To audit risk management, you test the framework rather than the risks themselves: confirm the design against named criteria, test whether the process actually operated over the period, and report to the board. Independence governs the whole exercise, because internal audit may assure risk management but must never own it.
On February 2, 2018, the Federal Reserve capped Wells Fargo’s total assets at roughly $1.95 trillion, citing widespread consumer abuses and failures in governance and firmwide risk management. The cap stayed in force for seven years, an extraordinary constraint on a bank of that size.
The Fed terminated it on June 3, 2025, and the exit condition is the part practitioners should notice. The bank had to complete a third-party review of its governance and risk management program, after which the Fed ran its own assessment.
| How to Audit Risk Management: Key Takeaways |
| You audit risk management by testing the framework, not by re-running the risk assessment. Design effectiveness and operating effectiveness are two separate tests with two separate evidence sets. |
| Independence decides the result before fieldwork starts. Under the IIA position paper, internal audit assures risk management but must never set appetite, own the framework or make risk decisions. |
| The Federal Reserve capped Wells Fargo’s assets at roughly $1.95 trillion in February 2018 over governance and risk management failures, and lifted it on June 3, 2025 only after independent review. |
| Nobody can be certified to ISO 31000 or COSO ERM. Both are guidance documents you audit against, unlike ISO 27001 or ISO 22301, which accredited bodies do certify. |
| The IIA’s Global Internal Audit Standards took effect on January 9, 2025, replacing the 2017 Standards and raising the bar on conformance evidence. |
| The most common finding is not a missing framework. It is a documented framework that nobody operated, which is why sampling actual escalations beats reading the policy. |
An order to audit risk management independently, end to end, was the price of getting the balance sheet back. That is the clearest statement available of what this work is worth, and it reframes the exercise from a compliance chore into the mechanism regulators trust when they will not take management’s word.

Figure 1. Seven years of constrained growth, ended once regulators forced the bank to audit risk management independently.
What It Means to Audit Risk Management
Start with the scope error that wrecks more of these engagements than any other. When you audit risk management, you are not re-performing the risk assessment, and you are not arguing about whether a given risk is scored correctly, though both temptations are strong.
The subject when you audit risk management is the system: the policy, the criteria, the roles, the reporting lines and the evidence that all of it ran. Whether a specific risk sits at 12 or 16 is management’s call, and challenging it directly pulls you across the independence line.
| Question | In scope for the auditor | Management’s call, not yours |
| Risk criteria | Were criteria defined, approved and applied consistently? | Where exactly the severity thresholds sit |
| Risk scores | Was the scoring method applied as documented? | Whether a risk is rated 12 or 16 |
| Appetite | Is appetite documented, approved and used in decisions? | How much risk the organization accepts |
| Treatment | Do actions have owners, dates and evidence of completion? | Which treatment option to select |
| Escalation | Did breaches escalate as the policy requires? | The escalation thresholds themselves |
| Reporting | Does the board receive accurate, timely risk information? | The format the board prefers |
Read the right column carefully, because it is where most attempts to audit risk management drift. Every item there belongs to management, and an auditor who starts making those calls has stopped being an auditor. Our guide to the risk management process sets out what management is accountable for delivering.
Why Independence Decides the Result Before Fieldwork Starts
This is the section most articles on this topic skip, and it is the one that determines whether your report means anything. If the team asked to audit risk management helped build the framework, the engagement cannot produce assurance no matter how thorough the testing is.
The IIA drew that line explicitly, and in some detail, in its position paper on the role of internal auditing in enterprise-wide risk management. Core roles are assurance activities, some advisory roles stay legitimate provided safeguards apply, and a third group of roles is off limits to internal audit entirely.

Figure 2. Facilitating a risk workshop is permitted with safeguards. Owning the framework never is.
The safeguards are specific rather than a matter of judgment. Advisory work is treated as a consulting engagement, it is disclosed, and the auditor who did it does not later provide assurance over the same thing. The IIA’s knowledge brief on the subject is direct about management retaining responsibility.
