A misconception in modern risk management is that an organisation controls its own risk. In Kenya’s connected economy, a business may secure its premises, systems and people yet still be exposed through a cloud platform, payments partner, telecommunications network or software supplier.
Traditional approaches built around organisational boundaries are no longer enough: when services, data and money move across an ecosystem in seconds, risk does too. Internal audit must help leaders see and manage that wider field of exposure.
Today’s losses are less likely to begin with someone physically taking cash from a bank. They may start with an intercepted transaction, compromised account, unauthorised application access or weakness in a supplier’s technology. A single failure can travel quickly across connected institutions and reach customers before conventional controls register it.
The question is no longer only whether each organisation is secure, but whether it understands the pathways through which disruption can enter, spread and become systemic.
This is most visible in financial services, where banks depend on technology firms, payment platforms and telecommunications infrastructure to deliver everyday services. These relationships enable scale and innovation, but they also create concentration and continuity risks that cannot be managed by reviewing contracts alone.
Leaders need a current map of critical dependencies, clear accountability when services fail and credible evidence that recovery arrangements will work across organisational boundaries. As organisations add cloud services, automated decisions and artificial intelligence (AI) to this network, the number of connections and the potential points of failure continues to grow.
AI raises the stakes further. It can improve processes, products and customer experiences, but it can also magnify weak data, unclear decisions and poorly governed access. Assurance must therefore evolve alongside adoption. The wider lesson for business is straightforward: innovation must be matched by clear accountability, ethical guardrails and independent challenge, especially where automated tools rely on data or services supplied by others.
Internal audit is central to this shift because it can connect evidence across functions, entities and suppliers. Its value is not simply confirming that controls exist, but testing whether leaders can spot emerging threats, understand how exposures combine and respond at the speed of the business.
This requires teams with expertise in data, cybersecurity, fraud and technology, alongside the judgement to turn technical findings into practical decisions. Done well, audit is not a brake on innovation; it challenges assumptions early and gives boards and management greater confidence that growth is being pursued responsibly.
Resilience, in turn, must be demonstrated rather than declared. The lesson is that leaders must test preparedness, track weaknesses and ask whether lessons from incidents are changing controls.
Independent audit strengthens that discipline by assessing whether responses work and recurring issues are addressed at their source.
Kenya’s cyber-threat landscape shows the scale of the challenge. The Communications Authority reported more than 842 million cyber-threat events between July and September 2025. Its latest report, covering April to June 2026, indicates that ransomware, distributed denial-of-service attacks and social-engineering scams remain prevalent.
These are not isolated IT events: they can disrupt connected services and suppliers, erode customer trust and impose real costs on the wider economy.
For business leaders, the shift begins with better questions.
Which critical services would fail if a key provider became unavailable, and how long could customers tolerate the disruption? Where are the hidden concentrations in our technology, data and payment chains? As AI reshapes decisions and processes, are controls adapting at the same pace? And does internal audit have the access, expertise and authority to give leadership an independent view of risk across the business and its partners?
The writer is the Head of Audit, Kenya & Africa and Audit Director, Standard Chartered