BDO's Global Risk Landscape 2026 puts a number on something operators already feel in the weekly meeting: eight in ten business leaders say the global risk landscape is now more defined by crisis than at any point they can remember. That finding is not surprising. The one underneath it is. Only 9% describe their own risk management as very proactive, and 53% still classify themselves as risk-minimising — protective posture, held by default, in a market that punishes hesitation.
Read those two numbers together and the diagnosis writes itself. The problem is not that companies fail to see risk. It is that risk lives inside a specialist function, arrives at the operating table late, and gets discussed in a language that does not convert into a decision. Risk aversion, in that setup, becomes a risk in itself.
Signal Versus Noise Is the Real Constraint
More than half of leaders — 52% — say they struggle to identify which risk signals genuinely matter against background noise. That is not an information shortage. Most businesses have more dashboards than they had five years ago. It is a filtering failure, and filtering is an operating discipline: someone has to decide, on a fixed cadence, which three signals move the plan this month and which forty do not.
When no one owns that decision, every signal gets escalated with the same urgency, and the organization learns to discount all of them equally. The practical fix is unglamorous. Fold the risk review into the operating review rather than running it as a parallel process, cap the list at the small number of exposures that could actually break the plan, and assign each one to the executive who owns the number it threatens.
Where Leaders Say They Are Least Prepared
- Cyber — 40% name it the top risk they are unprepared for, up 17 points year over year. Spending is rising; attacks are rising faster.
- AI — 27%, a category that did not appear in the prior year's survey at all.
- Geopolitics — 25%, flat year over year, and the risk that reshapes all the others.
- Supply chain — 24%, down slightly, but structurally harder than the number suggests.
- Regulatory burden — 24%, down 11 points, largely because attention moved rather than exposure falling.
- Economic slowdown — 22%, up 12 points, the sharpest single-year rise after cyber.
The composition matters more than any single line. Three of the top six are technology-shaped, and two of those — cyber and AI — are the categories where control maturity lags adoption by the widest margin. That is the profile of a risk portfolio moving faster than the governance built to hold it.
The Timing Problem: Invited Too Late
The most operationally useful finding in the report is about sequence, not severity. Only 10% of risk and cyber teams are involved at the ideation stage of transformation initiatives. They are brought in once the design is fixed, the budget is committed, and the only remaining question is whether the thing can be signed off. At that point the risk function is not managing risk. It is issuing a verdict on decisions someone else already made.
Every operator has seen the downstream version of this: a systems consolidation that has to be re-scoped in month four, an integration where access control was assumed rather than designed, a new channel that clears launch and fails audit. None of those are risk failures. They are sequencing failures, and sequencing is the CEO's to fix — it costs nothing to move a name earlier on an invitation list.
Fraud Is Falling Off the Agenda at Exactly the Wrong Moment
The sharpest reversal in the data is fraud. 93% of leaders no longer rank it as a top risk, and the share actively updating their fraud defences collapsed from 79% last year to 13% this year. That is not a reassessment of exposure. It is a bet that technology has quietly solved the problem — made at the same moment generative tools have lowered the cost of convincing impersonation to almost nothing.
Controls that were adequate against a human attacker working slowly are not adequate against an automated one working at volume. Payment authorization thresholds, vendor-change verification, and executive-request confirmation are cheap to re-test and expensive to skip. This is the clearest example in the report of a risk deprioritised on the assumption that someone else's technology is handling it.
AI: Adoption Without Matching Control
62% of leaders expect AI to become a larger part of how the business runs, and AI has entered the unprepared-for list at 27% in its first year of being asked. The pattern in the field is consistent with both numbers: adoption is being driven from the functions, not from the centre, so tools arrive in the workflow well before anyone has defined what data may enter them, who reviews output before it reaches a customer, and which decisions a model is permitted to make unattended.
The answer is not a moratorium. It is a short, boring register of where AI already touches the operation, an owner against each entry, and a rule about what class of decision stays human. Most companies can write that in an afternoon. Very few have.
What Shared Ownership Actually Looks Like
- One risk conversation, inside the operating review — not a separate committee that meets on a different clock and reports to a different audience.
- A named executive owner for each material exposure, chosen because they own the P&L line it threatens, not because they own the risk framework.
- Risk and cyber in the room at ideation on any transformation, integration, or system change — before the design is fixed.
- A cap on the escalated list. If everything is a top risk, the filter has failed and the organization will discount all of it.
- A standing re-test of fraud and payment controls on a fixed interval, independent of whether fraud feels urgent this quarter.
- A written line between decisions a model may make and decisions a person must make, reviewed as adoption widens.
The Operator's Read
The encouraging signal in the report is that 36% of leaders now describe themselves as risk-taking when necessary, against 26% a year ago. Calculated risk-taking is expanding. But it will only compound where the operating model can absorb it — where signals are filtered, exposures are owned by the people carrying the numbers, and the risk function is consulted while a decision is still shaped rather than after it is made.
That is the argument for pulling risk ownership out of the risk function and distributing it across the operating team. Not to dissolve the specialists, but to stop treating their work as a review gate. The companies that make this shift do not become more cautious. They become faster, because they stop discovering their exposure in the same week they have to act on it.
Figures cited from BDO, Global Risk Landscape 2026: Risk Everywhere — Extending ownership beyond the risk function.
