0 cumulative citations
View corpus contextPublic auditors are moving upstream: performance audits are evolving from after-the-fact compliance reviews into anticipatory, system-level instruments that shape preparedness, procurement and resilience for public-sector cyber and AI systems—though legal mandates and capability gaps limit their role in recovery and long-term adaptation.
Citation observations
Cumulative provider counts captured on specific dates; providers are never combined.
0 cumulative citations
View corpus contextPurpose This study asks which Performance Audit (PA) practices Supreme Audit Institutions (SAIs) prioritize to address cybersecurity risks and how these contribute to public sector cyber-resilience. Design/methodology/approach Drawing on semi-structured interviews with sector participants across several jurisdictions, complemented by documentary analysis and international training materials, our exploratory qualitative design analyses the reconfiguration of PA practices to respond to public sector cyber-resilience imperatives. Findings We show that public sector cyber-resilience goals re-temporalize and re-scale PA. Rather than focusing primarily on retrospective compliance, high-functioning SAIs increasingly orient PA towards anticipatory, system-level and future-facing forms of governance. Empirically, this shift is expressed through new audit objects, new audit practices and new audit products. Combined, these changes reposition PA as a catalytic and infrastructural governance device for building public sector cyber-resilience. Research limitations/implications PA contributes most strongly to cyber-resilience planning and anticipatory preparedness and increasingly to absorptive capacity, while recovery and adaptation remain uneven and often constrained by mandates, capabilities and institutional boundaries. Thus, PA has potential for, and limitations in, governing cybersecurity risk. The imperative of cyber-resilience underscores emerging tensions between independence, collaboration, transparency and security in cyber-related audits. Originality/value What is new here is not “audit adapts to cybersecurity risk”, but that public sector cyber-resilience forces a reconfiguration of what counts as auditable, when audit intervenes (ex-ante or ex-post) and what the audit product is (including guidance, simulations, readiness reviews and cross-system coordination). Thus, PA moves beyond retrospective evaluation towards anticipatory and system-oriented governance.
Summary
Main Finding
Public-sector cyber-resilience is reconfiguring Performance Audit (PA) in Supreme Audit Institutions (SAIs). Rather than remaining primarily retrospective compliance checks, high-functioning SAIs are re-temporalizing and re-scaling PA toward anticipatory, system-level, future-facing governance. This shift creates new audit objects, practices and products—repositioning PA as a catalytic, infrastructural device for building public-sector cyber-resilience, while also exposing limits tied to mandates, capabilities and institutional boundaries.
Key Points
- Re-temporalization: PA is moving from mostly ex-post compliance reviews toward ex-ante and readiness-oriented activities (planning, preparedness, simulations).
- Re-scaling: Audits increasingly target system-level risks and cross-cutting dependencies rather than single-agency, siloed controls.
- New audit objects/practices/products: examples include guidance documents, tabletop exercises/simulations, readiness reviews, cross-system coordination assessments and system-of-systems evaluations.
- Primary strengths: PA contributes most to cyber-resilience planning, anticipatory preparedness, and growing absorptive capacity (ability to detect and absorb shocks).
- Primary constraints: Recovery and longer-term adaptation are unevenly addressed—limited by SAI mandates, capability gaps, legal/institutional boundaries and tensions with operational security needs.
- Governance tensions: Cyber audits surface trade-offs between independence, collaboration, transparency and security (e.g., how much detail to disclose vs. protecting vulnerabilities).
- Original contribution: The study frames the novelty not as “audit adapts” but as a deeper redefinition of what is auditable, when audits intervene (ex-ante/ex-post), and what constitutes an audit product.
Data & Methods
- Design: Exploratory qualitative study.
- Methods: Semi-structured interviews with sector participants across several jurisdictions; documentary analysis; review of international training materials.
- Analytical focus: How PA practices are reconfigured to meet public-sector cyber-resilience imperatives (temporal and scalar shifts; new artifacts and outputs).
- Inference scope: Interpretive, cross-jurisdictional insights rather than quantitative generalizability. Findings highlight patterns and emergent practices across SAIs.
Implications for AI Economics
- Anticipatory audit for public AI deployments: The move toward ex-ante, system-level audits implies SAIs could play a crucial role in assessing and stress-testing public-sector AI systems before deployment, reducing downstream economic losses from failures or systemic harms.
- Internalizing externalities and systemic risk: System-oriented PA can identify interconnected risks (e.g., AI-driven automation cascades, shared-model dependencies) and thus inform policies that internalize negative externalities across government services.
- Procurement and market incentives: SAI readiness requirements and audit products (guidance, readiness reviews) will influence procurement specifications and vendor incentives—raising entry costs for suppliers but improving resilience standards and potentially shifting markets toward higher-quality, auditable solutions.
