Internal auditors are facing a host of risks during the COVID-19 pandemic in business continuity, crisis management, cybersecurity and other areas, according to a new report.
The report, released Monday by the Institute of Internal Auditors, follows up on a similar report released last year, and discusses the top 11 risks facing organizations. For the report, the IIA surveyed members of corporate boards, executive management teams and chief audit executives.
The report found that 93 percent of CAEs rated business continuity/crisis management as highly or extremely relevant, compared to 87 percent of board members who ranked those risks as highly or extremely relevant. Far fewer members of the C-suite identified them that way, with only 63 percent describing business continuity/crisis management as highly or extremely relevant. Members of corporate boards and C-suites who responded to the survey rated their level of personal knowledge lowest when it comes to cybersecurity.
Prof. Johnson is the Ronald A. Kurtz (1954) Professor of Entrepreneurship at the MIT Sloan School of Management. He is also a senior fellow at the Peterson Institute for International Economics in Washington, D.C., a co-founder of BaselineScenario.com (a much cited website on the global economy), a member of the Congressional Budget Office's Panel of Economic Advisers, and a member of the FDIC's Systemic Resolution Advisory Committee. He is also a member of the private sector systemic risk council founded and chaired by Sheila Bair in 2012. Prof. Johnson is a weekly contributor to NYT.com's Economix, is a regular Bloomberg columnist, has a monthly article with Project Syndicate that runs in publications around the world, and has published high impact opinion pieces recently in The Washington Post, The Wall Street Journal, The Atlantic, The New Republic, BusinessWeek and The Financial Times, among other places. In January 2010, he joined The Huffington Post as contributing business editor. Professor Johnson is the co-author, with James Kwak, of 13 Bankers: The Wall Street Takeover and The Next Financial Meltdown, a bestselling assessment of the dangers now posed by the U.S. financial sector (published March 2010) and White House Burning: The Founding Fathers, Our National Debt and Why it Matters to You (April 2012). In his roles as a professor, research fellow and author, Professor Johnson's speaking engagements include paid appearances before various business groups, including financial institutions and other companies, as well before other groups that may have a political agenda. He is not on the board of any company, does not currently serve as a consultant to anyone, and does not work as an expert witness or conduct sponsored research. His investment portfolio comprises cash and broadly diversified mutual funds; he does not trade stocks, bonds, derivatives or other financial products actively. From March 2007 through the end of August 2008, Prof. Johnson was the International Monetary Fund's Economic Counselor (chief economist) and Director of its Research Department. He is a co-director of the NBER Africa Project, and works with nonprofits and think tanks around the world. Johnson holds a B.A. in economics and politics from the University of Oxford, an M.A. in economics from the University of Manchester, and a Ph.D. in economics from MIT. He won the Nobel Prize in Economics in 2024.
Johnny Poulsen is the CEO of Income Lab, a company that wants to revolutionize the way retirement is planned and experienced.
With over two decades of experience in financial services, Poulsen co-founded Income Lab to equip advisors with better tools to help clients retire with clarity and confidence.
Sam Krishnamurthy is the Chief Technology Officer for Turvi.
Other risks discussed in the report include sustainability, disruptive innovation, economic and political volatility, third-party risks, board information, data governance, talent management, and culture.
“This is the second year we’ve done this survey,” said IIA president and CEO Richard Chambers. “The most revealing headline was that boards thought their organization was in a lot better position to address risk than management. That’s a little bit unsettling.”
This year, the COVID-19 pandemic exposed risks to business continuity and crisis management in particular. “The most revealing insight was that COVID and the aftermath is front and center in how management, boards and auditors are seeing risks in their organizations,” said Chambers. “Business continuity and crisis management are very high on their list of the key risks. Two years don’t make a trend, but it doesn't surprise me that there is closer alignment between management and auditors on the risks their companies are facing. When everybody is focusing on a looming storm, you’re more apt to have agreement. From that standpoint, COVID and the crisis we’re facing with the pandemic has allowed for management and auditors to see risks in much the same way.”
Talent management and innovation are seen as big risks by management. “Management has insights into the risks they face, but I also recognize that management isn’t always forthcoming about the risks they face because it could be a reflection on how well they’re managing,” said Chambers. “You can’t always get a candid assessment.”
That’s why it’s especially important for internal auditors to keep corporate boards informed about such risks. “I’ve always been one who believes that internal auditors can be the eyes and ears for the board when they’re not around,” said Chambers.
Cybersecurity has become even more of a risk for many companies with so many of their employees now working from home, with access to corporate systems available around the clock and few eyes watching other workers in their remote offices. Cybercriminals can also take advantage of the remote access if it’s not secured.
“When the workforce is distributed, people are working from home, and people are not as careful with the data they are sharing,” said Chambers. Cybersecurity also ranked high in last year’s survey, but he sees a clear correlation between COVID-19 and why cybersecurity risks are seen as even higher this year.
The IIA issued the report at a time when many internal audit teams are making their audit plans for next year. “We think it will be very revealing to them and a good source of information as they look at their own risks in their companies,” said Chambers.


