Internal audit shifts toward high-risk areas like AI

The efforts of internal auditors are increasingly focusing on digital disruptions, especially from artificial intelligence, as well as geopolitical uncertainty, according to a new survey.

Processing Content

The survey, released Tuesday by the Institute of Internal Auditors, found that some of the fastest-rising organizational risks are also among the least mature areas for governance and full audit coverage. Based on feedback from over 3,000 audit leaders globally, the annual survey found digital disruption/AI and geopolitical uncertainty showed the largest increases in risk level compared to last year, to 58% and 48%, respectively.

The largest increase in audit priority came from digital disruption. A much higher percentage of the survey respondents cited digital disruption as one of their top five risks (58%), compared to a top five audit priority (42%). Similarly, human capital and geopolitical uncertainty had high risk ratings compared to their audit priority levels. 

The most rapidly changing risks had some of the weakest governance and coverage, according to the respondents. Only 23% of them rated digital disruption governance as managed or optimized, and only 11% considered internal audit coverage fully adequate. For geopolitical and macroeconomic uncertainty, the equivalent results were 29% and 10%. Cybersecurity remains the top global risk at 80%, up seven percentage points from last year.

There were some distinctive regional differences. Respondents in Africa reported risks from heightened fraud and financial pressure; while internal auditors in the Asia Pacific region emphasized digital disruption, supply chains, resilience and talent. Respondents in Europe cited elevated cyber, geopolitical and regulatory risks; while those in Latin America highlighted cyber, AI, geopolitics and fraud risks. Survey respondents in the Middle East stressed how conflict can rapidly transform resilience and liquidity; while respondents in North America reported the highest digital disruption risk.

The IIA believes the mandate for chief audit executives is clear: develop dynamic plans, assess risks as connected systems, compare risk with maturity and coverage, coordinate assurance across its Three Lines model and build the capabilities needed to address what the organization is becoming — not only what it has historically been.

"The most consequential events rarely remain within one category," said the report. "AI adoption can create data, cyber, compliance, fraud, talent, third-party and reputation risks. A geopolitical event can create supply disruption, price volatility, liquidity pressure, regulatory change, operational interruption and social instability. A cyberattack can trigger financial loss, customer harm, regulatory action and loss of trust. CAEs should consider structuring parts of the audit universe around risk pathways or scenarios. This helps internal audit identify common dependencies, cumulative exposures, weak handoffs and controls that affect multiple risks."

During the IIA's recent Financial Services Exchange conference in Brooklyn, New York, internal auditors discussed some of the priorities they are addressing.

"There's this entire profession around the world of internal audit, but we sincerely see that one of our main jobs is to provide independent assurance to governance bodies, including boards of directors and Congress and legislators," said Terry Grafenstine, executive vice president and chief audit executive at PenFed Credit Union, during one session. "We're independent and we're presenting the facts just the facts."

She asked Rep. Mike Lawler, R-New York, about areas where Congress or regulators could lean more on internal auditors to provide an independent assurance function, rather than adding new direct reporting requirements and regulations.

"I think government as a whole needs internal audits all the time, and frankly, it's underutilized, both in terms of everyday expenditures and from a budgeting standpoint," Lawler replied. "When there is an issue, the work that is undertaken by internal auditors to really just drill down on the facts, the data, the information is vital. I'm aware right now of something in my district where an internal audit is being done, and it's already uncovered numerous things, and that's a good thing. Oftentimes people are afraid of it because it is going to expose things. But to me, that's vital. Otherwise, you keep making the same mistakes, or worse, it's not mistakes, it's intentional. I think transparency and accountability are critical in anything you do, including the private sector, but especially the public sector when you're talking about the use of taxpayer money. I think internal audit should be a way bigger function, and it would help guide a lot of decisions that get made in government if it was more prevalent as an every-year function."

Terry Grafenstine of PenFed Credit Union (left) talks with Rep. Mike Lawler, R-New York, at the IIA Financial Services Exchange
Terry Grafenstine of PenFed Credit Union (left) talks with Rep. Mike Lawler, R-New York, at the IIA Financial Services Exchange

In some cases, internal auditors need to do real-time audits, for example, when a sudden crisis like a pandemic emerges.

"Even today there are incidents that happen in the industry and even to us at the bank, and we will put a real-time audit in if we need to," said US Bank senior executive vice president and chief audit executive Christopher Paulison. "We have flexibility with our audit plan, where as long as we're staying within budget and within a quarter, we can move some things around. I just have to report those to the audit committee so they can see the transparency of that. But sometimes I'll push an audit up just because I see something about our strategy alignment needs to take place now, or there's some high risk, so we do the real-time auditing."

A client company's products and services can produce risks as well. "When it comes to products and services, they're weighing in on internal audit to see if there are any duplicate products, if there's risks," said Charmone Adams, a partner in the risk advisory services practice at Grant Thornton. "If it's not, it's  from regulatory bodies and so forth. More importantly, if we launch a new product, is that going to cause more burden from a compliance scrutiny perspective in the long run?" 

AI is increasingly being seen as one of the largest risks, and not only for companies. "I think we all need to be focusing a lot of time on AI and really not just AI governance, and making sure that when your team's using AI that they've got the right controls in place across your organization, or the risk that you're not using AI and you're going to fall behind, but really how AI amplifies all those risks around it," said IIA global board chair Stacy Schabel, senior vice president and chief audit executive at Jackson Financial. "All those are really important risks. We've still got to focus on them, but we need to make sure that we're thinking about how AI amplifies each of those."


For reprint and licensing requests for this article, click here.
Audit Audit preparation Artificial Intelligence Risk management
MORE FROM ACCOUNTING TODAY
Load More