Gana Misra
By Gana MisraCEO, Finrep
Tue Sep 08 2026

How Internal Audit Should Update Risk Assessments and Audit Plans for DISE and IFRS 18 (2026 Guide)

Share
How Internal Audit Should Update Risk Assessments and Audit Plans for DISE and IFRS 18 (2026 Guide)

How Internal Audit Should Update Risk Assessments and Audit Plans for DISE and IFRS 18 (2026 Guide)

Two regulatory tsunamis are hitting finance functions at the same time, and most internal audit plans were written before either arrived. IFRS 18 is effective 1 January 2027 with mandatory retrospective restatement of 2026 comparatives. DORA has applied to approximately 22,000 EU financial entities since 17 January 2025. If your 2026 audit plan does not explicitly cover both, your audit committee will notice before your next presentation.

This guide gives Chief Audit Executives (CAEs) and internal audit directors a concrete, sequenced walkthrough: what risks each standard creates, how to score and prioritise them, which new audit engagements to add, and how to present the updated plan to the audit committee.

Key takeaway: Because IFRS 18 requires restatement of 2026 comparative data, internal audit must act in 2026, not 2027. A post-implementation audit next year will be too late to catch transition-year control failures.

What Does "DISE" Mean for Internal Audit Purposes?

"DISE" is used in different contexts and the ambiguity creates real planning risk. In the context of EU digital regulation, DISE most commonly refers to the broader Digital Information Security in Europe framework, which encompasses DORA (for financial entities), NIS2 (for essential and important entities across 18 sectors), and the Cyber Resilience Act (for product manufacturers). For financial entities, DORA (Regulation (EU) 2022/2554) is the primary lex specialis. Note that in some Finrep content, "DISE" also refers to the FASB's ASC 2024-03 disaggregation standard for US GAAP reporters. This article covers the EU digital resilience meaning.

For groups with mixed entity types, the NIS2/DORA boundary matters. NIS2 (Directive (EU) 2022/2555) required transposition into national law by 17 October 2024, but Article 1(2) of NIS2 makes DORA the governing regime for in-scope financial entities. Internal audit must map which regulation applies to which legal entity before updating the risk assessment. A bank with a non-financial subsidiary faces both regimes in the same group structure.

What New Risks Do IFRS 18 and DORA Actually Create?

Before you can score risks, you need to be precise about what is genuinely new. Neither standard is a minor tweak.

IFRS 18 Risk Categories

IFRS 18 was issued by the IASB on 9 April 2024 and replaces IAS 1. It does not change recognition or measurement. What it changes is the structure of the statement of profit or loss, the rules for classification, and the disclosure regime for non-GAAP metrics. The IASB confirmed in its Basis for Conclusions that existing audit coverage of revenue recognition and asset valuation does not address these new risks. Internal audit programmes need to add, not just expand.

The four distinct risk categories IFRS 18 creates are:

  1. Classification judgment risk. All income and expenses must be classified into one of five mandatory categories: operating, investing, financing, income taxes, and discontinued operations. The operating category is a residual, meaning anything that does not meet the definition of another category falls here. PwC's IFRS 18 technical guide identifies the investing/operating boundary as the highest-judgment area, particularly interest income for non-financial entities. A non-financial entity that classifies interest income as operating rather than investing, or vice versa, produces a materially different operating profit subtotal.

  2. MPM disclosure risk. Management-defined Performance Measures (MPMs) must now be disclosed in a dedicated note within the audited financial statements, with a reconciliation to the most directly comparable IFRS subtotal, an explanation of why the measure provides useful information, and the tax and non-controlling interest effect. KPMG's IFRS 18 guide flags that the most operationally complex aspect is identifying all measures used in "public communications outside the financial statements" including investor presentations and earnings releases, but excluding oral communications and social media. Management must maintain a complete, live inventory of MPMs. Most do not yet have one. For a detailed walkthrough of the MPM reconciliation mechanics, see Finrep's IFRS 18 MPM reconciliation guide.

