IIA Guidance: Internal Audit's Evolving Role in ERM and the Future of Assurance
The IIA has released new guidance exploring how internal audit can take a more direct and integrated role in Enterprise Risk Management (ERM). This shift is crucial for audit professionals to demonstrate continued value in an era where AI and automation are transforming traditional audit functions, pushing towards continuous assurance and potentially blurring the lines between internal audit and risk management. Understanding these evolving expectations and the safeguards required is essential for internal audit leaders looking to strategically position their teams for the future.
Internal Audit's Shifting Landscape: Embracing ERM
The Institute of Internal Auditors (IIA) has published new guidance that signals a significant evolution in the role of internal audit, particularly concerning Enterprise Risk Management (ERM). This guidance acknowledges that the traditional, more isolated function of internal audit is becoming outdated. Instead, it advocates for internal audit teams to play a more direct and integrated role in ERM, moving beyond their conventional 'Third Line of Defense' position. This strategic pivot is partly driven by economic pressures leading organizations to consolidate functions, but also by the disruptive potential of artificial intelligence (AI) and automation, which are rapidly making traditional periodic control testing less relevant.
Navigating the Integration: Opportunities and Safeguards
The IIA's guidance outlines five key areas where internal audit can contribute to ERM: identifying risks, assessing risks, advising on risk management, monitoring risk action plans, and reporting on risk processes. While internal audit can offer valuable insights into risk taxonomy, consistency of language, and the effectiveness of risk reporting, the guidance stresses a critical distinction: internal audit should advise on policies and controls but not own final risk response decisions. This careful balance is crucial to maintain internal audit's independence and objectivity. The document also addresses the growing trend of Chief Audit Executives (CAEs) taking on Chief Risk Officer (CRO) responsibilities, highlighting the need for clear boundaries.
To prevent conflicts of interest and preserve independence when internal audit assumes ERM responsibilities, the IIA recommends several safeguards:
- Clearly documenting the allocation of responsibilities across all three lines of defense.
- Obtaining formal board approval for expanded responsibilities.
- Separating advisory and assurance work, ensuring different personnel handle related tasks.
- Transparently disclosing any potential impairments to the board.
- Empowering the CAE to challenge proposed ERM duties that could compromise internal audit's independence.
- Arranging for independent assurance (e.g., from an external auditor) if internal audit oversees the ERM program.
These measures are designed to ensure that while internal audit expands its influence, its core principles of independence and objectivity remain intact.
The Imperative for Change: Continuous Assurance and AI
The underlying motivation for internal audit to embrace ERM is the accelerating impact of AI and automation. These technologies are enabling a shift from traditional sample-based auditing to continuous assurance, where all transactions can be monitored in real-time for anomalies. This capability blurs the lines between auditing and risk management, as continuous monitoring inherently identifies and flags risks as they emerge. If internal audit does not adapt and integrate these capabilities, other risk management functions will, potentially marginalizing the internal audit department. By proactively engaging with ERM and leveraging new technologies, internal audit can secure its relevance, demonstrate greater value to the organization, and avoid being relegated to less impactful, easily automatable tasks like SOX compliance. The IIA's guidance serves as a roadmap for internal audit leaders to navigate this transformation strategically and effectively.
Read more