Independence is far easier to assert than to demonstrate, so we put every engagement through a short set of questions before planning is signed off. Answer them honestly, because an external quality assessor will eventually ask the same ones in writing:
- Did anyone on the audit team draft, edit or approve the risk policy, criteria or appetite statement?
- Does the chief audit executive also hold a risk management title, formally or in practice?
- Does audit maintain the risk register, chair the risk committee, or consolidate risk reporting for the board?
- Would the audit team have to criticize its own prior advice to report the finding honestly?
- Does the reporting line run to the audit committee, or to the executive whose function is being audited?
A yes to any of the first four means you need an external reviewer for that scope, or at minimum a disclosed scope limitation. The Three Lines Model exists precisely to keep these accountabilities apart, and we set it out in our three lines of defense guide.
The Criteria Question: What Are You Auditing Against?
Any attempt to audit risk management without agreed criteria is just an opinion with formatting. Before fieldwork begins you need a written statement of what good looks like, signed off by the audit committee, because every finding you raise is a gap between observed practice and that stated benchmark.
Here is where a widespread misconception costs credibility. You cannot be certified to ISO 31000, and no accredited body issues an ISO 31000 certificate. It is a guidance document, which makes it a perfectly good audit benchmark and a useless compliance claim.

Figure 3. Audit risk management against ISO 31000 freely. Never let a report imply certification to it.
| Criteria source | What it gives you | Watch out for |
| ISO 31000:2018 | Principles, framework and process clauses to test against | Not certifiable; never imply conformance was certified |
| COSO ERM 2017 | Five components and twenty principles, governance-led | Also guidance; the 2004 eight-component version is superseded |
| ISO 19011:2018 | How to run the audit itself, including auditor competence | Guidance on auditing, not on risk management content |
| Regulatory expectations | Binding requirements such as OCC heightened standards | Sector-specific; confirm applicability before citing |
| Internal policy | The organization’s own stated commitments | Weak alone; a bad policy met perfectly still passes |
| IIA Standards | How internal audit must conduct and report the work | Mandatory for IIA-conforming functions since January 2025 |
Combine sources rather than picking a single one. When we audit risk management we test framework design against ISO 31000 and COSO ERM together, operating effectiveness against the organization’s own internal policy, and the conduct of the audit itself against ISO 19011.
The last row of that table matters more than it used to. The IIA’s Global Internal Audit Standards took effect on January 9, 2025, replacing the 2017 Standards, so a function claiming conformance now has a different and more demanding evidence burden.
How to Audit Risk Management in Nine Steps
With criteria fixed and the independence position settled, the fieldwork itself is comparatively mechanical, which surprises people who expect testing to be the hard part. This is the sequence we run to audit risk management, sized for an enterprise scope over roughly six to eight weeks.
| Step | What you do | Primary technique | Evidence you keep |
| 1 | Agree scope, criteria and the independence position in writing | Planning memo | Signed engagement letter naming criteria |
| 2 | Walk the framework: policy, appetite, criteria, roles | Document review | Approved policy with version and date |
| 3 | Test whether criteria were actually applied to entries | Sampling the register | Sampled entries traced to the scoring rules |
| 4 | Trace a sample of risks from identification to treatment | End-to-end tracing | Treatment actions with owners and dates |
| 5 | Test escalation: did breaches reach the right body? | Exception testing | Minutes showing the breach was discussed |
| 6 | Assess reporting accuracy against underlying data | Recalculation | Board pack reconciled to source register |
| 7 | Interview first and second line on how it works in practice | Structured interviews | Notes contrasting stated and actual practice |
| 8 | Rate findings and agree management actions | Closing meeting | Agreed actions with owners and due dates |
| 9 | Follow up on implementation after the due dates | Verification testing | Evidence the action actually operates |
Step three separates a real attempt to audit risk management from a document review. Reading the policy tells you the framework was designed; sampling twenty register entries against the scoring rules tells you whether anyone applied it, and those two findings are frequently opposite.

Figure 4. The top-right quadrant is where most organizations that audit risk management actually sit.
