The GRC landscape has rarely changed as quickly as it is changing now. Regulatory requirements are expanding in scope, specificity, and enforcement intensity. New risk categories have moved from emerging concerns to board-level obligations in the space of two or three years. Technology is creating more capable tools for managing risk and new categories of risk that did not exist a decade ago. And the expectations of boards, investors, and regulators around governance quality continue to rise.
Organisations that approach GRC as a static compliance exercise, doing what was sufficient last year without asking what the standard will be next year, are finding themselves progressively more exposed. These are the trends that are most directly reshaping what GRC functions need to do and what boards need to oversee.
Artificial intelligence is being adopted at a pace that has outstripped most organisations' ability to develop governance frameworks around it. AI is being used in customer-facing services, in credit and underwriting decisions, in fraud detection, in HR and performance management, and in operational processes across almost every sector. The governance questions this creates, who is accountable for AI-driven decisions, how algorithmic risks are identified and managed, what controls govern development and deployment, and how the organisation ensures AI outputs are explainable to regulators and customers, sit squarely within the GRC domain.
The EU AI Act, which began applying to prohibited AI practices and general-purpose AI systems in 2024 and to high-risk AI systems from 2025, creates specific governance, documentation, and risk management obligations for organisations developing or deploying AI in regulated contexts. High-risk AI systems, including those used in credit scoring, employment decisions, critical infrastructure management, and law enforcement applications, require conformity assessments, risk management systems, data governance practices, and transparency measures that align directly with established GRC disciplines.
For regulated financial services firms in particular, AI governance is not a separate technology concern. It is a GRC responsibility, requiring the same structured identification, assessment, and oversight of AI-related risks that the organisation applies to its other material risks. The European Banking Authority's guidance on machine learning for IRB models signals the direction of regulatory expectations for AI use in regulated decision-making.
GRC functions need to expand their risk taxonomies and governance frameworks to include AI-related risks explicitly. The questions to ask are: what AI systems are in use or planned, what decisions do they support or make autonomously, what governance and testing standards apply, who is accountable for their performance, and how are errors identified and remediated? These are risk management questions applied to a relatively new risk category, and the same disciplined approach that applies to operational and regulatory risk applies here.
The volume and specificity of regulatory requirements that GRC functions must navigate has expanded substantially in recent years and continues to do so. Several major frameworks came into application in 2025 or are phasing in through 2025 and 2026.
DORA, the Digital Operational Resilience Act, applied across EU financial entities from January 2025, bringing detailed ICT risk management, incident reporting, resilience testing, and third-party risk requirements that represent one of the most prescriptive operational risk frameworks financial services has faced. The EBA's DORA guidance and regulatory technical standards provide detailed specification of what compliance requires.
NIS2, which EU Member States were required to transpose by October 2024, extended cybersecurity regulatory obligations across 18 sectors and introduced personal management liability for compliance failures that many organisations are still assessing the implications of.
CSRD, the Corporate Sustainability Reporting Directive, is phasing in mandatory sustainability reporting across large EU companies and non-EU companies with significant EU operations. Wave 1 entities, those already subject to the Non-Financial Reporting Directive, reported on their 2024 financial year. Wave 2 companies face a delayed but confirmed requirement following the EU's Omnibus simplification proposals.
Consumer Duty, which came into force for the FCA's regulated firms in July 2023, continues to reshape how financial services firms approach customer outcomes, with supervisory scrutiny of implementation intensifying through 2025 and beyond.
The cumulative pressure from multiple concurrent regulatory frameworks is itself a significant GRC challenge. Compliance functions that were managing a manageable number of regulatory obligations now find themselves simultaneously absorbing new detailed requirements across digital resilience, cybersecurity, sustainability reporting, customer outcomes, and data protection, each with its own taxonomy, its own timeline, and its own enforcement authority.
