Outsourced internal audit in Luxembourg: turning it into an asset

In Luxembourg, internal audit can be outsourced for its operational tasks, but responsibility remains within the entity and requires robust governance, direct access to the board and a service provider that masters the CSSF framework.
The risk-based approach: auditing where the real stakes lie

The risk-based approach allows internal audit to concentrate its resources on the most significant issues for the organisation and to adapt its plan when the risk profile evolves.
Getting the best out of internal audit: the role of the leader

The board and management can maximise the value of internal audit by protecting its independence, providing it with resources suited to the risks, and regularly evaluating its quality and impact.
Cyber, AI, ESG: internal audit facing new risks

Faced with cybersecurity, artificial intelligence, ESG issues and geopolitical risks, internal audit must provide the board with agile and independent assurance focused on the most significant emerging risks.
From compliance to value creation: internal audit is evolving

Internal audit is evolving from a compliance-driven approach towards a risk-based function that is more anticipatory and designed to create, protect and sustain value for the organisation.
The Three Lines of Defence model: who does what in the face of risk

The three lines model clarifies responsibilities between the business operations that manage risks, the oversight functions that monitor them, and internal audit, which provides independent assurance to the board.
Why internal audit is an ally of the board of directors

Internal audit provides the board of directors with independent assurance on the actual management of risks and offers a complementary perspective to management reporting to better inform its decisions.
DORA: digital resilience, a governance issue

DORA imposes a digital resilience framework on financial entities that places the management of IT risk, incidents, and ICT third-party providers under the direct responsibility of governance.
IIA Code of Practice: a new benchmark for internal audit

The cyber audit must articulate an approach based on business risks, the requirements of the IIA cybersecurity framework and the DORA regulatory baseline applicable to regulated entities.
Cybersecurity audit: balancing risks and applicable requirements

The cyber audit must articulate an approach based on business risks, the requirements of the IIA cybersecurity framework and the DORA regulatory baseline applicable to regulated entities.