Step five is the highest-yield test you run when you audit risk management. Escalation is where a framework either works or quietly does not, and a policy promising board notification within five days is trivially falsified by checking whether any breach in the period reached the minutes.
Step seven usually contradicts steps two through six, and that contradiction is the point. Interviews surface the workarounds that documents are designed to hide, and our internal audit risk assessment questionnaire gives a starting question set you can adapt to your own scope.
Evidence That Holds Up, and Evidence That Does Not
Findings survive challenge on the strength of their evidence, and engagements that audit risk management attract more pushback than most because the subject is a process rather than a transaction. Weak evidence gets a finding quietly downgraded in the closing meeting, or dropped from the report altogether.
| Assertion | Weak evidence | Evidence that holds |
| The framework exists | A policy document on the intranet | Approved policy with an approval date and minuted sign-off |
| Criteria are applied | Management confirms they are | Twenty sampled entries traced to the documented scoring rules |
| Escalation works | The policy describes escalation | A breach in the period, traced to the committee minutes |
| The board is informed | Board packs contain a risk section | Board figures reconciled to the underlying register |
| Actions get done | The action log shows items closed | Verification that the closed control now operates |
| Roles are clear | An organization chart | Interviews confirming the same split across both lines |
Notice the pattern running down the right-hand column. Every strong item is either a reconciliation or a trace to a dated artifact created by somebody other than the auditor, which is exactly what makes it hard to argue with when the finding lands.
Sampling deserves an explicit decision rather than a habit carried over from last year. For a register of a few hundred entries we typically sample twenty to twenty-five judgmentally, weighted toward high-rated risks and toward entries touching operational risk and regulatory exposure.
Rating Findings and Writing for a Board
Bridging from evidence to output: the report is the only part of the engagement most directors will ever actually see. A finding written for auditors rather than for the board tends to die quietly in an appendix that nobody ever opens.
Rate against impact on the objective, not against how much work the fix requires. A missing escalation route is high whatever the effort to correct, and a formatting inconsistency in the register stays low even if it appears three hundred times.
Findings that get acted on share a structure, and it pays to be mechanical about it. Every finding we issue carries the same five components, because one missing any of them invites a debate about something other than the actual problem:
- The criterion, quoted, with its source and date
- The condition observed, with the sample size and period
- The consequence in business terms, not in audit terms
- The root cause, distinguished from the symptom
- A management action with a named owner and a due date
Write the consequence in the board’s currency. A finding stating that criteria were inconsistently applied means little, while the same finding stating that four of twenty high risks would have escalated under the documented thresholds but did not is impossible to defer.
Keep the opinion proportionate to the work done to audit risk management. If the scope excluded a subsidiary or a risk category, the report says so plainly, since a clean opinion implying coverage you did not test is the fastest way to lose the audit committee’s confidence.
Follow-Up: The Step Most Reviews Skip
An engagement to audit risk management that ends at the report has done roughly half the job. Follow-up is where the value actually gets realized, and it is the step most commonly dropped once the next engagement’s planning deadline starts to bite on the schedule.
Verify rather than confirm, because the two are not the same exercise. Management stating that an action is complete is an assertion, and the real test is whether the control now operates, which usually means sampling again after the due date has passed.
Track overdue actions to the audit committee by name and age. Aggregate counts hide the pattern, whereas a list showing three actions from two engagements ago still open under the same owner produces a conversation that fixes the underlying issue.
Where remediation genuinely takes quarters rather than weeks, agree interim milestones instead of one distant date. A risk management plan with staged deliverables gives you something to test at each checkpoint rather than a single pass or fail at the end.
The Questions Boards Keep Asking About How to Audit Risk Management
Who should audit risk management in an organization?
Internal audit should audit risk management, reporting to the audit committee, provided it played no part in building the framework. Where audit helped design or run risk management, bring in an external reviewer for that scope, because self-review destroys the assurance the engagement is meant to produce.
How often should you audit risk management?
