Survey of 184 Senior Enterprise Risk Executives Reveals Shifts in Top Five Emerging Risks
The Quarterly Emerging Risk Report series captures the views and concerns of enterprise risk management (ERM) leaders, risk management professionals, auditors, and senior executives views on emerging risks or over-the-horizon risk.
The 3Q25 report, based on a survey of 184 senior risk and assurance executives, also revealed mounting concern around artificial intelligence (AI). AI-related information governance-driven risks, moved up in rank, from the fourth most cited spot in 2Q25 to the second rank in 3Q25, and shadow AI moved from the fifth ranked spot to the third spot, as organizations face challenges in effectively monitoring its use (see Table 1).
“The top five emerging risks in the third quarter highlight a continuum of concern related to two broad themes for enterprises that emerged in the second quarter: A volatile low-growth macroeconomic environment, and AI as the disruptive technology that can increase compliance risks quickly as it is adopted by the mainstream,” said Gamika Takkar, Director, Research, in the Gartner Risk & Audit Practice.
Figure 1: Top Emerging Risks of Q3 2025
![[Image Alt Text for SEO]](https://emt.gartnerweb.com/ngw/globalassets/en/newsroom/images/graphs/2025-11-06-top-emerging-risks-q325.png)
Source: Gartner (November 2025)
Navigating Complex Emerging Risk Signals
“Amid varying emerging risk signals, heads of ERM should prioritize tactics to identify emerging risks that require immediate stakeholder attention for timely response,” said Takkar.
To effectively recognize risks that need immediate attention, risk leaders should take these three steps to fully evaluate the impact and prioritize response:
- Set up impact thresholds using diverse parameters. Assess diverse impact parameters, including regulatory, reputational and ESG dimensions to shortlist high-priority emerging risks.
- Link emerging risks with strategic priorities. Analyze how emerging risks impact strategic priorities to facilitate targeted action steps that prevent must-avoid outcomes (MAOs).
- Use response time with impact and velocity. Factor in organizational response time along with impact and velocity to prioritize emerging risks.
“Enabling ERM leaders to navigate the noise and identify risks that require timely action is top of mind for any enterprise,” said Takkar. “To make sense of conflicting signals, leaders must be cognizant of risk prioritization tactics and ensure timely stakeholder to avoid strategic derailment.”
Gartner clients can access the study at 3Q25 Emerging Risk Report. Nonclients can read: Top Emerging Risk Trends Report.










