CRX | October 13-15, 2026 | Up to 17 CPEs | In-person & virtual options available | Register Now!

Customers
Login
Optro's logo

September 15, 2026 11 min read

Converging risks, competing priorities: Top takeaways from Risk in Focus – North America 2026/2027

Richard Chambers avatar

Richard Chambers

Risk is more volatile, complex, and interconnected than ever. The Internal Audit Foundation’s (IAF’s) Risk in Focus – North America 2026/2027 report, sponsored by Optro, vividly illustrates this new risk reality. Effective coverage is a perpetually moving target as new risks emerge, existing risks transform, and risk’s ripple effects cascade across supply and value chains.

As internal auditors strive to make effective use of increasingly limited risk resources, the truth we’ve always known comes into sharper focus: We can audit anything but not everything. We do our best to prioritize and strategize, but today’s audit plans cannot keep pace.

Risk in Focus reliably delivers vital insights. This year’s North America report is exceptional, revealing new dimensions of how internal auditors are squaring off with 2027’s risks. Risk’s interconnectedness complicates our view, with digital disruption a force multiplier across the risk landscape and rising AI risks displacing focus on other critical risks. At the same time, risk management maturity and audit coverage aren’t measuring up, leaving organizations vulnerable. Download your copy of Risk in Focus – North America 2026/2027 and read on for top takeaways.

1. Cybersecurity and digital disruption once again dominate the risk landscape

What do North American CAEs see as the top five risks facing their organizations in 2027? Cybersecurity held onto its top spot, cited by 85% of CAEs as a top-five risk, and #2-ranked “digital disruption (including AI)” experienced the largest increase of any risk (16%), landing in 69% of CAEs’ top-five risks. Four close competitors followed:

  • Human capital (45%), echoing ongoing economic volatility and AI’s job market impact
  • Geopolitical/macroeconomic uncertainty (43%), reflecting the Ukraine and Middle East conflicts, trade/tariff policy volatility, etc.
  • Regulatory change (42%), influenced by the current administration’s deregulation push (higher for public sector/nonprofits)
  • Market changes/competition (up 7% to 41%) reflecting growing concern about the business impacts of all of the above

Business resilience risk saw a 17-point drop, ranking in 29% of CAEs’ top-five risks. Does this suggest CAEs see this topic as less important for 2027? The likely answer is no — other risks are simply becoming more urgent. It could also be that respondents believe resilience is an outcome of effectively managing the other risks.

exhibit 1.2

2. Digital disruption is displacing other risks

Risk displacement has always been part of the story told by Risk in Focus: As some risks become more urgent, others by necessity recede in overall priority. As always, we must follow the risks. But displacement takes center stage in 2027, as digital disruption and cybersecurity absorb much of our focus. Of course, our other top risks haven’t budged. How can internal auditors cover all of it? We can’t.

Let’s turn back to business resilience, which appeared on organizations’ risk radar during the pandemic. Risk in Focus 2021’s new risk category “disasters and crisis response” (ultimately renamed “business resilience”) debuted in 34% of CAEs’ top fives globally. On first read, 2027’s 17-point drop could suggest organizations feel better prepared, having spent recent years shoring up. But business resilience risk hasn’t abated. When the 2026/2027 report compares top-five and “high risks” — repeatedly showing how lower-ranking risks haven’t actually dropped in severity — 29% of CAEs designated resilience a top-five risk and another 47% a “high risk.” As the report notes, the 17-point drop likely reflects “choice displacement” given heightened digital-disruption risk and resilience’s absorption into other high-ranked risks.

I call this out because it helps illuminate our central challenge amid permacrisis: As we turn our focus to emerging risks, what gets less focus? And how can we adapt to improve coverage? As I’ve repeatedly asserted, AI itself is central to helping us solve the very coverage problems it’s helping create.

3. Today’s risks are increasingly interconnected

The 2027 report reads like a case study in the converging, overlapping nature of risk. In particular, it highlights AI’s multiplying effect across risk domains:

  • Cybersecurity, enabling more sophisticated and automated attacks
  • Supply chain, now incorporating software risk
  • Third-party, with vendors passing digital disruption risk to clients
  • Human capital, given AI-driven concerns about job loss and training/upskilling
  • Fraud, given AI-enabled fraud schemes

As another example, geopolitical uncertainty risk remains high — but organizations also feel its impact on cybersecurity. The report quotes World Economic Forum data that over 60% of organizations say cybersecurity strategy must consider geopolitically motivated cyberattacks.

4. Risk governance maturity deserves increased focus

This year’s report places a new focus on risk governance maturity, “the extent to which risk management is embedded, formalized, and effective across the organization,” with the goal of understanding maturity and coverage in high-risk areas. I applaud the IAF’s efforts to spotlight this topic. After all, calling digital disruption a top-five risk and audit focus is one matter — and having the risk governance maturity to effectively assess and manage it is another.

Indeed, most CAEs report low risk governance maturity for digital disruption: Only 23% score their maturity as “managed” or “optimized” and 9% report audit coverage as adequate. Also ranking poorly: #4-ranked geopolitical/macroeconomic uncertainty, with 31% of CAEs reporting “managed” or "optimized" risk governance and 15% reporting adequate coverage. On the other side of the coin, financial/liquidity risk received the highest scores for both maturity (68%) and coverage (53%). However, while cybersecurity ranked fairly high for maturity (59%), only 35% of CAEs claim adequate coverage.

As Risk in Focus stresses, ideally, organizations could build mature risk governance for every significant risk. Clearly, internal audit’s shrinking resources and growing mandate don’t make this a simple proposition.

5. Risk priority and audit effort continue to be misaligned in key areas

First, some good news: Many CAEs increased focus on digital disruption, which saw the largest increase in audit priority (9%). Focus has more than doubled since 2023, from 25% to 53%. Further, fraud’s 7-point increase mirrors a very real uptick in fraud risk, and more than half of CAEs still call business resilience a top-five audit priority.

Unfortunately, several critical areas remain seemingly misaligned:

  • While 84% of CAEs prioritize cybersecurity as a top-five audit effort, their low confidence in audit coverage adequacy is noteworthy. They’re overwhelmed by the attack surface and underequipped by existing skillsets.
  • Geopolitical/macroeconomic uncertainty still receives less focus than its #4 rank warrants: Only 6% of CAEs call it a top-five audit priority. It’s important to note that geopolitical and macroeconomic events impact the enterprise in many ways, such as operational costs, sales/revenue, third-party risks, and so on. Increased focus on these second- and third-order effects is likely a reflection of the rising geopolitical and macroeconomic risks themselves.
  • Market changes/competition is a top-five audit priority for only 11% of CAEs. Inarguably, this risk is central to business success and resilience.
  • Culture receives less focus but shouldn’t be underestimated — especially given AI’s impact on roles and workplace values.
  • Audit plans still place disproportionate emphasis on regulatory change and corporate reporting compared to their risk rankings. Despite the clear need to establish internal auditors as strategic business partners, many internal auditors seem unwilling to give up their historical identity as finance and compliance auditors. These backward-looking assurance areas are exactly where AI is most likely to supplant us.

Risk in Focus – North America 2026/2027: Risk rankings compared to audit-effort prioritization

Risk

Risk Rank

Audit Priority

Rank to Priority Gap

Cybersecurity

#1 (85%)

#1 (84%)

-1%

Digital disruption (including AI)

#2 (69%)

#3 (53%)

-15%

Human capital

#3 (45%)

#9 (20%)

-25%

Geopolitical/macroeconomic uncertainty

#4 (43%)

#15 (6%)

-37%

Regulatory change

#5 (42%)

#2 (54%)

12%

Market changes/competition

#6 (41%)

#13 (11%)

-30%

Supply chain (including third parties

#7 (33%)

#8 (34%)

1%

Business resilience

#8 (29%)

#4 (51%)

22%

Financial/liquidity

#9 (24%)

#6 (46%)

22%

Fraud

#10 (18%)

#7 (35%)

17%

Expect the unexpected — plan for disruption and stay agile

As we enter the home stretch of the 2020s, the 2027 risk outlook shouldn’t surprise anyone. The entire decade has been characterized by volatility and disruption as we collectively navigate an era of permacrisis.

If the decade has taught us anything, it is to expect the unexpected. 2027 is already shaping up to be another challenging year, and we don’t know what surprises lie beyond the horizon. Get ready, buckle up, and stay flexible. Just as the risk landscape keeps reshaping itself, so must internal audit reshape itself into the strategic partner organizations urgently need.

About the authors

Richard Chambers avatar

Richard Chambers, CIA, CRMA, CFE, CGAP, is the CEO of Richard F. Chambers & Associates, a global advisory firm for internal audit professionals, and also serves as Senior Advisor, Risk and Audit at Optro. Previously, he served for over a decade as the president and CEO of The Institute of Internal Auditors (IIA). Connect with Richard on LinkedIn.

You may also like to read

helvetia spotlight on success
Internal Audit

How Helvetia Baloise gave internal audit room to focus on risk

LEARN MORE
reflective light
Internal Audit

The agentic audit era: What CAEs must rethink now

LEARN MORE
colleagues looking at a laptop
Internal Audit

Agentic AI in internal audit: which controls should you automate first?

LEARN MORE

Discover why industry leaders choose Optro

SCHEDULE A DEMO
upward trending chart
confident business professional
Converging risks, competing priorities: Top takeaways from Risk in Focus – North America 2026/2027