An Assessment Framework for Foresight Under GIAS

Insights
Key takeaways

null — summary_bullets is null/empty in the NL source (publications.summary_bullets for id=16), so no bullets exist to translate; left as null to mirror the source.

The Global Internal Audit Standards name four things internal audit must deliver: assurance, advisory, insight, and foresight. Foresight is new to that list. The GIAS introduces the word in the Purpose Statement but never explains it. And foresight is the hardest of the four to pin down.

Insight is already well established. The notable IIA NL Practice Guide "Insight & Foresight" (2026) devotes a full chapter to it, and in practice 65% of audit functions deliver it as a separate product. Insight is about understanding what is happening and why. You can assess that today, because the analysis already exists. Foresight is about what is still to come, and only 35% of internal audit functions deliver a recognizable product there. This article is about that harder half.

Foresight, what the word means

English (Oxford English Dictionary, also cited in the Practice Guide): "the ability to predict what is likely to happen and to use that understanding to prepare for the future."

Dutch: the official GIAS translation used in the Purpose Statement renders the term as "vooruitzichten" (outlook), and "inzicht" for insight. A more precise translation would be "vooruitziendheid" or "anticipatievermogen" (foresight capability, anticipatory capacity). The GIAS glossary itself gives no definition. Given this discrepancy, since the translation is not literal and may therefore be interpreted incorrectly, it matters to clarify what "foresight" actually means in the Dutch-language context.

You Cannot Comply With What You Cannot Assess

The GIAS expects foresight but never defines it itself. The Practice Guide does attempt one: it borrows the dictionary definition, as we do here, and devotes a full chapter to it, with methods and examples. But that is a description, not a testable definition. And what you cannot test, you cannot comply with either: it never becomes standard practice. The 35% figure from the survey may well be a consequence of that.

In the one place where the GIAS mentions foresight, the Purpose Statement, the official Dutch translation chooses "vooruitzichten" (outlook):

Internal auditing strengthens the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, and objective assurance, advice, insight, and outlook.

But an outlook is the future picture itself, the what. In English, foresight is precisely the skill, the capability, to see that coming and prepare for it. The translation names what you see and leaves out the skill or capacity to see it, before anyone even defines the term.

That translation choice carries through everything that follows. Read foresight as an output, and you comply by delivering a product, then test it by assessing that product. Read it as a capability or a skill, and it demands a completely different operationalization. We work that out in this article.

The Practice Guide's authors surveyed 31 CAEs. The biggest obstacle they name is competence, cited by nearly 90% of respondents. Evidence comes next. And that is where foresight runs into a problem ordinary audit work does not have: the standards require sufficient evidence, foresight included, while foresight is precisely the kind of thing that resists evidence. The paper flags this and leaves the solution open. For anyone who builds and assesses a quality system, that is not enough. Because that is exactly what we do, build and assess GIAS quality systems, we take this further here.

Why You Cannot Test Foresight on Its Outcome

Internal audit looks in three directions: back (hindsight), at the present (insight), and forward (foresight). All three require skill, but one difference decides everything.

Hindsight, insight, and foresight as directions of view across time, with testability per direction
Three directions of view across time. All three require capability; only hindsight and insight can be tested on their result.

A foresight product is a prediction: a scenario, an early signal, a risk estimated to become material in two years. Whether that prediction was right, you only know once the future arrives. At the moment you deliver it, it is reasoning built on assumptions.

That is where it clashes with Standard 4, due professional care, which requires you to demonstrate diligence now, not later. An auditor who says "my horizon scan was good, because the risk later became real" is offering evidence after the final whistle. The reverse fails too: a risk that never materialized might reflect a successful intervention, or it was never there to begin with. You cannot prove a prediction at the moment you make it.

Insight is different, and that difference is the whole point. Insight concerns the present. Was the root-cause analysis accurate, does the thematic analysis hold up? You assess that now, on the work itself. Foresight has nothing to do with that: foresight concerns something that has yet to happen. It needs a different way of testing.

