Why these five Internal Audit, Risk Management and Regulatory Compliance risks — and why your framework is usually not the problem
Every organization we work with has a risk framework. Most have a risk register, a policy suite, a heat map refreshed quarterly, and a maturity score that has improved for three consecutive years. The framework is rarely the problem. The problem is that the framework describes an organization that has since changed — a new system, an acquired entity, a silently enabled AI feature, a restructured finance team — and nobody has re-tested whether the controls it assumes still operate. Maturity scores measure the presence of controls; loss events measure whether they work.
That gap is what a Synergy-IA Fractional Chief Audit Executive exists to close.
What a fractional CAE is. An experienced chief audit executive engaged on a retained or part-time basis to provide independent, third-line assurance: an internal audit charter approved by the board, a risk-based audit plan, actual testing of the controls the business depends on, and reporting of residual risk to the Audit Committee or board rather than to the executives being audited. It is the assurance capacity a company needs before, and often instead of, a full-time CAE, not a lighter version of one.
What it is not. It is not an outsourced compliance function, not a second-line control owner, not a substitute for your external auditor, and not a document-production exercise. A fractional CAE who also performs the second-line work cannot credibly provide third-line assurance on that work. We treat that as a scoping constraint, not a commercial inconvenience.
Who is this written for? Four groups, each holding a different question they need answered before their next board cycle, diligence process, or audit committee self-assessment:
|
Stakeholder |
The question they are actually asking |
|
Board / Audit Committee |
What independent evidence exists that the guardrails work — not that they exist? |
|
Leadership Team (C-suite) |
What are we carrying that we have not priced, and who decides when something new is approved? |
|
PE Operating Partners |
Where is this a value lever, and where is it an unquantified liability that surfaces in diligence or in a warranty claim? |
|
External Audit Partners |
Can we rely on the control environment and on the internal audit function, or must we re-perform the work? |
The five risks, in one line each. These are the topics we are asked about most often, across all four groups:
How to read what follows. Each topic answers the same three questions in the same order: what the risk actually is, what the fractional CAE does about it, and what each stakeholder should specifically take away. The Q&A format is deliberate; these are the questions as they are asked, in the words they are asked in. If you are reading this ahead of a specific decision, a board cycle, an acquisition, an exit, an audit committee assessment, start with the topic that matches that decision, not the one that matches your industry. Where a topic cites a regulation, we link the primary source, and we date it, because these dates move.
Almost never where the policy says. Exposure sits in (i) AI features embedded in software already licensed and silently enabled, (ii) models procured by business units without IT or risk review, (iii) internally built models and prompts that no one has inventoried, and (iv) agentic tools that can now take actions, such as issue payments, send communications, modify records, without human approval. The governance artifact usually covers a small fraction of what is live.
NIST AI RMF - https://www.nist.gov/itl/ai-risk-management-framework
EU AI Act implementation timeline - https://artificialintelligenceact.eu/implementation-timeline/
|
Stakeholder |
What they must take away |
|
Board / Audit Committee |
Whether AI use is inventoried, who owns it, what the worst-case harm is, and what independent evidence exists that guardrails work — including human approval for autonomous actions |
|
Leadership Team |
The list of live AI use cases they were not aware of, the three to pause pending review, and the decision rights for approving new ones |
|
Private Equity Operating Partners |
Where AI is a value lever versus where it is an unquantified liability that will surface in diligence or in a warranty claim |
|
External Audit Partners |
Whether AI is touching transaction processing, revenue recognition, or financial reporting data — and whether IT general controls over those systems are reliable enough to be relied upon |
Because maturity scores measure the presence of controls, while loss events measure whether they work. An improving heat map alongside rising near-misses, longer recovery times, or growing third-party exposure is a reporting failure, not progress.
