The Commonplace
Home Papers Evidence Explore Trends Syntheses Digests References Docs 🎲 Workforce Futures
← Papers
Direction, evidence grade, and study type are AI-generated labels (gpt-5-mini), not human-verified. Syntheses are LLM-written. "Tensions" are machine-detected candidates, not confirmed contradictions. A research-acceleration tool, not peer review. How this is built →

Public auditors are moving upstream: performance audits are evolving from after-the-fact compliance reviews into anticipatory, system-level instruments that shape preparedness, procurement and resilience for public-sector cyber and AI systems—though legal mandates and capability gaps limit their role in recovery and long-term adaptation.

Building public sector cyber-resilience through performance audit: responses to cybersecurity risks
Carolyn J. Cordery, Tarek Rana · July 27, 2026 · Accounting Auditing & Accountability Journal
openalex descriptive medium evidence 7/10 relevance Summary only summary available; pdf_status=paywall DOI Source PDF

Structured author observations

Linked only from stored provider relations; the raw author line above is never matched by name.

OpenAlex

Latest observation:

  1. Carolyn J. Cordery provider ID
  2. Tarek Rana provider ID

Semantic Scholar

Latest observation:

  1. Carolyn Cordery provider ID
  2. Tarek Rana provider ID
Supreme Audit Institutions are shifting performance audit from retrospective, siloed compliance checks to anticipatory, system-level practices—creating new audit objects and products that strengthen public-sector cyber-resilience while revealing constraints tied to mandates and capabilities.

Citation observations

Cumulative provider counts captured on specific dates; providers are never combined.

Purpose This study asks which Performance Audit (PA) practices Supreme Audit Institutions (SAIs) prioritize to address cybersecurity risks and how these contribute to public sector cyber-resilience. Design/methodology/approach Drawing on semi-structured interviews with sector participants across several jurisdictions, complemented by documentary analysis and international training materials, our exploratory qualitative design analyses the reconfiguration of PA practices to respond to public sector cyber-resilience imperatives. Findings We show that public sector cyber-resilience goals re-temporalize and re-scale PA. Rather than focusing primarily on retrospective compliance, high-functioning SAIs increasingly orient PA towards anticipatory, system-level and future-facing forms of governance. Empirically, this shift is expressed through new audit objects, new audit practices and new audit products. Combined, these changes reposition PA as a catalytic and infrastructural governance device for building public sector cyber-resilience. Research limitations/implications PA contributes most strongly to cyber-resilience planning and anticipatory preparedness and increasingly to absorptive capacity, while recovery and adaptation remain uneven and often constrained by mandates, capabilities and institutional boundaries. Thus, PA has potential for, and limitations in, governing cybersecurity risk. The imperative of cyber-resilience underscores emerging tensions between independence, collaboration, transparency and security in cyber-related audits. Originality/value What is new here is not “audit adapts to cybersecurity risk”, but that public sector cyber-resilience forces a reconfiguration of what counts as auditable, when audit intervenes (ex-ante or ex-post) and what the audit product is (including guidance, simulations, readiness reviews and cross-system coordination). Thus, PA moves beyond retrospective evaluation towards anticipatory and system-oriented governance.

Summary

Main Finding

Public-sector cyber-resilience is reconfiguring Performance Audit (PA) in Supreme Audit Institutions (SAIs). Rather than remaining primarily retrospective compliance checks, high-functioning SAIs are re-temporalizing and re-scaling PA toward anticipatory, system-level, future-facing governance. This shift creates new audit objects, practices and products—repositioning PA as a catalytic, infrastructural device for building public-sector cyber-resilience, while also exposing limits tied to mandates, capabilities and institutional boundaries.

