Spotlight on Women in GRC: Director of Risk’s predictions for enterprise risk management

We’re living in a risk environment that is becoming harder to untangle. BDO’s 2026 Global Risk Landscape survey of 500 C-suite executives found that 80% of business leaders believe the global risk environment is more defined by crisis than ever before.   Meanwhile, Aon’s 2025 Global Risk Management Survey, drawing on nearly 3,000 risk and business…

Esme Dyos Avatar

We’re living in a risk environment that is becoming harder to untangle. BDO’s 2026 Global Risk Landscape survey of 500 C-suite executives found that 80% of business leaders believe the global risk environment is more defined by crisis than ever before.  

Meanwhile, Aon’s 2025 Global Risk Management Survey, drawing on nearly 3,000 risk and business leaders across 63 countries, describes technology, trade, weather, and workforce risks as increasingly convergent rather than isolated.  

How can risk management professionals effectively manage this complex interconnected risk landscape? 

Knowing the frameworks? Understanding controls? Being able to navigate regulation? All important. But for Melanie Barnard, Director of Risk, Conduct and Governance at AXA Health, there is something more fundamental: understanding the business and having the curiosity to ask the question others haven’t. 

In the latest Spotlight on Women in GRC podcast, host Lucy Montague sits down with Melanie, who has spent around 25 years in insurance, working across first-line risk, second-line risk, and within the business itself. Today, she leads AXA Health’s first-line risk function, covering governance, conduct and compliance, non-financial risk, third-party risk management, and risk assurance.  

In this conversation, AXA Health’s Director of Risk shares: 

  • Why risk ownership starts with business acumen 
  • Why GRC needs to speak the language of the business 
  • How asking one extra question can uncover unintended consequences 
  • Why climate risk shows the importance of understanding interconnected risk 
  • Why AI should free risk professionals to deliver more insight, not simply more process 
  • Why diversity in risk leadership is a business and risk issue, not just a representation issue 

Why risk ownership starts with understanding the business 

Risk ownership is something almost every organization wants to improve. Melanie’s team is responsible for ensuring employees outside of the risk department (first line), understand and own their relevant risks effectively. But how do you get stakeholders outside of GRC to care about this alongside doing their day jobs? 

There is a danger in overwhelming with more training, more attestations, more assigned owners, more workflows. 

Melanie starts somewhere else. She leads with empathy and curiosity.  

“I think the biggest thing that anyone can do is firstly understand the business, build your business acumen.” 

Melanie Barnard, Director of Risk, Conduct and Governance, AXA Health  

You can’t expect somebody to own a risk simply because their name appears next to it in a system. They need to understand how that risk relates to what they are trying to achieve and why it matters to the decisions they make. 

For Melanie, the risk professional’s role therefore isn’t always to provide an answer. Sometimes, their greatest contribution is prompting someone else to think differently. 

This approach aligns with Gartner Security and Risk’s speaker, Fadeen Davis, recommending to CISOs and Risk leaders to “optimize for influence by being credible, engaging and persuasive in communication style.”  

Melanie motivates her team to do this by posing a deceptively simple challenge to her team:

“What extra question did you get someone to ask today? Have you helped them understand the unintended consequences?” 

Melanie Barnard, Director of Risk, Conduct and Governance, AXA Health  

Examples could include:  

  • What could this mean for customers?  
  • What could the operational impact be?  
  • Have we considered the financial implications?  
  • Is there an opportunity as well as a threat? 

Those questions move risk management away from being something performed periodically and toward something embedded in everyday decision-making. 

And perhaps that’s a better test of risk maturity. 

A mature risk program shouldn’t be judged solely by how much risk information it produces. It should be judged by whether that information improves the decisions the business makes. 

GRC has a language problem, it’s time to rephrase  

There is another barrier to genuine risk ownership: GRC isn’t always particularly easy to understand. 

Frameworks, taxonomies, control classifications, methodologies, regulatory terminology, and a seemingly endless supply of acronyms all have legitimate purposes. But the language familiar to a risk professional can sound very different to someone whose primary responsibility is sales, HR, procurement, operations, or product development. 

