Risk leaders do not need more information. They need more of the right context.
That was one of the clearest themes we took from the 2026, North American, Gartner’s Enterprise Risk, Audit and Compliance Conference. Across sessions the conversation repeatedly came back to a bigger question: how can GRC help organizations make better decisions and achieve what they set out to do?
Risk teams have spent years improving registers, reporting, controls and frameworks. Those capabilities remain important, but the pace of business change is testing whether traditional approaches can turn specialist risk expertise into action quickly enough.
For us, that resonated strongly with an objective-centric view of GRC: organizations do not exist to manage risks. They exist to achieve objectives. Risk management creates the most value when it helps people understand what could prevent those objectives, what must go right to deliver them, and what decisions need to be made now.
3 key lessons from Gartner brought that shift into particularly sharp focus.
1. The future of risk is about creating better decision-makers
Gartner’s opening keynote, “Co-Managing Risk: How Risk Leaders and AI Partner to Transform Business Risk Ownership,” with Tegan Gebert VP advisor at Gartner, and Nancy Queally, Managing VP at Gartner, set a clear challenge for risk functions. Specialist resources cannot scale at the same rate as business change. If every meaningful decision depends on a risk expert being in the room, risk expertise itself becomes a constraint.
The ambition discussed in the session was much bigger: help the organization “make 1,000 business decisions safely.”
In other words, scale risk know-how so business leaders can understand what risks to avoid, which risks may be worth taking and when a change in context should change a decision. On top of this we need to shift individual siloes to work together, risk and audit should be interconnected, expand the partnership to improve productivity and to scale how we help business leaders become better risk owners.
Only 33% of business leaders can translate insight into concrete actions, according to a statistic shared in the Gartner keynote. The session’s answer was simple: “Guided application is key.”
This is an important distinction for GRC leaders. Insight does not automatically create capability. A dashboard may tell a leader that exposure has increased, but does it explain what that means for the objective they own? Does it help them understand the trade-off? Does it show whether action is needed, and where?
The goal, therefore, is better risk-informed decision-making across the business, not just achieving green tiles on your risk dashboard.
Particularly with 64% boards agreeing that organizations should take on greater risk.
That changes the role of the risk function from being primarily a producer of risk information to being an enabler of better judgment. It also changes how GRC information needs to be structured.
A risk rarely has meaning in isolation. Its significance depends on the objective, outcome or obligation it could affect, the organization’s appetite, the controls and dependencies around it, and the consequences of action or inaction.
2. Start with the objective, not the risk, process or technology
A separate Gartner session on AI by Eren Fry Sr Director Analyst at Gartner, made the same point from a very different direction.
In “No Plan, No Payoff: AI Business Impact Demands a Clear Strategy”, they predicted, by 2030 AI will be consistently used to address strategic priorities around process efficiency and quality, risk coverage.
However, Gartner highlighted that we’re not there today, with common ways AI plans go wrong: no link to department outcomes, no measurement of results, weak prioritization and too much emphasis on technical details.
The reframing offered in the session was telling. Rather than asking, “How do we use AI in audit?”, ask: “How can AI enable achievement of department strategic objectives?”
That is useful advice about AI, but it is also a useful principle for GRC more broadly: Technology is the enabler. The business objective is the starting point.
Consider how the same shift changes familiar GRC questions:
- Instead of “What risks do we have?”, ask “What are we trying to achieve, and what uncertainty could affect it?”
- Instead of “What controls do we have?”, ask “What must be true for this objective to succeed, and where do we need confidence?”
- Instead of “Where can we use AI?”, ask “What outcome are we trying to improve, and where can AI add value without weakening oversight?”
Gartner’s AI session also emphasized defining the outcome and vision first, then prioritizing use cases based on value and feasibility.
The principle is straightforward: begin with the outcome you need, then determine which capabilities, technology, controls and assurance will help you achieve it.
This is where objective-centric risk management becomes more than a change in terminology. It creates a common business context for risk, controls, resilience, assurance, performance and technology decisions. Instead of each discipline optimizing its own process, they can organize around the outcome the organization actually cares about.

3. Embedding risk into strategic planning for earlier action
The strongest evidence at the conference came from practitioners describing what changed when enterprise risk management became part of strategic planning.
In the executive story panel, “How to Successfully Integrate ERM into Strategy,” Albert Abbey (Senior VP Head of ERM at Vystar Credit Union), Darryl Frazier (Deputy for Programs & Analysis at US Department of Commerce), and Deidre Melton (CRO at Florida A&M university) discussed the practical work required and the reward achieve when bringing risk and strategy together.
The changes they described were not about building a bigger risk register. They were about changing when and how risk expertise reached the business. Examples included:
- Bringing the CRO into strategic planning
- Conducting industry and organizational risk scans
- Monitoring emerging trends
- Holding quarterly risk check-ins on the strategic planning to see where to adapt/pivot
- Using continuous workflows
- Giving leaders access to more timely risk information via intuitive dashboards
Just as importantly, the panel emphasized culture and language. Risk teams need to communicate in business terms and operate more like internal consultants than risk administrators. That makes risk relevant to the decision in front of the leader, rather than an adjacent process they have to satisfy.
From reporting risk to changing outcomes, the benefits of objective-centric risk management
The practical benefits described by the panel are what make this shift worth paying attention to.
- Earlier action: emerging issues can be identified and addressed before their effect becomes more significant.
- Greater strategic adaptability: regular risk check-ins can inform when plans need to change rather than waiting for the next annual cycle.
- Better leadership context: decision-makers receive risk information against the strategy and business environment they are managing.
- More proactive mitigation: one panelist described tracking significant federal regulatory changes early, operationalizing the mitigation plan early and limiting the resulting impact.
That last example is particularly important. It demonstrates the difference between recording risk and using risk intelligence to influence an outcome.
This is what integrated ERM can look like when it is connected to strategy. The value is not the risk assessment itself. The value is what the organization is able to do differently because of it.
What should GRC leaders do now based on Gartner’s insights?
If Gartner’s direction of travel is right, its time to examine whether your current GRC model gives the business enough context to make good decisions at the pace required.
5 questions are a useful place to start:
- Can leadership see which risks could materially affect our most important strategic objectives?
- Can we show what must go right to achieve those objectives, not only what could go wrong?
- Are relevant risk insights reaching decision-makers while there is still time to act?
- Are risk, controls, assurance, resilience and performance connected around business outcomes, or still managed as separate activities?
- Are we helping business leaders become better risk owners, or simply giving them more risk information?
For many enterprises, the underlying data already exists. The challenge is connecting it in a way that reflects how decisions are actually made.
Putting objectives at the center of GRC
These Gartner insights and takeaways resonated with us because they reflect the problem CoreStream GRC and BRAVE have been exploring through Objectives@Risk™: what changes when the organization’s objectives, rather than the mechanics of risk management, become the organizing principle for governance?
Objectives@Risk™ begins with objectives and essential outcomes, then connects them with critical obligations, risks and risk appetite, scenarios, dependencies, controls, assurance, response capabilities and performance outcomes. The aim is to give leaders context not just on what could go wrong, but on what must go right.
BRAVE brings the objective-centric governance methodology and board-level practitioner perspective. CoreStream GRC provides the configurable technology to operationalize those connections through data, workflows, dashboards and integrated governance processes.
But the bigger point from Gartner is not about any one methodology or platform. It is that risk management needs to help organizations act.
Connecting objectives, risk, controls, assurance, performance and decisions is what turns GRC from an administrative process into a business capability.
“The future of GRC is not about managing more risk. It is about helping the organization achieve its objectives in the face of risk.”
Nancy Queally, Managing VP at Gartner
Ready to put objectives at the center of your risk program, and scale your expert know-how?
Explore how Objectives@Risk™ Powered by CoreStream GRC connects business objectives, risk, resilience and governance to support more confident decision-making.
Frequently asked questions for strategic enterprise risk management
Objective-centric GRC is an approach that aligns governance, risk, compliance, controls, and assurance activities to business objectives. Instead of managing risks as separate activities, organizations connect risk information directly to strategic goals, helping leaders understand what could impact success and what actions are needed to achieve desired outcomes.
Risk leaders can improve risk-informed decision making by providing business context rather than simply reporting risk data. This includes connecting risks, controls, risk appetite, performance metrics, and strategic objectives so decision makers can evaluate trade-offs, understand potential impacts, and act with greater confidence.
Integrating enterprise risk management with strategy helps organizations identify emerging risks earlier, adapt more quickly to changing conditions, and make better strategic decisions. When risk management is embedded in planning and execution, leaders gain clearer visibility into threats, opportunities, dependencies, and potential obstacles to achieving objectives.
AI can help GRC teams improve risk identification, monitoring, reporting, and decision support. When implemented with appropriate governance and oversight, AI can scale risk expertise across the organization, provide more timely insights, and help business leaders make informed decisions while maintaining compliance and managing risk effectively.


