This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Good morning {{name}},

I’m Tim Buckley, an audit, risk and controls leader and founder of Beyond the Lines™. Beyond the Lines™ helps current and aspiring CAEs, Heads of Internal Audit and senior audit leaders become more board-trusted, decision-ready and future-ready in a Human + AI world through practical frameworks, resources and implementation-focused development.

Less control theatre. More decisions, ownership and outcomes.

You Cannot Transform Internal Audit by Simply Adding More Work

Recently, a new Beyond the Lines™ subscriber described a challenge many audit leaders will recognise: managing transformation’s impact on the team, responding to AI expectations before the capability and benefits are developed, and still delivering the core assurance mandate.

That’s not a narrow technology problem. It’s an operating model problem.

Internal audit functions are being asked to modernise reporting, increase insight, introduce AI and analytics, improve stakeholder experience, develop capability, become more efficient and respond faster to emerging risk. In many cases, the audit plan, review hierarchy, meeting load, reporting cycle and expectations of management remain almost untouched.

The new work arrives. The old work stays. The most dependable people are asked to absorb the difference.

I have spent my career across audit, risk, controls and transformation, where the quality of an idea is only one part of whether it works. Beyond the Lines™ helps internal audit leaders become more board-trusted, decision-ready and future-ready in a Human + AI world, with practical thinking grounded in the realities of leading a function, not just describing what good could look like.

This edition is about one of those realities: transformation needs capacity decisions, not just ambition.

Transformation needs a trade-off

Every meaningful transformation expectation requires at least one of three decisions:

  1. Existing work stops or reduces.

  2. Other work is deliberately sequenced later.

  3. Additional capacity or capability is provided.

If none of those decisions is made, transformation becomes side-of-desk activity. It competes with live audits, issue escalation, committee deadlines, stakeholder requests, quality reviews and the unexpected work that arrives whenever the risk environment changes.

This doesn’t mean every transformation programme needs a large new team or a blank cheque. It means leadership must be honest about the transition effort. A new reporting method still needs design, testing, review and adoption. An AI pilot still needs governance, evidence boundaries, manager training and quality control. A new analytics capability still needs accessible data, appropriate skills and time to integrate it into the audit lifecycle.

The promised efficiency may be real. It’s rarely available on day one.

Why “business as usual plus transformation” is not an operating model

Business as usual plus transformation sounds energetic. In practice, it creates conflicting expectations. Teams are told to experiment, but are still judged against the same delivery timetable. Managers are asked to coach new skills while carrying the same review load. Reports are redesigned, but legacy templates and approval layers remain in circulation “just in case”.

The workload also becomes harder to see. Transformation is fragmented across pilot meetings, prompt testing, data cleansing, process mapping, extra quality checks, stakeholder briefings and informal support. None of those tasks looks decisive on its own. Together, they consume the thinking time the function needs to make the change credible.

Quality and morale then come under pressure. The team may comply with the initiative while protecting delivery through longer hours, narrower challenge or greater reliance on a few trusted people. Those people receive more transformation work precisely because they are dependable. What looks like commitment from above can feel like an endless expansion of responsibility below.

Leadership can compound this by protecting too much legacy activity. Every existing report, meeting, test and approval is treated as essential because removing it requires a visible decision. The result is a pilot that sits beside the old method rather than replacing it. Two versions of the work continue, so the efficiency claim is undermined by the transition itself.

Eventually, the pilot is labelled promising but difficult to scale. The deeper problem is often not resistance to change. It’s that nobody created the conditions in which the new method could become the normal method.

That is why I use the Transformation Capacity Contract.

The Transformation Capacity Contract

The contract is a leadership agreement about what the function will protect, remove, sequence, build and prove. It turns transformation from a collection of aspirations into an explicit set of operating choices.

The framework at a glance

The full Transformation Capacity Contract is summarised in the practical visual below. Screenshot it, save it or use it during your next transformation planning discussion to force the capacity choices into the room.

1. Protect the mandate

Central question: What assurance work cannot be allowed to weaken?

Transformation loses credibility if it weakens evidence, professional judgement, emerging-risk visibility, regulatory confidence or audit committee trust. Define the non-negotiable outcomes of the mandate rather than protecting every activity performed in its name.

Warning signs include calling every audit-plan commitment critical, treating long-standing templates as quality controls or measuring protection through volume. Familiar does not always mean essential.

Name the assurance outcomes that must remain strong, then challenge which activities genuinely support them. Protect the standard, not every inherited mechanism.

Example: A function protects traceable evidence, independent rating decisions and timely escalation, but does not automatically protect a 12-page report format or three sequential formatting reviews.

2. Remove old work

Central question: What will stop, reduce, simplify or be retired?

Transformation cannot create capacity if the old method remains fully operational. Removal means retiring work that duplicates assurance, adds little value or can be safely absorbed by a better process or technology.

Warning signs include parallel templates, repeated status meetings, duplicated reporting, unnecessary approvals and “temporary” dual running with no exit date.

Give each initiative a retirement decision. Name what stops, who can approve it, the conditions for withdrawal and the date.

Example: A redesigned audit committee paper replaces, rather than supplements, two internal summaries that repeat the same status information for different review forums.

3. Sequence the change

Central question: What happens now, next and later?

When every initiative is urgent, the function switches between priorities instead of embedding them. Sequencing makes dependencies visible and lets the team learn from one credible change before expanding it.

Warning signs include multiple pilots competing for the same managers, target dates driven by enthusiasm rather than readiness, or new initiatives launched before the data, governance or process they depend on exists.

Separate the immediate need, the next controlled expansion and the longer-term ambition. State what must be true before each stage begins.

Example: The function first improves the executive-summary stage of reporting, then tests AI-supported theme analysis, and only later considers broader automation across planning and fieldwork.

