Organizational Resilience: From Crisis Response To A Governance Priority | INTERNAL AUDIT DEPARTMENT audit
» ARTICLE » Organizational Resilience: From Crisis Response to a Governance Priority

Organizational Resilience: From Crisis Response to a Governance Priority

Article search by: Mohd Syairol Azwan Shabudin (Accountant), Internal Audit Division UPM

 

Organizations today operate in an increasingly complex and unpredictable environment. Cybersecurity threats, geopolitical uncertainty, changing economic conditions, rapid technological developments, regulatory requirements, and supply chain disruptions are among the risks that can affect operational continuity and the achievement of organizational objectives.

This environment has transformed organizational resilience from what was once viewed primarily as a crisis management concern into an important component of governance and enterprise risk management.

According to Tone at the Top, published by The Institute of Internal Auditors (The IIA), 47% of internal auditors participating in the 2026 Risk in Focus Global Survey identified business resilience as one of the greatest risks facing organizations. At the same time, 53% identified business resilience as one of the top three areas on which internal audit spends the most time and effort.

What Is Organizational Resilience?

In general, organizational resilience refers to an organization's ability to adapt, continue operating, and achieve its objectives when confronted with unexpected change or disruption.

It involves more than simply maintaining a disaster recovery or business continuity plan.

A resilient organization should be capable of identifying risks early, preparing appropriate responses, maintaining critical functions during disruption, and adapting its approach as the operating environment changes.

 

Resilience Starts With Governance

The IIA emphasizes that organizational resilience should be embedded within a clear governance structure rather than addressed through ad hoc responses after a crisis has occurred.

Important questions for organizations to consider include:

  • Does the organization have a formal resilience strategy that is overseen by its governing body?
  • Are resilience objectives aligned with the organization's overall approach to risk management?
  • Are policies and procedures for critical operational, technological, and financial processes regularly reviewed, tested, and updated?
  • Are incident command, communication, decision-making, and escalation arrangements clearly defined?
  • Do individuals performing critical resilience roles possess the necessary competencies?
  • Have relevant internal and external stakeholders been identified and appropriately engaged in resilience planning?

These considerations demonstrate that resilience cannot be the responsibility of a single department. It requires coordination across management, information technology, finance, human resources, procurement, facilities, risk management, compliance, and assurance providers, including internal audit.

 

The Role of Internal Audit

Internal audit is uniquely positioned to assess how prepared an organization is to respond to disruption.

Through independent assessment, internal audit can evaluate whether critical risks have been identified, governance arrangements are operating effectively, and existing controls are capable of supporting the continuity of critical operations.

Areas that may be considered in an internal audit assessment include:

  • the effectiveness of business continuity arrangements;
  • dependency on critical systems, infrastructure, or suppliers;
  • preparedness for technology and cybersecurity disruptions;
  • succession planning for critical personnel;
  • crisis communication and escalation mechanisms;
  • financial contingency planning; and
  • implementation and testing of recovery arrangements.

The IIA also provides an example of a public-sector internal audit function incorporating risks such as logistical disruption, public health events, and critical infrastructure dependencies into its risk-based audit planning process.

Moving From “Reacting” to “Being Prepared”

Traditional approaches often focus heavily on actions taken after disruption occurs. Today's risk environment, however, requires organizations to move from a reactive approach towards one that emphasizes preparedness and resilience.

This means integrating resilience into strategy, risk management, long-term planning, competency development, resource allocation, and organizational culture.

Internal audit can contribute by providing independent insight into organizational preparedness, risk exposure, and control effectiveness. Such information enables management and governing bodies to make better-informed decisions before an emerging risk develops into a crisis.

 

Conclusion

Organizational resilience is not simply the ability to recover after disruption. It is the ability to anticipate, prepare, adapt, and continue delivering critical functions in an environment of constant change.

From a modern governance perspective, a resilient organization is one that understands its critical risks, establishes clear accountability, regularly tests its controls, and is prepared to adapt when circumstances change.

Internal audit can play an important role by providing assurance and independent insight that helps the organization move beyond reacting to disruption and towards building resilience as a sustained organizational capability.

 

Source: The Institute of Internal Auditors (The IIA), Organizational Resilience: A Critical Board Priority, Tone at the Top, Issue 135, 23 June 2026.

 

Date of Input: 19/08/2026 | Updated: 19/08/2026 | faiz_suparman

MEDIA SHARING

INTERNAL AUDIT DEPARTMENT
Universiti Putra Malaysia
43400 UPM Serdang
Selangor Darul Ehsan
03-9769 1346
03-9769 6176
W, (05:27:47pm-05:32:47pm, 19 Aug 2026)   [*LIVETIMESTAMP*]