 billion by 2030. The research agency also found that institutions that deploy dedicated AI governance platforms are 3.4 times more likely to achieve high governance effectiveness than those relying on manual processes, a relevant benchmark given the phase 3 and phase 4 milestones in the roadmap above both depend on AI integration done well rather than fast.
This approach is grounded in delivered outcomes for our clients. For example, we used this path for a mid-sized insurance provider to move it from fragmented ownership across six functions to a centrally managed risk operating model with defined accountability. This was driven initially by a DORA compliance project that made its board directly accountable for risk assurance. We used the same approach for a major Australian bank to fix incomplete vendor inventory and manual, fragmented monitoring processes to comply with CPS 230. The approach improved the bank’s onboarding speed and audit and exam readiness within its third-party risk management program.
Institutions that continue to rely on annual testing cycles, siloed risk functions, and manual third-party oversight will find themselves structurally unable to keep pace with regulatory change, cyberthreat evolution, and stakeholder expectations.