top of page

Why Risk Functions Keep Growing Without Feeling Better Resourced

Writer: Julien Haye
Julien Haye
3 days ago
12 min read


Risk and compliance professionals managing growing risk management workload and organisational capacity demands in a financial institution.

Financial institutions have invested heavily in risk management and compliance over the past two decades. Specialist teams have expanded, governance has strengthened, new risk disciplines have emerged and technology has improved the ability to identify, monitor and report risk.


Yet resourcing remains a persistent concern.


The conventional explanation is straightforward: regulatory expectations have increased, risks have become more complex and risk functions need more resources. All three may be true. But they explain only one side of the equation.


The other is the amount of work the organisation now generates to manage risk.

A new business activity can require multiple risk assessments, specialist reviews, controls, evidence, reporting and assurance. An issue can generate remediation, governance and validation. Existing requirements can remain in place as new ones are added. Much of this work is also performed outside formal Risk and Compliance functions.


This creates a different question for financial institutions.

Rather than asking only whether risk functions have sufficient resources, should organisations also be asking what creates the demand for those resources?

That distinction between Risk Resources and Risk Demand is the focus of this article.


Executive Takeaways

For readers scanning rather than reading in full, five insights frame the argument:

  1. Risk management resources cannot be understood through risk headcount alone.

    Risk and compliance activity extends across the organisation. Business teams, control owners, senior management and assurance functions all contribute time to assessments, controls, evidence, governance, reporting and remediation.

  2. Risk exposure and Risk Demand are different.

    Organisations facing similar risks can generate very different levels of risk management workload depending on how regulatory requirements, controls, governance, reporting and assurance are designed.

  3. Legitimate requirements can still create significant cumulative workload.Individual assessments, controls and governance activities may each serve a valid purpose. Resource pressure emerges when multiple requirements converge around the same business activity and their combined organisational impact is not visible.

  4. Technology improves productivity but does not automatically reduce Risk Demand.

    AI and automation can make assessments, testing, evidence collection and reporting faster. They do not determine whether an activity remains necessary, proportionate or duplicated elsewhere.

  5. Better risk management productivity starts with understanding demand.

    Before adding resources or automating existing processes, organisations need to understand what risk activity exists, why it exists, where requirements overlap and whether the effort remains proportionate to the outcomes it supports.


Risk Management Is Consuming More And More Organisational Resources


The pressure on risk and compliance functions is not simply a perception. There is growing evidence that the organisational resource devoted to regulatory compliance has increased substantially.


Research by the Bank Policy Institute provides one of the clearest illustrations. Across the banks surveyed, employee hours dedicated to complying with financial regulation and supervisory requirements increased by 61% between 2016 and 2023. Total employee hours increased by only 20% over the same period. The demands also extended well beyond specialist compliance teams. By 2023, respondents estimated that regulatory and supervisory compliance consumed 42% of C-suite time and 43% of board time, compared with 24% and 27% respectively in 2016.


UK research points in the same direction. TheCityUK and PwC estimate that regulatory compliance costs the UK financial services sector approximately £33.9 billion annually, equivalent to more than 13% of average operating costs. Among the compliance leaders surveyed, 84% reported that their costs had increased or significantly increased during the previous five years.


Perhaps the more interesting finding is where those costs arise. Costs typically measured directly by firms, including the compliance function itself, regulatory change and enforcement, represented an estimated 2.6% of operating costs.

The end-to-end cost of meeting compliance requirements across the organisation was estimated to be more than four times greater. PwC also found that many firms do not systematically measure these wider costs.


That does not mean every control activity performed outside Risk or Compliance represents an additional regulatory burden. Much of running a financial institution involves managing risk. Operations teams reconcile transactions, investigate exceptions, approve payments, validate data and supervise processes because these activities are necessary to run the business safely and effectively. Many would exist irrespective of a specific regulatory requirement.


The distinction becomes harder because business, risk and regulatory requirements frequently meet in the same activity. A control may protect customers, reduce operational losses and satisfy a regulatory obligation at the same time. That same control may also require documentation, testing, evidence, reporting and assurance through the organisation's risk and governance frameworks.


The important question cannot simply be how many people perform risk or control activities. It is whether organisations understand what is driving that activity, where different requirements overlap, and how much additional work is created by the way those requirements are governed, evidenced and assured.


The Missing Denominator


Financial institutions measure risk extensively. They track headcount and budgets, regulatory obligations, controls, incidents, issues and actions, assurance activity, losses and exposures. What is often less visible is how much work these requirements generate across the organisation and, importantly, why that work exists.


Consider a daily reconciliation. It may be a control, but it is also part of running the business properly. A regulatory requirement may reinforce the need for it, but the requirement itself does not determine every aspect of how the organisation responds. It must be interpreted and translated into policies, controls, evidence, reporting and governance. The organisation's risk framework may add further requirements for assessment, documentation and monitoring.

An oversight function may test the control, Internal Audit may provide assurance over it, and a weakness may generate an issue and remediation activity.


This distinction is important when understanding where Risk Demand originates. External regulation can create substantial demand, but so can the way an organisation interprets and implements regulatory expectations. Two organisations subject to the same requirement may therefore generate different levels of activity around it, depending on the controls, evidence, governance and assurance they put in place.


Understanding Risk Demand does not mean weakening regulatory requirements in pursuit of efficiency. It means being able to distinguish the underlying regulatory expectation from the organisational activity created to implement and demonstrate compliance with it, and whether that activity remains proportionate.


These activities all relate to the same underlying risk, but they represent different sources of organisational demand.


This is the distinction behind Risk Demand: the total organisational activity required to manage risk, together with the additional activity generated by how that risk is governed, evidenced and assured.


Risk exposure and Risk Demand are therefore not the same thing. Two organisations facing similar risks could require very different levels of organisational effort depending on how their processes, regulatory obligations, controls, governance and assurance arrangements are designed.


Understanding that difference matters. Without it, organisations can see how much risk activity they have without necessarily understanding what is creating it.


Infographic showing four sources of risk demand in financial institutions: business requirements, regulatory requirements, risk framework requirements, and assurance and oversight. It illustrates how these overlapping drivers can create additional assessment, evidence, reporting and assurance activity, while distinguishing core business activity from additional governance demands.

How a Business Decision Creates Risk Management Demand


Risk management workload does not originate only within the risk function. It is also generated by business decisions that require different forms of risk assessment, regulatory review, control and assurance.


Consider the launch of a new digital financial services product. Depending on the proposition, a single product launch may require:

  • Compliance and conduct risk: regulatory requirements, customer outcomes and Consumer Duty considerations

  • Financial crime risk: AML, fraud and customer due diligence requirements

  • Data and privacy risk: personal data use, retention and data protection requirements

  • Cyber risk: security requirements, access controls and technology vulnerabilities

  • Third-party risk: due diligence and oversight where external providers support the service

  • Operational resilience: dependencies, important business services and disruption considerations

  • Model and AI risk: additional governance where automated models or artificial intelligence support decisions


These reviews are not unnecessary bureaucracy. Each can identify a different exposure and improve the quality of the original business decision. But from the perspective of the business, they converge around the same product, often drawing on the same people, information, processes and evidence.


The workload can then extend beyond the initial assessments. A review may identify a need for new controls. Those controls require owners, documentation and evidence. Governance may require approval or formal risk acceptance. Implementation creates monitoring and risk reporting requirements. Control testing or assurance may subsequently identify weaknesses requiring issues, actions and remediation. The resulting activity can involve teams across the first, second and third lines.


This creates three forms of layering in Risk Demand.

  1. Horizontal layering occurs when different specialist disciplines apply their respective requirements to the same business activity.

  2. Vertical layering occurs when those requirements generate further controls, evidence, monitoring, governance, testing, assurance and remediation.

  3. Temporal layering occurs as new requirements are introduced over time while earlier controls, reporting, governance or assurance remain in place.


The three can also interact. A new regulatory requirement, incident or business change may trigger several specialist reviews, each of which can create further activity while requirements established previously continue. The resulting workload is therefore shaped not only by the number of requirements, but by how they combine across disciplines, propagate through the risk management process and accumulate over time.


This pattern is not unique to product launches. Third-party relationships, technology change, data use, customer journeys and other business activities can attract requirements from multiple disciplines and functions, with further activity generated as those requirements move through governance, control and assurance processes.


This is what makes Risk Demand different from simply counting risk professionals or controls. The important question is not whether each activity has a legitimate purpose. It is whether the organisation understands the cumulative workload created when multiple legitimate risk and regulatory requirements converge and layer around the same business activity, where information or evidence could serve multiple purposes, and where requirements have become duplicative or remain in place after their original purpose has changed.


