Synergy-IA Thinking

The Five GRC Risks That Matter Most — Practical Q&A

Written by Information Synergy-iA | Sep 28, 2026, 1:33:58 AM

Why these five Internal Audit, Risk Management and Regulatory Compliance risks — and why your framework is usually not the problem

Every organization we work with has a risk framework. Most have a risk register, a policy suite, a heat map refreshed quarterly, and a maturity score that has improved for three consecutive years. The framework is rarely the problem. The problem is that the framework describes an organization that has since changed — a new system, an acquired entity, a silently enabled AI feature, a restructured finance team — and nobody has re-tested whether the controls it assumes still operate. Maturity scores measure the presence of controls; loss events measure whether they work.

That gap is what a Synergy-IA Fractional Chief Audit Executive exists to close.

What a fractional CAE is. An experienced chief audit executive engaged on a retained or part-time basis to provide independent, third-line assurance: an internal audit charter approved by the board, a risk-based audit plan, actual testing of the controls the business depends on, and reporting of residual risk to the Audit Committee or board rather than to the executives being audited. It is the assurance capacity a company needs before, and often instead of, a full-time CAE, not a lighter version of one.

What it is not. It is not an outsourced compliance function, not a second-line control owner, not a substitute for your external auditor, and not a document-production exercise. A fractional CAE who also performs the second-line work cannot credibly provide third-line assurance on that work. We treat that as a scoping constraint, not a commercial inconvenience.

Who is this written for? Four groups, each holding a different question they need answered before their next board cycle, diligence process, or audit committee self-assessment:

Stakeholder

The question they are actually asking

Board / Audit Committee

What independent evidence exists that the guardrails work — not that they exist?

Leadership Team (C-suite)

What are we carrying that we have not priced, and who decides when something new is approved?

PE Operating Partners

Where is this a value lever, and where is it an unquantified liability that surfaces in diligence or in a warranty claim?

External Audit Partners

Can we rely on the control environment and on the internal audit function, or must we re-perform the work?

 

The five risks, in one line each. These are the topics we are asked about most often, across all four groups:

  1. AI and agentic AI: Exposure concentrated where no inventory exists: embedded features already licensed, business-unit procurement, internally built models, and agentic tools that can take action without human approval.
  2. Cyber and digital resilience: Improving maturity scores measured against loss events that are not being tested for, including under the assumption that identity, email, and primary communications are compromised at once.
  3. Financial reporting integrity, ICFR, and SOX sustainability: An ICFR conclusion assessed for a period rather than for change, held up by documentation describing a process the entity no longer follows.
  4. Regulatory convergence and horizon risk: Obligations tracked as a list rather than as control-mapped requirements with named owners, so change is discovered by the external auditor, a regulator, or a customer audit.
  5. Talent, succession, and the effectiveness of the audit function itself: The difference between an audit function delivering assurance and one delivering reassurance.

How to read what follows. Each topic answers the same three questions in the same order: what the risk actually is, what the fractional CAE does about it, and what each stakeholder should specifically take away. The Q&A format is deliberate; these are the questions as they are asked, in the words they are asked in. If you are reading this ahead of a specific decision, a board cycle, an acquisition, an exit, an audit committee assessment, start with the topic that matches that decision, not the one that matches your industry. Where a topic cites a regulation, we link the primary source, and we date it, because these dates move.

Topic 1 — AI and Agentic AI: Governance Where the Inventory Does Not Exist

Q: Where are we actually exposed on AI today?

Almost never where the policy says. Exposure sits in (i) AI features embedded in software already licensed and silently enabled, (ii) models procured by business units without IT or risk review, (iii) internally built models and prompts that no one has inventoried, and (iv) agentic tools that can now take actions, such as issue payments, send communications, modify records, without human approval. The governance artifact usually covers a small fraction of what is live.

Q: What does a fractional CAE do differently?

  • Build a complete, current inventory of AI models, use cases, and vendors in your environment as a precondition for any meaningful governance. Without this, the framework is decorative.
  • Apply the NIST AI RMF's Govern, Map, Measure, Manage structure as an operating discipline rather than a reading exercise.
  • Map exposure to the EU AI Act's phased obligations where the organization has EU reach or EU customers (typically high-risk system obligations with enforceable deadlines).
  • Test the controls that actually exist: pre-deployment validation, human-in-the-loop thresholds for agentic actions, data lineage, output monitoring, model change management, and vendor contract terms on training data and liability.
  • Report AI to the Audit Committee as an assurance topic, with a clear statement of residual risk, not as a technology briefing.

