1. Financial loss (7.3 on a 10-point scale, with 10 representing the highest risk level
and 1 indicating the lowest)
3. Loss of intellectual property (6.6)
5. Viruses and malware (5.6)
But even though CAEs have had minimizing these risks on their radar screens, not even
half of those surveyed (47 percent) are including social media risk in their current year
audit plans. According to the report, only 25 percent have social media risk included in
their plans this year, up from 20 percent last year, while 31 percent noted they will
include social media risk in next year’s audit plan, down from 35 percent in 2013.
What factors inhibit internal audit’s involvement in assessing social media risk?
According to the survey, the top five factors include:
1. Perceived risk (29 percent)
3. Lack of management support (23 percent)
5. Lack of IT support (15 percent)
For organizations that do have social media policies, significant concerns remain as many
still fail to address critical issues. For example, in cases where respondents said a social
media policy is in place, nearly 30 percent fail to address disclosure of employee
information, and only 66 percent address information security, according to the survey.
For the survey, internal audit professionals were also asked to assess their competency in
49 areas of technical knowledge and then indicate whether they believe their knowledge
is adequate or needs improvement. Based on the findings, the top five areas for technical
knowledge improvement are:
1. Mobile applications
3. Social media applications
5. Data analysis technologies