2026-09-17
Added
The AFM's September 2026 report analyzes the maturity of internal audit functions at 6 large banks, 4 large insurers, and 5 large financial service providers in the Netherlands, building on previous research from 2021 and 2022. It finds that banks and insurers generally have mature functions but need to explicitly evaluate their contribution to organizational culture and ensure expertise for future risks. Large financial service providers, however, show diverse forms of independent review with significant shortcomings in independence, positioning, and professionalism. The AFM identifies room for further professionalization for these functions, particularly in independence, expertise, and risk-oriented prioritization, emphasizing that functions must align with the enterprise's nature, size, and complexity and contribute to controlled business operations, compliance, and customer interests.
AFM published 3 documents in the last 30 days — get each new one by email the day it lands.
REPORT ANALYSIS
Internal audit banks, insurers and financial service providers: a market exploration In brief - Internal audit plays an important role in controlled and ethical business operations. Our research shows that the maturity of internal audit functions within the financial sector continues to increase. Banks and insurers generally have professionally organized audit functions that contribute to internal control. For large financial service providers, we observe various forms of independent review and assurance, with room for further professionalization. The main task is to further strengthen independent, expert, and risk-oriented functions that contribute to managing risks for consumers and the market. SEPTEMBER | 2026
© AFM 2026 | Internal audit banks, insurers and financial service providers: a market exploration 2
1.1 Introduction
The AFM is committed to fair and transparent financial markets. As an independent conduct supervisor, we contribute to sustainable financial well-being in the Netherlands. Effective internal control in (financial) enterprises, including an effective tone-at-the-top, compliance functions, and audit functions, contribute to this mission. Internal audit plays a crucial role in managing enterprise risks. As a third line, it provides independent and objective assurance on the extent to which risks are controlled, and whether governance and control systems function effectively. This makes internal audit within enterprises an important link for identifying risks that affect customer interests and market integrity. In 2026, we investigated how internal audit relates in practice to the AFM's supervisory priorities. We conducted this research among banks, insurers, and financial service providers. In 2021 and 2022, we conducted similar research. We observed that audit functions, particularly at banks and insurers, were generally mature and professionally organized. At the same time, their contribution to themes relevant to the AFM was often too limited and not structurally embedded. During the current research, we measure progress on the findings from previous studies. In the first half of 2026, we also conducted research, together with De Nederlandsche Bank (DNB), into the effectiveness of internal audit functions at Proprietary Traders (HERs). The results of this research will be discussed with involved parties but offer clear parallels with the results we see among financial service providers. During this period, we also reported on internal audit functions at fund managers (Points of attention for compliance and internal audit functions at managers). Our research focuses on what internal audit actually does and where its focus lies. The population within this research concerns 5 large financial service providers, 6 large banks, and 4 large insurers. The selected enterprises represent a substantial part of the market, allowing us to make relevant sector-wide recommendations. The research consisted of an analysis of audit annual plans and audits performed in 2025, supplemented by a targeted inquiry on three core expectations of the AFM regarding (I) the contribution of the internal audit function to compliance with conduct-specific laws and regulations, (II) the assessment of organizational culture, and (III) the identification of (future) risks for violations of customer interests. We further deepened the insights from the provided information with on-site sessions at the enterprises. We find it important to keep track of the effectiveness of internal audit functions. Periodic research has a dual purpose. It provides insight into the functioning of the role and serves as an incentive for enterprises to more explicitly embed supervisory themes, such as conduct and customer interest, in their audit practice. In addition, recent developments, such as the
introduction of DORA, lead to additional expectations regarding the involvement of internal audit in assessing digital operational resilience. In this report, you will read two sector overviews: one for banks and insurers, and one for (large) financial service providers. Each sector overview contains the findings from the respective sectors. To further assist the sectors, we also provide good practice examples we have observed.
© AFM 2026 | Internal audit banks, insurers and financial service providers: a market exploration 3
2. Sector Overview: Our Findings
2.1 Banks and Insurers
Banks and insurers have long operated within the Three Lines Model and have clear standards for the organization of internal audit. From laws and regulations (including EBA Guidelines on Internal Governance under CRD), enterprises are expected to have an effective internal audit function that operates according to international standards, such as those of the Institute of Internal Auditors (IIA).
This standardization is visibly translated into practice. Internal audit functions generally have an established quality cycle with internal reviews, periodic evaluations, and external validations. The foundation is thus in order, and functions generally operate at a high level of maturity.
This maturity primarily lies in the organization and safeguarding of the process. Audit planning, execution, and reporting are structured and consistent, and internal audit functions are well capable of monitoring and developing their own quality.
The main development task for banks and insurers lies in explicitly evaluating the internal audit function's contribution to organizational culture and in ensuring sufficient knowledge and expertise regarding future risks. Functions often evaluate the generic setup of the audit function and its operation. It is not always clear whether the specific elements concerning organizational culture and preparation for future risks are also part of the evaluations.
