Staying attuned to the company鈥檚 changing risk profile has put a premium on internal audit being in sync with the audit committee.
Understanding a company鈥檚 strategic and operational risks in an increasingly complex聽 business environment is both a top priority and a top challenge鈥攁nd internal audit has a vital role to play. Staying attuned to the company鈥檚 changing risk profile鈥攊ncluding its control environment, culture, and crisis readiness鈥攈as put a premium on internal audit being in sync with the audit committee.
This year alone, major shifts in the regulatory and business landscape are demanding more agility from internal audit. New cybersecurity disclosure rules for public companies have arrived, and final climate disclosure rules and proposed human capital management disclosure rules could follow shortly. The use and experimentation with artificial intelligence is becoming pervasive as well.
The chief audit executive (CAE) can help audit committees monitor these trends, understand what鈥檚 happening at every level of the company (as the committee鈥檚 eyes and ears), and connect the dots.
As panel members suggested during the 乐鱼(Leyu)体育官网 Audit Committee Leadership Forum in June, keys to the CAE鈥檚 value-add to the audit committee include the following:
鈥淚nternal control is a team sport,鈥� said one audit committee chair at a recent 乐鱼(Leyu)体育官网-sponsored event. 鈥淎s an audit committee, you have to have a CAE whom you can rely on, who is agile, and who can adjust to changes in both reporting expectations and the risk environment.鈥�
Given the increasingly complex risk environment and the intense focus of regulators, investors, and other stakeholders, the audit committee should closely monitor internal audit鈥檚 risk assessment process and its development of the audit plan. The committee should ask, for example, the following questions:
Currently, CAEs view cyber, information technology, and sustainability risks at opposite ends of the risk spectrum in terms of the time and attention that internal audit devotes to them. According to the 2023 North American Pulse of Internal Audit, from the Institute of Internal Auditors, 78 percent of internal audit professionals viewed cybersecurity as a high or very high risk, with 57 percent responding the same for broader technology issues. By comparison, only 9 percent said the risk level for the range of sustainability risks was high or very high.
While climate and sustainability may be a long-tail or distant risk for some companies (and nearer for others), new regulatory mandates for climate disclosures both in the United States and globally鈥攁s well cybersecurity, human capital management, and other sustainability disclosures鈥攚ill require an increased focus by internal audit.
鈥淭he chief audit executive needs to be comfortable with a risk environment that is rapidly changing,鈥� said another audit committee chair. 鈥淲hen significant shifts are needed in the audit plan鈥攆or example, with new disclosure requirements鈥攆lexibility is key .鈥�
This article originally appeared in the Fall 2023 issue of聽NACD Directorship听尘补驳补锄颈苍别.
Sign up to receive Board Leadership Weekly and Directors Quarterly