Every year the Internal Audit Foundation publishes Risk in Focus, the profession’s most widely read snapshot of what internal auditors are actually worried about. The 2026 edition landed recently, and it is worth ten minutes of any Maldivian internal auditor’s time, both for what it says and for what it cannot tell us.
What the report is
Risk in Focus asks chief audit executives and audit directors two deceptively simple questions against a fixed list of 16 risk areas:
- What are the top five risks your organisation currently faces?
- What are the top five areas where internal audit spends the most time and effort?
The 2026 edition drew 4,073 responses from 131 countries and territories, gathered online between 28 April and 6 June 2025, supported by 18 roundtables with 182 participants and 24 in-depth interviews. Results are published globally, by region, by sub-region and by industry, and the reports are free to the public.
The 2026 headlines
Cybersecurity remains number one, named a top-five risk by 73% of respondents globally. Nothing surprising there, it has held the top spot for years.
What moved is more interesting. Geopolitical and macroeconomic uncertainty rose 10 percentage points in a single year, the largest jump of any risk. Digital disruption, including AI, rose 9 points to second place at 48%. Business resilience (47%), human capital (43%) and regulatory change (41%) round out the global picture.
The most useful finding, though, is a gap rather than a ranking. When you compare what auditors say is risky against where they actually spend their time, three areas stand out:
| Risk area | Rated a top-5 risk | A top-5 audit priority | Gap |
|---|---|---|---|
| Geopolitical uncertainty | 38% | 11% | −27 |
| Digital disruption (incl. AI) | 48% | 32% | −16 |
| Human capital | 43% | 29% | −14 |
In other words, the profession globally knows these risks matter and has not yet worked out how to audit them. That is a fair description of a lot of audit plans here in Maldives.
Where the Maldives sits
Here is the uncomfortable part, and it is worth stating precisely, because the companion Asia Pacific report publishes the numbers.
The Maldives contributed two responses.
Two. Out of 4,073 worldwide. And we are not grouped where you might expect. The report places the Maldives in its Pacific sub-region, alongside Australia, Fiji and New Zealand, not in South Asia. The Pacific sample breaks down as Australia 29, Fiji 18, New Zealand 8, Maldives 2, for a total of 57.
So when a Maldivian internal auditor looks up their regional benchmark, what they find is a profile built roughly half from Australian organisations, cybersecurity and business resilience tied at 61%, human capital 49%, regulatory change 42%, digital disruption 39%. Read the supporting commentary for that sub-region and it discusses Australia’s new CPS 230 prudential standard for banks and insurers, an Australian blood service, and a New Zealand financial services firm. The one reference to the particular vulnerability of “a somewhat isolated island nation” is about New Zealand.
There is no Maldivian voice anywhere in it. There could hardly be, on two responses.
None of this is a criticism of the research. The Foundation reports what it receives, and it reports it transparently, we only know any of this because they publish the country counts. But the conclusion is unavoidable: that sub-region profile is not a Maldivian risk profile, and we should stop treating it as one.
Consider what the global 16 categories flatten. “Financial and liquidity risk” is a reasonable label in most markets; here it has to carry foreign currency availability and dollar access, which is a distinct and, for many organisations, dominant concern. “Supply chain” means something different when service continuity runs across dispersed atolls. “Climate change and environment” sits well down the global list at 18%, for the Maldives it is closer to an existential operating assumption. Add concentration risk from tourism dependence, fiscal stress transmitting from government to state-owned enterprises, a small and highly mobile pool of qualified professionals, and the effect of political cycles on board and management continuity, and it becomes clear that a CAE in Malé cannot lift the global top five into next year’s audit universe and call it a risk assessment.
The proposal
So let us produce our own.
A Maldives edition, same two questions, same 16 categories so our results can be benchmarked directly against the global, Asia Pacific and Pacific sub-region figures, plus a second module of risks framed for our actual operating environment. Survey the people who would know: heads of internal audit and senior internal auditors across government, state-owned enterprises, banks and insurers, listed companies, resorts and tourism groups, telecoms; and those leading risk management functions. Follow the survey with a small number of roundtables, run under the Chatham House Rule, to explain what the numbers mean.
The arithmetic is encouraging, and this is the part worth pausing on. Our current national evidence base is two responses. Sixty to eighty would be thirty to forty times that — and would give the Maldives a larger sample than the entire Pacific sub-region the IIA currently files us under.
For a community our size that is not ambitious. It is roughly one response from each organisation that already employs an internal auditor.
And then let us do it every year, alongside the global report, so that trends become visible rather than anecdotal.
What it would give us is concrete: an evidence base for annual audit planning and risk assessment; a benchmark to put in front of an audit committee when you argue for resources; early visibility of risks your peers are seeing before they reach you; and, over time, a record of how risk in this country actually moves. As far as I am aware, nothing like this has been done for the Maldives before.
How it will work
The survey takes about ten minutes and is completely anonymous. It collects no name, no email address and no organisation name, only broad categories such as sector, role level and the size of your internal audit function. No organisation will be linked to any response, and no result will be published for any group small enough to identify anyone. Those terms are set out on the first screen of the form, and they are not negotiable: honest answers about governance, fraud and culture are only possible if nobody has to worry about their name being attached.
If you would like a copy of the report, or to take part in a roundtable, there is a separate optional form for that, kept deliberately separate so your contact details can never be matched to your answers.
[→ Take the survey] (internalaudit.mv/survey)
Fieldwork closes on 20th September 2026, and the report will be published in the last quarter of 2026, in time for 2027 audit planning.
If you lead an internal audit or risk function in the Maldives, please also forward this to one peer who should be counted. The value of this report scales directly with how many of us take part.
This is an independent initiative of the Internal Audit Maldives. It is not produced by, or affiliated with, the Institute of Internal Auditors or the Internal Audit Foundation. The risk taxonomy is drawn from the IIA’s published Risk in Focus framework so that results can be compared. The Risk in Focus 2026 Global Summary is free to the public at theiia.org/RiskInFocus.
Leave a Reply