Article

The board’s blind spot: When operational risk never reaches the audit committee

June 16, 2026

Key takeaways

Boards are now more engaged in risk oversight, but many risks still never reach the audit committee.

The speed of risk accelerates challenges, requiring a change in how risk is managed and governed.

The goal is not to eliminate risk, but to eliminate surprises before they become events.

#
Risk consulting Cybersecurity consulting

Boards are more engaged in risk oversight than ever before. Yet many of the most consequential risks still never reach the board’s audit committee in a meaningful way. Not because they are invisible—but because no one truly owns them. By changing the alignment of how risk is managed and governed, organizations can anticipate and address risk challenges before they affect operations.

Awareness is high. Clarity is not.

Global risk awareness is strong. According to the Institute of Internal Auditors’ Risk in Focus Global Survey—drawing on insights from more than 4,200 chief audit executives worldwide—cybersecurity, human capital and business continuity consistently rank as the top current risks across industries and geographies.

What remains inconsistent is not recognition of risk, but how risk is governed—how it is owned, escalated and translated into board-level judgment.

The result is a paradox many directors recognize well: growing volumes of risk reporting, paired with limited clarity about where true exposure sits and who is accountable for it.

Where risk gets lost

Many of today’s most consequential risks live between functions—between finance and IT, operations and compliance, or large-scale transformation initiatives and day-to-day execution.

Internal audit alignment typically highlights this challenge. Chief audit executives often have limited involvement in continuous monitoring of key processes—where cross-functional operational risks most often emerge—while many also lack insight into enterprise risk management activities. This limits the organization’s ability to aggregate and elevate risks that cut across silos.

These gaps are rarely the result of disengagement. More often, they reflect governance models built around functional ownership, while risk increasingly materializes horizontally—across systems, processes, geographies and third-party relationships.

Consider a large enterprise resource planning (ERP) system transformation: IT owns the implementation, finance owns reporting accuracy and operations owns the execution.

Yet no single executive owns the risk of controls potentially degrading across the transition. Each function assumes another is monitoring the exposure—until breakdowns surface in reporting, compliance or operations.

We consistently see this dynamic play out in large transformation programs—ERP implementations, outsourcing initiatives and artificial intelligence deployments—where ownership of risk is fragmented across IT, finance and operations. In these environments, risks are actively managed within functions—but rarely aggregated into a shared view of enterprise exposure or brought forward for integrated decision making.

The “someone else owns it” myth

A persistent governance blind spot is the assumption that if a risk does not clearly sit with one function, it must be covered elsewhere. For example:

  • Technology assumes finance will flag financial exposure
  • Finance assumes operations or IT has assessed broader control implications
  • Compliance assumes internal audit will identify systemic issues
  • Internal audit sees the risk—but without a clearly accountable executive owner, escalation stalls

Research from the Internal Audit Foundation continues to show that risks are becoming more interconnected and systemic, while accountability structures remain fragmented. When responsibility is diffused, escalation depends on individual judgment rather than governance design—and risks surface only after disruption forces attention, often after damage has already occurred.

This is less a failure of awareness than a failure of ownership and escalation.

In working with clients, we often find that simply clarifying executive ownership for cross-functional risks—through governance forums, escalation protocols and internal audit alignment—can materially improve decision speed and reduce late-stage surprises.

Audit committees are overloaded—not underengaged

Audit committees are deeply engaged in risk oversight. Survey data from the Center for Audit Quality indicates that 93% of audit committee members rank cybersecurity as a top three priority, with enterprise risk management close behind.

At the same time, nearly 80% in that survey believe internal audit could add more value, particularly through forward-looking insight and better integration across risks that span the organization.

Research from the National Association of Corporate Directors (NACD) reinforces this tension. Boards are spending more time on risk than ever before, yet often struggle to translate fragmented discussions into clear ownership, effective escalation and timely decision making.

The issue is not attention. It is that risk agendas are expanding faster than governance mechanisms are evolving.

Digital and operational risks are outrunning governance models

Risk speed only amplifies the challenge. NACD guidance highlights that boards now oversee a broader, more interconnected risk landscape—spanning cybersecurity, technology, third-party exposure and organizational change. As oversight responsibilities expand, many boards lack sufficient visibility into how risks are aggregated, prioritized and escalated across the enterprise.

Internal audit research reinforces this concern. The IIA’s Risk in Focus findings show that cybersecurity and digital disruption remain among the highest-ranked risks worldwide, yet internal audit leaders consistently report difficulty translating awareness into coordinated governance action, especially for cross-functional risks without a natural owner.

RSM’s 2026 Attack Vectors Report underscores that today’s cyber incidents are rarely detection failures. Instead, they stem from fragmented ownership, unclear escalation paths and limited board‑level visibility into how identity, AI and third‑party risks compound across the enterprise.

At the same time, regulatory expectations continue to rise. U.S. Securities and Exchange Commission cybersecurity disclosure requirements now require companies to describe board oversight, governance structures and management accountability—making visible to regulators and investors what may remain ambiguous internally.

In this environment, risks can become externally visible before internal governance is fully aligned to manage them.

In our experience, this is where governance breakdowns become most visible—not in isolated control failures, but in how risks compound across functions without a clear path to ownership or escalation.

The role internal audit can—and must—play

Internal audit occupies a unique position within the organization. It is one of the only functions designed to see how risk behaves across the enterprise. Yet in many organizations, it is still used to confirm compliance rather than inform governance decisions.

The IIA’s Global Internal Audit Standards explicitly define internal audit’s purpose as strengthening the organization’s ability to create, protect and sustain value through independent assurance, advice, insight and foresight to the board and management. Internal audit is most effective when empowered to look beyond isolated controls and assess how risks interact and accumulate.

Yet in many organizations, internal audit remains severely underutilized.

Elevating internal audit from “coverage” to “connection”

Closing the board’s risk blind spot requires internal audit to evolve from a function that validates controls to one that connects risk signals across the enterprise.

This does not mean internal audit should own risk, replace management judgment or become a second-line function. Independence and objectivity remain essential.

It does mean internal audit should be explicitly chartered and expected to:

  • Identify risks that cut across organizational boundaries
  • Highlight where accountability is unclear or fragmented
  • Elevate themes and patterns not visible within individual functions
  • Frame issues in terms of enterprise exposure, not just localized findings

NACD governance guidance is clear: boards need aggregated, connected insight to meet their oversight responsibilities in a complex risk environment. Internal audit is one of the few functions structurally positioned to provide that perspective.

Changing the perspective on risk

In our experience, leading organizations are not solving this challenge by adding more reporting—they are changing how risk moves through the organization.

We typically see three areas of focus:

Explicitly assigning executive ownership for cross-functional risks, particularly in transformation initiatives

Establishing structured escalation paths for risks that do not fit neatly within functional boundaries

Leveraging internal audit as a connector to aggregate risk themes and surface enterprise-level exposure to the board

What this looks like in practice

To elevate internal audit, organizations must adjust expectations, mandates and behaviors, not just dashboards.

1. Reframe the internal audit mandate

Audit committees should explicitly define internal audit’s role to include enterprise risk connectivity, not just assurance execution.

Action steps

  • Update the internal audit charter to include identification of cross-functional and systemic risk themes
  • Ask internal audit to report what it sees between audits, not only completed results
  • Reserve agenda time for risk themes and judgments—not just issue tracking

2. Use internal audit as an escalation mechanism, not a backstop

High-performing organizations use internal audit as an early warning system, not a checkpoint after decisions are made.

Action steps

  • Involve internal audit earlier in major initiatives (digital transformation, ERP, outsourcing, AI) as an independent challenger
  • Encourage management to surface unclear ownership and ask internal audit to assess the risk implications
  • Treat observations about governance gaps as design input, not criticism

3. Shift reporting from findings to exposure

Internal audit leadership plays a critical role in shaping how the function is perceived.

Action steps

  • Replace audit-centric language (“findings,” “deficiencies”) with business-centric language (“exposure,” “decision risk,” “resilience gaps”)
  • Aggregate issues across audits to illuminate systemic patterns, even when individual issues are immaterial
  • Call out where the organization relies on coordination or informal controls to manage material risks

What boards should expect from an elevated internal audit function

When internal audit is properly positioned, boards should reasonably expect answers to questions such as:

  • Which critical risks exist today without a clearly accountable executive owner?
  • Where do we rely on coordination across functions—and how confident are we that it works under stress?
  • What risks would not appear in our reporting until after an incident occurs?
  • Where do “green” indicators mask structural exposure?
  • What cross‑functional risks does internal audit see that do not fit neatly into management ownership models?

These are governance-level insights, not audit minutiae—and they align squarely with the NACD’s view of effective board oversight in complex environments.

The takeaway

The greatest risk to boards today is not lack of information—it is misplaced confidence in how well risk is governed. When accountability is unclear, risk doesn’t escalate—it compounds. Organizations that get this right don’t eliminate risk, they eliminate surprises—before they become events.

RSM contributors

  • Nicolas Falquez
    Director