Download as pdf or txt
Download as pdf or txt
You are on page 1of 10

2023 RISK IN

FOCUS
Board
Briefing
BOARD BRIEFING:
Risk in Focus 2023
Boards should harness internal audit to navigate the ‘perfect storm’ of high-impact interlocking risks

In 2022, a ‘perfect storm’ of high-impact, interlocking For example, fast-moving human capital and climate-
risks threw many businesses into a permanent state of related risks require a strategic response. While changes
crisis. Following an ongoing pandemic, the war in Ukraine to laws and regulations are important from a compliance
intensified supply chain failures, fuelled inflation and perspective, chief audit executives can help boards Venn Diagram Illustrating the Perfect Storm
energy price increases. undertake deep-rooted cultural, governance, and risk of High-Impact Interlocking Risks
management transformations to meet these challenges.
Boards must rapidly adapt to the new reality of heightened
geopolitical instability, climate-related natural disasters, In addition, taking a strategic approach to cybersecurity
Geopolitical tensions
looming recession, an accelerating cost of living and data governance can help organisations combat
catastrophe in Europe, food shortages, employee industrialised hacking attacks, ensure that reporting on
Financial
welfare and skills deficits, and a rapidly industrialising issues such as sanctions compliance and climate change liquidity Supply chain
transparency
cyberattack landscape. is accurate, and pave the way for effective digitalisation at – inflation,
cost of living,
a time when automation is a key tool for realising strategic strikes etc
The key to success will be for senior management teams goals, including in human capital to tackle skills shortages.
and boards to stop seeing sudden, systemic organisation-
wide risks with contagious, unpredictable ramifications Finally, chief audit executives are ideally placed to help
throughout the enterprise as Black Swan events: they are organisations tackle employee burnout and changing
interlocking elements of a continuous storm that will blow attitudes to employment. Working with the board to use Raw material Cyber attacks
through Europe in 2023 and beyond. the Environmental, Social and Governance agenda to shortages

discover and communicate purpose as well as protect staff


Chief audit executives have identified five key areas of focus wellbeing can help win the all-important war on talent. Transport/distribution
to help boards navigate these headwinds: geopolitical bottlenecks

uncertainty, climate change, organisational culture, cyber


and data risk, and digitalisation and artificial intelligence.

PAGE 2 OF 10
Key findings:
2022 vs 2023

2023
What are the top five risks your organisation currently faces?
2023 2022
Human capital risk moves into second place this year followed by macroeconomic and geopolitical uncertainty.
2022

Cybersecurity and data security


Human capital, diversity and talent management
Macroeconomic and geopolitical uncertainty
Changes in laws and regulations
Digital disruption, new technology and AI
Climate change and environmental sustainability
Business continuity, crisis management and disasters response
Supply chain, outsourcing and 'nth' party risk
Financial, liquidity and insolvency risks
Organisational governance and corporate reporting
Organisational culture
Fraud, bribery and the criminal exploitation of disruption
Communications, reputation and stakeholder relationships
Health, safety and security
Mergers and acquisitions

0 10 20 30 40 50 60 70 80 90 100

PAGE 3 OF 10
CALL TO ACTION FOR BOARDS

1. Focus on systemic risks that create vulnerabilities in many


parts of the organisation simultaneously and ensure risk
assessment and risk management efforts provide the
board with clear oversight of such risks

2. Ensure that governance, risk management and control


efforts are coupled to strategic risks

3. Check that the board’s risk appetite is up to date in order


to provide clarity in rapid strategic decision making

4. Work with the chief audit executive to ensure the internal


audit function spends as much time as necessary on
emerging strategic and systemic risk areas

5. Provide the chief audit executive with the profile,


authority and resources to properly support the
organisation in achieving its strategic goals

PAGE 4 OF 10
HOT TOPICS
MACROECONOMIC AND GEOPOLITICAL RISK,
EMERGING AND STRATEGIC RISK
Auditing in a time of crisis
Chief audit executives ranked in some sectors supporting their businesses crisis management teams are not equipped
macroeconomic and geopolitical risk as in maintaining up-to-date risk assessments to deal with non-stop emergencies – the
the third most pressing threat in the Risk and strengthening controls for screening effects of which can jump rapidly and
in Focus 2023 quantitative survey, up from suppliers and shareholders. Data governance unpredictably through the enterprise. An
seventh place last year. On the other hand, is key to increasing transparency in these up-to-date risk appetite can provide greater
they ranked it just 15th in terms of where they areas to avoid compliance-related fines and clarity to rapid strategic decision-making in
spend their time, which they expect to rise legal action. times of crisis.
only to 13th place over the next three years.
Given the pressure such high-impact, Following the conflict in Ukraine and
fast-moving events place on financial increasing tensions with China, supply
and liquidity risk, for example, the lack of chain risks pose existential threats to both

3rd
attention to this key area seems either organisations and life. The nature of extended
short-sighted or untenable. Board members enterprises means that such risks cut across
could use these results to discuss whether all areas of the business and demand a
internal audit’s time is currently being strategic (rather than operational and
focused on the risk areas of highest strategic tactical) response from boards and internal
importance, or whether they need more audit teams. Supply chain visibility is vital,
including the ability of businesses to digitally
Chief audit executives
resources to give these emerging strategic
model their supply chain structures to stress ranked macroeconomic and
risk areas sufficient attention.
test and improve them. geopolitical risk as the third
In the first quarter of 2022, as a result of the most pressing threat, up from
War in Ukraine, sanctions risk arose as a Large-scale, interconnected risk events are
seventh place last year.
major area of focus with internal auditors becoming systemic. Traditional operational

PAGE 5 OF 10
HOT TOPICS
CLIMATE CHANGE AND
ENVIRONMENTAL SUSTAINABILITY
Transition to climate change auditing
Climate change has become one of the most Internal audit also has a key role to play in Governance (ESG) lens to the issue provides
dynamic, fast-moving areas for businesses, providing assurance to the board that the businesses with the transparency they need
according to the Risk in Focus 2023 organisations’ climate-related objectives are to both avoid reputation risk from charges of
quantitative survey of chief audit executives. linked to its core strategy, have adequate green-washing and to assure stakeholders
It moved from eighth to sixth place in the risk management to ensure that strategy is that the organisation is on the right path to
risk rankings – and respondents expect it achieved, and have robust data and reporting achieve net zero objectives.
to move to third place in three years’ time. structures, relevant KPIs and that they
The qualitative interviews and round table comply with international standards. Boards
sessions revealed that many chief audit must ensure that internal audit helps in the
executives are working to integrate climate development of such frameworks from the
change aspects into every audit assignment. outset to make certain that risks are managed
in line with risk appetite. The business should
The Conference of the Parties (COP26) have a firm grip on how and why it does
set new targets for net global emissions. business with key third party suppliers and
European Sustainability Reporting Standards seek assurance that they are not a weak link
(a key component of the Corporate in its climate change strategy.
Sustainability Reporting Directive) and Climate change moved from
the International Sustainability Standards Given increasing pressure from shareholders eighth to sixth place in the
Board’s own rules should be finalised by the and stakeholders on climate-related risk rankings – and respondents
end of 2022. Internal audit functions need reporting, a key risk is that legal, voluntary expect it to move to third place
to help companies rapidly get to grips with and marketing statements are wrong. in three years’ time.
developing key performance indicators Organisations must not view climate change
around these rules and robust data reporting disclosure as a compliance exercise. Instead,
systems that are accurate and timely. applying an Environmental, Social and

PAGE 6 OF 10
HOT TOPICS
HUMAN CAPITAL, DIVERSITY
AND TALENT MANAGEMENT
The human factor
Human capital, diversity and talent Organisations must create a core, purposeful Chief audit executives can provide assurance
management ranked as the second highest and diverse culture to accommodate, for that their organisations have created
threat in Risk in Focus 2023 qualitative survey: example, hybrid working and inclusion, while governance structures with adequate risk
50% of chief audit executives rated it as a top remaining highly operational, productive and management controls that are aligned with
five risk. Respondents said it would retain functional however people choose to work. strategic talent objectives. Assignments
its new second-place position over the next may include assessing the current culture
three years. Some boards fail to either articulate or and helping management develop a
communicate a sense of purpose that roadmap for change and helping ensure
The pandemic has accelerated skills connects with the workforce and the the desired strategy is well articulated and
shortages as many mature workers have communities in which they operate. The communicated. The right tone set at the top
retired and younger people have favoured European Union’s pandemic recovery plan, by the board and senior management is the
education or alternative career routes. A NextGenerationEU, is built on the UN’s key to success.
leeching of institutional knowledge and Sustainable Development Goals. Internal
burnout has left many organisations with auditors can play a key role in supporting
hard-to-fill gaps for key projects, such as the board, by using such a framework to Businesses must tackle
digitalisation – a process that promises to help bridge potential gaps between the wage inflation, skill
alleviate such shortages in future. organisation’s purpose, the workforce and shortages and the need to
external stakeholders. Refreshing a business’
Businesses must tackle wage inflation, Environmental, Social and Governance
offer better psychological
skill shortages and the need to offer better framework can help it strengthen its support to staff.
psychological support to staff. That entails strategic human capital, diversity and talent
retooling their organisational culture. management goals.

PAGE 7 OF 10
HOT TOPICS
CYBERSECURITY
AND DATA SECURITY
Auditing at the speed of crime
Cybersecurity and data security remained the The European General Data Protection access rights, are properly implemented
number one threat for chief audit executives Regulation places responsibility for data on the ground. In addition, in less mature
in the Risk in Focus 2023 quantitative survey: breaches and losses squarely on the organisations chief audit executives could
82% ranked the risk in their top five. In shoulders of businesses – an approach facilitate breach simulation and tabletop
addition, internal auditors said they spent adopted in Europe’s revised cybersecurity exercises to strengthen defences and the
most time and effort working on this area. directive NIS2. These data protection rules effectiveness of remediation measures. With
are mirrored in the UK GDPR and moves are effective insurance protection difficult to
Ransomware has been a major threat in 2022, underway to strengthen the UK’s version of quantify or purchase, businesses must do all
but the nature of cyberattacks is changing. the NIS regulation. they can to mitigate such risks with their own
Relatively inexperienced hackers now take resources.
advantage of a sophisticated ransomware-as- Despite the intensity and gravity of
a-service industry. More ominously, “killware” cybersecurity and data security risk, many
attacks have also increased, targeting critical chief audit executives participating in Risk in Cyber and data breaches
infrastructure and threatening lives. Focus 2023 said boards often lacked either impact not only the
sufficient knowledge or interest in such quality and availability
That means that cyber and data breaches threats. While chief audit executives can play
impact not only the quality and availability a key role in helping spread cyber and data
of products and services,
of products and services, an organisation’s best practice, the interest and support of the an organisation’s
trustworthiness and reputation, but also its board is also critical. trustworthiness and
financial stability and very existence. Where reputation, but also
businesses have robust defences, hackers Internal audit has an important role in giving
seek entry via their less well protected third assurance that an organisation’s cyber
its financial stability
party suppliers or cloud-enabled systems. and data controls and policies, including and very existence.

PAGE 8 OF 10
HOT TOPICS
DIGITAL DISRUPTION
AND NEW TECHNOLOGY
Switching to automatic
Between 2020 and 2021, the pandemic forced balanced in an organisation’s culture – and processes for evaluating their reliability and
many organisations to accelerate lagging that innovation efforts are properly aligned to validity. But given the proposed tough new
digitalisation efforts as sales and distribution strategic objectives. regulations on AI in Europe and similar rules
networks needed to rapidly virtualise and as in the UK, internal audit must have the skills
many staff moved to homeworking. In addition, sound data governance is critical, and knowledge to assess the risk of bias
and boards must focus on strategic data risk. associated with such cognitive technologies
This year, chief audit executives responding Data risk can impact many areas at the same so that unfairness does not become baked
to the Risk in Focus 2023 quantitative survey time including, for example, reputational, into an organisation’s infrastructures.
ranked digital disruption and new technology regulatory, operation and financial risk. Yet
as the fifth most pressing risk, down two unlike with other emerging systemic risks,
places from 2022. But in three years’ time, organisations can better control such threats
they said it would rank as the second biggest by tackling the root cause of the problem –
area of internal audit effort. But rocketing poor data governance and management.
inflation, pay increases and supply chain
disruption threaten to sink such projects – As well as supporting businesses at a
despite the need for businesses to use new strategic level, internal audit must keep In three years’ time, chief audit
technologies to cut costs in the face of rising abreast of new technologies deployed in their
executives said digital disruption and
prices and to plug growing skill shortages. organisations, including artificial intelligence
new technology would rank as the
(AI). That can include working with the first
second biggest area of internal audit
Organisations that succeed in digitalising and second lines to use the business’ AI to
their businesses have strong innovation automate audit processes. Internal audit
effort, but rocketing inflation, pay
cultures, clear strategic vision and the right can also assess whether the organisation increases and supply chain disruption
talent. Internal audit can play a key role has a credible roadmap for progressing threaten to sink such projects.
in ensuring innovation and risk are well- to AI, as well as provide assurance over its

PAGE 9 OF 10
ABOUT RISK IN FOCUS
For the past seven years, Risk in Focus has sought to highlight key risk areas to help internal auditors
prepare their independent risk assessment work, annual planning and audit scoping. It helps Chief
Audit Executives (CAEs) to understand how their peers view today’s risk landscape as they prepare
their forthcoming audit plans for the year ahead.

This year, Risk in Focus 2023 involved a collaboration between 14 Institutes of Internal Auditors
spanning 15 European countries which included: Austria, Belgium, Bulgaria, France, Germany, Greece,
Italy, Luxembourg, the Netherlands, Slovenia, Spain, Sweden, Switzerland and the UK & Ireland.
The highest number of European countries involved so far.

The survey elicited a record-breaking 834 responses from CAEs across Europe. Simultaneously, four
roundtable discussions were organised with 39 CAEs on each of the risk areas covered in the report.
In addition, we also conducted 9 one-to-one interviews with subject matter experts that included
CAEs, Audit Committee Chairs and industry experts to provide deeper insights into how these risks are
manifesting and developing.

The colour scheme for this year’s Risk in Focus has been chosen as the same colours of the Ukraine
flag, to express European solidarity and support with the people of Ukraine.

IIA
The Institute of
Luxembourg Internal Auditors
Netherlands Slovenia

The Institute of
Internal Auditors
Switzerland

You might also like