Welcome to the 2027 edition of our annual report on the technology and digital risks shaping internal audit and risk agendas.
Technology risk is entering a new phase. Artificial Intelligence (AI) is becoming embedded across organisations; AI-enabled cyber threats are accelerating, and dependence on interconnected technology ecosystems continues to grow. For executives, the challenge in 2027 is not simply to adopt technology innovation, but to govern it confidently, protect critical operations and ensure assurance keeps pace.
Internal audit and risk functions face a critical imperative to adapt and prioritise. The regulatory landscape is characterised by a dynamic interplay of innovation, evolving risks, and increasing supervisory expectations. Technology risk and audit practitioners must proactively engage with these technology topics, moving beyond traditional compliance checks to provide assurance on the strategic management of these complex and interconnected risks. This requires a forward-looking approach, robust governance, and continuous adaptation to ensure firms can navigate this landscape effectively.
Our survey covered organisations across the UK and the US, providing a broader international perspective for 2027. Whilst it highlights a strong consensus around the most significant risks facing organisations, it also reveals subtle differences in priorities across jurisdictions. These insights provide valuable context for functions operating across global organisations, while reinforcing the importance of aligning assurance activities to local regulatory expectations, market dynamics and organisational objectives.
We hope this publication continues to drive meaningful discussions between internal audit, technology, risk and business leaders as they navigate an increasingly dynamic and technology-driven environment.
As always, we welcome ongoing dialogue and collaboration with technology and audit leaders on these critical topics, so please do not hesitate to contact us if you’d like to discuss any aspect of this report further.