For internal audit and assurance professionals. Curated, not algorithmic.

New since July 28

April 2026

internalaudit360.com · · Curated 3 months ago
IIA Urges Congress to Modernize SOX Act, Elevating Internal Audit's Role

The Institute of Internal Auditors (IIA) has issued a public policy paper advocating for updates to the Sarbanes-Oxley (SOX) Act. This initiative is crucial for internal audit and assurance professionals as it seeks to formally recognize and integrate the internal audit function within the SOX framework, potentially streamlining compliance efforts and enhancing the profession's influence in corporate governance and investor protection. The recommendations aim to improve efficiency, reduce compliance burdens, and strengthen the overall assurance ecosystem.

News & Blogs · Global Read more
internalaudit360.com · · Curated 3 months ago
Beyond the Checklist: 10 Enduring Lessons from a Veteran Internal Auditor

A seasoned internal audit professional shares ten invaluable lessons learned over a 45-year career, emphasizing the critical importance of perspective, communication, and relationship-building. These insights are crucial for audit and assurance professionals looking to enhance their effectiveness, navigate complex organizational dynamics, and foster more constructive engagements with stakeholders, ultimately leading to more impactful audit outcomes.

News & Blogs · Global Read more
normanmarks.wordpress.com · · Curated 3 months ago
Optimizing SOX Scope: A Call for Annual Review and Refinement

Many organizations are over-scoping their SOX programs, leading to unnecessary costs and inefficient resource allocation. This article highlights the critical need for internal audit and assurance professionals to annually reassess and refine their SOX scope using a top-down, risk-based approach, ensuring controls are directly tied to the prevention or detection of material financial misstatements.

News & Blogs · Global Read more
normanmarks.wordpress.com · · Curated 3 months ago
Risk is Everywhere: Prioritizing Audit Focus on Enterprise Objectives

This article challenges the notion that internal audit should address every conceivable risk, arguing instead for a strategic focus on risks that directly impact enterprise objectives. For audit and assurance professionals, this emphasizes the critical need for risk-based auditing, where resources are allocated to assess controls over the most significant threats to organizational success, rather than attempting to audit every minor operational issue.

News & Blogs · Global Read more
insightcpe.com · · Curated 3 months ago
Beyond Compliance: Advanced IT Auditing for Cybersecurity Threats and Technical Control Effectiveness

This article emphasizes a shift from compliance-based cybersecurity auditing to a threat-informed approach. For internal audit and assurance professionals, this means focusing on whether technical controls effectively mitigate realistic threats, rather than just checking for their existence. It highlights the need for auditors to understand attacker methodologies, assess the true effectiveness of vulnerability management and penetration testing, and continuously monitor control performance to provide meaningful assurance in a dynamic threat landscape.

News & Blogs · Global Read more

March 2026

tobyderoche.substack.com · · Curated 4 months ago
The New Power Triangle: Government, Big Tech, and the Future of Control

The formation of a technology advisory panel featuring prominent tech leaders like Mark Zuckerberg, Larry Ellison, and Jensen Huang signals a fundamental shift in the relationship between government and Big Tech. This integration moves beyond traditional oversight to direct alignment, creating a 'power triangle' that consolidates influence over information, infrastructure, and intelligence. For internal audit and assurance professionals, this development necessitates a re-evaluation of how compliance, systemic risk, and technological dependencies are assessed, as regulatory frameworks may increasingly reflect negotiated realities rather than independent standards.

News & Blogs · Global Read more
normanmarks.wordpress.com ·
Beyond Compliance: Auditing for Strategic Impact and Enterprise Objectives

Internal audit's focus remains heavily operational, with only 5% of auditors prioritizing strategic issues. This article argues for a shift from mere compliance to auditing what truly matters: the significant risks to achieving enterprise objectives. Internal auditors should assess whether policies and practices are not just followed, but are also effective and aligned with the organization's strategic goals, ultimately framing findings in terms of their strategic consequences.

News & Blogs · Global Read more
linkedin.com ·
T.R.U.S.T.: An Internal Audit Framework for the AI Era

Tom McLeod introduces the T.R.U.S.T. framework, a critical guide for internal auditors navigating the complexities of Artificial Intelligence. This framework emphasizes that in the AI era, trust is not merely a concept but a measurable outcome built on evidence and robust controls. It outlines five key pillars—Traceability, Responsibility, Understandability, Safeguards, and Testing—essential for ensuring the reliability and integrity of AI systems.

Social & Media · Global Read more
normanmarks.wordpress.com ·
Foresight vs. Forward-Looking: Navigating the Future of Internal Audit

Internal auditors are often criticized for focusing on past events. This article delves into the critical distinction between "foresight" and being "forward-looking," arguing that while predicting the future is impossible, internal audit must proactively provide assurance, advice, and insight on future risks and organizational changes. It emphasizes the need for internal audit to align with management's focus on tomorrow, ensuring controls and processes will be effective in an evolving landscape, particularly with the rise of technologies like AI.

News & Blogs · Global Read more
insightcpe.com ·
The Evolving Landscape of IT Audit: Five Realities Reshaping the Profession

This article outlines five critical shifts that will redefine IT audit, moving it from a reactive, compliance-focused function to a proactive, intelligence-driven assurance provider. Audit professionals must adapt their skills and methodologies to address emerging risks in AI, digital trust, human-system interaction, digital identity, and organizational resilience to remain relevant and add value.

News & Blogs · Global Read more
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →