Skip to content
Internal Audit & ERM: Turning Risk Oversight Into Confidence
Internal Audit Management

Internal Audit & ERM: Turning Risk Oversight Into Confidence

William C Hord
William C HordChief Strategy Officer - ERM Pilot

ERM Pilot | Risk Management Series by William Hord - Chief Strategy Officer

Enterprise Risk Management has matured considerably. For many organizations, ERM is no longer viewed simply as a risk register, an annual assessment exercise, or a report prepared for the board.

The expectation today is considerably higher.

Management and boards want to understand the organization's most significant risks, how those risks relate to strategy, whether exposures remain within approved risk appetite, and whether the controls and responses designed to manage those risks are actually working.

That creates an important opportunity for Internal Audit.

Internal Audit should not own ERM. Management owns risk. The board provides oversight and challenge. Risk management, compliance, and other second-line functions support management in identifying, assessing, monitoring, and responding to risk.

Internal Audit has a different responsibility.

It provides an independent perspective on whether governance, risk management, and control processes are designed and operating effectively.

When those roles work together appropriately, ERM can become more than a framework for documenting risk.

It can become a source of credible confidence for management and the board.

ERM provides the risk view. Internal Audit helps determine whether that view can be trusted.

The question isn't whether ERM exists

A common mistake is equating an established ERM process with an effective ERM program.

An organization may have:

  • A comprehensive enterprise risk register
  • Documented risk appetite and tolerance
  • Risk owners assigned to significant risks
  • Key risk indicators
  • Formal risk assessments
  • Risk committees
  • Board-level risk reporting
  • Policies and procedures

And still have weaknesses in how risk is actually managed.

The more important question is:

Does the ERM process provide management and the board with a reliable understanding of the organization's risk exposure?

That requires looking beyond whether processes exist and examining whether they work.

Are risk assessments supported by evidence?

Are risk owners making meaningful assessments or simply completing a required exercise?

Are controls actually reducing residual risk?

Is risk appetite influencing decisions - or merely appearing in policy documents?

Are significant issues escalated promptly?

Does the enterprise risk profile change when the business, strategy, technology, regulatory environment, or external environment changes?

And perhaps most importantly, does the information reaching the board accurately represent the organization's current risk position?

These are areas where Internal Audit can provide considerable value.

Internal Audit as independent assurance - not another risk owner

The Institute of Internal Auditors' Global Internal Audit Standards establish Internal Audit as an independent and objective assurance and advisory function intended to strengthen governance, risk management, and control processes.

That independence is fundamental.

Internal Audit should not be responsible for making management's risk decisions. It should not own risk responses or operate the organization's risk management processes.

Its value comes from being able to ask questions that management may not always be positioned to ask independently.

How do we know this risk rating is accurate?

What evidence supports the assessment?

Are the controls actually operating as management believes?

Is the residual risk consistent with our approved appetite?

What has changed since the last assessment?

Are recurring findings indicating a systemic problem?

Are management's remediation efforts reducing the underlying exposure - or simply closing individual findings?

Those questions are not an indication that ERM has failed.

They are evidence of a healthy governance environment.

Connecting the enterprise risk profile to Internal Audit

One of the most effective ways to connect ERM and Internal Audit is through risk-based audit planning.

The enterprise risk assessment should inform Internal Audit's understanding of where assurance is most needed. At the same time, Internal Audit's independent observations can challenge or refine management's understanding of the risk environment.

Consider third-party risk.

Management may identify dependence on critical vendors as a significant enterprise risk. A conventional audit approach might test selected vendor-management controls.

A more integrated approach asks broader questions:

  • Is the vendor inventory complete?
  • Are critical third parties appropriately identified?
  • Is vendor criticality consistently determined?
  • Are assessments proportionate to the risk?
  • Are contractual requirements addressing the organization's key exposures?
  • Is ongoing monitoring occurring?
  • Are exceptions escalated?
  • Are unresolved vendor issues reflected in the enterprise risk profile?
  • Does management have sufficient information to understand concentrations of third-party exposure?

The difference is subtle but important.

The audit is no longer simply testing whether individual procedures were followed.

It is evaluating whether the risk-management system surrounding the risk is functioning effectively.

That is where Internal Audit can become a powerful extension of enterprise risk insight without becoming an owner of risk.

Internal Audit sees something ERM sometimes cannot

There is another reason the relationship matters.

Internal Audit has a unique enterprise-wide vantage point.

It sees different functions, processes, business units, systems, controls, and issues over time. That perspective can reveal patterns that are difficult to see when risks are managed within individual organizational silos.

A finding in Information Technology may appear unrelated to a finding in Vendor Management.

A business continuity weakness may appear unrelated to an issue in operational processes.

A recurring compliance issue may appear unrelated to an audit finding in another business unit.

But taken together, those observations may reveal a broader weakness in governance, accountability, change management, or risk ownership.

This is where Internal Audit can move beyond reporting individual findings and begin identifying enterprise themes.

That distinction matters to the board.

A board generally does not need to know only that three departments have three separate moderate findings.

It needs to understand what those findings collectively mean.

Is there a systemic weakness?

Is the organization experiencing increasing concentrations of exposure?

Are the same root causes appearing repeatedly?

Is management addressing symptoms rather than underlying causes?

Are remediation efforts actually changing the organization's risk profile?

Those are ERM questions.

Internal Audit's independent observations can help answer them.

Challenge is part of assurance

Risk assessments are inherently dependent on management judgment.

That doesn't make them unreliable. It means they should be subject to appropriate challenge.

