Showing posts with label Audit standard. Show all posts
Showing posts with label Audit standard. Show all posts

Friday, June 26, 2026

Culture Risks within Internal Audit

 In a recent Wolters Kluwer webinar on Talent, Culture, and Workforce Transformation in Internal Audit, Liz Sandwith highlighted the growing expectation for internal audit to provide assurance on organizational culture, ethics, and leadership resilience.


Equally important, she emphasized the need to turn the lens inward, examining the culture within the internal audit function itself. Because how we operate as auditors directly shapes the credibility and value we deliver.

Liz also shared examples of cultural risks within internal audit. One that resonated deeply with me was the “fear culture suppressing professional skepticism.”

In my long consulting career, I have seen firsthand how fear can erode the performance of internal audit teams, silencing voices, weakening challenge, and ultimately diminishing assurance. Sadly, this culture still exists in some functions today.

For over two decades, I have been calling on internal auditors to be courageous. I am relieved that this principle is now emphasized in the Global Internal Audit Standards. Yet, adoption remains uneven, and many functions have yet to embed courage as a defining trait of their culture.

It is time for internal auditors to break free from fear, embrace skepticism, and stand firm as guardians of integrity.




#InternalAudit #Culture #ProfessionalSkepticism #Courage #GlobalStandards

Monday, June 15, 2026

Do we need more skepticism in the age of AI?

 

Dr. Michael Shermer reminds us:

“Skepticism is not a position; it’s a process.”


That process feels more urgent and important than ever. AI can generate dazzling insights, but it can also produce errors, biases, and illusions of certainty. Skepticism isn’t about cynicism or rejection; it’s about critical inquiry, verification, and disciplined questioning.


In a world where algorithms shape decisions, the real advantage belongs to leaders and professionals who ask:


* What evidence supports this output?

* What assumptions are hidden in the model?

* Where could bias creep in?


Skepticism in the AI era isn’t resistance; it’s resilience. It’s how we ensure technology serves truth, not just speed.


Question for you:

Do you see skepticism as a skill we need to teach more actively in organizations adopting AI?








#internalaudit #risk #grc #skills #skepticism #ai


Saturday, March 7, 2026

Fraud Awareness Begins at Home

Fraud is not just a corporate or financial issue; it’s a human one. Every scam, phishing attempt, or deceptive scheme ultimately targets individuals and families. That’s why fraud awareness must start at home.

  • Early Education: Teaching children and family members about online safety, suspicious messages, and too-good-to-be-true offers builds lifelong resilience.

  • Shared Vigilance: Discussing fraud cases openly at home helps normalize caution. When one person spots a red flag, the whole household learns.

  • Digital Habits: Simple practices, such as verifying links, protecting passwords, and questioning unusual requests, are as vital at home as in the workplace.

  • Empowerment: Awareness transforms fear into strength. Families who understand fraud tactics are less likely to fall victim and more likely to protect others.

Fraud prevention is not just about compliance or corporate training; it’s about safeguarding trust, dignity, and security in our daily lives. When awareness begins at home, it extends naturally into our communities and organizations.




Thursday, January 15, 2026

Is SOC audits a substitute for third‑party risk assessments?

Could SOC audits serve as a practical substitute for third‑party risk management practices, particularly in smaller organizations? We posed the question to AI, and here’s what it had to say:


SOC audits are not a substitute for third‑party risk assessments.

They are a piece of the puzzle, not the whole picture.

A SOC report provides independent assurance that a vendor’s controls have been tested. It’s a valuable trust signal, but it doesn’t tell the full story.

Third‑party risk assessment goes further:

🌐 Evaluates financial stability, compliance posture, and resilience

🔍 Considers governance, subcontractors, and reputational exposure

📊 Provides a holistic view across people, processes, and technology

👉 Best practice: Use SOC reports within your risk assessment program, not instead of it. True resilience requires layered assurance.


What’s your perspective?

Monday, December 30, 2024

Are You Ready for the New Global Internal Audit Standards?

 With the Global Internal Audit Standards set to take effect on January 9, 2025, it is crucial that the audit committee is well-prepared and familiar with these standards. To assist with this, we have created a brief presentation designed to equip audit committee members with essential information.

Reach out to us to schedule an in-person or remote presentation.




Saturday, December 21, 2024

Is Climate Change a Greater Risk in the Middle East than Geopolitical Risks?

 Is climate change a greater risk in the Middle East than geopolitical risks in the next three years? According to the 179 respondents to the IIA Foundation's "2025 Risk in Focus—Middle East" survey, it seems so!

Geopolitical risk in the Middle East is real and should definitely be among the top five risks on the list of emerging risks. Anyone who disagrees is out of touch with reality!"

CAEs in the region often avoid addressing what could appear to be politically sensitive issues, which is understandable given the context. However, CAEs, in our opinion, must give more serious attention to the impact of geopolitical risks on their region and organizations.




Friday, November 24, 2023

Takeaways from my 2023 ethics CPEs

 As you are aware, licensed CIA's are required to take at least two hours of training in the field of ethics. I have just completed mine and I would like to share with you some takeaways:

1. Becoming the everyday ethicist:

This session was presented by Amanda Erven. The one technique I liked about how to achieve this objective is by developing your own personal value statement and code of self-conduct! It is a great idea. I encourage internal auditors to adopt this important step towards becoming an everyday ethicist.



2. Exploring workplace honesty and ethical gray areas:
This session was presented by Christian Miller. I liked his discussion regarding the differences between an honest person and someone who exhibits honest behavior as shown below.






Finally, I came across a white paper by IIA Australia entitled "Why people do not accurately disclose their conflicts of interest". Here is a paragraph from it:

"There are three significant ways in which people withhold information about conflicts of interest:
  1. People do not disclose conflicts of interest
  2. People only partially disclose conflicts of interest
  3. People give misleading disclosures that result in information being hidden

These are referred to in this White Paper as the sides of the ‘Conflict of Interest Bermuda Triangle’. Examining the reasons people do not make full disclosures of conflicts of interest will help us improve disclosure systems and internal controls over conflicts of interest."

Please share your takeaways from your ethics training with the group so we can raise awareness of the importance of ethics in our lives.


Monday, August 21, 2023

Why did you become an Internal Auditor?

Many years ago, I have prepared a presentation for training purposes aimed at new and "would be" internal auditors. The presentation title was "So, you want to be an internal auditor!". It addresses the reasons why someone would want to be an internal auditor and if he/she have what it takes to be a successful one.
I am sharing it with you today although it needs to be updated.

https://www.linkedin.com/feed/update/urn:li:activity:7099449373981327360?utm_source=share&utm_medium=member_desktop



Thursday, August 25, 2022

Takeaways from my recent readings

In this post, I am sharing some interesting takeaways from my recent readings. I will keep it very brief to enable you to go through it despite of your busy schedule! Of course, you can always download the original documents if you wish to learn more.

 Key Components of Digital Trust:

ISACA in a new free guide (Understanding the Six Key Components of Digital Trust| ISACA) defines digital trust as:

"Digital trust is confidence in the integrity of relationships among providers and consumers in a digital ecosystem."

The guide has identified six key components of the trust as follows:

  • Quality of products and services
  • Availability of information 24/7/365
  • Security and Privacy
  • Ethics and Integrity
  • Transparency and honesty 
  • Stability and Resilience


 Recession Playbook for Chief Audit Executives:

A Gartner 2022-2023 playbook identified the following 9 actions across three main areas that is believed to help in managing resources, being agile in securing talent, and accelerate digital and technological initiatives:


You can download the playbook by following this link:


Turning Audit Clients into Allies

In its 2022 audit management playbook, AUDITBOARD offered some tips for turning audit clients into allies:




You can download a copy by following this link:

The Audit Management Playbook [2022 Updated] | AuditBoard


Friday, December 11, 2020

It is time for an honest self-assessment!

As this unprecedented year is winding down, it is time for internal audit to take a moment and perform an honest self-assessment that goes beyond the requirements of standard 1311 of the International Standards of the Professional Practice of Internal Auditing.

If you have not already performed the assessment, here is a list of some suggested questions internal auditors need to ask themselves:

  • Did we really try our best to help our company to survive and succeed in any way we could?
  • Did we act fast enough or did we panic and hesitated?
  • Did we adapt to the new normal in a reasonable time?
  • Were we prepared for a crisis like this in terms of training, communication skills, and mindset? 
  • Did we lead or did we wait to be told what to do?
  • Did we realize that the pandemic also presented a unique opportunity for internal audit to rise and shine? Did we take advantage of this opportunity?
  • What did we learn about ourselves at the professional and personal levels? Is an internal audit career still in our future?
  • Did we accurately identify our weaknesses and shortcomings and developed a plan to deal with them?
  • Are we now more relevant or less relevant to the company? Did our stakeholders change their perception about internal audit? 
  • Do we have a clear vision of our role and responsibilities post-pandemic? Do we understand how we can contribute to business resilience and the continuation of operations?
  • If we have failed, do we have the courage to admit it and seek help to transform and pave the way back to success?
Some of the above questions are difficult to digest and answer. But, unless we do so, we can not move forward and achieve our goals. 

