Internal audit in 2027: where assurance can have the greatest impact

For internal auditors planning for 2027, the question is no longer simply what new risks are emerging, but where assurance can have the greatest impact, write Colm Laird and Ann Marie Conroy

8th October 2026

As organisations begin to look ahead to 2027, the focus for most will not be on identifying new risks. Most already have a good understanding of the issues that could affect their objectives in the new year.

The harder task is deciding where assurance will be needed most and ensuring that audit coverage keeps pace with a changing risk landscape. So, where should Internal Audit focus?

Not every emerging risk belongs on the audit plan. The challenge is to identify where rapid change, uncertainty and growing dependency have created a gap between what an organisation believes is controlled and what is happening in practice.

A changing risk landscape

Artificial intelligence (AI) is changing how work is done and how decisions are made. Cyber threats continue to develop. Geopolitical tension is affecting trade, regulation and supply chains.

At the same time, many organisations are cutting costs, changing operating models and relying more heavily on a small number of technology and service providers. These risks are converging rather than developing in isolation. A cyber incident may start with a third party, interrupt a critical service, expose poor data governance and create regulatory consequences. A cost programme may deliver its savings while quietly removing experienced staff or weakening important controls. An AI tool may improve productivity but introduce new data, fraud and accountability risks.

Your audit plan for 2027 should therefore be selective rather than simply “longer”. It should focus on where risks converge, where dependencies could transmit disruption across the organisation and where management and the board have the least reliable assurance.

Internal Audit can add value by helping boards understand not only whether controls are operating effectively, but whether or not management is responding to change quickly enough.

In many organisations, the challenge is not a lack of information, but whether management information is timely, reliable and capable of supporting effective decision-making. Strong governance depends as much on the quality of information available to decision-makers as it does on the controls themselves.

These themes are particularly relevant to Irish organisations operating within a highly open economy, an increasingly complex EU regulatory environment and interconnected international supply chains.

The ability to anticipate disruption, adapt quickly and maintain trust has become important across both the public and private sectors.

AI, automation and accountability

By 2027, many organisations will have moved beyond small AI trials. AI will increasingly be embedded within day-today operations, existing software platforms and third-party services, influencing how decisions are made, how information is analysed and how customers are served.

The challenge is that organisations may be using AI without fully understanding where it operates, which data it uses or who is accountable for the resulting decisions and outcomes.

Governance must extend beyond the approval of standalone AI tools. Management needs visibility over AI developed internally, accessed by employees or embedded within supplier platforms and business applications. The risks increase as AI moves from assisting employees to making recommendations, initiating or making decisions – particularly where those decisions affect customers, financial reporting or regulatory obligations.

For Internal Audit, the focus should be less on the existence of AI policies and more on whether governance reflects how AI is being used in practice. Reviews should assess whether:

• management has sufficient visibility over AI use;

• controls are proportionate to the risks involved; and

• appropriate oversight exists where AI influences decisions or business outcomes.

Reviews should also determine whether human oversight is meaningful in practice.

A process described as “human in the loop” may provide limited protection if employees lack the information, time, expertise or authority required to challenge an AI-generated output.

Internal Audit should apply the same discipline to its own use of AI. Technology can support planning, analysis and reporting, but responsibility for evidence, judgement and conclusions remains with the auditor.

Cyber resilience: beyond prevention

Cybersecurity remains a core audit priority, but the discussion is increasingly moving beyond prevention.

Organisations must be able to detect, contain and recover from incidents in an environment in which AI-enabled impersonation, deepfakes, ransomware and supplier compromise continue to evolve.

Attention should also extend to operational technology and connected infrastructure, concentration in cloud and technology providers and the longer-term implications of quantum computing for the cryptography underpinning data security and digital trust.

The most significant cyber failures often occur not because controls are absent, but because organisations struggle to respond effectively when incidents occur. Boards need confidence that recovery arrangements, communications and decision-making processes will operate effectively under pressure.

“THE RISKS INCREASE AS AI MOVES FROM ASSISTING EMPLOYEES TO MAKING RECOMMENDATIONS, INITIATING OR MAKING DECISIONS – PARTICULARLY WHERE THOSE DECISIONS AFFECT CUSTOMERS, FINANCIAL REPORTING OR REGULATORY OBLIGATIONS”

Internal Audit can provide real value by assessing whether organisations are genuinely prepared to respond to and recover from a cyber incident, rather than simply demonstrating that controls exist.

Reviews should focus on whether critical controls operate in practice and whether incident-response and recovery arrangements would remain effective if normal communications, trusted identities or a critical technology provider were unavailable or compromised.

Geopolitical and economic exposure

Tariffs, sanctions, export controls, conflict and competition for critical resources are changing costs, markets and supply chains. Organisations do not need to operate directly in affected regions to experience disruption.

Exposure may sit with customers, suppliers, technology providers or assumptions built into strategic plans.

Financial pressure can also create risk indirectly. Cost reduction targets, refinancing pressures and weaker trading conditions may encourage optimistic forecasting, management override or underinvestment in important control and resilience activities.

These issues may not justify a standalone audit in every organisation, but they should influence risk assessments and audit planning decisions.

Internal Audit should consider these pressures when scoping reviews of strategy, financial planning, procurement, supply chains, third-party management and operational resilience.

The objective is not to predict geopolitical events, but to assess whether material assumptions and dependencies are understood, monitored and linked to practical management actions.

