Connected Risk Is Key to Elevating Audit’s Value: 4 Key Insights to Help Every Team Make Progress

What do you call it? Connected risk, integrated risk, coordinated risk, combined assurance, aligned assurance, or just reliance work?
Whatever you call it, the core concept is the same: The IIA defines it as the “process of internal (and potentially external) parties working together and combining their activities to reach the goal of communicating a clear, collective view of risk and controls to management and the board.”
In plain English, as CAE Anne DeTraglia put it during “Connected Risk,” the third webinar in the Internal Audit Collective’s Women in Leadership series, “At the end of the day, it’s just: How do we rely on the work of other people, and the assurance work that they’re doing in the organization?”
During the August 2026 webinar, Anne moderated an engaging panel discussion featuring Audit & Risk Senior VP Amanda Pope, Head of Internal Audit Rebecca Sternberg, and Executive Consultant and long-time Internal Audit leader Linh Truong, who shared their experience implementing connected risk.
You can call it whatever you want. We’re calling it connected risk because:
- It covers everyone while keeping the risks central to the focus. As Internal Audit Leader Wendy Huang pointed out, “Technically, with the right governance, Internal Audit is the only internal ‘assurance’ provider. So we’re not connecting assurance, we’re connecting risks.”
- Richard Chambers nailed it, IMHO. Chambers coined the term and wrote a whole book about it, explaining why and how creating and protecting value in today’s risk landscape requires us to break down silos, improve collaboration, and embrace technology.
- We can’t do it without technology. Heather, who actually helped Richard write the book, clarifies that “connected risk” is always technology-enabled. It’s an intentional distinction worth making given the importance of connecting data, systems, and insights across teams.
Connected risk is an imperative for every Internal Audit team and every organization — but it’s easier said than done. Wherever you are on your journey, these four key takeaways from the webinar can help you make progress.
1. Connected Risk Can Be Informal, Iterative, and Imperfect
Sometimes, connected risk efforts are stalled by the simple fact of Internal Audit’s job description: We’re here to catch the stuff everyone else misses. How can we make sure we still do that while relying on others’ work?
Amanda acknowledged that her biggest roadblock to relying on others’ work is “being comfortable not knowing everything.” She explained, “I worry that 90% of a risk is going to be covered in the work we’re relying on — but we’re going to miss the 10% that’s not covered, and that 10% is going to be big. I always think of Richard Chambers saying that, after something goes wrong, people are always going to ask, ‘Why didn’t Internal Audit catch this?’”
Still, the panelists agreed that when it comes to connected risk, we shouldn’t “let perfect be the enemy of good.” Risk keeps growing, but our budgets and headcounts keep shrinking. We have to increase risk coverage by using existing resources more effectively.
That’s why you don’t need a perfect plan or assurance map for your connected risk efforts to start delivering value. As Anne summarized, “Ugly action is better than unfinished perfection.”
For example, Rebecca’s team’s connected risk efforts have “been born out of a bunch of informal channels. For example, maybe I have a regularly recurring sync with Legal, and Legal may have uncovered an issue through their procedures. They share their early investigation signals with us, and we share back systemic control gaps or oversight weaknesses by management that we've identified in fieldwork. We have a two-way street that allows everyone to cover more ground.”
These efforts help create a continuous feedback loop that enables faster detection of how risks are emerging and changing, and more dynamic responses, resource allocation, and audit planning.
Both Rebecca and Amanda shared that while they’re making progress on assurance mapping, they haven’t yet created formal documentation. But as Rebecca shared, “I know where I’m going and what I want to achieve. So I can put these principles into practice while knowing we eventually want to have a formalized map that we feel good about sharing with the board.”
Your assurance map can mature alongside your connected risk approach. The important thing is to start improving collaboration, sharing more information, and investigating where reliance makes sense.
2. Maturity Can Help Guide Reliance Decisions
While I feel silly saying this to Internal Auditors, I have to say it anyway: You should never assume that others’ work can be relied on.
The panelists repeatedly stressed that reliance should always be determined through deliberate assessment of the other groups’ maturity. For example, is there clear evidence of competence and objectivity? What’s your take on the quality of their methodology, documentation standards, and supervision, review, and follow-up procedures?
Linh — who has extensive experience working for small, “scrappy” audit departments — shared how assessing second-line groups’ maturity levels helped her team be “very intentional about how we spent our resources, and how we can leverage other resources in the rest of the organization.”
For example, when her team decided to start doing annual vendor audits, Linh began by interviewing second-line C-Suite leaders about their vendor audit practices. Whereas one group’s leader was “like a deer in headlights,” saying, “we don't have the resources,” another group’s leader regularly conducted vendor audits, readily showing Linh the methodology they update annually, vendor-selection policies and procedures, and audit templates. “I thought, ‘This is so robust!’ So when my team does vendor audits, we’re not going to redo their work and duplicate their efforts,” said Linh. “If you do a risk assessment, kick the tires, and find out how mature one group is versus another, you’ll be more likely to feel comfortable relying on some of their work. That way, your team can focus on other areas.”
When deciding whether to rely on others’ work, Rebecca regularly asks herself, “Am I at that full-confidence level of being able to place reliance? Perhaps not, right? So if they’re earlier in the maturity scale, we’re considering their learnings as inputs… and if I were to report to the board, I probably don’t want to say that they’ve got it covered.”
3. Independence and Objectivity Are Non-Negotiable — But Navigable
It’s also critical to do a gut-check: Does the work demonstrate an objective, independent mindset?
The increased coordination and collaboration required for connected risk can absolutely be compatible with Internal Audit’s mandate to remain independent and objective. But it’s on us to make sure we’re staying objective as we critically evaluate other sources of assurance.
It’s obviously easier to rely on groups whose reporting relationships help them avoid independence conflicts. For example, several panelists stressed that their past reliance has primarily been on external groups (e.g., External Audit, PCI Auditors, other third-party service providers) or other groups reporting to the board (e.g., Legal, Compliance, Information Security, Data Privacy, Safety).
Conversely, potential conflicts are more likely when groups report to management. Said Linh, “Where I don't see a green checkmark for reliance, a lot of times it's due to independence and objectivity. Because if you look at the org chart, some of these groups should be reporting higher up.” She gave the example of Safety reporting to Operations or the CISO reporting to the CIO, both of which would be more potentially “reliable” if they reported to the board.
Still, as all the panelists reinforced, it’s important to be open to relying on management’s work in some situations. Without increasing reliance in appropriate areas, our organizations won’t get the increased risk coverage they need. They mentioned opportunities such as:
- Control self-assessments (CSAs)
- Self-reported issues
- Quality audits
- Compliance inspections
- Environmental or safety audits
- Risk insights drawn from technology-enabled continuous monitoring
- “Connecting the dots” across assurance work performed by others
4. External Assurance Is Only Valuable If Management Takes Action
Again, Internal Audit teams often feel more comfortable relying on the work of external groups. But it’s not just because of their perceived independence and objectivity.
In many cases, reliance just feels easier, given similarities to Internal Audit’s approach.
As Amanda shared, because External Audit providers “have standards they have to abide by,” they tend to provide “more structure, not just to the way they approach the work, but to their testing evidence, populations, and sampling methodology. Their methodology is far more aligned with The IIA methodology for Internal Audit, so the External Audit groups and Internal Audit really marry a lot better than what other internal groups may do.
That kind of familiarity and comfort can lead Internal Auditors to assume that external assurance work was probably pretty comprehensive.
In reality, we have to be careful not to overvalue external assurance. The panelists cautioned against treating any external assessment as automatically sufficient. Because external groups can’t own remediation, there’s no guarantee management took action to remediate the findings.
As several panelists pointed out, when management receives external assessments, they sometimes “put it on the shelf and check the box” instead of addressing the identified gaps and recommendations.
That’s why, as Linh asserted, Internal Audit has to follow up, asking: “What came of it? What are some of the recommendations? What are the gaps? What high-risk areas may have failed?”
Anne shared an example where an external group had done a fantastic review of the organization’s Procurement function — but nobody did anything in response. Two years later, Anne’s Internal Audit team was asked to review Procurement’s effectiveness. Said Anne, “I found the report, and everything in that report was still true. So I basically said, ‘Go do what they told you to do in this report. Why do you need me? I can rely on the work done by these people. You just need to go execute what they told you to do two years ago’.”
For true assurance, the quality of remediation matters just as much as the quality of the assessment. Make sure your team consistently ensures that management takes responsibility for remediating issues and acting on recommendations.
THE LAST WORD: Progress Is Progress — and Benefits Add Up Fast
Teams implementing connected risk are quick to see benefits.
“We obviously get better risk coverage across the organization. We avoid all the duplication of effort, and reduce audit fatigue,” said Anne. “And you really do get the benefit of deploying your subject matter experts more effectively — plus the sharing of the resources, plans, and findings.”
Amanda’s team’s connected risk approach boils down to answering two simple questions: “How can we make this easier for the business?” and “What can we NOT do because we’re getting coverage elsewhere?” When they shifted their approach, they realized two key benefits:
- “Better conversations with audit customers,” because they know Internal Audit is trying to be as efficient as possible with their time and focus
- “More trust,” given Internal Audit’s ability to deploy their SMEs more effectively — often in different parts of the business.
In the big picture, better-coordinated risk and assurance work changes how the business experiences Internal Audit — moving away from “compliance police” and toward true partnership with the business.
Small steps and a fresh mindset can help you make big progress. Ready to take your next step? Here are four ideas:
- Start building your assurance map. An assurance map is a powerful tool for identifying reliance opportunities and highlighting coverage gaps or overlaps. Here’s how.
- Plan a project that helps build the foundations for connected risk. For example, see #5 in this blog for a recommended project around organizing, connecting, and aligning GRC data.
- Ask your connected risk questions in the Internal Audit Collective forum. Want to find out how others are implementing connected risk, share your challenges, or get specific guidance? Ask our 1,400-member community directly.
- Download The IIA’s “Coordination and Reliance” practice guide. The Global Internal Audit Standards specifically encourage coordination and reliance; to facilitate it, this guide (available only to IIA members) offers tools for assurance mapping, reliance assessments, and more.

Recent Articles

Connected Risk Is Key to Elevating Audit’s Value: 4 Key Insights to Help Every Team Make Progress

What Is an AI Operator? How Can You Become One and Why Does Your Internal Audit Team Need One?

How to be a Better Internal Audit Leader to the Business
Want to be updated as new blog posts are released? Subscribe to our newsletter.
Join 1K+ readers of The Enabling Positive Change Newsletter for tips, strategies, and resources to improve your approach to Internal Audit and SOX compliance.