The Global Internal Audit Standards name four things internal audit must deliver: assurance, advisory, insight, and foresight. Foresight is new to that list. The GIAS introduces the word in the Purpose Statement but never explains it. And foresight is the hardest of the four to pin down.
Insight is already well established. The notable IIA NL Practice Guide "Insight & Foresight" (2026) devotes a full chapter to it, and in practice 65% of audit functions deliver it as a separate product. Insight is about understanding what is happening and why. You can assess that today, because the analysis already exists. Foresight is about what is still to come, and only 35% of internal audit functions deliver a recognizable product there. This article is about that harder half.
Foresight, what the word means
English (Oxford English Dictionary, also cited in the Practice Guide): "the ability to predict what is likely to happen and to use that understanding to prepare for the future."
Dutch: the official GIAS translation used in the Purpose Statement renders the term as "vooruitzichten" (outlook), and "inzicht" for insight. A more precise translation would be "vooruitziendheid" or "anticipatievermogen" (foresight capability, anticipatory capacity). The GIAS glossary itself gives no definition. Given this discrepancy, since the translation is not literal and may therefore be interpreted incorrectly, it matters to clarify what "foresight" actually means in the Dutch-language context.
You Cannot Comply With What You Cannot Assess
The GIAS expects foresight but never defines it itself. The Practice Guide does attempt one: it borrows the dictionary definition, as we do here, and devotes a full chapter to it, with methods and examples. But that is a description, not a testable definition. And what you cannot test, you cannot comply with either: it never becomes standard practice. The 35% figure from the survey may well be a consequence of that.
In the one place where the GIAS mentions foresight, the Purpose Statement, the official Dutch translation chooses "vooruitzichten" (outlook):
Internal auditing strengthens the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, and objective assurance, advice, insight, and outlook.
But an outlook is the future picture itself, the what. In English, foresight is precisely the skill, the capability, to see that coming and prepare for it. The translation names what you see and leaves out the skill or capacity to see it, before anyone even defines the term.
That translation choice carries through everything that follows. Read foresight as an output, and you comply by delivering a product, then test it by assessing that product. Read it as a capability or a skill, and it demands a completely different operationalization. We work that out in this article.
The Practice Guide's authors surveyed 31 CAEs. The biggest obstacle they name is competence, cited by nearly 90% of respondents. Evidence comes next. And that is where foresight runs into a problem ordinary audit work does not have: the standards require sufficient evidence, foresight included, while foresight is precisely the kind of thing that resists evidence. The paper flags this and leaves the solution open. For anyone who builds and assesses a quality system, that is not enough. Because that is exactly what we do, build and assess GIAS quality systems, we take this further here.
Why You Cannot Test Foresight on Its Outcome
Internal audit looks in three directions: back (hindsight), at the present (insight), and forward (foresight). All three require skill, but one difference decides everything.

A foresight product is a prediction: a scenario, an early signal, a risk estimated to become material in two years. Whether that prediction was right, you only know once the future arrives. At the moment you deliver it, it is reasoning built on assumptions.
That is where it clashes with Standard 4, due professional care, which requires you to demonstrate diligence now, not later. An auditor who says "my horizon scan was good, because the risk later became real" is offering evidence after the final whistle. The reverse fails too: a risk that never materialized might reflect a successful intervention, or it was never there to begin with. You cannot prove a prediction at the moment you make it.
Insight is different, and that difference is the whole point. Insight concerns the present. Was the root-cause analysis accurate, does the thematic analysis hold up? You assess that now, on the work itself. Foresight has nothing to do with that: foresight concerns something that has yet to happen. It needs a different way of testing.
Foresight Is a Capability, Not a Service
In practice, the conversation quickly slides toward the service catalogue. Do you offer foresight as a separate product, yes or no? The question sounds reasonable, but it is framed wrong. A board member cannot order a "foresight engagement" the way they order an IT audit. They can expect the audit function to tell them in time what is coming. That is a property of the function itself, not a defined product: a capability.
It helps to separate two axes. Assurance and advisory are the work; insight and foresight are the value that results from it. Foresight is not a separate service you order, but a forward-looking form of that value, one that can show up in both assurance and advisory work.

