Building Risk Culture in 2026: ERM vs GRC, Internal Audit, Operational Resilience, and Board AI Oversight Explained

Boards today are being asked to do more than approve risk registers and sign off on audit reports. They are being asked to shape the culture that determines whether an organisation actually behaves the way its policies say it should. That shift is why a cluster of questions keeps coming up in my conversations with directors and risk leaders across Southeast Asia: how do you build a genuine risk culture, what really separates ERM from GRC, how has internal audit changed, what does operational resilience mean in practice, how does a board strengthen its risk oversight, and what should directors be asking about AI? This article brings those questions together, because in practice they are not separate problems. They are five faces of the same challenge: making risk management a living part of how an organisation thinks and decides, not a compliance exercise that happens after the fact. If there is one question that comes up more than any other, it is simply this: how to build risk culture in an organisation so that it survives leadership changes, market pressure, and the temptation to cut corners when targets are tight. The honest answer is that it takes more than a policy – it takes structure, repetition, and visible consequences, which is what the rest of this article works through. What Is Risk Culture, and Why It Has Become a Board Priority Risk culture is the set of shared values, attitudes, and behaviours that shape how people across an organisation identify, discuss, and act on risk – especially when no one is watching. It shows up in whether a junior manager feels safe escalating a bad-news item, whether risk appetite statements actually influence pricing and investment decisions, and whether “speaking up” is rewarded or quietly punished. Regulators and rating agencies have made risk culture a formal supervisory focus precisely because strong controls on paper have repeatedly failed to prevent failures in practice. A control framework only works if the people operating it believe it matters. How to Build Risk Culture in an Organisation Building risk culture is not a single initiative; it is a set of reinforcing habits that boards and executives sustain over years. A few practices consistently separate organisations with a genuine risk culture from those with a paper one: In other words, learning how to build risk culture organisation – wide takes deliberate, repeated reinforcement from the board down through middle management, because culture is ultimately shaped by what leaders do under pressure, not what they say in calmer moments. ERM vs GRC: Understanding the Difference One of the most common points of confusion I encounter with directors is the difference between ERM and GRC. The two are related, but they are not interchangeable. Enterprise Risk Management (ERM) is a strategic discipline. It is the structured process an organisation uses to identify, assess, prioritise, and respond to risks that could affect its objectives – financial, strategic, operational, and reputational. ERM asks: what could stop us from achieving our strategy, and how much risk are we willing to accept in pursuit of it? Governance, Risk, and Compliance (GRC) is a broader operating framework. It integrates governance structures, risk management processes, and regulatory compliance activities into a coordinated approach, often supported by a shared technology platform, common data taxonomy, and unified reporting. GRC asks: how do our governance, risk, and compliance functions work together so we are not duplicating effort or leaving gaps between them? In short, ERM is a core discipline focused on strategic and operational risk-taking, while GRC is the wider architecture that connects ERM with regulatory compliance, internal controls, and governance oversight. A mature organisation typically houses ERM as one critical component within a broader GRC structure – rather than treating the two as competing frameworks. How Does Internal Audit Work in 2026? Internal audit has changed considerably from its traditional role as a periodic checker of financial controls. Several shifts define how internal audit works in 2026: Continuous, data-driven assurance: Rather than relying solely on annual cyclical reviews, internal audit functions increasingly use continuous monitoring and analytics to flag anomalies as they emerge, allowing auditors to focus scarce resources on higher-risk areas. Broader risk universe: Internal audit’s scope now regularly extends beyond financial and operational controls into cyber resilience, third-party and vendor risk, ESG reporting integrity, and increasingly, the governance of AI systems used across the business. Closer alignment with the three lines model: Internal audit works more deliberately alongside the first line (business operations) and second line (risk and compliance functions), providing independent assurance over how well those lines are actually functioning – rather than duplicating their work. Skills evolution: Auditors are expected to bring data analytics literacy and a working understanding of emerging technology risk, in addition to traditional audit and accounting expertise. Stronger reporting lines to the board: Audit committees increasingly expect direct, unfiltered access to the Chief Internal Auditor, and expect internal audit findings to feed directly into board risk oversight discussions rather than sitting in a separate reporting track. The net effect is that internal audit in 2026 functions less like a rear-view mirror and more like an early-warning system that boards rely on for real-time assurance. What Is Operational Resilience, and Why It Matters to the Board Operational resilience is an organisation’s ability to anticipate, prevent, respond to, and recover from disruptions to its critical business services – while continuing to deliver on its most important obligations to customers, employees, and markets. It differs from traditional business continuity planning in an important way: operational resilience starts from the outside in, focusing first on the services that matter most to customers and stakeholders, and then works backward to identify every people, process, technology, and third-party dependency that supports them. For boards, operational resilience has become a governance issue, not just an operational one, for three reasons: Boards should expect regular reporting on impact tolerances for critical services, results of resilience testing (including severe-but-plausible scenarios), and clear accountability for who owns