Signify Insights
Spotlights
A publishing & interactive-learning property · Philadelphia · est. 2019
Back to Frameworks
FRAMEWORK  ·  Internal Audit  ·  Agile Risk

improve™ 2.0 — The Agile Risk Operating Model

From a diagram to a complete, assessable operating model — built to grow. A closed flywheel on an AI assurance engine, bounded by governance guardrails and measured by the value it delivers.

improve™ 2.0 is Signify Solution's enhanced operating model for agile, AI-augmented assurance. It takes internal audit from a fixed annual plan to a continuous, value-led flywheel — a closed loop running on an AI assurance engine, bounded by governance guardrails and measured by the value it delivers. What follows is the full anatomy: the principles that steer it, the phases and tasks that run it, the rails that keep it safe, a maturity model to place yourself on, and the roles and cadence that make it real.

Piece 01 · The compass

Principles

The behaviours every decision in the flywheel is steered by.

01

Tech-driven

Data, automation and AI do the heavy lifting so people focus on judgement.

02

Value-centric

Every cycle is prioritised by genuine business value and real risk impact.

03

Growth Mindset

With teeth — a capability model that builds T-shaped, data- and AI-literate auditors.

Pieces 02 & 03 · The cycle

Phases & tasks

Consolidated from eight tasks to six — value discovery merged into one backlog, monitoring lifted into the core engine, and the two old wrap-up steps fused into a single retrospective that closes the loop.

Plan & Sense

Value Backlog

A living, prioritised backlog of value propositions and value-stream insights — owned by IA — replacing the fixed annual plan.

AI clusters risk signals and surfaces candidate value items.
Owner: Audit Product OwnerCadence: Continuous · refined each sprintKPI: Coverage of top & emerging risks
Plan & Sense

Risk Sensing

Real-time, dynamic risk and horizon scanning, connected to ERM and the second line, continuously refreshing the backlog.

AI scans data, controls and external signals for emerging risk.
Owner: Risk Sensing Lead + data/AI specialistCadence: ContinuousKPI: Time-to-detect emerging risk
Execute

Sprint Iterations

Time-boxed sprints with defined outcomes, pulling the next highest-value items from the backlog.

AI agentic testing and evidence review accelerate fieldwork.
Owner: Audit Sprint Lead + podCadence: Per sprint (2–4 weeks)KPI: Time-to-assurance
Execute

Improvements Register

A living record of issues, opportunities and control enhancements captured as the work happens.

AI drafts findings and links them to the right controls.
Owner: Audit podCadence: Continuous within the sprintKPI: Critical issues remediated on time
Report & Reflect

Continuous Insight

Always-on dashboards and audience-ready insight, alongside periodic board reporting and an annual opinion.

AI generates dashboards and narrative on demand.
Owner: CAE + Audit Product OwnerCadence: Continuous + quarterly + annualKPI: Board confidence & value realised
Report & Reflect

Retrospective

One review-and-learn ceremony that closes each cycle and feeds lessons straight back into the Value Backlog.

AI mines patterns across cycles to sharpen the backlog.
Owner: Audit Sprint LeadCadence: End of each sprintKPI: Cycle-over-cycle improvement
The always-on core
Engine

AI Assurance Engine

An AI- and data-driven engine running continuous control monitoring and testing beneath every phase — with a human always in the loop.

AI this IS the AI engine; it powers and validates every task on the wheel.
Owner: Data & AI Assurance LeadCadence: Always-onKPI: % of key controls continuously monitored
The fixed rail

Governance guardrails

Agility is bounded, not unbounded. The loop can spin as fast as it likes — but only inside these four rails, the questions every Chief Audit Executive and Audit Committee will ask first.

Rail 01

Independence & Objectivity

IA owns the backlog and the opinion. Collaboration with the business informs the work — it never lets management own the plan.

Rail 02

Risk-Universe Coverage

Value-led prioritisation sits on top of guaranteed coverage of mandatory, regulatory and top enterprise risks. Nothing required gets crowded out.

Rail 03

Quality & Conformance

Iterative work still meets workpaper, evidence and QAIP standards — including a human validating every AI-assisted conclusion — ready for external scrutiny.

Rail 04

Board Assurance

Continuous dashboards are complemented by periodic reporting, escalation of significant issues, and an annual internal audit opinion to the committee.

The journey

Maturity model

A function doesn't switch on agile overnight. improve is the path from a reactive annual plan to an adaptive, AI-augmented function — and a way to assess where you are today.

Level 1

Reactive

Fixed annual plan, point-in-time testing, manual evidence, retrospective reporting.

Level 2

Hybrid

Agile pilots and some continuous monitoring; value focus and tooling emerging.

Level 3

Agile

The improve loop runs end-to-end: value-led, continuous, and closed.

Level 4

Adaptive

An AI assurance engine predicts and prioritises; the function self-improves.

CapabilityReactiveHybridAgileAdaptive
Planning & ValueAnnual planPlan + ad-hocLiving backlogAI-curated backlog
Monitoring & RiskAnnual assessmentPeriodic refreshContinuous sensingPredictive sensing
AI & ToolingManualPoint toolsIntegrated automationAgentic AI engine
Reporting & AssuranceStatic reportsSome dashboardsContinuous + opinionReal-time, AI-generated
Talent & GovernanceSiloed skillsUpskillingT-shaped pods + QAIPAI-literate, self-optimising

Most functions today straddle Level 2 · Hybrid; the five-year target for improve is Level 3 · Agile and beyond.

How it runs

Roles & cadence

An operating model needs owners and a rhythm. These are the agile-audit roles — and the heartbeat that keeps the loop turning.

Audit Product OwnerOwns and prioritises the value backlog — IA-side, protecting independence.
Audit Sprint LeadFacilitates sprints, runs the ceremonies and removes blockers.
Audit Pod / SquadCross-skilled auditors plus data & AI specialists delivering the work.
Chief Audit ExecutiveOwns the opinion, conformance and the Audit Committee relationship.
Audit CommitteeSets coverage expectations and receives the annual internal audit opinion.
Business Risk ChampionsFeed risk signals from the first and second line — never own the plan.
DailyStand-up & signal triage
Per sprint · 2–4 wksBacklog refinement · review · retrospective
QuarterlyValue & coverage review with stakeholders
AnnuallyRisk-universe assessment & board opinion
The horizon

Built for the next five years

Five forces that decide whether agile assurance still works in 2030 — wired into the model, not bolted on.

🤖

Audit WITH AI

Agentic continuous testing, evidence review and drafting accelerate the engine and every sprint.

🛡️

Assurance OVER AI

Model, agent and AI-governance risk become a permanent — and fast-growing — domain in the backlog.

🔗

Connected assurance

Wired into ERM and the second line so risk is sensed dynamically and work is never duplicated.

🌱

Talent & capability

Growth Mindset with teeth: T-shaped auditors, AI literacy, and a product-owner for the backlog.

⚖️

Standards-aligned

Mapped to the IIA's 2024 Global Internal Audit Standards — conformant, not experimental.

Put it to work — assess yourselfAI Governance Self-Assessment