The figure below shows the average maturity scores of (I) banks and (II) insurers on the three core expectations of the AFM. It also shows what we, based on documentation and interviews, have determined (III).
Figure: Average maturity per expectation banks/insurers
0 1 2 3 4 5 6
Future risks
Organizational culture
Laws and regulations
(I) Banks (II) Insurers (III) AFM score on banks/insurers Based on these insights, we conclude that the maturity of internal audit functions at banks and insurers aligns with the expected maturity levels. In line with the maturity model, banks and insurers score on average well above a 4 (on a scale of 6) on all expectations. This means that the enterprises have a sound setup and periodically monitor its effectiveness. At the same time, the next development step lies in more consistently and explicitly embedding supervisory priorities within audit practice. Precisely there, the function can make an even greater impact on further contributing to customer interests.
© AFM 2026 | Internal audit banks, insurers and financial service providers: a market exploration 4
2.2 (Large) Financial Service Providers
The market for financial service providers is highly diverse in terms of size, complexity, and business operations. In this research, we therefore focused on a limited group of large financial service providers belonging to the top end of the Dutch market. Unlike banks and insurers, financial service providers are often not legally obliged to establish an independent internal audit function. However, the organization of governance, risk management, and internal control must align with the nature, size, and complexity of the enterprise. For large financial service providers, this means an appropriate level of independent review and assurance, while for the majority of the sector, the focus is on demonstrating sufficient insight into risks, compliance, and controlled and ethical business operations. Among large financial service providers, we observe diverse forms of independent review and assurance. In several cases, functions are designated as internal audit functions but do not fully meet the characteristics typically associated with an independent third line, for example, regarding positioning, mandate, or independence. The absence of a direct legal obligation to establish an internal audit function explains some of these differences. At the same time, we expect that enterprises choosing to establish an internal audit function will design it in a way that fits the role and responsibilities of an independent third line. Particularly in the areas of independence, positioning, and professionalism, we observe significant shortcomings. In several cases, work is performed by employees who are insufficiently independent of the processes they assess, a formal audit mandate is lacking, or work is only partially conducted according to generally accepted audit standards. Although the activities performed often yield valuable insights for the organization, these functions therefore do not qualify as fully-fledged internal audit functions. Where there is a professionally organized audit function, we observe another point of attention. These functions generally meet the basic requirements of independence and possess sufficient audit methodology and professional competence. At the same time, we note that the number of audits performed is relatively limited and that topics directly affecting customer interests do not always receive sufficient priority within audit planning. The causes for this appear to be diverse. In some cases, we see that the size of the audit function does not match the size and complexity of the organization. This necessitates choices in the coverage of the audit universe. Additionally, we observe internationally organized functions that primarily deploy their capacity for group priorities, leading to less attention for Dutch supervisory priorities. Finally, we note that knowledge and experience on specific supervision-relevant themes, such as customer interest, product governance, and conduct, are not always sufficiently present within
the audit function. We also observe that smaller audit functions do not always have the same economies of scale as larger functions, for example, in quality assurance, knowledge development, and specialization. The consequence is that important risks for consumers are not always visibly reflected in audit practice. Although topics such as operational risks, IT, and governance are frequently audited, we see less explicit attention to the question of how products, processes, and decision-making actually contribute to good customer outcomes. This leaves a significant part of the internal audit function's potential untapped. The way large financial service providers have organized independent review and assurance varies widely. The AFM sees room for further professionalization of these functions, particularly in the areas of independence, expertise, and risk-oriented prioritization. It applies that
© AFM 2026 | Internal audit banks, insurers and financial service providers: a market exploration 5 the organization must be appropriate to the nature, size, and complexity of the enterprise and must contribute to controlled business operations, compliance with laws and regulations, and customer interests.
© AFM 2026 | Internal audit banks, insurers and financial service providers: a market exploration 6
3. Good Practice Examples
3.1 Alignment with IIA Standards and Function Organization
Strong internal audit functions are characterized by clear alignment with international standards. In practice, we see functions that operate in accordance with the IIA Global Internal Audit Standards (GIAS) and use topical standards for specific risk areas. These functions have well-structured audit universes, risk assessments, and planning, and ensure consistent execution and quality monitoring.
It is notable that these functions have sufficient capacity and clear governance. We often see staffing that aligns with a ratio of approximately 1 auditor per 150 employees, under the direction of an independent chief audit executive (CAE). This CAE plays a central role in ensuring quality and monitoring effectiveness throughout the entire audit cycle. Additionally, the CAE is well-positioned to be (in)formally aware of important developments within the enterprise. Precisely this combination of standards, capacity, and clear responsibilities ensures that the function performs stably and can develop in a targeted manner. International or group-driven audit functions explicitly pay attention to Dutch risks and supervisory themes. Although these functions often work with central standards, methodologies, and specialist expertise, they ensure that local risks, relevant laws and regulations, and customer interest themes are visibly incorporated into risk analysis, audit planning, and audit execution.
