top of page
Search

Risk in Focus 2026/27

Writer: Katarzyna  Celińska
Katarzyna Celińska
9 hours ago
2 min read

Recently I wrote about KPMG’s Compliance report. Now I have moved to Risk in Focus 2026/27, the internal audit view of the world and its risks.

 

Definitely worth reading. But I would not be myself if I did not find a few things that made me raise an eyebrow. Or even two. My questions are about the answers provided by CAEs and what they tell us about how InternalAudit perceives risk.


Photo: jcomp na Magnific

 

The results are familiar:

➡️ Cybersecurity — No. 1 at 86%

➡️ Digital disruption, new technology and AI — No. 2 at 52%

➡️ Macroeconomic and geopolitical uncertainty — No. 3 at 51%.

 

So far, so good. But then it gets more interesting.

1️⃣ Cybersecurity maturity — really?

Cybersecurity ranks 2nd out of 16 areas for risk-management maturity.

I find this result surprisingly optimistic. We are watching AI-assisted reconnaissance, automated attacks, faster exploitation, more convincing social engineering, supply-chain attacks and the rapid deployment of GenAI and agentic AI inside organisations.

The report itself says attacks are increasing in velocity and sophistication.

2️⃣ Climate change apparently took a 100-year holiday.

Climate Risk dropped to 10th place, selected by only 21% of CAEs.

Apparently climate change has decided to move backwards by at least a century.

Even the report itself notes that downgrading climate risk runs “against the logic of objective data”.

3️⃣ OperationalResilience as a separate “risk”

This one is conceptually difficult for me.

Operational resilience is the ability to continue, recover and adapt when something happens, e.g.: cyberattack, supply chain failure, geopolitical event, natural disaster, technology outage, or another disruption.

So are we really measuring a separate risk category here, or our ability to respond to many other risks?

4️⃣ Digital Disruption: one category to rule them all

Digital disruption includes AI, technology change, data breaches, regulatory impact, supplier concentration, business-model disruption and AI-human interaction.

Its maturity is ranked 16th, the lowest of all areas. At the same time, cyber is ranked 2nd for maturity and laws/regulation 7th.

So we have one category containing pieces of several other categories, and then we compare their maturity as if they were cleanly separated.

 

This leads me to my broader reflection.

I increasingly get the impression that CAE risk assessments follow mainstream narratives and current “hot topics” more than a deep analysis of causes, dependencies, scenarios and real organisational exposure.

 

My recommendation:

  • Read reports.

  • Use benchmarks.

  • Think independently.

  • Challenge assumptions.

  • Look for causal chains.

  • Look for hidden dependencies.





 
 
 

Comments


Stay in touch

ITGRC ADVISORY LTD. 

590 Kingston Road, London, 

United Kingdom, SW20 8DN

​company  number: 12435469

​

Privacy policy

  • Facebook
  • Twitter
  • LinkedIn
  • Instagram
bottom of page