To thrive in today’s rapidly evolving risk environment, risk, audit, and compliance leaders must develop ‘reflexive risk ownership’, says Gartner. This is a future state where business leaders instinctively and automatically recognize, respond to, and manage risks.
During the opening keynote at the Gartner Enterprise Risk, Audit & Compliance Conference, Gartner experts said that organizations now face risks that emerge quickly, are highly interdependent, and are increasingly difficult to classify, making this shift in risk management critical.
Developing an organization’s risk reflex will require a mix of coaching risk owners and leveraging advancements in enterprise technology, particularly AI.
Three foundations of an organizational risk reflex
Gartner has identified the following three foundational areas for developing a risk reflex:
- Engineer: the first foundation focuses on engineering systems that make the right risk behaviours both easy to perform and difficult to ignore. For example, Gartner experts foresee an environment where vendors offer contract management systems that double as a third-party risk management platform. This would enable a risk owner to renew a contract or choose from a pre-approved list of suppliers without long due diligence checks. Compliance would be hard to avoid, and it would improve risk management.
- Provoke: the second foundation is intentional provocation – creating stimuli that prompt risk owners to think deeply and act decisively. Examples include asking more thought-provoking questions in risk surveys, or planning audits to focus on what is novel or insightful – for example, auditing the underlying project environment rather than just project governance.
- Recognize: the third foundation reinforces the right risk behaviours by putting processes in place to make them visible and rewarding. Examples include celebrating proactive risk management, sharing successes across teams, and using dashboards and recognition platforms to highlight exemplary behaviours.






