New! AI Board Member: Walk into every meeting knowing nothing was missed. Request early accessarrow_forward
Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

GC Risk Index 2026: Conducting governance, risk and compliance

July 27, 2026
11 min read
Smiling businessman using digital tablet outside modern glass office building.

In this article

  • Intro
  • The General Counsel’s changing role
  • Methodology
  • Acknowledgments
  • Analysis
    • An “always on” risk environment
  • The expanding legal department mandate
  • Integration and reporting lines
  • Challenges to board oversight of risk
  • AI in the legal function and the boardroom
  • Implications and questions for GCs and Boards
    • For General Counsels and Legal Leaders
    • For Boards and the C Suite
  • Appendix: Respondent demographics
  • Download the full GC Risk Index 2026 report
Kira Ciccarelli

Kira Ciccarelli

Senior Manager of Research & Programs

In an era defined by geopolitical shocks, regulatory flux and rapid advances in AI, general counsel (GCs) and senior legal leaders are being asked to do more than ever before. They are no longer responsible solely for legal risk and advisory work; increasingly, they are expected to coordinate governance, risk and compliance (GRC) across the entire enterprise while helping boards and management teams make sense of a relentlessly shifting risk landscape.

The General Counsel Risk Index is Diligent Institute’s semiannual survey of the risk landscape facing GCs, Chief Legal Officers (CLOs) and other senior legal leaders. The survey is designed to quantify how they see today’s risk environment, how they structure and lead GRC activities at their organizations, how AI is showing up their work and boardrooms, and how confident they are that boards receive the right mix of risk information.

The General Counsel’s changing role

This edition of the General Counsel Risk Index reveals a picture of elevated, “always on” risk, expanding expectations of the GC, and an infrastructure that has not fully caught up:

Key findings

  • Risk remains high: GCs rate the overall risk level facing their organizations at an average of 7 out of 10
  • The GC’s risk mandate is expanding fast: Nearly half (46%) of respondents now spend 21-40% of their time on enterprise wide risk and compliance coordination on top of traditional legal work. Over the past year, 67% say time spent on these activities has increased.
  • Systems and structures lag: Only 19% of legal leaders say their organization’s GRC systems are fully integrated; Reporting lines for Risk and Compliance are fragmented across GC/Legal, CEO/board and other functions, with no single dominant model or playbook.
  • GCs lack confidence in board reporting: Only 21% of respondents are very confident that their board receives the right mix of risk information.
  • Uneven efficiencies from AI: Only about half of legal teams (52%) report significant or measurable efficiency improvements from AI use in the last six months.

Methodology

Diligent Institute fielded this GC Risk Index as an online survey from March 2–25, 2026. The survey captured responses from 147 senior legal leaders globally, including general counsel, chief legal officers, heads of legal, corporate secretaries and other senior legal roles, representing a mix of publicly held and privately held corporations, as well as a smaller share of not for profit and government organizations. Detailed demographics appear at the end of this report.

Acknowledgments

Diligent Institute would like to thank Corporate Board Member, the Society for Corporate Governance, Governance Professionals of Canda, and the Singapore Corporate Counsel Association for promoting this survey to their members and readers.

Analysis

An “always on” risk environment

Respondents rate the current risk environment at a 7 out of 10, where 1 = Negligible and 10 = Significant. Very few organizations reported risk at the negligible end of the spectrum; most responses clustered in the upper end of the range, reinforcing the sense that high risk is now a baseline condition, not an episodic spike.

This elevated risk level is consistent with findings from our 2025 editions of the GC Risk Index conducted with Corporate Board Member – in our initial reading in Q1 2025, the risk level was at a 5.8 out of 10 and rose to nearly 8 by the end of the year.

To understand what underpinned this risk rating, respondents were then asked which risks most influenced their assessment. Several themes stand out:

  • Geopolitical conflicts and regulatory change are the two most frequently cited drivers, reflecting an external environment where cross border tensions and shifting rules can rapidly alter risk profiles.
  • AI related risks and cyber threats each appear in nearly four in ten responses, confirming that technology risk is now embedded across the enterprise-wide risk register.
  • A third of respondents highlight supply chain and sourcing disruptions, and more than a quarter cite workforce, culture and talent risks, indicating that GCs view operational resilience and human capital as central to risk oversight.

Which of the following risks most influence your rating of the current risk level?

  • Geopolitical conflicts: 52%
  • Changes in the regulatory environment: 48%
  • AI-related risks: 39%
  • Cyber threats: 39%
  • Supply chain / sourcing disruptions: 33%
  • Workforce / culture and talent risks: 27%
  • Economic impact of tariffs / trade negotiations: 20%
  • Inflation and currency fluctuations: 18%
  • Other: 7%

Respondents were asked what percentage of their time is spent on enterprise wide risk and compliance coordination (versus traditional legal work). Roughly half of legal leaders (46%) already spend between 21-40% of their time on cross enterprise risk and compliance coordination, while another quarter (25%) devote between 41-60% of their time to these activities.

