Spotlight on Women in GRC on value-based internal audit and why business value matters more than findings 

In a recent Spotlight on Women in GRC podcast, Lucy Montague sat down with Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc, to discuss the evolution of internal audit, risk-based assurance, and the growing expectation for GRC functions to deliver measurable business value. Having recently expanded her remit from internal audit into enterprise…

Esme Dyos Avatar
CoreStream GRC podcast Spotlight on Women in GRC: Internal Audit and Risk Director on value-based internal audit and why business value matters against pink background with blue green strobe gradient

In a recent Spotlight on Women in GRC podcast, Lucy Montague sat down with Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc, to discuss the evolution of internal audit, risk-based assurance, and the growing expectation for GRC functions to deliver measurable business value. Having recently expanded her remit from internal audit into enterprise risk management, Rachel offers a practical perspective on how assurance teams can move beyond compliance to become strategic partners to the business.  

In this conversation, Rachel shares: 

  • Why internal audit should focus on business value, not audit activity alone.  
  • How risk-based assurance helps organizations prioritize what matters most.  
  • Why communication is one of the most important skills an auditor can develop.  
  • How continuous improvement should apply to audit functions as much as operational teams. 
  • Why internal audit and risk management are becoming increasingly interconnected.  
  • What the future of governance, risk, and compliance may look like in an era of uncertainty and AI.  

The question that changes everything: would anybody care? 

For decades, many audit functions have been measured: 

  • by coverage 
  • completion rates 
  • the number of audits delivered 

But as organizations face growing complexity and limited resources, those metrics alone are becoming less meaningful. Rachel believes there is a much more powerful question auditors should ask before including an area in the audit plan: 

“If we found an issue there, would anybody care? If no one’s going to jump if we find an issue, then maybe we shouldn’t be covering it.”  

Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc

Rachel’s perspective reflects a broader shift taking place across the audit profession. As CoreStream GRC’s Audit Management Guide argues, the purpose of audit is not simply to generate findings, but to help business leaders make better decisions about risk, control, investment, and accountability. In other words, assurance should be judged not by the volume of audits completed, but by whether it provides decision-makers with confidence in the areas that matter most. 

The guide makes a distinction between traditional and value-based assurance that closely mirrors Rachel’s philosophy: “A traditional approach asks, ‘Did we complete the audit?’ A value-based approach asks, ‘Did we audit the right thing, for the right reason, with evidence that improves decisions, accountability, and cost control?’”  

That shift is increasingly important as audit teams face expanding risk landscapes, competing stakeholder demands, and finite resources. Rather than allowing assurance activity to default to legacy plans or compliance cycles, leading organizations are prioritizing audits that directly support strategic objectives and business outcomes. 

This thinking aligns closely with the principles of ISO 31000, which defines risk as the “effect of uncertainty on objectives”. If risk exists in relation to objectives, then assurance should be focused on the risks and controls that have the greatest influence on achieving those objectives. 

For GRC leaders, the implication is clear: not every control deserves the same level of attention. The most effective audit functions prioritize assurance activity where it can protect, create, or enable the greatest amount of organizational value. 

From compliance function to strategic business partner 

One of the strongest themes from Rachel’s career is her belief that internal audit should not be viewed as the organization’s compliance police. 

“Internal audit can be seen as a compliance police. I don’t think that’s where internal audit should be.” 

Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc

Instead, Rachel sees audit as a catalyst for improvement. 

“The role focus of internal audit is about actually helping a business improve.”  

Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc

This shift reflects a broader evolution taking place across the profession. Boards and executive teams increasingly expect assurance functions to provide insights, challenge assumptions, and help leaders make better decisions, rather than simply identifying control failures. 

The profession is already moving in this direction. According to The Institute of Internal Auditors’ 2025 North American Pulse Survey, nearly one-third of Chief Audit Executives now have responsibility for enterprise risk management, up from 24% nine years earlier, demonstrating how audit leaders are increasingly being trusted with broader strategic and risk responsibilities. 

