This website uses cookies

Read our Privacy policy and Terms of use for more information.

Sponsored by

Good morning {{name}},

I’m Tim Buckley, founder of Beyond the Lines™.

Beyond the Lines™ exists to help current and aspiring CAEs, Heads of Internal Audit and senior audit leaders become more board-trusted, decision-ready and future-ready in a Human + AI world.

Less control theatre. More decisions, ownership and outcomes.

Culture is not what leaders say. It is what survives pressure.

Last week, I was honoured to be joined by Sandro Boeri for the latest Beyond the Lines™ Leadership Signals session.

The topic was: Culture in action: How to audit behaviour without it becoming subjective

This is exactly the kind of conversation I created Beyond the Lines™ for.

Not because culture is a nice topic. Not because it makes audit sound modern. But because many of the biggest issues Internal Audit sees are not really caused by a missing policy, a weak procedure or a badly written control description.

They are caused by what happens when people are under pressure.

  • What gets rewarded.

  • What gets ignored.

  • What gets escalated.

  • What gets tolerated.

  • What gets quietly worked around because the formal process does not reflect the reality of the business.

That’s where a lot of risk actually lives. And it is also where Internal Audit has a real opportunity to move beyond describing control weaknesses and start helping organisations understand why things happen.

In this edition, I want to do two things.

  • First, summarise the key themes from the webinar, with full credit to Sandro for the insightful perspectives and expertise he shared.

  • Second, connect the topic to a very practical problem: technically valid audit findings that still fail to create movement.

Because that is the real issue. Audit can be right and still not land. The report can be accurate and still not change the conversation. The finding can be accepted and still not change the risk position.

That is the gap BtL is being built around.

Watch the replay

The full webinar replay is now available.

This is worth sharing with your internal audit, risk, controls or governance teams if you are thinking seriously about how to engage with culture and behaviour in a more practical, evidence-based way.

1. Culture is not usually the problem on paper

One of the strongest themes from the session was that culture is rarely missing from the formal documents. Most organisations already have values, policies, risk frameworks, escalation routes, conduct statements, governance forums, training records, committee packs and control attestations.

On paper, everything often looks sensible. The harder question is what happens in practice.

That is where Sandro’s expertise was so useful. He brought the conversation back to behaviour. Not vague commentary about whether an organisation has a “good culture” or “bad culture”. Not broad statements or subjective opinions dressed up as audit findings.

Behaviour.

  • What people actually do.

  • What leaders reinforce.

  • What managers ignore.

  • What gets rewarded.

  • What gets punished.

  • What happens when commercial pressure, deadlines, personal incentives or fear of escalation start to shape decision-making.

That is the difference between culture as a slogan and culture as an audit-relevant risk.

One of the most powerful messages from Sandro was that Internal Audit can lose credibility very quickly by using the word “culture” too loosely. The board does not need another vague observation that “culture needs improvement”. Management does not need a finding that sounds like a moral judgement. The business does not need audit trying to become amateur psychologists.

What they need is something more useful:

Evidence of where behaviour is increasing exposure, weakening control effectiveness or stopping good insight from turning into action.

That is a stronger conversation.

Not “the culture is poor”.

But:

“The operating reality does not match the formal expectation, and here is the risk this creates.”

That is where Internal Audit becomes useful.

2. Behavioural risk makes culture more auditable

A key theme from Sandro was the value of reframing culture as behavioural risk.

That shift matters.

Culture can feel abstract. Behavioural risk is more practical.

It asks whether people are behaving in a way that supports the organisation’s objectives, risk appetite, control expectations and strategic priorities. That gives Internal Audit a more credible entry point.

Instead of asking, “What is the culture like here?”, audit can ask better questions:

  • Are people making decisions in line with expected risk behaviours?

  • Are incentives supporting or undermining the right behaviours?

  • Are leaders communicating expectations clearly?

  • Are consequences applied consistently?

  • Are people being trained in a way that changes behaviour, or only in a way that records completion?

  • Are escalation routes used when pressure hits?

  • Are known behavioural patterns increasing exposure?

That’s not soft. It’s about whether human behaviour is supporting or undermining the organisation’s ability to deliver safely, ethically and effectively.

Internal Audit is usually comfortable auditing formal process. We are often less comfortable auditing the human reality around that process. But the two cannot be separated.

A control does not fail only because the design is weak. It can fail because someone does not understand it, believe in it, is incentivised to bypass it, knows there will be no consequence or is under pressure to prioritise speed over control.

