Tuesday, September 15, 2026

Is internal audit unintentionally diminishing the significance of compliance?

 When internal auditors and risk management professionals emphasize that their role extends beyond compliance, do they risk unintentionally diminishing the perceived importance of compliance itself? I posed this question to Gemini, and here is the perspective it offered:


No. Framing services as "going beyond compliance" elevates compliance rather than undermining it, positioning compliance as the non-negotiable baseline, not the ceiling.
When internal audit (IA) and risk management emphasize value beyond compliance, they are addressing a common perception that risk functions exist solely as check-the-box regulatory police.
Why "Beyond Compliance" Strengthens the Baseline:
* Establishes compliance as table stakes: To provide strategic advisory, operational insights, or performance optimization, a risk or audit function must first assume that regulatory and legal standards are fully met.
* Prevents blind spots: A pure compliance focus often misses strategic, reputational, or emerging operational risks that aren't governed by explicit laws. Moving beyond compliance ensures those gaps are monitored.
* Drives business integration: Leaders rarely engage deeply with audit findings if they only address low-level administrative rules. Linking compliance to business objectives, risk mitigation, and revenue protection increases buy-in across management.

Where the Risk Lies:
The narrative only becomes problematic if internal audit or risk management neglects core compliance duties in pursuit of strategic consulting. If baseline internal controls fail or regulatory mandates are overlooked while chasing "strategic value," then compliance and organizational credibility are undermined.
True value exists in a spectrum: Compliance protects value, while going beyond compliance builds and optimizes value.
hashtaginternalaudit hashtagcompliance hashtagrisk hashtagGRC




Thursday, July 23, 2026

Humans: The Real Risk Factor in AI

 Artificial Intelligence is often seen as the looming risk to society. However, the greatest risk lies not in the algorithms themselves, but in us, the humans who design, deploy, and govern them.


Human-Centric Risks:
* Bias in design: AI reflects the data and assumptions we feed it. When those inputs are biased, the outputs amplify discrimination.
* Governance failures: Weak oversight and profit-driven motives often push unsafe systems into critical domains.
* Overreliance on automation: Blind trust in AI outputs can sideline human judgment, leading to catastrophic errors.
* Weaponization risks: AI becomes dangerous when deliberately misused for surveillance, cyberwarfare, or autonomous weapons.
* Transparency gaps: Corporate secrecy and opaque models prevent accountability, leaving users and regulators in the dark.

Why Humans Are the Core Risk:
AI is a mirror. It reflects our values, decisions, and flaws. Systemic issues, corporate incentives, political agendas, and cultural biases shape whether AI becomes a tool for progress or a weapon of harm.

Key Takeaway:
The narrative that "AI is dangerous" misses the point. Humans are the variable that determines whether AI advances society or undermines it. Stronger governance, transparent design, and ethical foresight are not optional; they are the safeguards against our own misuse.

Instead of fearing AI, we should fear complacency in how we manage it. The question isn’t whether AI will be safe; it’s whether we will be responsible enough to make it so.

#risk #airisk #governance #ai #internalaudit
This post was prepared using AI





Friday, June 26, 2026

Culture Risks within Internal Audit

 In a recent Wolters Kluwer webinar on Talent, Culture, and Workforce Transformation in Internal Audit, Liz Sandwith highlighted the growing expectation for internal audit to provide assurance on organizational culture, ethics, and leadership resilience.


Equally important, she emphasized the need to turn the lens inward, examining the culture within the internal audit function itself. Because how we operate as auditors directly shapes the credibility and value we deliver.

Liz also shared examples of cultural risks within internal audit. One that resonated deeply with me was the “fear culture suppressing professional skepticism.”

In my long consulting career, I have seen firsthand how fear can erode the performance of internal audit teams, silencing voices, weakening challenge, and ultimately diminishing assurance. Sadly, this culture still exists in some functions today.

For over two decades, I have been calling on internal auditors to be courageous. I am relieved that this principle is now emphasized in the Global Internal Audit Standards. Yet, adoption remains uneven, and many functions have yet to embed courage as a defining trait of their culture.

It is time for internal auditors to break free from fear, embrace skepticism, and stand firm as guardians of integrity.




#InternalAudit #Culture #ProfessionalSkepticism #Courage #GlobalStandards

Friday, June 19, 2026

When oversight fails, trust takes a nosedive

 


The revelation that an Air Canada pilot flew for 17 years with fraudulent licences is more than a headline; it’s a governance crisis. Internal audit and compliance functions missed repeated opportunities to uncover the fraud, relying on documents rather than independent validation. The result? A fraud that persisted for nearly two decades, exposing passengers to unacceptable risk and eroding public confidence.

For executives and boards, the lessons are clear:

  • Professional skepticism must be embedded into every audit process.

  • Governance credibility depends on robust, independent checks, not blind trust.

  • Aviation risk lessons remind us that continuous monitoring and real-time assurance are essential in industries where lives are at stake.

If internal audit cannot help detect fraud in time, governance collapses into guesswork.

The question for leaders today: Are your internal audit functions truly equipped to protect what matters most?




Monday, June 15, 2026

Do we need more skepticism in the age of AI?

 

Dr. Michael Shermer reminds us:

“Skepticism is not a position; it’s a process.”


That process feels more urgent and important than ever. AI can generate dazzling insights, but it can also produce errors, biases, and illusions of certainty. Skepticism isn’t about cynicism or rejection; it’s about critical inquiry, verification, and disciplined questioning.


In a world where algorithms shape decisions, the real advantage belongs to leaders and professionals who ask:


* What evidence supports this output?

* What assumptions are hidden in the model?

* Where could bias creep in?


Skepticism in the AI era isn’t resistance; it’s resilience. It’s how we ensure technology serves truth, not just speed.


Question for you:

Do you see skepticism as a skill we need to teach more actively in organizations adopting AI?








#internalaudit #risk #grc #skills #skepticism #ai


Sunday, June 7, 2026

Being an internal auditor doesn’t stop at the office; it shapes who we are.

 As we conclude Internal Audit Awareness Month and celebrate our pride in being internal auditors, it is important to remember that every profession leaves its mark not only on our careers, but also on our personalities and personal lives.


Being an internal auditor doesn’t stop at the office; it shapes who we are.

The positives?
We bring integrity, reliability, and critical thinking into every relationship.
The challenges?
Sometimes our vigilance makes us overly cautious or skeptical with family and friends.


The key is balance: carrying our strengths proudly while softening the edges in personal spaces. Internal audit isn’t just a profession; it’s a way of living with trust and accountability.




Is internal audit unintentionally diminishing the significance of compliance?

  When internal auditors and risk management professionals emphasize that their role extends beyond compliance, do they risk unintentionally...