The most important risk is not always the one internal audit spends the most time on.
This is one of the most interesting findings from Risk in Focus 2026/27, the European study conducted among 797 internal audit leaders and professionals. For its 11th edition, the study goes beyond asking which risks are considered the most important. It compares risk level, severity, management maturity, audit effort, coverage adequacy and proportionality.
And this cross-analysis highlights a deeper question:
Do audit plans really reflect the risks the organization is facing today?
🔐 Cybersecurity: almost perfect alignment, but one that still needs explaining
Cybersecurity remains by far the most frequently cited risk. 86% of respondents place it among their top five risks. It also ranks first for severity and for the level of effort devoted to it by internal audit.
At first sight, the signal is reassuring: the risk is identified, audit resources are allocated to it, and coverage is relatively strong. But the report introduces an essential nuance: alignment between risk and audit effort does not, by itself, prove that the audit plan is genuinely risk-based.
Cybersecurity is also a highly regulated area, highly visible to audit committees, and one in which organizations tend to have relatively mature capabilities. Internal audit leaders are therefore encouraged to check whether this alignment really results from risk analysis, or whether it is also influenced by regulatory pressure, audit committee expectations or the level of reliance on second-line functions.
This distinction matters. Spending significant audit effort on a major risk does not necessarily mean that resources are allocated optimally.
🕳️ The real blind spot: risks that are rising but remain difficult to audit
Two risks account for a large part of the tensions identified by the study:
- digital disruption, new technologies and AI;
- macroeconomic, social and geopolitical uncertainty.
They rank second and third respectively among the risks assessed. Yet their management maturity is among the lowest: digital disruption ranks last, while macroeconomic risk ranks second to last.
Organizations consider these risks important while recognizing that their ability to manage them remains relatively immature.
And this is precisely where audit coverage falls behind.
The macroeconomic case is particularly striking
Macroeconomic and geopolitical uncertainty ranks 3rd in terms of risk, but only 15th in terms of audit effort. Management maturity also ranks 15th, while coverage adequacy and proportionality of effort are among the lowest scores.
The report does not provide a single explanation for this gap. It points to several possible factors: the external and volatile nature of the risk, its maturity, internal audit capabilities and the role mandated for internal audit. But above all, it raises a much more operational question: have we actually translated this risk into auditable areas? Strategy, resilience, supply chain, treasury, pricing, sanctions, business continuity.
The problem may therefore not be that internal audit is “overlooking” macroeconomic risk. It may be more subtle: the risk is identified at the risk-mapping level, but it has not been sufficiently translated into concrete areas of control and assurance.
🤖 AI reveals another problem: risk is moving faster than control
Digital disruption and AI present a different profile. The risk ranks 2nd, and so does its severity. But management maturity ranks 16th out of 16. Audit effort sits only around the middle of the ranking, while coverage adequacy and proportionality remain low.
This is probably one of the study’s most significant findings. When maturity is low, internal audit cannot simply apply the same methods used for a well-established area.
The report highlights the need to consider governance, responsibilities, controls, model risk, data quality, third parties, ethics and performance.
In other words, it is not enough to audit AI projects or IT controls. Organizations also need to assess their ability to govern and manage these new uses sustainably.
And organizations appear to be starting to respond: 57% of respondents report an increase in audit coverage of digital disruption and AI, the largest increase reported. But here again, the report urges caution: the evolution of audit coverage does not yet appear to be fully keeping pace with the evolution of the risk.
⚖️ Conversely, some risks remain heavily covered despite lower priority
The study also shows the opposite pattern. Financial risk ranks 8th in the overall risk ranking and 11th for severity. Yet it ranks 1st for management maturity, coverage and proportionality.
Governance, reporting and fraud show a similar profile: these are areas that are historically well established in audit plans, with audit effort exceeding their relative position in the risk ranking.
This does not, of course, mean that these areas are over-audited. The report raises a more useful question: is their current level of coverage still justified by today’s risk signals, or does part of this effort reflect established planning habits?
This is a genuine governance question. Reallocating resources toward an emerging risk may sometimes require reducing the effort devoted to an area that has historically received strong coverage. The report therefore explicitly encourages internal audit leaders to ask themselves what they could stop or reduce in order to rebalance their coverage.
❔ So the real question is not “Is it covered?”
This is probably the most interesting shift in perspective in this edition. For the first time, the study asks internal audit leaders to assess not only their level of coverage, but also its adequacy and proportionality.
This distinction is essential. An organization may have an audit covering a given risk. But that does not necessarily mean that:
- the risk is sufficiently covered;
- the right areas are being audited;
- the resources allocated are proportionate;
- internal audit provides the expected level of assurance.
The gaps are particularly interesting when it comes to proportionality: the lowest scores are found for macroeconomic uncertainty, digital disruption and AI, and market developments.
The question therefore becomes less “Do we audit this risk?” and more:
Is the level and nature of assurance we provide consistent with the risk we are actually exposed to?
⏳ The annual audit plan is no longer enough
The report reaches a particularly clear conclusion: in an environment shaped by volatility, rapid technological change and increasingly interconnected risks, annual planning cycles can fall behind reality.
This is where the issue extends beyond internal audit. If a risk changes during the year, organizations still need to be able to:
- detect the change;
- measure how the risk is evolving;
- understand its consequences;
- identify the controls and risk management arrangements affected;
- assess the existing assurance coverage;
- decide where resources should be reallocated.
The report recommends defining explicit criteria that can trigger a risk escalation, together with a mechanism for rapidly reallocating resources, including during the year.
The question is therefore no longer simply how to build a good audit plan. It is about having a framework that can adapt the plan when risks change.
🔗 An issue that concerns all three lines
This is probably where the study takes on a broader significance. The gap between the risks an organization identifies as priorities and what the audit plan actually covers is not solely an internal audit issue. It is a governance signal. It needs to be visible, shared and discussed across the three lines.
The report itself stresses the need to clarify with stakeholders what “adequate” and “proportionate” coverage actually mean, particularly for complex and cross-functional risks such as AI and macroeconomic uncertainty.
This becomes especially important when several functions contribute to assurance:
- Risk Management identifies and assesses risks;
- business functions and the second line implement and monitor risk management and control arrangements;
- Internal Audit provides independent assurance.
If each function works with its own framework, priorities and view of coverage, the gap between risk and assurance may remain invisible. Conversely, when information is brought together, that gap becomes a subject for discussion.
🧭 From risk mapping to assurance management
Ultimately, Risk in Focus 2026/27 asks a simple question:
Are assurance resources really aligned with the risks that matter today?
Answering this question requires more than looking at the risk map on one side and the audit plan on the other. The two need to be viewed together.
A risk increases: does it appear in the audit plan?
Its maturity remains low: is coverage sufficient?
Controls already exist: what assurance does the second line provide?
Internal audit steps in: on which risks and controls, and with what level of coverage?
The report specifically encourages internal audit functions to identify these gaps, check that allocation decisions are deliberate, and be able to reallocate resources quickly as risks evolve. It also highlights the importance of agreeing with stakeholders on what “adequate” and “proportionate” coverage mean, particularly for complex and cross-functional risks.
💡 This is where a GRC platform makes a difference
The goal is not to create yet another table. It is to connect the information that already exists: risks, assessments, controls, action plans, second-line activities, audit engagements and findings.
Within a shared framework, internal audit can immediately see:
- which risks are priorities;
- which risks have low management maturity;
- which controls contribute to their mitigation;
- what level of coverage is provided by the different lines;
- where gaps remain between risk level and assurance level.
The platform does not make decisions on behalf of the functions involved. It makes the gaps visible so they can analyze them, challenge them and make decisions together.
This is particularly important for risks that evolve quickly. The report highlights how annual cycles can fall behind reality and calls for mechanisms that allow resources to be reallocated during the year.
With a shared GRC framework, a change in the risk map can therefore become a signal to review audit coverage. And conversely, an audit finding can enrich the organization’s understanding of the risk and how it is being managed.
📄 The study referenced in this article: Risk in Focus 2026/27, full report (IFACI, 32 pages, in English), freely available without a form or registration.
❓ Frequently Asked Questions
What is Risk in Focus?
The annual survey conducted by European internal audit institutes, including IFACI, on priority risks and audit planning. The 2026/27 edition is the eleventh. The survey ran from 2 March to 7 April and collected 797 responses across Europe. The full report is freely available without a form.
What exactly does the study measure?
Sixteen risks, each assessed across seven dimensions: the risk ranking, its severity, the maturity with which the organization manages it, the time and effort internal audit devotes to it, the adequacy of its coverage, confidence in the proportionality of that coverage to the risk, and its change between the previous audit plan and the 2026/27 plan. It is the comparison of these seven dimensions that reveals the gaps.
Why can a highly cited risk receive little audit effort?
The report does not identify a single cause. It points to the external and volatile nature of the risk, the maturity of its management within the organization, internal audit capabilities and its mandated role. There is also a more practical difficulty: a diffuse risk is harder to translate into auditable areas. Macroeconomic uncertainty, for example, ranks 3rd in terms of risk but 15th in terms of audit effort.
What does “adequate” coverage mean, and what does “proportionate” coverage mean?
These are two distinct questions, both introduced in this edition and each rated on a scale from 1 to 7.
Adequacy asks whether coverage is at the right level for the risk concerned, from 1 for insufficient coverage to 7 for complete coverage. It is considered strongest for established areas, financial risk and governance and reporting, and weakest for digital disruption, macroeconomic uncertainty and human capital.
Proportionality measures the internal audit leader’s confidence that the effort devoted to a risk is consistent with its magnitude. It goes beyond asking “Is this risk covered?” and asks “Is the balance right?”. The lowest scores are associated with macroeconomic uncertainty, digital disruption and AI, and market developments. They nevertheless all remain above the midpoint of the scale, within a range of 4.04 to 5.37.
Why do digital disruption and AI pose a particular challenge?
Because the risk is considered high while its management is still immature: 2nd for risk and severity, but 16th out of 16 for maturity. An immature area cannot be audited in the same way as a stable one: it requires attention to governance, responsibilities, controls, model risk, data quality, third parties, ethics and performance, not only to the delivery of projects.
Should internal audit reduce its work on financial risk, governance and fraud?
The study does not say so. It observes that these areas receive more audit effort than their position in the risk ranking would suggest, and encourages internal audit leaders to consider whether this level remains justified by current risk signals or whether it partly reflects established planning habits. Reallocating resources toward a rising risk generally means reducing effort elsewhere, which is a governance decision, not simply a planning adjustment.
SIGR, RMIS, IRM, GRC: are we talking about the same thing?
They overlap, but they are not synonymous. SIGR is the French term, for système d’information de gestion des risques, and RMIS its English equivalent; IRM and GRC refer to broader scopes. The annual Panorama published by AMRAE with EY places them within the same market, that of risk management information systems.
What is a shared GRC framework?
A common database where the same objects live: risks and their assessments, controls, action plans, second-line activities, audit engagements and their findings. Each function works in it with its own permissions, scope and approval level, without re-entering what is already documented elsewhere. It is not another dashboard layered on top of existing spreadsheets: the value lies in the fact that the risk, the control and the audit engagement refer to the same object, which makes the gap between risk level and assurance level visible without manual reconciliation.
How can you connect your risk map to your audit plan during the year?
By keeping them in the same framework, so that each audit engagement is linked to an assessed risk and the allocation of effort can be reviewed as soon as the risk rating changes. As long as the risk map lives in one file and the audit plan in another, the gap only becomes visible at the annual review.
📄 Go to the source
- Risk in Focus 2026/27, full report (IFACI, PDF, in English), 32 pages, freely available without a form.
- Risk in Focus 2026/27 Interim Report (ECIIA, PDF, in English), published ahead of the full report. It contains the ten questions internal audit leaders can ask themselves, as well as the detailed proportionality scores.
Learn more
- The Internal Audit module
- The Risk Management module
- Three Lines Model: what the 2026 version changes
- Our answers to over 70 GRC questions
Does your audit plan keep pace with your risks during the year?
Risk map, audit plan, engagements, action plans: a single database, role-based permissions, and the gap shows as soon as it appears.