Melanie has seen that gap throughout her career. 

“When we’re talking to people, how do we make that so that they understand?” 

Melanie Barnard, Director of Risk, Conduct and Governance, AXA Health  

She gives the example of looking at a control or process and naturally thinking in terms of preventative and detective controls, while recognizing that many people outside risk have little reason to know what those terms mean. 

The answer isn’t to turn everyone in the organization into a risk specialist. 

GRC needs to get better at speaking business. 

That means using practical examples, storytelling, simpler terminology, and, crucially, connecting risk back to the objectives people already care about. 

Melanie also actively encourages colleagues to speak up:

“If I am using jargon, please shout. Please stop me and say, ‘Mel, you’ve literally gone too technical for me. What do you mean by that?’” 

Melanie Barnard, Director of Risk, Conduct and Governance, AXA Health  

There’s a risk-culture dimension here too. 

Marsh points to communication, workforce engagement, and positive leadership as important elements of safety culture. It also warns that when employees perceive reporting negatively, incidents can be significantly underreported, obscuring an organization’s true risk picture.   

In other words, creating an environment where someone feels comfortable saying “I don’t understand” isn’t trivial. It contributes to the psychological safety needed for people to say “I’m worried about this,” “I think we’re missing something,” or simply, “Have we considered what happens if…?” 

If people need a risk dictionary just to participate in the conversation, perhaps the problem isn’t the business. It’s how GRC is communicating. 

Why risk professionals shouldn’t underestimate climate risk and it’s wider impact  

When asked which emerging risk leaders could still be underestimating, Melanie deliberately doesn’t choose AI. 

She chooses climate risk. 

“I still think the extremes are underestimated… Are we really testing ourselves in terms of some of those scenarios, what that means?” 

Melanie Barnard, Director of Risk, Conduct and Governance, AXA Health  

This isn’t climate risk viewed exclusively through the lens of sustainability reporting or regulation. Melanie points to the potential consequences for infrastructure, operations, people, healthcare equipment, and an organization’s wider third and fourth-party ecosystem.  

The World Economic Forum’s Global Risks Report 2026, based on input from more than 1,300 experts, found that 50% expect a “turbulent” or “stormy” global outlook over the next 2 years, rising to 57% over the next decade. While environmental risks have slipped down the immediate-term agenda, extreme weather, biodiversity loss and ecosystem collapse, and critical change to Earth systems dominate its longer-term outlook.  

And the real challenge may be less about any one of those risks than what they touch. 

Consider the chain: 

Extreme weather → infrastructure → operations → suppliers → customers → strategic objectives. 

A climate event might begin as one category of risk but quickly become a business continuity problem, a third-party problem, an employee problem, a technology problem, and a customer problem. 

That’s where Melanie’s thinking connects strongly with our recent exploration of cascading and interconnected risk. As we argued there, catastrophic outcomes frequently aren’t caused by risks nobody knew existed. They’re caused by known risks combining in ways nobody mapped.  

The World Economic Forum similarly describes global risks as increasing in “scale, interconnectivity and velocity”, with technological, climatic, geostrategic, and demographic forces increasingly converging and amplifying one another.  

Melanie’s experience managing third-party risk brings another layer to the discussion: 

“And fourth parties as well is another area of risk. So have we considered those clauses? Are we setting those expectations because we understand the risk exposure that could bring?” 

Melanie Barnard, Director of Risk, Conduct and Governance, AXA Health  

The question, then, isn’t simply whether climate change appears on the risk register. 

It’s whether the organization has followed that risk far enough through its infrastructure, operations, people, suppliers, and customers to understand what could actually happen. 

Once again, it comes back to the extra question. 

Third-Party Risk Management solution download

AI should mean less process and more thinking for risk teams 

Greater interconnectedness creates another challenge for risk teams: there is simply more to understand. 

More data. More regulation. More dependencies. More emerging risks. More change. 

That’s where technology, and particularly AI, becomes interesting. 

But Melanie’s view of the opportunity isn’t simply about doing the same work faster. 

“I want people to be more insight rather than just process led.” 

