With Version 2.2 of DIIR Audit Standard No. 2, the focus of the audit of the risk management system shifts noticeably: away from the question of whether risks are merely identified, assessed, and reported, toward the question of whether risk information actually reaches the decision-makers who set the course for the business. The new Chapter 7 establishes the preparation of significant business decisions as a distinct area of focus for internal audit. This transforms a principle already laid out in Version 2.1 into a significantly more concrete audit criterion.
A Standard with a Significantly Broader Scope
DIIR Audit Standard No. 2 views risk management as a management responsibility and an integral part of business, planning, and monitoring processes. In doing so, Internal Audit does not merely examine the risk management function as an organizational unit. The subject of the audit is the risk management system in the broader sense—that is, the interplay of governance, strategy, risk identification, assessment, aggregation, control, monitoring, reporting, and decision preparation.
Version 2.2, dated August 2026, maintains this systems-based perspective but refines it in several areas. This is particularly evident in the preamble: The "decision-oriented focus of risk management" is explicitly identified as the subject of the audit. For significant business decisions, it should be apparent during the preparation phase which opportunities and threats are associated with the decision and how it alters the company's risk profile. The standard therefore devotes a separate Chapter 7 (paras. 82–95) to this topic for the first time.
The core of the change is thus not that companies must suddenly take risks into account in their decisions. This was already laid out in Version 2.1. What is new, rather, is that DIIR significantly operationalizes the scope of the audit: What constitutes a business decision? How is the decision-making process structured? What information must be available? How should alternatives be compared? How must neutrality and documentation be organized? And how does Internal Audit examine not only individual cases but also the underlying management system?
The most important change compared to Version 2.1
Version 2.1 from 2022 already incorporated the decision-oriented perspective in several places. Even then, it required that the impact on future risk exposure be made transparent when preparing material business decisions. The inclusion of risk analyses in business decisions pursuant to Section 93 of the German Stock Corporation Act (AktG) was also explicitly part of the company-wide understanding of risk management.
Version 2.2, however, takes a decisive step further. Chapter 7 describes, for the first time, a complete audit trail for "business decisions involving risk." The starting point is the Business Judgment Rule: In the case of business decisions of " " significance, the governing body should act on the basis of appropriate information. The standard notes that this includes, in particular, information about the risks associated with the decision. What is decisive is not only the risk analysis of the project or investment in isolation, but also the question of how the decision alters the company's overall risk exposure and, consequently, the extent to which its continued existence may be threatened.
This is technically significant because it brings risk aggregation and the decision-making process together. An investment may appear plausible when considered on its own, yet, when combined with existing risks, it can place a critical strain on the company's risk-bearing capacity. It is precisely this perspective that should be made visible in decision-oriented risk management.
| Topic | Version 2.1 | Version 2.2 |
|---|---|---|
| Business Decisions | Decision-making orientation already incorporated into the concept of risk management, method review, and reporting. | A separate Chapter 7 covering scope, process model, system audit, case-by-case review, information requirements, and implementation/review aspects. |
| Business Judgment Rule | Mentioned as part of the legal context. | Operationalized much more strongly than audit logic; evidence of adequate information and robust documentation are explicitly emphasized. |
| Decision-Making Process | No separate, end-to-end audit process. | Seven phases: need for a decision, information gathering, alternatives, comparison, selection, implementation, review. |
| Overall Risk Scope | Risk aggregation and the impact of decisions have already been addressed. | Clear connection: A decision must be assessed in terms of how it affects the overall risk exposure and potential threats to the organization's continued existence. |
| Global Internal Audit Standards | Reference to the IIA Standards in effect at that time, particularly Standard 2120. | Update to the Global Internal Audit Standards, including Standard 9.4 and the current definition of internal audit. |
| Data Quality | Information systems and data as part of the system audit. | Data integrity is explicitly mentioned as an audit consideration. |
| Risk Culture | An open approach to risk as a foundation. | Practical audit guidance has been added, e.g., whistleblower systems, "tone-at-the-top" analysis, and risk awareness surveys. |
| Emerging Risks | Rare/extreme risks and new risks are already relevant. | Explicit requirement for systematic monitoring of emerging risks, such as horizon scanning and weak signal analysis. |
| External Reporting | Focus on internal and statutory risk reporting. | Additional explicit reference to CSRD/ESRS and material sustainability risks. |
| Audit Guidance | RMS Audit Guide. | Additionally, a standalone audit guide titled "Business Decisions" as an Excel tool. |
Table 01: The Most Important Changes from Version 2.1 to 2.2
What "Decision-Oriented Risk Management" Actually Means
Decision-oriented risk management is not an additional reporting loop. It changes the purpose of risk information. Risks are not merely recorded to maintain a risk inventory or to prepare a periodic report. They are analyzed in such a way that decision-makers can compare alternative courses of action under conditions of uncertainty.
To this end, the standard combines three levels. First, the opportunities and threats associated with a decision must be identified and—where appropriate—quantified. Second, different courses of action must be made comparable. Third, the impact of the decision on the overall risk position must be considered. It is precisely at this third level that a decision-oriented approach differs from an isolated project or investment risk analysis.
The attached DIIR assessment guide for business decisions elaborates on this concept. Among other things, it calls for a clear definition of objectives, systematic risk identification, neutral information gathering, data integrity, appropriate evaluation matrices, objective weighting of decision criteria, and the quantification of opportunities, benefits, and risks. For the final decision proposal, it identifies key elements such as the initial situation and objectives, alternatives, projected impacts, costs and benefits, underlying assumptions, and the effect on earnings and overall business risk.
In this way, risk management becomes an integral part of the decision-making framework. Its quality is evident not only in the risk report but also in whether a proposal for an investment, acquisition, market expansion, or new technology transparently addresses the uncertainties relevant to the decision.
What decisions does Chapter 7 cover?
The standard deliberately narrows the scope of the new audit subject. Significant business decisions are defined as strategic—rather than operational or tactical—decisions made by management bodies. Examples include new business areas, international expansion, major production facilities or technologies, mergers, acquisitions, partnerships, new product lines or business models, and fundamental strategic adjustments.
Decisions that are predetermined with no real discretion—particularly in the case of mandatory compliance requirements—do not fall under this framework. Thus, the audit does not focus on every management decision, but rather on those decisions where there is business discretion and whose scope requires correspondingly thorough preparation.
Of particular relevance to Internal Audit is that Version 2.2 distinguishes between two levels: the audit of the management system or decision-making process, and the audit of specific decision proposals. Case-by-case audits may be conducted on a random basis as part of a system audit or as a separate audit engagement.
The auditor is not intended to substitute for the business decision in terms of content. Rather, the subject of the audit is whether the process is fundamentally suitable for producing appropriately prepared decisions—and whether specific proposals meet the essential requirements. The standard also emphasizes the burden of proof resting with management and, consequently, addresses the ability to provide evidence in the event of a dispute. A decision proposal should be complete, transparent, and free from inappropriate distortions. As a possible governance measure, the standard cites the responsibility of a neutral function or an independent quality assurance process.
The Seven Phases of the Decision-Making Process as a New Audit Roadmap
The process model introduced in Version 2.2 is particularly well-suited to audit practice. It comprises seven steps: determining the need for a decision, gathering information, identifying alternatives, comparing alternatives, making a decision or selecting an alternative, implementing the decision, and reviewing the decision.
During the phase of identifying the need for a decision, one must examine, among other things, whether the company has clearly defined which decisions are considered business decisions and what responsibilities exist. The information gathering phase focuses on relevant data, appropriate effort, and the involvement of suitable functions. Risk analyses can be prepared by the risk management function itself or—in accordance with its methodological guidelines—by functions such as Controlling or M&A. The key consideration remains the ability to assess whether additional risks trigger a critical increase in the level of threat to the company's continued existence.
When identifying and comparing alternatives, the standard requires a reasonable comparison, clear criteria, and an evaluation matrix. During the selection phase, it must be verified whether the decision proposal is grounded in a reasonable proportion to the risk level and investment volume. The risk perspective does not end once a decision has been made: identified risks should be transferred to operational risk management; implementation and subsequent review may also be subject to audit.