Key Points

  • Re-temporalization: PA is moving from mostly ex-post compliance reviews toward ex-ante and readiness-oriented activities (planning, preparedness, simulations).
  • Re-scaling: Audits increasingly target system-level risks and cross-cutting dependencies rather than single-agency, siloed controls.
  • New audit objects/practices/products: examples include guidance documents, tabletop exercises/simulations, readiness reviews, cross-system coordination assessments and system-of-systems evaluations.
  • Primary strengths: PA contributes most to cyber-resilience planning, anticipatory preparedness, and growing absorptive capacity (ability to detect and absorb shocks).
  • Primary constraints: Recovery and longer-term adaptation are unevenly addressed—limited by SAI mandates, capability gaps, legal/institutional boundaries and tensions with operational security needs.
  • Governance tensions: Cyber audits surface trade-offs between independence, collaboration, transparency and security (e.g., how much detail to disclose vs. protecting vulnerabilities).
  • Original contribution: The study frames the novelty not as “audit adapts” but as a deeper redefinition of what is auditable, when audits intervene (ex-ante/ex-post), and what constitutes an audit product.

Data & Methods

  • Design: Exploratory qualitative study.
  • Methods: Semi-structured interviews with sector participants across several jurisdictions; documentary analysis; review of international training materials.
  • Analytical focus: How PA practices are reconfigured to meet public-sector cyber-resilience imperatives (temporal and scalar shifts; new artifacts and outputs).
  • Inference scope: Interpretive, cross-jurisdictional insights rather than quantitative generalizability. Findings highlight patterns and emergent practices across SAIs.

Implications for AI Economics

  • Anticipatory audit for public AI deployments: The move toward ex-ante, system-level audits implies SAIs could play a crucial role in assessing and stress-testing public-sector AI systems before deployment, reducing downstream economic losses from failures or systemic harms.
  • Internalizing externalities and systemic risk: System-oriented PA can identify interconnected risks (e.g., AI-driven automation cascades, shared-model dependencies) and thus inform policies that internalize negative externalities across government services.
  • Procurement and market incentives: SAI readiness requirements and audit products (guidance, readiness reviews) will influence procurement specifications and vendor incentives—raising entry costs for suppliers but improving resilience standards and potentially shifting markets toward higher-quality, auditable solutions.
  • Fiscal planning and cost–benefit trade-offs: Anticipatory audits help quantify preparedness investments versus expected costs of cyber/AI incidents, supporting better budgeting, insurance decisions and allocation of scarce public funds.
  • Capacity and labor-market effects: Demand for anticipatory, technical audits increases need for specialized audit skills (data science, machine learning risk assessment), affecting public-sector labor demand and training investments.
  • Limits imply complementary instruments: Because PA has limited reach in recovery/adaptation, economic policy should combine audit-driven preparedness with contingency funding, insurance markets, regulatory backstops and operational incident-response capabilities.
  • Transparency vs. security trade-offs for algorithmic governance: Auditors’ push for transparency in AI systems will interact with security concerns and vendor intellectual property—raising policy questions about mandated disclosure, redaction standards and trust in audit outputs.
  • Distributional and public-value assessment: System-level PA can surface distributional impacts of AI (service access, bias, labor displacement), informing welfare-maximizing interventions and redistribution choices.
  • Recommendations for AI-economic governance:
    • Integrate anticipatory SAIs’ audits into AI lifecycle governance and procurement processes.
    • Develop simulation-based audit products for AI systems (tabletop exercises, red-team scenarios) to assess systemic vulnerabilities.
    • Expand SAI mandates/resources for recovery/adaptation oversight or create formal pathways for cross-institutional coordination post-incident.
    • Invest in auditor technical capacity and create frameworks that balance transparency with security and IP concerns.

Summary takeaway: The reconfigured PA model—anticipatory, system-oriented and product-diverse—offers powerful levers for governing economic risks from public-sector AI and cyber systems, but its effectiveness depends on mandate clarity, capability building, and complementary policy instruments for recovery and adaptation.