For Rachel, becoming a business partner starts with understanding what is already working well. 

When audit functions focus exclusively on weaknesses, they miss an opportunity to identify and scale good practice across the organization. By highlighting successful approaches and sharing lessons across teams, auditors can contribute to performance improvement in a way that creates tangible business value. 

That mindset moves internal audit from being a function people tolerate to one that stakeholders actively seek out. 

Communication is the most underrated audit skill 

Many audit challenges begin long before testing starts. 

Misunderstood objectives, unclear expectations, and poor stakeholder engagement can create unnecessary friction throughout an audit engagement. 

Rachel believes communication is one of the most powerful tools available to audit leaders: 

“I think it’s really important to set up for success, but communicate to set up for success.”  

Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc

Her approach emphasizes transparency from the start. Rather than arriving with a predefined agenda, she encourages conversations with stakeholders before audits begin, explaining what the team plans to review and why it matters.  

The same principle applies throughout the audit process. 

The importance of communication becomes even clearer as internal audit’s remit expands beyond traditional assurance. Deloitte’s Global Chief Audit Executive Survey notes that audit leaders must become better at identifying, translating, and communicating the value they create for the wider business. As the report states: “CAEs must think and communicate like CEOs, selling their value proposition and unique selling points across the organization.” 

“I think there’s less value in hitting someone with a list of issues at the end of an audit.”  

Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc

Instead, findings should be discussed in real time, allowing stakeholders to provide context, address concerns early, and begin implementing improvements before the final report is issued.  

This approach creates a more collaborative relationship between auditors and the business and helps ensure assurance activities drive action rather than simply generate reports. 

Continuous improvement starts with the audit team 

Organizations often expect their operational teams to embrace continuous improvement, but Rachel argues audit functions should hold themselves to the same standard. 

“Every audit should be better than the last one.”  

Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc

At Coats Group plc, this means continually evaluating not only what the audit team found, but also how the audit was experienced by the business. Rachel actively seeks feedback from stakeholders and uses it to improve future engagements.  

“Tell me about how the experience was from your point of view. How could I and my team be better?” 

Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc

KPMG’s Internal Audit, Evolved report agrees that internal audit should be a function that “evolves with the organization,” combining stakeholder engagement, risk insight, business improvement, and operating model agility to remain effective in a fast-changing environment. High-performing audit teams are no longer solely assurance providers; they are continually refining how they work, how they engage stakeholders, and how they create value for the business 

It also reflects a broader truth about modern GRC. In an environment where risks evolve rapidly and stakeholder expectations continue to rise, static assurance models quickly become outdated. The organizations that create the most value are those that continuously learn, adapt, and improve. 

Audit Management solution download

The future of GRC is integrated, agile, and connected 

Rachel’s recent move into a combined Internal Audit and Risk leadership role has given her a unique perspective on where the profession is heading. 

While the Three Lines Model remains an important governance framework, she believes the traditional boundaries between assurance functions will continue to evolve. 

“We’ll continue to see the three lines of defence merge and become less clear, but in a really good way.”  

Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc

GRC analyst Michael Rasmussen explains: 

“For years, audit has been the entry point for many organizations adopting GRC technology. But the market is changing. Organizations no longer have the luxury of managing audit, risk, compliance, cyber, internal control, and assurance as disconnected functions with separate systems, separate workflows, and separate views of the business. 

The modern enterprise needs connected visibility. 

It needs to understand how risks relate to objectives, how controls support resilience, how cyber exposures connect to operational risk, how compliance obligations impact business processes, and how assurance functions can coordinate rather than duplicate effort.”  

Michael Rasmussen, GRC Analyst and Pundit, GRC 2020

This closely aligns with Rachel’s view that the boundaries between assurance functions will continue to blur. Rather than operating as separate disciplines, audit, risk, and compliance teams are increasingly being brought together to provide a more holistic view of organizational performance, resilience, and uncertainty. The goal is not to remove accountability between the lines of defense, but to create better visibility, reduce duplication, and support more informed decision-making across the business. 

