For internal audit and assurance professionals. Curated, not algorithmic.

October 2025

cpapracticeadvisor.com ·
Trustworthy Sustainability Data is Vital, Says ACCA and Internal Audit Foundation

ACCA and The Institute of Internal Auditors emphasize that trustworthy sustainability data is crucial for business success and global progress, urging that internal control principles be robustly applied to this data. Their report calls on accountancy, finance, and internal audit professionals to embed sustainability into core business objectives and ensure proper data ownership and internal control skillsets throughout organizations.

News & Blogs · Global Read more
wolterskluwer.com ·
Specialize or generalize: The future of internal auditing

Scott Madenburg CIA, CISA, CRMA examines the ongoing debate within internal audit functions regarding the ideal mix of specialists and generalists, emphasizing that a balanced team is crucial for managing increasingly complex risks, regulations, and technologies. Drawing on industry guidance and practical examples, it concludes that effective risk management and organizational performance require both deep subject expertise and broad risk coverage within internal audit teams.

News & Blogs · Global Read more
internalauditor.theiia.org ·
Innovating to Stay Relevant by Cindy Tu

As automation rises, soft skills matter more," writes Xin (Cindy) Tu /CPA/CISA/CISSP/CDMC/AWS-CSA. Ahead of her technology presentation at the Financial Services Exchange conference, she offers tips for leading an audit function through an era of disruption.

News & Blogs · Global Read more
coauditor.com ·
Preparing to Audit AI-Enabled Business Environments

This article by the CoAuditor team explains that as AI becomes integral to business operations, internal auditors must ensure its governance is transparent, accountable, and compliant with evolving regulations. It highlights how combining the ISO/IEC 42001 standard, the EU AI Act, and the IIA AI Auditing Framework equips auditors with clear criteria, legal obligations, and practical methods to effectively audit AI-enabled environments.

News & Blogs · Global Read more
linkedin.com ·
Fraud Risk Assessments, Oh Yes there is a Need

In the last article we discussed whether a Fraud Risk Assessment (FRA) was a need or a waste?

My opinion is there is a need, and they are most assuredly a value add. We spend enormous amounts of time and money to hire, train, equip, and retain employees, not to mention the sums spent to advertise and entice customers or the lengths we go to find and groom suppliers and vendors. So why would we not spend a small portion to ensure our controls are sufficient to prevent or detect the tried and true as well as the newest fraud scenarios?

So, what kind of FRAs are available? Many people feel there is only one kind of FRA, a full-fledged assessment covering the entire organization with:
• Surveys to numerous managers and employees
• in-person and virtual interviews and brainstorming sessions involving executive, senior, and mid-level management and selected senior employees
• Scenario development
• Controls analysis across the organization for their consistency or not
• Development of a heat map showing the low to high fraud risks based on their impact and likelihood
Whew, I am tired just thinking and writing about one.
While a full FRA is certainly a great idea and needed at times such as:
• Recent merger or acquisition to determine new additional fraud risks
• Significant fraud loss
• Fraud loss by a senior management official
• Expansion to country that requires an FRA
• Company significantly expands into geographic area with high fraud risk
• Company significantly expands into a service or function they have no prior experience/expertise in

There are other less resource rich and more nimble ways to keep your fingers on historical, current, and future fraud risks in between a full FRA.

I will outline the ones I have used over the years and found them to be helpful and timely in educating the management and employee populations as well as detecting and preventing fraud risks and control gaps and weaknesses.

They are:
• Enhance the current or Add a section on Fraud Risk to the Annual Risk Assessment.
• Include 2 to 4 unscheduled reviews, time, and resources available, in Annual Audit Plan. Quarterly review of management requests, audits from previous 6 to 12 months, and/or Annual Risk Assessment rankings for unscheduled review candidates.
• Include a Fraud Risk Questionnaire in Internal Audit planning and share with the auditee for their input.
• Quarterly meeting with department representatives involved in investigations for fraud, ethics, cyber, and administrative violations. The goal is learning about respective current investigations for crossover, duplications, and department/function process education.
o Example: HR Employee Relations investigating management timecard misuse but felt funny. Internal Audit Investigations follow up review determined manager not misusing from lack of training but colluding with employee and intentionally abusing timecard for kickbacks.
• Form a special committee from selected departments to advise on current/potential fraud risks they are concerned about. Suggested areas are Finance, Accounting, Supply Chain, Sales, Marketing, Security, Ethics, Legal, HR/ER.

What we need to remember for any FRA is the goal is to not only make sure we identify and mitigate known and potential fraud risks, but also to educate our front-line defenders, the managers, and employees. They know the job, the area, and what is and is not suspicious; they just need education, guidance, and an escalation process. They are the tip of the spear to identify anomalies and suspicious activities and understand who to report to, their job is then done, except to provide support during the follow-on investigation.

I hope this provides some ideas on the different kinds of FRAs. In the next two articles I will share examples that have worked for me in various companies, and I hope they will provide templates for your use. Please remember that one size FRA does not fit all entities at any given time.

Other resources to consider on this topic can be found on:
Association of Certified Fraud Examiners - https://www.acfe.com/search?s=ethics
Institute of Internal Auditors - Global Resources in Internal Audit | The IIA

Please let me know if I can help or be a resource for your questions / comments on the content of this article. If you would like clarification on or related articles, please connect with me and I can share any you would like. My fraud risk assessment experiences have included healthcare and manufacturing environments.
George

News & Blogs · Global Read more
linkedin.com ·
Other Ways to Assess Fraud Risk

In my last article we discussed there are various ways to have a Fraud Risk Assessment (FRA) other than a resource intensive one.

