Emerging Technology Risks in Audit Planning
In CIA Part 3, which covers business knowledge for internal auditing, emerging technology risks are a key input to the risk-based internal audit plan. Under the IIA Global Internal Audit Standards, the chief audit executive must build a plan from a documented assessment of the organization's strate… In CIA Part 3, which covers business knowledge for internal auditing, emerging technology risks are a key input to the risk-based internal audit plan. Under the IIA Global Internal Audit Standards, the chief audit executive must build a plan from a documented assessment of the organization's strategies, objectives, and risks. That plan must be updated as the risk landscape changes, and rapidly evolving technologies are among the fastest-moving drivers of change. Emerging technologies include artificial intelligence and machine learning, robotic process automation, cloud computing, blockchain and distributed ledgers, the Internet of Things, big data analytics, and mobile and remote-work platforms. Each creates opportunities and new exposures. These include cybersecurity threats, data privacy and regulatory compliance issues, algorithmic bias and model risk, third-party and vendor dependence, weak data integrity, inadequate change management, skills shortages, and governance gaps where adoption outpaces policies and controls. When planning, auditors should first identify which technologies the organization is adopting or piloting and how they link to strategic objectives. They should then assess inherent risk, control maturity, and potential impact on financial reporting, operations, and reputation, and prioritize engagements. Internal audit can add value by providing advisory services early in implementation, such as reviewing project governance, system development controls, and security by design, rather than waiting for post-implementation assurance. Planning must also address internal audit's own capability. The CAE should evaluate whether staff have sufficient competencies in IT, data analytics, and cyber risk. Gaps can be closed through training, guest auditors, or cosourcing, consistent with proficiency and due professional care requirements. Many functions adopt agile or rolling audit plans, continuous risk assessment, and continuous auditing tools so they can respond quickly to technological change. Coordination with second-line functions such as IT risk, information security, and compliance helps avoid duplication and supports combined assurance. Finally, the CAE communicates technology-related risks and resource needs to senior management and the board, ensuring the plan reflects the organization's risk appetite and strategic direction.
Emerging Technology Risks in Audit Planning (CIA Part 3: Internal Audit Plan)
Introduction
Emerging technology risks in audit planning is a key topic in CIA Part 3 (Business Knowledge for Internal Auditing). It covers how internal audit identifies, assesses, and prioritizes risks from new technologies when it builds the risk-based internal audit plan.
Examples of such technologies include:
- artificial intelligence (AI) and machine learning (ML)
- generative AI
- robotic process automation (RPA)
- cloud computing
- blockchain and distributed ledgers
- the Internet of Things (IoT)
- big data analytics
- mobile and remote-work platforms
- quantum computing
Exam questions test whether you understand how these technologies change the organization's risk profile and how the Chief Audit Executive (CAE) should respond in the audit plan.
Why It Is Important
1. Technology changes risk quickly. Traditional annual audit plans assumed fairly stable risks. Emerging technologies can create new exposures within months, such as:
- data leakage through generative AI tools
- bias in algorithmic decisions
- ransomware spreading through IoT devices
- third-party failures at cloud providers
2. Standards require a risk-based plan. The IIA's Global Internal Audit Standards (and the earlier Standard 2010 – Planning) require the CAE to create a risk-based plan. The plan must reflect the organization's strategies, objectives, and risks, and the CAE must review and adjust it as conditions change. Ignoring emerging technology would leave a major gap in that risk assessment.
3. Stakeholder expectations. Boards and audit committees increasingly ask internal audit for assurance and advice on digital transformation, cybersecurity, AI governance, and data privacy.
4. Strategic value. Internal audit can add value by giving advisory input early in technology adoption. This means internal audit is "at the table" before systems go live, instead of auditing problems after the fact.
5. Regulatory pressure. New laws carry significant compliance risk. Examples include:
- data protection laws (e.g., GDPR, CCPA)
- AI regulations (e.g., the EU AI Act)
- cybersecurity disclosure rules
What It Is
Emerging technology risks are uncertainties arising from adopting, using, or failing to adopt new technologies that could affect achievement of organizational objectives. They fall into several categories:
- Strategic risk: failing to adopt technology (competitive disruption) or adopting it poorly (wasted investment, misalignment with strategy).
