In a fast-changing, complex risk universe, new approaches to emerging and enterprise risks are a must.
In a fast-changing, complex risk universe, new approaches to emerging and enterprise risks are a must.
By Zachary Ginsburg | April 3, 2025
Amid fast-changing risk exposures, organizations face little time between risk emergence and impact. U.S. federal policy shifts, geopolitical events and novel AI developments pose significant challenges — and require enterprise risk management (ERM) leaders to drive faster action, optimize risk ownership and expand risk insights.
But only 18% of ERM leaders express high confidence in identifying and managing emerging risks, highlighting the need for enhanced processes to navigate this dynamic environment.
To achieve enterprise goals and ERM success, chief risk officers (CROs) must navigate an expanding risk landscape while enhancing risk ownership and maximizing the value of technology.
As risks continue to emerge and impact organizations more swiftly, only 19% of CROs and ERM leaders express high confidence in knowing when their organizations should transition from monitoring to actively managing emerging risks.
In the current climate of heightened volatility and uncertainty, executives will rely on CROs and ERM leaders to define the emerging risk universe and determine appropriate actions. This involves identifying risks that require immediate intervention, as opposed to “far horizon” risks that can continue to be monitored. With a comprehensive view of the enterprise risk portfolio, ERM leaders are also on deck to guide the organization in determining the most effective actions.
As the risk universe grows, organizations increasingly rely on risk owners who can skillfully manage their own risks and actively participate in the ERM process. However, the responsibilities of risk ownership are becoming more complex. ERM leaders report that only 18% of risk owners provide high-quality information about their risks, and just 14% have effective mitigation plans.
ERM leaders often assume that underperformance is due to insufficient motivation or accountability. However, CROs and ERM leaders who incorporate more support for risk owners into their ERM programs see a 43% improvement in risk owner performance, compared to only a 7% improvement when focusing solely on motivation.
With greater risk complexity and speed, CROs and ERM leaders are increasingly turning to technology like governance, risk and compliance (GRC) tools to gain faster insights. Despite increased investments in these areas, many ERM leaders report that technologies, with long deployment times and only moderate improvements to the ERM process, often fail to meet expectations.
While vendors often portray their products as turnkey solutions that deliver immediate value, research on technology adoption in ERM suggests a more cautious approach. On average, it takes about a year, significant effort from ERM leaders and their teams, and substantial (and sometimes unforeseen) costs to fully deploy any given digital tool for ERM. Given the lengthy time frames to realize value and the costs of technology implementation, CROs and ERM leaders should ensure that technology projects align with long-term ERM strategic planning and objectives.
Gartner’s 2025 Leadership Vision for Heads of Enterprise Risk Management outlines a priorities roadmap for risk leaders. Based on data-driven insights, it highlights key priorities, emerging trends and actionable goals. Use this guide to sharpen stakeholder discussions and effectively shape your 2025 ERM strategy.
In 2025, chief risk officers and heads of enterprise risk management face three primary challenges: managing an accelerating emerging risk universe, driving enterprise risk ownership effectiveness and expanding risk insight with ERM technology and analytics. Gartner’s 2025 Leadership Vision for Heads of Enterprise Risk Management offers guidance on how to respond.
Attend a Conference
Join Gartner experts and your peers to accelerate growth
Gather alongside fellow leaders on September 8–9 in Grapevine, TX to gain insight on emerging trends, receive one-on-one guidance from Gartner experts and create a strategy to tackle your priorities head-on.
Gartner Enterprise Risk, Audit & Compliance Conference
Grapevine, TX
Drive stronger performance on your mission-critical priorities.