More organisations than ever have created a centralised governance, risk and compliance (GRC) team to work across business areas and geographies in the hope of achieving better consistency and efficiency in managing risks.
That’s according to the latest annual IT Risk and Compliance Benchmark Report from security and compliance platform Hyperproof, which found that 91% of organisations now have a core GRC team, up from 88% last year and the highest number seen in six years.
According to Hyperproof, these figures are evidence of a shifting perspective, toward strengthening GRC efforts, a trend likely driven by increasing regulatory complexity, heightened enforcement, and the growing need for organisations to demonstrate accountability and transparency.Â
In what is clearly an ongoing trend, of the more than 1,000 senior leaders and C-suite executives polled for Hyperproof’s survey, almost three-quarters (72%) said they plan to grow their compliance teams this year.
Investing in broad GRC activities has tangible benefits, with the report finding that 60% of those who are forced to manage risk on an ad-hoc basis, or only when a negative event happens, experienced data breaches in 2024, followed closely by those who relied on siloed departments or tools (49%).
Such positive effects haven’t gone unnoticed, with the majority of senior leaders (63%) reporting that they will continue to increase GRC budgets over the next two years, which promises to be a weighty chunk of capital given that three-quarters (74%) of business already have annual security budgets of over $1 million (£793k).
The study also found that although most businesses are confident that they have taken steps to mature their GRC programmes, half still spend between 30% and 50% of their time on administrative tasks like manual data entry.
To address these burdens, many organisations are turning to purpose-built tools and software solutions designed to alleviate the manual, fragmented aspects of GRC work.Â
Some of these tools, inevitably, are being built on more integration of AI. However, firms are being cautious of implementing more AI-controls because they are wary of the risks that increased AI use might bring, especially under new regulations such as the EU’s DORA, which asks firms for a comprehensive ICT risk management framework encompassing AI being utilised within financial operations.
Recommended reading
- Data Security Holding Back Growth for UK Financial Services Firms
- Report: Most Firms Are Struggling To Keep Up With New Regulations
- UK Businesses Face Compliance Leadership Gap
In some respects, a number of businesses are slightly lagging in their preparations for AI regulations, with just 59% having implemented risk management frameworks due under the EU’s AI Act, although 90% have started preparing for DORA, despite those rules coming into force in January.
Regardless of that fact, 97% of firms believe that they are meeting their GRC objectives, although admit that certain actions are harder to implement. Almost a quarter (23%) said that they are not confident in their processes for reviewing and remediating issues, while 17% said they are not meeting their objectives when documenting risk decisions.Â