Infographic showing how launching a new digital customer proposition can generate Risk Demand across a financial institution, from specialist reviews covering compliance, financial crime, data privacy, cybersecurity, third-party risk, operational resilience and AI risk, through governance, controls and documentation to ongoing monitoring, testing, assurance and remediation.

The Organisational Cost of Risk Management Extends Beyond the Risk Function


Risk management is delivered across the organisation, not by the risk function alone.


An RCSA requires business teams to assess risks and controls. A control assessment requires owners to provide evidence. An issue investigation may involve Operations, Technology, Finance, Product or Legal. Remediation draws on many of the same teams, while risk reporting and governance require input from senior management, executives and board committees.


This wider contribution is significant. TheCityUK and PwC estimated that directly measured compliance costs, including Compliance function costs, regulatory change and enforcement, represented around 2.6% of operating costs. When the wider cost of meeting regulatory requirements across the organisation was included, the estimate was more than four times greater.


This points to an important distinction between visible and distributed risk costs.


Visible risk costs include dedicated Risk and Compliance people, systems and budgets. Distributed risk costs arise when people elsewhere in the organisation spend time supporting risk assessments, regulatory requirements, governance, evidence, testing and remediation alongside their primary responsibilities.


Not all of that activity is additional or avoidable. Much of it is necessary to manage the business effectively.


But it means risk headcount alone tells us very little about the total organisational resource involved in managing risk.


How Controls, Issues and Remediation Increase Risk Management Workload


Risk management activity does not end when a risk has been identified and controlled. Managing the risk creates ongoing requirements of its own.


A new control needs an owner and may require documentation, evidence, monitoring and testing. Control weaknesses can generate issues. Issues require root-cause analysis, remediation actions, governance and progress reporting. Closure may require independent validation or assurance before the issue can be formally resolved.


Each step can be entirely appropriate. Controls need to remain effective, material weaknesses need to be addressed, and organisations need evidence that remediation has worked.


The workload can accumulate because resolving one requirement does not necessarily remove the activity created around it. A new control may remain subject to monitoring and testing after the original issue has been addressed. Remediation may introduce further controls. A significant incident may result in enhanced reporting or assurance that continues after the immediate problem has been resolved.


Over time, organisations can therefore accumulate layers of controls, evidence, testing, reporting and assurance. Each may have originated from a legitimate risk management need, but the conditions that justified the activity may have changed, other controls may now address the same risk, or subsequent requirements may have created overlap.


Risk frameworks are generally effective at identifying when additional activity is required. They can be less effective at identifying when existing controls, reporting, governance or assurance should be simplified, consolidated or retired.


Without that discipline, today's response to risk becomes part of tomorrow's risk management workload.


Case Study: When a 1.5 Line Review Reveals Hidden Risk Demand


Consider an organisation reviewing its risk operating model to determine the appropriate scope of a 1.5 Line risk function. The starting question appears relatively simple: which risk and control activities should sit within the function, what capabilities does it require, and how should responsibilities be divided between the business and the Second Line?


Answering that question can expose a more fundamental challenge. Risk and control activity is often distributed much more widely across the business than the formal operating model suggests. Employees outside dedicated risk roles may perform controls, produce evidence, support risk assessments, investigate exceptions and contribute to governance and remediation as part of their day-to-day responsibilities.


This makes the true scale of risk activity difficult to establish. Counting people within Risk, Compliance or a 1.5 Line can understate the organisational resource involved. Yet counting everyone performing a control can overstate it. Many of those activities are integral to running the underlying business processes safely and effectively rather than additional risk management overhead.


The question therefore shifts from who performs risk activity to why the activity exists. Some activities are inherent in running the business. Others reflect regulatory requirements. Further activity arises from internal risk frameworks, documentation, evidence, governance, testing and assurance. In many cases, the same activity serves several purposes simultaneously.


Defining the 1.5 Line around the existing organisational structure can solve the wrong problem. Without first understanding the purpose and ownership of existing activity, redesign may simply redistribute workload between teams rather than address what is generating it. Activities that belong within day-to-day business processes may migrate into a specialist function, while responsibilities intended to support the First Line can begin to overlap with independent Second Line oversight.