Foresight Is a Capability, Not a Service

In practice, the conversation quickly slides toward the service catalogue. Do you offer foresight as a separate product, yes or no? The question sounds reasonable, but it is framed wrong. A board member cannot order a "foresight engagement" the way they order an IT audit. They can expect the audit function to tell them in time what is coming. That is a property of the function itself, not a defined product: a capability.

It helps to separate two axes. Assurance and advisory are the work; insight and foresight are the value that results from it. Foresight is not a separate service you order, but a forward-looking form of that value, one that can show up in both assurance and advisory work.

Matrix: the work (assurance, advisory) against the value (insight, foresight)
The work delivers the value. Foresight runs through both types of work, and testability breaks down exactly on that column.

The standards themselves confirm this. The paper links foresight to Standard 9.2, on strategic planning and environmental scanning, and to 9.4, on risk-based planning. Both concern how the audit function is set up, not a single engagement. Testing foresight against 9.2 means assessing the capability of the function itself. Foresight therefore belongs in the function's maturity thinking, not on its product list.

An internal audit function can produce one sharp picture of the future. But if the team does not track sector developments, if the analytical capacity rests on one departing colleague, and if the audit plan stays reactive for lack of time, that picture was a fluke. Capability is the difference between doing it once and being able to do it consistently.

An Assessment Framework for Foresight

If you cannot test the outcome, and with foresight you cannot, test the capability to deliver foresight instead. That capability can be made visible and backed with evidence. The object under review is not the prediction itself, the way an audit's outcome can be reviewed, but the skills of the function that underpin the prediction. We worked this out into an assessment framework along three aspects, each with concrete indicators and its own basis in the GIAS: methods, competencies, and preconditions.

These three aspects are not arbitrary, and they are not simply lifted from the guide either. They follow the ordinary anatomy of a capability, the same logic as people-process-technology. Methods are the capacity to act: the tools you look ahead with. Competencies are the people who master those tools. Preconditions are the room to deploy them: evidence, alignment, and time. Most indicators come directly from the paper and its survey of 31 CAEs. We added several ourselves, because that survey mainly describes what functions do today and not what they fail to do. The survey does not cover everything a mature foresight function needs.

AspectIndicatorSourceStandards basis
MethodsHorizon scanning: systematically tracking internal and external developments for early signalsPG §4.2Std 9.2 and 9.4
Scenario analysis: assessing plausible future scenarios and their impact pathsPG §4.2
Early-warning indicators with threshold values and escalation routesPG §4.2
Outside-in benchmarking against peers, regulation, and market developmentsPG §4.2
Trend analysis to identify emerging risks and themes earlyPG §4.2
Assumption and premortem testing: explicitly holding the prediction and the assumptions beneath it up to scrutinyAudirium
Backcasting: reasoning back from an explicit future picture to what is already visible or needed nowAudirium
Wargaming / response simulation: actively playing out a scenario to test the organization's response and controlsAudirium
Weak-signal detection: deliberately searching for weak, contrary, or anomalous signals outside the current risk pictureAudirium
CompetenciesBusiness and sector knowledge within the teamPG §5.1.2Std 3
Systems thinking, broad perspective, and strategic thinking capacityPG §5.1.2
Analytical capability: data, patterns, interpretationPG §5.1.2
Acting as a trusted adviser and communicating clearly with the boardPG §5.1.2
Knowledge of AI and its application in audit workPG §5.1.2
Scenario thinking and curiosity about future developmentsPG §5.1.2
Handling uncertainty: reasoning in probabilities and making the degree of certainty explicitAudirium
Bias awareness: recognizing and correcting cognitive biases (anchoring, confirmation, recency) in forward-looking assessmentsAudirium
PreconditionsSufficient evidence underpinning conclusions (due professional care)PG §5.1.3Std 4, 9.2, 11 and 12
Expectations aligned with the board and senior managementPG §5.1.3
Formally embedded in the audit plan, with time and capacity securedPG §5.1.3
Access and position: involved early and independently enough in the strategy and risk dialogue for signals to landAudirium
Learning loop: checking afterward whether earlier signals came true, to adjust methods and judgmentAudirium
Independent challenge: forward-looking judgments are challenged before delivery (a challenge session or independent review)Audirium
Link to decision and escalation: signals are tied to a pre-agreed decision and escalation path with the board or managementAudirium
Data and analysis foundation: reliable data and analytical capacity to substantiate forward-looking signalsPG §5.1.1

Source: PG = the IIA NL Practice Guide, with the section where the indicator appears (methods from §4.2, competencies from §5.1.2, preconditions from §5.1.1 and §5.1.3); Audirium = added by us.

Two rules apply when using it. You judge readiness per aspect, so three separate outcomes, not one combined score. And that judgment stays outside the function's maturity or performance score. Readiness is not the same as good foresight: a team with every aspect in order can still miss because of a wrong assumption, and a team weak on several aspects can still get one right. The framework shows whether the capability is present. It does not judge whether a specific prediction was correct, because nobody can assess that at the moment the prediction is made. A score there would suggest a certainty that does not exist. Withholding a score is therefore itself a form of due professional care.

Turning It Into Questions

An indicator stays an abstraction until you turn it into a question someone can answer. That is why we built an Insight & Foresight scan into our AQUA tooling. Every indicator becomes a concrete statement, scored on the same five maturity levels as the rest of the scan: ad hoc, developing, structured, embedded, or leading. No open text field and no score from one to ten, but a choice among five that forces a position and that you can back with evidence afterward.

Take an example. The early-warning-indicators indicator becomes the question of whether the function works with indicators that carry threshold values and escalation routes. The answer is not "yes, somewhat," but one of the five levels, with the relevant GIAS standard next to it. Each aspect thereby becomes a short list of such questions, and the state of that list is the readiness of that aspect. The questions stay close to practice: they ask what the function demonstrably does, not what it would like to do. Above the individual aspects, the scan derives a single Insight & Foresight level. Because an average can paper over a blind spot (strong insight methods but no forward-looking method at all), the assessor chooses whether that single level follows the weakest pillar or the average of the aspects.

Not every method is relevant to every function. You can therefore mark an indicator not applicable, and it then no longer counts toward the readiness of that aspect. And because no list is ever complete, you can add your own indicators per aspect: your own method or practice, in your own words. With one click, the AI in the AQUA tooling proposes a substantiated level for it, which you can accept or adjust yourself. The framework stays in charge, but the scan adapts to the practice of the function.

For how such a forward look works in practice, see The strategic risk radar: from picture to working monitoring, which turns horizon scanning and early-warning indicators into concrete, ongoing monitoring.

Example of the Insight and Foresight scan in AQUA
Example of the Insight & Foresight scan in the AQUA tooling (demo data). Each aspect gets its own readiness meter; above them, the scan derives a single Insight & Foresight level (weakest pillar or average, by choice). Any item can be marked n/a; at the bottom, a custom indicator carries an AI assessment.

The AI Improvement Plan

The scan shows where you stand. The AI improvement plan goes further: it reads the scan's outcome and proposes a concrete improvement action for each weak point, with the relevant GIAS standard, a first step, and an estimate of impact and effort. The audit function decides; the AI makes a substantiated proposal, not a judgment.

The AI improvement plan: diagnosis and prioritized improvement actions from the readiness scan
The AI improvement plan: the readiness scan yields a diagnosis and prioritized improvement actions per aspect.

Accept an action, and it lands directly in the audit function's action tracker inside the AQUA tooling. There, every improvement action gets an owner, a status, and a review step, so the improvement plan does not sit in a document but moves through ordinary follow-up.

The accepted AI actions in AQUA's action tracker (kanban)
Accepted actions flow through the action tracker: from open to in progress and review, with the GIAS standard each action touches attached.

In Closing

Foresight is the value that will distinguish the profession in the coming years. But it does not happen by itself. Capture it in observable practices, anchor it in the function's maturity, test the capability and not the prediction, and keep that test visible as a diagnosis rather than hidden inside a number. That way, a word the GIAS left open becomes something an audit function can work with tomorrow.

Want to see how far your function has come with foresight?
Audirium's AQUA app includes a readiness scan along these three aspects, linked to the GIAS standards, with the outcome feeding straight into your QA report. The feature just went live and has had limited real-world testing, so I would love to hear how it works for you. Sign up for the Beta Program, or email [email protected].
Back to Insights