Skip to main content

      European banks are operating in an increasingly complex environment marked by geopolitical uncertainty, rapid advances in technology, evolving regulation and emerging risks. As the role of the Chief Risk Officer (CRO) continues to evolve, today’s risk leaders are doing more than managing risk. They are helping organizations build resilience, support innovation and enable sustainable growth.


      The European banking industry faces an unprecedented convergence of challenges – geopolitical uncertainty, macroeconomic volatility, technological disruptions, artificial intelligence (AI), cyber threats, sustainability considerations and continuous regulatory changes. At the same time, shareholders continue to expect profitable growth, while supervisors demand stronger governance, greater resilience and robust risk management capabilities.

      Across Europe, these challenges are remarkably consistent. Whether operating in Luxembourg, Frankfurt, Paris or Milan, banks are subject to increasingly harmonized regulatory landscape through European legislation and common supervisory expectations. Yet implementing these requirements efficiently while continuing to innovate and compete remains one of the defining challenges for today’s Chief Risk Officers (CROs).

      A recent KPMG thought leadership highlights a fundamental shift in the role of the risk function. The CROs are expected to move beyond their traditional oversight role and become strategic business partners. They must balance resilience with innovation, enable growth while maintaining robust governance and leverage technology to transform how risks are identified, measured and managed. As a result, the CRO is no longer the sole guardian of the institution, but an enabler of sustainable value creation.



      What is keeping European banking CROs awake at night?

      ‘Traditional’ financial risks remain central to every bank’s risk agenda. While these risks are mature and well understood, they are not static: the evolving economic environment keeps shifting where closer attention is needed. The rise in instant payments, for example, is putting a new focus on intraday liquidity monitoring. Increasing geopolitical risks put pressure on credit risk monitoring, while real estate market development requires closer scrutiny of credit exposures and more active management of non-performing loans in the affected segments. Finally, CRR3 and evolutions in terms of regulatory expectations, following the waves of ‘return to compliance programs’ are reshaping the modelling landscape. Beyond compliance, many banks are focusing on capital optimization techniques to ensure capital levels reflect the underlying risk of the financed activities.

      The risk agenda has also expanded significantly over recent years. Operational resilience has evolved from a simple compliance exercise to a strategic priority. Banks are now strengthening their internal control environments, modernizing operational risk frameworks and embedding stronger risk cultures across their organizations. Therefore, operational resilience is increasing, which is a key differentiator for banks, requiring them to withstand disruptions, recover critical services swiftly and maintain stakeholder confidence during periods of stress.

      At the same time, digitalization, outsourcing and increasingly complex technology ecosystems are prompting firms to reconsider how non-financial risks are managed across the three lines of defense and how third-party relationships should be managed.

      AI has rapidly become one of the most significant transformational forces in financial services. Banks increasingly view AI as a powerful tool for enhancing productivity, improving customer experience and supporting better decision-making. From a risk management perspective, it has multiple facets that need to be factored in:

      The rise of generative AI is enabling increasingly sophisticated fraud, cyberattacks and identity manipulation techniques. As a result, banks are enhancing fraud detection, cyber resilience and monitoring capabilities. 

      The adoption of AI requires a robust governance, clear accountability, ongoing validation and compliance with evolving regulatory expectations, including the EU AI Act. Banks view AI governance as an extension of model risk management rather than a separate compliance exercise. 

      AI is also helping risk functions become more efficient through automation, continuous monitoring and enhanced analytics, enabling faster and more informed decision-making.


      In a risk landscape shaped by risks such as AI, a proper risk culture ensures that employees within an organization adopt the right attitude and habits, and risks are properly managed. As a result, the allocation of risk ownership across the lines of defense is key for CROs. Clear ownership and accountability are critical for addressing issues, rather than being detected downstream through controls after the damage has already occurred.

      Meanwhile, ESG, and climate and environmental risk, in particular, are increasingly viewed as core risk drivers rather than compliance workstreams. On the credit side, supervisors expect climate and environmental factors to be reflected in credit ratings, IFRS 9 provisioning and internal capital planning, which are already implemented by several banks for large corporates. In addition, physical and transition risks translate directly into operational exposure, through business continuity, supply chain and third-party dependencies, and into reputational risk, as stakeholders scrutinize both a bank’s own footprint and the activities it finances. As these risks flow through into provisioning and capital adequacy, ESG is ultimately a capital question as much as a disclosure one. The ‘prudential transition plans’ that each bank must now put in place illustrates the relationship between ESG strategy and associated risks. CROs who treat ESG as an enterprise-wide risk lens, spanning credit, operations, reputation and capital, are better positioned than those who manage it as a standalone reporting obligation.

      Finally, the regulatory landscape continues to evolve. Rather than dealing with isolated regulatory initiatives, banks are now navigating a continuous stream of interconnected reforms spanning prudential requirements – on both ‘going concern’ and ‘gone concern’ (such as resolution). The challenge lies in implementing the regulations efficiently and maintaining agility for the future.

      Data is the common denominator among all these priorities. High-quality, well-governed and readily accessible data has become the foundation for effective risk management, regulatory reporting, stress testing, AI adoption and strategic decision-making. As risk management becomes increasingly interconnected, siloed approaches are no longer sufficient to support executive decision-making.



      A Luxembourg perspective: 

      Global priorities, local accountability

      These industry-wide trends are particularly relevant in Luxembourg, one of Europe’s leading international banking centers and home to a diverse mix of domestic banks, branches and subsidiaries, and larger groups. While the former face similar challenges as their European peers, the latter face an additional layer of complexity. They must strike the right balance between leveraging group-led initiatives and infrastructure while maintaining effective local governance and oversight with generally smaller teams, making efficiency the top priority.

