BDO Global Risk Landscape 2026


Published: 
 

Why not only a bad decision, but also excessive caution and inaction can become a risk in the current environment 

How companies' preparedness for cyber, geopolitical and other interconnected threats is changing 

What role artificial intelligence plays in risk management and why companies need to connect risk more closely with strategy and decision-making 



The results of this year's BDO Global Risk Landscape 2026 are out. And the main message is quite clear: Risk is no longer a standalone discipline managed by a close-knit team of experts. Risk is everywhere – in strategy, technology, supply chains, regulation, geopolitics and the day-to-day decision-making of companies. This year's study shows a fundamental shift.

Companies are increasingly aware that being overly cautious can be a risk in itself. In an environment where crises are accelerating and uncertainty is becoming the new normal, it is not enough just to protect existing business. Organizations that can make informed decisions even without perfect information will have a competitive advantage.

What are the main findings?
 

1. Risk is no longer just a specialist's agenda.

Today, risk arises across the entire company – in technology, supply chains, regulation, finance and day-to-day decision-making. 89% of companies already consider how individual risks affect each other when assessing threats. Yet many organizations still manage risks separately by team.
 

2. Inaction is a risk in itself today.

Companies can no longer wait for the environment to calm down. Uncertainty has become a normal part of business. 80% of leaders say that the global environment is more affected by crises today than ever before. At the same time, 68% say that crises are hitting their companies faster than in the past.
 

3. Companies want to take risks more cautiously, but also more intelligently.

It is not about greater courage at all costs. It is about the ability to distinguish which risks to take and which to actively limit. The proportion of companies that are willing to take risks when necessary has increased from 26% to 36%. At the same time, only 9% of companies describe their risk management as very proactive.
 

4. Cyber risk returns to the forefront.

Cyber threats are growing faster than companies' ability to defend against them. 40% of leaders cite cybersecurity as the main risk they are not prepared for. Last year, it was 23%. This represents an increase of 17 percentage points.
 

5. Security gets involved in projects too late.

Cybersecurity often comes into play only when the crucial decisions have already been made. Only 10% of cyber teams are involved at the initial idea stage. 26% are involved only at the implementation stage and 6% even just before launch.
 

6. Geopolitics amplifies all other risks.

Geopolitics is no longer a standalone threat. It affects suppliers, regulation, data, customs, technology and cybersecurity. Geopolitical risk is one of the three most significant risks for which companies do not feel prepared. However, different members of management see its impacts differently: some deal with supply chains, others with regulation or cyberattacks.
 

7. Artificial intelligence brings opportunity, but also greater demands on management.

Companies are more optimistic about artificial intelligence. But the risks do not disappear. Rather, they are shifting into the areas of data, accountability and controls. 66% of companies see the development of artificial intelligence as an opportunity. Last year, it was 57%. At the same time, 27% of companies cite artificial intelligence as a new risk for which they are not prepared.
 

8. The biggest risks of artificial intelligence are not only technical.

Companies are most concerned about the impact on data privacy, compliance and cybersecurity. The top five risks of AI include data protection, regulatory compliance, cybersecurity, complex integration and inaccurate outputs.
 

9. Fraud is disappearing from management's attention – and that can be a problem.

The risk of fraud is not decreasing. It is often simply hidden under cyber risks, artificial intelligence or digital security. 93% of leaders do not consider fraud to be one of the main risks they are not prepared for. At the same time, technologies, including artificial intelligence and deepfake tools, allow fraud to scale faster.
 

10. Fraud defence lags behind technological developments.

Companies know that artificial intelligence is changing the nature of fraud. Yet few of them are actively adjusting their defences. Last year, 79% of leaders said they had a plan in place to defend against AI-powered fraud. This year, only 13% are actively monitoring and updating their defences against these threats.
 

11. Companies do not lack data, but the ability to distinguish what is important.

Risk signals are increasing. The problem is knowing which ones require a real response. 52% of companies have trouble distinguishing important warning signs from ordinary noise. 55% say that short-term operational pressures often crowd out long-term risk planning.
 

12. Risk management must become a tool for growth.

Well-managed risk does not hold a company back. It helps it make decisions faster, more confidently and with greater resilience. 99% of organizations plan to improve risk management in the next three years. But the real difference will be made by those companies that combine strategy, operations, technology, finance and leadership into a single decision-making framework.
 

Authors