If Internal Audit wants to understand whether a control environment is genuinely working, it has to understand the behavioural conditions around it.

3. Audit needs evidence, not labels

Another important point we discussed is that one of the biggest risks in this area is jumping from observation to conclusion too quickly. That’s where culture work can lose credibility.

Sandro was clear that audit needs to be careful with labels. A great example he used was this: If audit observes that junior people rarely speak in meetings, that may be a useful observation. But concluding that the environment is psychologically unsafe is a much stronger claim.

There may be several possible explanations, so the audit point needs to stay close to the evidence.

  • What was observed?

  • How often?

  • In what setting?

  • What was the impact?

  • What risk did it create?

  • What control, decision or escalation process was affected?

That is how Internal Audit keeps the work credible.

4. Internal Audit needs to move from hindsight to foresight

Another important theme was the future relevance of Internal Audit. Sandro made the point that Internal Audit is still too often seen as backward-looking, compliance-led or focused on what went wrong, which I fully support.

That should make us uncomfortable. If Internal Audit only explains the past, its value will keep being questioned. The stronger opportunity is to use behavioural insight to support foresight. Instead of only reporting that a project failed, audit can help explain the behavioural conditions that made failure more likely.

For example:

  • Unclear ownership.

  • Weak escalation.

  • Inconsistent leadership messaging.

  • Incentives that rewarded speed over quality.

  • Training that did not prepare people for real decisions.

  • Reluctance to challenge senior stakeholders.

  • Poor follow-through when early warning signs appeared.

That type of insight does not just explain what happened. It helps the organisation understand what may happen again if the same conditions are still present.

That is much more useful to boards and executives, and this is the future of internal audit leadership.

Not more reports. Not more ratings. Not more action trackers.

Better insight. Better questions. Better connection between evidence, exposure and decisions.

The audit leaders who stand out over the next few years will not simply be the ones who produce technically correct reports. They will be the ones who can sit with a board or executive team and explain:

  • “This is what the evidence tells us.”

  • “This is why it matters.”

  • “This is where exposure is building.”

  • “This is what needs to change.”

  • “This is the decision you need to make.”

That is board-trusted Internal Audit. Behavioural risk has a major role to play in that shift.

5. Behaviour does not need to start with a standalone culture audit

One of the most practical points from Sandro was that Internal Audit does not need to start by launching a big standalone culture audit. In fact, doing that too early can create resistance. It can sound personal. It can sound political. It can sound like audit is about to tell senior leaders they are failing at the thing they probably believe they are already doing well.

Sandro explained that a more practical starting point is to embed behavioural risk into existing audit work. That means looking at behavioural pressure points within normal audits, such as hiring, training, incentives, leadership communication, escalation, remediation, consequences, decision-making and accountability.

This makes the work more grounded.

Rather than auditing “culture” as a broad theme, audit can look at how behaviour affects a specific risk area, process, project or control environment.

This is probably the most pragmatic route for many internal audit functions. Do not start by trying to boil the ocean. Start by adding better behavioural questions into work you are already doing.

Sandro gave us a clear example regarding Cyber. If you are auditing cyber risk, do not only ask whether training was completed. Ask whether the training is contextual enough to change behaviour and make people truly understand the risk itself, the impact this could have on them personally, and their responsibilities within the organisation.

Some other examples to consider:

  • If you are auditing change delivery, do not only ask whether governance forums exist. Ask whether bad news is escalated early enough to influence decisions.

  • If you are auditing financial controls, do not only ask whether reconciliations were performed. Ask whether review, challenge and accountability actually happen when something looks wrong.

That is where audit moves from assurance over activity to assurance over whether the system works in real life. And that is where the value sits.

6. Boards care when behavioural risk connects to business pain

During the Q&A, one of the questions was how to make the board see the value of auditing behavioural risk.

One point I took from Sandro’s response was to start where there is already pain.

  • A failed project.

  • A regulatory issue.

  • A recurring control failure.

  • A major incident.

  • A strategic initiative that is slipping.

  • A repeated finding that never seems to get fixed properly.

When Internal Audit can show that behavioural conditions are contributing to a live business problem, the conversation becomes much more relevant.

This is not about asking the board to care about culture in the abstract. It is about helping the board understand why something important is not working.

7. Global organisations need curiosity before judgement

Another strong theme from the Q&A was the challenge of applying common values across different countries, regions and operating environments.

Sandro’s message was that audit needs curiosity. Not naivety. Not moral relativism. Curiosity.

Different locations may have different norms, legal systems, expectations, incentives and business practices.

That does not mean everything is acceptable. But it does mean audit needs to understand the local context before jumping to conclusions.

This is where Internal Audit needs both backbone and humility:

  • Backbone to hold the line on the organisation’s values, risk appetite and legal obligations.

  • Humility to understand how things actually work on the ground.

The worst audit work in this area starts with judgement and then goes looking for evidence.

Better work starts with evidence and asks better questions.

  • Why is this happening here?

  • What do people believe is expected?

  • What do they think will be rewarded?

  • What do they think will be punished?

  • What do they see leaders doing?

  • Where does the formal requirement clash with local commercial reality?

That is how audit earns the right to challenge. Not by preaching. By understanding first, then connecting behaviour to risk, exposure and outcomes.

What internal audit functions can do now

Audit functions do not need to wait until behavioural risk becomes a formal compliance exercise. Sandro gave some practical advice on what Internal Audit functions can do now.

  • Review the audit universe and identify where behavioural risk is most relevant.

  • Decide where behavioural risk can be embedded into existing audits.

  • Consider whether behavioural risk is visible in the risk taxonomy.

  • Train auditors to recognise behavioural pressure points.

  • Build stakeholder understanding before the work lands.

  • Brief the audit committee on the approach.

  • Avoid a tick-box response to emerging requirements.

The biggest mistake would be to treat this as another methodology update. Add a few questions to the audit programme. Train the team for an hour. Tell the audit committee it is covered and move on.

That might satisfy a surface-level requirement, but it will not change the value Internal Audit creates.

The better opportunity is to use this as a trigger to improve how audit thinks about real-world control effectiveness.

Not just whether the control exists.

Not just whether the evidence is present.

But whether the behaviours around the control make success more or less likely.

That is a much more mature conversation. And it is one Internal Audit needs to become comfortable having.

Do this Monday: a practical starting point to build readiness

The December 2026 effective date for the IIA’s Organizational Behavior Topical Requirement is getting closer, and internal audit functions don’t need to wait until then to start building the muscle.

To apply the themes discussed in the session, I’ve drafted a simple exercise I would be running with my own Internal Audit team now. It’s a practical starting point to help audit teams begin testing how behaviour affects risk, controls and decisions in work they are already doing.

This is not a substitute for reading and applying the full IIA requirement. But it’s a useful way to start preparing, because it moves the conversation from vague culture labels to observable behavioural risk.

Pick one audit already in your plan. Start with a live piece of work where behaviour is likely to affect the outcome. That could be a cyber audit, transformation audit, procurement audit, financial controls audit, conduct audit, third-party audit or remediation review.

Then add five questions.

1. Where does pressure show up?
Look for deadlines, targets, incentives, resource constraints, senior stakeholder pressure or competing priorities.

2. What behaviour does the process depend on?
For example: challenge, escalation, review, honesty, documentation, follow-through or timely decision-making.

3. What evidence shows that behaviour is happening?
Do not rely only on interviews. Look for meeting records, decisions, exception logs, escalation history, review notes, overdue actions or repeated workarounds.

4. What happens when the right behaviour is uncomfortable?
This is often where culture becomes visible. Do people escalate early, challenge properly and own the issue, or stay quiet until the risk has already grown?

5. What risk does the behaviour create or reduce?
Connect it back to exposure, decision quality, control effectiveness, customer impact, resilience, financial loss, regulatory risk or delivery failure.

The point is not to label the culture. The point is to evidence how behaviour affects governance, risk, controls and decisions.

That is the shift audit functions need to start practising now.

Toolkit spotlight: when a technically right audit finding goes nowhere

Separate from Sandro’s work, this topic also connects to where I am taking Beyond the Lines™ and the practical tools I am building for internal audit leaders.

A lot of audit findings are technically right. The evidence is there. The control weakness is valid. The rating is defensible. The report is approved. The action is agreed. And then very little actually changes.

The finding gets closed eventually. The tracker turns green. The audit committee sees progress. But the real exposure remains.

That is one of the reasons I developed the Board-Trusted CAE Toolkit.

Internal Audit often does good work, but the work does not always land in a way that changes decisions, ownership or outcomes. And if you want to be seen as a serious audit leader, that gap matters.

  • It affects how executives see you.

  • It affects how the board values you.

  • It affects whether Internal Audit is viewed as a strategic partner or a necessary governance function.

  • It affects your own credibility as someone who can lead beyond process and into impact.

The Toolkit is designed to help close that gap.

  • Not by giving you prettier templates.

  • Not by adding more audit jargon.

  • Not by making reports longer.

But by helping you take one piece of live audit work and sharpen how it moves through the leadership system.

The problem: the finding is valid, but the message doesn’t create movement

This is one of the most common issues I see. An audit finding might explain what failed, what evidence was reviewed, what the control weakness is, what action management agreed and when the action is due.

That may be enough for a report. But it is not always enough for a decision.

The board or executive team may still be unclear on:

  • Why this matters now.

  • What exposure remains.

  • What decision is needed.

  • Who really owns the outcome.

  • What happens if action is delayed.

  • Whether the proposed fix will actually reduce risk.

  • How this links to strategy, performance or accountability.

That is where technically correct audit work leaks impact.

How the Toolkit helps

The Toolkit helps internal audit leaders reframe audit work so it becomes more decision-ready. For this specific use case, it guides you through five practical moves.

1. Reframe the finding
Move from “what failed” to “why this matters”.

This helps you sharpen the issue so it is not just a control weakness, but a clearer explanation of exposure, consequence and decision relevance.

2. Make the report decision-ready
Translate audit evidence into a message leadership can actually use.

That means reducing noise, clarifying the decision point and making the insight more useful for executives and audit committees.

3. Build the board message
Turn the audit point into a concise board-level narrative.

This is where you move from operational detail to strategic relevance.

4. Map ownership and follow-through
Test whether the agreed action has the right owner, route, consequence and evidence of movement.

An action without real ownership is just another line on a tracker.

5. Create a 30-day sprint
Turn the insight into a practical short-term improvement plan.

Not theory. Not a transformation programme that takes months to start. A focused way to create visible movement quickly.

Why this matters for your career

This is not just about improving audit reports. It is about how you are seen as an audit leader.

The next generation of CAEs and senior audit leaders will not stand out because they can produce more findings. They will stand out because they can help the business understand exposure, make better decisions and create clearer accountability.

That is the difference between being seen as someone who reports issues and someone who improves the way the organisation thinks, acts and responds.

The Toolkit is built for that shift.

It is for audit leaders who want to be more than technically competent. It is for people who want to become more board-trusted, decision-ready and future-ready. It is for people who know Internal Audit needs to move beyond control theatre and into decisions, ownership and outcomes.

Why I built it

I built the Toolkit because I have been on both sides of this problem.

  • I have written findings that were technically right but did not land as well as they should have.

  • I have seen audit teams produce strong work that gets diluted, delayed or misunderstood because the message was not sharp enough.

  • I have worked with clients where the issue was not the quality of testing, but the gap between audit insight and business action.

  • And I have seen how much more powerful Internal Audit becomes when the work is framed around the decision that needs to be made, the exposure that needs to be understood and the ownership that needs to be clarified.

That is what the Toolkit is designed to help with. Not as a theoretical framework. As a practical operating system for audit leaders who want their work to matter more.

If you want a preview of the toolkit itself, watch the video below. This will be launching very soon, so keep reading the BtL newsletter to find out more.

Share this with a colleague

If you know a CAE, Head of Internal Audit, Audit Director or senior audit leader who is trying to make culture, behaviour and control effectiveness more practical, feel free to forward this edition.

The more Internal Audit can connect behaviour to evidence, risk and decisions, the more useful it becomes.

Final thought

Culture is not separate from control. Behaviour is not separate from risk. Leadership is not separate from assurance.

If Internal Audit wants to stay relevant, it needs to get better at connecting these things.

That does not mean becoming vague. It means becoming more precise. More evidence-led. More commercially aware. More useful to the decisions that matter.

That is the work.

Less control theatre. More decisions, ownership and outcomes.

Best,

The website you've been putting off? Done in 2 minutes.

Every SMB owner has that tab open: "build a website." It's been there since Q2.

Readdy.ai turns one paragraph about your business into a full, mobile-ready site — with SEO, hosting, booking, and payments built in. No blank Wix canvas. No Fiverr ghosting. No $3K agency quote.

Describe your business. Get a site that looks like you hired a designer. Need to change the hours, swap a photo, add a new service? Just ask the AI in plain English.

It's the website you've been meaning to build, finished before your next coffee.

Keep Reading