The Brief · Issue #2
Good morning,
Every September the internal audit profession publishes what it fears, and how it rates its own coverage of it. This year, for the risk it ranks second, 11% call that coverage fully adequate. This issue is about that distance, and what an audit committee should do with it before next year's plan is signed.
▪ THE SIGNAL
What happened. On 15 September the Internal Audit Foundation released Risk in Focus 2026/2027, drawn from 3,285 chief audit executives and audit directors in 132 countries (IIA release, report). Digital disruption, which the report defines to include AI, rose ten points to become the second-ranked organisational risk, named in the top five by 58% globally and 69% in North America. Audit priority rose to 42%. Two other figures from the same survey sit against it: 23% rate their organisation's governance of it as managed or optimised, and 11% consider their internal audit coverage of it fully adequate (Internal Audit Foundation). On 17 September Internal Auditor published an article in which practitioners argued that internal audit's value on AI lies in judging whether models remain appropriate as conditions change, not in re-performing second-line validation (Internal Auditor).
The analysis. A survey records what leaders say, not what organisations do; we read it as a benchmark, not a diagnosis. Even so, it describes a profession that has seen the risk and not reorganised around it, now with the profession's own numbers on it. Three explanations compete. Capacity: few audit functions can re-perform model validation. True, and the wrong frame, since this week's practitioners place that task with the second line. Scope: AI is audited as a strand inside a wider technology review, so coverage is partial by design. Accounting: no single document states which material AI uses had independent review last year and which did not. Our read: the third is the one a committee can test this quarter. Ask for the count, and the answer will often be that no one has been asked to produce it. The profession knows the risk is large. What it has rarely done is count where its assurance lands.
So what: the assurance response. Before the 2027 plan reaches the audit committee, build the coverage map: every material AI or automated-decision use, against the independent review it received in the last twelve months, by which line, with a date. Where a row is blank, management states whether the exposure is accepted, and the committee sees the blanks as a list, not a footnote. Success criterion: the map is complete before the plan is approved, each row records who performed the review and to what scope, and the plan's AI work is selected by risk, with every blank row either scheduled or explicitly accepted by management. Scope the reviews as this week's practitioners describe (Internal Auditor): does the model still fit the business, who takes the final decision and against what threshold, are overrides tracked and their causes established, and who re-examines it when the business changes. None of those four questions requires the reviewer to open the model. They only need asking.
So what: the strategic read. Our read: where a board has approved AI spending without asking what independent review the estate has had, it is relying on assurance it has never specified. In most of this sample, the leaders closest to that assurance say it covers less than it should, a governance exposure before it is a technical one. Assurance stands as the early warning here, and the warning concerns assurance itself. A CAE who tells the committee "here is what we have not looked at" does more for the board than one who reports another clean general-controls review, and boards that hear it this planning cycle can allocate capital to AI with their eyes open.
◐ MEDIUM · plan
▪ THE RADAR
Agent security now has a published baseline to be tested against.
On 15 September ISACA published Cybersecurity Recommendations for Securing AI Agents, a free white paper and fifteen-item checklist whose recommendations include per-agent identity with no shared or long-lived credentials, sandboxed tool execution, human approval for destructive, financial, legal, regulated or irreversible actions, tamper-resistant logging and kill switches (ISACA).
So what: our read: a public list an audit team can hand to a technology owner with one question, which of these can you show us evidence for.
◐ MEDIUM · plan
A 24-hour reporting clock now runs for manufacturers of connected products sold into the EU.
From 11 September, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA's single reporting platform: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within 14 days of a fix being available for an exploited vulnerability, or within one month of the 72-hour notification for a severe incident (European Commission).
So what: the duty follows the manufacturer, not the home market, so any group placing connected products, or software with digital elements, on the Union market is in scope; manufacturers already in scope should treat the 24-hour path from detection to the platform as immediate readiness work.
◐ MEDIUM · plan
The pace of AI adoption remains your organisation's own decision.
In a September essay, Anthropic's chief executive Dario Amodei argued that frontier capability gains should be slowed so safety work can catch up, and committed his company to hosting embedded third-party evaluators (Dario Amodei); Nextgov reported that on 14 September the US President dismissed warnings about AI risk as a hoax, and ABC News reported OpenAI's chief executive saying that pacing did not mean stopping (Nextgov, ABC News).
So what: our read: do not plan on an external slowdown. The rate at which an organisation extends AI authority is its own decision, and assurance's job is to make that rate explicit, approved and evidenced.
○ WATCH · monitor
▪ THE BOARDROOM LINE
Across 3,285 audit leaders in 132 countries, 58% rank digital disruption and AI a top-five risk; 11% rate their audit coverage of it fully adequate. The question for the committee room is short: for each AI system this business depends on, who last reviewed it independently, when, and what is on the list nobody has reviewed? A CAE can answer on one page. A committee that has not seen that page should ask for it before approving next year's plan.
▪ LATEST UPDATES
On 15 September the Internal Audit Foundation released Risk in Focus 2026/2027 (Internal Audit Foundation).
On 15 September ISACA published Cybersecurity Recommendations for Securing AI Agents (ISACA).
On 15 September the US House Committee on Science, Space, and Technology held a bipartisan briefing with Hugging Face, METR, OpenAI and Anthropic on AI agent security incidents, some first disclosed by Hugging Face in July and others reported since (House Science Committee). So what: reconstructing agent incidents is now a legislative interest, not only a vendor's.
On 14 September, Nextgov reported, the US President dismissed the call led by Anthropic's chief executive in a September essay to slow frontier AI development (Nextgov).
On 14 September Microsoft AI published a draft Humanist AI Code of Conduct for its own models, open to six weeks of consultation, stating its models will not resist shutdown or tamper with their reasoning traces (Microsoft AI). So what: a draft code a buyer can ask to see written into contract.
On 16 September NIST closed comments on its AI Standards Zero Draft on public-facing AI documentation templates, which it will revise before submitting it into the private-sector standardisation process (NIST). So what: prepare for public AI claims to be judged against a common template.
On 17 September the EU AI Board held its ninth meeting, covering enforcement priorities, recent frontier AI incidents, and the transparency rules applicable since 2 August (European Commission). So what: expect requests for transparency evidence; check your deployers can produce it.
On 17 September Internal Auditor published Governing AI Analytics (Internal Auditor).
Know what matters. See you next Tuesday.
Ansh
New here? Subscribe at combinedassurance.com and The Brief lands in your inbox every Tuesday morning.