- Operational risk: system failures, automation errors (e.g., a bot repeating an error thousands of times), integration problems, loss of human expertise.
- Cybersecurity and information security risk: larger attack surface (IoT, cloud, APIs), misconfigurations, identity and access weaknesses.
- Data and privacy risk: poor data quality feeding AI models, unauthorized use of personal data, data residency issues in the cloud.
- Compliance and legal risk: breaching privacy laws, AI transparency rules, intellectual property issues (e.g., generative AI content).
- Third-party/vendor risk: reliance on cloud service providers, SaaS vendors, and AI model providers. Assurance may come from SOC 2 reports.
- Ethical and reputational risk: algorithmic bias, lack of explainability, misuse of surveillance technology.
- Governance risk: unclear ownership, shadow IT, no AI or technology governance framework.
- Financial reporting risk: automated controls replacing manual ones, crypto-asset valuation, completeness and accuracy of data flowing through new systems.
Key technology-specific risks to know:
- AI/ML: model bias, lack of explainability ("black box"), model drift, poor training data, hallucinations (generative AI), inadequate human oversight.
- RPA: bots running with privileged credentials, errors repeated at scale, weak change management, unclear bot ownership, broken processes when underlying applications change.
- Cloud computing: shared responsibility model confusion, misconfiguration, vendor lock-in, data location, availability, and right-to-audit clauses.
- Blockchain: private key management, smart contract coding errors, irreversibility of transactions, regulatory uncertainty, oracle reliability.
- IoT: weak default passwords, unpatched devices, physical safety risks, huge volumes of data.
- Big data/analytics: data quality, privacy, data governance, integrity of the data lineage.
How It Works in Audit Planning
Step 1 – Understand the organization's strategy and technology roadmap. The CAE reviews strategic plans, digital transformation initiatives, IT project portfolios, and budget allocations. The CAE interviews the CIO, CISO, Chief Data Officer, business leaders, and the board.
Step 2 – Update the audit universe. Add new auditable entities, such as:
- the AI governance program
- cloud migration projects
- the RPA center of excellence
- third-party technology providers
- data governance
Step 3 – Perform the risk assessment. Evaluate impact and likelihood. Also consider:
- velocity: how fast the risk could hit
- complexity
- maturity of controls
- the organization's risk appetite
Use ERM outputs where reliable, but form an independent view. Emerging risks are often high-velocity and poorly understood, which typically raises their priority.
Step 4 – Consider internal audit's own capability. Assess whether the team has the competencies needed (IIA Standards on proficiency). Options include:
- training staff and pursuing certifications (CISA, cloud, data analytics)
- hiring specialists
- guest auditors from other functions
- co-sourcing or outsourcing
If resources are insufficient, the CAE must communicate the impact of the limitation to senior management and the board.
Step 5 – Choose the type of engagement. Choices include:
- Advisory (consulting) engagements during design and implementation, e.g., pre-implementation reviews, participation in project steering committees as an advisor while preserving independence.
- Assurance engagements after implementation, e.g., post-implementation reviews, AI model governance audits, cloud security audits, third-party risk audits.
- Continuous auditing and monitoring using analytics for fast-changing risks.
Step 6 – Use frameworks. Common reference points include:
- COBIT 2019 (IT governance)
- NIST Cybersecurity Framework
- ISO/IEC 27001 (information security)
- ISO/IEC 42001 and the NIST AI Risk Management Framework (AI)
- the IIA's AI Auditing Framework
- COSO ERM and COSO Internal Control
- the IIA's GTAGs (Global Technology Audit Guides)
Step 7 – Keep the plan dynamic and agile. Prefer rolling or quarterly plans, agile auditing, and a reserve of unallocated hours for emerging issues. Communicate significant changes to the board for approval.
