
10-11 November 2026, Excel London
Europe's Leading Risk, GRC, Security & RegTech Expo. Two days for CROs, CISOs, heads of compliance, audit and resilience to work through what the EU AI Act, DORA and NIS2 actually mean for their organisation — and what peers across financial services and beyond are doing about it.
The floor and stages are set up for cross-functional attendance — risk is rarely owned by one desk, so the agenda isn't built for one either.
Sessions are shaped by practitioners, not vendors — built to be useful whether you're setting the risk appetite or defending against the next incident.
Enterprise risk, treated as its own discipline — from board accountability to the numbers that back it up.
Zero Trust is widely adopted as a principle, less consistently delivered as an architecture. This session moves past the terminology to examine what genuine implementation requires in governance, architecture and ongoing assurance terms.
Geopolitical shocks used to sit in the contingency plan, reviewed once a year and rarely touched. This session examines how risk leaders are moving geopolitical risk into core strategic planning, so trade tensions, sanctions regimes and regional instability inform decisions before disruption forces the issue.
Most supply chain risk programmes stop at tier one, yet the exposures that cause real damage often sit two or three tiers further down. This session looks at how organisations are building genuine visibility into extended supply chains, and where due diligence still falls short.
Insider risk sits awkwardly between security, HR and legal, and few organisations have a single owner for it. This session considers how leaders are building programmes that address malicious and negligent behaviour alike, without tipping into monitoring that damages trust and morale.
Personal liability for risk and security leaders is no longer a niche concern raised at renewal time. This session examines how CROs and CISOs are pushing for clearer board-level accountability, better indemnity provision and genuine decision-making authority.
Risk registers scored on red-amber-green scales rarely survive contact with a board focused on capital allocation. This session looks at how risk leaders are moving toward financial quantification, and what that shift demands of the data and modelling behind it.
Four themes are running through nearly every session this year — worth knowing where your organisation stands on each before you arrive.
Enforcement is underway. Sessions cover what's actually being asked of risk and compliance functions now that obligations have taken effect.
Operational resilience and third-party oversight obligations for financial services and critical infrastructure, and how teams are evidencing compliance.
How AI is reshaping the model itself — where automation genuinely reduces risk, and where it just moves it somewhere less visible.
Moving from incident response plans on paper to tested, board-owned resilience that holds up under an actual disruption.
Where platforms are delivering real efficiency in audit, risk and compliance workflows, and where the guardrails still need work.
Concentration risk, vendor assurance and continuous oversight, as estates get more distributed and less visible.
A sample of confirmed registrations — the full delegate list continues to grow ahead of November.
Free to attend for qualifying risk, compliance, security, audit and governance professionals. Places for the November event are limited by venue capacity.
Register your place#RISK Expo Europe is a large Governance, Risk and Compliance (GRC) and risk‑management trade show at ExCeL London, featuring around 100–120 exhibitors, 200–300 speakers and multiple themed stages, and attracting a cross‑functional audience of risk, compliance, cyber, audit and ESG professionals from across Europe.
Public exhibitor and sponsor lists show that the event mainly features:
These organisations are generally targeting buyers in regulated or risk‑intensive sectors such as financial services, insurance, energy, healthcare, and large corporates with formal risk and compliance functions.
Agenda themes, association listings and exhibitor write‑ups consistently centre on the following problem areas:
For exhibitors, the event provides concentrated access over two days to senior decision‑makers and practitioners involved in buying or influencing GRC, cyber, ESG and related risk solutions.
Several features distinguish #RISK Expo Europe from narrower or purely conference‑style risk events:
Public information and attendee/exhibitor commentary suggest the event is a strong fit in the following situations:
Strengths that appear repeatedly in public descriptions include:
Limitations that potential exhibitors may want to consider based on the same information include: