52% of US organizations have not integrated risk and resilience capabilities, accountabilities, or organizational structure, according to a new KPMG Risk & Resilience survey.
The survey of 208 US C-Suite leaders also shows that cybersecurity continues to be considered the biggest risk challenge for businesses over the next five years at 57%, followed by data privacy risk at 43%, and technology risk at 41%. Each of these top risks are critical considerations for strong risk and resilience programs.
Centralized risk & resilience structures drive performance
Survey results indicate that approximately half, 48%, of the organizations surveyed have centralized or coordinated structures for managing risk and resiliency. Most organizations, 51%, also test and update their resilience plans annually, while a quarter, 23%, are doing so more than once a year.
The survey results show that organizations with centralized structures for managing risk and resilience are more mature in their capabilities to handle disruption than their counterparts. Those organizations are also more likely to have specialized tools to manage risk including GRC, risk reporting and risk monitoring technology with advanced analytics. This leads to greater confidence that their C-suite understands the business risks posed by disruption.
Tim Phelps, Risk Services Leader, KPMG LLP
Organizations with centralized risk and resilience structures are using specialized tools for the majority of risk processes, much more frequently than those with decentralized structures. In addition, organizations with centralized risk and resilience management are twice as likely to have timely data than those with decentralized management structures.
Survey participants indicated that commonly used specialized tools include GRC technologies, risk monitoring tools, and risk reporting technologies. Advanced analytics, such as monitoring and sensing, scenario analysis, and predictive modeling, are also being employed, with about half of the organizations regularly employing these tools.
Organizations still face significant barriers to effective risk management
A significant number of organizations – ranging from two-thirds to nearly three-quarters – face moderate to strong barriers in effectively managing risk. These barriers include performing duplicative efforts (71%), cultural resistance (66%), lack of awareness and communication (72%), lack of an integrated view of risks (71%), and inadequate skills and competent resources to keep pace with growing volatility and emerging technologies (66%).
Organizations with centralized risk and resilience management structures are less likely to cite any risk management barriers, demonstrating the importance of a cohesive strategy and integrated approach to risk and resilience management.
Joey Gyengo, U.S. Enterprise Risk Management Solution Leader, KPMG LLP






