GRC talent shortage: why one expert in three leaves within 18 months

28 percent annual turnover in GRC teams. The fix is not salary. It is governance, working conditions and tooling. What the organisations that keep their experts do differently.

Professional team in a strategy meeting, risk governance and compliance

ENISA puts the European shortfall of security and compliance professionals at 300,000 roles by the end of 2026. Inside the GRC sub-segment, governance, risk and compliance, the pressure is sharper still: NIS2, DORA and the EU AI Act created simultaneous demand that training pipelines cannot absorb. Average turnover in GRC teams now reaches 28 percent a year (Gartner, 2024). Roughly one expert in three leaves within 18 months of being hired. This article covers why the standard retention levers fail here, what separates the organisations that keep their experts, and how to frame an approach that fits the 2026 regulatory context.

A structurally unbalanced market

The GRC talent shortage is not new, but it accelerated sharply once NIS2 landed and DORA came into application. Both texts created new obligations for thousands of European entities at once, lifting demand for qualified profiles, DPOs, risk officers, compliance managers, GRC analysts, faster than training could adapt.

ISC² puts the global cybersecurity workforce gap at 4 million in 2024. In France, fewer than 40 percent of open GRC roles were filled within the expected timeframe in 2024. That imbalance structurally favours candidates over employers. For organisations in scope of NIS2 or DORA it creates a double constraint: hire qualified people, which is hard, and keep them long enough for the training investment to pay back, which is harder. Retention here is not one HR topic among others. It is a continuity lever for your entire GRC programme.

Why the usual levers fail

The standard answer to a shortage is money. Raise salaries, add bonuses. Necessary, but insufficient, and sometimes counterproductive when it becomes the only lever pulled.

Specialist recruiters converge on one point: in GRC, people rarely leave an employer over pay. They leave because they cannot see their work producing real effect. A 2024 Compliance Week study found that 67 percent of compliance officers who left within the year cited "lack of influence on strategic decisions" as the deciding factor. Money came third.

The mechanism is specific to this profile. These professionals chose a demanding, regulatorily complex field with little visibility outside control functions. Their intrinsic motivation is strong: they want the compliance programme to actually protect the organisation, not merely satisfy an external auditor. When the culture treats compliance as a box to tick rather than a resilience lever, the gap becomes intolerable for the most competent people, precisely the ones you are trying to keep.

The error to avoid: treating GRC retention as an isolated salary negotiation, without addressing working conditions and where GRC sits in the governance structure.

Three practices that keep experts

GRC has a direct voice at decision level. The risk director or chief compliance officer reports to the executive committee, not only to finance or to the CISO. That visibility changes the nature of the work: GRC experts stop being report producers and become advisers. It is a change of posture that attracts and retains senior profiles, the scarcest on the market.

Regulatory frameworks are treated as an opportunity. Organisations that use NIS2 or DORA to modernise governance, and not only to satisfy an auditor, give their GRC experts real problems to solve. Intellectual interest is a major retention driver in a field where regulatory complexity keeps moving. An expert handling DORA operational resilience, EU AI Act obligations and customer data governance at once is not ticking boxes, and does not leave.

Skills development is structured and funded. Organisations that fund targeted certifications and sector forums cut turnover measurably. It is not a cost. Training a GRC expert averages 8,000 euros in certification and 60 days of ramp-up. Replacing one costs more than 35,000 euros in recruitment, onboarding and lost productivity (Robert Half, 2024). Training pays for itself.

Working environment: the underrated lever

Beyond governance and training, retention plays out in daily conditions, and particularly in tooling.

A GRC expert who spends 60 percent of the week manually consolidating data from scattered spreadsheets is a frustrated GRC expert. Automating low-value work, evidence collection, regulatory deadline tracking, compliance report generation, frees time for risk analysis, advising the business, and preparing management reviews. Organisations that invested in integrated GRC platforms report a measurable improvement in compliance team satisfaction.

Cross-functional collaboration is the other differentiator. The best GRC experts do not want to work in a silo. An organisation that structures that collaboration, active risk committees, security reviews built into projects, clear escalation channels, offers a more stimulating environment than a competitor offering only a higher salary.

A three-question self-check

Is your chief compliance officer or risk manager in the room when strategic decisions create or change exposure? If not, your GRC programme is perceived, rightly, as a control function rather than a governance one.

Has your organisation formalised a development path for the GRC people already in post? A certification roadmap, cross-functional assignments, access to sector bodies. Their absence signals a short-term investment only.

Do your experts spend less than 30 percent of their time on manual collection and consolidation? If not, the first retention lever is not HR. It is operational.

Presidio centralises evidence collection, regulatory tracking and report generation, which is where most of that manual load sits. See Presidio →

Conclusion

The GRC talent shortage is structural and will last. It does not resolve through pay alone. Organisations that keep their experts understood that retention starts in governance: give GRC a strategic voice, a stimulating environment, and the tools that let expertise produce visible effect. That is not an HR programme. It is a management decision about the place the organisation gives to controlling its own risk.

Read next: The silent flaw in your risk dashboard design.

A project? A question?

Contact us →