It takes honesty, courage, and determination to address the above questions and take appropriate actions.

These are my thoughts, please share yours!



Picture source:https://efisoul63.wordpress.com

Tuesday, August 25, 2020

What does innovation mean to Internal Audit?

 

The pressure is mounting on Internal Audit to become innovative and this is understandable and expected. The call for innovation is not new but has certainly intensified during the COVID 19 pandemic as organizations are going through changes and transformation to adapt to the new normals. Innovation may mean different things to different people, in this post I will discuss what innovation means to internal audit.

What is innovation?

In traditional dictionaries, innovation is defined as developing a new idea, method, service, or product. In reality, it is more than that. It also refers to updating current processes to improve the quality of services and products. It does not mean that you always start from scratch!

What is innovation in internal audit?

There may not be a unified definition of what innovation in internal audit means. For some it could mean reinventing internal audit, for others, it means one or more of the following:
  • transformation to agile internal auditing
  • better leveraging of technology and greater use of data analytics, RPA, and AI
  • exploring and accepting new ideas and alternative processes to improve audits
  • empowering the creativity of internal auditors and encouraging brainstorming
  • better utilization of available resources
  • understanding how the organization is changing its business model and operations and adjusting audit plans and procedures accordingly
  • more access to specialized skills internally and externally
  • enhanced reporting and real-time communication
  • more investment in relevant training
  • risk anticipation and enhanced risk assessment
  • change of internal audit mindset and culture
  • striking the right balance between consulting and assurance services
What else do you consider as an innovation in internal audit?
Please share what innovation means to you. I would love to update the above-mentioned list with your definition and understanding of innovation in internal audit.

How to become innovative?

The first step is to clearly define innovation and ensure that your stakeholders agree with it. Then develop your objectives and start working on your mindset and the mindset of your team. Don't be afraid to think loudly even if what you are thinking about sounds crazy and illusional! Put some of these crazy ideas to test and see what happens!  I like the advice offered by a  themuse article on how successful people become more innovative. It lists the following characteristics.
  • they don't discount their crazy ideas
  • they get comfortable with fear
  • they learn about anything and everything
  • they never think they know it all
  • they surround themselves with heroes

Please share what innovation means to you and what have you done in practice to become innovative.

These are my thoughts, please share yours.





Getty Images

Tuesday, August 11, 2020

Has your Internal Audit function tested positive for the irrelevance virus?

 By now, most of you have realized that the world as we knew it has changed forever! The change has affected almost everything in our lives at the personal and professional levels. Some of the changes could be opportunities in disguise, while others could bring devastating consequences to some businesses and certain functions within an organization.

Has your Internal Audit function tested positive for irrelevance?
While many Internal Audit functions have shined and demonstrated that they are indispensable during the crises, others were not so lucky! If your Internal Audit has failed to provide help, add real value, and start the evolution process during the pandemic, it could be because it has been infected with the "irrelevance" virus! In this case, your Internal Audit is dying or most probably has been dead for a while!

On a more serious note, can the COVID 19 pandemic weaken internal audit in some organizations? The answer depends on many factors such as:

  • The performance of Internal Audit: if you have not proved your value to the organization during this crisis, it is unlikely that your Internal Audit function will emerge from it unscathed.
  • The performance of the organization: financial difficulties may lead to cuts in the Internal Audit budget, lay off of auditors, and/or other measures.
  • Some fear that management may attempt to use the crisis as an excuse to weaken Internal Audit to serve its agenda or in retaliation for previous actions by Internal Audit! I would like to believe that this scenario will not happen.

Get Vaccinated!
Yes. there is a vaccine against irrelevance and if you have not taken it yet, do that now. It is not too late. Here are some basic vaccine dose recommendations:
  • Leave your comfort zone immediately and be agile. At AdapGility Consulting we developed the motto " Be agile, be alive" because these days if your IA function is not agile it means it is paralyzed or dead!
  • Work on your mindset (that could be the hardest part). Become flexible and adaptable, it is essential to enable you to transform into agile internal auditing.
  • Understand the true meaning and intention of the internal audit independence concept. Don't hide behind it!
  • Do not wait for a seat at the table to be offered to you. Invite yourself to the party.
  • Keep your eyes, ears, and more importantly your mouth fully open! Real-time communication of what matters is the key to relevance.
  • Maintain an up-to-date understanding of the company's objectives and business. This is a cornerstone for auditing what matters and adding value. Keep the conversation going with your stakeholders in these uncertain and unprecedented times.
  •  Understand what is the stakeholders' perspective of what adding value by IA means to them.
  • Take a tablespoon of the "courage syrup" three times a day!
  • Put serious efforts into developing your soft and technical skills. Invest in yourself.
  • Utilize available technology to its fullest potential.
The above is not rocket science and has been repeated time and time again by the IIA, the consulting firms, thought leaders, and others. Almost all internal auditors are familiar with it. However, there is still a gap between what internal auditors know and what they can successfully implement. Bridge the gap!

