Risk in Focus: Top 10 Takeaways from This Year’s Findings
Blogs Anthony Pugliese, CIA, CPA, CGMA, CITP Sep 16, 2026

Each year, the Internal Audit Foundation’s Risk in Focus report provides a global view of the top risks shaping organizations today, as well as their governance priorities and the priorities of internal audit functions tasked with helping teams navigate them.
The results of this initiative — a collaborative, global effort involving more than 3,000 internal audit leaders across more than 130 countries — are an essential benchmark for boards, management, and governance leaders on how the risk landscape is changing, where attention is shifting, and where there are opportunities to strengthen organizational preparedness.
This year, Risk in Focus 2026/2027 went a step further. For the first time, we asked internal audit practitioners to assess not only the risks their organizations face and where internal audit is focusing its resources, but also the maturity of risk governance and the extent of audit coverage across those risks. The goal was to provide a more complete picture of organizational preparedness and to help identify not only where risks are rising, but to what extent governance and assurance are keeping pace.
The findings reinforce the increasingly critical nature of our work in helping organizations navigate disruption and rapid change. They also underscore that keeping pace with today’s highly interconnected and evolving risk landscape requires a collective, integrated effort across boards, management, internal audit, and other governance and assurance functions.
Here are my top ten takeaways from this year’s research:
1. Cybersecurity remains the top organizational risk.
Cybersecurity continues to lead the global risk landscape for internal auditors, with 80% of respondents ranking it among their organization’s top five risks, up seven percentage points from last year. It also continues to garner significant internal audit attention, with 75% identifying it as a top five audit priority.
2. Digital disruption is accelerating rapidly.
Perhaps unsurprisingly, digital disruption, including artificial intelligence (AI), recorded one of the largest increases in risk level from the previous year, rising ten percentage points to 58% globally. North America reported an even higher risk level at 69%, reflecting a heightened impact from AI and other emerging technologies.
3. Geopolitical uncertainty is rising quickly.
Geopolitical and macroeconomic uncertainty also rose significantly, up ten percentage points, with 48% of respondents now identifying it as a top five organizational risk. Combined with last year’s findings, this risk jumped 20 percentage points over the past two years — the most of any risk category. This warrants particular attention, given that geopolitical developments can have far-reaching consequences across supply chain management, financial liquidity, legal compliance, regulation, market competition, and business resilience.
4. External risks have internal consequences.
One of the clearest messages from this year’s research is that organizations must quickly assess and respond to the impact of external risks. Cyber incidents, geopolitical events, and accelerating technological disruption can quickly drive consequences related to business operations, supply chains, fraud, talent, regulatory exposure, and financial performance. Organizations today must understand how these individual risks are evolving, and also how they intersect and compound one another.
5. Internal audit continues to increase its focus on technology.
As technology risks evolve and accelerate, internal audit functions continue to adapt their priorities. Digital disruption saw the largest increase in audit priority, rising ten percentage points to 42%, reflecting practitioners’ agility in responding to rising risks related to technological change and AI. While this shift is encouraging, the sheer speed of change means audit functions must continue building the skills and capabilities needed to proactively assess and address emerging technologies effectively.
6. Risk levels and audit attention don’t always align.
For certain risk areas, audit priorities do not directly align. Geopolitical and macroeconomic uncertainty provides a clear example of this. While 48% of respondents rank it as a top five risk, only 13% identify it as a top five audit priority. This doesn’t necessarily mean that geopolitical risks are being ignored. It may reflect the fact that its impacts are being assessed through other related areas, such as supply chain, liquidity, regulatory compliance, and business resilience. The task for internal audit is to understand where adequate assurance already exists and where important gaps remain.
7. Governance maturity varies across the fastest-changing risks.
For the first time, Risk in Focus examined governance maturity, revealing an important gap in organizational preparedness for some of the fastest-changing risks. Just 23% of respondents rate governance of digital disruption as managed or optimized, while only 29% say the same for geopolitical uncertainty. The findings suggest that some risks are evolving faster than their governance structures and internal controls.
8. Emerging risks with low audit coverage and low risk governance maturity must be addressed.
Only 11% of respondents report full audit coverage for digital disruption and 10% for geopolitical uncertainty. By comparison, for financial and liquidity risk — a more established area — 62% report mature governance and 47% identify full audit coverage. As emerging risks continue to grow, audit resources, capabilities, and skills will need to evolve alongside them.
9. Reinforcing organizational preparedness is a shared responsibility.
These findings highlight the need for stronger collaboration across the organization. Effective preparedness requires boards, management, internal audit, and other risk and governance functions to understand their respective responsibilities while working together to build a more complete view of the organization’s risk exposure and strategy. No one function can address today’s interconnected risks in isolation.
10. Having foresight and being proactive are more critical than ever.
Above all, the findings suggest that today’s risk landscape is evolving rapidly. Geopolitical risk, for example, has recorded the largest increase in perceived risk level for two consecutive years. These fast-moving risks require a more strategic, forward-looking approach, which includes scenario analysis, stress testing, and other assessments that help organizations understand potential exposures before they materialize.
As the risk landscape evolves, our approach to governance and assurance must evolve alongside it. The organizations best positioned for what comes next will be those that can work collectively to identify emerging risks and assurance gaps early, adapt quickly, and work collaboratively across functions to translate risk awareness into organizational preparedness and resilience.