Global risk consulting market nears $70 billion, top 30 consultancy firms

13 December 2018 7 min. read

The global market for consulting services in the area of risk management will book double digit growth in the coming two years. This would see it surpass the $70 billion mark next year and even $80 billion by 2020, according to a new analysis.

The market sizing estimate is sourced from a UK analyst firm, Source Global Research, which in its estimates found that risk consulting market will have grown by nearly $30 billion in just five years. The firm found the global risk services market grew 7% to $62 billion in 2017, while offering up the prediction that that figure will increase to more than 10% by 2019. This would see the industry blow past the $80 billion mark by 2020.

When it comes to defining the size of the risk consulting industry, much comes down to where the line is drawn between risk and other services. The researchers themselves stipulate that if other components of the risk market are factored in – such as risk-related work that organisations currently do internally and revenue generated by adjacent solutions and services – the addressable risk services market would reach a size of $188 billion – or roughly three times the total revenue generated by risk services providers globally today.

Risk consulting service areas

The main service is enterprise risk management and/or financial risk management. This field helps clients identify, assess, manage, report and limit the risks they face through establishing more robust risk processes and better internal controls and KPIs to precede and monitor risk management. This can span strategic risks and operational risks (e.g. supply chain interruptions) to credit risk, market and liquidity risks. It also includes functional risks, such as IT risk and internal audit risk. In providing risk services, these consultants also work across strategy, organisation, processes, governance and culture to drive change. This line of work has “benefited from an increase in investment by clients seeking to bolster their internal risk capabilities and ensure that the risk management function is positioned effectively within their organisations,” stated the researchers in a press release.

The global market for risk consulting services

Another service area is Cybersecurity, which according to the researchers has grown to the biggest risk management service, estimated at $15 billion. Consultants specialised in cybersecurity help clients with developing a frontier that makes them stronger in battling attacks, this includes improving IT infrastructure, embedding security across all processes, but also changing culture internally that makes cyber vulnerability lower – several studies show that cybercriminals capitalise on errors made by internals. Having right culture in place is important too, as in many cases the criminals actually are on the inside.

Due to massive the massive threat landscape amid an online and smartphone boom, the field is also one of the fastest growing, aspects of consulting, at 11%. Deloitte is according to one estimate the globe’s largest cybersecurity consultancy, and Ed Marsden, a leader in Deloitte’s Risk Advisory practice, recognised the development sketched by the researchers.

Marsden explained, “Cyber is front of mind and on the front of the newspapers, and that’s only going to increase. As companies migrate large portions of their legacy IT estate to the cloud; develop increasingly complex ecosystems; and innovate with AI, blockchain and robotics, there’s a need for even greater vigilance.”

The attractiveness of cybersecurity service line is leading to heating competition. On one hand, there is an influx of technology-focused new entrants to account for. For instance, in a recent analysis of North America’s leading cybersecurity consulting firms, analyst firm ALM identified technology-heritage players such as Optiv Security, Mandiant (a FireEye company), Secureworks and Cognizant as firms that are taking on the market leaders – the Big Four, Booz Allen Hamilton, McKinsey & Company and Capgemini. Other service areas typically included in the risk management consulting landscape include third-party assurance, internal audit risk, compliance services, crisis management and regulation.

Callum Jack, a senior analyst at Source Global Research, highlighted the importance digital skills play in winning market share in the cyberspace. “Technology expertise will be central to winning work in cyber risk. For this reason, digital know-how will play an increasingly important role in the delivery of both low-cost and high-value services.”

In the regularity aspects of the field, firms with strong brand, such as the big Four have an edge, because regulators look at credibility. One managing director from the financial services sector commented, “Sometimes we’re engaging consultants as a result of a direct suggestion from the regulators, who might tell us that we need to go out and get an independent view on X, Y, or Z. We’ll definitely go to a name-brand firm in that case so we can show the regulator that we’ve been responsive and engaged the right people.”

Global risk consulting market nears $70 billion, top 30 consultancy firms

Across the entire risk consulting landscape, the Big Four dominate. In a previous study of the market, Source estimated the Big Four to hold market share of almost two thirds (61%). ALM, a rival analyst firm from the US, annually conducts research into which consulting firms are best positioned in the risk consulting space, and found that beyond the Big Four, there is a group of thirty players that belong to the leading pack in the segment. The researchers assessed consultancies by the breadth and depth of their services. The group of top risk consulting firms includes: Protiviti, Crowe, McKinsey & Company, Promontory, Rubin Brown, RSM, Marsh, Boston Consulting Group, Aon, Milliman, Capgemini, IBM, Willis Tower Watson, Grant Thornton, Alvarez & Marsal, A.T. Kearney, Morgan Franklin, Cohn Reznick, Navigant, Bain & Company, Oliver Wyman, Control Risks, PA Consulting Group, BDO, Eisner Amper and MYR Consulting.

Industries and geographies

According to Source’s estimates, nearly all sectors of the economy are seeing greater demand for risk management services. Of this, by far the largest market is the financial services sector, as it is with the consulting industry more generally. This is the case thanks in the main to the regulatory environment, particularly since the financial crisis, along with the attractiveness of the sector to cybercriminals.

However, as many other industries become heavily regulated, such as pharmaceuticals and utilities, these sectors are outpacing financial services in terms of growth, though both remain smaller markets for risk management. According to Dennis Chesley, PwC’s global risk and regulatory consulting leader, though, while these have grown, it is health which is the industry that, shows the “greatest promise in terms of shifting its thinking to see risk management as including a view on opportunity”, with the shift touted to help the industry “build a more resilient landscape.”

At present, more than half of the entire risk services market is based in the US. This is primarily due to the size of its economy, the maturity of its professional services market, and a business culture that encourages the seeking of external advice. The US market is also boosted by the position of professional services firms like the Big Four, which have invested heavily in hiring technology experts. As a result, the US dominates the global risk services market, at $32 billion.

Commenting on the outlook, Callum Jack concluded, “There is huge potential in the risk services market and the outlook is very positive for firms that can convince clients that their services complement – or are better than – clients’ internal capabilities.”