      Luxembourg’s banking sector also has its own specific dynamics. The market is now facing growing competitive pressure from digital-native banks and new entrants offering more seamless, technology-led customer experiences. At the same time, the sector continues to grow: KPMG’s Luxembourg Banking Insights had total banking assets worth approximately €959 billion in 2025, up €38 billion since 2021, with particularly strong momentum in the most recent year. However, it came with its stress points: parts of the real estate market, particularly construction and development, have recorded a significant increase in non-performing loans, and given domestic banks’ exposure to this sector, credit risk teams are required to monitor these portfolios more closely than in recent years.

      Supervisory expectations continue to evolve. The CSSF and the ECB expect institutions to demonstrate robust governance, effective oversight of outsourced and centralized activities, high-quality regulatory reporting, operational resilience and a clear understanding of emerging risks. Local management is expected to comply with regulatory requirements as well as to demonstrate that governance arrangements remain proportionate, effective and aligned with the institution’s specific risk profile. Luxembourg’s banking sector is one of Europe’s most internationalized banking markets, with 7 out of 10 institutions being foreign-owned, primarily neighboring countries. Luxembourg entities are rarely free-standing: many operate as branches or subsidiaries within larger international groups, relying on group-wide frameworks, infrastructure and expertise. The CSSF, in line with its substance-over-form approach, expects boards and conducting officers to hold real authority, have direct access to information, demonstrate that they actively challenge and, where necessary, depart from group-led approaches, rather than acting as an administrative extension of the parent. This is compounded by the country’s role as Europe’s leading fund and asset-servicing center: banks providing depositary, custody and fund administration services carry a concentration of operational, outsourcing and third-party risk that is less prevalent in purely retail-oriented markets elsewhere in Europe. For Luxembourg CROs, the challenge is therefore not simply ‘doing more with less’, but building a risk function that is acts as a local decision-maker. Therefore, success depends on meeting today’s supervisory expectations and building an agile risk function capable of adapting to tomorrow’s challenges.



      Helping banks build the risk function of tomorrow

      At KPMG, we believe the risk function of the future is built around three distinct characteristics.

      • First, it is strategic

        Going beyond a purely control function role. Rather than solely focusing on historical reporting, it provides forward-looking insights that support business decisions and strategy, helping in anticipating trends and emerging risks, and taking pro-active decisions. Playing that role requires getting the underlying allocation of responsibilities right. Risk ownership needs to fit clearly with the first line of defense, with the business teams originating and running the activity. The second line focuses on challenge, calibration and setting the guardrails rather than absorbing that ownership itself. When that boundary is blurred, the first line can end with the assumption that risk is someone else’s job, while the second line gets pulled into regular execution of control. Balancing the first and second line accountabilities is a vector of adequate risk culture. 

      • Second, it is technology-enabled

        It leverages automation, advanced analytics and AI to improve decision-making, strengthen controls and reduce manual effort.

      • And finally, it is resilient

        It combines strong governance, high-quality data and integrated risk management capabilities across the organization while remaining flexible enough to respond to an evolving regulatory landscape.


      Across Europe, and particularly in Luxembourg, we work with banks to help them transform their risk functions, respond to new regulatory expectations, redesign operating models, strengthen governance, modernize risk infrastructures and unlock the value of emerging technologies.

      The objective is not just to comply with the next regulation. It is to build a risk function that enables better decisions, strengthens resilience and supports sustainable growth in an increasingly uncertain environment.

      As our clients’ needs evolve, our service offerings upscale to ensure we deliver spot-on value to our clients.


      How KPMG can help

      • Financial risk management

        Helping banks strengthen credit, market, liquidity and ALM risk frameworks through governance, quantitative analytics, stress testing, ICAAP/ILAAP, model risk management and optimization of the risk operating model.

      • Non-financial risk and internal controls

        Enhancing operational risk management, internal control frameworks, operational resilience and risk culture, while leveraging technology to improve efficiency and effectiveness across the three lines of defense.

      • AI governance and model risk

        Enabling clients to deploy AI confidently by establishing governance frameworks, validation methodologies, model inventories, controls and oversight aligned with evolving regulatory expectations.

      • Regulatory reporting transformation

        Supporting banks in improving the efficiency, quality and resilience of prudential and regulatory reporting through data transformation, automation, governance and future-ready operating models.

      • Recovery and resolution

        Assisting financial institutions in strengthening recovery planning, operational continuity, resolution capabilities and preparedness for evolving supervisory expectations.

      • Emerging risks

        Helping organizations identify, assess and integrate ESG, climate, geopolitical, cyber and other emerging risks into enterprise-wide risk management and strategic decision-making.

      Anticipate and manage risk with KPMG Luxembourg’s risk consulting team, helping you address regulatory change, cyber threats and ESG expectations while building resilient, future‑ready operations.


      Our expert

      Julien Thiry

      Partner, Consulting, Financial Risk Management Lead

      KPMG in Luxembourg

      Gianfranco Mei

      Partner, Advisory

      KPMG in Luxembourg


      Related content

      Anticipate and manage risk with KPMG Luxembourg’s risk consulting team, helping you address regulatory change, cyber threats and ESG expectations while building resilient, future‑ready operations.

      Explore how to turn risk into an opportunity for value creation and align your organization with the demands of the modern risk environment.

      Turning complexity into clarity – empowering smarter decisions through data, insight and experience.

      Delivering practical regulatory solutions backed by deep market and regulatory insight.