Research Report
72% of risk professionals say their capabilities have not kept pace. Factor's study of 700+ risk leaders on the gap that decides who absorbs disruption.
Research
Risk and Compliance
11 min read
72%
72% of the risk professionals surveyed say their risk management capabilities have not kept pace with the rapidly changi
83%
83% say complex, interconnected risks are emerging at a more rapid pace than ever before
38%
Research draws on more than 700 risk professionals across fifteen markets including Australia, surveyed between April an
14.5%
Only 14.5% of the organisations surveyed have advanced levels of risk management capability — implementing technologies
Key takeaways
Fund the data layer before the tooling.
Reverse the investment retreat and name it to the board.
Benchmark escalation by sector, not in aggregate.
Score compound exposures, not just categories.
Treat first-line ownership as the main programme.
The headline finding is an admission rather than a forecast. 72% of the risk professionals surveyed say their risk management capabilities have not kept pace with the rapidly changing landscape. That is not an outside assessment of the function; it is the function's own verdict on itself, and it is close to three in four.
Three further readings explain why. 83% say complex, interconnected risks are emerging at a more rapid pace than ever before. 77% say risks are more difficult to detect and manage. And 81% say risks in other sectors are now important to their business — a reflection of the fact that most large organisations no longer operate inside one industry, and that partnerships, platforms and alliances import exposures the register was never designed to hold.
Put those numbers side by side and the shape of the problem is clear. The volume of risk has risen, the detectability of risk has fallen, and the boundaries that used to contain risk within a sector have dissolved. A function whose operating model assumes discrete, classifiable, sector-bounded threats is being asked to manage something with none of those properties.
The research draws on more than 700 risk professionals across fifteen markets including Australia, surveyed between April and June 2023, at organisations generating at least US$1bn in revenue — 38% of them above US$10 billion. The sample is global and the figures below are global; the Australian reading is drawn as analysis, not as separately reported Australian data.
Only 14.5% of the organisations surveyed have advanced levels of risk management capability — implementing technologies to improve decision-making, onboarding leading data analytics skills into the risk function. The same proportion, 14.5%, sit at the bottom of the maturity index. The remaining 71% fall somewhere in between, which is the most commercially interesting fact in the study: the large middle is neither leading nor obviously failing, and it is easy for a board to mistake that middle for adequacy.
What the leading group does differently is not subtle. 96% of risk leaders are urgently improving their ability to collect enterprise-wide data, compared with 59% of the less mature group. 57% say investing in new technology for the risk team is a top-three priority, against 24% of those with less mature capabilities. 51% say bringing new skills into the function is a top priority, again against 24%.
These are not three separate budget lines. Data, tooling and skills are one capability expressed three ways, and the leading group is compounding all three while the bottom group funds none of them at anything like the same rate. A near two-to-one gap on technology and skills priority, sustained across a few planning cycles, is the difference between a function that can quantify a novel exposure in days and one that convenes a working group.
The leaders are also more likely to be growing as businesses. That correlation is the argument to put in front of an Australian executive committee: risk maturity is not presented here as a cost of compliance but as a feature of companies that are expanding.
Data, tooling and skills are one capability expressed three ways, and the leading group is compounding all three while the bottom group funds none of them at anything like the same rate.
The sharpest single divide in the study is that 96% versus 59% on enterprise-wide data collection, and it is worth being precise about why it drives everything else. Across all respondents, 84% say their organisation is urgently improving its ability to collect and analyse enterprise-wide data — so the intent is close to universal. The gap is in execution, and execution is where the maturity index actually separates people.
The mechanism is straightforward. A risk function without enterprise-wide data cannot model total exposure across the business, which means it cannot rank exposures, which means its technology and talent proposals arrive at the investment committee without a quantified target. The 24% figures on tooling and skills are not independent failures of ambition; they are downstream of not having the data to build a case.
The research describes the practical version of this problem in banking terms that generalise well: credit risk data in one system, market risk in a spreadsheet, operational risk in a different document altogether. Combine those rapidly and the organisation can assess total exposure across several risks at once and drive a real-time view of it. Leave them separate and every risk question becomes a manual reconciliation exercise with a two-week lead time.
