With the advent of new technology, increasing global supply chain dependences as well as the rapid metastasis of risks across companies and markets, risk in 2026 has become a series of interlinked complexities. With financial service providers relying on a network of providers, failure at any point within the web can impact multiple and disparate systems.
The increased frequency and sophistication of cyber-attacks on a sector reliant on its digital infrastructure has rendered cybersecurity and technology risk a prime concern of CROs. Credit and market risks maintain significance in present-day geopolitical instability, macroeconomic volatility and divergent monetary practices. Financial crime remains an important consideration despite persisting now as ‘less urgent’ in comparison to cyber threats, climate risk and the need for operational resilience. Equally urgent considerations in the wake of macroeconomic volatility and regulatory divergence include credit risk, scenario testing for shocks, downturns and so on, as well as resilience planning.
The speed and complexity of regulatory changes, particularly in sanctions and trade risks, demands continuous attention. Adjusting to new sanctions, whilst trade conflicts emerge as novel threats, is a taxing operational challenge. Beyond sanctions, new frameworks (DORA, MiCA and Basel 3.1) require fast adaptation, putting pressure on governance structures, technology platforms and skilled resources. The challenge is to maintain strong oversight while building enough flexibility into compliance processes to respond to continuous change.
In future, AI-related risks, bringing both opportunities and new threats across cybersecurity and operational resilience, alongside geopolitical fragmentation and regulatory divergence as businesses navigate different rules, markets and conditions, are bound to increase complexity. Moreover, climate risk and sustainability are more relevant than ever to long-term resilience, whilst talent and skills shortages, particularly in technology and risk analytics, could make it harder to respond effectively to emerging threats. With a risk environment so interconnected, dynamic and difficult to predict, future success is predicated on more than just identifying today’s risks – the need of the hour is building the agility, technology and resilience needed to adapt to what comes next.