How much time do legal leaders spend on risk and compliance coordination?

  • 0-20% time: 25%
  • 21-40% time: 46%
  • 41-60% time: 25%
  • 61-80% time: 1%
  • 81-100% time: 1%

This represents a significant share of GC capacity being channeled into coordination across risk and compliance functions, business lines and geographies, activities that extend well beyond traditional legal advisory work.

When asked how their time on enterprise wide risk and compliance has changed in the last year, the vast majority indicated that they had increased. Very few report any scaling back.

Time spent on enterprise-wide risk and compliance management

  • Increased: 67%
  • Stayed the same: 32%
  • Decreased: 2%

Integration and reporting lines

To understand whether systems are keeping pace with this expanded mandate, the survey asked: “To what extent are your organization’s governance, risk and compliance systems integrated?”

To what extent are your organization’s governance, risk and compliance systems integrated?

  • Not at all integrated: 16%
  • Somewhat integrated: 65%
  • Fully integrated: 19%
"This ‘partial integration’ picture is important context for understanding why GCs may struggle to deliver the concise, forward looking risk narratives boards are asking for. Without a single, connected view, GCs must invest additional time to stitch together data manually, a theme that surfaced in survey comments about the broader risk environment and GRC practices.”Nithya Das, Chief Legal Officer and GM of Governance at Diligent

Responses indicate that more than 4 out of 5 legal leaders are working with less than fully integrated GRC systems. For many, information about risk, compliance, incidents, controls and board reporting remains fragmented across multiple platforms or point solutions. This aligns with findings from our 2025 Transaction Readiness report, where only 4% of our respondents reported that they had fully integrated GRC systems for transactions specifically.

We also asked respondents to describe the reporting structure for risk and compliance in their organizations. These findings point to a highly varied - and often fragmented -organizational wiring across companies:

  • In just over a quarter of organizations, the GC clearly sits at the center of both Risk and Compliance reporting.
  • In many others, Compliance reports to Legal but Risk sits elsewhere, creating potential coordination challenges.
  • In about a quarter, both functions bypass Legal to report to the CEO or board, potentially leaving GCs to influence risk oversight without formal line authority.
  • Dotted line and “other” models introduce further complexity.

Which of the following best describes the formal reporting structure for risk and compliance in your organization?

  • Head of Compliance reports to the GC, Risk reports elsewhere: 29%
  • Head of Compliance and Head of Risk report directly to the GC/Legal: 27%
  • Both Compliance and Risk report to the CEO or Board: 23%
  • Risk and Compliance leaders have "dotted line" reporting to the GC: 15%
  • Other: 6%

Challenges to board oversight of risk

To gauge how well boards are being served by these arrangements, respondents were asked: “How confident are you that your board receives the right mix of information on risk – focused, forward looking, and not overwhelming?” Only 21% said they were “Very confident.”

How confident are you that your board receives the right mix of information on risk?

  • Very confident: 21%
  • Somewhat confident: 51%
  • Not very confident: 23%
  • Not at all confident: 6%

While a majority are at least somewhat confident that the board is being surfaced the right information, nearly one-third harbor significant doubts.

"In light of the earlier findings on partial system integration and fragmented reporting lines, this is unsurprising. Without integrated data and clear role definitions, it is hard to consistently provide boards with concise, forward looking and prioritized risk reporting.”Kira Ciccarelli, Senior Manager of Research at Diligent Institute

Meanwhile, only about half of our respondents say they have seen measurable improved efficiencies by using AI in their legal departments.

In the last six months, have you seen significant/measurable improved efficiency from your legal team using AI?

  • Yes: 52%
  • No: 48%

Those who have seen improvements highlight several common use cases:

  • Faster contract review and issue spotting.
  • Efficiency gains in document intensive tasks, including summarizing large volumes of information and drafting routine documents.
  • Reduced external counsel spend and faster turnaround times for certain workflows.

At the same time, many respondents described AI adoption as still nascent or exploratory: “Only taking baby steps so far,” notes one respondent. “We’re in the exploration phase and have not embedded any meaningful efficiency tools,” says another.

Barriers cited include:

  • Concerns about accuracy and hallucinations
  • Lack of tailored training and governance frameworks
  • Security and IT constraints, or tools not suited to specific markets.

The result is a split reality: some legal teams already see efficiency dividends from AI, while others are stuck in pilots, blocked by governance concerns or waiting for the right tools and policies.