This is why sequencing matters more than the size of the budget. Fund the data layer and the technology and skills cases write themselves; fund tooling first and it lands on top of fragmented inputs. Factor's work on resilience covers the organisational half of the same problem — the ability to sense change before it forces itself on you.
The most counterintuitive result in the study is a retreat. Just 37% of risk teams are using new technology such as cloud, automation and AI, compared with 49% in 2021. Only 37% are expanding the range of risks and scenarios they evaluate, versus 44% in 2021. Roughly one-third of risk functions use or have recently used technology like cloud computing to derive value from data, against 46% in 2021.
Every one of those lines moved backwards while the threat environment moved forward. Read alongside the 72% who say their capabilities have not kept pace, this is the study's most uncomfortable pairing: the function that has diagnosed its own shortfall is simultaneously reducing the investments that would close it.
The confidence data shows what that costs. Just 45% of respondents are 'very confident' in their ability to manage disruptive technology risks — the lowest confidence of any risk category measured — and only 44% are 'fully confident' in managing the risks associated with cloud, a technology that has been mainstream for over a decade. Less than one-third are prioritising the assessment and use of disruptive technologies as a capability to improve.
That last figure deserves attention from any Australian organisation currently accelerating an AI programme. The category the function is least confident about is also the category it is least likely to be building skills in. Factor's research on AI autonomy sets out how quickly that exposure is expanding.
There are positive readings. 42% are now 'very satisfied' with their progress in proactively identifying and defining new risks, up from 29% in 2021, and over nine in 10 risk leaders are satisfied with their ability to proactively identify and define new risks. Identification is improving. Response capacity is not keeping up with it.
The study's structural argument is that risks no longer behave as separate line items. Respondents rank strategic risk as the risk type most escalated by the rising importance of operational risk, and strategic risk is also exacerbated by financial, regulatory and technology risks. Each of those is scored well by most functions individually. The compound is not scored at all.
The worked example the research gives is a geopolitical one. A single event disrupts supply routes, which is supply chain risk; grows market risk where the customer base sits in the affected area; grows operational risk through a third party in the affected jurisdiction; complicates regulatory risk once sanctions land; and creates reputational risk for continuing to operate there. One event, five registers, five owners, no single view.
Fraud risk is the clearest casualty of this blindness. It sits low on most organisations' risk agendas, yet the survey data shows it increases materially once second-order impacts such as societal and financial risks are considered. Fraud lives across functions and carries both financial and non-financial consequences, which is exactly why a function-by-function register misses it — as the research puts it, you will not see it unless you are looking for it.
The practical implication is that assurance built on category-level confidence scores overstates readiness. A board that reads a register showing solid confidence on twelve individual risk types has learned almost nothing about how the organisation performs when four of them arrive together.
Aggregate risk rankings conceal more than they reveal, because the categories that escalated since 2021 differ sharply by industry. 40% of pharmaceutical respondents say the impact from regulatory and compliance risks rose most since 2021, the highest percentage of any industry. Software and platforms respondents, at 49%, led all industries in identifying disruptive technology risks as rising most in importance over the same period.
The pattern holds further down. 40% of utilities respondents say the impact from third-party risks rose most since 2021, again the highest of any industry. 41% of retail respondents say social change poses a high risk to their organisation. 42% of telecommunications respondents say net neutrality regulatory changes represent a significant risk to their future success.
Five sectors, five different top escalations, and no two of them would produce the same investment plan. A utilities business optimising for regulatory change and a software business optimising for third-party concentration would each be defending the wrong flank.
For Australian risk executives this argues against benchmarking to a cross-industry average, which is what most peer comparison in this market actually is. The useful comparison is your own sector's escalation profile, because that is what your regulators, your competitors and your board are responding to. Factor's banking research traces the same dynamic inside one heavily supervised Australian sector.
The largest separations in the entire study are not about the risk function's own tooling. They are about how well the rest of the organisation manages risk, and that is where the leading group is furthest ahead.
