What the profession is saying
ICA’s global GRC survey found that practitioners see AI and technology as the largest driver of change over the next five years. The survey also highlights relationship management as a leading future skill. Together, these findings point toward a compliance function that must become both more technical and more influential.
Technical literacy
Compliance professionals do not need to become data scientists, but they need enough understanding of AI, data, automation and model risk to challenge business proposals and interpret control limitations.
Judgement
As automation handles more routine work, the value of human compliance professionals will increasingly lie in ambiguity: interpreting incomplete evidence, balancing competing obligations and making defensible proportional decisions.
Relationships
A compliance function that cannot influence the first line will struggle regardless of technical competence. Relationship management is not softness; it is a control capability because effective challenge depends on access, trust and credibility.
Strategic role
Senior compliance leaders should connect regulatory risk with product strategy, technology, customer outcomes and reputation. This moves GRC from retrospective assurance toward forward-looking decision support.
Conclusion
The future GRC professional combines technical literacy, regulatory judgement and organisational influence. Firms should build those capabilities now rather than waiting for technology and regulation to force the change.
Practical actions for GRC leaders
- Build AI and data literacy across second-line teams.
- Preserve human judgement for ambiguous, high-consequence decisions.
- Develop relationship and influencing skills as formal control capabilities.
- Connect compliance reporting with strategy, technology and customer outcomes.
Related reading
See Governance, Risk and Compliance, Enterprise Risk and Governance.
About the author
Jonas Adam Mohamed Osman Abdelghafour writes about governance, risk and compliance, AI governance, regulatory risk and leadership. See About and Qualifications.
Source and editorial context
This is original analysis informed by the International Compliance Association GRC survey. No affiliation with or endorsement by ICA is claimed or implied.
Frequently asked questions
What the profession is saying?
ICA’s global GRC survey found that practitioners see AI and technology as the largest driver of change over the next five years. The survey also highlights relationship management as a leading future skill. Together, these findings point toward a compliance function that must become both more technical and more influential.
What should risk leaders know about technical literacy?
Compliance professionals do not need to become data scientists, but they need enough understanding of AI, data, automation and model risk to challenge business proposals and interpret control limitations.
What should risk leaders know about judgement?
As automation handles more routine work, the value of human compliance professionals will increasingly lie in ambiguity: interpreting incomplete evidence, balancing competing obligations and making defensible proportional decisions.
What should risk leaders know about relationships?
A compliance function that cannot influence the first line will struggle regardless of technical competence. Relationship management is not softness; it is a control capability because effective challenge depends on access, trust and credibility.
What should risk leaders know about strategic role?
Senior compliance leaders should connect regulatory risk with product strategy, technology, customer outcomes and reputation. This moves GRC from retrospective assurance toward forward-looking decision support.