NIST AI RMF - https://www.nist.gov/itl/ai-risk-management-framework

EU AI Act implementation timeline - https://artificialintelligenceact.eu/implementation-timeline/

Stakeholder

What they must take away

Board / Audit Committee

Whether AI use is inventoried, who owns it, what the worst-case harm is, and what independent evidence exists that guardrails work — including human approval for autonomous actions

Leadership Team

The list of live AI use cases they were not aware of, the three to pause pending review, and the decision rights for approving new ones

Private Equity Operating Partners

Where AI is a value lever versus where it is an unquantified liability that will surface in diligence or in a warranty claim

External Audit Partners

Whether AI is touching transaction processing, revenue recognition, or financial reporting data — and whether IT general controls over those systems are reliable enough to be relied upon

 

Topic 2 — Cyber and Digital Resilience: Beyond the Heat Map

Q: Our maturity scores keep improving. Why is that not reassuring?

Because maturity scores measure the presence of controls, while loss events measure whether they work. An improving heat map alongside rising near-misses, longer recovery times, or growing third-party exposure is a reporting failure, not progress.

Q: What must actually be tested?

  • Incident and recovery capability under realistic conditions — including the assumption that identity, email, and primary communication channels are compromised simultaneously.
  • The controls the business truly depends on: privileged identity, backup integrity and restore testing, and the small number of critical vendors through whom catastrophic loss would flow.
  • Third-party and Fourth-party concentration, with contract-level visibility into breach notification timelines and the right to audit — particularly where the organization operates in EU financial services, where DORA imposes operational resilience requirements in force since January 2025.
  • The disclosure decision process for public companies: the ability to determine materiality and file within four business days of that determination is itself a control, and it should be tested.

EIOPA DORA - https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en

SEC - https://www.sec.gov/rules-regulations/2023/07/s7-09-22

Stakeholder

What they must take away

Board / Audit Committee

Whether the function has tested recovery from a realistic worst case, and whether the disclosure machinery can execute on its regulatory clock

Leadership Team

Which single points of failure remain, what each is worth in loss terms, and the funded remediation sequence

Private Equity Operating Partners

Concentration exposure across the portfolio, one vendor incident hitting multiple companies at once, and the cyber-representation risk in an exit

External Audit Partners

Whether ITGCs over financially significant systems remain effective as the environment changes, and whether cyber risk implies any financial reporting or going-concern implication

 

Topic 3 — Financial Reporting Integrity, ICFR, and SOX Sustainability

Q: Our ICFR is 'effective'. What is the real question?

The real question is whether the control environment would still be effective under change — a new system, a new entity from an acquisition, a restructured finance team, or a remote process change, and whether remediation of any prior issue was verified rather than declared. SOX Section 404 requires management to assess internal control over financial reporting and, for accelerated filers, the external auditor to opine on it.

SOX 404 Overview - https://www.cbh.com/insights/articles/sox-404/

Q: Where do these engagements fail most often?

  • Key control documentation that describes a process the entity no longer follows — the most common driver of material weaknesses.
  • Insufficient, overstretched accounting resources, leading to compensating reliance on spreadsheets and manual review with no evidence of execution.
  • Management review controls evidenced by a tick rather than by documented challenge.
  • Repeated 'in progress' remediation with no independent verification that the new control actually operated for a sufficient period.
  • Entity-level controls — tone, ethics, fraud risk assessment — asserted rather than tested.

Stakeholder

What they must take away

Board / Audit Committee

Whether prior deficiencies were genuinely remediated and independently verified, and whether the control environment survives the next structural change

Leadership Team

The residual risk concentrated in a handful of controls, the resource gap behind it, and the cost of failing versus fixing

Private Equity Operating Partners

Whether the finance function can sustain a public exit — including the readiness gap that most delays a registration

External Audit Partners

The reliability of management's testing, and whether internal audit's work is of a standard that can be considered under AS 2605

PCAOB AS 2605 - https://pcaobus.org/oversight/standards/auditing-standards/details/as-2605-consideration-of-the-internal-audit-function_1528

 

Topic 4 — Regulatory Convergence and Horizon Risk

Q: We have a compliance team. Why is regulatory change still a surprise?

Because obligations are tracked as a list rather than as control-mapped requirements with named owners, and because horizon scanning is disconnected from the audit plan and the risk register. New obligations are therefore discovered late — usually by the external auditor, a regulator, or a customer audit.

Q: What does integration change?

  • One obligation inventory, mapped to the controls that satisfy each requirement and the owner accountable for each — so a change in the regulation immediately identifies which controls must change and who must change them.
  • A single horizon-scanning process feeding one risk register, so emerging obligations appear in the same heat map as everything else, on the same scale.
  • Coordinated testing: compliance, quality, cyber, IT, and internal audit test different parts of the same obligation without re-testing each other's coverage.
  • A defensible position when obligations conflict or overlap across jurisdictions — documented, decided at leadership level, and reported to the Board.