The organisations managing this pressure most effectively are those with integrated GRC programmes, where a new regulatory requirement can be absorbed into an existing framework rather than requiring a new standalone compliance programme. When regulatory obligations are connected to the risk register and controls framework, the process of adding a new obligation is considerably less resource-intensive than starting from scratch each time.
ESG, which many organisations approached as a reporting exercise managed by sustainability or corporate responsibility functions, is becoming a core GRC responsibility. The reasons are regulatory, commercial, and governance-related simultaneously.
CSRD creates mandatory reporting obligations that require the same rigour as financial reporting, including external assurance. The EU's Corporate Sustainability Due Diligence Directive requires large companies to conduct human rights and environmental due diligence across their value chains, creating compliance obligations that sit alongside traditional regulatory requirements. Supply chain customers are increasingly flowing sustainability requirements down to their suppliers, making ESG performance a commercial compliance issue as well as a reporting one.
Climate risk has been explicitly incorporated into financial regulatory expectations in multiple jurisdictions. The Financial Stability Board's Task Force on Climate-Related Financial Disclosures framework, now embedded in regulatory requirements in the UK, EU, and several other jurisdictions, frames climate risk within the standard categories of financial risk and requires boards to demonstrate active oversight of climate-related risk.
Integrating ESG into GRC means treating material ESG risks, climate risk, supply chain labour standards exposure, human rights due diligence requirements, as risks that belong in the enterprise risk register and are subject to the same governance as other material risks. It means treating CSRD and other sustainability reporting obligations as compliance obligations that the compliance function tracks and evidences alongside regulatory requirements. And it means the board receives ESG risk and compliance information through the same governance structures as other material governance matters, rather than as a separate sustainability update.
Operational resilience has moved from a risk management concept to a board-level regulatory obligation in multiple jurisdictions simultaneously. The FCA and PRA's operational resilience rules, which became fully effective in March 2022 with ongoing review and testing obligations, require boards to set explicit impact tolerances for important business services and to demonstrate those tolerances can be met under severe disruption scenarios.
DORA's resilience testing requirements, covering annual vulnerability assessments and advanced threat-led penetration testing for significant entities, add a specific testing and evidence standard to what resilience governance requires.
Operational resilience governance connects directly to GRC in two important ways. First, the risk management disciplines that identify where resilience is most vulnerable, dependency mapping, scenario analysis, control effectiveness testing, are the same disciplines that sit within operational risk management. An organisation with a mature operational risk framework is better positioned to meet its resilience governance obligations than one starting from scratch.
Second, the evidence requirements for resilience governance, documented impact tolerances, testing results, board sign-off, require the same evidence management and governance documentation capabilities that a GRC programme is built to provide. When resilience governance is integrated with the GRC programme rather than managed separately, the administrative overhead is considerably lower and the governance quality is considerably higher.
The capability of GRC platforms has advanced materially over the past three to five years. Real-time risk monitoring, automated regulatory change tracking, data analytics applied to control testing at population level rather than sample level, and integrated reporting across risk, compliance, and audit functions from shared underlying data are available from credible platforms in ways that were practically unachievable five years ago.
These capabilities are changing what boards and risk functions can expect from their GRC programmes. Quarterly risk reviews supplemented by automated KRI monitoring. Regulatory change flagged and mapped to affected controls the day the change is published. Control testing that covers the full population of a high-volume process rather than a sample. Board reporting that reflects the current risk and compliance position rather than the position as of the most recent manual compilation exercise.
Technology adoption that runs ahead of governance maturity produces sophisticated reports about an incoherent risk position. The most capable GRC platform available cannot compensate for unclear accountability structures, inadequate first-line ownership of risk, or a board that receives risk and compliance reporting without genuinely engaging with it.
The organisations getting the most from GRC technology are those that had sound governance foundations in place before adopting a platform. The technology amplified and scaled what was already working well. For those that adopted technology as a substitute for governance foundations they had not yet built, the investment tends to disappoint.