- Fiscal planning and cost–benefit trade-offs: Anticipatory audits help quantify preparedness investments versus expected costs of cyber/AI incidents, supporting better budgeting, insurance decisions and allocation of scarce public funds.
- Capacity and labor-market effects: Demand for anticipatory, technical audits increases need for specialized audit skills (data science, machine learning risk assessment), affecting public-sector labor demand and training investments.
- Limits imply complementary instruments: Because PA has limited reach in recovery/adaptation, economic policy should combine audit-driven preparedness with contingency funding, insurance markets, regulatory backstops and operational incident-response capabilities.
- Transparency vs. security trade-offs for algorithmic governance: Auditors’ push for transparency in AI systems will interact with security concerns and vendor intellectual property—raising policy questions about mandated disclosure, redaction standards and trust in audit outputs.
- Distributional and public-value assessment: System-level PA can surface distributional impacts of AI (service access, bias, labor displacement), informing welfare-maximizing interventions and redistribution choices.
- Recommendations for AI-economic governance:
- Integrate anticipatory SAIs’ audits into AI lifecycle governance and procurement processes.
- Develop simulation-based audit products for AI systems (tabletop exercises, red-team scenarios) to assess systemic vulnerabilities.
- Expand SAI mandates/resources for recovery/adaptation oversight or create formal pathways for cross-institutional coordination post-incident.
- Invest in auditor technical capacity and create frameworks that balance transparency with security and IP concerns.
Summary takeaway: The reconfigured PA model—anticipatory, system-oriented and product-diverse—offers powerful levers for governing economic risks from public-sector AI and cyber systems, but its effectiveness depends on mandate clarity, capability building, and complementary policy instruments for recovery and adaptation.
Assessment
Claims (10)
| Claim | Direction | Outcome | Confidence & Evidence | Details |
|---|---|---|---|---|
| Performance Audit (PA) in high-functioning Supreme Audit Institutions is shifting from primarily retrospective compliance review toward ex-ante, readiness-oriented activities such as planning, preparedness, and simulations. Governance And Regulation | positive | Temporal orientation of performance-audit activities |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Performance audits are increasingly addressing system-level cyber risks and cross-cutting dependencies rather than focusing only on single-agency controls. Governance And Regulation | positive | Scale and scope of audited cyber-resilience risks |
Reading fidelity
high
Study strength
medium
|
not reported
|
| The reconfiguration of PA has produced new audit objects, practices, and products, including guidance documents, tabletop exercises, readiness reviews, cross-system coordination assessments, and system-of-systems evaluations. Organizational Efficiency | positive | Diversity of performance-audit practices and products |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Performance auditing contributes most strongly to cyber-resilience planning, anticipatory preparedness, and the development of absorptive capacity for detecting and absorbing shocks. Organizational Efficiency | positive | Public-sector cyber-resilience planning, preparedness, and absorptive capacity |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Performance auditing addresses recovery and longer-term adaptation unevenly because of SAI mandates, capability gaps, legal and institutional boundaries, and tensions with operational security requirements. Governance And Regulation | negative | Coverage of cyber-resilience recovery and adaptation |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Cyber-resilience audits create governance tensions involving institutional independence, collaboration, transparency, and the need to protect information about vulnerabilities. Ai Safety And Ethics | mixed | Governance trade-offs in cyber-resilience auditing |
Reading fidelity
high
Study strength
medium
|
not reported
|
| The study’s central contribution is to frame the transformation of PA as a redefinition of what is auditable, when audits intervene, and what counts as an audit product, rather than merely as an adaptation of existing audit practice. Governance And Regulation | positive | Conceptual scope and institutional role of performance auditing |
Reading fidelity
high
Study strength
medium
|
not reported
|
| The study implies that anticipatory, system-level performance audits could be used to assess and stress-test public-sector AI systems before deployment, potentially reducing downstream losses from failures or systemic harms. Governance And Regulation | positive | Pre-deployment assessment of public-sector AI risks |
Reading fidelity
high
Study strength
speculative
|
not reported
|
| SAI readiness requirements and audit products could influence public-sector procurement specifications and vendor incentives, potentially increasing supplier entry costs while improving resilience standards. Market Structure | mixed | Procurement requirements and supplier incentives for cyber- and AI-resilient systems |
Reading fidelity
high
Study strength
speculative
|
not reported
|
| Expanding anticipatory and technical auditing is expected to increase demand for specialized public-sector audit skills, including data science and machine-learning risk assessment. Skill Acquisition | positive | Demand for specialized audit skills and training investment |
Reading fidelity
high
Study strength
speculative
|
not reported
|