Internal Audit

The PFMA and MFMA require public entities to maintain an internal audit function, and most private boards want one for the same reason: somebody independent checking whether controls actually operate. We provide that function outright or work alongside a team you already have. Professional independence rules prevent us from providing internal audit to an entity where we also act as external auditor, so these are alternative engagements rather than a package.

Smaller entities rarely justify a full internal audit department. We run the function under a service level agreement, reporting to your audit committee on the same basis an in-house head of internal audit would. Where you already have staff, we supplement them on the areas where they lack depth.

Coverage should follow risk rather than habit. We facilitate the risk assessment with management, translate it into an audit universe, and build a plan the audit committee can approve and hold us to. The plan is revisited when the risk picture changes, not only at year end.

Boards increasingly ask who is assuring what, and get an incomplete answer. We map every assurance provider across the organisation, show the board where coverage overlaps and where nothing is looking at all, and prepare the committee reporting that comes out of it.

Predetermined objectives attract findings year after year because the numbers reported cannot be traced back to evidence. We test reported performance information the way the external auditors will, early enough that you can still fix what we find.

Findings that are agreed and then forgotten reappear in the next report. We keep a live register of every finding, its owner and its due date, then re test the control once management says it is fixed rather than accepting the assurance on paper.

Discuss an internal audit engagement