Skip to content

22 April, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • AI agents

      The AI risk faced by every board right now

      Even if no one in the organisation planned their arrival, AI agents are already present...

      sustainability litigation

      Is your board at risk of sustainability litigation?

      ESG disclosures, until recently focused on reputational risk and stakeholder expectations, are now becoming legal...

      sustainability Asia

      Navigating sustainability in Asia

      Boards operating across regions need to leave aside assumptions and consider the impact of a...

  • Comment
      • View all
    • AI agents

      The AI risk faced by every board right now

      Even if no one in the organisation planned their arrival, AI agents are already present...

      sustainability litigation

      Is your board at risk of sustainability litigation?

      ESG disclosures, until recently focused on reputational risk and stakeholder expectations, are now becoming legal...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

      stewarding AI

      AI is a ‘special case for governance’

      As AI use in the boardroom grows, it’s essential to focus on the ethical and...

  • Board Careers
      • View All
    • female CEO

      Number of women in leadership stays unchanged

      In 2021, there were only eight female CEOs in the FTSE 100—a figure that is...

      female NED

      UK female non-executives earn £73k less than male NEDs

      Although the UK’s average gender pay gap on boards is shrinking, it is still one...

      directors duties

      3 top tips on directors’ duties

      When directors fall short of their responsibilities, the consequences can be devastating. How can board...

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • FRC audit approach cover march 2026

      An evolved audit supervision approach 2026

      The Financial Reporting Council outlines its revised approach to audit supervision, which focuses on firms’...

      Protiviti 2026 governance AI

      The Board’s AI Moment, 2026

      This report, from Protiviti’s 2026 Global Board Governance Survey results, focuses on artificial intelligence.

      HEIDRICK GOVERNANCE 2026

      Governing Under High Uncertainty: Opportunities for Emerging-Market Boards

      This report from Boston Consulting Group, Heidrick & Struggles and INSEAD examines how boards are...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

5 ways to embed risk into strategy

by Thomas Campanile

How to unlock resilience and growth in an environment of ‘nonlinear, accelerated, volatile and interconnected risks’.

risk strategy

Image: Macrovector/Shutterstock.com

Favorite

The need to align risk and strategy has intensified amid global shocks that have reshaped the operating landscape for companies across all sectors. Many risks now materialise seemingly overnight—from leaps in AI to successive geopolitical events—triggering cascading impacts with unexpected outcomes.

We call this the NAVI world, defined by risks that are:

• Nonlinear: triggering sudden tipping points
• Accelerated: demanding faster responses
• Volatile: testing agility with frequent shifts
• Interconnected: creating complex downstream effects

Firms that embed risk into strategy are better able to unlock both resilience and growth in this environment.

Our 2025 EY Global Risk Transformation study—based on interviews and survey responses from 1,200 risk professionals spanning 21 sectors and 12 countries, including 85 banking and capital markets firms (65% with more than $100bn in assets)—identified firms that appear to have cracked the code for navigating turbulence. These firms are half as likely to be surprised by external shocks and a third better at swiftly identifying incidents and mounting a rapid response. These firms are led by “risk strategists”—leaders who integrate risk with strategy and approach uncertainty with a different mindset.

This matters for banks and their boards as much as it does for those in other sectors. According to the 2024 EY/IIF Global Bank Risk Management Survey, cybersecurity remains the top priority for CROs (73%) and boards (72%), with operational resilience second. Geopolitical risk has surged from 12th to a top-three concern. Each of these risk themes share the NAVI characteristics identified in our study.

Firms that embed risk into strategy are better able to unlock both resilience and growth in this environment. Here are five actions to start now:

1. Define a vision and create a roadmap

A shared vision is the foundation of risk transformation. Leading banks are aligning risk and strategy through collaboration between risk leaders and senior executives. In today’s volatile environment, agility matters more than certainty. Some decisions can wait for more data; others must be made and refined over time.

Banks should prioritise ‘no-regret’ investments—those that strengthen financial and operational resilience, reporting accuracy and incident response, regardless of macro conditions. This includes uplifting risk-data quality, hardening cyber and tech recovery capabilities, and expanding stress testing as interconnected financial and non-financial risks manifest and evolve. External partnerships can help close capability gaps, accelerate response and scale efficiently. Embedding the risk vision into strategic and business plans helps guide boards and senior management on turning uncertainty into advantage.

2. Initiate cultural change

Culture drives transformation. While building a strong risk culture takes time, early visible actions set the tone. Risk strategist-led institutions are shifting the narrative from only focusing on risk avoidance to embracing intelligent risk-taking—and from compliance-only thinking to viewing risk as a driver of strategic value. Sharing examples where risk insights improved business decisions reinforces the shift. “Lessons learned” conversations on risk management performance should not just focus on where things went wrong—they should celebrate where things went right as well.

Creating space for challenge and early escalation is critical.