  3. Systems and data risk. Deloitte's IAS Plus IFRS 18 resource notes that entities need to update financial reporting systems, chart of accounts, and consolidation tools to support the new P&L classification. This creates IT general controls risk and data integrity risk. BDO's IFRS 18 implementation guide warns that mid-size entities often underestimate this, particularly when ERP systems aggregate P&L items in ways that do not map cleanly to the new categories.

  4. Retrospective restatement risk. EY's IFRS 18 implementation guide warns that entities with complex group structures face particular risk because historical data may not have been captured at the granularity needed to reclassify items under the new categories. The restatement methodology must be documented and consistently applied across all entities in the group.

DORA Risk Categories

DORA imposes four distinct risk areas that internal audit must cover as standing items:

  1. ICT risk management framework gaps. DORA Article 6 requires financial entities to maintain an ICT risk management framework that is documented, reviewed at least annually, and subject to independent audit. Article 6(5) states explicitly: "Financial entities shall establish and implement an ICT risk management framework... The ICT risk management framework shall be subject to internal audit at least once a year." This is a direct legislative mandate, not a best-practice recommendation.

  2. Incident classification and reporting control failures. DORA Article 19 requires financial entities to report major ICT-related incidents to their competent authority. The EBA's incident classification RTS (Commission Delegated Regulation (EU) 2024/1772), published in June 2024, sets the thresholds for what constitutes a "major" incident. Misclassifying a major incident as minor is a significant control failure with direct regulatory consequences.

  3. ICT third-party concentration risk. DORA Articles 28 to 44 require financial entities to maintain a register of all ICT third-party service providers, conduct risk assessments of critical providers, and include mandatory contractual provisions. The EBA's supervisory work programme for 2025 to 2026 identifies ICT third-party risk management as a priority supervisory focus area. Internal audit should align coverage to where supervisors are looking.

  4. TLPT programme governance. DORA Article 26 requires significant financial entities to conduct Threat-Led Penetration Testing (TLPT) at least every three years, using the ECB's TIBER-EU framework as the reference methodology. Internal audit does not conduct TLPT. Its role is to provide independent assurance that the TLPT programme is properly scoped, executed by qualified testers, and that remediation of findings is tracked to completion.

How to Update the Risk Assessment: A Step-by-Step Approach

The IIA's 2024 Global Internal Audit Standards, effective 9 January 2025, are unambiguous. Standard 9.2 on Risk-Based Planning requires the CAE to update the risk-based plan in response to "changes in the regulatory environment" and "significant business initiatives." DORA (a new regulatory requirement) and IFRS 18 (a significant accounting change initiative) both trigger this obligation. The question is how to do it systematically.

Step 1: Expand the Risk Universe

Add the following as distinct risk items in your audit universe. Do not fold them into existing line items or they will be under-resourced and under-scoped.

IFRS 18 risk items to add:

  • P&L classification judgments (operating/investing/financing boundary)
  • MPM identification completeness (inventory of all public communications)
  • MPM disclosure accuracy (reconciliation, tax effect, NCI effect)
  • Systems and chart-of-accounts changes for new P&L structure
  • Retrospective restatement methodology and data completeness
  • Accounting policy decisions and board/committee approval

DORA risk items to add:

  • ICT risk management framework design and operating effectiveness (Article 6 annual audit mandate)
  • ICT incident classification process and reporting controls (Article 19)
  • ICT third-party register completeness and contractual compliance (Articles 28 to 44)
  • TLPT programme scoping, execution, and remediation tracking (Article 26)
  • Board/management body approval and oversight of ICT risk framework (Article 5)

Step 2: Score Inherent Risk

Use your existing inherent risk scoring methodology (typically a combination of financial impact, likelihood, and complexity). Apply it consistently, but note the following calibration points:

Risk ItemInherent Risk DriversSuggested Starting Score
IFRS 18 MPM disclosuresNew concept, no prior controls, management override risk, audited for first timeHigh
IFRS 18 classification judgmentsSignificant judgment, inconsistent prior practice, investor scrutinyHigh
IFRS 18 retrospective restatementData granularity gaps, group complexity, one-time execution riskHigh
IFRS 18 systems changesIT project risk, ERP mapping complexity, UAT adequacyMedium-High
DORA ICT risk framework (Article 6)Legislative mandate, annual cycle, ECB supervisory focusHigh
DORA incident reporting (Article 19)Classification thresholds, regulatory reporting deadlines, misclassification riskHigh
DORA third-party risk (Articles 28-44)EBA supervisory priority, register completeness, contractual gapsHigh
DORA TLPT (Article 26)Three-year cycle, scoping complexity, remediation trackingMedium-High
DORA board governance (Article 5)Formal approval requirement, non-compliance regardless of control qualityMedium

