For internal audit and assurance professionals. Curated, not algorithmic.

New since August 9

December 2025

richardchambers.com ·
The 7th Annual Internal Audit Beacon Awards

The article announces the 2025 Internal Audit Beacon Awards, highlighting 12 internal audit thought leaders from 11 countries whose speaking, writing, teaching, and online engagement have significantly advanced the profession, particularly around AI, leadership, and stakeholder impact. It also notes that Robert Berry joins the elite Lighthouse Award group for earning his fifth Beacon Award, underscoring the growing global influence and diversity of these recognized leaders.

News & Blogs · Global Read more

November 2025

internalauditcollective.com ·
The Gen AI Playbook for Internal Audit Volume I

By Alan M. Maran & the Internal Audit Collective’s Gen AI for IA Working Group

* Practical guidance from practicing Internal Audit leaders.

* Step-by-step methods to deploy Gen AI securely and successfully.

* 20 ready-to-use prompts and agents across audit phases.

* Perspectives on the benefits of using Gen AI today.

News & Blogs · Global Read more
linkedin.com ·
Best Practices vs. Zero Trust: What Fitness Teaches Us About Cybersecurity

The article compares fitness habits to cybersecurity strategy, arguing that while best practices rely on trust, true progress comes from validation and evidence. Just as fitness has evolved through data-driven tools, Zero Trust transforms cybersecurity by continuously verifying, automating, and contextualizing every control to ensure real security health. A great quick read.

News & Blogs · Global Read more
normanmarks.wordpress.com ·
This is missing from most GRC and ERM programs

Norman Marks argues that most GRC and ERM programs fail because they take a bottom-up approach, identifying risks first and only later mapping them to objectives—thereby missing key strategic risks and opportunities. He emphasizes that true governance and risk management must start from enterprise objectives and strategies (a top‑down approach) to assess effectively the likelihood of achieving organizational goals.

News & Blogs · Global Read more
richardchambers.com ·
Chile’s Bold Step Toward Transparent Governance

Chile’s new Law No. 21,769 establishes the Servicio de Auditoría Interna de Gobierno (SAIG), an independent and professionalized public audit body that replaces the CAIGG and embeds risk-based, standardized internal audit practices across the government. This reform marks a major step forward for Chilean governance, strengthening transparency, accountability, and institutional resilience beyond political cycles.

News & Blogs · Global Read more
richardchambers.com ·
Bridging the Trust Gap Between Internal Audit and Management

The article emphasizes that trust is essential for a productive relationship between internal audit and management, yet many auditors are still viewed as enforcers rather than trusted advisors, which creates a significant trust gap. Building this trust requires transparency, empathy, consistent communication, and delivering value by helping management operate more effectively and manage risks intelligently, thereby shifting internal audit’s role from policing to partnering in organizational success.

News & Blogs · Global Read more

October 2025

grantthornton.com ·
The power of AI in efficient SOX compliance

The article explains how AI is transforming Sarbanes‑Oxley (SOX) compliance by enabling continuous monitoring, automated testing, and intelligent controls that reduce compliance costs and risks while improving reliability and transparency. It emphasizes a balanced approach where AI operates as a human‑overseen “co‑pilot,” supported by strong governance, ethics, and workforce upskilling to build trust with regulators and turn compliance into a strategic advantage rather than a burden.

News & Blogs · Global Read more
normanmarks.wordpress.com ·
The CAE as the SuperAuditor

The article highlights the critical role of the Chief Audit Executive (CAE) as a “SuperAuditor,” emphasizing that much of their impact comes from confidential discussions and providing assurance, advice, and insights directly to management and the board, rather than through formal reports. Real-world examples from the author’s experience demonstrate how the CAE’s involvement in top enterprise risks has led to significant organizational changes and improvements without compromising independence or objectivity.

News & Blogs · Global Read more
isaca.org ·
CISA, CISM and CISSP: Why They’re More Complementary Than Competing

Chidambaram Narayanan explains that CISA, CISSP, and CISM certifications serve distinct but complementary roles in information security—CISA assures trust through audit and control, CISSP focuses on technical security, and CISM centers on security management. It concludes that combining these certifications, and potentially adding AI-focused credentials like AAISM or AAIA, provides professionals with a complete, future-ready skill set for securing, managing, and assuring technology environments.

News & Blogs · Global Read more
normanmarks.wordpress.com ·
What is risk-based auditing?

The article "What is risk-based auditing?" by Norman Marks emphasizes the importance of focusing internal audit efforts on the most significant risks that could impact an organization's success and objectives, rather than auditing activities or controls indiscriminately. It advocates for aligning internal audits with enterprise risks that matter to senior leadership, enabling efficient, agile, and value-driven auditing that supports organizational success and risk management.

News & Blogs · Global Read more
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →