KPMG Survey Finds Compliance Chiefs Facing a Wider Risk Mandate
Key Takeaways
- Resilience Is Moving Into the Compliance Brief: KPMG’s survey finds CCOs increasingly involved in cybersecurity, data protection, third-party risk and business continuity as operational and compliance risks become more closely connected.
- Data and Cybersecurity Lead Investment: Among CCOs anticipating budget increases, 77% cited data analytics and 75% cited cybersecurity and data privacy as drivers of additional investment.
- Regulatory Pressure Remains the Leading Challenge: New regulatory requirements were cited by 33% of respondents as a top compliance challenge for the next two years, ahead of data analytics and predictive modeling at 31%.
- AI Optimism Comes With Limits: While 68% described their AI experience as mixed but leaning positive and another 24% reported significant improvements, adoption remains far lower for sensitive work such as investigations, anti-money laundering and legal drafting.
- Compliance Is Becoming More Collaborative: Eighty-one percent of respondents expressed confidence in working with cybersecurity teams, 68% with resilience and business continuity teams, and 67% in identifying synergies across functions including legal, HR, internal audit and operations.
Deep Dive
KPMG asked 725 chief ethics and compliance officers where they expect to put additional money. The answer was not subtle. Among respondents anticipating budget increases, 77% pointed to data analytics and 75% to cybersecurity and data privacy. AI or large language models came next at 50%, followed by process automation at 49%. Upskilling talent, at 34%, trailed considerably further behind.
KPMG’s 2026 Global Chief Ethics and Compliance Officer Survey, released in August, looks at what has happened to the compliance job. The rule book remains. So do the investigations, controls, training programs and regulatory examinations. But compliance leaders increasingly find themselves pulled into the risks that determine whether an organization can keep operating when something goes wrong.
The survey covered CCOs at large companies across eight countries and six industries: healthcare and life sciences, financial services, industrial manufacturing, consumer and retail, technology, media and telecommunications, and energy and natural resources. KPMG normalized the data to account for the larger U.S. response population.
The pressure is especially visible in the United States. Among U.S. respondents expecting higher budgets, 87% said cybersecurity and data privacy would drive additional investment, while 85% cited data analytics. The comparable cybersecurity figures were 57% in Japan and 58% in Australia. For data analytics, they were 69% and 63%, respectively.
KPMG’s larger conclusion is that operational resilience is becoming part of the compliance brief. Cyber incidents can trigger investigations, litigation and reputational damage. Third-party failures can interrupt operations. The growing use of compliance data creates its own privacy and security responsibilities. Risks that once belonged comfortably to different boxes on an organizational chart have become less considerate about staying there.
Regulation Has Not Loosened Its Grip
For all the new demands on compliance, the oldest one remains the most stubborn. Asked to identify the top challenges their organizations will face in compliance over the next two years, 33% of respondents selected new regulatory requirements, the highest result in the survey. Data analytics and predictive modeling for compliance monitoring and risk management followed closely at 31%. Implementing technological tools was cited by 25%, upskilling compliance professionals by 24% and data accuracy and completeness by 23%.
The regulatory pressure was more pronounced among U.S. respondents. Forty-one percent identified new regulatory requirements as a leading challenge, compared with 30% of respondents elsewhere. KPMG suggested that the difference may reflect the unpredictability of U.S. policymaking.
The combination matters. Compliance departments are not being relieved of their traditional responsibilities so that they can concentrate on cyber risk, analytics or AI. The new work has simply arrived.
That helps explain why KPMG places so much weight on operational resilience. The report urges CCOs to use dynamic risk assessments to understand how risk events connect, conduct scenario planning for events such as ransomware attacks and critical third-party failures, and develop more unified approaches to cybersecurity, privacy, sustainability and third-party risk. It also argues that compliance leaders should be involved when organizations govern and adopt new technologies rather than appearing only after a breach has occurred.
AI Gets a Cautious Welcome
Compliance officers are hardly hostile to AI. They are simply not prepared to hand it the keys. Sixty-eight percent of respondents characterized their experience using AI to improve compliance efficiency and effectiveness as “mixed, leaning positive,” meaning they had seen more benefits than challenges. Another 24% reported significant improvements. Seven percent leaned negative, while 1% reported significant challenges or had not yet implemented AI.
What organizations are willing to use AI for is more revealing than the sentiment numbers. Half of respondents said their organizations use automation or AI and machine learning for compliance risk assessment and management. Forty-four percent use it for data visualization and predictive analytics, and the same share use it for employee training and awareness. Regulatory change management followed at 43%, with KPI or KRI metrics and reporting at 39%.
Then the numbers fall. Only 17% reported using the technology to draft and review new legal documents and contracts. Twelve percent use it for anti-money laundering and the same share for contract compliance. Just 4% use it for hotlines and investigations. KPMG sees the pattern as a sign that confidence thins when AI moves into work demanding greater sensitivity, complexity and human judgment.
There are good reasons for the hesitation. KPMG identifies algorithmic bias, poor transparency, uncertain regulation and weak or disparate data among the barriers to wider adoption. Human oversight remains a particular problem for more complicated compliance work. The report also raises a quieter concern: as AI takes over entry-level tasks, junior employees may lose some of the experience through which they would ordinarily learn to judge the quality of AI-generated work later in their careers.
The organizational readiness behind the technology is not especially reassuring either. Only 21% of respondents said their organizations were very well prepared to upskill compliance professionals, while 20% said the same about enhancing compliance culture.
KPMG recommends beginning with lower-risk, higher-return applications before moving into more complex uses. It also calls for formal AI governance that establishes ethical guidelines, assigns responsibility for oversight and creates processes for vetting, approving and monitoring AI tools. Human review and explainability, the report argues, remain necessary if compliance teams are expected to understand and defend what their systems produce.
The Walls Between Functions Are Getting Thinner
Some of the survey’s strongest numbers concern neither regulation nor AI. They concern whom compliance officers trust themselves to work with. Eighty-one percent of respondents said they were confident collaborating with cybersecurity teams to manage cybersecurity compliance risks. Sixty-eight percent expressed confidence in working with resilience and business continuity teams on critical operations. Another 67% were confident in assessing compliance synergies and duplication across legal, human resources, investigations, internal audit and operations.
Those relationships are important to KPMG’s argument that the CCO is moving away from the role of a reactive steward of rules and procedures. The report describes compliance leaders as increasingly interested in changing the perception of their functions from cost centers into strategic business units capable of protecting reputation and contributing to business value.
That aspiration is hardly new. Compliance departments have been arguing that they create value for years. What is changing is the evidence available to make the case, and perhaps the consequences of failing to make it.
KPMG recommends embedding compliance in strategic planning for new markets, products and deals, developing stronger compliance analytics, harmonizing processes across jurisdictions and connecting compliance objectives with employee performance management. It also urges CCOs to explain their contribution to boards and senior management in terms that executives recognize: protection from regulatory scrutiny and fines, certainly, but also brand value and growth.
That is a considerably larger job than keeping an organization on the right side of its obligations. The survey suggests many compliance leaders already know it. They are investing in analytics because they need to see risk earlier, working with cyber and resilience teams because operational failures refuse to respect functional boundaries, and experimenting with AI while remaining wary of decisions they cannot explain.
The rule book has not become less important. It has simply become one part of a much heavier brief.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

