Blog

Internal Audit Newswire - July 26, 2026

Internal Audit Newswire

Subscribe now to join the Risk Register community:

Hero image

The Coca‑Cola Company files Form 8‑K after Fairlife ransomware disrupts U.S. production

Source: U.S. Securities and Exchange Commission (EDGAR)

Summary: On July 16, 2026 The Coca‑Cola Company filed a Form 8‑K reporting that fairlife, LLC identified unauthorized third‑party access to a portion of its systems "including its production‑related systems" in connection with a ransomware event. Coca‑Cola said it activated incident response and business continuity protocols, engaged outside advisors and law enforcement, and that product quality and safety were not impacted; U.S. production operations were temporarily suspended while Canada was not affected. The company said the full scope and impact remain unknown. ([sec.gov](https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm?utm_source=openai))

Internal Audit Implications: This Form 8‑K represents a material operational‑risk incident that intersects ICFR, IT‑OT segregation, and business continuity controls. The filing confirms unauthorized access to production‑related systems and a temporary suspension of U.S. manufacturing — facts that elevate operational and supply‑chain risk and may create disclosure obligations. Internal audit should prioritize (1) a rapid control mapping of production vs corporate networks to validate segmentation and compensating controls; (2) review of incident response evidence and root‑cause findings to assess whether privileged access, change‑management, or patching gaps enabled the intrusion; (3) assessment of the company’s determination on materiality and disclosure controls under SEC Item 1.05 and whether internal reporting timelines to governance bodies met policy; and (4) testing of business continuity and alternate supply arrangements claimed to prevent product safety impacts. From a SOX readiness and ICFR standpoint, operations‑affecting IT failures that ripple into inventory, revenue recognition, or cost of goods sold warrant focused substantive testing and walk‑forward analyses once systems restore. Internal audit should also consider targeted forensic assurance over third‑party providers, vendor contracts that include breach notification and remediation obligations, and a lessons‑learned audit to confirm remediation execution. These steps will help the board and audit committee see whether risk governance, control design, and control testing are sufficient to limit strategic and operational risk exposure and support timely SOX 404 assessments. ([sec.gov](https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm?utm_source=openai))


Hero image

Justice Department resumes targeted HSR merger review process

Source: U.S. Department of Justice (Antitrust Division)

Summary: On July 23, 2026 the DOJ Antitrust Division announced it is returning to a targeted Second Request process under the Hart‑Scott‑Rodino (HSR) Act. The change restores the historical practice of negotiated timing agreements that prioritize specific information likely to resolve competitive questions and reduce administrative burden; the Division said it may close investigations, modify Second Requests, or require full compliance depending on findings. The release states the approach is intended to accelerate review while preserving enforcement ability. ([justice.gov](https://www.justice.gov/opa/pr/justice-department-resumes-targeted-hsr-merger-review-process))

Internal Audit Implications: The DOJ’s move to resume targeted HSR Second Request investigations changes the operational cadence and risk profile for M&A diligence and post‑deal integration oversight. For internal audit and transaction controls, the practical implications include: (1) control redesign in the M&A playbook to ensure prioritized, high‑quality evidence is available quickly (market analyses, divestiture plans, customer/contracts lists) to satisfy targeted requests; (2) enhanced coordination between legal, competition economics, and finance so that the information prioritized in timing agreements is accurate and auditable; (3) update of transaction governance checklists and approval gates to reflect faster review timelines and potential conditional remedies; and (4) targeted testing of pre‑deal information‑governance controls (data room integrity, version control, privileged access logging) to limit misstatements or omissions that could trigger deeper inquiries. From a risk register perspective, the change reduces transaction timing risk but raises the need for stronger pre‑packaged control evidence — a strategic risk for deals relying on legacy data flows or complex third‑party contracts. Internal audit should schedule assurance over the M&A control environment, specifically control design and control testing around information completeness, confidentiality, and validation of competitive analyses, and ensure the board’s risk oversight reporting includes an M&A readiness metric tied to HSR response capability. ([justice.gov](https://www.justice.gov/opa/pr/justice-department-resumes-targeted-hsr-merger-review-process))


Hero image

Founders of Celsius Network ordered to pay $16.5M to resolve FTC charges

Source: Federal Trade Commission

Summary: On July 20, 2026 the Federal Trade Commission announced stipulated orders requiring former Celsius executives Alexander Mashinsky, Shlomi Daniel Leon and Hanoch Goldstein to pay a combined $16.5 million to resolve charges that they deceptively marketed Celsius deposits as safe, withdrawable at any time, and backed by large insurance and reserves. The FTC said the orders ban the individuals from marketing or selling products used to deposit, exchange, invest or withdraw assets and prohibit misrepresentations and certain disclosures of nonpublic consumer information. The proposed orders were filed in the U.S. District Court for the Southern District of New York. ([ftc.gov](https://www.ftc.gov/news-events/news/press-releases/2026/07/founders-celsius-network-ordered-pay-165-million-resolve-ftc-charges))

Internal Audit Implications: This FTC enforcement outcome underscores governance and compliance risks in fintech product marketing, disclosures, and controls over customer‑facing representations. Internal audit should treat the decision as a prompt to reassess three lines of defence: first, product‑level control design (accuracy of marketing claims, substantiation of yield and reserve statements, and archiving of promotional approvals); second, compliance controls for consumer data handling and Gramm‑Leach‑Bliley Act obligations (consent management, restrictions on sharing nonpublic personal information); and third, oversight and escalation channels to the board and audit committee when product promises intersect with liquidity or balance‑sheet risk. Specific internal audit actions: (1) sample marketing claims vs. underlying contract terms and liquidity/reserve ledgers to validate accuracy and traceability; (2) test change‑control and approval workflows for consumer‑facing disclosures; (3) review vendor and partner attestations that support advertised protections (e.g., insurance policies) and confirm contractual remedies and notification clauses; (4) evaluate the adequacy of customer complaint monitoring and remediation processes that feed into disclosure controls; and (5) ensure remediation plans include metrics for SOX‑relevant disclosure controls and ICFR where consumer promises could affect financial reporting. The ruling also highlights reputational and litigation risk exposures that internal audit should quantify in the risk register and track remediation progress to closure. ([ftc.gov](https://www.ftc.gov/news-events/news/press-releases/2026/07/founders-celsius-network-ordered-pay-165-million-resolve-ftc-charges))


Disclaimer: This content is provided for general informational purposes only and does not constitute legal, accounting, tax, investment, or other professional advice. Portions were generated using AI tools from public web sources and may contain errors or omissions — verify important details against the primary sources linked above before relying on them. Any example prompts, scripts, templates, or other artifacts are provided “as is” without warranty of any kind, express or implied; test them on non-production data and apply your own professional judgement before use. Cherry Hill Advisory disclaims all liability for any loss or damage arising from the use of, or reliance on, this content or any artifact it contains.

Subscribe now to join the Risk Register community:

Nk it'