Can the world live without Internal Audit?

 How would the world look like If Internal Audit fails and is marginalized or eliminated?
In researching materials for this topic I came across an undated article questioning  "What if Internal Audit disappeared?". The conclusion was basically that it will not be the end of the world, and that    "key stakeholders would still demand some degree of checks and balances and that the other functions—second-line compliance and risk management, external audit, regulators—would naturally fill much of the void". The interesting thing is that the author's conclusion was based on discussions with his friends in Internal Audit who he described as pragmatic!

What do you think will happen if Internal Audit ceases to exist?

These are my thoughts, please share yours!







/

Tuesday, May 12, 2020

Are you the same person you were before the COVID-19 crisis?

Now that you have stayed at home and working remotely for some weeks, it may be time to ask how this life-changing experience has affected you at the personal and professional levels?
Are you the same person you were before the crisis?
What has changed in your perspective of life, family, and your profession?
When you return to your office, hopefully in the near future, what would you be doing differently? Will you be doing audit planning, risk assessment the same way you used to do? How will your relationships with the stakeholders be reshaped? And more importantly, how your understanding of your role as an internal auditor has changed or evolved?
If you believe this experience has not changed you, can you share why you feel this way and what contributed to your status quo?
Please share your thoughts!




picture credit:https://liveboldandbloom.com

Sunday, April 5, 2020

How will Internal Audit look like after COVID-19?

There have been many articles and posts dealing with the Internal Audit's role during the COVID-19 crisis. These were useful, but now we need to plan for what happens next. The economic, social and financial implications of the crises are expected to be severe at least for the short term.

Eventually, this crisis will pass and most businesses will resume operations and will have to adapt to the new realities to survive. Changes to operations and mindset will need to be made at all levels including at Internal Audit Departments.

As most of you are at home during this difficult time and are probably bored, let's try to think about how the internal audit function at your organization will look like after the crises! For example:


  • Did the crisis change you as a person and how this will reflect on you as an internal auditor?
  • What lessons have you learned during the crises and what are you going to do about it?
  • What type of changes will you make to strengthen internal audit?
  • Do you anticipate an increase or decrease in the number of auditors within your department?
  • Do you anticipate management to change its perspective of internal audit (positive or negative)?
  • What would you do to be prepared for the next crisis?


I look forward to hearing your thoughts and feedback!


Tuesday, March 3, 2020

Can Internal Audit Apply Real-Time Quality Assurance?

I have recently attended a KPMG webinar that discussed "Trends and tips for internal controls over financial reporting". The presenter mentioned that the PCAOP is now focusing its reviews of the work of the accounting firms on the system of quality control such firms employe to ensure their audits meet the requirements. In response to this new approach, the presenter said that the accounting firms are improving their quality control process by shifting from "after the fact" to "real-time" quality control.

 In theory, Internal auditors should be applying the "real-time" approach to quality assurance as the International Standards for the Professional Practice of Internal Auditing require that the CAE must develop and maintain a quality assurance and improvement program that covers all aspects of the internal audit activity ( standard 1300). Moreover, standard (1311) calls for internal assessments to include ongoing monitoring of the performance of the internal audit activity.

The interpretation of standard  1311 explains ongoing monitoring as:

"Ongoing monitoring is an integral part of the day-to-day supervision, review, and measurement of the internal audit activity. Ongoing monitoring is incorporated into the routine policies and practices used to manage the internal audit activity and uses processes, tools, and information considered necessary to evaluate conformance with the Code of Ethics and the Standards". 

Do you believe the ongoing monitoring as mentioned above is equivalent to real-time quality control?
In practice, are you really able to apply ongoing monitoring on a daily basis?

Please share your thoughts and experience!






Picture credit:http://foothilllockandkey.com

Extreme Tail Risk vs. Black Swan Event

  When Canadian Prime Minister Mark Carney recently described the possibility of U.S. military action against Canada as an "extreme tai...