Open almost any corporate risk register and you will find people risk on it. Open the internal audit plan for the same organisation and you will usually find nothing that tests it.
This is not an oversight in the ordinary sense. It is structural. People risk is difficult to quantify, the evidence is soft, the processes are owned by a function that reports on its own performance, and auditors who are entirely comfortable testing a payment run will hesitate before testing a promotion decision. So the risk is recorded, rated amber, assigned to the head of human resources, and left there.
Meanwhile, the losses accumulate. Conduct failures that were visible in grievance data years before they became headlines. Capability shortfalls that were forecast and then not funded. Discrimination claims that trace back to a promotion process with no evidence trail. Key technical staff who left with knowledge nobody had captured. Pay structures that drifted out of alignment until the gap became a disclosure problem. Each of these is a control failure. Almost none of them were caught by assurance.
Human capital risk and assurance is the application of governance, risk and audit discipline to the workforce. It covers the identification of people risk across conduct, capability, capacity, culture, compliance and data, the design and testing of controls over reward, conduct, succession and workforce information, and the formation of an independent assurance opinion on whether those controls operate as intended.
Why people risk resists conventional assurance
Three characteristics make the workforce awkward for the traditional assurance model.
The first is that the outcomes are lagging. A financial control failure surfaces at reconciliation. A culture failure surfaces years later, in an employment tribunal or a whistleblowing report, long after the point at which intervention was possible. By the time the risk has materialised, the audit finding is archaeology.
The second is that the data is soft and the definitions are unstable. Turnover can be calculated four different ways within the same organisation. Engagement scores measure whoever chose to respond. Time to hire depends on when the clock starts. An auditor accustomed to a general ledger finds very little to anchor to.
The third, and the most serious, is self-assessment. In most organisations the people function designs the control, operates the control, and reports on whether the control is working. There is no independent challenge anywhere in that chain. If the same arrangement existed in treasury or procurement it would be flagged immediately.
Human capital risk and assurance is the application of governance, risk and audit discipline to the workforce. It covers the identification of people risk, the design and testing of controls over reward, conduct, succession and workforce data, and the formation of an independent assurance opinion on whether those controls operate as intended.
What actually sits in the people risk category
People risk is not one exposure. It is at least six, and they behave differently.
- Conduct risk: harassment, discrimination, bullying, fraud by employees, and the failure of the mechanisms meant to surface them
- Capability risk: the workforce cannot do what the strategy requires, now or on the horizon it requires it
- Capacity risk: there are not enough people, in the right places, at the right time
- Culture risk: the informal system of incentives and norms is driving behaviour the formal system prohibits
- Compliance risk: employment law, working time, right to work, pay equity, and the growing body of workforce disclosure obligation
- Data risk: workforce data held without lawful basis, retained too long, accessible too widely, or processed by an algorithm nobody has validated
Treating these as a single amber line on the register is what allows all six to go untested.
The three lines model, correctly applied
The framework already exists. It is simply not applied here.
The people function is the first line. It owns the processes and it owns the risk within them. That is appropriate, and it is where most organisations stop.
The second line is the risk and compliance function, which should be setting the framework within which people risk is assessed and challenging the first line's own assessment of it. In practice, second line coverage of the workforce is frequently thin, on the grounds that it is a specialist area better left to the specialists. That reasoning would not be accepted anywhere else in the business.
The third line is internal audit, providing independent assurance that the controls operate as intended. This is the line that is most often missing entirely. Where it exists, it tends to test the administrative periphery, such as whether personnel files are complete, rather than the decisions that carry the risk, such as whether the promotion that triggered the grievance followed the approved process and left evidence behind.
What a control test over people processes actually looks like
The objection that people processes cannot be tested does not survive contact with a specific example.
Take reward. The control is that pay decisions follow an approved framework, that exceptions are authorised at the correct level, and that incentive outcomes reconcile to documented performance evidence. Design effectiveness asks whether that framework exists and whether the authority levels are coherent. Operating effectiveness asks for a sample of pay decisions, including every exception in the period, and tests each against the framework and the authorisation record. This is an ordinary control test. It is only unfamiliar.
Take conduct. The control is that concerns raised are recorded, triaged, investigated within a defined period, and closed with a documented outcome and a consequence where one was warranted. Test the population of concerns raised in the period. Check how many were closed without an investigation record. Check how many took longer than the policy allows. Check whether the outcomes vary by the seniority of the person complained about. That last test is uncomfortable, which is precisely why it is worth running.
Take succession. The control is that critical roles are identified and that each has a named, assessed and developed successor. Test the population of roles designated critical. Check how many have no successor identified, how many have a successor who has not been assessed, and how many have a successor who has already left. Organisations are routinely surprised by the answer.
Key risk indicators that lead rather than lag
Assurance over people risk depends on indicators that move before the incident, not after it. Most workforce reporting does the opposite: it counts what has already happened.
Useful leading indicators include regretted attrition concentrated in pivotal roles, grievance volume analysed by manager rather than by division, the proportion of critical roles without an assessed successor, the time taken to close conduct investigations, exception rates in pay decisions, and the proportion of the workforce whose data is being processed by an automated decision tool that has not been validated.
None of these are exotic. All of them are available in systems the organisation already runs. They are simply not being read as risk indicators.
Where this is heading
The direction of travel is not in doubt. Workforce information is moving from internal management reporting into external disclosure, through ESG frameworks, through ISO 30414, and through regulatory requirement. The moment a workforce metric is published, it becomes a statement the organisation can be held to. At that point it needs the same evidential foundation as any other published figure, and somebody independent needs to have looked at it.
Organisations that have never audited the workforce are about to discover that they are disclosing numbers they cannot substantiate. The assurance question is arriving whether or not the audit plan is ready for it.
Building the capability
The skills required are not new. They are the skills of risk identification, control design, testing and assurance reporting, applied to a subject matter that most practitioners have not been trained on. What is missing is the domain knowledge: what the controls over reward and conduct and succession should look like, what evidence is available, where the failures typically hide, and how to form an opinion when the data is softer than an auditor would like.
GRC Academy's Human Capital Governance, Risk and Assurance training course is built around exactly that gap. Delegates construct a people risk register, define an indicator set, design and execute a control testing programme, and draft an assurance opinion on a people process. It is five days of applied work rather than theory.
The workforce is the largest cost in most organisations, the source of most conduct exposure, and the subject of the fastest-growing body of disclosure requirement. It is difficult to justify leaving it as the one category on the register that nobody tests.
Find out more about the Human Capital Governance, Risk and Assurance training course.