Key facts
- Big banks typically use at least four different governance, risk, and compliance platforms for ERM.
- Almost a quarter of banks report challenges with disparate systems and reporting gaps.
- ERM teams are increasingly tasked with new threats like AI and geopolitical risk.
- Despite expanding mandates, a majority of ERM teams report flat or shrinking headcount.
Enterprise risk management (ERM) leaders at large financial institutions are facing significant challenges due to fragmented technology systems and data fragmentation, according to Risk Benchmarking data. These issues often stem from banks running multiple, disparate governance, risk, and compliance (GRC) platforms, leading to poor user experience and reporting gaps. This fragmentation impedes effective risk management and oversight. Despite these operational hurdles, the influence of ERM functions is growing, with mandates expanding to encompass emerging threats such as artificial intelligence and geopolitical risks. However, this expansion of responsibility is occurring even as a majority of ERM teams report stagnant or decreasing headcount, creating a strain on resources.