Culture is often described in terms that are difficult to test. Organisations talk about openness, accountability, integrity, challenge and speaking up. Employee surveys measure perceptions. Boards receive culture dashboards. Policies describe expected conduct.
All of this can be useful. But none of it, on its own, tells a board how the organisation actually behaves when commercial pressure rises, a deadline is at risk, or somebody brings unwelcome information into the room.
That is where culture stops being an abstract concept and becomes a risk and governance issue.
The useful evidence is often found in what people do: which issues are escalated and which remain unresolved; whether challenge changes a decision; how frequently controls are overridden; what happens after someone reports a mistake; which behaviours are rewarded; and whether bad news reaches decision-makers intact.
Seen this way, culture becomes less abstract. Organisations may never be able to measure it with the precision of capital, liquidity or system availability, but they can examine the conditions and behaviours through which culture affects risk.
That distinction is becoming particularly relevant for internal audit. The Institute of Internal Auditors’ Organizational Behavior Topical Requirement, issued on 15 December 2025 and effective from 15 December 2026, describes organisational behaviour as the human side of risk: the observable actions, decisions and interpersonal dynamics of individuals and groups. It provides a baseline for assessing related governance, risk management and control processes.
The significance goes beyond preparing for another audit requirement. It points towards a more useful question for boards, executives and GRAC functions: what evidence would tell us whether the behaviours we expect are actually present when they matter?
Culture is easier to describe than to demonstrate
Most organisations already have substantial evidence about their intended culture.
Codes of conduct establish behavioural expectations. Values explain what the organisation wants to stand for. Remuneration frameworks define incentives. Training programmes reinforce responsibilities. Whistleblowing arrangements provide formal escalation routes. Leadership communications set expectations from the top.
These things matter. The problem arises when evidence of intention is treated as evidence of outcome.
A policy requiring employees to speak up does not establish that people feel able to do so. A control framework requiring escalation does not show that material concerns reach the right level quickly enough. A statement encouraging constructive challenge does not demonstrate that challenge survives contact with hierarchy, commercial pressure or a senior sponsor committed to a particular course of action.
There can be a considerable distance between the culture an organisation describes and the behaviour its operating environment produces. That distance is where risk functions and internal audit should become interested.
The IIA’s approach is notable because it reframes the subject around behaviour-related risk: how behaviour is governed, how related risks are identified and addressed, and whether controls, incentives and accountability encourage behaviour consistent with organisational objectives.
This does not make culture simple or every behavioural observation measurable. It does, however, give organisations a firmer basis for examining something too often regarded as important but intangible.
Look at what happens to bad news
One of the clearest behavioural signals is the movement of uncomfortable information.
Most governance arrangements work reasonably well when information is expected, performance is on plan and decisions are uncontroversial. Culture becomes more visible when the message is difficult.
Consider a recurring operational problem that could threaten a customer outcome. Does the issue move quickly towards somebody with the authority to act? Is its severity preserved as it moves through management layers? Is the person raising it expected to arrive with a fully formed solution before the concern is taken seriously? Does reporting the problem create scrutiny of the issue, or of the individual who reported it?
None of these questions can be answered adequately by knowing that an escalation procedure exists. The organisation needs to understand the behaviour around that procedure.
Useful evidence may already exist in incident records, complaints, audit findings, risk acceptances, overdue actions and committee papers. Timing can be revealing: when was a problem first identified, when was it formally escalated and when did somebody with sufficient authority act?
Repeated delays do not automatically prove a cultural problem. There may be legitimate operational explanations. But patterns deserve examination, particularly when similar issues repeatedly remain below formal reporting thresholds until their consequences become difficult to ignore.
The same principle applies to near misses. An organisation that records only events with realised losses may be missing valuable evidence about where employees noticed danger, intervened informally or worked around a weakness before harm occurred.
Culture can influence what becomes visible to governance as much as what happens operationally.
Challenge matters only if it can affect decisions
Many organisations rightly value challenge. Fewer can demonstrate what happens after a challenge is raised.
The presence of dissent in a meeting is not necessarily evidence of effective challenge. A stronger question is whether contrary evidence is considered seriously enough to influence the decision.
That does not mean the challenger should prevail. Good governance cannot require management to reverse a decision every time somebody disagrees. The relevant evidence is whether competing views can be raised without disproportionate personal cost, receive appropriate consideration and test significant assumptions before a decision becomes difficult to reverse.
Decision records can therefore reveal more about culture than a general statement about psychological safety.
Where significant decisions are documented, organisations can examine whose input was sought, which risks were considered, what assumptions supported the recommendation and how conflicting evidence was handled. They can also look backwards: when an outcome differed materially from expectations, did the organisation revisit the original reasoning or simply move on?
A pattern in which challenges are routinely recorded but rarely affect assumptions, conditions or decisions deserves attention. So does a process in which contrary evidence consistently appears late, after senior sponsorship and organisational momentum have made reconsideration difficult.
The concern is not disagreement for its own sake. It is whether the organisation’s decision-making environment allows inconvenient information to compete fairly with preferred outcomes.