Consider the spread. 52% of leaders are 'very satisfied' that the business understands risk mitigation is part of its remit, against 13% of the less mature group — a four-fold gap. 50% are very satisfied that the business is adopting a risk mindset, against 22%. 46% are very satisfied that the business understands the impact of new and interconnected risks, against 19%. On board-level engagement with risk the split is 63% to 19%, and on developing the skills needed to detect and mitigate risk it is 57% to 27%.
Across all respondents the same measures are weak. 82% say that outside the risk team the business is becoming more aware of risk, but only 35% are 'very satisfied' with the business's ability to adopt a risk mindset and only 34% that the business understands risk mitigation is part of its remit. Awareness has risen; ownership has not followed it. And 77% of risk functions say they struggle to support the wider business in developing risk capabilities and a risk mindset.
That struggle has a capacity cause. 80% of surveyed risk executives want their teams to spend more time on value creation and innovation, three-quarters say risk professionals are not connected enough with the business to do it, and 81% say balancing existing duties with value-adding activities is a major challenge. A team consumed by its own reporting cycle cannot coach the first line, and an uncoached first line generates more work for the risk team. Agility follows the same split: 52% of all risk teams are 'very agile' at using cloud platforms, tools and services to rapidly execute risk processes, against 83% of risk leaders.
Australia was one of the fifteen markets surveyed, but the study does not publish an Australian cut, so what follows is analysis of how these global patterns land in local conditions rather than separately reported Australian data.
Three features of the Australian market amplify the findings. First, concentration: in banking, telecommunications, insurance, grocery and energy a small number of large operators dominate, which means the cross-sector contagion described in the study — 81% of respondents already report risks in other sectors affecting them — travels through a shorter chain of counterparties here than in fragmented markets. Second, the supervisory environment is intensive and prudentially led, so the regulatory and compliance escalation that pharmaceutical respondents reported at 40% is a live pressure across large parts of the local economy, not a sector curiosity.
Third, and most constraining, is scale. An Australian risk function is typically smaller than its northern hemisphere equivalent while facing a comparable breadth of obligation. That makes the 37% technology-adoption figure more consequential here than elsewhere: where a global peer can absorb a manual data reconciliation with headcount, a local team of a dozen cannot. Automation is not an efficiency preference in that setting; it is the only way the coverage arithmetic works.
The talent picture compounds it. The skills the study identifies as most prioritised — detecting change in the external environment, advanced data science and analytics, and the ability to collaborate across functions while maintaining independent challenge — are contested in a shallow local market. Australian organisations competing for the same small pool of risk data scientists should assume that buying the capability outright will be slow, and plan a build-and-partner route in parallel.
The upside case is equally specific. In a market this concentrated, the organisation that can quantify a compound exposure faster than its three competitors has a genuine commercial advantage, because it can price and underwrite risk they will decline. That is the growth argument the study's leading group is already making internally.
Fund the data layer before the tooling. The 96% versus 59% split on enterprise-wide data collection is the divide that makes every other risk investment defensible, and 84% of all respondents already say they are urgently improving this. Intent is not the differentiator; a funded, sequenced programme is.
Reverse the investment retreat and name it to the board. Technology use fell from 49% to 37% and scenario expansion from 44% to 37% while 72% of the profession said its capabilities had not kept pace. Show the board both series on one page and let the contradiction make the case for you.
Benchmark escalation by sector, not in aggregate. 49% in software and platforms name disruptive technology, 40% in pharmaceuticals name regulatory and compliance, 40% in utilities name third-party risk, and none of those profiles is transferable to another industry. Build the peer set inside your own sector before you compare anything.
Score compound exposures, not just categories. Strategic risk is the type most escalated by rising operational risk, and fraud risk rises materially once societal and financial second-order effects are included — so add at least one multi-risk scenario to the reporting pack and give it a single named owner.
Treat first-line ownership as the main programme. The leaders' advantage is widest here — 52% versus 13% on the business understanding that risk mitigation is part of its remit — while only 34% of all respondents are satisfied on that measure and 77% of functions struggle to build it. Consult rather than mark homework, and move people between the first and second lines in both directions. Explore Factor's research library or join a Factor risk and security event to compare capability against Australian peers.
Part of
