Skip to main content
Welcome to Deloitte
If we have selected the wrong experience for you, please change it above.

Hot topics for technology and digital risk 2027

Risk at the Speed of Change: An internal audit perspective


Welcome to the 2027 edition of our annual report on the technology and digital risks shaping internal audit and risk agendas.

Technology risk is entering a new phase. Artificial Intelligence (AI) is becoming embedded across organisations; AI-enabled cyber threats are accelerating, and dependence on interconnected technology ecosystems continues to grow. For executives, the challenge in 2027 is not simply to adopt technology innovation, but to govern it confidently, protect critical operations and ensure assurance keeps pace.

Internal audit and risk functions face a critical imperative to adapt and prioritise. The regulatory landscape is characterised by a dynamic interplay of innovation, evolving risks, and increasing supervisory expectations. Technology risk and audit practitioners must proactively engage with these technology topics, moving beyond traditional compliance checks to provide assurance on the strategic management of these complex and interconnected risks. This requires a forward-looking approach, robust governance, and continuous adaptation to ensure firms can navigate this landscape effectively.

Our survey covered organisations across the UK and the US, providing a broader international perspective for 2027. Whilst it highlights a strong consensus around the most significant risks facing organisations, it also reveals subtle differences in priorities across jurisdictions. These insights provide valuable context for functions operating across global organisations, while reinforcing the importance of aligning assurance activities to local regulatory expectations, market dynamics and organisational objectives.

Some highlights

  • Cyber security, Artificial Intelligence, Data and regulatory reporting, and Technology Transformation occupy the top four positions across all jurisdictions, demonstrating a strong consensus on the most pressing technology priorities. This reflects the continued focus on defending against cyber threats, governing the rapid adoption of AI technologies, managing increasingly complex data environments, and delivering technology-enabled transformation successfully.
  • Findings suggest that while organisations share a common set of technology risk concerns, local regulatory expectations, market dynamics and strategic priorities influence the relative importance placed on resilience, third-party management, cloud adoption and technology governance.
  • These differences reinforce the need for technology risk and internal audit plans of global (or US/UK organisations) to be tailored to the specific environments in which organisations operate, and indeed the specific legal entity risk and regulatory profiles (where applicable).
  • Finally, while the report underlines today's most pressing priorities, it also looks ahead to emerging technology developments that may shape the future risk landscape. By maintaining a forward-looking perspective, internal audit can help organisations anticipate change, strengthen resilience and remain well-positioned to seize the opportunities presented by new technologies.

We hope this publication continues to drive meaningful discussions between internal audit, technology, risk and business leaders as they navigate an increasingly dynamic and technology-driven environment.

As always, we welcome ongoing dialogue and collaboration with technology and audit leaders on these critical topics, so please do not hesitate to contact us if you’d like to discuss any aspect of this report further.

Download the report to learn more

Download the full report now to delve deeper into these critical topics and gain valuable insights into developing a robust and future-proof technology and digital internal audit plan. 

Did you find this useful?

Thanks for your feedback