Melanie Barnard, Director of Risk, Conduct and Governance, AXA Health  

She talks about giving risk professionals the time to look outward, understand market intelligence, conduct deep dives, examine emerging risks, understand the organization’s strategy, and ask what changing external conditions might mean for the business.  

That’s an important distinction because, despite the volume of conversation around AI, adoption within GRC is still relatively immature. 

The International Compliance Association’s 2025 global survey of 383 GRC practitioners across 87 countries found that just 1.6% of GRC functions described AI as fully integrated into their processes, while 32% said they hadn’t adopted AI for GRC purposes at all. At the same time, 51.3% identified advances in AI and technology as the biggest driver of change in GRC over the next five years.  

“It will allow us to go faster, but it does bring a lot of risk and… new risk class that we need to be aware of as well. But you have to embrace it.” 

Melanie Barnard, Director of Risk, Conduct and Governance, AXA Health  

The opportunity shouldn’t be to add AI on top of already cumbersome GRC. 

Automating a bad process doesn’t make it a good process. It just makes the bad process faster. 

Instead, technology should help remove low-value administration and enable the risk professional to spend more time on the things humans remain particularly good at: curiosity, context, judgment, challenge, relationships, and joining the dots. 

Diversity in risk leadership is a risk issue 

And that brings us to people. 

Melanie speaks candidly in the podcast about confidence, self-limiting beliefs, mentorship, sponsorship, and some of the barriers she encountered during her own career. 

At one point, somebody suggested that progressing to Chief Risk Officer would require an actuarial background, something Melanie doesn’t have. 

Her response challenges an assumption that can stop talented people before they’ve even put themselves forward. 

“I have an amazing team around me… I’m not a specialist in everything… you can still do these things.” 

Melanie Barnard, Director of Risk, Conduct and Governance, AXA Health  

There is an obvious risk to the individual in selling themselves short. They don’t apply. They wait until they satisfy every perceived requirement. They assume somebody with a more conventional background belongs in the room instead. 

But there is also a risk to the organization. 

Melanie deliberately seeks difference when building teams: 

“I do try to recruit people who aren’t like me… because it really challenges me. And actually, it’s expanded my interests over time because I’ve learned new things from people as well.” 

Melanie Barnard, Director of Risk, Conduct and Governance, AXA Health  

That is particularly pertinent in risk. 

If leadership teams continually select people with the same career histories, disciplines, experiences, and ways of thinking, organizations risk creating blind spots inside the very function charged with finding blind spots. 

A 2024 Cambridge University Press study found that diversity in cognitive styles and information sources generally increased cooperation and could improve group outcomes under certain conditions.  

That matters because better risk management depends on challenge. 

Different backgrounds produce different experiences. Different experiences produce different questions. And, as Melanie’s entire conversation demonstrates, sometimes the question nobody else thought to ask is precisely the one the organization needs. 

The future of risk belongs to people asking better questions 

Technology will get better. 

Reporting will get faster. AI will take on more process. Risk data will become more connected and organizations will become increasingly capable of modeling relationships and dependencies that historically sat across multiple systems and spreadsheets. 

But Melanie’s perspective suggests that one of the defining capabilities of tomorrow’s GRC professional may be surprisingly human: curiosity. 

Understand what the business is trying to achieve. 

Speak its language. 

Ask the extra question. 

Follow a risk beyond its obvious first-order impact. 

Create space for different people to challenge assumptions. 

And use technology to create more time for thinking instead of more process. 

Because spotting the next major risk may not require predicting something completely new. 

It may simply require seeing the connection everybody else missed. 

About Melanie Barnard 

Melanie Barnard is Director of Risk, Conduct and Governance at AXA Health, where she leads a first-line risk function covering governance, conduct and compliance, non-financial risk, third-party risk management, and risk assurance. 

With around 25 years of experience in insurance, Melanie has worked across first-line risk, second-line risk, and business roles, with experience at organizations including Zurich, Capita, Hiscox, Direct Line Group, AXA, and Quilter. She describes curiosity, tenacity, problem-solving, and understanding the business as central to her career in risk.  

