KPMG Warning: Compliance Chiefs Must Break Silos or Risk Operational Resilience Failure
A new KPMG survey is putting a sharper question before chief compliance officers, Chief Compliance Officers: can compliance functions remain effective if they operate in isolation from cybersecurity,...
A new KPMG survey is putting a sharper question before chief compliance officers, Chief Compliance Officers: can compliance functions remain effective if they operate in isolation from cybersecurity, data, technology, business continuity and other risk functions?
KPMG’s 2026 Global Chief Ethics and Compliance Officer Survey argues that operational resilience is becoming a central test of modern compliance, as cyberattacks, data breaches, third party failures and regulatory intervention increasingly converge.
The survey, which draws on responses from CCOs across six industry sectors and eight countries, identifies operational resilience as a priority for compliance leaders seeking to manage interconnected risks. Rather than treating cyber, third party and regulatory exposures as separate problems, the report calls for a more integrated view of enterprise risk.
The investment numbers are significant. Data analytics emerged as the leading investment priority, with 77 percent of surveyed CCOs identifying it as an area requiring additional funding. Cybersecurity and data privacy followed at 75 percent. Process automation was cited by 49 percent, while 50 percent pointed to AI and large language models as investment areas.
The findings also reveal where compliance leaders expect pressure to intensify. New regulatory requirements ranked as the biggest compliance challenge over the next two years, cited by 33 percent of respondents. Data analytics and predictive modelling followed closely at 31 percent.
For CCOs, the implication is clear. Regulatory compliance can no longer be reduced to monitoring rules after the fact. Compliance teams are increasingly expected to anticipate how a cyber incident, technology failure, third party disruption or geopolitical shock could trigger regulatory, financial and reputational consequences simultaneously.
KPMG is therefore urging compliance chiefs to build stronger internal alliances and share the business case for resilience investment. The report specifically highlights collaboration with cybersecurity, business continuity, legal, HR, investigations, internal audit and operations.
The survey found that 81 percent of CCOs are confident in collaborating with cybersecurity teams, while 68 percent expressed confidence in working with resilience and business continuity teams. Another 67 percent said they were confident in assessing compliance synergies across functions including legal, HR, investigations, internal audit and operations.
The report also pushes compliance further into technology governance. KPMG argues that compliance leaders should have a role in technology and AI decisions from the outset, rather than becoming involved only after a breach or regulatory problem emerges.
That message comes as organisations accelerate AI adoption. KPMG found that 68 percent of CCOs viewed their experience with AI as mixed but leaning positive, while 24 percent reported significant improvements in compliance efficiency and effectiveness. Yet adoption remains concentrated in areas such as risk assessment, data visualisation, predictive analytics and employee training, with human oversight still considered essential for more sensitive compliance activities.
For compliance departments, the emerging model is therefore less about policing the business from the sidelines and more about building the controls, intelligence and institutional relationships needed to keep the business functioning when disruption strikes.
Compliance takeaway: The resilience agenda is moving compliance from the control room into the organisation’s strategic architecture. CCOs that cannot connect regulatory obligations with cyber risk, third party exposure, data governance and business continuity may find themselves managing fragments of a risk that has already become enterprise wide.



No Comment! Be the first one.