Rachel also believes future GRC leaders will need to become more comfortable operating in uncertainty. 

“The last couple of years has shown us it’s very much dealing with the unknown.”  

Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc

Rachel’s comments echo a theme raised by fellow Spotlight on Women in GRC guest Emma Price, who argued that disruption is no longer something organizations experience periodically before returning to normal. Discussing Peter Hinssen’s concept of The Never Normal, Emma explained that “disruption is no longer an occasional event that organizations recover from. It’s actually a permanent operating environment for us all now.” Instead of attempting to predict every possible scenario, she believes success comes from building organizations that are adaptable, continually learning, and ready to evolve as conditions change. 

Like many GRC leaders, Rachel also sees AI as a significant opportunity to help with this era of uncertainty.  

“I always talk to the team about working smarter, not harder, and technology and tools and I think AI gives us a really good opportunity to do that.”  

Rachel Paddon, Director of Internal Audit and Risk at Coats Group plc

The challenge will be ensuring technology supports better decision-making and business outcomes rather than simply increasing efficiency. 

Internal audit defined by value 

If there is one theme that runs throughout Rachel’s career and leadership philosophy, it is the belief that assurance should make organizations better. 

Whether that means prioritizing meaningful risks, improving communication, sharing best practice, or building stronger connections between risk and audit functions, the goal remains the same: deliver value where it matters most.  

As governance, risk, and compliance continue to evolve, successful audit leaders will not be measured by the number of audits they complete. They will be measured by the impact they have on organizational performance, resilience, and decision-making. 

Or, as Rachel’s simple but powerful question reminds us: 

If nobody would care about the finding, should it really be consuming valuable assurance resources in the first place?  

About Rachel Paddon 

Rachel Paddon is Director of Internal Audit and Risk at Coats Group plc, a FTSE 250 global manufacturing organization operating across more than 50 countries. With over 20 years of experience in governance, risk, compliance, and assurance, Rachel has built her career helping organizations strengthen performance through risk-based assurance, internal audit transformation, and continuous improvement.

Prior to joining Coats Group plc, Rachel spent 19 years at PwC, progressing from graduate trainee to Director, leading assurance engagements across multiple sectors and developing deep expertise in internal audit, risk management, and governance. Passionate about creating business value through assurance, Rachel champions a modern approach to internal audit that focuses on strategic priorities, meaningful stakeholder engagement, and helping organizations become better tomorrow than they are today. 

About Spotlight on Women in GRC podcast  

Spotlight on Women in GRC is a podcast series created to continue the conversations sparked by the Women in GRC Awards and shine a light on the professionals shaping governance, risk and compliance today. Hosted by CoreStream GRC’s Lucy Montague, the series explores career journeys, leadership lessons and the trends transforming the GRC profession.  

Condensed transcript of the Rachel podcast episode  

Lucy Montague: 

Welcome to Spotlight on Women in GRC, a podcast series created to continue the conversations sparked by the Women in GRC Awards 2026. Supported by CoreStream GRC, the series shines a light on the women shaping governance, risk and compliance. 

Today I’m joined by Rachel Paddon, Director of Internal Audit and Risk at Coats. Rachel, welcome. 

Rachel Paddon: 

Thanks, Lucy. It’s great to be here. 

Career journey 

Lucy Montague: 

Tell us a little about your role and career journey. 

Rachel Paddon: 

I’m currently Director of Internal Audit and Risk at Coats, a FTSE 250 global manufacturing organization operating across more than 50 countries. 

I joined Coats in 2024 as Head of Internal Audit and have recently expanded my responsibilities to include risk management. 

Prior to that, I spent 19 years at PwC, joining as a graduate and progressing through to Director. Throughout my career I’ve worked across assurance, internal audit and the broader GRC landscape, but internal audit has always been the area I’ve been most passionate about. 