Assessment

Paper Typedescriptive Evidence Strengthmedium — The paper presents consistent, cross-jurisdictional qualitative evidence (semi-structured interviews, documentary analysis, training material review) supporting descriptive claims about changing audit practice; however, it lacks representative sampling, quantitative measurement, or causal identification, limiting strength for broader generalization or causal inference. Methods Rigormedium — Methods are appropriate for an exploratory interpretive study (semi-structured interviews, document review, cross-jurisdictional comparison) and yield rich, theory-building insights, but the text lacks details on sampling strategy, interview/sample sizes, coding/analytic procedures, triangulation robustness, and potential researcher reflexivity or bias mitigation. SampleExploratory qualitative sample consisting of semi-structured interviews with sector participants across several jurisdictions (details on number and selection criteria not provided), documentary analysis of SAI outputs and guidance, and review of international training materials; cross-jurisdictional and interpretive rather than statistically representative. Themesgovernance org_design GeneralizabilityFindings rooted in high-functioning SAIs and may not generalize to weaker or differently mandated audit institutions, Cross-jurisdictional but non-representative qualitative sample limits ability to generalize to all countries or legal systems, Context-specific to contemporary cyber and public-AI governance landscapes; may change as technology, threats, and mandates evolve, Focus on public-sector audits—private-sector audit and market dynamics may follow different patterns, Lacks quantitative measures of economic impact, so implications for economic outcomes are inferential rather than empirically validated

Claims (10)

ClaimDirectionOutcomeConfidence & EvidenceDetails
Performance Audit (PA) in high-functioning Supreme Audit Institutions is shifting from primarily retrospective compliance review toward ex-ante, readiness-oriented activities such as planning, preparedness, and simulations. Governance And Regulation positive Temporal orientation of performance-audit activities
Reading fidelity high
Study strength medium
not reported
0.18
Performance audits are increasingly addressing system-level cyber risks and cross-cutting dependencies rather than focusing only on single-agency controls. Governance And Regulation positive Scale and scope of audited cyber-resilience risks
Reading fidelity high
Study strength medium
not reported
0.18
The reconfiguration of PA has produced new audit objects, practices, and products, including guidance documents, tabletop exercises, readiness reviews, cross-system coordination assessments, and system-of-systems evaluations. Organizational Efficiency positive Diversity of performance-audit practices and products
Reading fidelity high
Study strength medium
not reported
0.18
Performance auditing contributes most strongly to cyber-resilience planning, anticipatory preparedness, and the development of absorptive capacity for detecting and absorbing shocks. Organizational Efficiency positive Public-sector cyber-resilience planning, preparedness, and absorptive capacity
Reading fidelity high
Study strength medium
not reported
0.18
Performance auditing addresses recovery and longer-term adaptation unevenly because of SAI mandates, capability gaps, legal and institutional boundaries, and tensions with operational security requirements. Governance And Regulation negative Coverage of cyber-resilience recovery and adaptation
Reading fidelity high
Study strength medium
not reported
0.18
Cyber-resilience audits create governance tensions involving institutional independence, collaboration, transparency, and the need to protect information about vulnerabilities. Ai Safety And Ethics mixed Governance trade-offs in cyber-resilience auditing
Reading fidelity high
Study strength medium
not reported
0.18
The study’s central contribution is to frame the transformation of PA as a redefinition of what is auditable, when audits intervene, and what counts as an audit product, rather than merely as an adaptation of existing audit practice. Governance And Regulation positive Conceptual scope and institutional role of performance auditing
Reading fidelity high
Study strength medium
not reported
0.18
The study implies that anticipatory, system-level performance audits could be used to assess and stress-test public-sector AI systems before deployment, potentially reducing downstream losses from failures or systemic harms. Governance And Regulation positive Pre-deployment assessment of public-sector AI risks
Reading fidelity high
Study strength speculative
not reported
0.03
SAI readiness requirements and audit products could influence public-sector procurement specifications and vendor incentives, potentially increasing supplier entry costs while improving resilience standards. Market Structure mixed Procurement requirements and supplier incentives for cyber- and AI-resilient systems
Reading fidelity high
Study strength speculative
not reported
0.03
Expanding anticipatory and technical auditing is expected to increase demand for specialized public-sector audit skills, including data science and machine-learning risk assessment. Skill Acquisition positive Demand for specialized audit skills and training investment
Reading fidelity high
Study strength speculative
not reported
0.03

Notes