7.2 Emerging Risks and the Impact of Change

Key Takeaways

  • Emerging risks are newly arising or rapidly changing exposures not yet reflected in the activity's risk register, control descriptions, or prior engagement assessment—commonly new technology, regulation, business models, or third parties.
  • Change in people, processes, or systems amplifies residual risk even when inherent process risk is unchanged, because design, ownership, and last-period evidence may no longer hold.
  • Planning responses to material change include additional walk-throughs, dual-period (pre- and post-change) testing, and specialist help when the team lacks the new technology or regulation skill.
  • A system go-live, reorganization, or turnover of a key control owner is a reason to reduce reliance on last year's operating-effectiveness results, not a reason to skip walk-throughs.
  • CIA Part 2 A5c and A5e test the impact of emerging risks and of people/process/system change on the activity under review, not whether the CAE should rewrite the annual plan.
Last updated: August 2026

A completed matrix of financial, operational, IT, cybersecurity, and regulatory risks is only as current as the activity you walked. Emerging risks and change are why CIA Part 2 tests A5c and A5e as separate bullets: the impact of emerging risks on the organization as it shows up in this activity, and the impact of change of people, processes, and systems on risk. Both distort residual risk inside the engagement. Neither is an invitation to reopen the annual plan.

What Makes a Risk "Emerging"

An emerging risk is newly arising or changing fast enough that it is not yet fully reflected in the activity's documented risk register, control descriptions, key risk indicators, or the prior engagement's assessment. The exposure may already be hurting the organization; "emerging" means your evidence and management's inventory lag the fact pattern. Recurring overtime errors from the last three payroll audits are not emerging—they are known residual risk. A same-day-pay fintech that went live after the last payroll audit and is absent from the register is emerging.

Emerging does not mean "unmeasurable." You still estimate likelihood, impact, and velocity with incomplete data. You do not wait for a mature KRI. You do document that uncertainty itself raises residual risk and that procedures must gather more information early—usually extra walk-throughs and data analysis rather than a large sample of a process you do not yet understand.

Four Common Sources of Emerging Risk

The syllabus does not give a closed list, but exam scenarios cluster around four sources that rewrite how the activity operates:

SourcePayroll exampleTreasury exampleWhy residual risk jumps
New technologyRobotic process automation posting time edits; generative AI suggesting pay-code correctionsBank application-programming interface replacing manual payment files; cloud treasury workstationControl descriptions, logs, and last year's samples describe a process that no longer exists
New regulationA state wage-hour or predictive-scheduling rule; a privacy law covering employee dataTightened sanctions lists; updated beneficial-ownership rules on outbound wiresDesign of withholding, classification, or screening may be incomplete; "we always did it this way" is not a control
New business modelSame-day pay; contractor-heavy workforce sitting in the same engine as employeesMarketplace collections; in-house banking for new subsidiariesVolume, cutoff, and counterparties change; old materiality and sample sizes understate exposure
New third partiesHosted payroll vendor; outsourced garnishment deskPayment processor; outsourced sanctions screeningData, access, and availability now sit partly outside management's daily view; assess inside this activity, not only as a future standalone vendor audit

Third parties appear here because a new vendor, processor, or host is an emerging-risk source and a process/system change. You still judge significance for this engagement. You do not skip the issue because a Third-Party Topical Requirement has a later effective date, and you do not assume a full vendor audit is required whenever a processor exists. You ask whether the new party can distort payroll or treasury assertions this period.

Change as a Risk Amplifier

Change is not a sixth risk type. It is an amplifier: inherent process risk may look unchanged ("we still pay employees biweekly"; "we still release wires"), while residual risk rises because the people, process design, or systems that made last year's controls work are different. CIA items love this distinction. A candidate who copies last year's residual ratings after an enterprise-resource-planning (ERP) go-live is testing a process that exists only on paper.

Treat change along three axes the syllabus names—people, processes, and systems—and look for combinations. The highest-risk pattern on the exam is a bundle: new system plus lost control owner plus rewritten workflow in the same window.

Change axisHigh-risk pattern in the activityWhat last year's file no longer proves
PeopleTurnover of the only payroll-bank reconciler; reorganization so the reviewer is now the preparer's peer; temporary dual roles that break segregation of dutiesOperating effectiveness of reviews, reconciliations, and dual authorization
ProcessesNew approval workflow; a step outsourced; a policy rewrite that was not trainedWalk-through maps, narratives, and sample attributes
SystemsPayroll or treasury module go-live; interface or bank-file format change; robotic automation inserted into reconciliationsConfiguration, access, interface integrity, and exception reports

Reorganization and turnover of key control owners are people-change, not culture (Chapter 8). You care because the control may not have an owner who can operate it, not because you are scoring tone at the top. New-system go-live is systems-change: configuration may be wrong, parallel runs may have been skipped, and users may still process on shadow spreadsheets.

Planning Responses: Walk-Throughs, Dual-Period Testing, Specialists

When change or an emerging source is material to the activity, the planning response is to learn the new fact pattern before you lock samples:

  • More walk-throughs. Do not reuse last year's process map. Walk the current path with the current owner, including exception paths (failed bank file, rejected time batch, sanctions hit). If the process split across a go-live, walk both the legacy path still in the period and the new path.
  • Dual-period testing. Split procedures pre-change and post-change rather than drawing one annual sample that buries the go-live. A twenty-five-item sample spread evenly across twelve months can miss that eleven months were stable and six weeks were chaotic. Concentrate extra items in the change window, then test whether the new design actually operates.
  • Specialist help. If the team cannot evaluate a new payroll engine, bank API, ransomware-resilience control, or sanctions engine, bring IT, cybersecurity, or regulatory specialists (or a guest auditor) during planning, not after you have already written a weak work program. Resource limits themselves are Chapter 10; here the point is that change can create a skill gap that, unfilled, leaves high residual risk untested.

Also raise design questions before you test operating effectiveness. A new workflow may have no designed review; testing a sample of "approvals" will not find a missing control. Reduce reliance on prior-period operating-effectiveness results. Historical "no exceptions" is evidence about a different people-process-system combination.

Exam Traps

Three traps show up constantly. First, treating an ERP go-live as "an IT project audit only," so the payroll engagement ignores that pay calculations now come from the new module. The activity under review includes the change that hits its assertions. Second, treating turnover as a human-resources finding to "mention to the CAE" instead of asking whether reconciliations and releases still operate. Third, labeling every unfamiliar risk "emerging" to justify skipping scoring—emerging means score it with wider uncertainty, not park it. Structure and culture still matter to residual risk; those methods wait for Chapter 8. How complete the work program is after you have chosen procedures waits for Chapter 10. This section stops when you have adjusted the risk picture for newness and change and chosen a heavier planning response.

Loading diagram...
Change as a residual-risk amplifier and the planning response
Illustrative residual-risk index before vs after a payroll go-live and control-owner turnover
Test Your Knowledge

Which situation best illustrates an emerging risk for a payroll engagement?

A
B
C
D
Test Your Knowledge

A treasury ERP payments module went live six weeks ago, and the long-time payment-release owner left. What is the best planning response?

A
B
C
D
Test Your Knowledge

Turnover of the only employee who can reconcile the payroll bank account primarily affects risk through which change category, and why does it matter for this engagement?

A
B
C
D