The traditional boundaries between internal audit and enterprise risk management (ERM) are beginning to blur.
For decades, audit functions occupied a relatively well-defined position within organisations. Their role was to assess controls, test processes, identify weaknesses, and provide independent assurance to leadership and the board. Risk management, meanwhile, was responsible for identifying threats, assessing their potential impact, and helping the business navigate uncertainty.
That distinction may still exist on paper, but in practice, many organisations are finding that the complexity of today's risk landscape requires a different approach.
Recent guidance from the Institute of Internal Auditors (IIA) reflects a growing recognition that internal audit can no longer operate as a function that's largely disconnected from day-to-day risk conversations.
Instead, the profession is becoming increasingly involved in helping organisations understand and respond to enterprise-wide risks.
This points to a fundamental change in what organisations expect from audit professionals and, by extension, how careers in internal audit and ERM are likely to develop in the years ahead.
The changing expectations of internal audit
Business leaders are grappling with a level of uncertainty that feels increasingly permanent. Artificial intelligence is creating new governance challenges. Cyber threats continue to evolve. Regulatory expectations are expanding. Geopolitical instability can disrupt supply chains overnight. Risks that might once have been managed separately are now deeply interconnected.
In that environment, boards are looking a clearer understanding of how risks are emerging, where vulnerabilities are developing, and what those risks could mean for the organisation's strategy.
Internal audit is uniquely positioned to provide that perspective.
Because auditors already have visibility across multiple business functions, they often see patterns and themes that individual departments miss. Increasingly, organisations are recognising that this wider vantage point can be valuable not only in assessing risk management activities, but also in informing them.
The IIA's latest position reflects this reality, emphasising that enterprise risk management should be viewed as a coordinated organisational activity rather than the sole responsibility of a single function. Internal audit remains independent, but it is also expected to contribute insight, challenge assumptions, and support a more integrated approach to risk oversight.
The emergence of the audit-risk professional
Perhaps the most interesting consequence of this evolution is what it means for people building careers in the profession.
Historically, the career paths of auditors and risk professionals often diverged early.
At Leonid, we are witnessing how employers increasingly seek out professionals who understand both worlds; who can move comfortably between discussions about controls and conversations about strategy, emerging risks and business performance.
In many respects, a new professional profile is emerging: someone who combines the rigour and objectivity of an auditor with the broader perspective of a risk adviser.
This is particularly evident at senior levels. Organisations are creating leadership positions that span audit, risk, governance, and controls, recognising that these disciplines are often more effective when viewed together rather than in isolation.
For ambitious professionals, this creates opportunities that were less common a decade ago. An internal audit career is no longer solely a route toward becoming a Chief Audit Executive. It can also provide a pathway into enterprise risk leadership, governance roles, operational leadership, or broader executive positions.
Technical expertise is no longer enough
None of this diminishes the importance of core audit skills. Expertise in controls, assurance methodologies, governance frameworks and regulatory requirements remains absolutely essential.
What has changed is that these capabilities are increasingly viewed as the foundation, rather than the finish line.
Auditors of today can connect audit findings to commercial realities. They understand how risks influence strategic decisions. They are comfortable engaging with senior stakeholders and challenging assumptions constructively. Most importantly, they can translate complex issues into insights that executives and boards can act upon.
In many ways, the profession is becoming more ‘human’. Technical competence remains critical, but communication, influence, curiosity, and business judgement are becoming equally valuable differentiators.
A more influential future
The challenge for audit professionals is determining how they can create value while maintaining the independence that gives the function its credibility.
For those willing to embrace a broader remit, the outlook is positive. As risk environments become more complex and organisations seek more integrated approaches to governance and assurance, the demand for professionals who can bridge the gap between audit and risk is likely to grow. The level of influence that these roles have will only grow bigger, too.