On a recent episode of the Institute of International Finance’s (IIF) Global Regulatory Update podcast, EY’s Tom Campanile, Chris Woolard, and Jim Barkley reflected on how bank risk management has shifted from responding to discrete crises to navigating what they described as a “NAVI” environment, defined by risks that are Non-linear, Accelerated, Volatile, and Interconnected.
In the conversation hosted by the IIF’s Martin Boer, General Manager and Chief Representative for Europe, the discussants drew on the findings of the 15th Annual EY-IIF Global Bank Risk Management Survey. They noted that cyber and technology risks remain the top near-term priority, cited by 86% of CROs, but that the more significant shift is that those risks now intersect with geopolitics, third-party dependencies, data quality, and AI governance. Geopolitical uncertainty was a key focus, with 74% of CROs prioritizing trade policy, tariffs, and sanctions, and 68% prioritizing evolving cybersecurity threats.
Woolard noted that while existing supervisory tools have proven adaptable, regulators are struggling to keep pace with the speed of technological change. “The innovation cycle is very, very clearly moving a lot faster than the policy cycle,” he said. As a result, regulators are increasingly looking to boards to demonstrate agility and forward-looking judgment rather than waiting for policy to catch up.
The survey also exposes a persistent gap between framework maturity and real-world resilience. Crisis response, third-party risk, and data remain areas where banks most commonly overestimate their readiness, Barkley explained. “The biggest blind spot is crisis response,” he warned. “Playbooks gather dust, testing is infrequent, and the scenarios that matter the most … are still underrehearsed.”
Looking ahead, the discussants identified complacency, people risk, and geopolitical sovereignty as the most underestimated risks. Success in five years, Campanile argued, means the CRO evolving to become the Chief Strategic Risk Officer. “It will be a function where the CRO is no longer just managing a catalog of risks,” he said. “They are managing an ecosystem of uncertainty, and they’ve got a workforce that’s been reshaped around insight, as opposed to process and check the box.”
Join The Discussion
Sign in and be the first to comment.