4. Build the capability

Central question: What skills, data, technology, governance and management support are required?

Access to a tool is not capability. A team may generate an output without being able to validate evidence, challenge reasoning, explain the method or defend the conclusion, especially when AI expectations outrun the control environment.

Warning signs include telling teams to experiment without an approved environment, training only junior staff, leaving managers unsure how to review AI-supported work, or describing human oversight without defining who actually signs off what.

Define the operating capability, not just the use case. Specify the approved data boundary, review standard, escalation route, required skills and accountable human judgement point.

AI drafts. Humans decide.

AI organises. Humans validate.

AI speeds up mechanics. Humans sign off.

Example: Before AI supports report drafting, managers are trained to test source traceability, identify unsupported inferences, challenge tone and confirm that ratings remain evidence-led.

5. Prove the benefit

Central question: What evidence would show that transformation improved the function?

Launching a tool, completing a pilot or issuing a template does not prove success. The function must work better without weakening assurance quality.

Warning signs include counting licences, prompts, dashboards or training completions while ignoring rework, cycle time, reporting clarity, risk coverage and stakeholder use. “The team likes it” may be encouraging, but it is not a complete benefit case.

Agree a small set of measures before the change begins, balancing speed, quality, judgement and stakeholder value. Set a redesign point if the method underperforms.

Example: A reporting pilot is judged on the number of review rounds, days from fieldwork close to draft report, evidence corrections after manager review and whether the audit committee paper makes the central risk message clearer.

Worked example: AI-supported audit reporting

Consider a function that wants to use AI to improve audit reporting.

The weak approach starts with the tool. The same report structure, review hierarchy, approval layers, audit plan and management expectations remain. AI produces a first draft, then an additional manual check is added because leaders do not trust the output. The old drafting and formatting routines continue around it.

AI has become another drafting and checking step. No work has been retired, no evidence boundary has been defined and no clear success measure exists. The pilot may produce faster sentences, but the reporting lifecycle is not materially better.

The redesign starts with one lifecycle point: the executive summary after findings and ratings are agreed. Duplicated background content and a separate internal summary are retired. The function defines which evidence the tool may use and prohibits unsupported additions or rating changes.

A human quality gate is explicit. The Audit Manager verifies traceability, materiality and tone. The Audit Director retains judgement over the overall message and signs off the report. Managers learn to challenge output, not simply proofread it.

The pilot measures rework, cycle time, reporting clarity, evidence corrections and unsupported inferences. Only when the method proves credible does the function consider expanding it.

This is the difference between adding AI to the work and redesigning how the work operates.

The Transformation Load Ledger

Use this ledger whenever a new transformation expectation is proposed. A blank cell is not an administrative gap. It is an unresolved leadership decision.

New expectation

What stops or reduces

What is sequenced later

Capability required

Human judgement point

Evidence of benefit

Accountable leader

Use AI to improve audit executive summaries

Retire the duplicated internal summary and reduce manual formatting checks once the pilot quality threshold is met

Broader AI use across planning, findings and fieldwork

Approved environment, defined evidence boundary, report-drafting guidance and manager challenge training

Audit Manager validates traceability, materiality and tone; Audit Director signs off the final message

Fewer review rounds, shorter reporting cycle, no increase in evidence corrections and clearer central messages

Audit Director responsible for Reporting and Quality

A script for the capacity conversation

When expectations are being added without trade-offs, a CAE or Audit Director could say:

“I support the ambition and believe it can improve how the function serves the business. To deliver it without weakening the assurance mandate, we need to make one explicit capacity decision. We can reduce or retire an existing activity, sequence another initiative later, or provide the capability needed for the transition. My recommendation is to protect these assurance outcomes, pause this lower-priority work and test the new method in one part of the lifecycle. We will return with evidence on quality, rework and cycle time before expanding it. That gives us a credible route to the benefit, rather than adding another expectation to the current model.”

That is not resistance. It’s responsible transformation leadership.

Do this Monday: run a 20-minute capacity check

Choose one live transformation initiative. Put it at the top of a blank page and answer these questions with your leadership team:

  1. What are we adding?

  2. What are we stopping?

  3. What are we protecting?

  4. What can wait?

  5. What must the team learn?

  6. What judgement remains human-owned?

  7. What evidence would prove this improved the function?

  8. Who makes the final capacity decision?

Don’t spend the session designing the whole programme. Look for the unanswered question. If the function knows what it’s adding but cannot say what stops, waits or gets resourced, the initiative is not yet ready to be treated as an operating commitment.

The leadership test

Internal audit transformation should create a stronger way of operating, not a more crowded one.

Ambition matters. So do analytics, better reporting, improved stakeholder experience and thoughtful use of AI. But leadership is revealed in the trade-offs that make those ambitions deliverable. Protecting everything while adding more is not caution. It is a refusal to choose, with the cost quietly transferred to the team.

The serious question isn’t only, “What should Internal Audit become?”

It’s, “What are we prepared to change so it can become that?”

Reply and tell me

What transformation expectation is currently running ahead of your team’s capacity or capability?

Hit reply and tell me. One or two lines is enough. I read all the responses, and they help me keep Beyond the Lines™ grounded in the challenges audit leaders are actually managing.

A free resource

If this edition has made you question where your broader leadership model is strongest or exposed, the free Board-Trusted CAE Scorecard provides a practical baseline across ten dimensions of internal audit leadership.

Best,

Share with a colleague

Forward this to one audit leader who is trying to transform their department in a more strategic way.

Want to get the most out of ChatGPT?

ChatGPT is a superpower if you know how to use it correctly.

Discover how HubSpot's guide to AI can elevate both your productivity and creativity to get more things done.

Learn to automate tasks, enhance decision-making, and foster innovation with the power of AI.

Keep Reading