Do internal audit teams have the capabilities to audit the technology their entire risk universe now depends on? A global survey of more than 200 internal audit leaders across 25 countries makes it possible to answer with data — and the answer is a qualified "not yet".

The size of the gap

Barely 1 in 10 respondents say that half or more of their team focuses on technology audits, in a context where 65% of surveyed organizations run internal audit functions of 25 people or fewer. Technology is in everything; the talent that audits it is not.

By domain, the contrast is sharp. In IT general controls, 94% of functions consider themselves skilled — the classic ground. In data privacy, 80%, pushed by years of GDPR. But on emerging ground the floor drops: cloud security 53%, DevOps 45% and — the study's most striking figure — artificial intelligence and machine learning: 11% of teams skilled today, with 89% planning to invest soon. It is the widest gap between present and future of any capability measured.

The AI gap is not a hole in the training plan: it is the distance between the speed at which the business adopts technology and the speed at which a 25-person function can learn to audit it.

The three ways out (and why none is enough alone)

Asked how they plan to close the gap, teams split their bets: upskilling (34%) and co-sourcing (32%) dominate, far ahead of recruiting specialists (18%) or fully outsourcing (16%).

The reason is economic as much as technical: a full-time specialist in one specific technology is expensive and underutilized most of the year. The emerging model is hybrid — train your own team on what is transversal, bring in external depth for the occasional deep dive, and never outsource judgment.

There is a third lever the study hints at: tooling. The same report notes that generative AI can summarize configurations and code into terms understandable by auditors without deep technical profiles. Put differently: part of the gap is not closed by lifting the auditor up to the technology, but by bringing the technology down to the auditor.

What a pragmatic team would do this year

  1. Map capabilities against the plan, not against an ideal: which audits in the current cycle demand which skills, and where the real gap is.
  2. Train for what repeats (cloud, data, automation) and co-source what appears once a year.
  3. Demand that tools multiply the existing team — so an auditor with judgment can review technical evidence without depending on a specialist for every configuration file.

The capability gap will not be closed by hiring: there is neither enough market nor budget to sustain it. It closes by combining people, partners and technology — with the auditor's judgment always kept in-house.