Blog

Internal Audit Newswire - July 12, 2026

Internal Audit Newswire

Subscribe now to join the Risk Register community:

Hero image

Another massive data breach exposed millions of driver’s license numbers

Source: TechCrunch

Summary: TechCrunch reported on July 8, 2026 that AssuranceAmerica confirmed a data breach affecting roughly 6.99 million people. The company discovered unauthorized access on March 17 and completed its investigation on June 15, finding that hackers stole customers’ names, contact details, driver’s license numbers and policy/claims information. The company disabled compromised credentials and began notifications; state attorney general breach listings show notification letters scheduled for July 10. TechCrunch noted the company did not specify how credentials were stolen and that AssuranceAmerica did not respond to media questions.

Internal Audit Implications: This breach is a high-impact operational and information‑security risk that belongs on the enterprise risk register and should be prioritized in the next audit cycle. Driver’s license numbers and associated policy data are highly sensitive PII; their compromise increases identity‑theft, fraud and remediation liability exposure. Internal audit should treat this as an IT risk and controls review: validate access management and credential hygiene controls (multi‑factor authentication, privileged access reviews, segmentation), confirm incident detection and response timelines (time to detect March 17, investigation completion June 15), and test whether compromised credentials were isolated and rotated as reported. Review data classification and encryption controls for identity documents, retention and least‑privilege rules for agent access, and vendor/third‑party access that might have been involved in the credential theft. Update the risk assessment to reflect elevated threat likelihood and potential financial and reputational impact, and map the event to SOX‑relevant processes where customer data flows intersect financial reporting (e.g., billing, claims reserves) to ensure ICFR coverage where appropriate. Specific audit actions: perform targeted walkthroughs of IAM and identity‑document processing, test privileged account provisioning and deprovisioning, review security monitoring logs for scope and duration of access, and evaluate customer notification and remediation controls. Ensure remediation plans and control remediation timelines are documented and tracked in the risk register; schedule follow‑up testing after remediation milestones are met.


Hero image

SEC Forms New Retail Fraud Working Group

Source: U.S. Securities and Exchange Commission (SEC)

Summary: On July 7, 2026 the SEC announced creation of a Retail Fraud Working Group to strengthen the Division of Enforcement’s ability to identify and combat fraud targeting retail investors. The group will focus on offering frauds, pump‑and‑dump schemes, market manipulation and breaches of duties by advisers and broker‑dealers. It will coordinate across the Commission, partner with other regulators and foreign counterparts, engage in proactive case generation, and support investor outreach. The release names Kate Zoladz and Kim Frederick as leaders and notes the initiative will leverage data and technology.

Internal Audit Implications: The SEC’s new Retail Fraud Working Group signals increased regulatory focus on harms to retail investors and elevates enforcement risk for firms with retail‑facing products and services. For internal audit, this requires updating the risk register and prioritising reviews of governance and operational controls that protect retail customers. Key areas to reassess: customer on‑boarding and KYC/identity verification controls, suitability and product governance (product approvals, marketing claims), transaction monitoring and trade surveillance, client complaint handling and remediation processes, and escalation protocols to compliance and senior management. Internal audit should perform targeted risk‑based assurance over controls that prevent and detect market manipulation and offering fraud, including data integrity checks for surveillance systems, exception management effectiveness, and the design and operating effectiveness of customer‑facing disclosures and marketing controls. Given the SEC’s emphasis on data and technology, auditors should also evaluate data governance: source system fidelity, analytics governance, and model validation for surveillance algorithms. Specific audit actions: update the internal audit plan to include retail fraud scenarios, run walkthroughs and control testing on investor protection controls, test completeness and timeliness of complaint resolution and redress, and review governance forums that own product and marketing approvals. Finally, verify that training, tone at the top, and incentive structures do not create drivers for retail misconduct. Document findings in the risk register and track remediation with management to reduce exposure to regulatory enforcement.


Hero image

Consumers Were Left High and Dry: Attorney General Bonta Secures $45 Million Settlement with Block over Dishonest Practices on Cash App

Source: California Department of Justice - Office of the Attorney General

Summary: On July 8, 2026 California Attorney General Rob Bonta announced a multistate $45 million settlement with Block, Inc. (Cash App) resolving claims by 46 states that Block misled consumers about Cash App’s safety and failed to protect users from fraud. The settlement alleges insufficient identity verification, lack of live phone support, and failure to investigate and reimburse fraud victims. The agreement requires Block to cease misleading claims, provide expanded live customer support, discontinue marketing practices that increased fraud risk, and honour consumer redress provisions from a prior CFPB settlement.

Internal Audit Implications: The multistate enforcement outcome underscores a significant operational and customer‑protection control failure with concrete financial remediation consequences. Internal audit should treat this event as a control and governance failure that must be reflected in the enterprise risk register and in operational risk monitoring. Core control areas for immediate audit attention include customer onboarding and identity‑verification processes (fraud‑resistant KYC), transaction and fraud‑detection systems, customer service/resolution escalation matrices, and marketing‑approval controls that influence user behaviour (e.g., promotions that expose customer identifiers). Assess whether controls for investigating unauthorized transactions and issuing refunds were designed and operating effectively and whether SLAs for customer response matched public claims. Review interfaces between front‑line fraud teams, legal/compliance, and finance to confirm that consumer remediation liabilities are identified, calculated and routed correctly for financial reporting and reserves where applicable. Specific audit steps: perform process walkthroughs of complaint triage and reimbursement, test a sample of fraud investigations for timeliness and documentation, validate change controls around promotional campaigns, and evaluate vendor or third‑party dependencies (customer support providers, identity‑verification vendors). Ensure remediation obligations from the settlement are tracked in the risk register with owners, timelines and control validations; schedule follow‑up testing after Block reports implemented process changes (e.g., 24/7 live support windows and revised KYC). Finally, review board‑level governance and reporting to ensure management is accountable for operational risk reduction and that lessons learned are institutionalized into control design.


Disclaimer: This content is provided for general informational purposes only and does not constitute legal, accounting, tax, investment, or other professional advice. Portions were generated using AI tools from public web sources and may contain errors or omissions — verify important details against the primary sources linked above before relying on them. Any example prompts, scripts, templates, or other artifacts are provided “as is” without warranty of any kind, express or implied; test them on non-production data and apply your own professional judgement before use. Cherry Hill Advisory disclaims all liability for any loss or damage arising from the use of, or reliance on, this content or any artifact it contains.

Subscribe now to join the Risk Register community:

Nk it'