The Enterprise Risk Management (ERM) Initiative at NC State University, in partnership with Protiviti, has released its 13th annual edition of the Executive Perspectives on Top Risks report. This in-depth survey captures insights from 1,215 board members and c-suite executives worldwide.
The top 10 near-term risks (2025–2027)
Based on survey responses, the top 10 business risks for the next three years include a mix of macroeconomic, strategic, and operational concerns. The top ten risks are:
- Economic conditions, including inflationary pressures
- Cyber threats and data breaches
- Ability to attract, develop and retain top talent, manage shifts in labor expectations, and address succession challenges
- Talent and labor availability
- Increasing labor costs impacting profitability
- Heightened regulatory changes, uncertainty and scrutiny
- Third-party risks, including supply chain vulnerabilities
- The rapid speed of disruptive innovations in AI and emerging technologies
- Challenges in adopting AI and advanced tech requiring new labor skills in short supply
- New and emerging risks arising from AI implementation.
The top long-term risk concerns (2035 outlook)
Beyond the immediate horizon, executives foresee significant challenges over the next decade, particularly in the macroeconomic, strategic, and operational landscapes. The top two risks in each area are seen as:
Long-term macroeconomic risks
- Economic conditions, including inflationary pressures
- Talent and labor availability.
Long-term strategic risks
- Heightened regulatory changes, uncertainty and scrutiny
- Rapid speed of disruptive innovations enabled by new and emerging technologies and/or other market forces.
Long-term operational risks
- Cyber threats
- Ability to attract, develop and retain top talent, manage shifts in labor expectations, and address succession challenges.
Risk management strategies for business leaders
With risk oversight and enterprise risk management (ERM) frameworks becoming more vital, the report says that organizations must:
- Strengthen risk governance structures to address evolving threats.
- Invest in cybersecurity resilience to counter emerging AI-driven cyber risks.
- Develop future-ready workforce strategies to navigate talent shortages and workforce shifts.
- Enhance scenario planning and regulatory compliance to stay ahead of policy changes.