Taking on risk leadership 

Lucy Montague: 

You’ve recently taken on responsibility for risk as well as audit. What does that mean for your team? 

Rachel Paddon: 

It’s an exciting opportunity. 

The first step is understanding where we are today and developing a roadmap for where we want to go next. 

For the team, it creates opportunities to become more involved in second-line activities, work more closely with the business and develop new skills. It’s really about broadening our impact and helping the organization make better decisions. 

Why internal audit? 

Lucy Montague: 

What is it about internal audit that has kept you interested throughout your career? 

Rachel Paddon: 

I often describe myself as an internal audit geek. 

For me, internal audit gives you a unique license to understand every part of a business. Very few roles provide that level of access and visibility. 

I also love the fact that the purpose of internal audit is to help organizations improve. It’s about asking questions, understanding how things work and identifying ways things can be done better. 

If you’re naturally curious, it’s a fantastic career. 

Transforming internal audit into a value-adding function 

Lucy Montague: 

When you joined Coats, how did you transform the audit function into a value-adding, risk-based assurance function? 

Rachel Paddon: 

The first step was listening. 

I wanted to understand what people thought of internal audit, what was working well and where there were opportunities to improve. 

One of the key principles I introduced was focusing on what really matters. 

I often challenge my team with a simple question: 

“If we found an issue there, would anybody care?” 

If nobody would care about the outcome, we should question whether it’s the right use of our audit resources. 

The other important shift was viewing internal audit as a business partner rather than a compliance function. We should be helping the organization improve, not simply pointing out problems. 

Building trust through communication 

Lucy Montague: 

How have you improved the audit experience for stakeholders? 

Rachel Paddon: 

A lot of it comes down to communication. 

Before an audit begins, we explain what we’re reviewing and why. 

During the audit, we communicate findings as they emerge rather than waiting until the final report. 

I don’t think there’s much value in presenting someone with a long list of issues at the end of an audit. If you discuss things in real time, people can provide context, start making improvements and feel involved in the process. 

That helps create a much stronger partnership with the business. 

Career progression and sponsorship 

Lucy Montague: 

What helped you progress from graduate to director? 

Rachel Paddon: 

Performance is obviously important, but sponsorship became increasingly important as I progressed. 

At senior levels, it’s not enough to do good work. You need people willing to advocate for you, create opportunities and help pull you through to the next stage of your career. 

I think sponsorship is one of the most powerful factors in career progression. 

Women in GRC leadership 

Lucy Montague: 

Why do you think women remain underrepresented in senior GRC leadership roles? 

Rachel Paddon: 

There are several factors. 

Career breaks and limited senior part-time opportunities contribute, but I think one of the biggest challenges happens earlier in people’s careers. 

We need to ensure we’re creating inclusive environments, offering opportunities to a diverse range of people and actively sponsoring future leaders. 

I think sponsorship is one area where organizations can make a real difference. 

Lucy Montague: 

Have you experienced barriers or biases during your career? 

Rachel Paddon: 

One example was returning from maternity leave. 

After my first child, people immediately began asking when I was planning to have a second, almost as though my career had gone on hold. 

I’ve learned it’s important to challenge assumptions when they arise and separate career conversations from personal assumptions. 

Many biases aren’t intentional, but that doesn’t mean they shouldn’t be addressed. 

Supporting women into leadership 

Lucy Montague: 

What else can organizations do to support women into leadership roles? 

Rachel Paddon: 

Flexibility is important. 

We need to move away from rigid definitions of what work should look like and focus more on outcomes. 

I also think role models matter enormously. 

When people can see individuals who look like them succeeding in leadership positions, it helps them believe those opportunities are available to them too. 

Representation really does matter. 

The power of networks 

Lucy Montague: 

How have sponsors and networks helped your own career? 

Rachel Paddon: 

I’ve been incredibly fortunate to have both strong sponsors and mentors throughout my career. 

One thing I’ve learned is to be clear about where I want to go and to have honest conversations about how people can help me get there. 

