CCI staff share recent surveys, reports, and analysis on risk, compliance, governance, infosec, and leadership issues. Share details of your survey with us: editor@corporatecomplianceinsights.com.
59% of Companies ‘Always’ Compromise on Compliance Due to Business Pressures
Research from Creditsafe highlights a concerning trend among businesses: competitive pressures often prompt them to overlook compliance requirements. In a survey involving over 200 U.S. professionals across accounting, legal, and consulting sectors, a staggering 59% admitted they “always” compromise compliance due to these pressures, with an additional 16% acknowledging they do so frequently.
The survey also revealed worrying gaps in compliance programs. A notable 79% of respondents confessed to skipping compliance checks on customers or suppliers, often due to pre-existing relationships. This trend is alarming, especially as violations have surged across different areas, particularly in data privacy and financial accounting. In fact, 67% of respondents reported increased data privacy violations in 2024 compared to the previous year.
Key findings include:
- 43% assess their compliance maturity at the lowest level.
- 64% find it “very challenging” to recruit qualified compliance staff.
- 85% say team size affects their ability to manage compliance proactively.
- 51% cite lack of compliance leadership as the primary cause of failures.
80% of Companies Lack Dedicated Plans for Generative AI Risks
In another notable finding, research by Riskonnect reveals that organizations struggle to manage threats posed by artificial intelligence, despite an increasing focus on cybersecurity. According to their 2024 “New Generation of Risk Report,” while 72% of risk professionals report significant impacts from cybersecurity risks, a shocking 80% lack concrete plans to manage risks related to generative AI.
As AI evolves, nearly 24% of respondents indicated they anticipate the most significant business impacts from AI-driven threats like ransomware and phishing in the coming year. Yet, only 8% feel prepared to confront these emerging risks, highlighting a critical gap in strategy. Furthermore, a striking 65% have no policies governing generative AI usage among partners and suppliers.
Key findings include:
- 90% have increased or maintained risk management technology budgets.
- 62% are leveraging or planning to use AI within risk management.
- 56% have yet to simulate their worst-case scenarios.
“Cybersecurity has become paramount in organizational risk management,” stated Jim Wetekamp, CEO of Riskonnect. “However, it’s concerning that companies aren’t adapting their strategies quickly enough to meet these rising challenges.”
Only 12% of Financial Services Firms Using AI Have Risk Management Frameworks
A significant gap exists in the financial services sector regarding the adoption of AI and proper oversight measures. A recent survey by ACA Group found that while 75% of financial firms are using or looking to integrate AI, merely 12% of those utilizing AI have established a risk management framework. This oversight can leave companies vulnerable to risks associated with AI technologies.
Additionally, third-party oversight in AI governance is alarmingly insufficient. An overwhelming 92% of respondents reported a lack of policies guiding AI use by service providers. Without formal testing programs, firms may find themselves exposed to risks related to cybersecurity, privacy, and operational integrity.
Key findings include:
- 37% have already adopted AI tools for internal use.
- 52% of AI users rely on public tools like ChatGPT.
- 68% report that AI tools have had “no impact” on their compliance programs.
“The most concerning aspect is the lack of governance policies for third-party AI use,” articulated Carlo di Florio, president at ACA Group. “Regulators are stressing the importance of managing these risks as illustrated by recent regulatory movements.”
One-Third of Directors Cite Enterprise Risk Management as Top Governance Focus for 2025
As corporate dynamics evolve, a new survey from BDO indicates that board directors are increasingly aware of balancing growth initiatives with robust risk management practices. Among nearly 250 public company directors surveyed, 31% expect enterprise risk management to consume most of their attention in 2025, even as driving growth remains a primary strategic goal.
Directors have pinpointed monetary policy and inflation as critical areas of concern heading into the 2024 presidential election. Interestingly, while 51% plan to invest more in emerging technologies, 27% also cite challenges in tech implementation as significant risks.
Key findings include:
- Directors spend an average of 285 hours annually focusing on challenging board issues.
- 41% plan to boost spending on cybersecurity, data privacy, and governance initiatives.
- 43% regularly review compliance materials in board meetings.
- 40% discuss company-specific fraud risk factors in meetings.
“Directors have the unique opportunity and responsibility to guide management in executing strategies for sustainable growth while minimizing organizational risk,” noted Amy Rojik, national managing principal at BDO USA.
One-Quarter of Global Executives Cite Employer Risk as Top Threat
Recent research from Beazley reveals that employee-related risks have overtaken other business concerns as the most significant threat facing organizations. In a survey of 3,500 global business leaders, 23% ranked employer risk as their primary concern, a significant increase from 18% in 2022. Alarmingly, nearly a quarter of the executives surveyed feel unprepared to manage this emerging risk.
The survey also showcased growing apprehension about various risk factors, with 42% of executives indicating they operate in a high-risk environment, up from 31% the previous year. Similarly, reputational damage concerns are on the rise, with 20% citing potential brand and trust issues as top risks.
Key findings include:
- 26% intend to revise hiring policies to enhance diversity and inclusion.
- 67% believe ESG regulations are overly complex for their businesses.
- 70% crave more regulatory guidance on ESG requirements.
- 25% of financial services executives rank reputational damage as their top concern.
“While macroeconomic conditions seem to be stabilizing, directors and officers face ongoing liability risks that continue to dominate executive concerns,” asserted Bethany Greenwood, global head of specialty risks at Beazley. “The threat landscape has evolved, requiring leaders to remain vigilant.”
Half of Companies Boost Resources for Geopolitical Risk Management
As geopolitical tensions rise globally, companies are stepping up their defenses. Research from the Association of Corporate Counsel (ACC) indicates that 50% of companies have increased resources to manage geopolitical risks in recent years. This involves navigating complex landscapes involving up to 72 identified high-risk countries, including China, Russia, Mexico, and the United States.
Most companies plan to maintain or enhance engagement with high-risk nations, although Russia stands out; 53% of respondents intend to cease their interactions entirely due to escalating tensions.
Key findings include:
- 49% initiated new due diligence processes.
- 45% implemented risk-related training for staff.
- 43% began scenario planning for potential risks.
“Legal officers now provide a holistic view of risk management, leading firms not just through compliance requirements but also in proactive strategies to safeguard their assets and reputations,” stated Meg Rithmire, professor of business and government at Harvard Business School.

