Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»2024 Predictions»Risk and resilience predictions for 2024 (Page 2)
2024 Predictions

Risk and resilience predictions for 2024

Gary Lynam looks at risks that are likely to increase in importance in 2024 and the developments that we can expect to see in the operational resilience space.
December 21, 20236 Mins Read
2024 risk and operational resilience predictions - a finger drags a slider from 2023 to 2024 in front of a technology concept background

AI and Chat GPT

AI is here to stay and will continue to revolutionise the way organizations manage their business functions in 2024 and forever – risk and compliance included.

There are significant challenges ahead for UK organizations trying to understand the proliferation of AI usage. Aside from the forthcoming AI regulations and the UK’s revised Data Protection and Digital Information Bill, risk and compliance teams must consider the opportunities presented by generative AI.  Support functions are often left behind when new technology change is introduced. This can’t be the case this time. Perhaps a recent example is the UK’s recently adopted Consumer Duty requirements. With its focus on delivering positive outcomes for customers, the use of AI to make decisions based on historic data at this very earliest stage of AI integration could already be storing up problems for the future or ensuring positive customer outcomes which build sustainable reputations and drives competitive advantage.  

AI’s current limitations must not be overlooked, such as the AI models that invent fake case studies identified as ‘hallucination bias’ by the UK Financial Conduct Authority (FCA). In 2024, organizations must build capabilities within teams to ensure that the AI operating models and outcomes are fully understood and any bias is avoided. Ensuring that rigorous validation, testing, and audit processes are in place along with continuous monitoring is vital. While many organizations will find the prospect of implementing AI-powered risk and compliance management daunting, there’s never been a better time to start exploring it. And for those that don’t, they will surely get left behind. The FCA has recently reinforced that the Senior Managers & Certification Regime also gives us a clear framework to respond to innovations in AI. This makes clear that senior managers are ultimately accountable for the activities of the firm. This combined with the likely revisiting of UK SOX if the UK has a change in government in 2024 means a busy demanding year ahead for accountable managers.

Geopolitical risk

The world will remain an uncertain place for organizations in 2024. Next year is also going to be the biggest election year in history for democratic societies, including the US presidential election in November 2024. So, it’s not difficult to see that geopolitical risk is still viewed by many as a wildcard – there is so much difficulty predicting these outcomes with any certainty and subsequent direct or indirect impacts for organizations. But with voters in 40 countries heading to the polls, the results will have a significant impact on an already fragile geopolitical and economic environment. Further to this, 2023 saw a shift in trade relations. Russia sanctions have contributed to an increased level of activity amongst the BRICS (Brazil, Russia, India, China, and South Africa), with the main objective appearing to be a shift away from the US dollar. It will be interesting to observe if this maintains momentum in months ahead. 

Organizations can no longer ignore the potential impact and I expect to see more prioritising their efforts to monitor risks, forecast scenarios, and focus on identifying their potential exposure and response to geopolitical events. Given the geopolitical risk landscape, we will see more organizations considering their governance, risk, and compliance strategy, not just for 2024 but for the next three or even five years. Developing a strategic plan for the risk management function, based on a ‘blueprint’ of a future vision, serves as a roadmap to measure progress and adjust course as necessary.

Operational resilience / TPRM agenda

In 2024 third parties will become a more significant part of organizations’ operational resilience initiatives, including joint scenario testing with critical vendors. The operational resilience agenda will force organizations to shift mindset from ‘what if?’ to ‘assume failure’ and focus on the potential intolerable harm to important business services (IBS) from external uncertainties. In the UK, we’ve seen regulatory changes come into force with an emphasis on third party risk management to achieve operational resilience, such as the PRA’s Operational Resilience rules and FCA’s Consumer Duty standards.  Similarly, the EU’s Digital Operational Resilience Act (DORA) is enforcing obligatory rules for third party risk management, with accountability at a senior management level.  

With third party risk management (TPRM) firmly in the spotlight, in 2024 it’ll be more important than ever for organizations to identify, assess, and manage the interconnected nature of risks associated with third parties and related supply chains – in fact, it is now expected as a given. Regulators expect a level of sophistication to be achieved in this area by 2025.

This is also reflected in Protecht’s recent research findings, which found that seven out of 10 (70.3%) of financial organizations will be either making a significant or a slight increase in investment in TPRM solutions in their ERM programme over the next 12 months.

It is also expected there will be increased focus on the model risk management space, PRA implementation for SS1/23 is May 17, 2024, the focus for UK firms is now grasping the key principles of SS1/23 and find ways of embedding its requirements into their daily operational risk frameworks and their compliance processes.

Operational resilience – digitalisation

Currently, many companies lack the ability to effectively test their processes end-to-end, including third parties and suppliers. In 2024, the risk function will evolve to embrace the digitised landscape by using AI and advanced analytics to capture internal and external data, manage the third party management lifecycle and drive meaningful insights for decision making processes, based on the correlations between interdependent risks.

Protecht’s recent research findings indicate that financial organizations will increase investment over the next 12 months in tools and technology. 63.5% stated they will be boosting investment in projects such as digitalisation and automation of risk activities.

Operational resilience (18.6%), business continuity management (18.1%), and Consumer Duty (18.7%) were also identified as priority areas for digitisation driven by local regulatory FCA and PRA requirements.

The growth of resilience roles teams

In 2024, new senior leadership roles that own operational resilience, such as chief resilience officer will feature more prominently, and the role of the typical risk manager will evolve considerably. We’re also likely to see the continued growth of the resilience function, which we’ve witnessed this year with companies investing in people who have expertise to ensure that the organization can maintain critical services and recover quickly under period of disruption. Resilience teams will play a more prominent role in third party risk management to help the first line properly assess potential third party providers’ risk and resilience postures as well as enforce more rigorous monitoring of existing relationships for the most critical third parties.

Protecht’s recent research findings showed that 17% of UK firms highlighted concerns around skills shortages in this space, while 62.9% of organizations say they will be putting more money into hiring staff, including 28% indicating that they will significantly increase investment.

The author

Gary Lynam, Managing Director, EMEA, Protecht

UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleThe 9th Annual Global Risk and Resilience Trends Report
Next Article Hacker Holidays: why the holiday season is an open door for cyber attackers

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
AI enabled business processes concept.

Operational resilience in an AI-dependent enterprise

August 26, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?