What's Happening?
A new survey by the Institute of Internal Auditors reveals a significant shift in internal audit priorities, with digital disruption, particularly artificial intelligence (AI), and geopolitical uncertainty emerging as the fastest-rising organizational
risks. The survey, which gathered feedback from over 3,000 audit leaders globally, indicates that these high-risk areas often lack mature governance and comprehensive audit coverage. Digital disruption/AI saw the largest increase in perceived risk level, reaching 58%, while geopolitical uncertainty rose to 48%. Despite these elevated risk perceptions, only 23% of respondents rated digital disruption governance as managed or optimized, and a mere 11% considered internal audit coverage fully adequate for this area. Similarly, for geopolitical and macroeconomic uncertainty, governance was rated managed or optimized by 29%, with only 10% reporting fully adequate audit coverage. Cybersecurity remains the top global risk at 80%, marking a seven-percentage-point increase from the previous year. Regional differences were noted, with North American respondents reporting the highest digital disruption risk.
Why It's Important?
This shift in audit focus is critical for U.S. businesses and public sector entities as it highlights a growing vulnerability in rapidly evolving technological and geopolitical landscapes. The disparity between the perceived risk of AI and geopolitical uncertainty and the current state of governance and audit coverage suggests that many organizations may be unprepared to effectively manage these threats. Inadequate oversight of AI adoption can lead to significant data breaches, compliance failures, fraud, and reputational damage, impacting consumer trust and financial stability. Geopolitical instability can disrupt supply chains, create price volatility, and introduce regulatory complexities, directly affecting business operations and profitability. For the U.S. economy, a lack of robust internal controls in these areas could lead to systemic risks, affecting various industries from finance to technology. The call for dynamic audit plans and integrated risk assessments underscores the need for organizations to proactively adapt their risk management strategies to address these interconnected and rapidly changing challenges.
What's Next?
Chief audit executives are now tasked with developing more dynamic audit plans that assess risks as interconnected systems, rather than isolated incidents. This involves comparing risk levels with existing maturity and coverage, coordinating assurance across different organizational lines, and building new capabilities to address emerging threats. The Institute of Internal Auditors emphasizes that consequential events rarely fit into a single category, citing AI adoption's potential to create data, cyber, compliance, fraud, talent, third-party, and reputation risks. Therefore, internal audit functions are expected to structure audit universes around risk pathways or scenarios to identify common dependencies, cumulative exposures, and controls affecting multiple risks. This proactive approach will require continuous adaptation and investment in audit capabilities, particularly in understanding and mitigating risks associated with AI and geopolitical events. Lawmakers and regulators may also increasingly lean on internal auditors for independent assurance, potentially leading to greater integration of audit findings into policy-making and regulatory frameworks.
Beyond the Headlines
The findings underscore a deeper challenge: the rapid pace of technological advancement and global instability is outstripping traditional governance and risk management frameworks. The underutilization of internal audits in government, as noted by Rep. Mike Lawler, highlights a systemic issue where transparency and accountability are often compromised due to a lack of consistent oversight. This gap can lead to repeated mistakes or intentional misconduct, particularly concerning taxpayer money. The need for 'real-time audits' in response to sudden crises, as practiced by some financial institutions, points to a fundamental shift required in audit methodology—from periodic reviews to continuous monitoring and rapid response. Ethically, the responsible deployment of AI necessitates robust internal controls to prevent bias, ensure data privacy, and maintain accountability. Legally, evolving regulatory landscapes around AI and data governance will demand that internal audit functions stay ahead of compliance requirements, transforming their role from mere compliance checkers to strategic advisors in navigating complex ethical and legal terrains.













