
In an era defined by geopolitical shocks, regulatory flux and rapid advances in AI, general counsel (GCs) and senior legal leaders are being asked to do more than ever before. They are no longer responsible solely for legal risk and advisory work; increasingly, they are expected to coordinate governance, risk and compliance (GRC) across the entire enterprise while helping boards and management teams make sense of a relentlessly shifting risk landscape.
The General Counsel Risk Index is Diligent Institute’s semiannual survey of the risk landscape facing GCs, Chief Legal Officers (CLOs) and other senior legal leaders. The survey is designed to quantify how they see today’s risk environment, how they structure and lead GRC activities at their organizations, how AI is showing up their work and boardrooms, and how confident they are that boards receive the right mix of risk information.
This edition of the General Counsel Risk Index reveals a picture of elevated, “always on” risk, expanding expectations of the GC, and an infrastructure that has not fully caught up:
Key findings
Diligent Institute fielded this GC Risk Index as an online survey from March 2–25, 2026. The survey captured responses from 147 senior legal leaders globally, including general counsel, chief legal officers, heads of legal, corporate secretaries and other senior legal roles, representing a mix of publicly held and privately held corporations, as well as a smaller share of not for profit and government organizations. Detailed demographics appear at the end of this report.
Diligent Institute would like to thank Corporate Board Member, the Society for Corporate Governance, Governance Professionals of Canda, and the Singapore Corporate Counsel Association for promoting this survey to their members and readers.
Respondents rate the current risk environment at a 7 out of 10, where 1 = Negligible and 10 = Significant. Very few organizations reported risk at the negligible end of the spectrum; most responses clustered in the upper end of the range, reinforcing the sense that high risk is now a baseline condition, not an episodic spike.
This elevated risk level is consistent with findings from our 2025 editions of the GC Risk Index conducted with Corporate Board Member – in our initial reading in Q1 2025, the risk level was at a 5.8 out of 10 and rose to nearly 8 by the end of the year.
To understand what underpinned this risk rating, respondents were then asked which risks most influenced their assessment. Several themes stand out:
Which of the following risks most influence your rating of the current risk level?
Respondents were asked what percentage of their time is spent on enterprise wide risk and compliance coordination (versus traditional legal work). Roughly half of legal leaders (46%) already spend between 21-40% of their time on cross enterprise risk and compliance coordination, while another quarter (25%) devote between 41-60% of their time to these activities.
How much time do legal leaders spend on risk and compliance coordination?
This represents a significant share of GC capacity being channeled into coordination across risk and compliance functions, business lines and geographies, activities that extend well beyond traditional legal advisory work.
When asked how their time on enterprise wide risk and compliance has changed in the last year, the vast majority indicated that they had increased. Very few report any scaling back.
Time spent on enterprise-wide risk and compliance management
To understand whether systems are keeping pace with this expanded mandate, the survey asked: “To what extent are your organization’s governance, risk and compliance systems integrated?”
To what extent are your organization’s governance, risk and compliance systems integrated?
"This ‘partial integration’ picture is important context for understanding why GCs may struggle to deliver the concise, forward looking risk narratives boards are asking for. Without a single, connected view, GCs must invest additional time to stitch together data manually, a theme that surfaced in survey comments about the broader risk environment and GRC practices.” — Nithya Das, Chief Legal Officer and GM of Governance at Diligent
Responses indicate that more than 4 out of 5 legal leaders are working with less than fully integrated GRC systems. For many, information about risk, compliance, incidents, controls and board reporting remains fragmented across multiple platforms or point solutions. This aligns with findings from our 2025 Transaction Readiness report, where only 4% of our respondents reported that they had fully integrated GRC systems for transactions specifically.
We also asked respondents to describe the reporting structure for risk and compliance in their organizations. These findings point to a highly varied - and often fragmented -organizational wiring across companies:
Which of the following best describes the formal reporting structure for risk and compliance in your organization?
To gauge how well boards are being served by these arrangements, respondents were asked: “How confident are you that your board receives the right mix of information on risk – focused, forward looking, and not overwhelming?” Only 21% said they were “Very confident.”
How confident are you that your board receives the right mix of information on risk?
While a majority are at least somewhat confident that the board is being surfaced the right information, nearly one-third harbor significant doubts.
"In light of the earlier findings on partial system integration and fragmented reporting lines, this is unsurprising. Without integrated data and clear role definitions, it is hard to consistently provide boards with concise, forward looking and prioritized risk reporting.” — Kira Ciccarelli, Senior Manager of Research at Diligent Institute
Meanwhile, only about half of our respondents say they have seen measurable improved efficiencies by using AI in their legal departments.
In the last six months, have you seen significant/measurable improved efficiency from your legal team using AI?
Those who have seen improvements highlight several common use cases:
At the same time, many respondents described AI adoption as still nascent or exploratory: “Only taking baby steps so far,” notes one respondent. “We’re in the exploration phase and have not embedded any meaningful efficiency tools,” says another.
Barriers cited include:
The result is a split reality: some legal teams already see efficiency dividends from AI, while others are stuck in pilots, blocked by governance concerns or waiting for the right tools and policies.
Respondents were also asked about what they saw as the biggest risks of introducing AI in the boardroom. Several themes emerged:
"These concerns do not imply opposition to AI in the boardroom. Rather, they reflect a demand for governed, transparent and human centered approaches: AI tools that preserve confidentiality, provide explainable outputs, and support rather than supplant board oversight.” — Dottie Schindlinger, Executive Director of the Diligent Institute
What type of organization do you represent?
What sector does your organization belong to?
What region is your organization headquartered in?
What is your organization’s valuation / market capitalization in USD?
Equip your legal leaders and boardroom for continuous governance in an "always on" risk environment. Download the full 12-page GC Risk Index 2026 report to master these critical insights today.