Risk management
In an external environment defined by geopolitical crises, persistent economic uncertainty and the rapid advancement and adoption of generative AI, our risk landscape is changing.
Internally, we are adapting our services and operating models to harness AI-driven capabilities, shifting a greater proportion of our delivery to global delivery networks.
These combined external and internal developments accelerate the pace of change, introduce new interdependencies and create subsequent legal, regulatory, operational and reputational risks. Against this backdrop, a robust, forward-looking and adaptive risk management framework is essential to protect our brand, preserve the continuity of our service delivery and enable responsible innovation.
To navigate this complexity effectively, we have risk management capability in place, centrally captured in our Enterprise Risk Management Framework. Our risk management capability is forward-looking and increasingly fuelled by an “expect the unexpected” mindset. This proactive stance ensures that we are prepared to act on emerging risks and seize opportunities that may arise in this ever-changing environment.
We place significant emphasis on our crisis management and business continuity management capabilities. This ISO-certified capability is crucial in equipping us to respond effectively to unforeseen events, thereby minimizing the potential impact of disruptions and ensuring the continuity of our operations and service delivery.
Risk governance
Risk is deeply integrated within our overall governance framework. The primary responsibility for identifying and managing risks remains with line management, the Executive Committee and ultimately the Executive Board, under the oversight of our Supervisory Board.
Designated risk owners and business risk leaders are accountable for implementing comprehensive risk mitigation plans and for the ongoing management of risks within their areas of expertise and businesses.
The Risk & Reputation Leader (RRL), who is part of our Executive Committee and reports directly to the CQRO, holds day-to-day responsibility for the overarching quality control system for risk management and reporting. Within the Office of the RRL the following capabilities are centred in five RRL sub-departments that are being led by RRL team leads: Independence (Firm and Personal), Client and Engagement Acceptance, Ethics, Conduct & Risk, and Confidentiality, Privacy & Security.
The RRL has a seat on the Risk & Reputation Executive, chaired by the CQRO. This Executive brings together all relevant risk roles and convenes to align material risk themes, control effectiveness and emerging issues.
The Risk & Reputation Executive works closely with business risk leaders to ensure all intelligence and assessments are grounded in operational realities and to challenge and validate the effectiveness of key controls.
Activities in 2025/2026
During 2025/2026, we performed an exercise to centrally identify our key controls. All key controls are captured in our Risk Mitigation and Assurance Map, including key control details such as risk appetite, desired level of assurance, lines of defence, main risks and operating effectiveness. This updated Risk Mitigation and Assurance Map forms the basis for our Statement on Risk Management (“Verklaring Omtrent Risicobeheersing”).
As part of our reporting cadence, we provide quarterly consolidated reporting to the Risk & Reputation Executive that captures all relevant trends and themes from across the entire organisation, including both our Businesses and Enabling Functions. This consolidated view is significantly enhanced to brief our Executive Board and Supervisory Board on what to expect, enabling timely strategic and governance decisions. The Risk & Reputation Executive works closely with business risk leaders and the RRL to ensure that intelligence and assessments are grounded in operational realities and to challenge and validate the effectiveness of key controls.
This year we also further explored the concept of integrating conduct risk into our risk management capability. By closely monitoring trends and themes in a selection of conduct risk drivers, we are able to intervene where needed. Furthermore, we ensured that our sustainability risks are sufficiently addressed by our Risk Management approach.
Priority Business Risks
We continually update and reassess our Priority Business Risks through Risk & Reputation Executive reporting and use input from both DTTL and NSE to challenge our thinking.
Based on the periodic reassessment, we have identified priority business risks and opportunities related to our strategy (see the risk radar below). Current exposure (or residual risk) is defined as the likelihood of a risk materializing and its expected impact given our current ability to mitigate that risk. It is assessed on a scale from “medium” (green) to “very high” (red), taking both residual impact and residual likelihood into account.
The current “top of mind” themes - such as economic and geopolitical unpredictability, including subsequent growth outlook; the exponential growth of Gen-AI; and the volume and pace of internal change and conduct - are integrated into our priority business risks in the risk radar. Most of the risks in which these themes have been integrated have the highest exposure.