The ECB's 2025 supervisory newsletter noted significant gaps in ICT third-party risk management and TLPT scoping across significant institutions. If your entity has known gaps in these areas, score residual risk as high regardless of inherent risk calibration.

Step 3: Assess the Existing Control Environment

For most entities, the honest answer is that controls for both IFRS 18 and DORA are immature or non-existent. That is not a criticism; it reflects the newness of both regimes. Document the control environment assessment explicitly:

  • Has management completed an IFRS 18 impact assessment? Is it documented?
  • Has an accounting policy decision been made and approved for each classification judgment area?
  • Does a process exist to identify all MPMs used in public communications?
  • Has the DORA ICT risk management framework been formally approved by the management body (Article 5)?
  • Does an ICT third-party register exist and is it complete?
  • Has the incident classification process been tested against the Article 19 RTS thresholds?

Where controls do not yet exist, residual risk equals inherent risk. Score accordingly.

Step 4: Prioritise and Allocate Audit Resources

With finite audit days, you cannot cover everything at maximum depth simultaneously. The prioritisation logic for 2026 is:

  1. IFRS 18 transition readiness review (2026, pre-implementation) takes priority over a post-implementation audit in 2027. Grant Thornton's internal audit IFRS 18 briefing recommends a dedicated readiness review engagement in 2026 to assess whether management's transition project covers all required changes, whether accounting policy decisions are documented, and whether the retrospective restatement methodology is robust. This is a different engagement from the 2027 first-year compliance audit.

  2. DORA Article 6 ICT risk framework audit is mandatory annually. It cannot be deferred or combined with a lighter-touch review. Schedule it as a standing engagement.

  3. DORA third-party risk and incident reporting controls are the EBA's stated supervisory priorities. Score these as high-priority engagements for 2026.

  4. IFRS 18 MPM disclosure controls should be audited before the 2026 year-end close, because MPM disclosures in the 2026 comparative restatement will be subject to external audit scrutiny in 2027.

What Audit Engagements to Add to the 2026 Plan

Here is the concrete audit plan update. These are new engagements, not expansions of existing ones.

New Engagement 1: IFRS 18 Transition Readiness Review (Q2/Q3 2026)

Objective: Provide independent assurance that management's IFRS 18 transition project is complete, accounting policy decisions are documented and approved, and the retrospective restatement methodology is robust.

Key audit procedures:

  • Obtain and assess management's IFRS 18 impact assessment for completeness against the five P&L categories and two mandatory subtotals.
  • Test a sample of P&L line items against the classification criteria, focusing on the investing/operating boundary for interest income and investment-related items.
  • Assess whether an MPM inventory process exists and whether it captures all public communications (investor presentations, earnings releases, management commentary).
  • Review the IT project plan for systems changes: scope, timeline, resources, and user acceptance testing protocols.
  • Assess whether the retrospective restatement methodology is documented, approved, and consistently applied across group entities.
  • Review whether accounting policy decisions have been formally approved by the appropriate governance body.

Timing: Complete by Q3 2026 so findings can be remediated before the 2026 year-end close. The 2026 year-end data will become the comparative period restated under IFRS 18 in the 2027 financial statements.

New Engagement 2: IFRS 18 MPM Controls Audit (Q4 2026)

Objective: Provide assurance that the MPM identification, disclosure preparation, and review controls are designed and operating effectively before the 2026 year-end close.

Key audit procedures:

  • Independently identify MPMs from a sample of public communications (investor day presentations, quarterly earnings releases, analyst briefings) and compare to management's inventory.
  • For each identified MPM, assess whether the required disclosures are complete: description, reconciliation, explanation of usefulness, tax effect, NCI effect.
  • Assess management override risk: are there measures that management has excluded from the MPM inventory that meet the IFRS 18 definition? The revised ISA 240 (2024) signals that MPM disclosures, where management has discretion over labelling and presentation, are a new vector for management override risk.
  • Test the reconciliation arithmetic for accuracy.