EIOPA DORA - https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en
SEC - https://www.sec.gov/rules-regulations/2023/07/s7-09-22
|
Stakeholder |
What they must take away |
|
Board / Audit Committee |
Whether the function has tested recovery from a realistic worst case, and whether the disclosure machinery can execute on its regulatory clock |
|
Leadership Team |
Which single points of failure remain, what each is worth in loss terms, and the funded remediation sequence |
|
Private Equity Operating Partners |
Concentration exposure across the portfolio, one vendor incident hitting multiple companies at once, and the cyber-representation risk in an exit |
|
External Audit Partners |
Whether ITGCs over financially significant systems remain effective as the environment changes, and whether cyber risk implies any financial reporting or going-concern implication |
The real question is whether the control environment would still be effective under change — a new system, a new entity from an acquisition, a restructured finance team, or a remote process change, and whether remediation of any prior issue was verified rather than declared. SOX Section 404 requires management to assess internal control over financial reporting and, for accelerated filers, the external auditor to opine on it.
SOX 404 Overview - https://www.cbh.com/insights/articles/sox-404/
|
Stakeholder |
What they must take away |
|
Board / Audit Committee |
Whether prior deficiencies were genuinely remediated and independently verified, and whether the control environment survives the next structural change |
|
Leadership Team |
The residual risk concentrated in a handful of controls, the resource gap behind it, and the cost of failing versus fixing |
|
Private Equity Operating Partners |
Whether the finance function can sustain a public exit — including the readiness gap that most delays a registration |
|
External Audit Partners |
The reliability of management's testing, and whether internal audit's work is of a standard that can be considered under AS 2605 PCAOB AS 2605 - https://pcaobus.org/oversight/standards/auditing-standards/details/as-2605-consideration-of-the-internal-audit-function_1528 |
Because obligations are tracked as a list rather than as control-mapped requirements with named owners, and because horizon scanning is disconnected from the audit plan and the risk register. New obligations are therefore discovered late — usually by the external auditor, a regulator, or a customer audit.
|
Stakeholder |
What they must take away |
|
Board / Audit Committee |
The obligations whose non-compliance carries the greatest combined financial, license, and reputational consequence, and the evidence of readiness |
|
Leadership Team |
The costed compliance runway for the next 12–24 months and the operating changes required |
|
Private Equity Operating Partners |
Regulatory exposure that could affect valuation, deal conditions, or post-close integration timelines |
|
External Audit Partners |
Whether legal and regulatory compliance risk has financial statement consequences, and whether the control environment addresses it |
Scale is not the problem; under-resourcing relative to the risk profile is. Most notably, a function that cannot produce an external quality assessment, cannot maintain independence from the second line, and cannot cover cyber, AI, and IT at all is not delivering assurance; it is delivering reassurance.
The IIA Global Internal Audit Standards - https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/
The IIA Cybersecurity Topical Requirement - https://www.theiia.org/en/standards/2024-standards/topical-requirements/cybersecurity/
|
Stakeholder |
What they must take away |
|
Board / Audit Committee |
Whether the function is adequately resourced and independent enough to rely upon, and what a quality assessment would say |
|
Leadership Team |
The coverage the function cannot currently provide and the exposure that leaves unassured |
|
Private Equity Operating Partners |
Whether the function is a stabilizer or a dependency risk — and the cost of replacing it after exit |
|
External Audit Partners |
Whether the function's competence and objectivity support reliance, or whether the external team must re-perform the work |
These are not five risks. They are one risk, observed in five places. Look at the five topics together, and the same failure appears in each:
The corrective sequence is the same in every case, and it is not expensive relative to the alternative. Build the inventory before the framework — you cannot govern what you have not enumerated. Map each obligation to the control that satisfies it and the owner accountable for it, so that regulatory change immediately identifies which controls must change. Test the small number of controls through which catastrophic loss would actually flow, such as privileged identity, backup integrity and restore, human-in-the-loop thresholds for autonomous actions, management review, and the critical vendors. Then report residual risk to the board as an assurance statement, with a clear account of what remains unassured.
The alternative is not neutrality. It is discovery by someone with a clock running: an external auditor, a regulator, a customer audit, or a buyer's diligence team. Each brings its own evidence, standards, timeline, and view of who was responsible. The cost of arriving second is not a fine; it is a finding that the organization did not know its own exposure.
Three questions to ask any practitioner — including us
Before you engage a fractional CAE, or the firm you are already using, ask these three. Each one tests evidence or independence, not credentials.
The answers to those three questions tell you whether you are buying assurance or buying comfort.
To learn more about Synergy-IA or our Fractional CAE Services, email us at information@synergy-ia.com