KPMG’s 2026 CCO Survey

I have just read KPMG’s 2026 Global Chief Ethics and Compliance Officer Survey. A very interesting report, although some of its findings made me raise an eyebrow.
The direction: Compliance is moving far beyond its traditional regulatory role.
75% of respondents identify Cybersecurity and Data Privacy as areas driving additional investment, 77% point to data analytics, 81% are confident collaborating with cybersecurity teams, and 68% with resilience and Business Continuity teams.

The report goes further: it recommends elevating Compliance’s role in technology governance, connecting cyber and privacy with regulatory obligations and championing scenario planning for ransomware, third party failures and geopolitical disruption.
Collaboration? Absolutely. Understanding regulations affecting cyber, privacy, resilience and technology? Definitely. But collaboration is not the same as ownership or technical assessment.
I somehow do not remember Compliance trying to be involved in cybersecurity, BCM, resilience, or technology 10–15 years ago. Today these are hot topics, so suddenly everyone wants a seat at the table.
The risk starts when people without sufficient technical or domain expertise begin assessing controls, challenging architectures, or issuing recommendations to specialist teams. I have seen what can happen: additional controls, duplicated evidence, another spreadsheet, another report and another “compliance requirement”, sometimes creating significant work while reducing very little actual risk.
This is exactly why organizations need clear Responsibility Maps and Assurance Maps. There should not be a “compliance of everything”.
Compliance has an important role, but primarily in understanding obligations, coordinating regulatory requirements, monitoring compliance risk and challenging whether appropriate mechanisms exist. Domain specialists should remain accountable for their domains. We already understand this perfectly well in taxation. I rarely hear that a Compliance department should take responsibility for tax compliance. Why? Because tax specialists possess very specific domain knowledge.
A mature GRC model should integrate specialist functions, not absorb them.
Risk, Compliance, Internal Audit, Privacy, Cybersecurity, BCM, Legal, Finance and other assurance functions should understand where responsibilities begin and end, how information flows between them and where assurance overlaps.
Otherwise, instead of integrated assurance, we may simply create more assurance activity.
Author: Sebastian Burgemejster



Comments