About Spotlight on Women in GRC 

Spotlight on Women in GRC is a podcast series created to continue the conversations sparked by the Women in GRC Awards and shine a light on professionals shaping governance, risk, and compliance today. Hosted by CoreStream GRC’s Lucy Montague, the series explores career journeys, leadership lessons, and the trends transforming the GRC profession.  

Condensed transcript of the Melanie podcast episode  

Lucy Montague:

Welcome to Spotlight on Women in GRC, a podcast series created to continue the conversations sparked by the Women in GRC Awards 2026. Supported by CoreStream GRC, the series shines a light on the women shaping governance, risk and compliance.

Today I’m joined by BARNARD Melanie, Director of Risk, Conduct and Governance at AXA Health. Melanie, welcome.

Melanie Barnard:

Thank you, Lucy. Delighted to be here.

Career journey

Lucy Montague:

Tell us a little about your role and career journey.

Melanie Barnard:

I’m Director of Risk, Conduct and Governance at AXA Health, where I lead the first-line risk function, covering governance, conduct and compliance, non-financial risk, third-party risk management and risk assurance. Our role is to act as trusted advisors and help the business achieve its strategic objectives.

I’ve spent around 25 years working in insurance across organizations including Zurich, Capita, Hiscox, Direct Line Group and Quilter. My career hasn’t been linear. I’ve worked across first-line risk, second-line risk and operational business roles, which has given me a broad perspective on how risk management supports organizations.

Finding a career in risk

Lucy Montague:

What first attracted you to governance, risk and compliance?

Melanie Barnard:

I began my career handling complaints and investigating issues where things had gone wrong. I was curious, enjoyed problem-solving and liked getting underneath complex situations.

Those qualities led me into risk management, where I found a profession that combined curiosity, investigation and helping organizations make better decisions. That’s what has kept me interested throughout my career.

Improving risk ownership

Lucy Montague:

What’s the most effective thing leaders can do to improve risk ownership?

Melanie Barnard:

It starts with understanding the business.

Risk professionals need strong business acumen and a clear understanding of organizational objectives. When you understand what people are trying to achieve, you can help them ask better questions, consider unintended consequences and think about the impact of their decisions.

Risk ownership isn’t created through policies. It’s created when people understand how risk connects to the outcomes they’re responsible for delivering.

Making risk language accessible

Lucy Montague:

How do you help risk teams communicate effectively with stakeholders who don’t work in risk every day?

Melanie Barnard:

We have to simplify our language.

Risk professionals often use terminology that feels natural to us, but can be confusing for people outside the profession. Storytelling, practical examples and real-life scenarios help make risk concepts easier to understand.

I also encourage people to challenge jargon and ask questions. Creating psychological safety is important because people are far more likely to engage with risk conversations when they feel comfortable admitting what they don’t know.

The most underestimated emerging risk

Lucy Montague:

Which emerging risk do you believe leaders are underestimating?

Melanie Barnard:

While AI continues to dominate conversations, I’d actually point to climate risk.

We’ve seen how extreme weather events can affect infrastructure, operations, suppliers and customers. Organizations need to think more deeply about scenario planning and explore the wider consequences of climate-related disruption.

From third-party risk to operational resilience, there are still areas of climate risk that many organizations haven’t fully considered.

Women in leadership

Lucy Montague:

Why do you think women are still underrepresented in senior GRC leadership positions?

Melanie Barnard:

Confidence plays a major role.

Many women face self-limiting beliefs throughout their careers, and there are still relatively few senior role models in some areas of GRC. Mentorship, sponsorship and professional networks can make a huge difference by helping women build confidence and gain visibility.

When people can see leaders who look and feel like them, it becomes easier to imagine themselves in those positions.

Career growth through sponsorship

Lucy Montague:

What’s helped you progress into senior leadership?

Melanie Barnard:

Mentorship and sponsorship have both been incredibly valuable.

Early in my career, mentors helped me better understand my leadership style and build self-awareness. Sponsors have also been important, opening doors and advocating for opportunities when I’m not in the room.

I’ve learned that feedback, even when it feels uncomfortable, is one of the most powerful tools for personal and professional growth.

Preparing for the future of GRC

Lucy Montague:

What are you and your team focused on right now?

