Skip to content

Invest1 publisher3 min readPublished

Internal auditors name geopolitical risk nearly four times as often as they plan to audit it

Cybersecurity holds first place at 80% in the Internal Audit Foundation's survey of more than 3,000 practitioners, and the two risks that rose fastest, digital disruption at 58% and geopolitics at 48%, are drawing very different audit attention.

The Investor · Invest desk

Illustration accompanying Internal auditors name geopolitical risk nearly four times as often as they plan to audit it

What happened

  • The Internal Audit Foundation's latest annual Risk in Focus research was informed by feedback from more than 3,000 internal audit practitioners working across 132 countries.
  • Digital disruption, including AI, and geopolitical uncertainty each gained 10 percentage points as risk ratings, reaching 58% and 48%, the largest increases recorded since last year.
  • Cybersecurity remained the number one global risk, rising seven percentage points to 80% of respondents placing it among their organization's top five.
  • Digital disruption also posted the largest increase of any area for audit priority, up 10 percentage points to 42% of respondents naming it a top-five call on audit time and effort.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • decision An audit plan holds a fixed number of engagements, so the ten points digital disruption gained have to come from somewhere, and financial and liquidity risk still holds a top-five audit slot with 49% of respondents.
  • exposure Boards asking what assurance they have on geopolitical exposure will be pointed at supply chain, liquidity and resilience engagements, because the Internal Audit Foundation says that is where political risk is being covered.
  • constraint The area gaining audit attention fastest is the one respondents rate lowest on governance maturity and coverage adequacy. That low base limits how much of the new attention converts into usable assurance this year.

Set each risk rating beside the share of respondents who put the same item in their top five for audit time and effort. Cybersecurity's gap is five points, 80 against 75 [4][6][1]. Digital disruption's is sixteen, 58 against 42 [2][5][2]. Geopolitical and macroeconomic uncertainty runs 48 against 13, a gap of 35 points [7][3]. In North America that gap widens to 37, where 43% call it a top-five risk and 6% a top-five audit priority [8][4], while the same region rates digital disruption highest in the world at 69% [3].

One line runs the other way. Financial and liquidity risk is a top-five audit priority for 49% of respondents and a top-five risk for 34%, so its audit attention sits 15 points above its rating [9][5].

None of these figures is money. Each is the share of more than 3,000 practitioners across 132 countries naming an item in a top five [1]. The ten points digital disruption gained in audit priority means more plans now list it, not that a measured number of hours or dollars moved [5].

The Internal Audit Foundation's own explanation for the thin geopolitical coverage is that the work happens under other names. Political risk, the research says, is likely addressed through engagements for supply chain, financial and liquidity health, business resilience, regulatory compliance and market changes [10].

Anthony Pugliese is President and CEO of The Institute of Internal Auditors [12]. He said: "The challenge for organizations is no longer simply identifying individual risks, but understanding how they intersect, how quickly their impact can spread across the enterprise, and whether governance, internal audit and decision-making are keeping pace." [11]

This year's survey asked for the first time how mature risk governance is and whether internal audit coverage is adequate. It found some of the fastest-changing risks among the least mature and least covered areas [13]. Digital disruption ranked among the lowest on both measures [14]. The research treats the 58-against-42 spread as a reason for organizations to adapt skills, governance structures and evaluation criteria [15].

In my view the 16-point digital disruption gap is where next year's audit hiring gets decided. The same respondents who moved it onto their plans rated its governance among the least mature [14]. The competing reading is that geopolitics never becomes its own audit line at all. The research already has digital disruption running through supply chain and third-party risk, fraud, human capital, regulatory obligations and market competition [16], and a risk that turns up inside five other engagements is being covered without a label. What would prove me wrong: digital disruption's audit priority climbing another ten points next year while governance maturity stays flat. That would mean plans are being relabelled and not staffed.

What to watch

  • Whether digital disruption's governance maturity score moves next year, now that Risk in Focus has a baseline for it for the first time.
  • Whether North America's 6% geopolitical audit priority rises off the floor while 43% keep calling it a top-five risk.
  • Whether financial and liquidity risk gives up any of its 49% audit-priority share as digital disruption climbs past 42%.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories