KPMG’s 2026 CCO Survey: Operational Resilience Is Now the Job, Not a Side Project

Why Operational Resilience Has Moved to the Center
The core finding driving this year’s report is that interconnected cyber, third-party, and regulatory risks have made operational resilience a top priority for compliance leaders, not an adjacent concern owned by IT or business continuity teams. Three-quarters of CCOs surveyed, 75 percent, identified cybersecurity and data privacy as key areas for additional investment, and 77 percent named data analytics as a primary investment driver going forward. That pairing is telling. Cybersecurity investment without the analytics capability to actually monitor, detect, and respond to emerging risk in real time is incomplete, and compliance leaders appear to understand that these two investment categories function together rather than as separate line items competing for budget.
Regulatory pressure remains a distinct challenge layered on top of this. A third of respondents, 33 percent, cited new regulatory requirements as their top compliance challenge over the next two years, which tells you that even as compliance functions expand into operational resilience and cyber risk territory, the traditional core mandate, tracking and responding to a shifting regulatory landscape, hasn’t gotten any easier. If anything, it’s competing for the same limited attention and budget that resilience investment now demands.
Cross-Functional Collaboration Is the Real Story Underneath the Numbers
What I find most significant in this survey isn’t the investment figures on their own. It’s what those figures say about how compliance functions now have to operate structurally. Sixty-seven percent of CCOs surveyed reported confidence in assessing compliance synergies across legal, HR, investigations, internal audit, and operations, a genuinely broad set of functions to be coordinating with effectively. Even more notably, 81 percent expressed confidence collaborating specifically with cybersecurity teams, and 68 percent with resiliency and business continuity teams.

That level of confidence in cross-functional collaboration reflects something important about how compliance’s mandate has evolved. Operational resilience isn’t something a compliance function can build on its own, sitting in its traditional lane of policy, training, and monitoring. It requires genuine partnership with the teams that actually own network security, incident response, and business continuity planning. A CCO who treats cybersecurity as someone else’s department, to be consulted only when a breach or incident actually occurs, is no longer positioned to do the job KPMG’s survey respondents describe themselves as doing. The compliance function increasingly has to sit inside the operational resilience conversation from the planning stage forward, not get looped in after the fact when a risk has already materialized into an incident.
AI in Compliance: Real Adoption, Measured Enthusiasm
The survey’s findings on AI use inside compliance functions are worth their own attention, because the tone is notably calibrated rather than either dismissive or overly enthusiastic. Sixty-eight percent of CCOs described their view of AI use as “mixed, leaning positive,” reporting that they’ve seen more benefits than challenges so far. That’s a meaningfully different posture than blanket AI optimism, and it reflects a compliance function actually grappling with AI’s real tradeoffs rather than adopting it reflexively because it’s the technology of the moment.
The specific use cases where AI is gaining traction inside compliance functions are instructive. Fifty percent of respondents reported using AI for compliance risk assessment and management, the single most common application. Data visualization and predictive analytics, and employee training and awareness, each came in at 44 percent. That combination suggests compliance functions are gravitating toward AI applications where the technology’s strengths, pattern recognition across large data sets and scalable content delivery, map cleanly onto tasks compliance teams already struggle to do manually at scale: sorting through transaction or communication data for risk signals, building visual risk dashboards for leadership and the board, and delivering consistent training content across a large, distributed workforce.

What This Means for Compliance Leaders Building Their 2027 Priorities
A few practical implications follow from this survey that compliance officers should be translating into actual planning conversations now.
If your compliance function’s investment planning for the next budget cycle doesn’t include a meaningful allocation to cybersecurity, data privacy, and the data analytics capability needed to make that investment actually functional, you’re planning against a materially different reality than the one 75 percent of your peer CCOs are already investing against. Operational resilience investment isn’t optional anymore, and treating it as a lower priority than traditional compliance program elements risks leaving your function meaningfully behind where the field is actually heading.
Structural collaboration with cybersecurity and resiliency teams needs to be built into your compliance function’s actual operating model, not treated as an ad hoc relationship that activates only during an incident. The CCOs reporting high confidence collaborating with these teams didn’t develop that confidence by accident; it reflects deliberate investment in cross-functional processes, shared risk assessment frameworks, and regular touchpoints well before any specific risk event forces the collaboration into existence under pressure.
And on AI specifically, the survey’s findings suggest the most productive path forward isn’t broad, undifferentiated AI adoption across every compliance function, but targeted application to the specific use cases where compliance teams are already seeing real value: risk assessment and management, predictive analytics and visualization for reporting up to leadership and the board, and training delivery at scale. Compliance leaders evaluating AI tools should be asking whether a proposed use case maps onto one of these proven categories, rather than adopting AI capability generically and hoping a use case emerges afterward.
The broader message from this survey is one I’d encourage every compliance officer to sit with directly: the function’s mandate has genuinely expanded, from risk mitigation toward resilience and measurable value creation, and that expansion isn’t optional or temporary. It’s the new baseline expectation for what a modern compliance program actually needs to deliver.











