Skip to main content
When Independence Becomes Ambiguity: The IIA's Enterprise Risk ExpansionEnterprise Risk Management
3 min readFor Internal Auditors

When Independence Becomes Ambiguity: The IIA's Enterprise Risk Expansion

Introduction

In July 2026, the Institute of Internal Auditors (IIA) released two position papers that redefined the operational boundaries of internal audit within enterprise risk management (ERM). These papers authorized internal audit functions to engage in activities traditionally managed by second-line risk management, such as facilitating risk identification workshops and advising on risk response options. While the IIA aimed to clarify roles with its updated Three Lines Model, it introduced ambiguity regarding accountability when internal audit participates in these activities.

Historical Context

January 2013: The IIA formalized its Three Lines of Defense model, positioning internal audit as the third line providing independent assurance.

2015: Basel's Corporate Governance Principles for Banks incorporated Three Lines terminology, reinforcing the model within financial services.

2020: The IIA updated the model to the Three Lines, emphasizing collaboration and integrating senior management with Lines 1 and 2.

July 2026: The IIA expanded internal audit's role in ERM, including decision support functions typically associated with second-line risk management.

Governance Design Challenges

The 2026 papers highlight a governance design issue: role ambiguity presented as flexibility.

Accountability Boundaries: The papers allow internal audit to advise on risk responses without selecting or implementing them. However, this creates a self-review risk. If internal audit facilitates a workshop to identify risks, then audits whether those risks were comprehensively identified, accountability becomes unclear.

Value Propositions: The papers describe overlapping competencies between internal audit and second-line risk management. Both should understand risk appetite and link risk to objectives, but the papers don't clearly define who does what. Internal audit is assigned the role of "integrator of assurance," yet second-line functions often build assurance maps due to their closer work with operational controls.

Scope Creep Checks: The papers permit internal audit to perform ERM work in certain scenarios, but they lack mechanisms to sunset these arrangements or manage their permanence.

Standards and Frameworks

The IIA's International Standards for the Professional Practice of Internal Auditing require internal audit to be independent and objective. Standard 1100 mandates independence, while Standard 1130.A1 addresses impairment, stating that internal auditors should not assess operations they were previously responsible for. The 2026 papers suggest safeguards like separating advisory and assurance work, but they assume boards can distinguish between collaboration and role dilution.

The COSO ERM Framework establishes that management owns risk, without designating a coordinating function. When internal audit becomes the "integrator" of risk information, it assumes a role that conflicts with its independent assurance function.

Actionable Steps for Your Organization

Define Distinct Purposes: Ensure each line has a clear purpose:

  • Line 1 makes decisions and owns outcomes.
  • Line 2 enhances decision quality through expertise and frameworks.
  • Line 3 provides independent assurance over decision-making processes.

Document Advisory Engagements: If internal audit advises on control design, commit to not auditing that control for two years. Extend the cooling-off period beyond the Standards' minimum to avoid perception issues, and present this to the audit committee in writing.

Assign Assurance Coordination Appropriately: If your second-line risk function handles control testing or compliance monitoring, it should build the assurance map. Internal audit should validate the map's completeness and reliance, not create it.

Separate Reporting Lines for ERM Work: If the risk function reports to the Chief Audit Executive, consider having it report directly to the CEO or CFO to prevent temporary arrangements from becoming permanent.

Test for Self-Review Annually: Present a matrix at each audit committee meeting showing which activities internal audit advised on in the past 24 months and which are scheduled for assurance review in the next 12 months. Reschedule overlapping assurance work or assign it externally.

Challenge "Integrated Conclusions": If your Chief Audit Executive claims to provide integrated conclusions about risk coherence, question what unique information internal audit has that the Chief Risk Officer does not. If none, internal audit may be duplicating Line 2 work.

The 2026 papers expand what internal audit may do. Your responsibility is to determine what it should do. Flexibility without boundaries leads to ambiguity, not effective governance.

You Might Also Like