This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Good morning {{name}},

I’m Tim Buckley, and this is the weekly Beyond the Lines™ newsletter.

Beyond the Lines™ is an internal-audit-led platform for people working across audit, risk, controls, governance and culture who want to turn insight into better decisions, clearer ownership and stronger outcomes in a Human + AI world.

Less control theatre. More decisions, ownership and outcomes.

Over the last week, a lot of new subscribers have joined Beyond the Lines™, which I’m very excited about. Many of which replied to the welcome email with the biggest audit, risk and control challenges they are facing right now.

The replies were not theoretical. They were practical, specific and grounded in real operating problems.

One person talked about the risk of not being heard meaningfully by management. Another raised business ownership of risk and controls. Another pointed to controls that exist mainly to create audit evidence. Others raised leadership buy-in, immature ERM, siloed working, governance, resources, learning, auditing and organisations preparing to pass audits rather than building real resilience.

Individually, those sound like different problems.

Together, they point to something bigger.

Many organisations are better at handling audit activity than using audit insight.

They can process findings, assign actions, produce evidence, update trackers and prepare for reviews. But that does not always mean the risk has reduced, the owner has changed behaviour, the control has become stronger or the organisation is more resilient.

That is the theme of this week’s issue.

Not a Q&A. Not an inbox dump. A market-pulse edition built from real subscriber replies on where good audit, risk and control work breaks down after the formal process has started.

Because the difficult question is not always, “Did audit identify the issue?”

Very often, the more useful question is:

Did the organisation do anything meaningful with it?

The subscriber replies every audit leader should read

There is a pattern in the replies I received this week.

It is not simply that audit teams want more attention, better reporting or cleaner stakeholder communication. Those things matter, but they are not the whole issue.

The deeper problem is that assurance activity can look complete while the business remains unchanged.

A finding can be accepted without being properly absorbed. A control can be evidenced without being effective. A management action can be closed without the cause being addressed. A risk can be owned in theory while the practical accountability is still unclear. A business continuity control can pass review while the organisation remains unprepared for stress.

That is the gap this issue is about.

The gap between assurance process and operating reality.

The pass-the-audit mindset

One of the strongest subscriber replies described organisations preparing to pass audits and checklists without real preparations or resilience underneath.

That line is worth taking seriously.

A business can be audit-ready and still fragile.

The documentation can be prepared. The folder can be complete. The checklist can be updated. The evidence can be available. The sample can pass. The owner can explain the process confidently.

But if the real event happened tomorrow, would the organisation hold?

That is the difference between audit preparedness and operational resilience.

Audit preparedness is about surviving scrutiny. Resilience is about surviving stress.

This is especially obvious in areas such as business continuity, cyber, third-party risk, operational resilience, regulatory change and crisis response. But the same principle applies across many control environments.

A business continuity plan is not strong because it exists. It is strong because assumptions have been tested, dependencies are understood, people know what to do under pressure, escalation routes are clear, decisions can be made quickly and the organisation has practised enough to expose weaknesses before a real event does.

If a control only works when the business is preparing for audit, it is not a reliable control.

It is a rehearsed answer.

That is where internal audit can add real value. Not by rewarding the organisation for producing evidence, but by asking whether the control, process or plan would still work when the situation is messy, time-pressured and real.

How siloed working creates invisible risk

One subscriber asked how to choose audit topics that show top management how siloed working creates risks, especially when Enterprise Risk Management is still immature or new.

That is a strong audit planning question, and it matters because silo risk is often difficult to see through standard audit planning.

It rarely sits neatly inside one function. It shows up in handoffs, assumptions, duplicated controls, unclear decision rights, conflicting priorities and local decisions that create enterprise-level consequences.

When ERM is immature, the problem becomes harder. Risk registers may be functional rather than connected. Risk descriptions may be broad. Owners may be assigned based on department rather than actual accountability. Controls may be tested individually, even though the real exposure sits in how activities connect.

In that environment, internal audit can add value by auditing the seams.

That means choosing topics that force the organisation to show how work moves across teams. Third-party onboarding is a good example because it often involves procurement, legal, cyber, finance, operations and risk. Incident response is another because it tests escalation, communication, ownership and decision rights under pressure. Business continuity shows whether plans, dependencies and responsibilities work across functions rather than just within them.

Regulatory change, transformation programmes, customer complaints, data quality in reporting and AI deployment can also reveal silo risk because they cut across functions, systems and decisions.

The point is not to audit the organisation chart.

The point is to audit the flow of work.

That is where silo risk usually lives.

Governance and resources are not side issues

One subscriber raised a challenge around governance, resources, human and learning capability, and internal and external auditing.

That point matters because it is easy to treat these as separate issues.

Governance sits in one conversation. Resourcing sits in another. Learning and capability sit somewhere else. Internal and external audit become periodic review mechanisms rather than part of the operating system.

In real organisations, those things are connected.

