
Are We Auditing the Past While the Future Destroys the Business?
I started my career at Nile Bank, before its acquisition by Barclays Bank, which was acquired by Absa. Nile Bank was moving from manual to digital banking. Files were becoming screens, ledgers were becoming systems and decisions that took days could happen in minutes. It was a great time to be alive.
What surprises me is that boardrooms discuss digital transformation as buying software, launching an app or automating broken processes. The conversation remains siloed. Strategy sits with executives, risk sits with risk officers, internal audit sits at the end of the corridor, finance reports numbers. The board receives thick papers and calls this governance.
That model is finished. The chief executive knows the problem, revenue is under pressure, customers are disloyal, technology costs rise, regulators expect more, fraud is faster, and talent is restless. Competitors no longer come from the same industry, yet each control function brings its own framework and dashboard. Heck, even the board still manages in silos! It is bad.
The business does not fail in silos but as one system. Strategy decides where to compete and how to win, Risk identifies what may prevent that win or destroy value, and Finance translates ambition into capital, cash, returns and trade-offs. Governance determines who decides, who challenges and who is accountable, while Internal audit must assure that these parts are aligned and working.
When these disciplines operate separately, the company creates false safety. Everyone is busy, but nobody is protecting the future. The first practice I would kill is the annual audit plan built mainly from last year’s risks. We are told to create a risk universe, score it, select entities and complete the plan. What we actually must do is build a strategic assurance plan around the assumptions that must hold for the strategy to succeed.
If the strategy depends on digital growth, internal audit should test adoption, system resilience, data integrity, cyber recovery, partner dependence and digital economics. Auditing password controls while customers abandon the platform is technically correct and strategically useless.
The second practice I would kill is finance as the historian of the company. We are told finance must close the books, control expenditure and protect margins. What we actually must do is turn finance into the economic navigator of strategy.
I want finance to show which customers create value, which products consume capital, which channels destroy margin and which initiatives waste cash. A board cannot govern strategy using revenue growth alone. It needs return on capital, cost to serve, risk-adjusted profitability, cash conversion and scenario exposure. It is so painful and surprising that most finance teams cannot provide such data when asked during strategy sessions, and you wonder why the company pays them. Numbers should not merely explain what happened but change what management does next.
The third practice I would kill is governance by committee volume.
We are told that more committees, policies, dashboards and board packs improve oversight. What we actually must do is reduce governance to decision quality, accountability and speed. A board should ask: Which assumptions are no longer true? Which risk could make this strategy irrelevant? Which investment should we stop? Which capability must we build before markets force us? Which executive owns the consequence?
A forty-page risk report that does not alter a decision is useless. You are probably saying that these changes blur roles: Internal audit must remain independent, Finance must not become strategy, Risk must not run the business, and Boards must not interfere with management.
I agree with the principle but reject the lazy interpretation. Independence does not mean isolation. Role clarity does not require silos. The goalkeeper, defenders, midfielders and strikers have different roles, but they play the same match. A team that protects departmental boundaries while losing is not well governed, it is just well organised for failure.
The future company needs fewer control specialists who only administer frameworks and more enterprise thinkers who understand value creation, technology, capital, behaviour and execution. Some roles should disappear. The auditor who only checks compliance, the risk officer who only updates registers, the finance leader who only reports variances, the company secretary who measures governance by meeting frequency, and the board member who reads papers but cannot challenge the business model.
These roles once provided comfort today, they can provide cover for decline. I have learned that the most dangerous organisation is not the one with weak controls, it is the one with strong controls around an obsolete strategy. The chief executive does not need five assurance conversations but rather one integrated view of whether the company can win, what may stop it, whether the economics work, whether accountability is clear and whether the evidence can be trusted.
That is the new internal audit mandate. Audit the strategy, the assumptions, the economics, decisions, and the organisation’s ability to adapt. The greater professional risk is no longer challenging management too much. It is assuring yesterday while tomorrow quietly takes the company.
Copyright Institute of Forensics & ICT Security, 2026. All rights reserved.