What Characterizes an Effective Risk Management System According to DIIR
Version 2.2 defines effectiveness not in abstract terms, but within the context of a coherent system. An appropriate risk management system is based, in particular, on risk management strategies, suitable measures, and internal controls. It is effective when the risk management phases are carried out in a sequential and proper manner, the achievement of corporate objectives is supported with sufficient probability, significant events are identified, and appropriate responses can be made.
Internal audit should therefore evaluate the design, implementation, and effectiveness over a defined audit period. Appropriateness encompasses methodology, organization, assignment of responsibilities, processes, information systems—including storage, transmission, and data integrity—documentation, adaptability, and integration into monitoring and management systems. Effectiveness additionally requires evidence that the system actually achieved the intended results during the audit period.
1. Governance, Organization, and Risk Culture
Responsibility for the risk management system lies with senior management. It establishes risk strategy and framework guidelines, ensures organizational implementation, and is responsible for neutral and timely risk reporting. The risk management phases should function across organizational units and hierarchical levels.
A new emphasis is placed on the verifiability of the risk culture. The standard maintains the statement that an open approach to opportunities and threats forms the basis of an effective system, but adds specific audit options: evaluation of whistleblower systems, "tone-at-the-top" analyses, and employee surveys on risk awareness. Risk culture thus evolves from a rather abstract governance requirement into an auditable system element.
2. Risk Strategy, Tolerance, and Risk-Bearing Capacity
The risk strategy must be derived from the overall strategy. It should link risk appetite, risk coverage potential, management objectives, and measures, and be specific enough to enable operational risk management to be derived from it.
Audit considerations include risk tolerances or limits, the risk-bearing capacity concept, thresholds for corrective actions, reporting to the supervisory body, and an operational definition of a development that threatens the entity's continued existence. The standard distinguishes between risk-bearing capacity—related to the avoidance of a development that threatens the company's existence—and risk tolerance as a more conservative safety target set by management.
3. Risk Identification: More Integrated and Forward-Looking
Risk identification does not begin with the risk register, but with objectives and strategic decisions. The DIIR requires a methodical identification of relevant risks and a regular risk inventory. Risks that become apparent in planning, budgeting, quality management, information security, or other management systems should be incorporated into risk management.
Version 2.2 explicitly adds the systematic monitoring of emerging risks. For early detection, the standard cites horizon scanning and weak signal analysis as examples. This shifts the focus more strongly toward risks that are not yet visible in historical loss data or established risk categories.
4. Risk Analysis and Aggregation: The Overall Risk Scope Remains the Core
The DIIR remains quantitatively rigorous. Risks should be assessed in terms of cause-and-effect relationships, probability of occurrence, and quantitative impacts. Net risks take existing mitigation measures into account; gross risks can be useful for transparency and the identification of key controls. Uncertain impacts should generally be described as a range or through appropriate probability distributions.
Risk aggregation is particularly crucial. According to the standard, individual risks cannot simply be added together; combination effects and stochastic dependencies must be taken into account. The standard cites Monte Carlo simulations and equivalent stochastic methods as options. Aggregation should be aligned with corporate planning so that dependencies and risk coverage potential are appropriately reflected. This is particularly crucial for decision-making: Only when the additional risk contribution of an alternative course of action is incorporated into the existing overall risk position can its impact on risk-bearing capacity and the threat to the company's continued existence be assessed.
5. Risk Management and Monitoring: Effectiveness and Cost-Effectiveness
Risk management encompasses avoidance, transfer, reduction, and acceptance. For relevant risks, the standard recommends indicators and thresholds that signal changes at an early stage. If critical thresholds are exceeded, countermeasures—including restructuring plans—must be initiated.
Internal audit should not only verify whether measures are in place but also whether they are actually effective. This includes the suitability of risk indicators, the effectiveness of control measures, the quality of controls, the adequacy of monitoring in the first and second lines of defense, and explicitly the cost-effectiveness of the selected measures in relation to risk reduction.
