For internal audit and assurance professionals. Curated, not algorithmic.

New since July 28

March 2026

insightcpe.com · · Curated 4 months ago
Navigating the EU AI Act: A Guide for Internal Audit Professionals

The EU AI Act is the world's first comprehensive regulatory framework for artificial intelligence, extending its reach beyond Europe to impact any organization developing, selling, deploying, or using AI systems affecting EU residents. For internal auditors, this isn't just a legal compliance issue; it signifies a critical shift towards product safety, robust risk governance, and accountability for algorithmic decision-making. Understanding its risk-based framework and the distinction between AI providers and deployers is crucial for effective audit planning and ensuring responsible AI adoption.

News & Blogs · Europe Read more
ey.com ·
EY Survey: Autonomous AI Adoption Surges in Tech, Oversight Lags

A recent EY Technology Pulse Poll reveals that 97% of US tech executives prioritize autonomous AI, yet over half of department-level AI initiatives lack formal oversight. This rapid adoption is outpacing governance capabilities, leading to concerns about data leaks and the effective management of associated business risks. Despite these challenges, investment in AI, particularly in cybersecurity, continues to grow.

News & Blogs · Global Read more
linkedin.com ·
Think With AI: Preserving Human Intelligence in the Age of Automation

This article explores the critical need for professionals to evolve their approach to AI, moving beyond simply automating tasks to actively engaging with AI outputs to enhance human intelligence. It highlights the dangers of over-reliance on AI, likening it to 'cognitive offloading,' and advocates for a 'co-pilot' mindset where AI serves as a powerful tool that still requires human judgment and critical evaluation. The author emphasizes that the future of work belongs to those who can leverage AI to sharpen their own cognitive skills, not replace them.

News & Blogs · Global Read more
linkedin.com ·
Failure to Prevent Fraud: Demonstrating Reasonable Procedures in Practice

This article discusses the implications of the UK's Economic Crime and Corporate Transparency Act 2023, specifically the "failure to prevent fraud" offense, which comes into effect on September 1, 2025. It emphasizes that large organizations must credibly demonstrate a proportionate, coherent, actively maintained, and dynamic fraud prevention framework to avoid liability. The piece highlights the shift from mere compliance to a governance issue requiring clear evidence of effective fraud risk management.

News & Blogs · Europe Read more
internalauditnext.com ·
Regulatory Watchdog's Retreat: Implications for Internal Audit and Corporate Governance

A significant decline in PCAOB and SEC enforcement actions against auditors, coupled with budget cuts to the PCAOB's enforcement division, signals a shift towards deregulation. This trend, alongside other factors like the rise of AI in financial reporting and a dry accounting talent pipeline, creates a "governance vacuum" that internal audit professionals must recognize and address. The article warns that while some deregulation may be justified, the simultaneous weakening of traditional checks on corporate financial integrity could lead to future governance failures.

News & Blogs · North America Read more
tobyderoche.substack.com ·
AI Sovereignty Without Guardrails: A Call for Global Governance and Auditability

This article argues that national AI strategies prioritizing rapid deployment and 'AI sovereignty' without robust, coordinated global governance and auditability risk creating systemic fragility akin to nuclear proliferation. For internal audit and assurance professionals, this highlights the critical need to embed independent validation, transparent model governance, and secure supply chain visibility into AI initiatives. The piece emphasizes that fragmented oversight creates vulnerabilities and that true AI sovereignty hinges on resilience, which can only be achieved through effective governance and international cooperation.

News & Blogs · Global Read more
codewall.ai ·
Autonomous AI Agent Hacks McKinsey's Internal AI Platform, Exposing Sensitive Data and Prompt Layer Vulnerabilities

An autonomous AI agent from CodeWall.ai successfully breached McKinsey & Company's internal AI platform, Lilli, gaining full read and write access to its production database within two hours. The breach exposed 46.5 million chat messages, 728,000 files, and 57,000 user accounts, highlighting critical vulnerabilities in the platform's security, particularly concerning the prompt layer. This incident underscores the evolving threat landscape where AI agents can autonomously identify and exploit weaknesses, even in systems developed by organizations with significant security investments.

News & Blogs · Global Read more
linkedin.com ·
Navigating Disruption: A Modern CAE's Playbook for Unprecedented Times

In an era of rapid change, Chief Audit Executives (CAEs) must move beyond traditional audit plans and embrace innovation to deliver true value. This article emphasizes the need for internal audit to adapt quickly, prioritize human-centric leadership, and align strategically with organizational goals to remain relevant amidst constant disruption. It calls for CAEs to think like CEOs, foster strong relationships with both the board and management, and leverage their professional networks for collective wisdom.

Social & Media · Global Read more
swissgrc.com ·
GRC 2026: Accountability, Resilience, and Constant Pressure

By 2026, Governance, Risk, and Compliance (GRC) has evolved from a mere obligation to a strategic imperative, driven by AI, evolving regulations, and persistent cyber threats. Organizations face increasing pressure to demonstrate adaptive, intelligent, and globally aligned GRC frameworks. The focus is now on real-time execution, continuous monitoring, and embedded resilience to navigate a complex and volatile operational landscape.

News & Blogs · Global Read more
linkedin.com ·
COSO vs. NIST AI RMF: Understanding the Differences for AI Governance and Audit

This post distinctions between the NIST AI Risk Management and the COSO GenAI frameworks, two prominent tools for AI governance. While NIST offers a flexible, non-prescriptive approach for AI developers to manage risk, COSO GenAI provides a prescriptive, audit-ready framework for controlling AI risks, aligning with existing internal control principles. The author suggests that most organizations will ultimately need to leverage both frameworks for comprehensive AI governance and assurance.

Social & Media · Global Read more
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →