Ask an experienced airline director to name the decisions that most moved last year's result, and the answers come quickly: how seats were priced, how fuel exposure was hedged, how capacity was deployed, what partners were paid and what partners paid back. Then open the internal audit plan. In many carriers, none of those answers appears. What follows are five risks we repeatedly find absent — and, more usefully, what an audit of each would actually test.
1. Revenue management behaviour
Revenue management systems recommend; people override. Analyst overrides, fare-class closures, group displacement decisions and event-driven adjustments are individually small and collectively enormous, yet in most airlines nobody outside the RM department reviews them. An audit here is not a challenge to commercial judgement. It tests whether override authority is defined, whether overrides are logged and reviewed against outcomes, whether system recommendations are systematically ignored on particular routes, and whether forecast accuracy is measured and fed back. The plan usually omits it because auditors assume the subject is too specialised — an assumption the RM team rarely discourages.
2. Interline and codeshare settlement
When passengers travel across carriers, revenue is divided by proration rules and settled through clearing-house mechanisms. Rejected billings, stale proration agreements, unclaimed involuntary-rerouting recoveries and ageing disputes can sit unresolved for long periods, because the function that manages them is small, technical and far from management attention. An audit tests the completeness of billings out, the challenge rate on billings in, the ageing and write-off discipline of disputes, and whether special proration agreements still reflect current commercial reality. The risk is missed because it lives between finance, alliances and revenue accounting — and entities that belong to everyone belong to no one.
3. Slot utilisation and airport rights
At coordinated airports, slots are among the most valuable assets an airline holds, yet they seldom appear on any asset register. Use-it-or-lose-it thresholds, seasonal handbacks, ad-hoc leasing arrangements and the operational punctuality that protects historic rights all carry real economic consequence. An audit asks: who owns the slot portfolio as an asset, who monitors utilisation against retention thresholds, and how are decisions to hand back or lease slots priced and approved? Because the subject sits with network planning and government affairs, it is typically classified as "strategy" — and strategy, by unexamined convention, is left out of scope.
The pattern is consistent: the risks missing from the plan are the ones that sit between departments, require industry mechanics to understand, and have no obvious precedent audit to copy.
4. Fuel-hedging execution
Boards usually approve the hedging policy; far fewer receive assurance on its execution. The distinction matters. An execution audit tests whether trades stayed within approved instruments, counterparties and volume bands; whether effectiveness testing and margin-call exposure are monitored; whether the treasury middle office is genuinely independent of the dealers; and whether reporting to the board reflects the position honestly, including when the policy performed poorly. This is missed because hedging outcomes get debated as market judgement — loudly — while hedging discipline goes untested quietly.
5. Wet-lease and capacity-partner oversight
ACMI and wet-lease arrangements let an airline fly capacity it does not operate. They also transfer the airline's brand, safety reputation and customer obligations to a partner selected under schedule pressure. An audit examines how partners are vetted and rate-benchmarked, whether invoiced block hours reconcile to operated schedules, who monitors the partner's operational and compliance standards during the contract, and how disruption costs are allocated when the partner fails to perform. These arrangements are often struck quickly and renewed by inertia — the precise conditions under which control quality decays.
Why they are missed — and what to do
Across all five, three causes recur:
- Orphaned ownership. Each risk spans two or more departments, so the annual risk workshop finds no single sponsor to raise it.
- Specialist deterrence. Each requires industry mechanics — proration, coordination rules, hedge accounting — that a generalist audit team hesitates to engage without support.
- No precedent file. Audit plans propagate by inheritance. What was never audited before quietly stays that way.
None of these is an argument for leaving the risks alone; each is an argument for planning deliberately rather than by habit. The practical answer to specialist deterrence, in particular, is co-sourcing: pairing the in-house team with practitioners who have run these functions inside carriers, so the first audit of a difficult subject builds capability rather than borrowing it forever.
Where to start
Pick one — the one where your management accounts show the least explained movement — and commission a short, senior scoping review rather than a full audit. Its purpose is to size the exposure, name an owner and define what a proper audit would test. One well-chosen scoping review typically does more to reshape next year's plan than any amount of risk-register wordsmithing.