#RISK Expo Europe video showcase-low

#RISK Expo Europe

Secure Your Place at Europe’s Leading Risk, GRC, Security & RegTech Expo.

10-11 November 2026, Excel London

Register & Save the Date

 

#RISK Expo Europe — Europe's Leading Risk, GRC, Security & RegTech Expo
10–11 November 2026 · ExCeL London

Risk. It's everyone's business.

Europe's Leading Risk, GRC, Security & RegTech Expo. Two days for CROs, CISOs, heads of compliance, audit and resilience to work through what the EU AI Act, DORA and NIS2 actually mean for their organisation — and what peers across financial services and beyond are doing about it.

5,000 attendees 50 content streams 100 exhibitors 3 stages 10 workshops
On the agenda
EU AI Act DORA NIS2 Operational resilience AI-enabled GRC Third-party & supply chain risk Zero Trust in practice Financial crime & fraud Board-level risk reporting Geopolitical risk Consumer Duty & culture Supply chain risk Insider risk ESG & climate risk Three Lines of Defence Executive accountability Quantifying risk in financial terms
5,000+
Attendees
50+
Content streams
100+
Exhibitors
3
Stages — Risk, BFSI, GRC
10+
Workshops
Who's in the room

Built for the people who own risk, not just those who report on it.

The floor and stages are set up for cross-functional attendance — risk is rarely owned by one desk, so the agenda isn't built for one either.

01BFSI leadership
02Cyber, IT & security
03GRC & risk management
04CEOs, CFOs & MDs
05Internal audit
06RegTech & policy
07Financial crime prevention
08AI & digital transformation
The agenda Themes

Three stages. One set of problems, seen from every angle.

Sessions are shaped by practitioners, not vendors — built to be useful whether you're setting the risk appetite or defending against the next incident.

BFSI Stage

Financial services risk, in practice

  • Beyond Basel: next-generation risk management for BFSI leaders
  • DORA, NIS2 and beyond: operational resilience obligations for banks and insurers
  • AI in the Three Lines of Defence: automating risk, audit and compliance
  • Cyber, fraud and financial crime: building a unified defence stack
GRC Stage

Governance without the silos

  • Designing a connected GRC framework across governance, risk and compliance
  • AI-enabled GRC: use cases, limits and guardrails
  • Board-ready GRC: reporting, metrics and storytelling that drive action
  • Third-party risk, TPRM and supply chain assurance in a volatile world
Risk Stage

Risk, as its own discipline

  • Zero Trust in practice: governance, architecture and assurance
  • Geopolitical risk: building resilience into strategy, not just contingency plans
  • Supply chain risk: visibility, concentration and the limits of due diligence
  • Insider risk: managing trust, access and behaviour without a surveillance culture
Spotlight

Inside the Risk Stage

Enterprise risk, treated as its own discipline — from board accountability to the numbers that back it up.

Zero Trust in Practice

Zero Trust is widely adopted as a principle, less consistently delivered as an architecture. This session moves past the terminology to examine what genuine implementation requires in governance, architecture and ongoing assurance terms.

Geopolitical Risk

Geopolitical shocks used to sit in the contingency plan, reviewed once a year and rarely touched. This session examines how risk leaders are moving geopolitical risk into core strategic planning, so trade tensions, sanctions regimes and regional instability inform decisions before disruption forces the issue.

Supply Chain Risk

Most supply chain risk programmes stop at tier one, yet the exposures that cause real damage often sit two or three tiers further down. This session looks at how organisations are building genuine visibility into extended supply chains, and where due diligence still falls short.

Insider Risk

Insider risk sits awkwardly between security, HR and legal, and few organisations have a single owner for it. This session considers how leaders are building programmes that address malicious and negligent behaviour alike, without tipping into monitoring that damages trust and morale.

Executive Accountability

Personal liability for risk and security leaders is no longer a niche concern raised at renewal time. This session examines how CROs and CISOs are pushing for clearer board-level accountability, better indemnity provision and genuine decision-making authority.

Quantifying Risk in Financial Terms

Risk registers scored on red-amber-green scales rarely survive contact with a board focused on capital allocation. This session looks at how risk leaders are moving toward financial quantification, and what that shift demands of the data and modelling behind it.

Why now

The regulatory calendar isn't waiting for your roadmap.

Four themes are running through nearly every session this year — worth knowing where your organisation stands on each before you arrive.

EU AI Act

Enforcement is underway. Sessions cover what's actually being asked of risk and compliance functions now that obligations have taken effect.

DORA & NIS2

Operational resilience and third-party oversight obligations for financial services and critical infrastructure, and how teams are evidencing compliance.

Three Lines of Defence

How AI is reshaping the model itself — where automation genuinely reduces risk, and where it just moves it somewhere less visible.

Operational resilience

Moving from incident response plans on paper to tested, board-owned resilience that holds up under an actual disruption.

AI-enabled GRC

Where platforms are delivering real efficiency in audit, risk and compliance workflows, and where the guardrails still need work.

Third-party & supply chain risk

Concentration risk, vendor assurance and continuous oversight, as estates get more distributed and less visible.

Risk, compliance and security leaders joining us this year include those from
Google BP Bank of England NHS HSBC Sky BBC Santander Aon Amazon Lloyds Bank Heathrow Shell Barclays America Express Arsenal FC Netflix Ministry of Justice Meta

A sample of confirmed registrations — the full delegate list continues to grow ahead of November.

Secure Your Place at #RISK Expo Europe, ExCeL London

Free to attend for qualifying risk, compliance, security, audit and governance professionals. Places for the November event are limited by venue capacity.

Register your place

Previous Speakers

Stefan Gershater Head of Risk and Governance, Co-op
Joe Tidy, BBC Cyber Correspondent
Derek Leatherdale Geopolitical Risk Adviser, Sibyline (1)
Jesse Tayler, Founder & CTO of TruAnon, Inventor of the App Store
Fergus Hay, CEO and Co-Founder, The Hacking Games
Michael Rasmussen GRC Analyst & Pundit, GRC 2020, “Father of GRC”
Eric Alter
Nish Imthiyaz, Global Legal Counsel – Privacy, AI, and Digital Regulations, Vodafone
Gayle Sparkes, Head of Conduct and Compliance Risk Insights, MD, NatWest
Michael Colao Former Global Chief Underwriting Officer - Direct and Indirect Cyber Risks, AXA XL, a division of AXA
Sharon Sharples  Director, Group Operational Risk & Risk Oversight Chief of Staff, Barclays
Prof. Markus Krebsz United Nations
Speakers

Stefan Gershater

(Head of Risk and Governance, Co-op): Sharing his highly strategic, military-trained approach to risk management and providing insights following the recent high-profile operational challenges faced by the Co-op.

Speakers

Joe Tidy

Joe Tidy, BBC News Cyber Correspondent & Author - The investigative journalist who speaks directly to the hackers.

Speakers

Derek Leatherdale

Senior Geopolitical Risk Adviser, Sibylline

Speakers

Jesse Tayler

(Founder & CTO of TruAnon, Inventor of the App Store): Offering a unique perspective on fraud, technology, and building security into innovation.

Speakers

Fergus Hay

Fergus Hay (CEO and Co-Founder, The Hacking Games): Leading the charge to combat the $10.5 trillion cybercrime threat by sharing his mission to inspire a new generation of ethical hacking talent and discussing the intersection of media, talent, and cyber defense.

Speakers

Michael Rasmussen

(GRC Analyst & Pundit, GRC 20/20): Known as the “Father of GRC,” he will set the strategic roadmap for governance in the age of AI.

Speakers

Eric Alter

(Senior Vice President – Cyber/AI Engagement Leader, Marsh Corporate & Commercial): Discussing the future of cyber risk insurance and mitigating AI liability.

Speakers

Nish Imthiyaz

(Global Legal Counsel – Privacy, AI, and Digital Regulations, Vodafone): Offering expert legal guidance on navigating the convergence of Privacy and the EU AI Act.

Speakers

Gayle Sparkes

(Head of Conduct and Compliance Risk Insights, MD, NatWest): Sharing practical strategies for embedding compliance culture and managing conduct risk.

Speakers

Michael Colao

Former Global Chief Underwriting Officer - Direct and Indirect Cyber Risks, AXA XL, a division of AXA

Speakers

Sharon Sharples

Director, Group Operational Risk & Risk Oversight Chief of Staff, Barclays): Providing senior-level insight into building genuine operational resilience.

Speakers

Prof. Markus Krebsz

United Nations/UNECE, Project lead for AI and other digital technologies / 
The Human AI Institute, Founding Director

Overview of #RISK Expo Europe

#RISK Expo Europe is a large Governance, Risk and Compliance (GRC) and risk‑management trade show at ExCeL London, featuring around 100–120 exhibitors, 200–300 speakers and multiple themed stages, and attracting a cross‑functional audience of risk, compliance, cyber, audit and ESG professionals from across Europe.

Types of companies that typically exhibit

Public exhibitor and sponsor lists show that the event mainly features:

  1. GRC and integrated risk‑management software vendors.
  2. Cybersecurity, threat‑management and ransomware‑prevention providers.
  3. RegTech, data‑protection and privacy‑technology companies.
  4. ESG, sustainability and climate‑risk or resilience‑analytics providers.
  5. Professional services, audit, certification and assurance firms focused on risk, governance and compliance.

These organisations are generally targeting buyers in regulated or risk‑intensive sectors such as financial services, insurance, energy, healthcare, and large corporates with formal risk and compliance functions.

Main problems it helps address

Agenda themes, association listings and exhibitor write‑ups consistently centre on the following problem areas:

  • Fragmented risk and compliance activities spread across GRC, security, ESG, legal, audit and supply‑chain teams.
  • Keeping up with regulatory change in areas such as data protection, financial crime, AI governance and ESG reporting.
  • Managing interconnected risks across cyber, third‑party and supply‑chain risk, operational resilience, climate and culture.
  • Developing risk and compliance capabilities that support wider organisational resilience and strategic decision‑making.

For exhibitors, the event provides concentrated access over two days to senior decision‑makers and practitioners involved in buying or influencing GRC, cyber, ESG and related risk solutions.

What differentiates #RISK Expo Europe from other events?

Several features distinguish #RISK Expo Europe from narrower or purely conference‑style risk events:

  1. Broad thematic scope: governance, enterprise risk, compliance, privacy, cyber, AI governance, ESG and supply‑chain risk are all covered within one combined programme.
  2. Exhibition‑led format: a sizeable trade‑show floor with around 100–120 exhibitors sits alongside multi‑track content stages and workshops, rather than a small tabletop expo attached to a conference.
  3. Cross‑functional audience: attendee descriptions emphasise participation from CEOs, CROs, CISOs, compliance leads, privacy officers, ESG leaders, auditors and data‑governance professionals, giving exhibitors access to multi‑stakeholder buying groups.
  4. Pan‑European focus: the evolution from #RISK London to #RISK Europe, the ExCeL London location and partnerships with European GRC associations support a reach that extends beyond the UK market.
  5. Integration into a larger portfolio:#RISK Expo Europe forms part of the #RISK Series and the GRC World Forums/Emerald portfolio, which also includes regional and thematic risk events, awards and digital channels.

Situations where #RISK Expo Europe is a particularly good fit

Public information and attendee/exhibitor commentary suggest the event is a strong fit in the following situations:

  • Vendors of GRC, cyber, RegTech, ESG or assurance solutions seeking to engage cross‑functional buying groups that span risk, compliance, security, legal and ESG.
  • Organisations that rely on thought leadership, case studies or education about newer risk domains (for example AI governance, climate risk, supply‑chain resilience or integrated risk) as part of their sales process.
  • Teams looking for exposure to risk leaders from multiple European jurisdictions at a single, English‑language event.
  • Exhibitors that want to combine in‑person conversations with ongoing visibility via a family of related events and media targeting the same risk community.

Commonly cited strengths and limitations

Strengths that appear repeatedly in public descriptions include:

  1. Wide coverage of risk‑related topics, with a relatively large number of stages and speakers.
  2. Access to a sizeable audience of senior GRC, cyber, compliance, audit and ESG professionals.
  3. Opportunities to meet stakeholders from different risk disciplines in one place rather than at separate vertical events.

Limitations that potential exhibitors may want to consider based on the same information include:

  1. The breadth of the agenda can mean less technical depth for highly specialised niches than at focused, single‑topic conferences.
  2. A busy exhibition floor with many vendors can make outcomes more dependent on pre‑event targeting, stand visibility and clear messaging than at smaller meetings.

GRCWF Ticket Tailor Headers

#RISK Expo Europe, 10-11 November 2026, Excel London - Europe’s leading Risk, GRC, Security & RegTech Expo.