Risk Is Rising But Only 11% Manage It Well said the 2026 Report

This article will count 0.25 units (15 minutes) of unverifiable CPD. Remember to log these units under your membership profile.

Every year the American Institute of Certified Public Accountants (AICPA) and the Enterprise Risk Management Initiative at North Carolina State University run the same survey. They ask senior finance leaders how their organisations find, rank and respond to risk. They have done it for 17 years, which is why the trend lines matter more than any single number.

The 17th edition covers 331 organisations, surveyed in the second quarter of 2026. Respondents are mostly CFOs, chief risk officers and heads of internal audit. About 88% of the organisations are US based, and 31% have revenue above one billion dollars. Roughly 30% are government agencies, universities or non-profits.

So it is not a South African survey. But it is the closest thing the profession has to a long-run scoreboard on whether risk management actually works. And the 2026 scoreboard is uncomfortable.

One number tells the whole story

Risk went up. Capability did not.

Chart 1, risk versus readiness: The share of organisations reporting rising risk complexity climbed from 61% to 69% in a year, while the share rating their own risk oversight as mature or robust slipped from 32% to 30%.

Risk versus readiness: The share of organisations reporting rising risk complexity climbed from 61% to 69% in a year, while the share rating their own risk oversight as mature or robust slipped from 32% to 30%.

Nearly three quarters of respondents, 74%, also had a significant operational surprise in the past five years. So people are being hit, they know they are being hit, and the machinery for dealing with it is going backwards. The report calls this the gap between awareness and strategic integration. In practice it is the gap between knowing and doing.

Six findings that matter to a practice

  1. The risk environment is genuinely harder, not just noisier. Geopolitical uncertainty now hits business models directly. Just over a third of respondents say it affects their business model and new strategic initiatives "mostly" or "extensively". Not-for-profits report the highest pressure of all, with 78% saying risk volume and complexity have climbed.

  2. Stakeholders are pushing and organisations know they are behind. Audit committees are the loudest voice, with 38% saying the audit committee is asking for more senior executive involvement in risk. The trigger is usually painful. Thirty-eight percent say what raised the temperature was an unanticipated risk event that hit their own organisation. And 39% believe their business continuity and crisis management needs significant change.

  3. Maturity is thin, even at the top end. Only 3% of the full sample describe their risk oversight as robust. Only 37% have a complete formal enterprise risk management process. Among large organisations that rises to 63% and among listed companies 67%, which tells you the discipline exists but is bought with resources most SMEs do not have.

  4. The blockers are attention and money, not regulation. The top barriers are insufficient resources at 45% and competing priorities at 44%. A third say risk management is simply not seen as valuable. Only 8% blame legal or regulatory obstacles. This is a leadership problem wearing a compliance costume.

  5. Organisations look where the light is. Risk identification concentrates on IT systems at 71% and legal and compliance at 63%. Emerging strategic, market and industry risk sits at 46%, and only 22% are looking at risks five to ten years out. The risks that actually end businesses get the least attention.

  6. Governance improved faster than communication. Half of organisations now have a chief risk officer, up from 45%. Sixty-one percent have a management-level risk committee. Boards delegate risk oversight to a committee in 62% of cases, rising to 93% of listed companies, and that committee is usually the audit committee. But the way risk actually gets escalated is still a conversation in the corridor. The most common method is ad hoc discussion at management meetings, at 56%. Only a quarter say their key risk indicators are robust.

Where the attention goes: Organisations concentrate their formal risk work on IT systems and compliance, the risks that are easiest to see, and give the least attention to emerging strategic and market risks, the ones most likely to end a business.

The finding that should sting

Only 11% say their risk management process gives them a real strategic or competitive advantage.

Everything else in the report flows from that. Twenty-nine percent have written down their risk appetite. Thirty percent say risk information is formally discussed when the board talks about the strategic plan. Twenty-nine percent factor risk into capital allocation.


Chart 3, the strategy gap: Fewer than half of organisations factor risk into new initiatives, and only 11% believe their risk management process gives them any real competitive advantage.

Read that again. Forty-three percent think about existing risk when they evaluate a new initiative. Only 11% think the whole exercise gives them an edge. Most organisations have built the furniture of risk management, a committee, a policy, an annual register, and then left the room empty.

Why this lands differently in South Africa

Two numbers in this report have increased importance for South African NPOs:

  1. The first is that boards delegate risk oversight to the audit committee in 53% of cases, and 63% among not-for-profits. If the audit committee owns risk, the person advising that committee needs to talk about more than the trial balance. That is a direct line into the work CIBA members already do for boards, school governing bodies, NPO committees and family businesses.

  2. The second is the not-for-profit picture, and it is bleak. Non-profits report the highest rise in risk volume at 78%, the lowest maturity at 25%, and the weakest key risk indicators at 16%. Anyone acting for an NPO, a school, a trust or a municipal entity will recognise that shape. Our coverage of the new IFAC and CIPFA governance principles for the public sector made the same point from the regulator's side, including the expectation that entities embed enterprise risk management aligned to COSO ERM or ISO 31000 rather than treating it as a filing exercise.

Then there is the local risk landscape the survey does not measure. King V has made climate risk a board-level governance matter, and as we covered in the piece on client green claims and litigation exposure, SMEs in agriculture, construction, retail and transport are not exempt. Add load-shedding, water infrastructure failure, municipal collapse, currency swings and a client base with no cash buffer. Your clients carry more risk than the average American respondent, with less structure to manage it.

There is money in this gap

Here is the part that matters commercially. Only 11% of organisations think risk management gives them an advantage. That is not a warning. That is a market. If your client's board is being asked harder questions by an audit committee, and the client has no risk register, no risk appetite statement and no key risk indicators, somebody is going to get paid to build those. It may as well be you.

This is the same move we mapped in the 12-month plan for going from compliance shop to advisory firm. The work is not harder. It is more useful. And usefulness is what moves a fee. It also answers the complaint in what is keeping business accountants up at night, where the practices that struggle are not the ones with the smallest budgets, but the ones running 2018's service line in 2026.

One more thing. Before you sell risk services, look at your own firm. ISQM 1 already requires you to identify, assess and respond to quality risks in your practice, not just tick controls. If you have done that properly, as set out in our introduction to ISQM 1, you have already run a risk assessment process end to end. You can sell what you have practised.

What you can do this week

Pick your three largest clients. For each one, do four things. None of this takes longer than an hour per client.

  1. Ask who owns the most important risks. If the answer is "the accountant" or "nobody", write that down, as this is your opening.

  2. Write a one-page risk register with them. Five to nine risks, not fifty. The report found most organisations report between five and nineteen risks to the board, and 34% report fewer than five. Small is normal. Start there.

  3. Force one emerging risk onto the list. Not IT, not SARS. Something five years out. A key customer concentration, a succession gap, a climate or water exposure, a supplier in one country. The survey says almost nobody does this, which is exactly why it is worth billing for.

  4. Give each risk an owner and one indicator you can actually measure monthly. A number, not a colour. That single step puts your client ahead of the 75% who say their key risk indicators are weak.

Then price it. A risk register review, an annual refresh and a quarterly conversation with the board is an advisory engagement, not a favour attached to the annual financial statements.

👉 Join CIBA and we'll show you how to turn your clients' risk blind spots into a service they gladly pay for.

Next
Next

AI, Efficiency and Burnout: The Hours Accountants Lose