Boards are now more engaged in risk oversight, but many risks still never reach the audit committee.
Boards are now more engaged in risk oversight, but many risks still never reach the audit committee.
The speed of risk accelerates challenges, requiring a change in how risk is managed and governed.
The goal is not to eliminate risk, but to eliminate surprises before they become events.
Boards are more engaged in risk oversight than ever before. Yet many of the most consequential risks still never reach the board’s audit committee in a meaningful way. Not because they are invisible—but because no one truly owns them. By changing the alignment of how risk is managed and governed, organizations can anticipate and address risk challenges before they affect operations.
Global risk awareness is strong. According to the Institute of Internal Auditors’ Risk in Focus Global Survey—drawing on insights from more than 4,200 chief audit executives worldwide—cybersecurity, human capital and business continuity consistently rank as the top current risks across industries and geographies.
What remains inconsistent is not recognition of risk, but how risk is governed—how it is owned, escalated and translated into board-level judgment.
The result is a paradox many directors recognize well: growing volumes of risk reporting, paired with limited clarity about where true exposure sits and who is accountable for it.
Many of today’s most consequential risks live between functions—between finance and IT, operations and compliance, or large-scale transformation initiatives and day-to-day execution.
Internal audit alignment typically highlights this challenge. Chief audit executives often have limited involvement in continuous monitoring of key processes—where cross-functional operational risks most often emerge—while many also lack insight into enterprise risk management activities. This limits the organization’s ability to aggregate and elevate risks that cut across silos.
These gaps are rarely the result of disengagement. More often, they reflect governance models built around functional ownership, while risk increasingly materializes horizontally—across systems, processes, geographies and third-party relationships.
Consider a large enterprise resource planning (ERP) system transformation: IT owns the implementation, finance owns reporting accuracy and operations owns the execution.
Yet no single executive owns the risk of controls potentially degrading across the transition. Each function assumes another is monitoring the exposure—until breakdowns surface in reporting, compliance or operations.
We consistently see this dynamic play out in large transformation programs—ERP implementations, outsourcing initiatives and artificial intelligence deployments—where ownership of risk is fragmented across IT, finance and operations. In these environments, risks are actively managed within functions—but rarely aggregated into a shared view of enterprise exposure or brought forward for integrated decision making.
A persistent governance blind spot is the assumption that if a risk does not clearly sit with one function, it must be covered elsewhere. For example:
Research from the Internal Audit Foundation continues to show that risks are becoming more interconnected and systemic, while accountability structures remain fragmented. When responsibility is diffused, escalation depends on individual judgment rather than governance design—and risks surface only after disruption forces attention, often after damage has already occurred.
This is less a failure of awareness than a failure of ownership and escalation.
In working with clients, we often find that simply clarifying executive ownership for cross-functional risks—through governance forums, escalation protocols and internal audit alignment—can materially improve decision speed and reduce late-stage surprises.
Audit committees are deeply engaged in risk oversight. Survey data from the Center for Audit Quality indicates that 93% of audit committee members rank cybersecurity as a top three priority, with enterprise risk management close behind.
At the same time, nearly 80% in that survey believe internal audit could add more value, particularly through forward-looking insight and better integration across risks that span the organization.
Research from the National Association of Corporate Directors (NACD) reinforces this tension. Boards are spending more time on risk than ever before, yet often struggle to translate fragmented discussions into clear ownership, effective escalation and timely decision making.
The issue is not attention. It is that risk agendas are expanding faster than governance mechanisms are evolving.
Risk speed only amplifies the challenge. NACD guidance highlights that boards now oversee a broader, more interconnected risk landscape—spanning cybersecurity, technology, third-party exposure and organizational change. As oversight responsibilities expand, many boards lack sufficient visibility into how risks are aggregated, prioritized and escalated across the enterprise.
Internal audit research reinforces this concern. The IIA’s Risk in Focus findings show that cybersecurity and digital disruption remain among the highest-ranked risks worldwide, yet internal audit leaders consistently report difficulty translating awareness into coordinated governance action, especially for cross-functional risks without a natural owner.
RSM’s 2026 Attack Vectors Report underscores that today’s cyber incidents are rarely detection failures. Instead, they stem from fragmented ownership, unclear escalation paths and limited board‑level visibility into how identity, AI and third‑party risks compound across the enterprise.
At the same time, regulatory expectations continue to rise. U.S. Securities and Exchange Commission cybersecurity disclosure requirements now require companies to describe board oversight, governance structures and management accountability—making visible to regulators and investors what may remain ambiguous internally.
In this environment, risks can become externally visible before internal governance is fully aligned to manage them.
In our experience, this is where governance breakdowns become most visible—not in isolated control failures, but in how risks compound across functions without a clear path to ownership or escalation.
Internal audit occupies a unique position within the organization. It is one of the only functions designed to see how risk behaves across the enterprise. Yet in many organizations, it is still used to confirm compliance rather than inform governance decisions.
The IIA’s Global Internal Audit Standards explicitly define internal audit’s purpose as strengthening the organization’s ability to create, protect and sustain value through independent assurance, advice, insight and foresight to the board and management. Internal audit is most effective when empowered to look beyond isolated controls and assess how risks interact and accumulate.
Yet in many organizations, internal audit remains severely underutilized.
Closing the board’s risk blind spot requires internal audit to evolve from a function that validates controls to one that connects risk signals across the enterprise.
This does not mean internal audit should own risk, replace management judgment or become a second-line function. Independence and objectivity remain essential.
It does mean internal audit should be explicitly chartered and expected to:
NACD governance guidance is clear: boards need aggregated, connected insight to meet their oversight responsibilities in a complex risk environment. Internal audit is one of the few functions structurally positioned to provide that perspective.
In our experience, leading organizations are not solving this challenge by adding more reporting—they are changing how risk moves through the organization.
We typically see three areas of focus:
Explicitly assigning executive ownership for cross-functional risks, particularly in transformation initiatives
Establishing structured escalation paths for risks that do not fit neatly within functional boundaries
Leveraging internal audit as a connector to aggregate risk themes and surface enterprise-level exposure to the board
To elevate internal audit, organizations must adjust expectations, mandates and behaviors, not just dashboards.
Audit committees should explicitly define internal audit’s role to include enterprise risk connectivity, not just assurance execution.
Action steps
High-performing organizations use internal audit as an early warning system, not a checkpoint after decisions are made.
Action steps
Internal audit leadership plays a critical role in shaping how the function is perceived.
Action steps
When internal audit is properly positioned, boards should reasonably expect answers to questions such as:
These are governance-level insights, not audit minutiae—and they align squarely with the NACD’s view of effective board oversight in complex environments.
The greatest risk to boards today is not lack of information—it is misplaced confidence in how well risk is governed. When accountability is unclear, risk doesn’t escalate—it compounds. Organizations that get this right don’t eliminate risk, they eliminate surprises—before they become events.