Risk management

In an external environment defined by geopolitical crises, persistent economic uncertainty and the rapid advancement and adoption of generative AI, our risk landscape is changing.

Internally, we are adapting our services and operating models to harness AI-driven capabilities, shifting a greater proportion of our delivery to global delivery networks. 

These combined external and internal developments accelerate the pace of change, introduce new interdependencies and create subsequent legal, regulatory, operational and reputational risks. Against this backdrop, a robust, forward-looking and adaptive risk management framework is essential to protect our brand, preserve the continuity of our service delivery and enable responsible innovation.

To navigate this complexity effectively, we have risk management capability in place, centrally captured in our Enterprise Risk Management Framework. Our risk management capability is forward-looking and increasingly fuelled by an “expect the unexpected” mindset. This proactive stance ensures that we are prepared to act on emerging risks and seize opportunities that may arise in this ever-changing environment.

We place significant emphasis on our crisis management and business continuity management capabilities. This ISO-certified capability is crucial in equipping us to respond effectively to unforeseen events, thereby minimizing the potential impact of disruptions and ensuring the continuity of our operations and service delivery.

Risk governance

Risk is deeply integrated within our overall governance framework. The primary responsibility for identifying and managing risks remains with line management, the Executive Committee and ultimately the Executive Board, under the oversight of our Supervisory Board.

Designated risk owners and business risk leaders are accountable for implementing comprehensive risk mitigation plans and for the ongoing management of risks within their areas of expertise and businesses.

The Risk & Reputation Leader (RRL), who is part of our Executive Committee and reports directly to the CQRO, holds day-to-day responsibility for the overarching quality control system for risk management and reporting. Within the Office of the RRL the following capabilities are centred in five RRL sub-departments that are being led by RRL team leads: Independence (Firm and Personal), Client and Engagement Acceptance, Ethics, Conduct & Risk, and Confidentiality, Privacy & Security.

The RRL has a seat on the Risk & Reputation Executive, chaired by the CQRO. This Executive brings together all relevant risk roles and convenes to align material risk themes, control effectiveness and emerging issues.

The Risk & Reputation Executive works closely with business risk leaders to ensure all intelligence and assessments are grounded in operational realities and to challenge and validate the effectiveness of key controls.

Activities in 2025/2026

During 2025/2026, we performed an exercise to centrally identify our key controls. All key controls are captured in our Risk Mitigation and Assurance Map, including key control details such as risk appetite, desired level of assurance, lines of defence, main risks and operating effectiveness. This updated Risk Mitigation and Assurance Map forms the basis for our Statement on Risk Management (“Verklaring Omtrent Risicobeheersing”).

As part of our reporting cadence, we provide quarterly consolidated reporting to the Risk & Reputation Executive that captures all relevant trends and themes from across the entire organisation, including both our Businesses and Enabling Functions. This consolidated view is significantly enhanced to brief our Executive Board and Supervisory Board on what to expect, enabling timely strategic and governance decisions. The Risk & Reputation Executive works closely with business risk leaders and the RRL to ensure that intelligence and assessments are grounded in operational realities and to challenge and validate the effectiveness of key controls.

This year we also further explored the concept of integrating conduct risk into our risk management capability. By closely monitoring trends and themes in a selection of conduct risk drivers, we are able to intervene where needed. Furthermore, we ensured that our sustainability risks are sufficiently addressed by our Risk Management approach.

Priority Business Risks

We continually update and reassess our Priority Business Risks through Risk & Reputation Executive reporting and use input from both DTTL and NSE to challenge our thinking.

Based on the periodic reassessment, we have identified priority business risks and opportunities related to our strategy (see the risk radar below). Current exposure (or residual risk) is defined as the likelihood of a risk materializing and its expected impact given our current ability to mitigate that risk. It is assessed on a scale from “medium” (green) to “very high” (red), taking both residual impact and residual likelihood into account.

The current “top of mind” themes - such as economic and geopolitical unpredictability, including subsequent growth outlook; the exponential growth of Gen-AI; and the volume and pace of internal change and conduct - are integrated into our priority business risks in the risk radar. Most of the risks in which these themes have been integrated have the highest exposure.