The standards themselves confirm this. The paper links foresight to Standard 9.2, on strategic planning and environmental scanning, and to 9.4, on risk-based planning. Both concern how the audit function is set up, not a single engagement. Testing foresight against 9.2 means assessing the capability of the function itself. Foresight therefore belongs in the function's maturity thinking, not on its product list.
An internal audit function can produce one sharp picture of the future. But if the team does not track sector developments, if the analytical capacity rests on one departing colleague, and if the audit plan stays reactive for lack of time, that picture was a fluke. Capability is the difference between doing it once and being able to do it consistently.
An Assessment Framework for Foresight
If you cannot test the outcome, and with foresight you cannot, test the capability to deliver foresight instead. That capability can be made visible and backed with evidence. The object under review is not the prediction itself, the way an audit's outcome can be reviewed, but the skills of the function that underpin the prediction. We worked this out into an assessment framework along three aspects, each with concrete indicators and its own basis in the GIAS: methods, competencies, and preconditions.
These three aspects are not arbitrary, and they are not simply lifted from the guide either. They follow the ordinary anatomy of a capability, the same logic as people-process-technology. Methods are the capacity to act: the tools you look ahead with. Competencies are the people who master those tools. Preconditions are the room to deploy them: evidence, alignment, and time. Most indicators come directly from the paper and its survey of 31 CAEs. We added several ourselves, because that survey mainly describes what functions do today and not what they fail to do. The survey does not cover everything a mature foresight function needs.
| Aspect | Indicator | Source | Standards basis |
|---|---|---|---|
| Methods | Horizon scanning: systematically tracking internal and external developments for early signals | PG §4.2 | Std 9.2 and 9.4 |
| Scenario analysis: assessing plausible future scenarios and their impact paths | PG §4.2 | ||
| Early-warning indicators with threshold values and escalation routes | PG §4.2 | ||
| Outside-in benchmarking against peers, regulation, and market developments | PG §4.2 | ||
| Trend analysis to identify emerging risks and themes early | PG §4.2 | ||
| Assumption and premortem testing: explicitly holding the prediction and the assumptions beneath it up to scrutiny | Audirium | ||
| Backcasting: reasoning back from an explicit future picture to what is already visible or needed now | Audirium | ||
| Wargaming / response simulation: actively playing out a scenario to test the organization's response and controls | Audirium | ||
| Weak-signal detection: deliberately searching for weak, contrary, or anomalous signals outside the current risk picture | Audirium | ||
| Competencies | Business and sector knowledge within the team | PG §5.1.2 | Std 3 |
| Systems thinking, broad perspective, and strategic thinking capacity | PG §5.1.2 | ||
| Analytical capability: data, patterns, interpretation | PG §5.1.2 | ||
| Acting as a trusted adviser and communicating clearly with the board | PG §5.1.2 | ||
| Knowledge of AI and its application in audit work | PG §5.1.2 | ||
| Scenario thinking and curiosity about future developments | PG §5.1.2 | ||
| Handling uncertainty: reasoning in probabilities and making the degree of certainty explicit | Audirium | ||
| Bias awareness: recognizing and correcting cognitive biases (anchoring, confirmation, recency) in forward-looking assessments | Audirium | ||
| Preconditions | Sufficient evidence underpinning conclusions (due professional care) | PG §5.1.3 | Std 4, 9.2, 11 and 12 |
| Expectations aligned with the board and senior management | PG §5.1.3 | ||
| Formally embedded in the audit plan, with time and capacity secured | PG §5.1.3 | ||
| Access and position: involved early and independently enough in the strategy and risk dialogue for signals to land | Audirium | ||
| Learning loop: checking afterward whether earlier signals came true, to adjust methods and judgment | Audirium | ||
| Independent challenge: forward-looking judgments are challenged before delivery (a challenge session or independent review) | Audirium | ||
| Link to decision and escalation: signals are tied to a pre-agreed decision and escalation path with the board or management | Audirium | ||
| Data and analysis foundation: reliable data and analytical capacity to substantiate forward-looking signals | PG §5.1.1 |
Source: PG = the IIA NL Practice Guide, with the section where the indicator appears (methods from §4.2, competencies from §5.1.2, preconditions from §5.1.1 and §5.1.3); Audirium = added by us.
Two rules apply when using it. You judge readiness per aspect, so three separate outcomes, not one combined score. And that judgment stays outside the function's maturity or performance score. Readiness is not the same as good foresight: a team with every aspect in order can still miss because of a wrong assumption, and a team weak on several aspects can still get one right. The framework shows whether the capability is present. It does not judge whether a specific prediction was correct, because nobody can assess that at the moment the prediction is made. A score there would suggest a certainty that does not exist. Withholding a score is therefore itself a form of due professional care.
Turning It Into Questions
An indicator stays an abstraction until you turn it into a question someone can answer. That is why we built an Insight & Foresight scan into our AQUA tooling. Every indicator becomes a concrete statement, scored on the same five maturity levels as the rest of the scan: ad hoc, developing, structured, embedded, or leading. No open text field and no score from one to ten, but a choice among five that forces a position and that you can back with evidence afterward.
Take an example. The early-warning-indicators indicator becomes the question of whether the function works with indicators that carry threshold values and escalation routes. The answer is not "yes, somewhat," but one of the five levels, with the relevant GIAS standard next to it. Each aspect thereby becomes a short list of such questions, and the state of that list is the readiness of that aspect. The questions stay close to practice: they ask what the function demonstrably does, not what it would like to do. Above the individual aspects, the scan derives a single Insight & Foresight level. Because an average can paper over a blind spot (strong insight methods but no forward-looking method at all), the assessor chooses whether that single level follows the weakest pillar or the average of the aspects.
Not every method is relevant to every function. You can therefore mark an indicator not applicable, and it then no longer counts toward the readiness of that aspect. And because no list is ever complete, you can add your own indicators per aspect: your own method or practice, in your own words. With one click, the AI in the AQUA tooling proposes a substantiated level for it, which you can accept or adjust yourself. The framework stays in charge, but the scan adapts to the practice of the function.
For how such a forward look works in practice, see The strategic risk radar: from picture to working monitoring, which turns horizon scanning and early-warning indicators into concrete, ongoing monitoring.
The AI Improvement Plan
The scan shows where you stand. The AI improvement plan goes further: it reads the scan's outcome and proposes a concrete improvement action for each weak point, with the relevant GIAS standard, a first step, and an estimate of impact and effort. The audit function decides; the AI makes a substantiated proposal, not a judgment.

Accept an action, and it lands directly in the audit function's action tracker inside the AQUA tooling. There, every improvement action gets an owner, a status, and a review step, so the improvement plan does not sit in a document but moves through ordinary follow-up.

In Closing
Foresight is the value that will distinguish the profession in the coming years. But it does not happen by itself. Capture it in observable practices, anchor it in the function's maturity, test the capability and not the prediction, and keep that test visible as a diagnosis rather than hidden inside a number. That way, a word the GIAS left open becomes something an audit function can work with tomorrow.
Audirium's AQUA app includes a readiness scan along these three aspects, linked to the GIAS standards, with the outcome feeding straight into your QA report. The feature just went live and has had limited real-world testing, so I would love to hear how it works for you. Sign up for the Beta Program, or email [email protected].