The Risks Hidden by the Average
Blogs Sarah Kuhn, CIA, CRMA, CCSA Oct 05, 2026

I recently listened to a scientist talk about what he called the shift from the “age of the mean” to the “age of standard deviation.” His point was that many of today’s most important problems can no longer be understood by looking at averages alone. What matters just as much is the variation around those averages.
As I listened, I immediately thought about internal audit.
The Risk in Focus 2026/2027 report describes a risk environment that is becoming more digital, interconnected, and volatile. Cybersecurity remains the top global risk, while digital disruption and geopolitical uncertainty continue to accelerate. For internal audit, the challenge is not just identifying change. It is translating rapid and interconnected change into timely assurance and useful insight.
I wonder if part of that challenge is that risk is not only increasing. It is becoming less evenly distributed.
Historically, auditors have relied on metrics that describe the average state of a process: average compliance rates, average control performance, average training completion, average exception levels, and average operating results. Those measures still matter. But many modern risks do not emerge because controls are weak everywhere. They emerge because controls operate differently across the organization.
Consider a process with a 98% compliance rate. On the surface, that sounds strong. But what if most of the noncompliance is concentrated in a newly acquired business unit? What if the exceptions all occur in a high-risk geography or with a critical vendor relationship? The average may suggest stability, while the distribution tells a very different story.
I see this often in risk interviews and audit planning discussions. Leaders describe issues that are really about variation. Controls struggle to keep pace with transformation. Ownership becomes less clear as operating models evolve. Data sits in multiple systems. Different business units adopt new technologies at different speeds. None of that necessarily means every control is failing. It may mean risk is emerging where execution is uneven.
Increasingly, the problem may not be weak controls. It may be uneven controls.
That shift matters for how we audit. Traditional testing often begins with sample selection. We identify a population, determine a sample size, and begin testing attributes. That approach is still necessary, but I think auditors should pause first to understand the shape of the population. Where is activity concentrated? Which locations look different from their peers? Which vendors account for a disproportionate share of spend? Are there outliers, unusual trends, or patterns that suggest elevated risk?
This is where AI can help. Before selecting a sample, an auditor can ask AI to analyze a population for concentration risk, dispersion, stratification opportunities, unusual trends, outliers, and indicators of elevated risk. The point is not to replace auditor judgment. The point is to aim auditor judgment where it can create the most value.
For example, an auditor might use AI to identify whether a small number of contracts account for most spending, whether approval patterns differ by location, whether exceptions cluster around a particular system, or whether process execution varies across business units. Those observations can then influence scope, sampling strategy, and testing focus.
I also think this matters after testing, when auditors are evaluating root causes and action plans. If the issue is excessive variation, the solution cannot focus only on improving the average result. A process may achieve better overall performance while still leaving pockets of elevated risk. Effective action plans should improve performance while also reducing unwarranted variation in ownership, execution, governance, data quality, and control performance.
Put differently, organizations should ask two questions: Will this improve the average outcome? And will it reduce the spread between our strongest and weakest performers?
The average will always have value. Internal auditors will continue to evaluate control effectiveness, compliance, and performance. But in a world characterized by rapid change and interconnected risks, some of the most meaningful insights will come from identifying concentration, variability, and fragility.
The next meaningful audit insight may not come from what is typical. It may come from discovering where the organization behaves differently.
The views and opinions expressed in this blog are those of the author and do not necessarily reflect the official policy or position of The Institute of Internal Auditors (The IIA). The IIA does not guarantee the accuracy or originality of the content, nor should it be considered professional advice or authoritative guidance. The content is provided for informational purposes only.