A risk owner may assess a risk as moderate because significant controls are in place.

But are those controls operating effectively?

A business unit may reduce a risk rating because no significant event has occurred recently.

But has the underlying exposure actually changed?

A risk may remain within appetite today.

But what happens if a key assumption changes?

Effective Internal Audit can help introduce disciplined challenge into these decisions.

The objective isn't to produce a different risk rating simply for the sake of disagreement.

The objective is to make the organization's risk assessment more defensible.

That is particularly valuable at the board level.

A board should not need to independently recreate management's risk assessment. It should be able to understand the basis for management's conclusions and have confidence that appropriate challenge and independent assurance exist around the process.

Independence does not mean isolation

This is where the Three Lines concept becomes particularly relevant.

Management remains accountable for managing risk.

Second-line functions provide expertise, support, monitoring, and challenge related to risk management.

Internal Audit provides independent assurance and advice.

The distinction between these roles should be protected - but that does not mean they should operate independently of one another.

Quite the opposite.

Effective organizations coordinate their assurance activities, share appropriate information, understand one another's responsibilities, and maintain a common view of significant risks.

Independence does not require isolation.

Internal Audit can work closely with ERM and other assurance functions while retaining the independence necessary to challenge management objectively.

That balance is essential.

If Internal Audit becomes part of operating the ERM process, it risks compromising its ability to independently evaluate that process later.

If Internal Audit operates completely disconnected from ERM, however, the organization can lose opportunities for meaningful coordination and enterprise-level insight.

The objective is neither extreme.

The objective is coordination without ownership.

What confidence should look like

Ultimately, the purpose of connecting Internal Audit and ERM is not to generate more reports.

It is to improve the quality of decisions.

A strong relationship between ERM and Internal Audit should help management and the board answer several fundamental questions:

Do we understand our most significant risks?

Are our risk assessments supported by credible information?

Are we operating within approved risk appetite?

Are our controls addressing the risks that matter most?

Are significant issues being escalated appropriately?

Are remediation efforts actually reducing risk?

Are recurring findings signaling a broader problem?

Are emerging risks being identified quickly enough?

Can we rely on the information being presented to us?

That last question may be the most important.

The board doesn't need to be told that the organization has eliminated risk.

It hasn't.

No organization can.

What the board needs is reasonable confidence that management understands the risks it is taking, that those risks are being managed deliberately, and that significant weaknesses will be identified, challenged, and escalated.

That is what effective assurance looks like.

Moving from documentation to decision support

For risk professionals, the opportunity is to stop thinking about ERM and Internal Audit as adjacent activities and start viewing them as complementary components of the organization's governance system.

ERM provides structure around how the organization identifies, assesses, responds to, monitors, and reports risk.

Internal Audit independently evaluates whether that system is functioning effectively.

Management makes the decisions.

The board provides oversight and challenge.

When those responsibilities are clearly understood - and appropriately connected - the organization can move beyond compliance-oriented risk management toward something more valuable.

Better information. Better challenge. Better decisions.

And ultimately, greater confidence.

The strongest ERM programs are therefore not necessarily the ones with the most risks documented, the most controls catalogued, or the most reports produced.

They are the ones where risk information actually influences decisions.

Where accountability is clear.

Where controls are tested against meaningful risks.

Where issues are remediated rather than merely closed.

Where emerging risks are recognized.

Where management's assumptions are challenged constructively.

And where the board can reasonably believe that the risk picture it sees reflects the reality of the organization.

That is the opportunity for Internal Audit.

Not to own ERM - but to help prove that it works.


Sources & References:

  1. The Institute of Internal Auditors (IIA). - Global Internal Audit Standards. The authoritative professional standards for the internal audit profession, addressing Internal Audit's purpose, independence, governance, assurance, risk management, and communication with the board. IIA - Global Internal Audit Standards
  2. The Institute of Internal Auditors (IIA). - The IIA's Three Lines Model. Provides the framework for distinguishing the responsibilities of governing bodies, management, second-line functions, and Internal Audit while emphasizing coordination and preservation of Internal Audit's independence. IIA - Three Lines Model
  3. Committee of Sponsoring Organizations of the Treadway Commission (COSO). - Enterprise Risk Management: Integrating with Strategy and Performance. COSO's ERM framework establishes the connection between risk, strategy, performance, governance, and decision-making. COSO - Enterprise Risk Management
  4. Board of Governors of the Federal Reserve System. - Internal Audit Function and Its Outsourcing; Supplemental Policy Statement. Federal Reserve guidance addressing Internal Audit independence, board and senior-management responsibilities, risk management, internal controls, audit committee oversight, and communication of significant concerns. Federal Reserve - Internal Audit Function and Its Outsourcing
  5. Board of Governors of the Federal Reserve System. - Supervisory Guidance on Board of Directors' Effectiveness. Guidance addressing board oversight, risk management, risk appetite, internal controls, Internal Audit, and management accountability. Federal Reserve - Supervisory Guidance on Board of Directors' Effectiveness
  6. U.S. Government Accountability Office (GAO). - Standards for Internal Control in the Federal Government, 2025 Revision (Green Book). The GAO's authoritative framework for internal control, including risk assessment, control activities, information and communication, monitoring, and organizational response to change. GAO - Standards for Internal Control in the Federal Government

Ready to transform your risk management?

Discover how ERM Pilot can streamline your compliance, automate workflows, and provide real-time insights for your organization.

Stay Updated on ERM Pilot

Join our newsletter to receive the latest news, feature updates, and expert insights on all things risk related.

We respect your privacy. Unsubscribe at any time.