Scenario planning should identify decision points, accountable owners and the indicators that would trigger a change in approach.

Operational resilience and critical dependencies

Business continuity documentation does not, by itself, demonstrate resilience. Organisations need a clear understanding of how critical services are delivered across people, premises, technology, data, utilities and suppliers.

Weaknesses often emerge in the connections between these components rather than within individual controls. The more important question is whether management genuinely understands what critical services depend on, and how these services would operate during a significant disruption.

“FOR INTERNAL AUDIT, ASSURANCE SHOULD FOCUS ON THE INFORMATION THAT SUPPORTS MATERIAL DECISIONS, REGULATORY OBLIGATIONS, PUBLIC REPORTING AND HIGHER-RISK AI USE, RATHER THAN ATTEMPTING EQUAL COVERAGE OF THE ENTIRE DATA ESTATE”

Management should also understand the minimum combination of services, people, technology, data and suppliers the organisation would need to preserve if normal recovery arrangements were overwhelmed, including what could be stopped, degraded or deferred.

Resilience testing should involve realistic scenarios and difficult decisions rather than simply validating that plans exist. Actions arising from incidents and exercises should address root causes and be independently verified before closure.

Internal Audit can add value by assessing whether management has visibility of critical dependencies and whether recovery assumptions remain realistic if several services fail simultaneously.

The focus should be on the organisation’s ability to continue delivering critical services rather than simply maintaining resilience documentation.

Third-party dependencies and concentration risk

Organisations are becoming increasingly dependent on third parties, cloud providers and specialist service providers.

The most important dependency is not always the largest contract. Smaller suppliers may support critical controls, hold sensitive information or provide services for which there are limited alternatives.

Concentration risk can also be hidden. Different suppliers may rely on the same cloud platform, technology provider or sub-contractor, creating dependencies that are not immediately visible.

As organisations increase outsourcing and digitalisation, these risks become more significant.

For Internal Audit, the real test is not simply whether a third-party risk management framework exists, but whether it changes sourcing, contracting, monitoring and resilience decisions.

Reviews should focus on critical dependencies, common fourth parties, concentration risk, continuous monitoring and the credibility of contingency, substitution and exit arrangements.

The central question is whether management can move from supplier to service, to dependency, to business impact – and, ultimately, to timely action.

Information integrity and digital trust

Organisations increasingly need confidence not only that information is accurate, but also that it is authentic, complete and produced through a trusted process.

AI, automation, regulatory reporting and management decision-making all depend on reliable information.

Yet ownership, definitions and lineage often remain unclear until information is needed for an important decision or external submission. At this point, inconsistencies and control weaknesses can become difficult to address quickly.

The reliability of information is increasingly becoming a risk. Synthetic documents, voice cloning and deepfake technology can be used to impersonate executives, alter evidence and support fraudulent transactions.

Regulatory expectations regarding data, AI and public disclosures continue to rise, requiring organisations to support key decisions with reliable information and evidence.

For Internal Audit, assurance should focus on the information that supports material decisions, regulatory obligations, public reporting and higher-risk AI use, rather than attempting equal coverage of the entire data estate.

Reviews should assess ownership, quality, lineage, access, retention and change controls, while also considering whether the authenticity of critical documents, communications and transactions can be established.

People, culture and skill dependencies

AI and changing workforce expectations are rapidly reshaping organisational roles.

Many organisations continue to face shortages in technology, cyber, data and regulatory skills while simultaneously managing restructuring, succession risk and workforce change.

There is also a risk that organisations automate entry-level work without considering how future professionals develop judgement, scepticism and practical experience.

Without deliberate changes to career pathways and development, this may create capability gaps that only become visible after experienced employees have left the organisation.

Internal Audit should look beyond engagement surveys and policy statements. Culture is reflected in decisions, incentives, escalation and accountability. Reviews should consider whether:

• performance measures encourage the right behaviours;

• concerns are raised and acted upon;

• succession plans exist for critical roles; and

• key knowledge is concentrated in a small number of individuals.

Internal Audit is not immune to these pressures and should also assess whether it has the skills and capacity required to provide assurance over emerging and increasingly complex risks.

What should change in your 2027 audit plan?

Most organisations will already have extensive risk registers and a lengthy audit universe. The challenge now is deciding where assurance is likely to make the greatest difference.

Audit plans should remain grounded in organisational objectives, risk profile and available assurance.

However, the most effective plans will not simply allocate audits to individual risks: they will focus on areas in which uncertainty is increasing, dependencies are growing and failures could have wider consequences across the organisation. Internal Audit should distinguish between:

• issues requiring immediate assurance;

• risks requiring active monitoring; and

• areas where early engagement may prevent weak controls from becoming embedded.

The strongest Internal Audit functions in 2027 will not be those with the largest audit plans; it will be those that understand where risk is changing, where risks are converging and where assurance can have the greatest impact.

As organisations navigate a more uncertain and interconnected environment, the Internal Audit function has an opportunity to provide assurance over controls and help boards and management understand whether or not the organisation is genuinely prepared for the risks ahead.

Your audit plan for 2027 should also retain sufficient flexibility to respond when new information changes your organisation’s risk profile or exposes an assurance gap.

Colm Laird is a Partner in RSM Ireland’s Risk and Governance practice Ann Marie Conroy is a Senior Manager in RSM Ireland’s Risk and Governance practice