IIA Guidance: Internal Audit's Evolving Role in ERM and the Future of Assurance
The IIA has released new guidance exploring how internal audit can take a more direct and integrated role in Enterprise Risk Management (ERM). This shift is crucial for audit professionals to demonstrate continued value in an era where AI and automation are transforming traditional audit functions, pushing towards continuous assurance and potentially blurring the lines between audit and risk management. Understanding these evolving expectations and the safeguards required is essential for internal audit leaders looking to strategically position their teams for the future.
The Evolving Landscape for Internal Audit and ERM
The Institute of Internal Auditors (IIA) has published new guidance that signals a significant evolution in the role of internal audit, particularly concerning Enterprise Risk Management (ERM). This guidance acknowledges that the traditional, more isolated function of internal audit is becoming outdated. It suggests that internal audit teams can, and perhaps should, play a more direct and integrated role in ERM. This move is partly driven by economic pressures leading companies to consolidate functions, often by having Chief Audit Executives (CAEs) also serve as Chief Risk Officers (CROs. More profoundly, it reflects a growing concern that advancements in artificial intelligence (AI) are making traditional periodic control testing less relevant, pushing internal audit to find new ways to demonstrate value.
Navigating the Integration: Opportunities and Safeguards
The IIA's guidance outlines five key areas where internal audit can contribute to ERM: identifying risks (e.g., advising on risk taxonomy), assessing risks (e.g., evaluating risks across the organization and against risk appetite), managing risks (advising on policies and controls without owning final decisions), monitoring risks (e.g., tracking action plans and advising on KRIs), and reporting risks (providing assurance over reporting and escalation processes). While these present clear opportunities for internal audit to expand its influence, the guidance also emphasizes critical safeguards to maintain independence and objectivity. These include clear documentation of responsibilities, formal board approval for expanded roles, separation of advisory and assurance work, transparent disclosure of potential impairments, the CAE's right to challenge duties that compromise independence, and independent assurance arrangements for ERM oversight.
The Imperative for Change: Continuous Assurance and AI
The underlying driver for internal audit's deeper engagement with ERM is the rapid advancement of AI and automation. These technologies are enabling a shift from traditional sample-based auditing to continuous assurance, where all transactions can be monitored in real-time for anomalies. This capability allows for immediate identification of non-standard events and trends, effectively merging with the objectives of risk management. If internal audit does not embrace these ERM duties, other risk management teams will likely fill the void, potentially encroaching on internal audit's traditional turf and reducing its organizational clout. The guidance implicitly urges internal audit leaders to proactively adapt to this transformation, ensuring their teams remain relevant and effective in a continuously evolving risk landscape, rather than being relegated to less impactful, easily automatable tasks like SOX compliance.
Read more