Cybersecurity · Artificial intelligence · ESG
Cyber, AI, ESG: internal audit confronting new risks
Cyberattacks, artificial intelligence, sustainability, geopolitical uncertainty: the risk landscape is transforming rapidly. For a board, the question is not only «are we exposed?», but «who assures us that these risks are under control?». This is a key role for internal audit.
According to the report Risk in Focus 2026 According to the European Confederation of Institutes of Internal Auditors (ECIIA), more than 80 % of internal audit managers rank cyber security and data security as the top risks — and this is where they spend most of their time. The European DORA (Digital Operational Resilience in the Financial Sector) regulation has, moreover, tightened the requirements in this area.
Cybersecurity, risk number one
The role of internal audit is not to configure firewalls, but to provide the board with clear assurance: are our critical systems identified? What would a successful attack cost? Are our response capabilities equal to the threat? In early 2025, the IIA published a framework dedicated to cybersecurity, precisely to help translate technical risk into the language of decision-making.
Artificial intelligence: opportunity and blind spot
Digital disruption, driven by AI, is now among the top risks identified by European organisations. The challenge is twofold. On the one hand, AI represents an opportunity, including for internal audit itself, which uses it to analyse more data. On the other hand, it creates new risks: poorly controlled automated decisions, bias, poor quality data, and unregulated usage.
Sustainability and geopolitics: risks that are here to stay
Sustainability has entered the insurance sector with the European CSRD directive, which extends non-financial reporting obligations (environmental, social and governance — ESG). ESG information is becoming reliable data to be audited, just like financial figures. At the same time, geopolitical risk — trade tensions, sanctions, supply chain disruptions — has seen one of the sharpest increases among executives' concerns.
The common thread: agile insurance
These risks have one thing in common: they evolve faster than traditional audit cycles. The answer is not to audit everything, but to have a living audit plan, readjusted as soon as the landscape changes, and regular dialogue between the board, management and internal audit on priorities. It is this agility that makes the difference.
Cyber, AI, ESG: ARCAD designs specialised audits tailored to your exposure.
References & further reading
- Report Risk in Focus 2026, European Confederation of Institutes of Internal Auditing (ECIIA).
- Cybersecurity Topical Requirement, Institute of Internal Auditors (IIA), 2025.
- DORA Regulation (EU) and CSRD Directive (EU) — European reference frameworks for digital resilience and sustainability reporting.