Stakeholder

What they must take away

Board / Audit Committee

The obligations whose non-compliance carries the greatest combined financial, license, and reputational consequence, and the evidence of readiness

Leadership Team

The costed compliance runway for the next 12–24 months and the operating changes required

Private Equity Operating Partners

Regulatory exposure that could affect valuation, deal conditions, or post-close integration timelines

External Audit Partners

Whether legal and regulatory compliance risk has financial statement consequences, and whether the control environment addresses it

 

Topic 5 — Talent, Succession, and the Effectiveness of the Audit Function Itself

Q: We have a small audit function. Is that a problem?

Scale is not the problem; under-resourcing relative to the risk profile is. Most notably, a function that cannot produce an external quality assessment, cannot maintain independence from the second line, and cannot cover cyber, AI, and IT at all is not delivering assurance; it is delivering reassurance.

Q: What must be verified about the function?

  • Charter, mandate, and reporting lines conform to the Global Internal Audit Standards effective January 2025
  • An internal quality assurance program and an external quality assessment on the required cycle.
  • Coverage of the topical requirements now expected of internal audit — including cybersecurity, effective February 2026
  • Competence and succession: what happens when the single CAE or the single IT auditor leaves.
  • Independence safeguards when the same individuals perform second-line and third-line work.

The IIA Global Internal Audit Standards - https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/

The IIA Cybersecurity Topical Requirement - https://www.theiia.org/en/standards/2024-standards/topical-requirements/cybersecurity/

Stakeholder

What they must take away

Board / Audit Committee

Whether the function is adequately resourced and independent enough to rely upon, and what a quality assessment would say

Leadership Team

The coverage the function cannot currently provide and the exposure that leaves unassured

Private Equity Operating Partners

Whether the function is a stabilizer or a dependency risk — and the cost of replacing it after exit

External Audit Partners

Whether the function's competence and objectivity support reliance, or whether the external team must re-perform the work

 

These are not five risks. They are one risk, observed in five places. Look at the five topics together, and the same failure appears in each:

  • A governance artifact has drifted away from the operating reality, and the drift was invisible because nothing was being tested.
  • The AI policy covers a fraction of the AI in use.
  • The heat map improves while near-misses rise.
  • The ICFR conclusion is effective for a period that has already ended.
  • The compliance list is current but not mapped to the controls that satisfy it.
  • The audit charter is compliant on paper, and the function cannot cover cyber, AI, or IT at all.

The corrective sequence is the same in every case, and it is not expensive relative to the alternative. Build the inventory before the framework — you cannot govern what you have not enumerated. Map each obligation to the control that satisfies it and the owner accountable for it, so that regulatory change immediately identifies which controls must change. Test the small number of controls through which catastrophic loss would actually flow, such as privileged identity, backup integrity and restore, human-in-the-loop thresholds for autonomous actions, management review, and the critical vendors. Then report residual risk to the board as an assurance statement, with a clear account of what remains unassured.

The alternative is not neutrality. It is discovery by someone with a clock running: an external auditor, a regulator, a customer audit, or a buyer's diligence team. Each brings its own evidence, standards, timeline, and view of who was responsible. The cost of arriving second is not a fine; it is a finding that the organization did not know its own exposure.

Three questions to ask any practitioner — including us

Before you engage a fractional CAE, or the firm you are already using, ask these three. Each one tests evidence or independence, not credentials.

  1. Show me an engagement where your testing contradicted what management had reported. What was the finding, what evidence supported it, and was the remediation independently verified rather than merely declared? This is the question that separates practitioners who test controls from practitioners who document them. A provider with no such example is either new to this work or is producing paperwork. Ask specifically how remediation was verified as operating for a sufficient period, not whether it was marked complete.
  2. Who is your mandate accountable to, and what work would you decline because performing it would compromise your independence? The reporting line is the whole product. A fractional CAE who reports to the CFO is not providing third-line assurance. Neither is one who designs and implements the controls they later audit. The second half of the question matters as much as the first: a provider who cannot name work they would turn down has no independence constraint to offer you.
  3. If you became unavailable tomorrow, what could a successor or our external auditor, working under AS 2605, rely on? This tests documentation standards, succession, and whether the work is reliance-grade at the workpaper level, not merely readable at the summary level. It also exposes single-person dependencies, which is the same risk you are assessing in your own function.

The answers to those three questions tell you whether you are buying assurance or buying comfort.

To learn more about Synergy-IA or our Fractional CAE Services, email us at information@synergy-ia.com