COSO ERM is built around five components:
- Governance and culture
- Strategy and objective-setting
- Performance
- Review and revision
- Information, communication, and reporting
Internal audit often uses COSO ERM as an operational risk management framework to determine if an organization’s risk management efforts align with its strategy and whether risk information flows properly to leadership.
Internal audit’s role in operational risk management
Internal audit plays a critical role as the independent assurance provider within the organization’s governance model. By offering objective insights and advice, auditors assess the effectiveness of operational risk management (ORM) practices and support continuous improvement in risk oversight.
Evaluating the operational risk management framework
The first step for internal audit is to determine whether the organization has established a formal ORM framework that aligns with its strategic objectives, regulatory requirements, and industry standards. This evaluation involves reviewing how the organization identifies, assesses, and responds to risks. Auditors examine the methodologies used for risk identification, the criteria applied in risk assessments, and the quality of documentation around risk responses. Additionally, they review the use of Key Risk Indicators (KRIs), the protocols for risk reporting and escalation, and the assignment of roles and responsibilities for risk ownership.
Testing operational controls
Internal auditors are often most experienced in evaluating the design and effectiveness of internal controls. In this phase, auditors review process documentation, conduct walkthroughs, and perform control testing to determine if key operational controls are functioning as intended. They identify control gaps or inefficiencies and provide recommendations to enhance the control environment.
Assessing risk culture and governance
A healthy risk culture influences effective operational risk management. Internal audit assesses the organization’s risk culture by analyzing the tone at the top, employee awareness and training efforts, the escalation process for risk issues, and management’s responsiveness to identified risks. A robust risk culture supports better decision-making and risk ownership throughout the organization.
Validating risk assessments
Internal audit reviews how risk assessments are conducted across the organization and challenges underlying assumptions when necessary. This includes verifying the documentation related to risk assessments for consistency and justification of risk ratings, ensuring that emerging risks are incorporated, and confirming that risk appetite and tolerance thresholds are clearly defined and followed. These validations help align risk assessments with actual business exposures.
Advising on operational risk strategies
While maintaining independence, internal audit can provide proactive advisory support to strengthen operational risk strategies. Auditors may participate in risk management working groups, offer input into the design of risk reporting structures, and provide insight on emerging risks. These contributions can help improve the maturity and responsiveness of the organization's risk posture.
Challenges internal audit face in operational risk management
Operational risk management spans a broad spectrum of topics, which presents several challenges for internal audit. One key issue is the rapid evolution of risk, particularly in areas driven by technology such as artificial intelligence or blockchain, where the pace of change can outstrip traditional audit approaches. Additionally, limited resources mean auditors cannot be subject matter experts in every area. Striking a balance between offering advisory support and maintaining independence is also difficult. Lastly, collecting reliable and comprehensive risk data remains an ongoing hurdle, as information is often fragmented or incomplete.
To address these challenges, many internal audit teams are investing in upskilling, leveraging data analytics, and building closer, yet independent, working relationships with their risk management counterparts. Establishing stronger relationships outside of an audit creates a more open and understanding partnership. These efforts are essential for ensuring that internal audit remains a relevant and strategic partner in operational risk oversight.
Where is internal audit headed?
The role of internal audit in operational risk management isn’t static — it’s growing and changing quickly. Some trends shaping the future include:
- Dealing with emerging tech risks like AI and SaaS vulnerabilities
- Facing greater regulatory scrutiny, especially in critical industries
- Moving toward integrated risk management that connects operational, strategic, and compliance risks
- Adopting agile auditing to stay flexible and responsive
Audit teams that embrace these changes while staying true to their assurance roots will help their organizations thrive in uncertain times.
Internal audit as a strategic ally in ORM
Operational risks are not going away. In fact, they are getting more complex. Companies can manage them well with strong frameworks, clear leadership, and smart assurance efforts. Internal audit isn’t just about catching mistakes. It’s about ensuring risk management efforts work, helping companies avoid costly disasters, and turning effective risk management into a competitive edge. In a world where disruption is commonplace, having internal audit as a strategic partner in operational risk management is not just beneficial—it’s a strategic advantage.