Latest articles & Insights

Here, i go beyond the headlines to uncover practical solutions, expert analysis, and proven frameworks to help you win in the age of disruption. Whether you’re a CEO, entrepreneur, or a curious professional, my articles and insights are designed to challenge your thinking, sharpen your strategy, and inspire bold action.

Risk-based internal auditing is dead. You just didn’t attend the funeral

There was once a village plagued by livestock theft. So they hired a watchman.
Each night, he locked the front gate, inspected the fence, and logged everything in his notebook. Every morning, he presented his report: “No breach. All controls in place.”

Yet the goats kept disappearing. Turns out, the thief wasn’t breaking in. He was the trusted farmhand, walking out through the side gate, laughing at the audit reports.

This is the tragedy of Risk-Based Internal auditing today.
We are securing the gates our frameworks told us to monitor, while real risk walks out the side door of flawed decisions, toxic culture, and unchallenged power.

RBIA is not future-ready
Risk-Based Internal Auditing (RBIA) was a good step 20 years ago–a shift from routine compliance to relevance. But it has become a comfort blanket, not a compass.

Here is why it’s failing today’s auditor:
a) It assumes the risk register is reality. It is not. Most top risks are what leaders are willing to disclose, not what keeps them awake at night.
b) It’s too slow. Risks now evolve faster than your quarterly risk review cycle. RBIA is strategic archaeology–digging up yesterday’s threats.
c)  It ignores the battlefield of decisions. Risks do not fall from the sky. They are born at decision tables–in silence, bias, and false consensus.

From risk-based to decision-centric auditing. Forget processes. Forget the heat map. Ask:

“What are the top 10 irreversible decisions made this quarter?”
“Who made them, with what data, and under what pressure?”
“Did anyone challenge them?”
“How did this decision feel to the people involved?”

Most insurance trainers tell a story of an African insurance firm that had solid RBIA. Policies, procedures, and control tests passed with flying colours. Regulators were happy.

Then it collapsed. Why? A single decision, to underprice motor insurance premiums to win market share, had been made by the CEO and endorsed silently by a weak board.

There was no fraud. Just ambition. No red flags. Just a silent misjudgment. RBIA never flagged it because the control existed. Decision-Centric Auditing (DCA) would have.

RBIA makes auditors feel in control. But it lulls executives into false safety.
You passed the audit, but no one challenged the CEO’s magical thinking.
You flagged control weaknesses, but never asked who benefited from them.
Audit without courage is blind trust.

If your internal audit plan still begins with a spreadsheet of risks…You’re too late.
If your team still measures success by “auditable units covered,” you’re not a strategist. The most dangerous risk in your organisation right now is not on your risk register.

It’s in the boardroom. In the silence before a bad decision.

And if you’re not there, auditing that silence, you’ve failed.

What are the top bets your company is making?

I remain, Mr. Strategy

Read the latest articles

Cybersecurity & Risk Management Conference 2025, it’s Finally Here!

Cybersecurity & Risk Management Conference 2025, it’s Finally Here!

The countdown is over! The much-anticipated Cybersecurity & Risk Management Conference 2025,…

Cyber Hygiene is Not an IT Issue but a Culture Issue

Cyber Hygiene is Not an IT Issue but a Culture Issue

Imagine walking into a hospital. The walls are clean, the staff is…

The biggest uninsured risk is your own IT team

The biggest uninsured risk is your own IT team

It began, as most tragedies do, with trust. In a local insurance…

About Mustapha Mugisa

Mustapha B. Mugisa is one of those rare individuals who delivers unparalleled value-based consulting to professionals and corporate entities that demand excellence. As an alumnus of EY and the current President of the Association of Certified Fraud Examiners (ACFE) Uganda Chapter, Mustapha brings a wealth of experience and expertise to every engagement.

Transform your condition

What do you want me to transform today?

Personal Success

I want a clear personal strategy, action plan and be the best version of myself

Speak to Influence

I want to speak to influence, not to just inform. I want to stand out of the crowd. To lead.

Business Growth

I want to master governance secrets for business growth and maximize profits