Melanie Barnard:

We’re focused on supporting the business through its next strategic cycle, while ensuring our teams are prepared for emerging risks and opportunities.

AI governance is a major area of focus, alongside climate risk, geopolitical developments and broader market intelligence. We’re investing heavily in upskilling and making sure our teams have the capabilities needed to provide insight, not just process management.

The future of risk management

Lucy Montague:

What will define the next era of GRC?

Melanie Barnard:

Technology and AI will have a significant impact, but the most important capability will still be business understanding.

As technology automates more administrative activity, risk professionals will have greater opportunities to focus on insight, strategic thinking and decision support.

The future belongs to risk professionals who can combine technical knowledge with strong business acumen and curiosity.

Balancing leadership and family

Lucy Montague:

How have you balanced your career with raising a family?

Melanie Barnard:

I don’t think I’ve always got the balance right, and that’s an honest reality for many working parents.

I’ve been a single parent for much of my career, and there have been times when choices had to be made about opportunities, travel and priorities. Having a strong support network has been essential.

What has helped is genuinely enjoying my work. Risk management has always given me opportunities to learn and grow, which has made the challenges easier to navigate.

Advice and inspiration

Lucy Montague:

Are there any books, podcasts or resources that have influenced your career?

Melanie Barnard:

Two books I often recommend are Practical Project Risk Management: The ATOM Methodology and Resilience by Liggy Webb.

I’m also a big fan of The High Performance Podcast. I find it inspiring to hear how successful people have navigated challenges, setbacks and opportunities throughout their careers.

Lucy Montague:

Melanie, thank you so much for joining us.

Melanie Barnard:

Thank you for having me.

Lucy Montague:

And thank you to everyone listening to Spotlight on Women in GRC. Join us next time for another conversation with the women shaping the future of governance, risk and compliance

Frequently asked questions on risk management 

What is risk ownership in risk management?

Risk ownership means giving individuals clear accountability for understanding, monitoring, and responding to risks that could affect their business objectives. Effective risk ownership goes beyond assigning a name to a risk register entry. It requires business leaders to understand how risk connects to the decisions, outcomes, customers, and strategic objectives they are responsible for. 

How can organizations improve risk culture? 

Strong risk culture develops when people across the organization feel able to identify risks, ask questions, challenge assumptions, and raise concerns. Clear communication, psychological safety, leadership behavior, and making risk relevant to people’s everyday objectives can all help. 

Why is business acumen important for risk professionals? 

Business acumen allows risk professionals to understand the organization’s objectives, commercial environment, customers, operations, and strategic priorities. This helps them translate technical risk information into insight that business leaders can actually use. 

What is interconnected or cascading risk? 

Interconnected risk describes how one risk can influence, trigger, or amplify another. A climate event, for example, could affect physical infrastructure, disrupt a supplier, interrupt operations, impact customers, and ultimately threaten strategic objectives. 

Why is climate change a business risk? 

Climate change can create financial, operational, supply chain, infrastructure, workforce, regulatory, and customer risks. This makes it much broader than simply an ESG or sustainability issue.The challenge for GRC leaders is therefore not simply identifying climate risk, but understanding how its effects could cascade through the organization and its third and fourth parties. 

How is AI changing governance, risk, and compliance? 

AI has the potential to automate labor-intensive GRC activities, improve monitoring and reporting, analyze larger volumes of risk information, and help professionals identify patterns and emerging issues faster. But adoption remains relatively early. The bigger opportunity isn’t simply to automate more GRC processes. It’s to use technology to give risk professionals more time for analysis, judgment, challenge, and strategic thinking. 

Why is diversity important in risk management? 

Diversity can bring different professional experiences, information sources, and ways of thinking into risk discussions, helping teams challenge assumptions and consider perspectives that might otherwise be missed. For risk leaders, the important question is whether enough different perspectives are represented to challenge collective blind spots. 

What skills will future GRC professionals need? 

Technical risk knowledge will remain important, but the growth of AI and automation is increasing the value of skills such as business acumen, relationship management, communication, curiosity, judgment, and critical thinking.