Site navigation

91% of Firms Now Have a Dedicated GRC Team

Tom Quinn

,

GRC 2025
Businesses are investing more than ever in compliance and risk management, but new regulations are holding them back from adopting more AI-driven solutions.

More organisations than ever have created a centralised governance, risk and compliance (GRC) team to work across business areas and geographies in the hope of achieving better consistency and efficiency in managing risks.

That’s according to the latest annual IT Risk and Compliance Benchmark Report from security and compliance platform Hyperproof, which found that 91% of organisations now have a core GRC team, up from 88% last year and the highest number seen in six years.

According to Hyperproof, these figures are evidence of a shifting perspective, toward strengthening GRC efforts, a trend likely driven by increasing regulatory complexity, heightened enforcement, and the growing need for organisations to demonstrate accountability and transparency. 

In what is clearly an ongoing trend, of the more than 1,000 senior leaders and C-suite executives polled for Hyperproof’s survey, almost three-quarters (72%) said they plan to grow their compliance teams this year.

Investing in broad GRC activities has tangible benefits, with the report finding that 60% of those who are forced to manage risk on an ad-hoc basis, or only when a negative event happens, experienced data breaches in 2024, followed closely by those who relied on siloed departments or tools (49%).

Such positive effects haven’t gone unnoticed, with the majority of senior leaders (63%) reporting that they will continue to increase GRC budgets over the next two years, which promises to be a weighty chunk of capital given that three-quarters (74%) of business already have annual security budgets of over $1 million (£793k).

The study also found that although most businesses are confident that they have taken steps to mature their GRC programmes, half still spend between 30% and 50% of their time on administrative tasks like manual data entry.

To address these burdens, many organisations are turning to purpose-built tools and software solutions designed to alleviate the manual, fragmented aspects of GRC work. 

Some of these tools, inevitably, are being built on more integration of AI. However, firms are being cautious of implementing more AI-controls because they are wary of the risks that increased AI use might bring, especially under new regulations such as the EU’s DORA, which asks firms for a comprehensive ICT risk management framework encompassing AI being utilised within financial operations.


Recommended reading


In some respects, a number of businesses are slightly lagging in their preparations for AI regulations, with just 59% having implemented risk management frameworks due under the EU’s AI Act, although 90% have started preparing for DORA, despite those rules coming into force in January.

Regardless of that fact, 97% of firms believe that they are meeting their GRC objectives, although admit that certain actions are harder to implement. Almost a quarter (23%) said that they are not confident in their processes for reviewing and remediating issues, while 17% said they are not meeting their objectives when documenting risk decisions. 

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data