Building relationships takes courage, but those relationships can have a significant impact on your career. 

Leading through uncertainty 

Lucy Montague: 

What are you and your team focused on right now? 

Rachel Paddon: 

We’re currently focusing on three things. 

First, giving the team time to rest and recover after a busy first half of the year. 

Second, reflecting on what we’ve learned and how we can improve. 

And third, building our approach to risk management now that risk has formally joined the function. 

Alongside all of that, AI and technology remain major areas of focus. We’re constantly looking at how we can work smarter, not harder. 

The future of GRC 

Lucy Montague: 

What do you think will define the next era of governance, risk and compliance? 

Rachel Paddon: 

I think uncertainty will continue to be a defining characteristic of the environment organizations operate in. 

That means agility, resilience and adaptability will become even more important. 

I also believe we’ll see greater integration between audit, risk and the wider assurance functions. 

The traditional boundaries between the three lines of defense will become less rigid as organizations look for more connected and collaborative approaches to managing risk. 

Advice and inspiration 

Lucy Montague: 

Are there any books, podcasts or people that have influenced you? 

Rachel Paddon: 

A few that immediately come to mind. 

Lean In by Sheryl Sandberg is a fantastic book about taking opportunities and backing yourself. 

I also highly recommend The Let Them Theory by Mel Robbins. 

Podcast-wise, I enjoy The High Performance Podcast with Jake Humphrey and Damian Hughes, and How to Fail with Elizabeth Day. 

Both offer valuable insights into growth, leadership and learning from challenges. 

Lucy Montague: 

Rachel, thank you so much for joining us. 

Rachel Paddon: 

Thank you for having me. 

Lucy Montague: 

And thank you to everyone listening to Spotlight on Women in GRC. Join us next time for another conversation with the women shaping the future of governance, risk and compliance. 

Frequently asked questions about value-based internal audit and GRC

What is value-based internal audit? 

Value-based internal audit is an approach that focuses assurance activity on the risks, controls, and decisions that matter most to the organization. Rather than measuring success by the number of audits completed or findings raised, it asks whether audit work improves confidence, accountability, cost control, resilience, and business performance. 

How is value-based internal audit different from traditional internal audit? 

Traditional internal audit often focuses on coverage, completion rates, and whether controls are operating as expected. Value-based internal audit goes further by asking whether the right areas are being audited for the right reasons, and whether the results help leaders make better decisions about risk, resources, and strategic objectives. 

What is risk-based assurance? 

Risk-based assurance is an approach that aligns audit and assurance activity with the organization’s most significant risks and objectives. It helps internal audit teams prioritize work based on impact, likelihood, risk appetite, control effectiveness, and the level of assurance needed by the board and executive team. 

Why should internal audit focus on business value? 

Internal audit should focus on business value because assurance resources are limited and risks are constantly changing. By concentrating on the areas where findings would influence decisions, protect performance, or improve resilience, audit teams can move from compliance monitoring to strategic business partnership. 

How can internal audit become a strategic business partner? 

Internal audit can become a strategic business partner by engaging stakeholders early, understanding business objectives, communicating findings in real time, highlighting good practice, and focusing recommendations on practical improvements. The most effective audit teams help the business manage uncertainty, strengthen controls, and make more informed decisions. 

What is the relationship between internal audit, risk management, and GRC? 

Internal audit, risk management, and GRC are closely connected but play different roles. Risk management identifies and manages uncertainty against objectives. Internal audit provides independent assurance over the effectiveness of governance, risk management, and controls. GRC brings governance, risk, compliance, control, and assurance activity together so leaders have a more connected view of organizational performance and resilience. 

How does AI affect the future of internal audit and GRC? 

AI has the potential to help internal audit and GRC teams work smarter by improving data analysis, continuous monitoring, risk identification, and reporting. However, the value of AI depends on how well it supports better judgment, stronger assurance, and more timely decision-making rather than simply automating existing processes.