LONDON, September 28, 2026
How to Measure and Strengthen Your Risk Culture
November 17 2026
LONDON, September 28, 2026
Internal audit leaders should consider 12 areas of accelerating risk exposures as they develop their 2027 audit plans, according to Gartner, Inc., a business and technology insights company.
Speaking at the Gartner Enterprise Risk, Audit & Compliance Conference 2026 taking place in London today, Daniel Ryntjes, Senior Principal Analyst in the Gartner Audit & Risk Practice, explained that the 12 Audit Plan Hot Spots fall under three overarching themes (see Figure 1).
“The first theme is that organizations are under pressure to turn AI investment into meaningful value,” said Ryntjes. “Second, rapid AI adoption is placing a new strain on technology governance and oversight. Third, organizations must also build resilience for a more fragmented operating environment.”
The 2027 Audit Plan Hot Spots draw on a Gartner survey of 190 audit leaders conducted in May and June 2026, interviews with chief audit executives, and additional Gartner research and analysis of the wider risk environment.
“Heavy investment and intense expectations around AI are increasing pressure on organizations to demonstrate real value while managing the associated risks,” said Ryntjes. “AI systems are being deployed faster than governance can keep pace, with 85% of surveyed leaders saying their organizations lack comprehensive AI governance.
“Effective governance can’t depend solely on policies and broad oversight bodies. Accountability, monitoring and intervention mechanisms must be built into how AI systems operate.”
Daniel Ryntjes, Senior Principal Analyst, Gartner explored some of the top areas for internal audit plans in 2027 at the Gartner Enterprise Risk, Audit & Compliance Conference 2026 in London today.
AI-driven technology change is also exposing weaknesses in the technology ecosystem.
“As AI is embedded across workflows and organizations depend more heavily on third parties and cloud systems to store their critical data and processes, attackers are using AI to identify and exploit vulnerabilities faster.” said Ryntjes.
Gartner recommends audit leaders assess whether cyber teams are prioritizing the protection of critical assets and the attack paths leading to them, while maintaining visibility over data access and vendors’ embedded AI updates.
Regulatory divergence, supply chain disruption and macroeconomic volatility are becoming enduring features of the operating environment, increasing the cost and complexity of operating across borders.
“Organizations have spent several years responding to disruptions as temporary events,” said Ryntjes. “A more persistent pattern of fragmentation is forming across regulation, technology, supply chains and economic systems.”
Audit leaders should assess whether risk culture is evolving to manage rapid shifts in technology and supply chain dependencies, and whether management retains enterprise-wide visibility as local requirements reshape data flows, technology and controls.
This press release was adapted from the presentation 2027 Audit Plan Hot Spots Overview at the Gartner Enterprise Risk, Audit & Compliance Conference 2026 in London. Gartner clients can read more in 2027 Audit Plan Hot Spots.
Taking place in London on September 28-29, 2026, the Gartner Enterprise Risk, Audit & Compliance Conference explores how assurance leaders can translate risk insight into decisive business action in an increasingly dynamic environment. Under the theme “From Risk Insight to Action,” the conference highlights how progressive risk, audit, and compliance leaders are strengthening organizational risk reflexes, enabling faster and more effective responses to emerging threats while elevating the role of assurance within the business. Follow news and updates from the conferences on X and LinkedIn using the hashtag #GartnerERAC.
Gartner for Legal, Risk and Compliance Leaders provides expert guidance and tools to help leaders across legal, risk, audit and compliance departments more effectively manage an increasingly complex risk landscape and build next-generation functions. Additional information is available at gartner.com/en/audit-risk and gartner.com/en/legal-compliance. Follow news and updates on LinkedIn and X. Visit the Gartner Legal and Compliance Newsroom for more information and insights.
Gartner is an indispensable partner to C-Level executives and technology providers as they implement AI strategies to achieve their mission-critical priorities. The independence and objectivity of Gartner insights provide clients with the confidence to make informed decisions and unlock the full potential of AI. Clients across the C-Level are using Gartner's proprietary AskGartner AI tool to determine how to leverage AI in their business. With more than 2,500 business and technology experts, 6,000 written insights, as well as more than 4,000 AI use cases and case studies, Gartner is the world authority on AI. More information can be found here.
Rob van der Meulen
Gartner
rob.vandermeulen@gartner.com
Gartner (NYSE: IT) delivers actionable, objective business and technology insights that drive smarter decisions and stronger performance on an organization’s mission-critical priorities. To learn more, visit gartner.com.