Creating space for challenge and early escalation is critical. Institutions can signal that intelligent risk-taking is evidenced by timely identification, documented challenge and clear outcomes from scenario exercises. Making it safe to question assumptions—and empowering teams through senior management-sponsored scenario planning—embeds resilience into day-to-day business operations.

3. Use incentives and metrics strategically

Metrics and incentives are powerful levers for change, but only when aligned to meaningful outcomes. Banks are setting aside innovation budgets to test new risk methodologies and digital tools as part of a broader shift toward learning-led performance. Risk frameworks are increasingly looked to not just to avoid losses, but for how they enable smart business growth.

Embedding risk metrics into management dashboards—not just within risk reports—ensures that risk vision shapes capital, strategic and technology transformation decisions. When metrics reflect risk’s contribution to financial resilience, compliance and sustainable growth, they become a catalyst for long-term value.

4. Prepare for technology adoption

Emerging technologies—especially AI—are reshaping risk management. According to the EY/IIF survey, CROs are already using AI, including generative AI, to identify, assess and report on operational fraud (59%), compliance (44%) and credit (40%) risks.

Governance is a prerequisite for scaling AI with confidence.

Bank risk functions are also critical to guiding on broader responsible adoption of AI across financial institutions. Risk serves as a key partner to the business where AI deployments are authorised where model risk controls and data lineage are verifiably in place, with formal validation and post-implementation monitoring. Responsible AI adoption also requires closing the training-data visibility gaps flagged by many risk teams and addressing the top enabler of AI success: data quality. With data quality remaining the most cited data-usage risk for banks, governance is a prerequisite for scaling AI with confidence.

Many leading organisations seek early engagement of key stakeholders on responsible AI planning—enhancing alignment and reducing execution risks.

5. Find and foster the people who drive success

Even with powerful technology, risk transformation is a human endeavour. Banks are targeting a new skills mix: combining generative AI-oriented digital acumen, adaptability to a shifting risk environment, and deep domain expertise in specific risk stripes such as credit or cyber. Many plans measured growth in both first- and second-line risk teams over the next three years. Rotations are also being used to build bank-fluent risk professionals and risk-fluent bankers.

Attracting and developing this talent means broadening recruitment and upskilling strategies. Banks are looking beyond traditional profiles to bring in individuals with financial acumen, curiosity and strategic thinking—especially from data science, analytics and strategy backgrounds. Training risk professionals to speak the language of business, and embedding them in revenue-generating units, integrates risk thinking enterprise-wide.

Transformation must be human-centric. That means listening to employee concerns, communicating transparently, and empowering teams with clear roles, continuous learning and decision-making authority.

Becoming a risk strategist is, above all, a human endeavour—one that depends on the collective commitment of the entire organisation.

Thomas Campanile is global and Americas financial services risk consulting leader at EY.

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • A guide to risk management for board directors
    January 8, 2025
    guide to risk management for board directors

    Risk management goes beyond compliance: it’s a critical aspect of governance that supports long-term success.

  • US firms look to bring geopolitical expertise on board
    August 8, 2024
    geopolitical expertise

    As ‘geoeconomics’ moves into the forefront of corporate risk awareness, the effects are being felt at company level.

  • 5 reasons boards might struggle with risk
    August 8, 2024
    struggle with risk

    Recent failures in corporate governance raise questions about boards’ approaches to identifying and managing risk.

  • Stewardship strategies
    June 24, 2025
    long-term stewardship

    In times of uncertainty and growing risk complexity, boards need to evolve beyond stability. Here are some actions to take.

Search


Follow Us

Most Popular

Featured Resources

wef global risks 2025

The Global Risks Report 2025

The 20th edition of the Global Risks Report reveals an increasingly fractured global...
Supply chain management cover

Strategic Oversight in Supply Chain Management: A Guide for Corporate Boards 2025

Supply chains have become complex, interdependent and opaque and—according to research...

Cyber Security: What Boards Need to Know

Maintaining firewalls, protecting servers and filtering malicious emails rarely make...

C-suite barometer: outlook 2025 - UK insights

Forvis Mazars draws UK insights from its global study and looks at UK executives’...

The IA’S Principles Of Remuneration 2024 2025

This guidance from the Investment Association is aimed at assisting remuneration...
Diligent 2024 leadership tech cover

Leadership, decision-making & the role of technology: Business survey 2024

This research report by Board Agenda and Diligent sheds light on how board directors...

Director Reference Guide: Navigating Conflict in the Boardroom

The 'Director Reference Guide' on navigating conflict in the boardroom provides practical...
Nasdaq 2024 governance report cover

Nasdaq 2024 Global Governance Pulse

This Nasdaq survey gathered data from more than 870 board members, executives, and...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...
art & science brainloop new cover

The Art & Science of Creating an Effective Board

Boards are coming under more scrutiny and pressure than ever before from regulators,...
SAA First time NED guide

First Time Guide for Non-Executive Directors

The role of the non-executive director has never been more vital: to advise, support,...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy