Key takeaways
AI in operational and non-financial risk
Moving from experimentation to transformation
Service
ORX Membership
ORX Cyber
Risk programme
Management, Practice & Framework
Key takeaways - September 2026
Artificial Intelligence (AI) has rapidly become one of the most significant topics shaping operational and non-financial risk (ONFR) management.
Across our research, working group discussions, cyber community sessions and leader forums during 2026, a clear picture has emerged: firms are moving beyond experimentation and beginning to see tangible benefits from AI adoption.
At the same time, recent developments have highlighted that successful adoption is about more than deploying new technology. As AI capabilities evolve, firms are increasingly considering how AI is reshaping the risk landscape, creating new dependencies and introducing challenges around governance, resilience, oversight and strategic control.
This article brings together key insights from our AI-related activities during 2026, covering:
- AI adoption and emerging value.
- Strategy and transformation priorities.
- AI-driven risks and industry concerns.
- Governance and oversight.
- Future considerations around operating models, skills and culture.
Gated content start
This resource is available to all ORX members and ORX Cyber subscribers
Interested in reading more?
If your firm is a member of ORX, or subscribes to ORX Cyber, log in or create an account to access the article.
Not a member or ORX Cyber subscriber? Talk to us today to discuss how you could join the ORX community.
| Benefit | Example AI use case |
|---|---|
| Quicker speed and higher accuracy by reducing manual activities | AI-assisted compliance mapping, automatically linking new regulations to relevant policies and controls to reduce manual review and improve consistency. |
|
Becoming real-time and dynamic, less cyclical |
Always-on AI monitoring, flagging emerging risks, control weaknesses, cyber threats and regulatory changes in real time. |
| Improving data quality, accessibility and connectivity | AI enhancement of control descriptions, incident reports and risk data, supporting information standardisation and dataset connectivity. |
| Deeper insights from data | AI analysis of connected risk, control, issue and incident data to identify trends, patterns and relationships. |
| Enhancing efficiency and productivity | AI support for RCSA assessments, scenarios, report drafting and meeting summaries, reducing administration for risk teams. |
| Greater strategic focus | AI automation of monitoring, reporting and data gathering, freeing up risk teams for judgement, challenge and decision support. |
| Greater innovation | Rapid AI-enabled testing of new risk solutions, such as control monitoring or automated issue analysis. |
| Keeping pace with competitors and improving customer experience | AI-powered customer tools, such as chatbots or faster onboarding, improving responsiveness and competitiveness. |
| Keeping pace with bad actors | AI-enhanced cyber and fraud detection, identifying abnormal behaviour, attack patterns and suspicious activity faster. |
| Stage | Summary | Details |
|---|---|---|
| 1 | Efficiency - doing what we do now but cheaper and faster. |
Using AI to reduce manual effort, shorten cycle times and remove low-value process work. Example AI uses: RCSA automation, scenario generation, ongoing control performance monitoring, obligations mapping and compliance tracking. |
|
2 |
Capability - doing what we do now but cheaper, faster and better. |
Using AI not just to do the same work faster, but to improve the quality, consistency and usefulness of the output. Example AI uses: enhancing controls and proposing improved control designs. |
| 3 | Innovation - doing new things. | Using the productivity released in the first two stages to move higher up the value chain and do things that were previously too slow, too expensive or too difficult. |

