For internal audit and assurance professionals. Curated, not algorithmic.

April 2026

normanmarks.wordpress.com · · Curated 4 months ago
Risk is Everywhere: Prioritizing Audit Focus on Enterprise Objectives

This article challenges the notion that internal audit should address every conceivable risk, arguing instead for a strategic focus on risks that directly impact enterprise objectives. For audit and assurance professionals, this emphasizes the critical need for risk-based auditing, where resources are allocated to assess controls over the most significant threats to organizational success, rather than attempting to audit every minor operational issue.

News & Blogs · Global Read more
insightcpe.com · · Curated 4 months ago
Beyond Compliance: Advanced IT Auditing for Cybersecurity Threats and Technical Control Effectiveness

This article emphasizes a shift from compliance-based cybersecurity auditing to a threat-informed approach. For internal audit and assurance professionals, this means focusing on whether technical controls effectively mitigate realistic threats, rather than just checking for their existence. It highlights the need for auditors to understand attacker methodologies, assess the true effectiveness of vulnerability management and penetration testing, and continuously monitor control performance to provide meaningful assurance in a dynamic threat landscape.

News & Blogs · Global Read more

March 2026

tobyderoche.substack.com · · Curated 4 months ago
The New Power Triangle: Government, Big Tech, and the Future of Control

The formation of a technology advisory panel featuring prominent tech leaders like Mark Zuckerberg, Larry Ellison, and Jensen Huang signals a fundamental shift in the relationship between government and Big Tech. This integration moves beyond traditional oversight to direct alignment, creating a 'power triangle' that consolidates influence over information, infrastructure, and intelligence. For internal audit and assurance professionals, this development necessitates a re-evaluation of how compliance, systemic risk, and technological dependencies are assessed, as regulatory frameworks may increasingly reflect negotiated realities rather than independent standards.

News & Blogs · Global Read more
normanmarks.wordpress.com ·
Beyond Compliance: Auditing for Strategic Impact and Enterprise Objectives

Internal audit's focus remains heavily operational, with only 5% of auditors prioritizing strategic issues. This article argues for a shift from mere compliance to auditing what truly matters: the significant risks to achieving enterprise objectives. Internal auditors should assess whether policies and practices are not just followed, but are also effective and aligned with the organization's strategic goals, ultimately framing findings in terms of their strategic consequences.

News & Blogs · Global Read more
normanmarks.wordpress.com ·
Foresight vs. Forward-Looking: Navigating the Future of Internal Audit

Internal auditors are often criticized for focusing on past events. This article delves into the critical distinction between "foresight" and being "forward-looking," arguing that while predicting the future is impossible, internal audit must proactively provide assurance, advice, and insight on future risks and organizational changes. It emphasizes the need for internal audit to align with management's focus on tomorrow, ensuring controls and processes will be effective in an evolving landscape, particularly with the rise of technologies like AI.

News & Blogs · Global Read more
insightcpe.com ·
The Evolving Landscape of IT Audit: Five Realities Reshaping the Profession

This article outlines five critical shifts that will redefine IT audit, moving it from a reactive, compliance-focused function to a proactive, intelligence-driven assurance provider. Audit professionals must adapt their skills and methodologies to address emerging risks in AI, digital trust, human-system interaction, digital identity, and organizational resilience to remain relevant and add value.

News & Blogs · Global Read more
erpra.net ·
Auditors Overemphasize Segregation of Duties, Neglecting Critical Sensitive Access Risks

Auditors are spending too much time on Segregation of Duties (SoD) conflicts and not enough on sensitive access risks, especially in modern ERP systems. Many traditional SoD conflicts are mitigated by effective workflow designs, making their extensive testing redundant. The article advocates for a shift in focus towards identifying and auditing sensitive access risks, which can lead to significant financial fraud independently.

News & Blogs · Global Read more
internalaudit360.com · · Curated 4 months ago
AuditBoard Rebrands as Optro, Emphasizing AI-Powered GRC for Proactive Risk Management

AuditBoard, a prominent GRC platform provider, has rebranded as Optro, signaling a strategic shift towards leveraging AI for proactive risk foresight. This move highlights the increasing integration of artificial intelligence in governance, risk, and compliance, urging internal audit and assurance professionals to consider how AI-driven tools can enhance their capabilities in identifying and transforming risk into opportunity. The acquisition of FairNow further underscores Optro's commitment to AI Governance, a critical area for auditors navigating the complexities of AI adoption.

News & Blogs · Global Read more
internalaudit360.com · · Curated 4 months ago
Auditing IRRBB Models: Six Critical Dimensions for Banking Internal Audit

Interest Rate Risk in the Banking Book (IRRBB) is a significant source of financial and capital volatility for banks, impacting both short-term earnings (Net Interest Income) and long-term capital (Economic Value of Equity). Internal audit, as the third line of defense, plays a crucial role in providing assurance that IRRBB models are accurate, reliable, and compliant with regulatory expectations. This article outlines six critical dimensions for internal auditors to effectively assess IRRBB models, ensuring sound governance and robust risk management.

News & Blogs · Global Read more
internalaudit360.com · · Curated 4 months ago
Quality Management: The Strategic Imperative for Internal Audit's Value and Trust

Chief Audit Executives (CAEs) are under increasing pressure to deliver strategic value beyond mere assurance. This article emphasizes that a robust quality management program is no longer just a compliance requirement but a critical strategic lever for internal audit to maintain relevance, build trust, and position itself as a trusted advisor. It outlines a framework for achieving this, focusing on risk orientation, stakeholder management, resource optimization, and operational excellence, all supported by continuous feedback and improvement.

News & Blogs · Global Read more
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →