Cybersecurity · Artificial intelligence · ESG

Cyber, AI, ESG: internal audit confronting new risks

Cyberattacks, artificial intelligence, sustainability, geopolitical uncertainty: the risk landscape is transforming rapidly. For a board, the question is not only «are we exposed?», but «who assures us that these risks are under control?». This is a key role for internal audit.

Category: Risk management Reading time: 5 minutes Series: Understanding internal audit (4/7)

According to the report Risk in Focus 2026 According to the European Confederation of Institutes of Internal Auditors (ECIIA), more than 80 % of internal audit managers rank cyber security and data security as the top risks — and this is where they spend most of their time. The European DORA (Digital Operational Resilience in the Financial Sector) regulation has, moreover, tightened the requirements in this area.

Over 80 % Audit managers put cybersecurity top
3rd row Position of AI and digital disruption
ESG · Geopolitics Two risks that are becoming firmly established

Cybersecurity, risk number one

The role of internal audit is not to configure firewalls, but to provide the board with clear assurance: are our critical systems identified? What would a successful attack cost? Are our response capabilities equal to the threat? In early 2025, the IIA published a framework dedicated to cybersecurity, precisely to help translate technical risk into the language of decision-making.

Artificial intelligence: opportunity and blind spot

Digital disruption, driven by AI, is now among the top risks identified by European organisations. The challenge is twofold. On the one hand, AI represents an opportunity, including for internal audit itself, which uses it to analyse more data. On the other hand, it creates new risks: poorly controlled automated decisions, bias, poor quality data, and unregulated usage.

The right reflex: not treating AI as an isolated subject, but ensuring it is governed — who decides on its use, on what data, with what safeguards? Internal audit can assess this governance before incidents occur.

Sustainability and geopolitics: risks that are here to stay

Sustainability has entered the insurance sector with the European CSRD directive, which extends non-financial reporting obligations (environmental, social and governance — ESG). ESG information is becoming reliable data to be audited, just like financial figures. At the same time, geopolitical risk — trade tensions, sanctions, supply chain disruptions — has seen one of the sharpest increases among executives' concerns.

The common thread: agile insurance

These risks have one thing in common: they evolve faster than traditional audit cycles. The answer is not to audit everything, but to have a living audit plan, readjusted as soon as the landscape changes, and regular dialogue between the board, management and internal audit on priorities. It is this agility that makes the difference.

Align your internal audit with emerging risks.

Cyber, AI, ESG: ARCAD designs specialised audits tailored to your exposure.

Schedule an exchange →

References & further reading

  • Report Risk in Focus 2026, European Confederation of Institutes of Internal Auditing (ECIIA).
  • Cybersecurity Topical Requirement, Institute of Internal Auditors (IIA), 2025.
  • DORA Regulation (EU) and CSRD Directive (EU) — European reference frameworks for digital resilience and sustainability reporting.