The Professional Services Practice’s Keith Tracey summarizes the Aon’s GRMS 2023 results, compares them to the GRMS 2021, among other surveys, and comments on the value of professional service firms using surveys to make better decisions about enterprise risk management.
Aon has published the results of the
2023 Global Risk Management Survey. Aon’s commentary on the results identified:
1. Cyber is still the biggest concern.
2. Resilience is a boardroom discussion as regulators continue to apply pressure.
3. Human capital challenges are being recognized.
The results from
Professional Service Firm (PSF) respondents have also been published.
Risks Identified in PSF Survey
Looking at movements since the 2021 results, 9 of the top 10 risks appear again, albeit in a slightly different order.
Other responses about future risks displayed increased concerns around AI and geopolitical volatility. Regulatory changes also moved up the agenda.
Observations on 2023 Results
- Business interruption is down from 4, but of course it is a consequence that might be the result of a ransomware attack, a pandemic, or a flood, for example.
- Pandemics do not appear, but perhaps business continuity worked and professional service firms’ resilience proved to be strong. There could also be a mix of recency or optimism bias.
- Workplace and talent issues are appearing in most surveys. This no doubt reflects concern about the ability to innovate and respond to competition in a world where new skills are of rising importance.
Headline Results from Other Risk Surveys
It is the season for risk surveys, which come from many different perspectives. There are themes that are consistent with Aon’s results.
- Cyber risks routinely top the list.
- Technology, disruption, and the future growth of AI are frequent inclusions. On the latter, the concerns are very wide ranging, two examples being ethics and its use by cyber criminals.
- Perceptions of financial and economic uncertainty consistently appear.
- General political uncertainty, and growing disinformation fueled by social media, are concerns in this year of elections.
What are the Value of Surveys?
These manifestations of risk are clearly connected and frequently become cumulative. A cyber attack is an external threat to the business. Tolerance should be low, and IT architecture, security protections, and adequate training can limit or eliminate the threat. The source is external, but its manifestation could arise from internal human error, and the nature of attacks is continually evolving.
Actions? Responses?
Final Thoughts
- A multiskilled response is a critical success factor. It was suggested at a 2022 Swiss Re Conference that when building resilience, historians, political economists, and psychologists may have a place at the table.
- Creating a safe internal environment for challenges and creating resourceful employees is an important line of defense.
- How good are we at recognizing the top risks? Surveys focus on the past and thereby often miss the next big one. Many surveys up until 2020 did not have pandemics in the top 10 risks. This makes continuity, incident response, and crisis management planning vital.
The Professional Services Practice at Aon values your feedback. If you have any comments or questions, please contact Keith Tracey.
This article is adapted from Understanding Risk – Professional Service Firms and Aon’s GRMS 2023 Results (February 2024) from the Professional Services Practice at Aon