Understanding the activity already taking place, what is driving it and where responsibilities overlap therefore needs to precede decisions about where that activity should sit. What appears to be a question about the size and scope of a 1.5 Line function can become a question about Risk Demand across the organisation.


The difficulty of getting that answer is itself significant. If organisations cannot readily see the risk management activity embedded across their business, they may struggle to determine whether resource pressure requires more resources, a different allocation of responsibilities or a reduction in unnecessary demand.


How to Improve Risk Management Productivity Without Adding More Work


Technology, automation and AI can improve risk management productivity. They can reduce manual data collection, accelerate control testing, support regulatory analysis, streamline reporting and make large volumes of risk information easier to analyse.


But faster execution does not necessarily reduce Risk Demand.


A risk report may take minutes rather than hours to produce, while still serving no clear decision. Control evidence can be collected automatically, while several teams continue to request similar evidence for different purposes. AI can accelerate a risk assessment without addressing overlap with other assessments covering the same business activity.


Before focusing on how quickly an activity can be performed, organisations therefore need to understand the activity itself. Four questions matter:

  • Purpose: What business, regulatory, risk or assurance need does the activity serve?

  • Proportionality: Is the effort involved proportionate to the risk, obligation or decision it supports?

  • Overlap: Are different functions requesting similar assessments, information or evidence?

  • Automation: Where the activity remains necessary and well designed, can technology reduce the effort required?


This distinction matters. Technology can reduce the cost of performing individual risk activities. It does not necessarily address why those activities exist, how they interact or whether the cumulative workload remains proportionate.


The productivity challenge is therefore broader than doing the same risk management work with fewer resources. It is about reducing unnecessary demand while preserving the business, regulatory and risk outcomes that the activity is intended to deliver.


Doing unnecessary work faster improves efficiency. It does not improve effectiveness.


Five Questions Board Directors Should Ask About Risk Management Resource


1. Do we understand how much organisational resource risk management actually consumes?

Risk and compliance headcount captures only part of the picture. Boards should understand how much time is also being committed by business teams, control owners, executives and assurance functions to risk assessments, controls, evidence, reporting, governance and remediation.


2. Do we know what is driving growth in our risk management workload?

Increasing workload can arise from business complexity, regulatory requirements, internal risk frameworks, assurance expectations or a combination of these. Directors should seek visibility of the principal sources of demand rather than assuming resource pressure is primarily a resourcing problem.


3. Where are different risk, regulatory and assurance requirements creating overlapping activity?

Several functions may legitimately need information about the same business activity. Boards should ask whether assessments, evidence requests, reporting and assurance are sufficiently coordinated to avoid unnecessary duplication while preserving effective challenge and independence.


4. When we introduce new risk requirements, what existing activity stops or changes?

Incidents, regulatory developments and control weaknesses frequently result in additional controls, reporting or oversight. Directors should understand whether governance also provides a mechanism for simplifying, consolidating or retiring requirements that are no longer proportionate or necessary.


5. Are we using technology to improve risk management effectiveness or simply to process existing workload faster?

AI and automation can materially reduce manual effort, but technology can also make inefficient processes cheaper to operate without addressing their underlying design. Boards should ask whether transformation is reducing unnecessary Risk Demand while preserving the business, regulatory and risk outcomes that matter.


Conclusion: From Risk Resources to Risk Demand


Persistent resource pressure in risk management does not automatically mean that financial institutions need more risk professionals. Nor does the answer lie in simply removing controls, reducing oversight or automating more activity.

The starting point is understanding what is creating the workload.


Some risk and control activity is inherent in running a financial institution safely. Some is required by regulation. Some is generated by the organisation's own risk frameworks, governance and assurance arrangements. Often, the same activity serves several of these purposes at once.


That makes the resourcing question more complex than risk headcount and budgets suggest.


Senior leaders need visibility over both sides of the equation: Risk Resources, the people, technology and resources available to manage risk, and Risk Demand, the organisational activity generated by how risks and regulatory requirements are managed, governed, evidenced and assured.


The objective is not simply to reduce Risk Demand. It is to understand its sources, determine where the effort creates value and identify where requirements have become duplicative, disproportionate or disconnected from the decisions they were intended to support.


The next stage of risk management effectiveness may depend less on adding resource and more on understanding what creates the demand for that resource in the first place.

 
 
bottom of page