Corporate risk levels are holding near record highs as legal and compliance teams confront persistent cyber threats, tariff volatility, and fast-moving AI rules. New survey data from Diligent shows companies preparing for a year where exposure remains elevated even as budgets tighten.
Technology Dominates the Risk Landscape
Legal and compliance chiefs rated overall business risk at 7.9 out of 10 in Diligent’s Q4 Business Risk Index, a 16% jump from the first quarter. While the score has leveled off since Q3, respondents say the plateau reflects a new normal rather than relief. Diligent Institute Executive Director Dottie Schindlinger noted that 2025 marked a turning point: “Risk levels didn’t just spike, they settled into an ‘always-on’ baseline,” she said, adding that legal agendas are increasingly oriented around AI exposure, governance requirements, and technology-driven audits.
Technology clearly leads the list of concerns. Sixty percent of respondents identified it as their most significant source of risk, well ahead of economic volatility at 33% and tariffs at 23%. According to recent industry reports, the shift mirrors a surge in high-sophistication cyberattacks targeting identity systems, third-party access points, and cross-border data flows. Many governance teams say that evolving threats are now outpacing internal monitoring capabilities, increasing pressure on Boards to improve readiness.
AI-related concerns continue to rise as organizations prepare for expanding regulatory oversight in 2026. A majority of those surveyed said AI remains a top risk for the coming year, outstripping the economy (23%) and regulations (19%). The finding aligns with recent moves by U.S. and European regulators, who are advancing new disclosure rules, model-risk expectations, and automated decision-making standards.
Budget Constraints Collide With Growing Exposure
Respondents cited market conditions (33%) and cyber alerts (27%) as the leading risk indicators they will be tracking into early 2026. Despite this heightened vigilance, a third of organizations said they plan to keep risk management budgets flat or reduced next year. This dynamic is emerging alongside continued concerns around fragmented governance structures, with many compliance, audit, and finance teams struggling to integrate processes and data across departments.
For the minority expecting budget increases, the most common investments include regulatory tracking and monitoring platforms (26%) and enhanced cyber and data-privacy defenses (23%). These priorities reflect a broader corporate trend: recent public filings show more companies directing capital toward tools that automate regulatory scans, centralize risk signals, and improve detection of third-party vulnerabilities.
Cross-functional coordination remains a major pain point. Forty-four percent of respondents said improving collaboration across legal, compliance, audit, and finance would be their top focus if they had the opportunity. Only 4% reported that their governance, risk, compliance, and financial systems are fully integrated, a structural gap that keeps critical data siloed and weakens the timeliness of escalation processes.
Why Early Alignment May Shape Risk Outcomes Next Year
Governance research published throughout 2025 shows that organizations respond more effectively to regulatory shifts and cyber incidents when legal, compliance, finance, and technology teams decide early how information will flow and who owns specific decisions. Companies that put these structures in place ahead of new AI rules, tariff adjustments, or cross-border data requirements have reported fewer delays and lower compliance costs. With exposure expected to remain elevated in 2026, establishing that alignment before the next wave of regulations takes effect could materially change how organizations absorb emerging risks.