In the following table, the risks assessed with a high-risk rating are shown. The risks associated with the employment of financial instruments are described in Note 5 of the Financial Statements.

Risk

Risk description

Risk area*

Risk appetite**

Mitigating measures

Ability to adapt and deliver future changes

Failure to adapt and deliver our transformation agenda

Strategic, Operational

Medium: Deloitte is committed to successfully deliver transformation

Pages 4-9

Advisory delivery & risk management

Failure to prevent systemic or major failure of advisory quality.

Strategic, Operational

Low: Deloitte is committed to high quality execution

Pages 141-142

Conduct & Ethics

Failure to establish, embed and sustain an inclusive and ethical culture.

Strategic, Operational

Low: Deloitte is committed to our shared values and strives to limit ethical breaches

Pages 143-146

Confidentiality, privacy & security

Failure to manage data security and privacy.

Operational, Laws & regulations

Low: Deloitte is committed to preventing, being prepared for and responding to breaches and data loss in a timely fashion

Pages 147-148

Economic, geopolitical and competitor moves

Failure to anticipate, adapt to and respond to changes in the economic-, geopolitical- and competitor- landscape

Strategic, Operational, Financial

Medium: Deloitte is committed to (pro-)actively respond to economic-, geopolitical- and competitor driven changes

Pages 4-9

Gen AI and digital transformation

Failure to succesfully execute the digital (incl AI) transformation

Strategic, Operational

Medium: Deloitte is committed to embed AI and new technologies in the internal operations and external service delivery.

Pages 139-140

Our role & future public-interest impact

Failure to anticipate, adapt to and respond to external scrutiny, criticism and regulation.

Strategic, Operational

Low: Deloitte is committed to making an impact that matters on our clients and society

Pages 10-11, 141-142

People & Culture

Failure to attract, develop and retain high-performing and diverse professionals and world-class leaders.

Operational, Financial

Low: Deloitte is committed to employing top class personnel through agile talent models.

Pages 115-139

*The risks in the table above can be categorized in more than one of the four impact areas that we identify (see the risk radar above). For the sake of simplicity, we have placed them in the category that we deem most appropriate.

**Risk appetite is operationally translated in our Risk Mitigation & Assurance Map to monitor exposure and act if needed.

*** Next to Advisory delivery and risk management, audit quality remains a continued focus area.

Our ERF helps us maintain control, have the right information available, comply with applicable laws and regulations and meet our own high-quality standards. The Executive Board evaluated the design and operation of these systems and reviewed the findings. No significant weaknesses were identified that could have led to material losses or impact.  Where controls showed a need for improvement, remedial plans were formalised and monitored. However, because of inherent limitations and factors outside the Group’s control, this evaluation cannot provide absolute certainty that all material risks are being identified or mitigated at all times. Based on the entire system of quality controls and the assessment made, the Executive Board is able to state the following:

Statement on Risk Management

  1. The report provides sufficient insights into the effectiveness of the internal risk management and control systems;

  2. The aforementioned systems provide reasonable assurance that the financial reporting does not contain any material inaccuracies;

  3. Based on the current state of affairs, it is justified that the financial reporting is prepared on a going concern basis; and

  4. The report outlines the material risks and uncertainties that are relevant to the expectation of the company’s continuity for the period of twelve months after its preparation.

  5. Deloitte is not aware that aforementioned internal risk management and control systems, as specifically described in this Risk management paragraph, do not provide sufficient comfort that identified operational and compliance risks are effectively managed as per May 31, 2026 considering our risk appetite, complexity of our structure and inherent limitations to these systems and other disclosures on these systems as noted in our management report.

  6. The systems and procedures for our sustainability reporting as described in the Sustainability statement and Annex 3 of this report (Basis of reporting) are effective and provide limited assurance that the sustainability reporting does not contain material inaccuracies.

Rotterdam, July 16, 2026

Hans Honig, CEO

Dagmar Enklaar, COO

Jamie Gatt, CQRO