In the following table, the risks assessed with a high-risk rating are shown. The risks associated with the employment of financial instruments are described in Note 5 of the Financial Statements.
|
Risk |
Risk description |
Risk area* |
Risk appetite** |
Mitigating measures |
|
Ability to adapt and deliver future changes |
Failure to adapt and deliver our transformation agenda |
Strategic, Operational |
Medium: Deloitte is committed to successfully deliver transformation |
Pages 4-9 |
|
Advisory delivery & risk management |
Failure to prevent systemic or major failure of advisory quality. |
Strategic, Operational |
Low: Deloitte is committed to high quality execution |
Pages 141-142 |
|
Conduct & Ethics |
Failure to establish, embed and sustain an inclusive and ethical culture. |
Strategic, Operational |
Low: Deloitte is committed to our shared values and strives to limit ethical breaches |
Pages 143-146 |
|
Confidentiality, privacy & security |
Failure to manage data security and privacy. |
Operational, Laws & regulations |
Low: Deloitte is committed to preventing, being prepared for and responding to breaches and data loss in a timely fashion |
Pages 147-148 |
|
Economic, geopolitical and competitor moves |
Failure to anticipate, adapt to and respond to changes in the economic-, geopolitical- and competitor- landscape |
Strategic, Operational, Financial |
Medium: Deloitte is committed to (pro-)actively respond to economic-, geopolitical- and competitor driven changes |
Pages 4-9 |
|
Gen AI and digital transformation |
Failure to succesfully execute the digital (incl AI) transformation |
Strategic, Operational |
Medium: Deloitte is committed to embed AI and new technologies in the internal operations and external service delivery. |
Pages 139-140 |
|
Our role & future public-interest impact |
Failure to anticipate, adapt to and respond to external scrutiny, criticism and regulation. |
Strategic, Operational |
Low: Deloitte is committed to making an impact that matters on our clients and society |
Pages 10-11, 141-142 |
|
People & Culture |
Failure to attract, develop and retain high-performing and diverse professionals and world-class leaders. |
Operational, Financial |
Low: Deloitte is committed to employing top class personnel through agile talent models. |
Pages 115-139 |
*The risks in the table above can be categorized in more than one of the four impact areas that we identify (see the risk radar above). For the sake of simplicity, we have placed them in the category that we deem most appropriate.
**Risk appetite is operationally translated in our Risk Mitigation & Assurance Map to monitor exposure and act if needed.
*** Next to Advisory delivery and risk management, audit quality remains a continued focus area.
Our ERF helps us maintain control, have the right information available, comply with applicable laws and regulations and meet our own high-quality standards. The Executive Board evaluated the design and operation of these systems and reviewed the findings. No significant weaknesses were identified that could have led to material losses or impact. Where controls showed a need for improvement, remedial plans were formalised and monitored. However, because of inherent limitations and factors outside the Group’s control, this evaluation cannot provide absolute certainty that all material risks are being identified or mitigated at all times. Based on the entire system of quality controls and the assessment made, the Executive Board is able to state the following:
Statement on Risk Management
-
The report provides sufficient insights into the effectiveness of the internal risk management and control systems;
-
The aforementioned systems provide reasonable assurance that the financial reporting does not contain any material inaccuracies;
-
Based on the current state of affairs, it is justified that the financial reporting is prepared on a going concern basis; and
-
The report outlines the material risks and uncertainties that are relevant to the expectation of the company’s continuity for the period of twelve months after its preparation.
-
Deloitte is not aware that aforementioned internal risk management and control systems, as specifically described in this Risk management paragraph, do not provide sufficient comfort that identified operational and compliance risks are effectively managed as per May 31, 2026 considering our risk appetite, complexity of our structure and inherent limitations to these systems and other disclosures on these systems as noted in our management report.
-
The systems and procedures for our sustainability reporting as described in the Sustainability statement and Annex 3 of this report (Basis of reporting) are effective and provide limited assurance that the sustainability reporting does not contain material inaccuracies.
Rotterdam, July 16, 2026
Hans Honig, CEO
Dagmar Enklaar, COO
Jamie Gatt, CQRO