XLoD Global New York 2026: Everything You Need to Know

XLoD Global New York 2026 runs Sept 24 at the Javits Center. Streams, speakers, who attends, how to prepare and what to ask vendors.
Alexandre Berkovic

TL;DR: XLoD Global New York 2026 takes place September 24 at the Javits Center, drawing 650-plus executives who manage non-financial risk at systemically important financial institutions, plus their regulators. Frank Abagnale delivers the headline session. The organizers' own thesis is that the three lines model is straining under control-testing fatigue — a diagnosis supported by a Bank Policy Institute finding that employee hours spent on compliance rose 61% between 2016 and 2023.

The essentials

XLoD Global is run by 1LoD and is the largest event dedicated specifically to non-financial risk. New York is one edition of a series that also runs in London. It is a single-day, high-density event rather than a sprawling multi-day conference.

Detail Information
Date September 24, 2026, roughly 7:45am to 6pm ET
Venue Javits Center, 429 11th Avenue, New York, NY 10001
Scale 650+ senior risk and control executives, plus regulators
Format Four parallel streams of boardroom debates, practitioner panels and pre-booked interactive roundtables
Organizer 1LoD
Best for Heads of first line risk and control, CCOs, CROs, heads of internal audit, surveillance and control testing leads at large institutions

One scheduling note worth confirming at registration: the main New York event page and the lead sponsor both list a single conference day on September 24, while another 1LoD page for the New York edition shows September 23-24. That likely reflects an additional day or a pre-event session. Anyone booking flights should verify before assuming a one-day trip.

Who actually attends

Three stacked bands showing the lines of defence: first line management, second line risk and compliance, third line internal audit
The four content streams map to the three lines, so institutions that send one attendee per line get broader coverage.

XLoD is organized entirely around the three lines of defence, and the attendee list is segmented the same way. This is the clearest audience definition of any event on the fall calendar, and it is worth reading closely to judge fit.

The first line brings front-office COOs and business managers, chief control officers, divisional control officers, and heads of front-office risk and control, supervision, control testing, market abuse and culture and conduct. The second line brings Chief Compliance Officers, Chief Risk Officers, Chief Data Officers, CISOs, and heads of compliance monitoring, control assurance, surveillance, governance, legal, financial crime, regulatory risk, resilience, third-party risk, cyber, data analytics and AI. The third line brings chief internal auditors and heads of internal audit, including financial crime, compliance and regulatory audit.

The institutions are large. This is an event for globally systemically important banks and their peers, and the published speaker list reflects that: Nick Diieso, Managing Director and Head of Non-Financial Risk at Mizuho; Ine Lolomari, Managing Director and Head of Capital Markets Operational Non-Financial Risk at BMO; Jim Monagle, Americas Head of Non-Financial Risk for Markets and Securities Services at HSBC; and Katherine Stowe, Managing Director and Head of Enterprise Non-Financial Risk Programs at Morgan Stanley.

That concentration is the event's strength and its limitation. A compliance leader at a community bank or a mid-size fintech will find the operating-model discussions interesting but calibrated to institutions with several thousand control owners. Practitioners at that scale are better served elsewhere.

What's on the agenda

Four streams run through the day: Governance, Risk and Compliance; the 3 Lines Operating Model; Regulatory Compliance and Market Abuse; and NFR Innovation and Technology.

The topic list is unusually specific for a conference programme. It covers right-sizing the first line, control automation, opportunities to digitise controls, supervision, culture and conduct and behavioural science, market abuse surveillance, the first line's role in identifying misconduct, real-time risk identification, evolving risk and control operating models, managing control transformation programmes, more effective data management and analytics, improved collaboration across the three lines, and building a "future fit" internal audit function. Emerging risk coverage spans cyber, conduct, people, operational, resilience and digital asset risk.

The organizers' framing is worth quoting because it is more pointed than most conference marketing. Their report, "Leading Through Complexity," argues that the first line owns non-financial risk but the second and third lines struggle to keep pace with change, producing duplication, control-testing fatigue and persistent data problems. Their prescription is fewer box-ticking controls, common taxonomies and shared data, so that everyone is managing risk rather than producing evidence.

That distinction — managing risk versus producing evidence — is the single most useful idea to bring into the day, and it is measurable. A Bank Policy Institute survey found that employee hours spent on compliance rose 61% between 2016 and 2023, while IT spending on compliance climbed from 9.6% to 13.4% of IT budgets. Whether that expansion bought better risk outcomes or better documentation is precisely the argument the event is designed to have.

The scepticism is not confined to one organizer's report. PwC's EMEA AML Survey 2026, covering 531 financial institutions, found that fewer than 12% of non-EU institutions now consider current AML rules effective, and none of the US institutions surveyed did.

Sessions worth prioritizing

The format matters more than the topic list when planning a day here. 1LoD builds the agenda around debate rather than presentation: boardroom debates put opposing views on stage, panels work through where the three lines model holds and where it strains, and roundtables push the discussion further in smaller unscripted groups.

Book the roundtables first. They are pre-booked, capped, and the only format where an attendee can put a specific institutional problem in front of peers facing the same one. Everything else can be absorbed by sitting in a room; roundtables require planning.

Frank Abagnale's session is the headline draw and worth attending on its own terms. He has spent close to five decades advising financial institutions on forgery, fraud and cybercrime, with a long association with the FBI, and his current work centres on identity and passwordless authentication. The practical value for a risk audience is the threat-side perspective — most of the day is about control design, and one session about how controls actually get defeated is a useful corrective.

For second-line attendees, the control automation and digitising controls threads carry the most transferable content. The honest question in that stream is whether automation reduces control burden or simply produces evidence faster, which connects directly to whether automated compliance genuinely reduces regulatory risk. Attendees who want the conceptual groundwork on where autonomous systems fit in a controls environment may find agentic compliance a useful primer.

The surveillance sessions are strong at this event because the vendor and practitioner communities overlap heavily. Global Relay, a lead sponsor, is hosting a panel on how surveillance systems should handle profanity in trader communications, featuring its Director of Regulatory Intelligence — a narrower topic than it sounds, and a good proxy for the broader problem of lexicon-based surveillance producing volume without signal.

How to prepare

Confirm the date and the arrival time. The day starts early at 7:45am, and the Javits Center on the far West Side is not a quick trip from most Midtown hotels at rush hour.

Pre-book roundtables as soon as registration allows. This is the highest-return preparation step for this specific event, because the roundtable format is where the peer benchmarking happens and capacity is limited.

Read the "Leading Through Complexity" report before attending. The agenda is built on its argument, and sessions assume familiarity with the diagnosis. Arriving with a view on whether the thesis matches internal experience — whether control-testing fatigue is real at the institution, whether taxonomies are genuinely shared across the three lines — turns passive attendance into useful conversation.

Bring one benchmarking question. With 650 attendees drawn from a narrow band of large institutions, the scarce commodity is a candid answer about how peers actually staff, test or automate a specific control. Something like "how many full-time staff sit in your control testing function relative to control owners" gets better answers here than at any general compliance event.

Finally, coordinate internally before travelling. Because the streams map to the three lines, institutions that send one person from each line get substantially more coverage than institutions that send three people from the second line.

How to evaluate vendors on the floor

The sponsor and exhibitor base at XLoD skews toward surveillance, GRC platforms and control automation. The attendee seniority means vendors will lead with strategy rather than product, which makes concrete questions more valuable than usual.


     

     

     

     

     

     


That last question is the one this event is really about. Tooling that accelerates evidence production without reducing the control population addresses a symptom. Tooling that lets an institution retire redundant controls addresses the diagnosis in the organizers' own report, and very few vendors will claim the second without prompting.

Sphinx works inside existing systems rather than replacing them, automating the review work behind a decision while keeping the reasoning documented and reviewable by a human.

What to do after

A single-day event produces a manageable amount of material, which makes follow-through more likely than at a three-day conference. Use that. Within a week, write down the two or three places where peer practice diverged most sharply from internal practice, and name who owns the gap.

The relationships are the durable asset. A head of control testing at a peer institution who will take a call is worth more than any session, and the population of people with that exact job is small enough that the same names recur year to year. Follow up while the introduction is still warm.

For institutions weighing which other events justify the travel budget this season, the fall 2026 financial crime and compliance conference calendar compares XLoD against the anti-financial-crime and fintech alternatives, which serve noticeably different audiences.

Frequently Asked Questions

When and where is XLoD Global New York 2026?

September 24, 2026 at the Javits Center, 429 11th Avenue, New York, running from roughly 7:45am to 6pm ET. Note that one 1LoD page for the New York edition lists September 23-24, so it is worth confirming the full schedule at registration before booking travel.

Who should attend XLoD Global?

Senior executives responsible for non-financial risk at large financial institutions across all three lines of defence: heads of first line risk and control, chief control officers, Chief Compliance Officers, Chief Risk Officers, heads of surveillance, control testing, financial crime and regulatory risk, and chief internal auditors. The content is calibrated to globally systemically important institutions rather than community banks or early-stage fintechs.

What topics does XLoD Global New York cover?

Four streams cover Governance, Risk and Compliance; the 3 Lines Operating Model; Regulatory Compliance and Market Abuse; and NFR Innovation and Technology. Specific topics include right-sizing the first line, control automation and digitisation, supervision, culture and conduct, market abuse surveillance, real-time risk identification, control transformation programmes, data management and analytics, and building a future-fit internal audit function.

Is XLoD Global worth attending?

For risk and control leaders at large institutions, yes — it is the only event of its size focused specifically on non-financial risk, the format prioritises debate and pre-booked roundtables over presentations, and the peer group is narrow enough that benchmarking conversations are genuinely comparable. It is a poor fit for practitioners at smaller institutions, where the operating-model discussions assume a scale that does not apply.

Who is speaking at XLoD Global New York 2026?

Frank Abagnale delivers the headline session on fraud, forgery and the evolving cybercrime landscape. Published speakers include Nick Diieso, Head of Non-Financial Risk at Mizuho; Ine Lolomari, Head of Capital Markets Operational Non-Financial Risk at BMO; Jim Monagle, Americas Head of Non-Financial Risk for Markets and Securities Services at HSBC; and Katherine Stowe, Head of Enterprise Non-Financial Risk Programs at Morgan Stanley.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.