Benchmarking
For enterprise risk, influence runs deeper than any veto
Risk Benchmarking study finds formal veto rights concentrated among the largest lenders, but used only as a last resort
Enterprise Risk Benchmarking 2026: explore the data
View interactive charts from Risk.net’s 52-bank study, covering enterprise risk governance, appetite setting, board reporting, scenario analysis, culture and resilience
ERM’s influence is growing as its ranks are shrinking
Risk Benchmarking: Mandates expanding to include new threats like AI and geopolitical risk, but majority report flat to down headcount
Risk managers go softly-softly on AI adoption
ERM teams still in testing mode for most AI use cases, latest Risk Benchmarking study shows
Most banks embed risk appetite into business decisions
Risk Benchmarking: Second line more likely to be shut out when it comes to product launches or market entry
Four in five banks report breaching risk appetite in past year
Risk Benchmarking: Those reporting no breaches run skinnier appetite frameworks, despite similar governance mechanisms
Slimmed-down and automated, ERM seeks a seat at the top table
Latest Risk Benchmarking exercise finds ERM growing in influence, even as headcounts shrink
Banks building GenAI governance in parallel to model risk
Risk Benchmarking: Majority have established AI governance committees, but ownership is fragmented
Lower-risk models face excessive reviews, banks say
Risk Benchmarking: Validation workload stretching teams, amid emerging regulatory divergence
Model risk managers see growing regulatory divergence
Risk Benchmarking study finds most banks expect easing of model risk supervisory scrutiny in the US, but tightening in Europe
Many banks do not document failure plans for Tier 1 models
Risk Benchmarking: Strong predeployment validation gives way to ad hoc escalation of breaches, even at some large lenders
The evolution of operational risk scenario analysis
How structured scenario analysis paired with AI-enabled challenge can modernise banks’ operational risk practices
Model risk managers are being asked to do more with less
Risk Benchmarking study finds function being handed expanding AI workload, on flat resources
Banks are automating GenAI testing, but scope varies widely
Risk Benchmarking: LLM-as-judge offers model testing at scale, but few lenders use it to facilitate autonomous sign-off
Model Risk Benchmarking 2026: explore the data
View interactive charts from Risk.net’s 44-bank study, covering model inventories, resourcing, GenAI governance, validation and regulation
A third of banks do not maintain logs for GenAI models
Risk Benchmarking study finds few banks review prompt logs systematically, with larger firms focusing on higher risk use cases
Few banks formally evaluate GenAI human-in-the-loop controls
Risk Benchmarking: G-Sibs and challengers use tools to test controls efficacy; others rely on judgement
From gatekeeper to coach: model risk bids to reinvent itself
Model Risk Benchmarking data reveals a function in flux, grappling with resource cuts, AI models, regulatory divergence
Banks insure against cyber risk, but rarely claim
Risk Benchmarking study finds big banks aggressively negotiating on cost of cover, and seeking offsets to Pillar 2 capital
Four in five banks use AI to manage op risks
Risk Benchmarking: Cyber risk use cases growing; governance and ROI doubts give some pause
Build, or buy: banks still don’t love their GRC vendors
Risk Benchmarking study finds a record number of firms reviewing tech provision for top op risks, amid touted wave of AI-led self-builds