Blog

Internal Audit Newswire - September 06, 2026

Internal Audit Newswire

Subscribe now to join the Risk Register community:

Hero image

Trump v. Thakur

Source: United States Department of Justice — Office of the Solicitor General

Summary: Trump v. Thakur is a petition for writ of certiorari (docket 26-210) filed with the U.S. Supreme Court for the 2025 Term. The Office of the Solicitor General lists an August 17, 2026 filing date; the page indicates a September 1, 2026 update and hosts trump_v_thakur_petn_final.pdf. For internal audit, the significance is process, not posture: high‑profile Supreme Court petitions can influence governance, compliance, and disclosure risk. Tracking such matters supports timely risk assessment, litigation‑related controls, and contingency planning across functions.

Internal Audit Implications: Treat this filing as a trigger to test your legal-risk governance. The control objective is timely identification, assessment, and escalation of litigation that could affect strategy, compliance, or disclosure. Actions this quarter: 1) Verify your litigation intake and docket‑monitoring controls. Test completeness by reconciling legal’s matter list, outside counsel invoices, and enterprise risk register; assess escalation criteria and time to notify the disclosure committee. 2) Review disclosure controls and procedures around legal contingencies—decision logs, documented judgments, and sub‑certifications from legal, finance, and business leaders. 3) Evaluate risk governance: is there a standing cadence for management to brief the audit committee on significant petitions and potential outcomes? Inspect risk committee minutes and board packs for clarity, scenario ranges, and next steps. 4) Assess contingency planning: confirm playbooks for potential injunctions, regulatory shifts, or compliance obligations; check that owners, triggers, and communications protocols are defined and tested. 5) Validate legal hold and records‑preservation controls tied to significant litigation. 6) Where material nonpublic information may arise, review trading blackout and information‑barrier controls. Expect audit committee questions: How do we ensure completeness of legal exposure in the risk register? What are the predefined thresholds for disclosure and when will management reassess? What contingencies and funding are in place for plausible outcomes? Who owns cross‑functional coordination and how is it evidenced? Document gaps and secure commitment dates for remediation and retest.


Hero image

Boston Scientific Hit by Cyberattack, Global Operations Affected

Source: Insurance Journal (reporting Reuters)

Summary: Boston Scientific detected a cybersecurity incident on August 25, 2026 that disrupted global operations, including information systems used to process and ship customer orders. The company activated incident‑response procedures and brought in third‑party cybersecurity specialists to investigate and contain the threat. It has not determined whether the incident is reasonably likely to have a material impact, and the investigation is ongoing. Shares fell about 3.5% in premarket trading after disclosure. The event follows a string of attacks on other healthcare and medtech companies, underscoring sector exposure.

Internal Audit Implications: When order‑processing and shipping systems are disrupted, operational risk and ICFR intersect. Internal audit should immediately assess: 1) Incident‑response governance—review activation timing, roles, contact trees, and approvals in the runbook; test evidence of containment and decision logs. 2) Order‑to‑cash continuity—verify documented manual workarounds, dual reviews for order acceptance and pricing, and reconciliations that bridge orders received, shipments made, and billings during downtime and recovery. 3) Inventory and manufacturing controls—inspect controls over movement authorization, inventory counts/adjustments, and re‑entry of backlogged transactions to prevent duplicate or omitted postings. 4) Data integrity—test post‑incident validations, exception reporting, and reconciliations between shipping logs, carrier data, and ERP once systems resume. 5) Emergency change and access controls—confirm change freezes, approvals for containment‑related changes, and post‑incident privileged access reviews. 6) Third‑party risk—review investigator engagement terms, evidence handling, SLAs for status updates, and dependencies on providers critical to processing and logistics. 7) Disclosure controls—evaluate criteria and cadence for assessing material impact; confirm linkage to the disclosure committee and audit committee updates. Expect audit committee questions: Which processes and geographies were impaired, and for how long? What compensating controls are in place to protect ICFR? How will management validate completeness and accuracy of revenue and inventory after recovery? What is the timeline and ownership for lessons‑learned remediation? Capture gaps, assign owners, and set retest dates now.


Hero image

Breeze Acquisition Corp. II restates IPO balance sheet due to legal-fee accounting error

Source: Filing News (edgar.tools)

Summary: On August 28, 2026, Breeze Acquisition Corp. II’s Audit Committee concluded its audited balance sheet as of the May 14, 2026 IPO closing should no longer be relied upon due to errors in accounting for fees and obligations to legal advisors under an Engagement Letter. Advisors were entitled to up to $3.2 million (cash $2.2 million; equity $1.0 million). Breeze had recorded $1,957,000 accrued expenses, $93,000 additional paid‑in capital, and $1,150,000 as offering costs that should have been a receivable from the sponsor because no services were performed. Management identified a material weakness in contract‑review controls and will restate and remediate.

Internal Audit Implications: This is a textbook ICFR breakdown in contract review and transaction classification. Internal audit should: 1) Map the end‑to‑end process for vendor engagement letters—intake, approval, storage, and accounting. Test completeness by reconciling legal’s contract repository to accounts payable and the general ledger. 2) Evaluate control design that verifies services were performed before accrual or offering‑cost recognition; inspect evidence (service milestones, time entries, countersignatures) for a sample of agreements. 3) Review controls over classification and counterparty—distinguish company obligations from sponsor obligations; test that receivables from the sponsor are identified, recorded, and reconciled. 4) Assess the review control over complex or IPO‑related transactions—presence of accounting memos, second‑level review, and documented sign‑off criteria. 5) Examine period‑end close gating: checklists, segregation of duties, and precision of management review controls over unusual entries. 6) Validate the remediation program: root‑cause analysis, specific control redesign, training, ownership, timelines, and plans for sustained‑operation testing. Expect audit committee questions: Was the error isolated to this engagement or systemic across vendors? How was it detected, and why did existing reviews fail? What population is being re‑examined, on what timeline, and with what resources? What is the path to clear the material weakness and demonstrate effective operation over multiple quarters? Document deficiencies, track remediation to closure, and schedule retesting.


Disclaimer: This content is provided for general informational purposes only and does not constitute legal, accounting, tax, investment, or other professional advice. Portions were generated using AI tools from public web sources and may contain errors or omissions — verify important details against the primary sources linked above before relying on them. Any example prompts, scripts, templates, or other artifacts are provided “as is” without warranty of any kind, express or implied; test them on non-production data and apply your own professional judgement before use. Cherry Hill Advisory disclaims all liability for any loss or damage arising from the use of, or reliance on, this content or any artifact it contains.

Subscribe now to join the Risk Register community: