Internal Audit :2027 Risk in FocusÂ
IIA Belgium has published Risk in Focus 2027 (15 September 2026), the 11th edition of the annual European study on the key risks identified by Chief Audit Executives (CAEs). This benchmark report on internal audit and risk management shows how the risk landscape is evolving faster than traditional governance cycles, pushing boards, audit committees, and internal audit functions to rethink how they anticipate, monitor, and respond to disruption.
Three signals stand out
1. Cybersecurity still dominates. Cybersecurity and data security remain the highest-ranked enterprise risk, with 86% of CAEs placing it in their top five. Key drivers include AI-enabled cyber attacks, supply chain vulnerabilities, and rising geopolitical tension, underlining that cyber risk is now a strategic business issue rather than a purely technical concern.
2. AI is rising faster than organisations can govern it. Digital disruption, emerging technologies, and artificial intelligence moved from third to second place, cited by 52% of CAEs. The report warns that governance frameworks, risk maturity, and assurance activities are not keeping pace with rapid AI adoption, creating potential blind spots in AI risk management and internal controls.
3. Geopolitical uncertainty is high on the list, but little effort goes into it. Macroeconomic and geopolitical uncertainty has risen to third place among top risks. However, risk maturity, scenario planning, and internal audit effort in this area remain comparatively low, indicating a gap between perceived geopolitical risk and the level of assurance and oversight devoted to it.

The common thread: a governance gap
Across these examples, organisations clearly recognise emerging and strategic risks but are not yet structured or governed to manage them effectively. This is a familiar pattern from certification, compliance and sustainability schemes. Risk management systems can be carefully designed and fully compliant, yet still overlook the real exposures that matter most. Assurance that validates conformity with yesterday's standards does not automatically create resilience against tomorrow's risks, disruptions and regulatory expectations.
Questions for boards and assurance leaders
- Is the risk register still updated on an annual cycle while the risk landscape, including cyber, AI and regulatory risks, evolves monthly or even faster?
- Where is AI already in use across the organisation, how critical are these applications, and who is accountable for governing AI risk, ethics and compliance?
- Does the assurance programme focus on the organisation’s highest and most material risks, or mainly on the most familiar and historically tested ones?
- Are geopolitical, climate and supply chain disruption scenarios embedded in strategic decision-making, or only referenced in risk reports and board papers?
For more information and to access the full Risk in Focus 2027 report, click here

