Risk assessment, reimagined

Hero Image
  • August 17, 2026

Moving from annual planning to dynamic, data-driven risk coverage

Key takeaways:

  • Annual risk assessments are no longer sufficient for today's rapidly changing risk environment; leading internal audit (IA) functions are moving toward a dynamic, data-driven risk assessment.
  • Five capabilities distinguish more mature risk assessment programs: dynamic risk inputs, stronger ERM alignment, continuous audit planning, clearer translation of risk into audit coverage, and AI-enabled risk sensing.
  • Most organizations recognize the need to modernize, but relatively few have embedded continuous monitoring, trigger-based planning, or AI into their risk assessment process.
  • Practical near-term and long-term actions can help IA internal audit functions build a more responsive, risk-based audit planning process.

Internal audit's risk assessment has long served as the foundation for audit planning. But as organizations navigate accelerating technology transformation, evolving regulations, geopolitical uncertainty, and changing business models, many are finding that an annual risk assessment is no longer enough. To understand how leading IA functions are adapting, PwC surveyed IA leaders in early 2026. The findings highlight five capabilities that are helping organizations build more dynamic, data-driven risk assessment and audit planning processes.

Many IA functions continue to rely heavily on traditional risk assessment inputs such as management interviews, prior audit results, and strategic plans. While these remain valuable, relatively few organizations have embedded forward-looking risk signals. At the same time, management’s view on risk, defined risk appetite and tolerances continue to remain foundational to an effective risk assessment.

ERM is widely referenced during IA planning, yet formal alignment between enterprise risks and IA coverage may remain limited and sometimes occurs after the fact. Without clear mapping between enterprise risks, audit themes, and audit coverage, organizations may struggle to demonstrate IA’s alignment to strategic priorities, identify coverage gaps, or explain audit plan changes as risks evolve.

Many IA functions have introduced more frequent discussions around risk, yet audit plan changes continue to be driven primarily by major events rather than predefined risk triggers. The shift from annual planning to dynamic planning is underway, but most IA functions remain event-driven rather than indicator-driven.

While organizations are collecting more risk information than ever before, many IA functions struggle to articulate how their audit plans address the organization's most significant risks. As risk assessments become increasingly dynamic and audit plans evolve, communicating the rationale for audit decisions, demonstrating risk coverage, and reinforcing the value of the audit plan become just as important as the assessment process itself.

AI is beginning to reshape the IA risk assessment process, though adoption remains concentrated in foundational use cases. Over time, AI's greatest value may come from its ability to continuously synthesize large volumes of internal and external data, helping IA identify emerging risks, monitor changing conditions, and focus resources where they’re needed most.

Practical ways to modernize the risk assessment process

Explore the survey findings, maturity models, and implementation guidance

Contact us

Amanda Herron

Amanda Herron

Partner, US Internal Audit Leader, PwC US

Sean Torcasi

Sean Torcasi

Partner, Risk and Regulatory, PwC US

Follow us