The role of the Chief Risk Officer has never been more demanding. In 2026, the risk landscape is increasingly complex with advancements in technology alongside external forces (e.g., cyber-attack, sanctions, divergent trade policy) that can change rapidly. While financial services firms continue to modernise their risk frameworks, the pace of change means that traditional approaches alone are no longer sufficient.To navigate an environment of geopolitical volatility, regulatory divergence, technological disruption and changing workforce dynamics, here are five priorities for CROs in 2026. These are in order to ensure robust governance alongside agility to navigate an ever-evolving risk landscape.
1. Accelerate the evolution of the risk operating model
With greater diversity and interconnectedness of risk drivers, risk operating models must become more adaptable. CROs should focus on forming frameworks that enable quick decision-making, improve collaboration and allow for a fast response from organisations to emergent risks.
2. Strengthen nth-party risk management
The growing complexity of global supply chains amplifies the need for organisations to network beyond their immediate third-party relationships. CROs should establish clearer standards for assessing and monitoring risks further down the supply chain.
3. Adopt AI where it delivers measurable value
AI presents both significant opportunities and new risks. CROs should focus on specialised use cases that improve efficiency and/or risk management. At the same time, careful human oversight and regulatory alignment is imperative to ensure the responsible adoption of AI usage.
4. Strengthen cyber and technology resilience
Investment should focus not only on monitoring and incident response, but also on technology infrastructure and specialist capabilities. The key is to anticipate in order to be resilient.
5. Invest in talent and future-ready skills
Technology-driven risk management requires new capabilities. CROs should prioritise upskilling, retention and diversity across risk, technology and analytics teams, while fostering a culture of continuous learning.
CROs must pair vigilance with action, i.e., learning from industry peers, investing selectively in technology, developing future-ready personnel and continually reshaping operating models. In taking these steps today, risk leaders can ensure the capabilities needed to anticipate emerging challenges and help shape the future of risk management.