Respondents were also asked about what they saw as the biggest risks of introducing AI in the boardroom. Several themes emerged:

  • Confidentiality, privacy, data security and privilege: Concerns about sensitive board materials or non public information being exposed, mishandled or used to train external models were widespread.
  • Accuracy, hallucinations and over reliance on AI outputs: Many respondents worried about directors or management placing undue reliance on AI generated analysis, especially if hallucinations or subtle inaccuracies go undetected.
  • Director capabilities: A recurring concern was whether directors would have the skills and judgment to use AI tools effectively and critically, and whether AI could become a crutch for those who do not fully engage with materials.
"These concerns do not imply opposition to AI in the boardroom. Rather, they reflect a demand for governed, transparent and human centered approaches: AI tools that preserve confidentiality, provide explainable outputs, and support rather than supplant board oversight.”Dottie Schindlinger, Executive Director of the Diligent Institute

Implications and questions for GCs and Boards

  • Clarify your role: If you are already spending significant time coordinating risk and compliance activities across the organization, it may be time to formalize that in your mandate, reporting relationships and KPIs.
  • Push for more integrated systems and consistent data: There is a clear opportunity to advocate for technology and process investments that bring together governance, risk, compliance and audit data into a single view.
  • Co design the “right mix” of board risk information: Consider working with your chair and committee leaders to define what “focused, forward looking and not overwhelming” looks like in practice.
  • Approach AI adoption with both ambition and guardrails: Argue for structured AI strategies that blend pilot projects with strong controls, training and measurement.

For Boards and the C Suite

  • Examine whether reporting lines empower or dilute the GC’s role. If Risk and Compliance report in multiple directions, is your GC structurally equipped to act as the enterprise wide GRC conductor, or are you relying on informal influence alone?
  • Challenge the quality of risk information you receive. Given that a majority of GCs are less than fully confident in their board’s risk information mix, ask whether your materials are too backward looking, too voluminous, or insufficiently synthesized—and what data or dashboards would help.
  • Approach AI as both a strategic tool and a governance topic. The concerns GCs raise about confidentiality, hallucinations and over reliance in the boardroom are not reasons to avoid AI altogether, but signals that clear governance frameworks, usage policies and education will be essential as you explore AI enabled oversight.

Appendix: Respondent demographics

What type of organization do you represent?

  • Privately held corporation: 50%
  • Publicly held corporation: 43%
  • Government organization: 3%
  • Not-for-profit organization: 3%

What sector does your organization belong to?

  • Information Technology: 19%
  • Financials: 16%
  • Energy: 9%
  • Consumer Discretionary: 8%
  • Industrials: 6%
  • Real Estate: 6%
  • Communication Services: 5%
  • Consumer Staples: 5%
  • Healthcare: 5%
  • Other: 22%

What region is your organization headquartered in?

  • North America: 56%
  • Asia/Australia: 17%
  • Middle East/Africa: 13%
  • Europe: 9%
  • Central/South America: 5%

What is your organization’s valuation / market capitalization in USD?

  • Less than 300 million: 28%
  • 300 million to 1.9 billion: 27%
  • 2 to 9.9 billion: 25%
  • 10+ billion: 20%

Download the full GC Risk Index 2026 report

Equip your legal leaders and boardroom for continuous governance in an "always on" risk environment. Download the full 12-page GC Risk Index 2026 report to master these critical insights today.

GC risk index 2026

Research

· Apr 21, 2026

· 1 min read

General Counsel Risk Index: Global risk benchmarking for legal leaders

Gain critical insights into global risk benchmarking with the latest General Counsel Risk Index, which synthesizes data from 147 senior legal leaders. This report will help you assess your organization's risk posture, enhance governance, risk, and compliance strategies, and prepare for informed discussions with your board and C-suite. Download now to access essential benchmarks and elevate your legal leadership role.

General counsel discussing risk in boardroom

Blog

· Apr 24, 2026

· 4 min read

The GC Risk Index 2026: Always-on risk, expanding mandates and an AI reality check

By Dottie Schindlinger

Explore the evolving role of General Counsels in the latest GC Risk Index report, revealing how expanding responsibilities and a complex risk landscape demand new strategies and tools. Discover insights on the challenges of integrating risk management systems and the dual-edged impact of AI on legal leadership.

AI action plan GRC

Guide

· Apr 22, 2026

· 1 min read

AI action plan worksheet for public sector GRC leaders

Download this essential AI action plan worksheet for public sector GRC leaders, designed to help you navigate the complexities of AI implementation in governance, risk, and compliance. This practical 90-day template guides you in setting clear goals, assessing AI maturity, prioritizing use cases, and establishing necessary oversight to ensure transparency and accountability. Take the first step towards a controlled and evidence-ready approach to AI in your organization.