How uncomfortable questions help businesses future-proof themselves
The announcement “The internal audit is coming” rarely sparks enthusiasm. In the midst of a packed working day, the arrival of the audit team usually means a noticeable extra burden: gathering documents, explaining complex processes, answering questions and disclosing audit evidence.
This reaction is understandable. Nobody has much time. Day-to-day business is in full swing, new regulations are introduced on a weekly basis, systems are expanding and resources are scarce. It is therefore not uncommon for an audit to be perceived as a burden at first.
However, the Internal Audit function is not there to make life difficult for the business units. Nor is its remit to find as many errors as possible or to hold individual staff members responsible for non-compliance. Rather, it is about conducting an independent and risk-based review to ascertain whether processes, controls and governance are actually functioning as they should.
At first glance, this sounds self-evident. In practice, however, there is often a significant discrepancy between the formally prescribed process and what actually happens in practice.
This is because it is often not the obvious breaches of the rules that indicate the greatest need for action. It is the small deviations, manual additions and informal solutions that have become established over the years and which, at some point, nobody questions anymore. Internal audit can bring precisely these blind spots to light.
The patterns of day-to-day business: when the exception becomes the norm
Anyone who follows a process over a long period of time inevitably develops routines. At first, this makes sense. Routines create efficiency and provide guidance.
The problem arises when the operating conditions change but the process continues unchanged. New systems are introduced. Responsibilities shift. Products change. Requirements from regulators, customers or the market increase. Processes are digitised. New interfaces are added.
Nevertheless, the response within the department is often:
"We’ve always done it that way."
This statement is not automatically a problem. However, it may be an indication that a process has not been fundamentally questioned for a long time.
The situation is similar with a second classic example:
"That’s not my responsibility."
Auch hier geht es nicht zwangsläufig um fehlende Verantwortungsbereitschaft. Vielmehr kann die Aussage auf unklare Schnittstellen, fehlende End-to-End-Verantwortung oder organisatorische Silos hindeuten.
Gerade in komplexen Organisationen entstehen Risiken häufig nicht innerhalb einzelner Prozessschritte, sondern an deren Übergängen. Ein Bereich erledigt seine Aufgabe korrekt. Der nächste Bereich ebenfalls. Trotzdem funktioniert der Gesamtprozess nicht zuverlässig.
Die Frage der Revision lautet dann nicht nur:
"Who didn't carry out their step in the process correctly?"
but:
"Why is the organisation as a whole structured in such a way that such a discrepancy could have arisen?"
Not the mistake is the problem, but the lack of the ability to learn
Mistakes cannot be completely avoided in complex organisations. People make mistakes, systems can fail and processes can reach their limits in unexpected places. The crucial question is therefore not whether a mistake happens. What matters is how the organisation deals with it.
- Is a mistake merely corrected? Or is an investigation also carried out into why it occurred?
- Is it checked whether comparable risks exist elsewhere?
- Is the root cause eliminated?
- And is it verified whether the measures taken are actually effective?
This is precisely where one of the key strengths of internal audit lies. The finding ‘control not carried out’ is, at first, merely a description of the facts. Things become more interesting with the next question: why was the control not carried out? Only by analysing the root causes can sustainable improvement be achieved.
A fresh perspective on cost-effectiveness: the value of an independent view
“Internal audit incurs costs but does not generate direct revenue.” This view is too narrow. The value of an independent audit function lies precisely in identifying risks whose financial implications often cannot be quantified immediately.
- What is the cost of a control system that does not work?
- What is the cost of an inefficient process?
- What is the cost of relying on individual experts?
- What is the cost of an error-prone manual interface?
- What is the cost of a delayed response to regulatory requirements?
The answer to this is rarely a single figure. The economic contribution of internal audit therefore lies in improving the basis for decision-making and alerting management and specialist departments to risks and structural weaknesses at an early stage. A risk-based audit must be able to distinguish between an acceptable residual risk and a weakness that genuinely requires action.
Internal Audit as an independent sparring partner
For this role to work, the Internal Audit function needs one thing above all else: independence. It must be able to ask questions, even when the answers are uncomfortable. At the same time, it should not seek to take over the tasks of the departments it audits. Responsibility for processes and controls remains with management and the relevant specialist departments.
The role of Internal Audit is different: it independently assesses whether governance, risk management and internal controls are appropriately designed and functioning effectively. In this way, Internal Audit does not become a ‘substitute for management’, but rather an important sparring partner.
However, this also requires appropriate cooperation. An audit should not be a battle between two sides. The line department knows the operational reality. The audit function brings an independent perspective and an understanding of risks and interrelationships. Together, these can generate considerable added value.
Resilience does not only emerge in a crisis
The discussion surrounding resilience has become significantly more important in recent years. Resilience is often associated with the ability to react quickly to crises. Yet resilience begins earlier.
True resilience begins with processes that continue to function even under changing conditions, and with a corporate culture that is prepared to learn from mistakes. This is precisely why internal audit is more than just a downstream control function. An effective audit culture is therefore not recognised by the sheer number of findings, but by how they are dealt with:
- Is the focus on identifying those responsible, or on identifying the root causes?
- Are measures implemented merely so that the issue can be marked as resolved in the next report? Or is a genuine, sustainable improvement actually achieved?
Are uncomfortable questions a competitive advantage?
Of course, internal audit is uncomfortable. In a sense, that is precisely the point. After all, a function whose role is to independently scrutinise existing structures cannot ask only pleasant questions.
Such questions are not an expression of mistrust towards the business units. They are an expression of a professional approach to risk management. After all, a company does not become more stable simply because existing processes are scrutinised as infrequently as possible. It becomes more stable when it is able to critically examine itself and derive concrete improvements from the findings.
Conclusion: Better to face some discomfort today than be caught off guard tomorrow
“The internal audit is coming.” Perhaps this phrase will still fail to elicit waves of enthusiasm in the future. Nor does it need to. An audit may involve some effort. It may raise questions. And it may highlight issues that have not previously been a high priority in day-to-day operations.
What matters is what comes of it. A good internal audit does not produce lists of errors for their own sake. It creates transparency regarding risks, scrutinises the effectiveness of controls and helps to identify structural causes.
Its value is therefore not evident solely in the audit report. It becomes apparent when a process actually functions better following the audit. When responsibilities are clearer. When unnecessary manual work is eliminated. When a risk has been reduced. When a control is not merely documented, but is actually effective. And when management was alerted at an early stage to a development that could have caused considerable damage later on.
This is precisely where the value of constructive discomfort lies.
Better to ask an uncomfortable question as part of an internal audit today than to face an expensive, avoidable problem tomorrow, after which all parties involved will ask: “Why on earth didn’t anyone spot this beforehand?”


