Gartner Enterprise Risk, Audit & Compliance Conference 2026 London: Day 1 Summary

LONDON, September 28, 2026 

It’s not too late to join the conference

Overview

We are bringing you news and highlights from the Gartner Enterprise Risk, Audit & Compliance Conference 2026, taking place this week in London. Below is a collection of key announcements and insights coming out of the conference.

On Day 1 of the conference, we are highlighting sessions including: How To Prepare for High-Impact Audit Committee Interactions; Managing Newly Emerged, Highly Interdependent Risks; and From Risk Appetite to Cost Decisions: How ERM Enables Resilience That Gets Executed. Be sure to check this page throughout the day for updates.

Key Announcements

How To Prepare for High-Impact Audit Committee Interactions

Presented by Tim Berichon, Executive Partner, Business Services, Gartner

Effective Audit Committee engagement depends on matching each issue to the right forum while communicating with clarity, discretion and purpose. In this session, Tim Berichon, Executive Partner, Business Services at Gartner, explained how to successfully address these issues.

Key Takeaways

  • Use one-on-one meetings with the Audit Committee Chair to prepare for formal discussions, align on key messages, and seek guidance on sensitive issues.
  • Leverage private executive sessions to discuss systemic concerns, emerging risks, management responsiveness, and other matters requiring confidential committee awareness..
  • Reserve formal Audit Committee meetings for issues requiring full committee visibility, oversight or action, including audit plans, significant findings, resources and emerging risks.
  • Prepare for every interaction by aligning its purpose, attendees, topics, desired outcomes, and supporting materials.
  • Communicate objectively, emphasize systemic themes, protect confidentiality and appropriately document required interactions without compromising internal audit’s independence.

Journalists can receive additional information and/or request an interview with Tim Berichon by contacting Rob van der Meulen at rob.vandermeulen@gartner.com..

 

It’s not too late to join the conference

Managing Newly Emerged, Highly Interdependent Risks

Presented by Jim Mello, Senior Director Analyst, Gartner

Traditional risk management approaches struggle in the dynamic environment as newly emerged, highly interdependent risks become commonplace. In this session, Jim Mello, Senior Director Analyst at Gartner, explained how ERM leaders can better detect and coordinate risk responses across the business.

Key Takeaways

  • Newly emerged, highly interdependent (NEHI) risks are unlike enterprise risks or emerging risks because they are gradual, uneven and unpredictable. They often span multiple business areas in interconnected ways.
  • There are three main types of NEHI risk response misalignments heads of ERM have told us: missing response(s), wasteful response(s), and harmful response(s).
  • Missing response(s): Some risk drivers or impacts go untreated by any part of the business.
  • Wasteful response(s): Multiple part of the business invest in redundant or duplicative treatments.
  • Harmful response(s): Treatments in one part of the business have detrimental effects elsewhere.
  • To respond to NEHI risks caused by the new risk environment, ERM must first detect instances of harmful alignment.
  • ERM should guide the business to coordinate risk treatments.

Journalists can receive additional information and/or request an interview with Jim Mello by contacting Rob van der Meulen at rob.vandermeulen@gartner.com..

 

From Risk Appetite to Cost Decisions: How ERM Enables Resilience That Gets Executed

Presented by Suzie Petrusic, Vice President Analyst, Chief of Research, Gartner

Many ERM leaders struggle to see resilience decisions funded and operationalized. In this session, Suzie Petrusic, Vice President Analyst and Chief of Research at Gartner, explained how building enterprise resilience requires a business-led approach that connects risk management and investment decisions directly to the organization’s most critical objectives.

Key Takeaways

  • Start by identifying the strategic, operational, and revenue-generating priorities that matter most to the business.
  • Evaluate risks based on their potential impact on those priorities rather than attempting to address every conceivable threat.
  • Compare mitigation options and costs to ensure resilience investments deliver measurable business value.
  • Define clear risk and cost appetites, so leaders can make consistent trade-offs between protection, performance and efficiency.
  • Strengthen accountability by assigning resilience decisions to business owners and using phased actions, including near-term prioritization, a 90-day capability assessment, and longer-term metrics.

Journalists can receive additional information and/or request an interview with Susie Petrusic by contacting Rob van der Meulen at rob.vandermeulen@gartner.com..

 

That's a wrap for day 1 of the conference. Tune back in tomorrow for more highlights from day 2.

Media contact



Latest releases

About Gartner

Gartner (NYSE: IT) delivers actionable, objective business and technology insights that drive smarter decisions and stronger performance on an organization’s mission-critical priorities. To learn more, visit gartner.com.