New Engagement 3: DORA ICT Risk Management Framework Audit (Annual, Q1 2026)

Objective: Fulfil the Article 6(5) legislative mandate for annual internal audit of the ICT risk management framework.

Key audit procedures:

  • Verify that the ICT risk management framework has been formally approved by the management body (Article 5 requirement). If it has not, this is a non-compliance finding regardless of control quality.
  • Assess whether the framework has been reviewed within the past 12 months (or after any major ICT incident).
  • Test the design and operating effectiveness of key ICT risk controls within the framework.
  • Assess whether the framework covers all DORA-required components: ICT risk identification, protection, detection, response, recovery, and learning.

New Engagement 4: DORA Incident Classification and Reporting Controls (Q2 2026)

Objective: Provide assurance that management's incident classification process correctly applies the Article 19 RTS thresholds and that reporting timelines are met.

Key audit procedures:

  • Obtain the Commission Delegated Regulation (EU) 2024/1772 classification criteria and test a sample of historical incidents against the thresholds.
  • Assess whether any incidents classified as minor should have been classified as major under the RTS criteria.
  • Test whether the reporting timeline controls (initial notification, intermediate report, final report) are documented and have been followed.
  • Assess the interaction with financial reporting: does the finance function receive timely notification of DORA-reportable incidents to evaluate their disclosure implications under IAS 10 (events after the reporting period)?

New Engagement 5: DORA ICT Third-Party Risk Register and Contractual Compliance (Q3 2026)

Objective: Provide assurance that the ICT third-party register is complete and that contractual provisions meet DORA Articles 28 to 44 requirements.

Key audit procedures:

  • Assess the completeness of the ICT third-party register against procurement records, IT asset inventories, and accounts payable data.
  • For critical ICT third-party providers, assess whether mandatory contractual provisions are in place per the EBA/ESAs RTS on subcontracting of critical ICT services.
  • Assess whether risk assessments of critical providers have been completed and documented.
  • Evaluate concentration risk: are there single points of failure in the third-party ICT supply chain?

The DORA-IFRS 18 Interaction: A Risk No One Is Mapping

This is the gap that existing content universally misses. DORA's incident reporting obligations and IFRS 18's MPM disclosure requirements interact in a way that creates a specific, practical risk for finance and internal audit teams.

Under IAS 10 (which IFRS 18 does not change), material ICT incidents occurring after the reporting date but before financial statements are authorised for issue may require disclosure as adjusting or non-adjusting events. A major ICT incident that triggers a DORA Article 19 report to the competent authority is, by definition, significant. The finance function needs a process to receive timely notification of DORA-reportable incidents and evaluate their financial reporting implications.

Separately, if an entity uses a metric like "adjusted EBITDA excluding ICT incident costs" in investor communications, that metric is an MPM under IFRS 18. The ICT incident costs excluded from it must be reconciled and disclosed in the audited financial statements. Internal audit should assess whether the finance function has mapped this connection.

Key takeaway: Internal audit should add a specific procedure to its DORA incident reporting engagement: confirm that the finance function has a documented process to receive DORA incident notifications and assess their IAS 10 and IFRS 18 MPM disclosure implications.

Skills Gap: When to Co-Source

Most internal audit functions do not have deep IFRS technical expertise and cybersecurity expertise in the same team. Be honest about this before finalising the plan.

  • IFRS 18 MPM auditing requires technical IFRS knowledge that many internal audit teams do not have in-house. If your team relies on the finance function to explain what an MPM is, you cannot provide independent assurance on it. Consider a co-sourcing arrangement with a technical accounting specialist for the MPM controls audit.
  • DORA TLPT assurance requires understanding of penetration testing methodologies, TIBER-EU scoping requirements, and tester qualification criteria. Internal audit's role is assurance over the programme, not execution. A guest auditor with cybersecurity credentials may be needed to assess whether the TLPT was properly scoped and executed.
  • DORA third-party risk requires IT audit skills. If your function already has IT auditors, this is within scope. If not, co-sourcing is the practical answer.

