Skip to main content
Welcome to Deloitte
If we have selected the wrong experience for you, please change it above.

Financial Services | Internal audit planning priorities 2027

Building continuous trust and the evolution of the Three Lines for an AI-enabled future

Welcome to Deloitte’s Financial Services planning priorities for internal audit for 2025.

As we launch the 10th edition of this publication, we recognise the pivotal role internal audit continues to play. Internal audit is the backbone supporting organisations on their journey forward, acting as a strategic partner and providing insight and innovation for organisations to thrive today and in the future.

The Financial Services landscape in 2024 continues to be driven by increasing regulation, which is impacting many firms’ cost-base due to the need for more robust and well controlled processes. This is compounded by wider economic volatility stemming from ongoing global conflicts, a higher interest rate environment and elections taking place across 70 countries worldwide, including in the UK.

Despite the uncertainty this brings, the role of internal audit as a strategic partner remains unchanged, and many of the key topics for functions to consider today are common with those highlighted in the first edition of this publication in 2014, including model risk management, third party risk management and financial crime. This is perhaps unsurprising given that regulatory focus remain largely the same, centred on prudential stability, good customer outcomes and the reduction and prevention of financial crime.

Whilst similarities remain, internal audit functions must continue to evolve to keep pace with change, not just in terms of what they audit but how they audit. Generative AI (GenAI) in particular presents huge opportunities with a significant increase in the number of use cases emerging across the last 12 months, both in terms of how firms use GenAI, as well as how functions can benefit from it.

For the second year, we have a section dedicated to environmental, social, and governance (ESG). With notable increases in the quantity, quality and breadth of reporting and disclosures due over this and coming years, driven by regulations such as the Corporate Sustainability Reporting Directive (CSRD), ESG continues to be a focus area. Regulation aside, firms should be mindful of the strategic decisions required to effect change as well as report accurately.

The focus on financial crime, conduct risk and digital risk continues. There are also a number of new focus areas to consider including in annual audit plans. An increase in the volume and quantity of financial penalties resulting from failures to correctly identify off-payroll workers has brought employment taxes into focus. Regulators are also focusing on motor finance discretionary commission, which has also been included.

Navigate to the sectors below most relevant to you and your organisation for an overview and suggested actions on a range of priorities for 2025. These are intended to provide a useful reference point from which to drive conversations and ultimately help define internal audit plans.

We hope you find the topics useful and if you would like to discuss anything further, please get in touch.

 

Welcome to Deloitte’s Financial Services Internal Audit Planning Priorities 2027

Now in its 12th year, Deloitte’s Financial Services Internal Audit Planning Priorities report explores the issues that should be front of mind as firms shape their internal audit plans for the year ahead. The financial services landscape continues to be shaped by uncertainty, rapid technological change and evolving expectations from regulators, customers and wider society. For 2027, two areas stand out: the enterprise-wide adoption of AI across financial services, and the evolution of assurance across the Three Lines of Defence.

AI at Scale: From Experimentation to Enterprise Impact

AI is moving fast from pilots to enterprise-scale adoption, changing how financial services firms make decisions, serve customers, manage risk and run controls. The opportunity is significant, but so is the pace of risk.

As AI becomes more autonomous and embedded, firms need clear accountability, strong oversight, reliable data and model controls, resilient technology and explainable customer outcomes. In 2027, internal audit should treat AI as a strategic assurance priority: testing whether governance works in practice, material use cases are controlled, and the organisation has the skills to keep pace with the next wave of AI transformation.

Assurance Rewired: Rethinking the Three Lines of Defence

Automation, AI-enabled decisions and autonomous processes are reshaping the Three Lines of Defence. As controls become embedded into workflows, assurance is shifting from periodic review to continuous confidence in how systems operate.

This creates a chance to build trust at source, using real-time monitoring, automated controls and data-led validation to manage risk earlier and more proactively. For internal audit, the focus must move beyond point-in-time control testing to whether the wider assurance system can be relied upon.

With the First Line generating assurance through daily operations and the Second Line setting the standards and guardrails, Internal Audit needs to provide independent confidence that the overall control environment is effective, joined up and responsive to emerging risk.

Download the full report now.

Did you find this useful?

Thanks for your feedback