Most organizations audit risk management in full every two to three years, with lighter annual testing of escalation and reporting. Increase the frequency after a major restructure, an acquisition, a regulatory finding, or any incident that the framework failed to anticipate.
Can you be certified to ISO 31000 after an audit?
No, and the distinction matters commercially. ISO 31000 is guidance and is not certifiable, unlike ISO 27001 or ISO 22301. You can audit risk management against ISO 31000 and report conformance with its clauses, but any certificate claiming ISO 31000 certification is meaningless.
What is the difference between a risk management audit and a risk assessment?
A risk assessment identifies and evaluates risks, and management owns it entirely. To audit risk management is to test whether that assessment process was designed properly and whether it actually operated across the period under review. Our complete risk assessment guide covers the assessment side in detail.
What standards govern how internal audit conducts this work?
The IIA’s Global Internal Audit Standards, effective January 9, 2025, which replaced the 2017 Standards. Public sector engagements in the United States may also need to follow the GAO Yellow Book, and ISO 19011 supplies general guidance on auditing management systems of any kind.
How long does it take to audit risk management?
Plan six to eight weeks of fieldwork to audit risk management at enterprise scope, and two to three weeks for a single business unit. Planning and criteria agreement typically consume more calendar time than the testing, because the audit committee has to approve the benchmark.
What is the most common finding in a risk management audit?
Teams that audit risk management most often find a framework that exists on paper and was never actually operated. The policy is approved, the register is populated, and no breach during the period escalated the way that policy requires, which is precisely why sampling real escalations outranks reading documents.
What Goes Wrong, and the Fixes That Work
Seven failure patterns account for most of the failed attempts to audit risk management that we get asked to review or redo. Each one is avoidable at the planning stage and expensive to correct once the report has already gone out to the audit committee.
| Pitfall | Why it happens | Fix |
| Auditing the risks, not the framework | The team finds risk content more interesting than process | Restate scope: the system is the auditee, not the risk list |
| No agreed criteria | Fieldwork starts before the benchmark is signed off | Get criteria approved by the audit committee in the planning memo |
| Self-review | Audit helped build the framework it now assesses | Use an external reviewer or disclose the scope limitation |
| Document review dressed as an audit | Sampling takes longer than reading policies | Trace at least twenty entries end to end before concluding |
| Claiming ISO 31000 certification | The standard is misread as certifiable | Report conformance with clauses; never use the word certified |
| Findings written in audit language | The report is drafted for the working papers | Restate every consequence in business impact terms |
| No follow-up | The next engagement’s planning takes priority | Schedule verification testing at the time actions are agreed |
The self-review row is the one that quietly invalidates whole engagements. We see it most often in mid-sized organizations where a single person carries both the risk and the audit remit, which is understandable resourcing and still fatal to the assurance produced.
Where that describes your own structure, say so in the report rather than hoping nobody notices. A disclosed limitation still leaves you with a credible document, whereas an undisclosed one becomes the first thing a regulator or external quality assessor finds.
Where Efforts to Audit Risk Management Go From Here
Two shifts are already changing how this work gets scoped, and both push in the same direction. Each one moves the expected standard toward evidence that carries a timestamp, rather than a narrative which merely reads well in a committee pack.
The IIA’s new Standards raise the conformance bar considerably. Functions claiming conformance since the January 2025 effective date need demonstrable evidence across the domains, and external quality assessments now test against a materially different framework than the 2017 version did.
Disclosure pressure is pulling risk assurance forward too. Once a company describes its risk processes in a filing, as SEC registrants now do under the cybersecurity rules, the internal audit report becomes the evidence that the description was accurate.
Expect continuous testing to displace the two-year cycle for the highest-value assertions. Escalation and reporting accuracy can be tested monthly from system data, which frees the periodic engagement to examine design and culture, the parts that agile auditing handles poorly.
If the last attempt to audit risk management at your organization concluded that the framework was documented and nothing more, it probably tested design and skipped operation. We audit risk management against ISO 31000 and COSO criteria with the independence position stated up front. See our services, then tell us what you need and send the last report you received.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.