6. Risk Reporting: Decision-Relevant Rather Than Merely Comprehensive
Risk reporting should promptly convey to decision-makers and supervisory bodies the risk situation, the overall scope of risk, and the likelihood of a development that could threaten the institution's viability. Regular reports and ad hoc disclosures must be supported by clear processes, responsibilities, thresholds, and recipients.
The quality of the information is crucial: it must be understandable, complete, timely, tailored to the audience, and relevant to decision-making. Version 2.2 additionally highlights external requirements in the context of CSRD/ESRS and material sustainability risks. For Internal Audit, decision-making documents are explicitly part of the reporting framework, as they reveal whether relevant risk information was actually available prior to a material decision.
Practical Implications for Internal Audit and Risk Management
For audit management, the scope of the audit is expanding. In the future, an audit of the risk management system can hardly be considered complete if it examines only risk registers, quarterly reports, and limits. The interfaces with strategy, planning, investment processes, M&A, technology decisions, and other procedures in which significant business decisions are prepared must also be examined.
For risk managers, the demand for the interoperability of methods is growing. Risk information must be translatable into decision-making documents: into alternative courses of action, robust ranges, aggregated impacts, risk metrics, and, where applicable, changes in the probability of a risk occurring. A technically sound risk model that is not utilized in decision-making processes only partially meets the new emphasis of the standard.
Ultimately, documentation is becoming increasingly important for management teams. Version 2.2 makes it clear that good governance lies not only in the quality of a decision, but also in whether the process leading to it can be traced in retrospect: What information was available? What assumptions were used? What alternatives were considered? What risks were quantified? How did the overall risk profile change? And which function independently reviewed the decision proposal?
Conclusion: A Shift from Compliance to Decision Quality
The true significance of Version 2.2 therefore lies in a shift in perspective. Risk management is no longer understood primarily as a mandatory system that documents minimum legal requirements. It is treated as an information and control system for business decisions. This also brings internal audit closer to addressing the question of whether governance actually functions in critical decision-making situations.
This does not mean that Internal Audit becomes a co-decision-maker. On the contrary: Its independence requires that it examine the process, the quality of information, the methods, neutrality, and the documentation—not that it replace the business decision ex post with its own decision. It is precisely this separation that makes the new approach valuable: It combines business discretion with a verifiable quality framework for the preparation of that discretion.
Info Box: DIIR Standard No. 2, Version 2.2 at a Glance
→ Version 2.2, dated August 2026, introduces for the first time a separate chapter on the audit of significant business decisions involving risk.
→ The decision-oriented approach was already established in Version 2.1; what is new is its detailed operationalization as a separate audit subject.
→ Risk information must not only identify individual risks but also demonstrate how a decision affects the overall risk profile.
→ The Business Judgment Rule serves as the central legal reference point for the requirement of "adequate information" in business decisions.
→ Internal audit reviews both the management system governing the decision-making process and—on a random or case-by-case basis—specific decision proposals.
→ The standard structures the decision-making process into seven phases, from the need for a decision to the review of the decision.
→ An effective RMS requires coordinated phases, robust methods, data integrity, clear responsibilities, a risk culture, and integration into management and monitoring systems.
→ Risk aggregation, taking into account combination effects and interdependencies, remains central to risk-bearing capacity and the early detection of developments that threaten the company's continued existence.
→ Version 2.2 further emphasizes topics such as emerging risks, risk culture assessment, data integrity, and CSRD/ESRS-related risk reporting.
→ The practical assessment criterion thus shifts from the mere existence of a risk process to the question of whether this process actually enables better and transparently sound decisions.
Sources and further reading:
- DIIR – German Institute for Internal Auditing (2026): DIIR Auditing Standard No. 2: Audit of the Risk Management System by Internal Audit [in German language], Version 2.2, August 2026.
- DIIR – German Institute for Internal Auditing (2022): DIIR Auditing Standard No. 2: Audit of the Risk Management System by Internal Audit [in German language], Version 2.1.
- DIIR – German Institute for Internal Auditing (2026): Audit Guide: Business Decisions (xlsx file) [in German language]; based on Version 2.2, August 2026.




