惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog
B
Blog RSS Feed
小众软件
小众软件
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
大猫的无限游戏
大猫的无限游戏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 聂微东
WordPress大学
WordPress大学
月光博客
月光博客
S
SegmentFault 最新的问题
Engineering at Meta
Engineering at Meta
量子位
V
Visual Studio Blog
罗磊的独立博客
Last Week in AI
Last Week in AI
The Cloudflare Blog
H
Help Net Security
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Microsoft Azure Blog
Microsoft Azure Blog
The GitHub Blog
The GitHub Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
美团技术团队

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
With AI, Internal Audit Moves From Hindsight To Foresight
Nosa Omoigui · 2026-05-14 · via Forbes - Innovation

Nosa Omoigui, CEO of Weave.AI, neuro-symbolic GenAI and intelligent agents that transform alpha decision making and risk analysis.

Businessman show analyzing report, business performance concept

getty

In the traditional architecture of financial institutions, internal audit (IA) has long been viewed as the “rear-view mirror,” verifying compliance after risks materialize. That model is breaking down.

AI is changing this by making external signals, control evidence and peer activity continuously observable and testable at scale. In many failures, warning signs were visible well before losses materialized, but organizations lacked the ability to translate those signals into decisive action, resulting in capital strain, remediation costs, reputational damage and sustained board scrutiny.

As markets become more interconnected and opaque, driven by geopolitical volatility, third-party dependencies and rapid AI adoption, boards and executives are demanding independent, real-time and defensible assurance on where risk is emerging, not just where it has crystallized.

For chief audit officers (CAOs) and chief risk officers (CROs), this marks a fundamental shift. Internal audit is evolving from a retrospective control function into a horizontal assurance layer across the enterprise, providing the board with a continuously updated view of control effectiveness, risk exposure and systemic vulnerability.​

A New Expectation From The Board

Boards and audit committees now expect defensible, evidence-based insight into emerging risks and assurance gaps, not retrospective summaries. They want clarity on where assurance is insufficient and visibility into emergent risks.

Institutions that fail to evolve can risk creating a false sense of control, where assurance is incomplete, outdated or misaligned with external reality.​

From Assurance Over Assertions To Audit-Grade Evidence

Assurance must shift from management assertions to independently verifiable, evidence-linked proof.

In a modern IA function, every finding must be:

• Traceable to underlying source signals

• Contextualized within the broader risk ecosystem

• Defensible under regulatory, audit and board scrutiny

IA is moving from validating what management believes to be true to establishing what is provably true, increasingly enabled by AI systems that connect unstructured disclosures, internal data and external signals into traceable evidence chains.​

The collapse of Archegos Capital Management illustrates the consequences of failing to make this shift. Counterparties believed the risk was understood, yet total return swaps obscured the full scale of leverage and concentration. Without a consolidated, evidence-linked view to challenge those assumptions, exposures accumulated, contributing to losses exceeding $10 billion across major banks.​

The lesson is clear: Risk is often visible before it becomes catastrophic, but only if evidence is translated into decisive action.​

The Emergence Of Peer-Relative Assurance

Evaluating controls within the four walls of the institution is no longer sufficient.

AI enables continuous benchmarking across peer disclosures, regulatory actions and market signals, allowing IA to surface coverage gaps, identify externally tested risks not assessed internally and challenge internal assumptions with independent evidence.

In this context, the absence of coverage is itself a signal. If peers are actively auditing a risk domain and an institution is not, that gap may indicate exposure, not strength.​

From Fragmented Reviews To End-to-End Assurance

Modern risk does not respect organizational or domain boundaries. Patterns such as third-party concentration risk, cyber vulnerabilities and governance breakdowns propagate across systems, counterparties and sectors.

IA is evolving from fragmented, domain-specific reviews to end-to-end, cross-domain assurance, connecting findings across silos, identifying systemic weaknesses and surfacing dependencies that amplify risk.

The result is an integrated, enterprise-wide view of assurance that reflects how risk actually manifests.​

Real-Time Signals Replacing Point-In-Time Audits

Traditional audit models suffer from data lag, making point-in-time reviews insufficient in a fast-moving risk landscape.

AI enables continuous, signal-driven assurance by ingesting internal and external data in near real time, detecting emerging risks earlier and dynamically recalibrating audit priorities as exposures evolve.

​The Equifax data breach reflects the limits of static assurance. A known Apache Struts vulnerability remained unpatched, and controls failed to verify that remediation had actually occurred, leaving management assumptions untested and control effectiveness overstated.​

Linking Audit Findings To Real-World Impact

Audit findings must link control gaps to financial, regulatory, operational and reputational consequences. For boards and audit committees, the question is not just what is wrong, but why it matters.

​The Wells Fargo cross-selling scandal demonstrates the cost of failing to connect signals to systemic risk. Warning signs, including employee complaints and internal reports, were not escalated or synthesized into a clear risk narrative, delaying intervention and amplifying regulatory, financial and reputational consequences.​

Common Lessons Across Past Audit Failures

Across cases, including those cited above, three recurring failures emerge:

• Gaps in traceability, where institutions cannot demonstrate what was known and when

• Breaks in continuity, where episodic monitoring allows risk to accumulate

• A lack of challenge, where known issues are not tested against peer practice or forced into remediation

These reflect a systemic gap between available evidence and actionable assurance.

Translating Insight Into Action

For CAOs and CROs, this shift requires operational change, enabled by AI-driven monitoring, prioritization and evidence-based challenge.

Three priorities stand out:

1. Establishing End-To-End Traceability: Ensure every risk signal and audit finding is traceable from source evidence through escalation and resolution.

2. Moving To Continuous Monitoring: Supplement periodic reviews with ongoing signal ingestion across internal data, third-party exposures and external events.

3. Embedding Peer-Relative Challenge: Calibrate assurance not only against internal standards, but against how comparable institutions identify and manage similar risks.

These are not incremental improvements. They represent a shift toward continuously updated, evidence-based, decision-forcing assurance increasingly expected by boards, regulators and stakeholders.​

From Hindsight To Foresight

Internal audit is no longer a function that explains what went wrong. It is becoming the function that identifies where risk is emerging, where assurance is insufficient and what actions are required before loss materializes.

In an environment defined by complexity and interdependence, this shift is not optional. It separates institutions that anticipate risk from those that react to it.

Control failures rarely become existential because no one knew; they become existential because no one forced the issue early enough.

AI changes this dynamic by continuously surfacing risk signals, enabling IA to detect patterns and challenge gaps between assertions and evidence, shifting from passive reporting to active intervention.

Institutions that recognize this can redefine assurance as a strategic advantage. Those that do not may continue auditing the past while risk accumulates in the present.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?