Gartner Enterprise Risk, Audit & Compliance Conference 2026 London: Day 2 Summary

LONDON, September 29, 2026 

It’s not too late to join the conference

Overview

We are bringing you news and highlights from the Gartner Enterprise Risk, Audit and Compliance Conference 2026, taking place this week in London. Below is a collection of key announcements and insights coming out of the conference.

On Day 2 of the conference, we are highlighting the sessions: Ready Your Data for AI; Using Incident Data to Evaluate Risk Monitoring Activity Performance; and Building a Business-Led Compliance Operating System. Be sure to check this page throughout the day for updates.

Key Announcements

Ready Your Data for AI

Presented by Gleb Zhukov, Director Analyst, Gartner

To get the most from AI, assurance leaders must understand the data requirements for each use case before implementation. In this session, Gleb Zhukov, Director Analyst at Gartner, explained how to define the data required for priority use cases, assess whether existing data is usable and accessible, and determine the resources needed to close any gaps.

Key Takeaways

  • Poor-quality data can be amplified by AI, producing unreliable results at greater speed and scale.
  • Assurance leaders should begin with a priority AI use case and identify the data it requires. Different applications, such as fraud detection, AI-assisted data analysis and self-service chatbots, rely on different AI techniques and types of data
  • Most assurance teams do not lack data, but they may lack data that is usable for AI.
  • Leaders should establish what data they have, where it is stored, whether it can be accessed and whether its quality makes it suitable for the intended use.
  • The cost of preparing data depends on the people, tools and effort required. A relatively simple project may involve an internal team cleaning data from one source, while a more complex use case may require data scientists, specialist tools and continuously updated data from multiple systems.

Journalists can receive additional information and/or request an interview with Gleb Zhukov by contacting Rob van der Meulen at rob.vandermeulen@gartner.com

It’s not too late to join the conference

Using Incident Data to Evaluate Risk Monitoring Activity Performance

Presented by Mara Lindokken, Director Analyst, Gartner

Compliance teams are struggling to understand which monitoring activities detect real issues. In this session, Mara Lindokken, Director Analyst at Gartner, explained how compliance leaders can use precision and sensitivity to evaluate which risk-monitoring activities are effective, and where resources should be redirected.

Key Takeaways

  • Few compliance leaders are highly satisfied with their current risk indicators. These indicators commonly fail to give a complete picture, risk exposure, or show leaders where to focus their attention.
  • To improve risk monitoring activities, compliance leaders should evaluate them using two measures: precision shows how often alerts identify genuine policy or process deviations, while sensitivity indicates which monitoring activities identify the greatest share of verified incidents that lead to action
  • Compliance teams should assess precision by determining how often alerts point to genuine policy or process deviations.
  • To compare sensitivity, teams can use existing incident reports to track where verified, actioned incidents were first detected.
  • Combining sensitivity with precision allows leaders to decide which monitoring activities to continue, modify or stop, while also considering the cost of operating them.

Journalists can receive additional information and/or request an interview with Mara Lindokken by contacting Rob van der Meulen at rob.vandermeulen@gartner.com

Building a Business­ Led Compliance Operating System

Presented by James Crocker, Senior Director Analyst, Gartner

Key risk indictors (KRIs) often lack the business context to engage leaders and drive response. In this session, James Crocker, Senior Director Analyst at Gartner, explained how organizations can strengthen compliance and reduce operational risk by shifting from nominal accountability to active, business-led ownership supported by clear responsibilities, practical tools, and ongoing monitoring.

  • Only 10% of business leaders demonstrate highly active compliance involvement, while 90% have not received complete training and 68% have limited risk-management knowledge.
  • Active business ownership supports faster issue remediation, stronger mitigation plans and less operational disruption.

  • Effective compliance ownership requires both “know-what,” including clear roles and obligations, and “know-how,” including the skills and tools to manage risk.

  • Compliance functions should enable and coordinate risk management by providing enterprise-wide visibility, standardized methods, self-assessments, playbooks, benchmarks, and scenario-based training.

  • Organizations should strengthen ownership through a phased approach that assesses maturity, prioritizes high-risk areas, clarifies accountability, builds capabilities and monitors progress.

Journalists can receive additional information and/or request an interview with James Crocker by contacting Rob van der Meulen at rob.vandermeulen@gartner.com

That's a wrap on the Gartner Enterprise Risk, Audit & Compliance Conference 2026 from London. Hope to see you again next year!

Media contact



Latest releases

About Gartner

Gartner (NYSE: IT) delivers actionable, objective business and technology insights that drive smarter decisions and stronger performance on an organization’s mission-critical priorities. To learn more, visit gartner.com.