What Is Wrong with How Internal Audit, Risk Management, and Regulatory Compliance Engagements Are Executed Today?
These observations from our experience hold across large and small organizations, in both public and private sectors. The failure modes are the same; only the scale changes.
Internal audit has drifted, in too many organizations, into a compliance-production business.
The IIA's Global Internal Audit Standards, effective 9 January 2025, reset expectations: internal audit must be positioned independently, deliberately resourced, governed by a charter, and subject to quality assessment.
The IIA Global Internal Audit Standards remain the benchmark.
Many organizations have updated documentation without changing the behavior.
1.2 Risk Management
Risk registers have become administrative artifacts refreshed to a calendar rather than to a decision.
Compliance is usually organized around whichever regulator is loudest this quarter.
Quality functions typically own a management system and can produce certificates and calibration records, but struggle to show that the system prevents customer, patient, or product harm. Quality data — non-conformances, deviations, complaints, corrective-action aging — is analyzed in isolation from operational risk and internal audit, so the same underlying process weakness becomes simultaneously a quality deviation, a compliance breach, and an audit finding: recorded three times, owned by nobody.
AI entered the business through procurement, productivity features embedded in already-licensed software, and individual experimentation. The governance response is typically a policy, a principles statement, and an approval forum that reviews a small fraction of what is genuinely in use.
There is rarely a complete inventory of models and use cases, rarely any pre-deployment testing, rarely any monitoring of drift or bias afterward, and almost never a clear answer to the question the Board actually asks: what would have to go wrong with this to materially damage us?
The NIST AI Risk Management Framework's four functions — Govern, Map, Measure, Manage — remain the most practical operating structure. The EU AI Act's phased application is creating hard, dated obligations for high-risk systems.
Cyber assurance is dominated by maturity scores and control-coverage dashboards.
The IIA's Cybersecurity Topical Requirement, effective 5 February 2026, now expects internal audit to assess cybersecurity governance, risk management, controls, and resilience in a consistent, comprehensive way — which will expose how much prior cyber assurance was really vendor questionnaire management.
IT audit is still frequently delivered as a list of general controls: change management, access reviews, backups, job scheduling, and tested in isolation from the business processes they enable. Meanwhile, the actual IT risk has moved to the cloud, to the identities that span everything, and to a small number of vendors on which the entire operating model depends. IT and cyber findings are logged in a different register from audit findings, escalated on a different cycle, and reported in a different format, inadvertently ensuring that no reader or decision-maker ever sees the combined picture.
Independent research continues to place cybersecurity, digital disruption, and geopolitical uncertainty at the top of the global risk agenda.
The IIA Risk in Focus observations and practitioners wrestling with the same structural problems for a decade: unclear accountability between the three lines, weak independence, and duplicated assurance.
Duplication is not a harmless inefficiency: Deloitte's work on modernizing the three lines model shows that the first line experiences audit fatigue from duplicative testing by the second and third lines and loses time it should spend on the business (supporting the formulation and execution of a cohesive strategy).
To learn more about Synergy-IA or our Fractional CAE Services, email us at information@synergy-ia.com