Examples to consider include:
1. Include a Fraud Risk Questionnaire in Internal Audit planning and share with the auditee for their input. The questions should cover:
a. Last time they reported suspicious activity and to who?
b. Their knowledge of how and where to report suspicious activity (Hotline, Compliance, Internal Audit, Legal, etc.).
c. Fraud Awareness (aka: Policy Compliance and Employee Poor Choices) training. This is always fun because for the most part they do it, just do not realize they are. An example on timecards/card scan is each employee does their own card/scan. Consequences for punching in or scanning in another employee is generally termination and just like that they realize that is fraud awareness training. You can cover other areas like expense reports, corporate or P-card use, Accounts Payable, asset inventory order/check in/document, etc. This opens up a line of discussion and future education and collaboration.
d. Ethics education, compliance, Hotline use, and who to contact for questions.
e. Offer to share sample questionnaire upon request

2. Quarterly meeting with representatives from some/all for HR/Employee Relations, Cybersecurity, Ethics/Compliance, Security, Legal, and Internal Audit/Suspicious Financial Activity Unit. My luck with these meetings was to share the investigations each was working on, their status, if administrative action(s) planned hearing the allegation and investigation results could also lead to additional investigation from Internal Audit team if possible unrecognized financial fraud potential not part of the initial team’s investigation. Internal Audit would generally work in an advisory capacity with the initial team retaining control. The meeting was an exchange of each team’s work and if assistance or guidance was needed from another team or if the investigation should be transferred or if there were two or more investigations of different allegations involving the same person or department and how best to proceed with just one team taking control or forming a task force.

3. Form a Dirty Dozen Fraud Committee of department subject matter experts and hold periodic (quarterly) discussions/meetings for updates and insights on potential fraud risks in their areas. Additionally use them as a resource as needed for investigations.

4. Other ideas that help spread fraud awareness include:
a. Communication via organization intranet with high level and redacted information on relevant fraud investigations that show the policy(s) violated, if relevant control(s) in place and violated, in some instances how the case was reported, and the consequences to the employee and the control reviewer if they consistently failed to use the control that resulted in the fraud going on more than 2 or 3 review cycles. Z

This lets organization employees know there are policies and controls, and they are expected to be followed, there is a reporting process, and it is acted upon because there is zero tolerance for fraud.

b. Continuous Monitoring is always a great idea. A suggestion is to not label it as Fraud Monitoring, because fraud is determined after an investigation, not before. The monitoring identifies anomalies that need investigation to determine if there is:
i. Poor/Inadequate:
1. communications,
2. policies,
3. controls,
4. training,
ii. Employee arrogance to do it their way and not the policy/control directed way,
iii. Yes there are also intentional acts to circumvent the controls for employee personal gain.
The first 5 are policy non-compliant, but areas for management to address and mitigate. It is the sixth one that is fraud and needs referral to the appropriate investigations team for detailed follow-up.

I hope this provides some background on other ways to assess fraud risk.

Other resources to consider on this topic can be found on:
Association of Certified Fraud Examiners - https://www.acfe.com/search?s=ethics
Institute of Internal Auditors - Global Resources in Internal Audit | The IIA

Please let me know if I can help or be a resource for your questions / comments on the content of this article. If you would like clarification on this or related articles, please connect with me and I can share / comment on any you would like. My fraud risk assessment experiences have included healthcare and manufacturing environments.
George

News & Blogs · Global Read more
auditboard.com ·
How AI provides essential infrastructure for auditors

The article argues that internal audit must treat artificial intelligence as essential infrastructure rather than an optional tool, since AI enables faster risk detection, predictive insights, and connected assurance that manual methods cannot match. However, it stresses that strong governance is critical to manage AI-specific risks such as bias, data privacy, and over-reliance, ensuring audits remain credible, ethical, and forward-looking.

News & Blogs · Global Read more

September 2025

longbridge.com ·
In just a few minutes, AI easily passed the CFA Level 3 exam

Researchers from NYU Stern and GoodFin tested 23 large language models and found that cutting-edge reasoning models like Gemini 2.5 Pro, Claude Opus, and o4-mini successfully passed the notoriously difficult CFA Level III mock exam using chain-of-thought prompting. While these models outperformed traditional ones on complex financial reasoning, experts note AI still falls short of human professionals in contextual understanding and client interaction.

News & Blogs · Global Read more
auditboard.com ·
Rising risks, shifting priorities: What the IIA’s Risk in Focus 2026 report means for internal audit

The IIA’s 2026 Risk in Focus Report highlights a volatile risk environment for North American organizations, with geopolitical uncertainty, cybersecurity threats, and digital disruption driving major challenges for internal auditors. Chief audit executives are urged to close gaps between top risks and audit priorities by strengthening cyber assurance, engaging in AI governance, and developing agile strategies to address unprecedented volatility.

News & Blogs · Global Read more
linkedin.com ·
The Metrics That Matter: How to Measure Audit, Risk and Control Functions Without Killing the Culture

![beyond_the_lines](https://media.licdn.com/dms/image/v2/D4E12AQFIhXwOZ-7pRA/article-cover_image-shrink_720_1280/B4EZlrwPutKcAI-/0/1758449434850?e=1761782400&v=beta&t=vOXrPBtNmCBOvqImnoHhDH87g4DqFlfr5rzVUyXu2yw)
This article emphasizes that traditional activity-based metrics in audit, risk, and control functions often drive the wrong behaviors, such as prioritizing volume over insight or compliance over trust. Instead, it argues for outcome-focused, strategically relevant, and culture-supportive metrics that balance hard data with soft signals, promote transparency, and foster better decision-making.

News & Blogs · Global Read more
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →