Introduction: why #RISK Europe 2026 should be on every risk leader’s radar
Risk is moving faster, crossing more business functions and creating pressure than ever before. Cyber risk now touches third-party oversight. Operational resilience depends on supplier visibility. AI governance is becoming a compliance, security and board reporting issue.
This means risk leaders and their teams have a lot to stay informed and aware of, conferences like #RISK Expo Europe are a chance to bring together different sectors, and to help inspire key actions that can be implemented the next day.
“Coming together is a beginning, staying together is progress, and working together is success.”
Henry Ford
What is #RISK Expo Europe 2026?
#RISK Expo Europe 2026 is Europe’s leading Risk, GRC, Security and RegTech Expo.
- Date: 10-11 November 2026
- Location: ExCeL London
- 6,000+ attendees
- 300+ speakers
- 100+ exhibitors and partners
- 10+ workshops, breakout sessions and live demos.
The scale of the event matters. It brings together risk, security, resilience, GRC, audit, compliance and financial crime leaders in one place, creating space for attendees to move from thought leadership to live solution conversations, practical demos and meaningful networking.
For CoreStream GRC, the value of #RISK Europe is not just visibility. It is the chance to hear directly from the people dealing with risk and compliance every day.
“For me it’s really important to be at #RISK Europe because I want to hear what the struggles, the trials, the pain points and the ambitions of all the delegates that come here are.”
Lionel Matsuya, Head of Client Solution Design, CoreStream GRC
That is what makes #RISK Expo Europe useful. It brings the market together in one room, allowing risk leaders to compare challenges, test ideas, explore new solutions and understand where GRC is heading next.
What are the 5 dedicated content stages at #RISK Expo Europe 2026?
#RISK Expo Europe 2026 is built around 5 dedicated content stages, each tackling a different angle of today’s risk landscape. That structure matters because it reflects how risk now operates inside large organizations.
Information Security Stage: why security risk can no longer sit alone
The Information Security Stage will focus on AI, cloud security, ransomware, data protection and the human element of security culture.
These themes show why security risk cannot sit separately from controls, third-party oversight, incident management and enterprise reporting. As AI and cloud technologies create new opportunities and new exposures, organizations need clearer ways to connect security activity to wider governance and risk management.
BFSI Stage: why boards need clearer risk data
The BFSI Stage will focus on banking, financial services and insurance, with sessions covering operational resilience, board-level risk reporting, ESG and climate-related risk.
For regulated firms, the pressure is not just to manage risk, but to explain it clearly. Boards do not need bigger reporting packs. They need sharper risk data, clearer ownership and a better view of where action is needed.
We recently spoke to a Senior Risk Officer at a European bank,
“Geopolitical risk, it’s not a risk type in itself. It surfaces in multiple areas and impacts the various different risk types. And it’s how do you build all that in.”
Rita Parmar, a Senior Risk Officer at UK Bank
Protective Security Stage: why physical, personnel and cyber risk are converging
The Protective Security Stage will explore the convergence of physical, personnel and cyber risks, including identity management, biometric perimeters, insider threats and behavioral analytics.
This is another example of risk overlap in practice. Identity, access, people risk and digital exposure are increasingly connected, which means they need to be managed as part of a wider risk and control environment.
GRC Stage: why tick-box compliance is losing ground
The GRC Stage will focus on moving from “tick-box” compliance to joined-up, risk-led governance. With themes including unified GRC platforms, AI-enabled GRC and the regulatory burden in an AI-driven world.
This stage aligns closely with CoreStream GRC’s philosophy that technology should be an enabler, not a barrier. GRC should help teams make better decisions, reduce friction and give leaders confidence in the information they are using.
“Value-based GRC empowers an organization to achieve the right objectives with confidence.”
Paul Cadwallader, GRC Strategy Director
Third-Party & Supply Chain Stage: why supplier risk needs continuous oversight
The Third-Party & Supply Chain Stage will focus on DORA, NIS2, software supply chain attacks, end-to-end resilience and N-th party risk.
This reflects a wider shift in third-party risk management. One-off questionnaires are no longer enough for critical suppliers. Organizations need continuous oversight, clearer supplier visibility, stronger action tracking and reporting that shows how third-party risk is changing over time.
What did we learn from #RISK London 2024 and #RISK Europe 2025?
What did we learn from #RISK London 2024?
The key themes from #RISK London 2024 were clear: humanizing GRC, building a risk-based compliance culture and using technology for smarter decision-making. The conversation was not just about risk frameworks or compliance requirements. It was about making GRC easier for the wider business to understand, engage with and act on.
That matters because GRC is still too often seen as a blocker by people outside risk and compliance teams. As Eoin Fahy, Security and Compliance Specialist at Microsoft UK, put it:
“Non-GRC professionals see risk as negative and filled with red tape, you need to change this mindset.”
Eoin Fahy, Microsoft UK, #RISK Europe 2025
That same theme carried through the wider discussion. Victoria Brasier, Director of Information Management at Sky, connected risk understanding directly to business performance:
“If you understand your risks, you’re much more likely to achieve your planned objectives.”
Victoria Brasier, Sky, #RISK Europe 2025
For CoreStream GRC, that is still one of the most important lessons from 2024. GRC technology only works when people can use it, understand it and see how it helps them make better decisions.
What did we learn from #RISK Europe 2025?
By #RISK Europe 2025, the conversation had moved from awareness to execution. The central message was simple: organizations cannot keep pace with today’s risks using yesterday’s systems.
Across the sessions and conversations at the CoreStream GRC stand, the same pain points kept appearing: clunky systems, disconnected workflows, rising complexity and platforms that were not built for the pace risk teams now operate at. Leaders were not just asking for more technology. They were asking for technology that works around real people, real processes and real business pressure.
The 2025 discussions also made clear what better looks like: intuitive user experience, connected systems, real-time intelligence and technology that flexes to how teams actually work.
As Gayle Sparkes, Director of Operational Resilience at NatWest, said:
“We need to reinvent the processes we created decades ago.”
AI was also a major theme, but the message was grounded. It was not about replacing judgment. It was about using AI inside the right foundations.
Michael Rasmussen, Founder of GRC 20/20 Research, captured the risk of backward-looking GRC clearly:
“If you are always looking back, you crash.”
The lesson for 2026 is clear. AI will only create value when it sits inside strong governance, connected data, clear ownership and human oversight.
What do we expect risk leaders to be talking about at #RISK Europe 2026?
Prediction 1: AI governance moves from discussion to evidence
At #RISK Europe 2026, AI governance is likely to move from “what can AI do?” to “how do we govern, evidence and control it?” This is already visible in the market.
ISACA’s 2026 AI Pulse Poll says AI adoption is accelerating faster than organizational readiness, with persistent gaps in governance, training and risk management. The same research highlights that many organizations still lack clear controls, tested response plans and measurable ROI.
That gap matters for GRC teams. AI governance cannot sit in a standalone policy document. It needs to connect into risk registers, controls, policies, third-party oversight, audit evidence and reporting. If an organization cannot show who owns AI risk, what controls exist and how decisions are reviewed, then governance remains theoretical.
Prediction 2: Third-party risk becomes more continuous
Third-party risk is also set to stay high on the agenda. Annual supplier assessments are no longer enough for critical third parties, especially when supplier risk can become cyber risk, operational resilience risk or regulatory risk overnight.
The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 65% of large companies by revenue identify third-party and supply chain vulnerabilities as their greatest challenge, up from 54% in 2025. That is a clear signal that supplier oversight is moving from periodic review to continuous risk management.
For risk teams, this means lifecycle oversight, supplier criticality, action tracking, evidence and live reporting. Third-party risk management needs to show not only that a supplier was assessed, but how that risk is being monitored and managed over time.
Prediction 3: Board reporting gets sharper
Boards need clearer answers, not more data. This is not a new issue, but it is becoming more urgent as risk information grows across cyber, AI, third parties, operational resilience and compliance.
At #RISK London 2024, Samantha Smith, Head of Data Compliance at Merlin Entertainments, put it plainly:
“The board cares about one thing, risk. They want to know where the holes are and how we plan to fix them.”
That quote still captures the challenge. Boards do not need every detail from every system. They need risk information that is clear, current and tied to business objectives. The focus for 2026 will be sharper reporting: what has changed, what matters, who owns it and what decision is needed.
Prediction 4: Compliance culture becomes a business-enablement issue
Risk and compliance teams are also moving away from “no” and “checklist” mindsets. The #RISK Expo Europe 2026 agenda explicitly frames the event as a place where leaders can shift from a “no” or “checklist” mindset to becoming trusted advisors and business enablers.
That is not just event language. It reflects a real pressure inside organizations. PwC’s Global Compliance Survey 2025 found that 85% of respondents feel compliance requirements have become more complex in the last 3 years, while nearly 90% said the breadth of their compliance responsibilities has increased. When complexity rises, compliance teams cannot rely on more manual process and more friction.
One previous #RISK attendee put the shift clearly:
“One message that really stuck with me was the importance of being enablers, not blockers, shifting away from the ‘no’ and ‘checklist’ mindset.”
Compliance Decision Maker, Insights from Previous Attendees
Compliance culture in 2026 will need to be practical, risk-led and business-aware. GRC should help the business move safely, not block progress.
Community event: join CoreStream GRC after day 1
After day 1 of #RISK Expo Europe 2026, CoreStream GRC will host an exclusive community event. This will be a smaller, more relaxed space to step away from ExCeL London, decompress after a packed day, and continue the conversation with risk peers, clients, partners and the CoreStream GRC team over good wine and good company.
Event details
- Event: CoreStream GRC community event.
- Date: Tuesday 10 November 2026.
- Time: 6:00 pm.
- Location: Roka Canary Wharf
The event is designed for the same reason CoreStream GRC attends #RISK Europe in the first place: to keep listening, learning and challenging how GRC works in practice. The conversations around connected GRC, better reporting, AI governance, third-party resilience and practical risk management do not stop when the exhibition floor closes.
This community event creates space for more open discussion about what risk and compliance leaders are seeing, what is working, and where the market needs to go next.
“Thank you again for last night. Great food and drink – and I had some very engaging conversations with other professionals in the field. Very much appreciated.”
Conclusion: risk is everyone’s business, but it needs connected ownership
#RISK Expo Europe 2026 is built around a simple idea: “Risk. It’s everyone’s business.” That message is right. But if risk is everyone’s business, then ownership, evidence and reporting need to be connected too.
That is the direction GRC is moving in. The conversation is shifting from checklist activity to business enablement, from static reporting to live insight, and from disconnected processes to risk-led governance that helps organizations act with confidence.
The past 2 years show that shift clearly. 2024 was about humanizing GRC and making risk easier for the wider business to understand. 2025 was about connected technology, better user experience and execution. In 2026, the conversation looks set to move again, this time toward evidence, resilience, AI governance, third-party oversight and risk-led business enablement.
That is the conversation CoreStream GRC is bringing to #RISK Expo Europe 2026. Meet us at ExCeL London on 10-11 November 2026, and join us after day 1 at Roka Canary Wharf to continue the discussion with the CoreStream GRC community.
Frequently asked questions for #RISK Expo Europe 2026
#RISK Expo Europe 2026 is Europe’s leading event for risk, governance, compliance, security and RegTech professionals. It is designed for risk leaders, compliance officers, GRC specialists, security professionals, auditors and financial crime experts who want to stay ahead of emerging risks, regulatory changes and technology trends shaping the industry.
#RISK Expo Europe brings together thousands of professionals across security, GRC, operational resilience and third-party risk, creating a unique opportunity to learn, network and explore practical solutions. As risks become more interconnected, spanning AI, cyber security and supply chains, leaders need events like this to gain insights, share challenges and identify strategies they can implement immediately.
The event covers key areas such as AI governance, cyber security, operational resilience, third-party risk management, compliance transformation and board-level reporting. With five dedicated content stages, attendees can explore everything from information security and BFSI risk to GRC innovation and supply chain resilience.
Attending #RISK Expo Europe allows risk and compliance leaders to gain actionable insights, see live demonstrations of GRC technologies, connect with industry peers and better understand how to manage evolving risks. It also provides access to workshops, expert speakers and networking opportunities that support stronger decision-making and more effective risk management strategies.



