What will drive the next five years of change in governance, risk and compliance?

51.3% of practitioners rank ‘advancements in AI and technology’ as the number one driver of change in GRC over the next five years — more than double the next closest factor.

‘AI governance and ethics’ is expected to require the most attention (35.9%), ahead of data privacy and cybersecurity (25.0%).

Key Statistics

  • 51.3% rank ‘advancements in AI and technology’ as the biggest driver of GRC change over the next five years.
  • 35.9% say ‘AI governance and ethics’ will require the most attention in GRC over the coming years.
  • 25.0% say data privacy and cybersecurity will require the most attention.
  • 36.5% expect increased reliance on AI with fewer manual roles in GRC over the next five years.
  • An equal 36.5% expect greater integration of GRC with strategic decision-making.
    Recruiting or retaining skilled GRC professionals is rated the lowest-priority challenge of the four tested (score 1.96).

Source: ICA Global GRC Survey 2025. Survey of 383 practitioners across 87 countries and 30+ sectors.

Biggest drivers of change in GRC over the next five years (ranked)

AI and technology dominate as the expected driver of change, scoring well ahead of new regulation, globalisation, or shifting social expectations — despite new regulation traditionally being seen as GRC's primary forcing function.

Driver of change Rank 1 Rank 2 Rank 3 Rank 4 Score
Advancements in AI and technology 51.28% 21.15% 12.82% 14.74% 3.09
New regulations and laws 22.44% 35.26% 27.56% 14.74% 2.65
Globalisation and cross-border challenges 16.03% 26.28% 31.41% 26.28% 2.32
Evolving ethical and social expectations 10.26% 17.31% 28.21% 44.23% 1.94

Area requiring the most attention in GRC

AI governance and ethics is the clear leading concern, ahead of data privacy/cybersecurity and traditional areas like ESG or supply chain risk — notably, fraud risk is also named as a distinct area of future GRC attention.

Area % of respondents
AI governance and ethics 35.90%
Data privacy and cybersecurity 25.00%
Environmental, social and governance (ESG) compliance 15.38%
Supply chain and third-party risk management 9.62%
Fraud risk 9.62%
Other 4.49%

How GRC roles are expected to evolve

Practitioners are evenly split between two visions of the future: a third expect greater reliance on AI with fewer manual roles, and an equal share expect GRC to become more integrated into strategic decision-making — which, taken together, are two sides of the same shift.

Expected evolution % of respondents
Increased reliance on AI, with fewer manual roles 36.54%
Greater integration with strategic decision-making 36.54%
Expansion of teams to manage complex regulations 15.38%
Little to no change from current roles 11.54%

Challenges foreseen adapting to GRC requirements over the next five years (ranked)

Recruiting or retaining skilled GRC professionals is rated the least pressing challenge relative to the other three — keeping pace with rapidly changing regulation and balancing GRC with business goals are seen as the bigger tests.

Challenge Rank 1 Rank 2 Rank 3 Rank 4 Score
Balancing governance, risk & compliance and business goals 30.77% 28.21% 28.21% 12.82% 2.77
Keeping up with rapidly changing regulations 33.33% 25.64% 19.87% 21.15% 2.71
Costs associated with adopting new technologies 25.64% 26.28% 26.28% 21.79% 2.56
Recruiting or retaining skilled GRC professionals 10.26% 19.87% 25.64% 44.23% 1.96

Summary

The next five years, on this data, are expected to be defined by AI — both as the biggest driver of change and the area needing most governance attention — with GRC roles evolving toward either automation-supported efficiency or deeper strategic integration, and in many firms, likely both at once.