Step 8 – Coordinate and rely on others. Coordinate with the second line (risk management, compliance, information security) and external assurance providers. Use combined assurance mapping to avoid gaps and duplication.
Step 9 – Communicate. Present the plan, resource needs, and key emerging technology risks to senior management and the board. Include any areas internal audit cannot cover.
Example Scenario
A bank plans to deploy a generative AI chatbot for customer service and an ML credit-scoring model next year. The CAE should:
- add both to the audit universe
- assess risks (data privacy, biased lending decisions, regulatory fair-lending compliance, model explainability, vendor reliance, reputational harm)
- provide advisory input on the AI governance framework during development
- plan a post-implementation assurance review of model validation and monitoring controls
- bring in a data science specialist through co-sourcing
- present the updated plan to the audit committee
Exam Tips: Answering Questions on Emerging Technology Risks in Audit Planning
1. Think "risk-based and dynamic." The best answer usually adjusts the audit plan in response to new or changing risks. Be wary of options that rigidly stick to a fixed annual plan or a cyclical rotation.
2. Governance first. When an organization adopts AI, cloud, or RPA, the strongest answer often focuses on whether governance, ownership, policies, and risk management exist. Detailed technical testing usually comes later. Questions frequently reward "evaluate the governance framework" over "test individual transactions."
3. Get involved early, but protect independence. Advisory involvement during system development or adoption is generally preferred over waiting until after go-live. However, internal audit must not design controls, make management decisions, or own the implementation. Any option where the auditor takes on management responsibility is likely wrong.
4. Address competency gaps correctly. If the team lacks skills, the right responses include:
- training
- hiring
- co-sourcing/outsourcing
- using internal experts with appropriate objectivity
- informing the board of resource limitations
Wrong answers include skipping the area without disclosure or performing the work without proper skills.
5. Know the shared responsibility model for cloud. The customer remains responsible for its data, access management, and configuration even when the provider secures the infrastructure. Outsourcing a process does not outsource accountability. Look for answers about SOC reports, right-to-audit clauses, and vendor monitoring.
6. Recognize technology-specific signature risks. Match each technology with its typical exam keywords:
- AI: bias, explainability, data quality, model drift
- RPA: credential management, change control, errors at scale
- Blockchain: private keys, smart contract errors, irreversibility
- IoT: device security, patching
- Cloud: configuration, vendor dependency, data location
7. Prioritize by impact, likelihood, and velocity. Emerging technologies with high strategic importance, significant data sensitivity, or regulatory exposure generally deserve higher priority in the plan.
8. Board and senior management communication. Significant plan changes, resource limitations, and major emerging risks must be communicated to senior management and the board. The board approves the plan.
9. Use of technology by internal audit itself. Some questions ask how internal audit can use emerging technology, such as data analytics, continuous auditing, process mining, or AI tools. Remember that these tools also need validation, data governance, and confidentiality safeguards.
10. Elimination strategy. Eliminate answers that:
- ignore the risk because the technology is "new" or "managed by IT"
- have internal audit take operational ownership
- rely completely on management's or a vendor's assurance without evaluation
- delay assessment until a problem occurs
Then choose the answer that is proactive, risk-based, independent, and aligned with organizational objectives.
11. Watch the wording. Words like first, best, most important, and primary matter.
- The first step is usually to understand the technology, its objectives, and the related risks.
- The best response usually aligns assurance with strategy and risk.
12. Link to ERM and the Three Lines Model. Management (first line) owns the risks. Second-line functions (risk, compliance, information security) oversee them. Internal audit (third line) provides independent assurance and advice. Questions may test whether you can assign roles correctly.
Summary
Emerging technology risks must be built into a dynamic, risk-based internal audit plan. The CAE should:
- understand the organization's technology strategy
- update the audit universe
- assess risks using impact, likelihood, and velocity
- secure the necessary competencies
- balance advisory and assurance work while preserving independence
- use recognized frameworks
- coordinate with other assurance providers
- communicate clearly with the board
On the exam, favor answers that are proactive, governance-focused, independent, and adaptable.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!