Skip to content

What Is Wrong with How GRC Engagements Are Executed Today

Information Synergy-iA
Information Synergy-iA
What Is Wrong with How GRC Engagements Are Executed Today
6:10

What Is Wrong with How Internal Audit, Risk Management, and Regulatory Compliance Engagements Are Executed Today?

These observations from our experience hold across large and small organizations, in both public and private sectors. The failure modes are the same; only the scale changes.

1.1 Internal Audit

Internal audit has drifted, in too many organizations, into a compliance-production business.

  • Plans are built on last year's data and information, plus a rotation schedule, rather than on fresh evidence about where enterprise value is most exposed.
  • Scope is negotiated down by the auditee.
  • Findings are written to be agreed rather than to be useful.
  • The volume of observations is celebrated, while the same root causes recur for the third consecutive cycle.
  • In smaller organizations, internal audit is often one person with a partial workload, no external quality assessment, and no genuine reporting line to the Board.

The IIA's Global Internal Audit Standards, effective 9 January 2025, reset expectations: internal audit must be positioned independently, deliberately resourced, governed by a charter, and subject to quality assessment.

The IIA Global Internal Audit Standards remain the benchmark. 

Many organizations have updated documentation without changing the behavior.

 1.2 Risk Management

Risk registers have become administrative artifacts refreshed to a calendar rather than to a decision.

  • Risks are described in the language of discomfort ('talent retention challenges') instead of the language of loss ('we lose three of five plant managers within a quarter').
  • Inherent and residual ratings are assigned by workshop consensus rather than evidence, and are rarely connected to appetite statements anyone would recognize in a capital allocation meeting.
  • The  COSO ERM remains the reference architecture for many organizations, but architecture is not operation.

1.3 Regulatory Compliance

Compliance is usually organized around whichever regulator is loudest this quarter.

  • Horizon scanning exists but sits disconnected from the risk register and the audit plan, so new obligations are discovered late — frequently by the external auditor or a regulator rather than by the second line.
  • Obligation inventories are maintained as lists rather than as control-mapped requirements with named owners.
  • Testing happens once at implementation and is never repeated when the business process, system, or vendor changes.

1.4 Quality

Quality functions typically own a management system and can produce certificates and calibration records, but struggle to show that the system prevents customer, patient, or product harm. Quality data — non-conformances, deviations, complaints, corrective-action aging — is analyzed in isolation from operational risk and internal audit, so the same underlying process weakness becomes simultaneously a quality deviation, a compliance breach, and an audit finding: recorded three times, owned by nobody.

1.5 AI Governance

AI entered the business through procurement, productivity features embedded in already-licensed software, and individual experimentation. The governance response is typically a policy, a principles statement, and an approval forum that reviews a small fraction of what is genuinely in use.

There is rarely a complete inventory of models and use cases, rarely any pre-deployment testing, rarely any monitoring of drift or bias afterward, and almost never a clear answer to the question the Board actually asks: what would have to go wrong with this to materially damage us?

The NIST AI Risk Management Framework's four functions — Govern, Map, Measure, Manage — remain the most practical operating structure.  The EU AI Act's phased application is creating hard, dated obligations for high-risk systems.

1.6 Cyber

Cyber assurance is dominated by maturity scores and control-coverage dashboards.

  • Boards see heat maps that improve every year, while loss events, near-misses, and third-party exposures tell a different story.
  • Incident response plans exist but have never been tested against a scenario in which the primary communication channels and the identity provider are compromised.

The  IIA's Cybersecurity Topical Requirement, effective 5 February 2026, now expects internal audit to assess cybersecurity governance, risk management, controls, and resilience in a consistent, comprehensive way — which will expose how much prior cyber assurance was really vendor questionnaire management.

1.7 Information Technology (IT)

IT audit is still frequently delivered as a list of general controls: change management, access reviews, backups, job scheduling, and tested in isolation from the business processes they enable. Meanwhile, the actual IT risk has moved to the cloud, to the identities that span everything, and to a small number of vendors on which the entire operating model depends. IT and cyber findings are logged in a different register from audit findings, escalated on a different cycle, and reported in a different format, inadvertently ensuring that no reader or decision-maker ever sees the combined picture.

1.8 The pattern — and why it persists

Independent research continues to place cybersecurity, digital disruption, and geopolitical uncertainty at the top of the global risk agenda.

The IIA Risk in Focus observations and practitioners wrestling with the same structural problems for a decade: unclear accountability between the three lines, weak independence, and duplicated assurance.

Duplication is not a harmless inefficiency: Deloitte's work on modernizing the three lines model shows that the first line experiences audit fatigue from duplicative testing by the second and third lines and loses time it should spend on the business (supporting the formulation and execution of a cohesive strategy).

To learn more about Synergy-IA or our Fractional CAE Services, email us at information@synergy-ia.com  

Share this post