Rethinking Risk Assessment: From Intuition to Evidence
Read the original article ↗
The IIA · The Institute of Internal Auditors · Added July 5, 2025
The IIA · The Institute of Internal Auditors · Added July 5, 2025
risk-assessmentmethodologyanalytics
Why I'm reading this:
There's a gap between how audit functions describe their risk assessment process and how it actually works. The formal process involves scoring risks on likelihood and impact; the actual process involves a senior leader's intuition, with the scoring applied after the fact to justify the result. I'm not sure this is entirely wrong—experienced judgment has real value—but I think analytics can improve this process without replacing the judgment. The interesting design question is how to use data to challenge intuition, not just confirm it.