Change, Concentration, and AI Redefine the Risk Register for 2026

💡
Research Report | 21 Pages | 6 Exhibits | 10 Conclusions

Operational risk used to be the discipline of preventing yesterday's loss from recurring. 2026 makes it the discipline of surviving tomorrow's delivery calendar. Broker-dealers, investment managers and custodian banks enter the year carrying the heaviest simultaneous change load in memory, with Treasury clearing, three-market T+1, ISO 20022 and AI deployment all landing inside the same window.

Three forces are rewriting the register. Change, because capacity, testing collisions, key-person dependency and cutover risk have become a portfolio-level exposure rather than a program-level one. Concentration, because the European Supervisory Authorities named their first nineteen critical ICT providers in November and brought the industry's dependency pyramid inside the regulatory perimeter. And intelligence, both artificial and adversarial: large-language-model and agentic deployments outrun model-risk frameworks built for pricing models, while deepfake authorization fraud and machine-scale business email compromise target operations teams and participant accounts directly.

The uncomfortable exposure is reflexive. Where AI is used as a control, a model failure becomes a control failure. The full report sets out ten trends across the three segments with what changes, who is exposed and which mitigations hold, several of which turn out to be procedural rather than technical.

Selected Conclusions

•        The 2026-2027 change stack becomes the top operational risk. Treasury clearing, three-market T+1, ISO 20022 and AI deployment land simultaneously, making capacity, testing collisions, key-person dependency and cutover risk a portfolio-level exposure that needs change governance owned at the COO level, with protected regression capacity and pre-agreed descoping criteria.

•        Third-party and concentration risk comes under direct supervision. The designation of nineteen critical ICT providers and the UK regime awaiting its first designations bring the dependency pyramid inside the regulatory perimeter, and substitutability analysis without illusions, fourth-party mapping and tested degraded-mode operation replace vendor-diversity theater.

•        AI-enabled fraud and cyber threats industrialize. Deepfake authorization fraud, synthetic identity and machine-scale business email compromise target operations teams and participant accounts directly, and procedural discipline such as out-of-band verification and dual approval defeats them more reliably than technology does.

Subscribers to the Journal may download the full report, including all 10 Conclusions.

Test