Weak governance can create unclear decisions. Poor resourcing can make controls impossible to operate properly. Lack of learning can mean people follow procedures without understanding the risk behind them. External audit can focus attention on financial reporting requirements, while internal audit sees broader operational, cultural and control weaknesses that need management ownership.

The issue is not whether each component exists.

The issue is whether they work together.

A governance structure that does not clarify accountability will not fix a control problem. A control that depends on people having time, training and judgement will not work if the resource model makes that unrealistic. An audit plan that does not consider capability, ownership and operating pressure may identify symptoms without explaining why they keep returning.

This is where internal audit can be valuable without becoming management.

It can show how governance, resources, capability and controls interact. It can highlight where the formal design of the system does not match the practical conditions in which people are expected to operate. It can help the board and senior management see whether the organisation is genuinely equipped to manage the risks it says it owns.

That’s not soft work. It’s core assurance work.

Ownership gets diluted between the lines

Another subscriber put the issue in six words:

“Business ownership of risk and controls.”

That short phrase carries a lot of weight.

Most organisations say the business owns risk. Far fewer operate in a way that proves it.

In practice, ownership often gets diluted between functions. Management owns the process, but not always the control failure. Risk owns the framework, but not always the decision. Compliance owns the requirement, but not always the behaviour. Audit owns the finding, but never the fix.

That distinction matters.

Internal audit can assess, advise, challenge, escalate and provide assurance. But it should not become the owner of management’s problem. When that boundary gets blurred, the organisation can start to rely on audit pressure as a substitute for business accountability.

That is how action trackers create false comfort.

There is an owner, a due date, a status update and a comment. Governance can see progress. Audit can show follow-up. The issue appears to be under control.

But the real ownership question may still be unanswered.

Who has the authority to change the process? Who owns the consequence if nothing changes? Who is accountable for making the control work in real business conditions? Who would still care about the issue if audit stopped chasing it?

That last question is one of the most useful tests.

If audit stopped chasing this tomorrow, would management still care?

If the answer is no, the organisation may not have business ownership. It may have compliance with the audit process.

Real ownership is not a name beside an action. It is consequence, authority, proximity and follow-through.

The business owns the risk when it understands the issue, has the authority to address the cause, feels the consequence of inaction and is expected by leadership to fix the weakness properly rather than simply close the audit point.

Anything less is borrowed ownership.

A quick side note …

The next Beyond the Lines™ live session is this week. Thursday 28th May, 12.30pm BST.

It’s our second in the Leadership Signals mini-series, and I’ll be joined by Rania Bejjani, CEO & Founder of RB Advisory & Consultancy | Governance, Internal Audit & Risk Management to discuss:

Influence without authority: how audit and risk actually get decisions made

I’d love for you to join us as we get into all things influence. Not influence in the soft, networking sense, but the practical ability to make audit insight land with people who are busy, defensive, distracted or not yet convinced.

See you there.

Why leadership buy-in fails

Another subscriber raised leadership buy-in and made an important point about audit actions being designed around work, rather than focused on cause.

That is a common pattern.

When leadership buy-in is weak, management actions often become low-friction commitments. They are designed to get through the audit process, reduce escalation and show progress. They are not always designed to fix the reason the issue happened.

The action becomes more training, more communication, a refreshed procedure, a new checklist, an extra review or a reminder to the team. None of those actions are automatically wrong. Sometimes they are exactly what is needed.

But they are also some of the easiest actions to write when the real cause is harder to face.

The real cause might be unclear decision rights. It might be unrealistic capacity. It might be poor system design. It might be leadership tolerance of weak behaviour. It might be competing incentives. It might be a process that only works on paper. It might be a control that cannot operate properly under normal business pressure.

Root cause work becomes uncomfortable because it often moves the issue away from the visible failure and towards the system that made the failure likely.

That can create resistance.

So the action becomes smaller. Safer. Easier to accept. Easier to track. Easier to close.

And weaker.

This is where internal audit needs to be careful. A closed action is not the same as a solved problem. A management response is not the same as management ownership. A revised procedure is not the same as a changed operating reality.

If the action does not address why the issue happened, audit may have helped the organisation tidy the symptom rather than reduce the risk.

Controls built for evidence, not protection

Another subscriber described a problem that many audit and controls professionals will recognise immediately: controls that exist for the sake of evidence creation during audits.

That is uncomfortable because it cuts to the heart of a weak control environment.

The evidence exists. The review has been signed off. The spreadsheet has been updated. The checklist has been completed. The control can be shown to audit. The sample can be tested.

But the risk is not necessarily reduced.

This is how organisations become control-heavy without becoming well controlled. They accumulate activity, evidence and review points, but the control logic becomes weaker over time. People perform the control because it is expected. They save evidence because audit will ask for it. They complete the checklist because the checklist exists.

The control becomes a performance of control, not a mechanism of protection.

Evidence matters. Auditability matters. Documentation matters. But none of those are the purpose of a control.

A useful control should prevent something from going wrong, detect an issue early enough to act, escalate the right information, force a better decision or reduce the likelihood or impact of a real risk. If it does none of those things, but creates neat evidence, the organisation may have built an audit artefact rather than a control.

That is why audit and controls leaders need to challenge the order of the questions.

The first question should not be, “Can we evidence this?”

The first question should be, “What is this control protecting?” Or, in more direct terms, “What risk is it mitigating?”

Only after that should we ask what evidence proves it worked.

There is a big difference between evidence that proves activity happened and evidence that proves a control reduced risk.

What these problems have in common

The subscriber replies touched on different areas: governance, management buy-in, ownership, controls, ERM, silo risk, resources, learning, auditing and resilience.

But underneath the individual comments is a consistent pattern.

Good audit work gets stuck when organisations are better at demonstrating activity than changing reality.

They can show that the finding was accepted. They can show that the action was assigned. They can show that the control operated. They can show that the risk register was updated. They can show that the audit was passed.

But the deeper question is whether anything meaningful changed.

Did the control reduce risk? Did management fix the cause? Did ownership become clearer? Did the handoff improve? Did governance support a decision? Did people understand what they were doing and why? Did the organisation become more resilient?

That is where the real value sits.

And it is also where audit value often leaks.

A Reality Test for audit work

If audit work is not landing, do not only ask whether the report was clear enough. That may be part of the issue, but it is rarely the whole issue.

Start by asking whether the work has survived contact with operating reality.

First, test the control. Does it reduce risk under normal business conditions, or does it mainly create evidence for review? A control should help prevent, detect, escalate, decide or protect. If its main value is audit evidence, it may need redesigning.

Second, test the action. Does it address the cause, or does it simply create a manageable response? If the action is mainly training, reminders, re-communication or another checklist, it may be worth challenging whether the root cause has been avoided.

Third, test the owner. Does the named owner have authority to change the process, resource, behaviour or decision rights causing the weakness? If not, ownership may be weaker than the tracker suggests.

Fourth, test the handoff. Does the risk move across teams, systems, processes or governance forums? If it does, the audit should examine where ownership, information or decision-making breaks down between functions.

Fifth, test the stress point. Would the process, control or plan still work under pressure? If it only works when the business is preparing for audit, it may be audit-ready but not business-ready.

Finally, test the governance route. Does the issue reach the right forum in a way that supports a decision, or does it simply become another update? Governance should clarify accountability and action, not just record that something was discussed.

This diagnostic is not about making audit more complicated. It is about making audit more useful when the issue is not lack of activity, but lack of real-world movement.

Do this Monday

Pick one audit issue, one management action and one control that currently feels stuck.

For the audit issue, ask whether the organisation has treated it as an operating problem or merely as an audit item. If the issue only exists inside the audit report, it may not yet be connected to the part of the business that needs to change.

For the management action, ask whether it addresses the cause or simply creates a response that is easy to accept, track and close. If the action would not stop the issue happening again, it is probably weaker than it looks.

For the control, ask what it is protecting. If the strongest answer is that it creates evidence for audit, then the control may be consuming effort without reducing enough risk.

Then ask one final question:

Would this still work if audit was not watching?

That question can be uncomfortable.

It is also useful.

You do not need to redesign the whole audit function in one week. Start by finding one place where good audit work is being processed but not absorbed, and make that visible.

That is often enough to change the conversation.

Closing thought

The subscriber replies this week were useful because they were grounded in real work.

They were not asking for more theory. They were pointing to the places where audit, risk and controls break down in practice: evidence-led controls, weak resilience, unclear ownership, leadership buy-in, immature ERM, siloed working, governance, resources and capability.

That is the space internal audit leaders need to operate in.

  • Not just producing better findings, but understanding why good findings do not always move the business.

  • Not just testing whether controls exist, but whether they protect.

  • Not just tracking whether actions close, but whether causes change.

  • Not just confirming the process has been followed, but asking whether the organisation is stronger because of it.

That is where audit becomes more commercially relevant. That is where board trust is built. And that is where Beyond the Lines™ will keep focusing.

Less control theatre. More decisions, ownership and outcomes.

Best,

Useful links

Access the free Internal Audit Value Leakage Map
In the context of this week’s theme, the map helps answer a simple question: Where is good audit work being processed, but not absorbed?

Register for the next Beyond the Lines™ Leadership Signals session
Influence without authority: how audit and risk actually get decisions made. This week, Thursday 28th May, 12.30pm BST.

Share Beyond the Lines with a colleague
If this helped you think differently about internal audit leadership, forward it to one audit, risk or controls colleague who would value it.

The ops hire that onboards in 30 seconds.

Viktor is an AI coworker that lives in Slack, right where your team already works.

Message Viktor like a teammate: "pull last quarter's revenue by channel," or "build a dashboard for our board meeting."

Viktor connects to your tools, does the work, and delivers the actual report, spreadsheet, or dashboard. Not a summary. The real thing.

There’s no new software to adopt and no one to train.

Most teams start with one task. Within a week, Viktor is handling half of their ops.

Keep Reading