To better understand how Internal audit (IA) functions are adapting, PwC surveyed IA leaders on their risk assessment practices and objectives in early 2026 across a variety of industries and geographies. The results reveal a profession in transition: IA functions recognize the need for more dynamic and responsive risk assessment processes, yet many have not yet fully embedded the capabilities required to make that shift.
Survey insights
The survey highlights five themes shaping the future of IA’s risk assessment: dynamic risk assessment inputs, stronger alignment with Enterprise Risk Management (ERM), more continuous audit planning, translating the risk assessment results to IA coverage, and incorporating the use of AI.
Dynamic risk assessment inputs
Most IA functions continue to rely heavily on traditional risk assessment inputs such as management interviews, prior audit results, and strategic plans. While these remain valuable, relatively few organizations have embedded forward-looking risk signals. At the same time, management’s view on risk and defined risk appetite and tolerances continue to remain foundational to an effective risk assessment.
25% use key risk indicators (KRIs) or key performance indicators (KPIs) as risk assessment inputs
16% refresh their risk assessment and audit plan quarterly or continuously
85% rely on management interviews as a primary input. The average effort and interview count for the risk assessment cycle is 50 interviews, taking approximately 225 hours
87% use external thought leadership and industry publications, demonstrating growing interest in outside-in risk perspectives
What great looks like
How to get there
Risk assessment inputs:
- Standardize core risk signals across ERM, incidents, strategy, performance, and external indicators
- Establish a common taxonomy to enable consistent trending and comparison
- Work with management to define risk appetite, tolerances and thresholds
- Link dynamic signals directly to the risk universe and audit plan
Risk assessment refresh:
- Shift from an annual assessment to, at minimum, a quarterly refresh
- Use trigger-based updates and dashboard monitoring for significant changes
- Clarify ownership for ongoing refreshes and escalation