In the latest All Things Internal Audit episode, Daniel McCarville (Associate Vice President of Internal Audit at Arch Capital) speaks with Bill Bensing (Chief Technologist and Co-Founder of Attestify) about the evolving role of shadow IT in organizations.
Rather than viewing shadow IT purely as a risk, the discussion highlights how it often reflects innovation already happening within the business. The episode explores how internal auditors can help strike the right balance between experimentation, governance, and control—without stifling progress.
A key takeaway is the Exploration–Validation–Operation model, a practical framework that shows how ideas evolve from early experimentation into formal, scalable solutions. The conversation also emphasizes the importance of allowing imperfection in early stages, building internal innovation communities, and rethinking how risks related to shadow IT are assessed.
Ultimately, the episode encourages internal auditors to play an active role across the innovation lifecycle—supporting safe experimentation while ensuring appropriate controls are in place.
