Dependency and assurance both lead to the same difficult question: who is accountable when risk sits across several teams, systems, suppliers and controls at once?
For many firms, risk management has become more structured, more visible and more heavily governed than ever before.
There are frameworks for operational resilience, cyber security, third-party risk, data protection, financial crime, conduct, model risk and AI. There are committees, policies, reporting packs, control libraries, issue logs and assurance plans. There are named owners, accountable executives and defined escalation routes.
On paper, the landscape can look well managed.
In practice, the harder question is often not whether each risk area has a framework. It is whether the organisation can see what happens between them.
A technology change may create cyber, data, operational resilience, conduct and third-party implications at the same time. A new AI-enabled process may raise questions about governance, explainability, customer outcomes, model performance, data quality and human oversight. A supplier failure may become a service disruption, a regulatory issue, a customer impact event and an internal control weakness all at once.
Each area may have an owner.
But the gap between those owners is where risk can become harder to see.
That is where enterprise risk management should play an important role. Not as another layer of reporting or a separate framework competing for attention, but as the connective discipline that helps an organisation understand how risks interact, where ownership becomes blurred and where separate risk views need to be brought together.
Fragmentation is not only a regulatory problem
It is easy to describe this as regulatory fragmentation.
That is certainly part of the challenge. Firms operating across jurisdictions, sectors and business lines are often managing overlapping expectations from multiple regulators and standard setters. Requirements may differ in wording, timing, scope and reporting format, even when they are pointing to similar underlying concerns.
But fragmentation is not created by regulation alone.
It is also created by how organisations respond to it.
A new requirement arrives and a new workstream is created. A new risk theme emerges and a new committee paper is developed. A new technology is introduced and a specific governance process is added around it. Over time, firms can end up with separate frameworks for related risks, each with its own terminology, reporting cadence and ownership model.
The result is not always stronger control.
Sometimes it is more activity without a clearer view.
The organisation may be busy managing cyber risk, data risk, supplier risk, AI risk, operational resilience and customer risk, but still struggle to understand how those risks connect in a real service, process or decision.
That is the challenge senior GRC professionals are increasingly facing, and it is one of the reasons ERM matters. At its best, ERM should help move the organisation beyond a set of separate risk categories and towards a more comprehensive view of exposure, impact, interdependency and accountability.
The risk rarely fits the organisational chart
Risks do not always arrive in the same shape as the functions designed to manage them.
A cyber incident may begin as a technology issue, but quickly affect customer communications, service availability, regulatory reporting, operational continuity and third-party performance. A flawed automated decision may involve data quality, model governance, customer harm, compliance obligations and human review. A cloud outage may affect internal operations, client-facing platforms, transaction processing, reporting and incident response at the same time.
The event does not respect functional boundaries.
The organisation, however, may still be trying to manage it through them.
That creates a familiar pattern. Technology looks at the system. Compliance looks at obligations. Risk looks at the exposure. Operations looks at service impact. Legal looks at notification. Internal audit looks at assurance. Each team may be doing its job properly, but no single view may show the full consequence of the issue.
This is where ownership can become blurred.
Not because no one cares, and not because the organisation lacks governance, but because the risk sits across several forms of governance at once.
ERM should help challenge that fragmentation. It should ask whether the organisation understands the risk in the round, not only through the lens of the function that first identified it.
More frameworks do not always create more accountability
When risk becomes more complex, the instinct is often to add structure.
That can be necessary. Firms do need policies, controls, reporting and accountability. But more structure does not automatically mean better ownership.
In some cases, it can create the opposite effect.
If every risk has its own framework, owners may focus on their part of the picture rather than the shared outcome. If reporting is split across too many committees, senior management may receive multiple updates without a clear view of the connections between them. If each function uses different language, the same issue may be described in several different ways and treated as several separate problems.
That can make gaps harder to challenge.
A control weakness may appear to belong to operations, but depend on a technology fix. A supplier issue may sit with procurement, but affect resilience, data and customer outcomes. An AI governance question may sit with digital or innovation teams, but create implications for compliance, conduct and audit.
The organisation may have ownership for each component.
What it may not have is ownership of the combined risk.
This is where ERM needs to be more than a risk register, taxonomy or reporting cycle. Its value lies in helping senior leaders understand where risks connect, where they compound and where accountability needs to be made explicit.
The common themes are often hiding in plain sight
Although regulatory expectations can feel fragmented, many are pointing towards similar underlying questions.
Who is accountable? What data is being used? How is the decision made? What happens if the system fails? What impact could this have on customers or markets? What evidence supports management’s confidence? How would the organisation know if something was going wrong?
These questions appear across many areas of GRC.
They are present in operational resilience, cyber security, third-party risk, AI governance, financial crime, conduct, data protection and internal control. The terminology may change, but the underlying themes are often consistent: accountability, visibility, resilience, evidence, escalation and impact.
That matters because firms do not need to treat every new regulatory or risk development as a completely separate problem.
A mature ERM approach should help firms move beyond separate risk categories and identify the common themes running across them. If several frameworks require clearer ownership, the issue may be accountability rather than compliance. If several risk areas depend on the same system, supplier or data source, the issue may be concentration rather than process design. If several reports show exceptions, delays or overrides, the issue may be control reliability rather than isolated incidents.
This is where ERM can add real value.
Not by creating more documentation, but by helping the organisation interpret what connected signals are saying.
AI is making the accountability question sharper
AI is a useful example because it does not sit neatly in one function.
It may be introduced by technology teams, used by operations, overseen by risk, assessed by compliance, challenged by audit and experienced by customers. It may rely on external models, internal data, third-party tools and automated workflows that affect decisions at scale.
That makes accountability more difficult to define.
If an AI-enabled process produces a poor outcome, who owns the issue? The business area using it? The technology team that implemented it? The data team that supplied the inputs? The vendor that provided the model? The risk function that reviewed the framework? The senior manager accountable for the process?
The answer cannot be that everyone owns a part of it, but no one owns the outcome.
That is why governance needs to focus not only on the technology itself, but on the decision, the impact and the evidence around it.
The question is not simply whether an AI tool has been approved. It is whether the organisation understands where it is being used, what decisions it influences, what controls sit around it, how performance is monitored and who is accountable when it creates an outcome that matters.
ERM has a role here because AI risk is rarely only AI risk. It may also be data risk, supplier risk, conduct risk, resilience risk, model risk, operational risk and reputational risk. The organisation needs a way to see those connections before they appear as separate issues after something has gone wrong.
Internal audit has a role in challenging the joins
Internal audit is well placed to challenge fragmented accountability, provided it looks beyond individual frameworks.
Traditional audits of cyber, third-party risk, data governance or operational resilience remain important. But some of the most valuable assurance may come from testing how these areas interact.
That might mean looking at a critical service from end to end, rather than auditing each supporting function separately. It might mean reviewing how a technology change was governed across risk, compliance, data and operations. It might mean testing whether an incident response process captures customer impact, regulatory obligations, supplier dependencies and internal control weaknesses in one joined-up view.
The question is not only whether each function performed its role.
It is whether the organisation managed the risk as a whole.
That is a different type of assurance question, and it is becoming more important as risks become more connected.
It is also where ERM and internal audit should be complementary. ERM should help the organisation build a more connected view of risk. Internal audit should provide independent challenge on whether that connected view is complete, evidence-based and reflected in actual governance and control.
What boards and senior management should ask
Boards and senior management do not need to see every regulatory workstream or control detail.
They do need enough visibility to understand where connected risks may be creating gaps in ownership, evidence or escalation.
A practical set of questions might include:
- Which risks sit across more than one function, framework or committee?
- Where are we relying on several teams to manage one shared outcome?
- Do we have a clear owner for the combined risk, not just the individual components?
- Is ERM helping us understand how risks connect, or simply reporting them by category?
- Are cyber, technology, third-party, data, AI and resilience issues being reported separately or interpreted together?
- Where could a service failure create customer, operational, regulatory and control impacts at the same time?
- What evidence tells us that hand-offs between teams are working?
- Where might everyone assume someone else is responsible?
These questions are deliberately simple.
That is because fragmented risk does not always need a more complicated response. It often needs a clearer view of ownership.
From separate compliance to connected governance
The answer to fragmented risk is not to centralise everything or create a single governance structure that becomes too large to be useful.
Firms still need specialist expertise. Cyber risk, data protection, AI governance, third-party oversight, financial crime and operational resilience all require specific knowledge.
The opportunity is to connect those areas more intelligently.
That means identifying shared dependencies, common controls, cross-cutting obligations and points where several risks affect the same service, customer journey or business decision. It means designing governance around outcomes, not just frameworks. It means making sure that management information helps senior leaders understand the relationship between issues, rather than presenting each one in isolation.
This is where ERM should provide the glue.
The value of ERM is not simply that it gives the organisation a single risk taxonomy, risk appetite statement or reporting structure. Its real value is in helping senior leaders see how risks connect, where they compound and where accountability needs to be made clearer.
Because when a risk crosses boundaries, accountability cannot be allowed to disappear between them.
The firms that manage complexity well will not be those with the most committees, policies or reporting packs. They will be the ones that can see where different risks connect, understand what that means in practice and make ownership clear before a weakness becomes a failure.
Stay up to date with the latest stories from the world of governance, risk, audit and compliance >>>
Sources used to support the article:
IIA’s Risk in Focus 2026
OECD AI Principles





