- GRC
- 7th Aug 2026
- 1 min read
TEISS London 2026: GRC, AI Governance and Resilience Themes
- Written by
In Short...
- AI governance sits on the board risk register now: Regulators expect proof of control, ready on demand.
- Operational resilience has moved from documentation to demonstration: The FCA and PRA's March 2025 deadline was only the starting line.
- Third-party risk management needs to run continuously: Annual questionnaires miss the incidents that happen between assessments.
- Board reporting has to connect risk to financial consequence: Heat maps and RAG statuses rarely lead anywhere near a decision.
TEISS London 2026 sharpened four themes now shaping the GRC, cyber and resilience agenda: AI governance as a board-level risk, operational resilience that has to be demonstrated rather than documented, third-party risk management that runs continuously rather than annually, and cyber risk reporting that connects directly to board decisions. This briefing sets out why each theme matters now, plus the questions worth carrying into your next vendor or peer conversation.
Expert View
|
Matt Davies Chief Product Officer, SureCloud |
What our experts say about proving AI governance to regulators
"Most AI governance programmes fail on exactly the same detail: nobody can produce the audit trail on demand. We built Gracie’s reasoning logs so every decision stays timestamped and explainable, ready the moment a regulator actually asks." |
What Is TEISS London 2026?
TEISS, the European Information Security Summit, is one of the UK's leading annual gatherings for cyber security and risk leaders. The 2026 edition took place on 26 February at Convene 155 Bishopsgate in London's financial district, bringing together more than 400 CISOs, risk managers, compliance professionals and technology leaders for a full day of sessions, roundtables and peer exchange.
The agenda ran across three streams: CISO and Leadership, Culture and Education, and Threat Landscape. The themes that generated the most discussion cut across all three: how to govern AI responsibly, how to move from resilience planning to resilience execution, and how to give the board a risk picture that actually means something. More detail on SureCloud’s sessions and roundtables at the event is on the TEISS London 2026 page. What follows is our read on the four issues that defined this year’s event, drawn from the published TEISS London 2026 agenda and the conversations it generated.
Why TEISS Matters for GRC, Cyber and Resilience Leaders
TEISS runs as a peer forum rather than a product expo, and that distinction shapes its value. The real insight comes from hearing how other organisations navigate the same pressures: regulatory deadlines that don't move, boards that want clearer risk data, and AI tools proliferating faster than governance frameworks can keep pace.
The 2026 regulatory backdrop makes those pressures concrete. DORA (the EU's Digital Operational Resilience Act) is in its first full year of enforcement. NIS2 (the EU's second Network and Information Security Directive) has driven the UK's own Cyber Security and Resilience Bill through Parliament, with Royal Assent expected later in 2026.
The EU AI Act is phasing in through 2027, and the Financial Conduct Authority (FCA) issued £15.7 million in fines in the first quarter of 2026 alone. For regulated organisations, this pressure has already arrived.
SureCloud's own research puts the pressure in numbers: 49% of enterprises now manage five or more major regulatory frameworks at once, and 63% cite internal skills gaps as the main barrier to keeping pace. That's the environment TEISS operates in, and it's why conversations there tend to run more candid than a vendor briefing room.
Theme 1: AI Governance Becomes a Board-Level Risk
A year ago, AI governance sat with the technology team. Today it sits on board risk registers in regulated industries, and the shift has moved faster than most governance frameworks anticipated.
The reason is straightforward: organisations are deploying AI at pace, often without the controls, audit trails or oversight mechanisms regulators expect to see. The EU AI Act is phasing in through 2027. ISO/IEC 42001:2023, the international management-system standard for AI, gives boards a benchmark to measure against.
The FCA and Prudential Regulation Authority (PRA) have both signalled that AI in financial services faces increasing scrutiny. Boards used to ask whether the business was using AI; now they're asking whether they can prove it's being used responsibly.
What Good AI Governance Actually Requires
The gap between having an AI policy and running an auditable AI governance programme is significant. Effective AI governance for regulated teams means:
- Risk classification: identifying which AI systems carry high, limited or minimal risk under the EU AI Act framework
- Immutable audit trails: every AI decision or action logged, timestamped and locked against edits
- Human-in-the-loop controls: defined escalation points where people review outputs before they're acted on
- Evidence for regulators: documentation ready on demand, rather than reconstructed after the fact
- Framework alignment: ISO/IEC 42001, the NIST AI Risk Management Framework, and sector guidance from the FCA or PRA
The organisations that struggled most in TEISS discussions treated AI governance as a policy exercise. The ones ahead of the curve had operationalised it: controls mapped, evidence collected, oversight built into daily workflows. SureCloud's AI governance product gives risk and compliance teams a structured register for exactly this: every AI use case classified, assessed and connected to the wider GRC programme. AI governance as the emerging board-level risk goes deeper into why this shift happened so fast.
Theme 2: Operational Resilience Moves from Compliance to Execution
Most regulated organisations have a resilience framework in place. Far fewer have tested whether it holds up under real pressure.
The FCA and PRA set a 31 March 2025 deadline for operational resilience, and many firms treated that milestone as the finish line. The regulators saw it differently: mapping important business services, setting impact tolerances and producing scenario test evidence marked the starting point of an ongoing obligation. The real test now is whether those plans hold when something actually goes wrong.
The Gap Between Planning and Execution
The pattern resilience teams describe most consistently is thorough documentation paired with fragile operational capability. Plans exist in silos. Incident response sits apart from business continuity. Third-party dependencies get mapped in one system, controls tested in another, and board reports assembled by hand from both.
The execution gap is where resilience actually fails. Most teams understand the requirements; what's usually missing is the infrastructure to deliver on them continuously. For financial services firms, DORA raises the bar further. ICT incident classification, third-party ICT risk management and mandatory reporting timelines all demand a level of operational integration that spreadsheets and disconnected tools can't support.
The shift in this year's TEISS conversations moved from ‘have we documented our resilience?’ to ‘can we demonstrate it?’ That's a different question, and it needs different tooling. SureCloud's operational resilience product connects plans, incidents, controls and board reporting in one system, so the answer stops depending on a scramble across five disconnected tools.
Theme 3: Third-Party Risk Becomes Continuous
Third-party risk management has featured at every TEISS for the past five years. What changed in 2026 is the expectation attached to the word 'managed.'
The old model ran on a fixed cycle: send an annual questionnaire, review the responses, file the evidence, repeat. That approach always had limits, and those limits have hardened into a genuine gap. Regulators under DORA, NIS2 and the UK's own Cyber Security and Resilience Bill increasingly expect third-party risk management to run continuously, tracked in real time rather than refreshed once a year.
The Case for Continuous Assessment
Supply chains run longer and more complex than they did five years ago. A single critical supplier can carry dozens of sub-processors. A vendor that passed an assessment in the first quarter may have had a material incident, a change in ownership or a serious control failure by the third. Annual questionnaires miss all of that.
But the organisations making real progress on continuous third-party risk management share a few habits:
- Tiered supplier programmes: scrutiny scales with criticality and access, so high-risk, high-access suppliers get continuous monitoring while lower-risk vendors get proportionate assessment
- Automated evidence collection: controls get tested on a rolling basis rather than reconstructed for audit season
- Connected risk data: supplier risk sits alongside internal risk in the same system
- Faster onboarding: quicker assessments let programmes scale without matching headcount growth
The TEISS Threat Landscape stream flagged SaaS supply chain security as one of the most pressing attack vectors in 2026, and that tracks: third-party exposure is exactly where attackers look. SureCloud's third-party risk management product closes that gap with 50% faster vendor risk assessments and supplier risk visible alongside everything else on the risk register. The programmes still catching up are the ones treating third-party risk as an annual filing exercise rather than a live feed.
Theme 4: Cyber Risk Reporting Needs Stronger Business Context
Boards are asking their cyber and risk teams for more, and mostly getting more of the same: heat maps, RAG statuses and technical metrics that don't translate into business decisions.
The TEISS CISO and Leadership stream addressed this head-on: most GRC (governance, risk and compliance) teams already have plenty of data. The real challenge is translating that data into language a board can act on: financial exposure, operational impact, regulatory consequence.
What Board-Ready Risk Reporting Actually Looks Like
The gap between a risk register and a board report is significant. A genuine board report answers three questions:
1. What are our most material risks right now? A prioritised view of the risks most likely to hurt the business.
2. What's changed since last time? Boards need to track how the risk posture moves over time.
3. What decisions do we need to make? Reporting that leads to a decision earns board time.
The data point that lands hardest in board conversations: the global average cost of a data breach reached $4.44 million in 2025, according to IBM's Cost of a Data Breach Report. A financial figure. It connects risk to consequence in a way a heat map never does.
SureCloud customers making real progress on board reporting have moved away from manual consolidation: board reports that used to take two weeks to assemble now come together in about two days when risk data stays connected, current and held in a single system. The real gain shows up in the quality and timeliness of what the board actually sees.
Questions Worth Taking to Vendors and Peers
TEISS delivered its value in the specific questions attendees carried into vendor conversations and peer roundtables. The four themes above translate into a clear set of things worth probing wherever those conversations happen next.
Questions for Vendor Conversations
- AI governance: Can you show a live demonstration of the immutable audit trail behind a single AI decision?
- Operational resilience: How does your platform connect incident response to business continuity, and how does that feed into board reporting?
- Third-party risk: How do you support continuous monitoring of suppliers, and what does a tiered programme look like in practice?
- Cyber risk reporting: Can you produce a board-ready risk report from live data, and how long does that take?
- Evidence and audit: If a regulator asked for evidence of control effectiveness tomorrow, how quickly could you produce it?
Questions for Peer Conversations
Peer conversations at TEISS are often where the most useful intelligence comes from. Worth asking:
- How are you handling AI governance day to day, beyond the policy documents?
- What's your biggest operational resilience gap right now?
- Have you moved to continuous third-party risk management, and if so, what did it take?
- What does your board actually find useful in your risk reporting?
The answers you get will run more candid than anything in a vendor session, and they'll show you where the real execution gaps sit across the industry.
Put These Themes Into Practice
FAQ’s
What is TEISS London 2026?
TEISS London 2026, the European Information Security Summit, was a one-day UK gathering for cyber, risk, compliance and resilience leaders, held on 26 February 2026 at Convene 155 Bishopsgate in London. More than 400 CISOs, risk managers and compliance professionals attended, and the themes it surfaced, AI governance, operational resilience, third-party risk and board reporting, continue to shape GRC programmes for the rest of the year.
Why does TEISS matter to GRC teams?
TEISS is one of the few UK forums where GRC, cyber and resilience leaders compare notes candidly, away from a vendor sales pitch. That candour is what surfaces which tools and approaches actually work in practice, rather than what looks polished in a product demo.
What were the biggest themes at TEISS London 2026?
The biggest themes were AI governance, operational resilience, continuous third-party risk management and clearer cyber risk reporting. Together they reflect a shift from policy and planning toward connected, auditable execution across regulated teams.
What should GRC teams do with the TEISS London 2026 takeaways?
Treat the four themes as a working checklist for the rest of the year: audit-ready AI governance, demonstrable operational resilience, continuous third-party risk management and board reporting that leads to a decision. The vendor and peer questions in this piece work just as well outside the event, in any procurement or peer conversation.
Why is operational resilience such a key theme this year?
Operational resilience now means demonstrating, with evidence, that critical services hold up under pressure. That requires connecting incident response, business continuity, third-party dependencies and reporting within a single operating model.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
1 Sherwood Street, London, W1F 7BL, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.
