What will technology risk audit teams focus on this cycle? A recent global survey of more than 200 internal audit leaders across 25 countries gives a double answer: the podium does not move, but the ground around it does — and faster every year.
The podium holds: cybersecurity, data and general controls
The three areas most frequently selected for upcoming audit cycles are cybersecurity, data governance and IT general controls (ITGC) — exactly the same as in the previous edition of the study, conducted in 2021. The reading is not inertia: foundational assurance over critical applications remains the base everything else is built on. Breaches keep rising, data underpins every business activity, and no AI adoption is more reliable than the controls over the data that feeds it.
What pushes from outside: AI, cloud, DevOps, OT
Around that stable core, the risk universe keeps widening. The areas entering the map with force: AI and machine learning audit, cloud governance, DevOps security, OT/IoT and expanding regulatory reporting. These are fast-changing risks, many external in origin, with little consolidated audit doctrine.
The uncomfortable number: only 42% of respondents rate their preparedness to audit emerging technology risks — cloud, AI, blockchain — as "excellent" or "good". And the most repeated concern is unknown unknowns: risks that are not even identified and therefore never make it into the plan.
The audit plan is no longer inherited from one year to the next: it is redesigned. The question is not whether the risk universe has changed, but whether the plan has changed at the same speed.
The regulatory agenda sets the calendar
On top of that internal map sits an external calendar that does not wait. In Europe, DORA has applied to the financial sector since January 2025 — with explicit requirements on ICT risk management, activity logging and third-party control — and the EU AI Act obligations for high-risk systems take effect on 2 August 2026. For many teams, the question "should we audit AI?" now has a regulatory answer.
Three practical implications
- The classics cannot be dropped. The temptation to shift ITGC hours toward emerging areas is real; the study suggests the opposite: foundational assurance is what makes everything new reliable.
- Emerging areas demand method, not heroics. Auditing AI or cloud without consolidated methodology requires explicit criteria, traceable evidence and defensible conclusions — more discipline, not less.
- The plan is a living artifact. A risk universe that shifts quarter by quarter cannot be managed with a static annual plan.
The study's conclusion is sober: the role of technology risk audit has never been more central — and it has never had this much ground to cover with the same team.