3.2 Explicit Continuous Improvement
Internal audit functions that score highest in this research's benchmark are explicitly aware of the improvement points being pursued. These functions not only look at the organization they supervise but also at themselves. Annual SWOT analyses are conducted, strategic personnel analyses are performed, strategy sessions are held, and/or comparisons are made with other functions. The identified actions from these insights are then translated into the annual plan, and progress on these actions is effectively monitored. In this way, these functions explicitly ensure the continuous improvement of the function.
3.3 Specific Analysis from the Customer Interest Perspective
Progressive functions explicitly make room for an analysis from the customer interest perspective. Instead of implicitly including this theme in risk identification or audit planning, the topic is analyzed separately, for example, through working groups within the audit function. This systematically examines risks related to customer interest/duty of care and how these risks develop.
This analysis leads to sharper choices in audit practice. Functions explicitly ask whether they are doing enough in this domain, whether the topic is visibly reflected in the audit universe, and whether the planned coverage aligns with the risks. They also look ahead to new or emerging risks. This helps to not only retrospectively assess customer interest but also to make it part of audit planning.
© AFM 2026 | Internal audit banks, insurers and financial service providers: a market exploration 7
3.4 Use of AI and Data Analysis
Within internal audit, a clear movement towards the use of AI and data analysis is visible. More and more functions are using advanced analysis tools to identify risks, detect deviations, and organize audits more efficiently. This visibly contributes to the function's effectiveness and depth.
At the same time, ensuring audit quality remains paramount. The use of technology requires continuous attention to traditional audit principles such as integrity, completeness, and accuracy of information. The independence of the third line must also be maintained. Effective functions find this balance: they utilize technology where it adds value, without compromising the reliability and/or dilution of their assurance function. See also our publication 12 building blocks for safer use of advanced (GenAI) audit tools. An effective way to work more data-driven is to properly manage and monitor one's own audit processes. More and more functions gain insight into their own performance and the status of various audits being conducted through strong dashboarding. We also see functions that effectively combine their own insights and risk assessments from the first/second line and use them as a basis for the annual risk analysis. It is notable that not always the most complex/AI-driven analyses yield the most value.
3.5 Behavioral Elements in the Audit
We see that more and more functions have a strong foundation for incorporating behavior-specific elements into audits. Effective functions combine behavioral insights from root-cause analyses, specific behavioral audits, and other indicators into a periodic overarching insight for primary stakeholders. Functions that are more advanced explicitly make these insights clear to management and are able to link actions to them. On December 15, 2026, the IIA Topical Requirement Organizational Behavior will become effective. We expect this guideline to provide direction in audits related to behavior.
3.6 Translation to Customer Value
Effective internal audit functions explicitly link their activities to the value for the end customer. This requires positioning close to business operations and in connection with management. Audits are not only performed from a process or compliance perspective but also assessed for their relevance to customer interests. In practice, we see that these functions explicitly translate their work into impact for the consumer. In audits, they ask why a particular topic matters to the end customer and how findings contribute to better outcomes for consumers. This approach helps to sharpen priorities and increases the visibility and relevance of the audit function within the organization.
3.7 Periodic Judgment on Internal Control
A number of functions go beyond reporting on individual findings and periodically provide an overall judgment on internal control. This happens, for example, on a quarterly basis, where Internal Audit makes a clear statement about the effectiveness of control as a whole.
We see this as a valuable development. While many functions report on outstanding issues and follow-up, an overarching judgment is often missing. Precisely this integrated perspective offers management and supervisors better insight into the state of the organization. It also compels the audit function
© AFM 2026 | Internal audit banks, insurers and financial service providers: a market exploration 8 moreover, to assess findings in context and explicitly weigh what these mean for the effectiveness of complete internal control.
Sign in to read the rest — it's free
Source: Autoriteit Financiele Markten — original document
Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
2026-09-15
Managers of Investment Institutions in Focus on Wwft and Sw Compliance
2026-08-24
Complaints Inquiry 2026: Insurance Providers 2025
2026-08-06
DORA-update 7
2026-07-22
From design to delivery – five enablers for effective European supervision
2026-07-10
IKO: A Sharp Instrument Yields a Sharp Image
2026-07-10
The Path to Digital Autonomy - More Control Over Digital Dependencies
2026-07-09
Do you want an insurance for that? - Online steering towards embedded insurance
2026-06-15
Interpretation of Articles 16 and 16b of the Wta
More like this from AFM
AFM published 3 documents in the last 30 days. We email you each new one the day it's published.