Quick answer: Periodic audits give a false sense of security against fast-moving, systemic risk. Michael Power's critique of the ritual of verification explains what boards should demand instead of ticking the audit box.
Originally published on LinkedIn: 2 March 2026.
An audit is a systematic, independent, documented evaluation of an organisation's records, operations or systems, intended to give an objective assessment of financial health, compliance and operational effectiveness. That objective is sound. The method, as commonly practised, is not well suited to the risks organisations now face.
Because audits provide a snapshot of the past based on legacy data, they cannot reasonably assure the future. This creates what researchers call a perverse blindness to real-time, emerging threats. A dominant reliance on quantitative, stochastic models compounds the problem: numerical precision looks rigorous but frequently overlooks organisational culture, management integrity and employee morale, the qualitative factors that most influence systemic risk.
The audit society
Professor Michael Power's work on "The Audit Society" describes how auditing has evolved into a ritual of verification, valued for its symbolic assurance more than its actual effectiveness at uncovering problems. That produces a box-ticking mentality, where organisations prioritise the appearance of compliance over substantive improvement, and a devaluation of local, contextual knowledge in favour of imported technical standards.
First-order limits
Traditional auditing constrains itself to first-order, visible cause-and-effect relationships. It is poorly equipped for the second- and third-order layers, feedback loops, systemic structural factors, and the broader social and political context, where genuinely wicked, networked risks actually live. Auditors also suffer from bounded rationality: they lack access to the full context available at the time a decision was made, a limitation shared with the AI models increasingly used to assist the process.
Structural and commercial bias
There is a material risk that industry bodies, lobbyists and commercial brands influence the standards auditors work against, creating a club benefit that traps organisations and regulators inside a branded ecosystem. Because no single universal audit standard exists, organisations can cherry-pick incompatible elements from different frameworks, producing methodological drift rather than genuine coverage.
The record of failure
The list of major audit failures, Wirecard, Carillion, Toshiba, 1MDB, Danske Bank, Luckin Coffee and many others, is long enough to establish a pattern rather than a series of isolated incidents. Research from the London School of Economics suggests the "Three Lines Model" widely used to structure audit accountability is prone to regulatory capture, where roles focus on protecting job titles and providing symbolic cover rather than substantiated oversight, and the model itself has been criticised for lacking empirical evidence of effectiveness.
What audits are, and aren't, good for
Auditing remains well suited to financial statements, internal controls, compliance and IT infrastructure. It is poorly suited to innovation, decision-making under uncertainty, human relationships and complex adaptive systems, precisely the domains organisations most need reliable risk information about today.
Moving beyond the mirror
Organisations that want more than symbolic assurance need to move beyond periodic audits toward continuous monitoring and horizon scanning, involve multidisciplinary specialists (psychology, sociology, organisational behaviour) when assessing culture and climate, prioritise resources by actual impact rather than uniform superficial coverage, and treat audit findings as material for root-cause analysis rather than a compliance certificate. Success requires analytic rigour and information hygiene, not another audit for the shelf.
If your organisation's assurance program is still built around periodic, historical audits rather than continuous, evidence-based risk monitoring, that gap is where the next Wirecard or Carillion starts. Tony Ridley works with boards and audit committees to pressure-test whether current assurance arrangements actually detect emerging risk or simply document compliance. Contact us to discuss your requirements.