Document the skills assessment and the co-sourcing decision in the audit plan. The IIA's Three Lines Model is clear that the third line provides independent assurance. Relying on the second line (risk/compliance functions) to fill a skills gap is not a substitute.

Coordinating with External Auditors

External auditors will be covering IFRS 18 classification judgments and MPM disclosures as part of their 2027 audit. The risk of duplication is real, but so is the risk of gaps.

The practical coordination approach:

  • Share your IFRS 18 readiness review findings with external auditors. They will use them in their risk assessment and may reduce the extent of their own procedures in areas where internal audit has already provided robust coverage.
  • Agree the boundary on MPM testing. Internal audit can cover the completeness of the MPM inventory and the design of disclosure controls. External auditors will test the accuracy of the reconciliation arithmetic as part of their substantive procedures.
  • For DORA, external auditors have limited involvement unless ICT risks are identified as critical audit matters. Internal audit is the primary assurance provider here.

Presenting the Updated Plan to the Audit Committee

Audit committees are already asking about IFRS 18 and DORA readiness. The updated risk assessment and audit plan should address three questions directly:

  1. What is the risk? Name the specific risk items, their inherent risk scores, and the current control environment assessment (immature/developing/established).
  2. What are we doing about it? Name the new engagements, their timing, and the resources allocated (including any co-sourcing arrangements).
  3. What are we not covering and why? Be explicit about resource constraints and the prioritisation logic. An audit committee that understands the trade-offs is better positioned to challenge management than one that receives a plan that appears to cover everything.

Frame the IFRS 18 readiness review as proactive assurance, not reactive compliance. The 2026 transition year is the only opportunity to catch restatement methodology failures before they become 2027 financial statement errors.

FAQ

Does DORA Article 6(5) really require internal audit specifically, or can another function do it? The text of DORA Article 6(5) states the ICT risk management framework must be subject to "internal audit" or "an equivalent independent function." For most regulated financial entities, this means the internal audit function. A compliance or risk function review does not satisfy the requirement because it lacks the independence of the third line.

When should internal audit start covering IFRS 18, in 2026 or 2027? 2026. IFRS 18 requires retrospective restatement of 2026 comparative data. Control failures in the 2026 transition process will produce errors in the 2027 financial statements. A readiness review in Q2/Q3 2026 and an MPM controls audit in Q4 2026 are the minimum coverage. The 2027 post-implementation audit is a separate, additional engagement.

Is DORA an IT audit topic or a financial audit topic? Both. The ICT risk management framework audit (Article 6) and TLPT assurance (Article 26) are IT audit matters. The incident reporting controls audit (Article 19) has a direct financial reporting dimension because DORA-reportable incidents may trigger IAS 10 disclosure obligations and affect IFRS 18 MPM reconciliations. The third-party risk audit (Articles 28 to 44) spans both. Treat DORA as a combined assurance engagement, not a siloed IT audit.

What is the difference between a 2026 IFRS 18 readiness review and a 2027 post-implementation audit? The readiness review assesses whether management's transition project is on track before the standard applies. It covers impact assessment completeness, accounting policy decisions, systems readiness, and restatement methodology. The post-implementation audit in 2027 assesses whether the first set of IFRS 18-compliant financial statements is accurate and complete. Both are necessary; neither substitutes for the other.

How do we handle NIS2 and DORA for a group with mixed entity types? Map each legal entity to the applicable regime first. For EU financial entities (banks, investment firms, insurers, payment institutions, crypto-asset service providers), DORA is the lex specialis and takes precedence over NIS2. For non-financial entities in the same group that are "essential" or "important" under NIS2, NIS2 applies. Document the mapping in the risk assessment and scope each engagement accordingly.

What if management has not yet completed an IFRS 18 impact assessment? This is itself a high-risk finding. EFRAG published its endorsement advice in June 2025, and the 2027 effective date is fixed. An entity without a completed impact assessment in Q3 2026 is behind schedule. Internal audit should report this to the audit committee as a risk management gap, not wait for the readiness review to surface it.

Run your financial reporting on Finrep