Controls show where pressure meets behaviour
Control environments also produce behavioural evidence.
Overrides and exceptions are an obvious example. Many are entirely legitimate. Businesses need judgement, and a control framework that cannot accommodate exceptional circumstances may create its own risks.
The more revealing questions concern patterns.
Which controls are overridden most frequently? By whom? Under what conditions? Are exceptions concentrated around reporting deadlines, sales targets, customer pressures or particular business units? Are temporary exceptions repeatedly renewed? Do the same rationales recur?
Viewed separately, each decision may be defensible. Viewed together, they may show how the organisation behaves when its formal controls become inconvenient.
A well-designed control can become weaker when employees are rewarded for speed but the control requires time, when managers are accountable for output but not for the risks created in achieving it, or when repeated workarounds gradually become accepted operating practice.
A control assessment that looks only at design and execution may therefore miss part of the picture. Behavioural evidence helps explain why a control is being followed, bypassed or slowly eroded.
Incentives deserve a wider interpretation
Discussions of culture and incentives often move quickly to remuneration. Financial rewards clearly matter, but the behavioural environment is broader.
People learn what an organisation values from promotion decisions, recognition, workload allocation, performance conversations and the behaviour leaders tolerate.
An organisation may formally encourage escalation while rewarding managers who deliver results by suppressing difficult issues. It may talk about prudent risk-taking while treating missed commercial targets far more seriously than repeated control weaknesses.
The resulting message does not need to be written down to become understood.
Employee survey results, conduct incidents, control exceptions, staff turnover, performance measures and promotion decisions may each tell only part of the story. Their value increases when relationships between them are examined.
A business unit with strong financial performance and unusually low escalation volumes may genuinely be exceptionally well managed. Alternatively, employees may have learned that escalation is unwelcome. Neither conclusion should be assumed. The combination should prompt investigation.
Indicators should create questions before they create conclusions.
The aim is not a culture score
Once organisations begin looking for behavioural evidence, there is a temptation to turn it into a dashboard and reduce culture to a collection of indicators.
That risks replacing one abstraction with another.
Escalation volumes, whistleblowing cases, employee survey scores, control overrides and staff turnover can all be informative. None has a universally desirable direction. A rise in reported concerns might indicate deteriorating conduct, greater confidence in speaking up or both. Low exception rates could reflect strong controls or reluctance to record exceptions. High challenge rates say little unless the organisation understands the quality and consequences of that challenge.
Context is essential.
The objective should therefore be stronger judgement rather than a single measure of cultural health. Boards and executives need enough connected evidence to identify where behavioural conditions may be increasing risk and to test whether management’s explanation is convincing.
Behavioural risk is unlikely to sit neatly within HR, risk, compliance or internal audit. Incentives may be designed in one function, controls owned in another, incidents recorded elsewhere and employee feedback held by another team again.
Viewed separately, each dataset can support its own reporting process. Viewed together, they can reveal how the organisation actually works.
Internal audit can test the gap between expectation and practice
The Organisational Behavior Topical Requirement does not mean internal audit must conduct a standalone culture audit. Its greater value may be in strengthening how behavioural evidence is considered across assurance activity.
A review of sales practices can examine incentives and challenge. A control audit can consider patterns of overrides and workarounds. An operational resilience engagement can examine whether bad news about dependencies reaches service owners quickly enough. A transformation audit can consider whether delivery pressure is changing risk acceptance or decision behaviour.
Internal audit is well placed to connect these observations because it sees across organisational structures. It can compare what leadership expects, what governance processes prescribe and what operational evidence suggests is happening.
But it also needs to resist overclaiming. A handful of interviews or an isolated survey result rarely justifies a sweeping conclusion about organisational culture. Behavioural findings become more persuasive when different forms of evidence point in the same direction.
From statements about culture to evidence about behaviour
Preparing for December 2026 should involve more than adding organisational behaviour to an audit methodology. It is an opportunity to examine whether the organisation has enough evidence to understand its own behavioural risk.
Boards and senior management should be able to ask where significant concerns are being delayed, whether challenge can genuinely alter important decisions, where controls are routinely overridden, what behaviour the incentive environment rewards in practice, and how the organisation responds when results fall short or mistakes become visible.
The answers are unlikely to come from one system or one function.
They may sit across risk events, control assessments, audit findings, HR information, complaints, decision records, whistleblowing data, performance measures and management actions. The governance task is to connect enough of that evidence to distinguish an isolated incident from a pattern and a reassuring narrative from a well-founded conclusion.
Culture will always contain elements that resist straightforward measurement. Human behaviour is contextual, and governance should be wary of false precision.
But that does not make culture unknowable.
Every organisation leaves traces of what it really rewards, tolerates, challenges and escalates. Those traces appear in decisions, exceptions, actions and outcomes long before they appear in a culture report.
The question for boards, risk functions and internal audit is whether they are looking at those signals together and whether they are prepared to act when the behaviour they reveal differs from the culture the organisation believes it has.
Stay up to date with the latest stories from the world of governance, risk, audit and compliance >>>





