
Based on BarnOwl GRC‘s review and synthesis of 48 GRC, risk, audit, governance and compliance publications released during May 2026, the following article brings together the key themes that risk managers, executives and boards should be paying attention to.
The review covered perspectives from risk management, internal audit, governance, compliance, enterprise risk management, AI governance, third-party risk management, and board oversight. What emerged was not simply another collection of risk trends. Instead, the period highlighted a significant shift in how organisations are expected to manage risk, govern artificial intelligence, oversee internal controls, and support strategic decision-making.
Several respected voices in the profession reached remarkably similar conclusions: traditional risk management approaches are being challenged, AI governance has become a board-level responsibility, information integrity is emerging as a critical enterprise risk, and organisations must move beyond risk reporting towards risk-informed decision-making.
For years, organisations have focused on refining risk registers, updating heat maps and debating risk appetite statements. While these tools still have value, recent developments suggest that the profession is undergoing a fundamental shift. The question is no longer whether risks are identified and documented. The question is whether organisations can make better decisions, faster, in an environment shaped by artificial intelligence, geopolitical uncertainty, information manipulation, and rapid organisational change.
1. Risk Management Must Move From Reporting to Decision Support
Perhaps the most significant development during the period was COSO’s release of From Guidance to Action: Exploring Practical Enterprise Risk Management.
The publication challenges the long-standing practice of treating Enterprise Risk Management (ERM) as a documentation exercise. Instead, it positions risk management as a discipline that should directly improve decision-making.
This aligns with a growing body of criticism from leading practitioners who argue that risk registers, heat maps and risk appetite statements often create the illusion of control without necessarily improving business outcomes.
For risk leaders, the key question is simple: can you demonstrate how risk management influenced a strategic decision?
The organisations that will succeed are those where risk professionals become trusted decision partners rather than report producers.
2. AI Governance Has Become a Board-Level Accountability Issue
The conversation around artificial intelligence has changed dramatically.
Boards, regulators, auditors and stakeholders are no longer asking whether organisations are experimenting with AI. They are asking whether AI is governed.
Across multiple publications, a common theme emerged: organisations must be able to demonstrate accountability, transparency and oversight over AI-enabled decisions.
This becomes even more important when AI systems continuously learn and evolve. Traditional assurance approaches, which test controls once during implementation, are no longer sufficient.
Boards should be asking:
- Can we explain how an AI-assisted decision was made?
- Who is accountable for AI outcomes?
- Who owns the AI kill-switch?
- How often are AI systems reassessed for drift, bias and unexpected behaviour?
AI governance is rapidly becoming one of the most important board oversight responsibilities of the decade.
3. Information Integrity Has Emerged as a Top Enterprise Risk
One of the most concerning emerging risks identified during the review is information integrity.
Organisations increasingly depend on vast quantities of data, much of which may be incomplete, manipulated, inaccurate or AI-generated.
The challenge is no longer simply protecting information. It is ensuring that decision-makers can trust the information on which critical decisions are based.
Risk leaders should consider:
- Strengthening data lineage and traceability.
- Implementing controls over AI-generated content.
- Validating critical data sources used in strategic decisions.
- Including information integrity as a formal enterprise risk category.
For many organisations, this risk is still receiving far less attention than it deserves.
4. AI-Driven Restructuring Creates Hidden Control Risks
One of the most practical and under-discussed risks highlighted during the period relates to organisational restructuring.
Many organisations are pursuing workforce optimisation initiatives supported by AI-driven efficiencies. However, experienced employees often perform critical controls that are undocumented and poorly understood.
When those individuals leave, key controls frequently disappear with them.
Before approving restructuring initiatives, executives should ask:
- Which key controls depend on the employees being removed?
- How will those controls operate after restructuring?
- Has Internal Audit assessed the impact on the control environment?
- What institutional knowledge may be lost?
The financial savings are often immediate. The control failures generally emerge much later.
5. Internal Audit Is Being Reinvented
Internal Audit featured more prominently in the review than any other assurance function.
Stakeholders increasingly expect Internal Audit to provide forward-looking insight rather than historical assessments.
At the same time, audit functions face growing expectations around AI, cyber security, third-party risk, culture, conduct and emerging risks—often without additional resources.
The future Internal Audit function will likely focus on:
- Continuous assurance instead of periodic reviews.
- Monitoring AI behaviour and governance.
- Identifying emerging risks earlier.
- Providing strategic insight to executives and boards.
If audit plans look the same as they did three years ago, organisations should question whether they remain aligned to today’s risk landscape.
6. Third-Party Risk Is Expanding Beyond Traditional Vendor Management
Third-party risk continues to grow in complexity and importance.
A key shift is that organisations are now exposed not only to the risks of their suppliers but also to the risks created by their suppliers’ use of artificial intelligence.
This means that a vendor’s AI governance practices may directly affect your organisation’s reputation, compliance obligations and operational resilience.
Questions to ask suppliers now include:
- How are you governing AI within your organisation?
- What decisions are being supported by AI?
- What controls exist to monitor AI outcomes?
- How would our organisation be impacted if those systems failed?
Third-party risk management is increasingly becoming ecosystem risk management.
7. African Organisations Face a Unique Risk Environment
Several Africa-focused publications highlighted a combination of risks that require particular attention:
- Trade fragmentation and tariff uncertainty.
- Currency volatility.
- Climate-related disruption.
- Accelerating regulatory requirements.
- Cybersecurity threats.
- Governance and corruption exposure through suppliers and partners.
For South African organisations, one theme stood out above all others: consequence management.
Many governance failures are not caused by missing policies or frameworks. They occur because breaches are not followed by meaningful consequences.
Effective governance requires both accountability and enforcement.
8. The GRC Technology Market Is Undergoing Major Transformation
The GRC technology landscape is shifting from disconnected modules towards integrated “command centre” architectures.
The key differentiator is no longer the number of features a platform offers. It is the ability to orchestrate information, provide meaningful insights and support decision-making across the organisation.
Executives evaluating GRC platforms should focus on:
- Data integration capabilities.
- AI explainability.
- Decision-support functionality.
- Real-time risk visibility.
- Cross-functional orchestration.
Technology should enable better decisions, not simply automate reporting.
What Risk Managers Should Do Next
Based on the themes emerging from the review, risk managers should consider the following priorities:
- Reposition risk management as a decision-support capability.
- Establish robust AI governance and assurance mechanisms.
- Add information integrity to enterprise risk discussions.
- Review control effectiveness following restructurings.
- Shift assurance activities towards continuous monitoring.
- Measure third-party risk outcomes rather than activities.
- Strengthen consequence management and accountability.
- Ensure GRC technology investments support decision-making.
Questions Every Board Should Be Asking
- How do we know our AI-enabled decisions are governed?
- What risks have emerged because of recent organisational changes?
- Can we trust the information informing our strategic decisions?
- Are risk and audit functions focused on the risks that matter most?
- Do our suppliers’ risks become our risks?
- Is our GRC technology helping us make better decisions?
The organisations that thrive in the coming years will not necessarily be those with the most sophisticated risk frameworks. They will be those that can consistently make better decisions in an increasingly uncertain world.
The message emerging from the April–May 2026 review is clear: the future of risk management is not about better reporting. It is about better decisions.
This article is based on BawnOwl’s review and synthesis of 48 GRC, risk, audit, governance and compliance publications released during April and May 2026, highlighting the themes most relevant to risk managers, executives and boards.
iGRECS strive to empower sustainable impact through good governance by connecting expertise, build capacity and fostering inclusive, transparent and integrated GRECS and related practices.