At Sonova Group, a legal leader’s move into internal audit has exposed how known risks can fall between functions, and why lateral moves can strengthen risk ownership.
Next year’s Risk-!n conference will take place from May 20-21 at the ZSC Lions Arena.
Risk ownership is rarely as clean in practice as it appears in a framework.
Some exposures sit neatly with one function, but most cut across operations, legal, finance, communications, compliance and risk. Those are often the areas where accountability becomes hardest to pin down.

Nicolas Kaeller-Cox is vice president, internal audit and risk at Sonova Group, a Swiss-listed hearing care company behind brands including Phonak, with around 18,000 employees and turnover of about CHF3.5bn.
Speaking at the Risk-!n conference in Zurich, he said that moving from legal and compliance into internal audit made the ownership gap more visible.
“There are many risks that are known to the company, but not necessarily owned,” he said.
He gives business continuity management as one example, pointing out it may involve operational resilience, policy drafting, financial exposure, crisis communications and disaster recovery planning. A risk on a register may be visible, but that does not mean someone has the authority, time and mandate to manage it.
“Before you know it, there are so many stakeholders that nobody really takes ownership and it kind of gets lost between the cracks,” Kaeller-Cox said.
Using audit’s access well
Kaeller-Cox did not come into audit through a conventional route. He began his career in law, worked across several jurisdictions and chose in-house roles because he wanted to stay close to business issues.
“I wanted to have the breadth of a company, to see the projects end to end, to work with teams, to be part of the broader management of issues rather than be a specialist in one specific field,” he said.
His legal background meant he knew the business, understood its internal dynamics and had experienced audit from the other side of the table.
“I thought they were the annoying kids who were asking questions and not stopping when I thought I had given them a satisfying answer,” he said.
Inside the function, that persistence looks different. He says that one of the benefits of audit is that it can follow threads across departments, locations and processes in a way few other teams can.
“We can say that we want to go to New Zealand, or we can say the next day that we want to audit procurement at the headquarters,” he said. “That’s really unique, and getting the most value out of it for the risk management, for the day-to-day operations, to improve the organisation, that’s a true challenge.”
One difficulty is turning access into impact. Audit reports can still be seen as another management burden, particularly when findings land as extra work for teams already under pressure. To change that, audit needs to be connected enough to understand operational reality, while still independent enough to challenge it.
“You don’t want people to think that you are independent and irrelevant,” Kaeller-Cox said. “You want to be approached when issues are spotted.”
To help achieve this, Sonova’s risk process focuses on 10 to 15 major group-level risks, with regular reporting to the board and audit committee. The model is pragmatic rather than highly elaborate, but it gives the organisation a focused view of major exposures.
Getting risk functions to speak the same language
Bridging silos is not just about governance charts, different functions often use the same words to mean different things.
Maximilien Roche, consultant at Rock Integrity & Investigations, said lawyers, investigators, auditors and risk managers may all talk about risk, but their working definitions can vary sharply. For a lawyer, risk may mean liability. For an investigator, once an allegation exists, the question becomes whether it can be substantiated. For an auditor, the focus may be evidence, controls and assurance.
“We’re all risk professionals, but we might have a completely different definition of what risk is,” Roche said.
Fraud, misconduct, business continuity, cyber incidents and regulatory breaches rarely sit in one domain. They can involve legal exposure, operational weakness, control failure and reputational harm at the same time.
Lateral moves can help close that gap. Kaeller-Cox brought a legal lens into audit, including experience of litigation, investigations and the consequences of risk materialising. He also brought language skills to a function whose reports are read by senior management and the board.
“Lawyers are good with language,” he said. “Our audit reports are sometimes ten, sometimes 20 or 30 pages. They go to the board of directors. They are read by the executive committee.”
“But if you go into a legal department and you talk about a P&L, big question marks come up in their eyes,” he said. “And then the other is process. In-house lawyers have a certain project, an M&A project, litigation, you work on that, you solve it, you wrap it up, you’re done. We are, as a breed, not necessarily very strong on establishing processes and sticking to them.”
Moving people across silos
Joint meetings and shared dashboards can help, but they do not automatically create understanding. People need to understand how other functions frame problems and where their blind spots are.
Kaeller-Cox said joining without a conventional audit background allowed him to challenge established ways of working, rather than arriving “primed” by audit standards. In his first year, he spent time learning the function before changing it, then focused on trusting and enabling the team.
He said companies should be more willing to move talent into and out of specialist functions, rather than treating audit or risk as closed career tracks.
“It’s really cool if you bring different perspectives into those specialist functions,” he said. “Auditors are super talented people that should be drawn into the organisation, and the organisation should put talented people into internal audit and into risk management.”
Next year’s Risk-!n conference will take place from May 20-21 at the ZSC Lions Arena.







No comments yet