Outsourced Internal Audit
The PFMA and MFMA require public entities to maintain an internal audit function, and the shortage of qualified internal auditors means most cannot staff one properly. We run the function under a service level agreement, reporting to your audit committee exactly as an in house head of internal audit would. Internal audit has to be independent of what it examines, so any area where we already deliver operational or systems work is scoped out of the plan.
1
Charter
Mandate and reporting lines
2
Assess
Risk based audit universe
3
Plan
Approved coverage plan
4
Execute
Fieldwork and reporting
5
Follow up
Retest and track closure
How the Function Runs
01
Charter and Mandate
Before any audit work, the function needs a mandate the board has approved. We draft or refresh the internal audit charter, establish the reporting line to the audit committee, and agree how independence is protected in practice rather than only in the document.
- Internal audit charter drafted or refreshed
- Reporting line to the audit committee established
- Independence and objectivity safeguards agreed
- Service level agreement with defined deliverables
02
Risk Assessment and Audit Universe
Coverage follows risk, not habit. We facilitate a risk assessment with management, build an audit universe from it, and score each auditable area so the plan can be defended to the committee rather than merely presented.
- Facilitated risk workshops with management
- Auditable universe defined and scored
- Alignment to the strategic and operational risk register
- Coverage rationale documented for the committee
03
Annual and Rolling Plan
A three year rolling plan with annual detail, approved by the audit committee. The plan is revisited when the risk picture changes rather than only at year end, because an audit plan built twelve months ago is auditing last year.
- Three year rolling plan with annual coverage
- Resource and budget estimate per engagement
- Quarterly reprioritisation against emerging risk
- Committee approval and formal adoption
04
Fieldwork and Reporting
Engagements are run to standard, with working papers that would survive external review. Reports go to management for comment and then to the committee, with findings rated so attention lands where it belongs.
- Engagement planning and terms of reference
- Testing with retained working paper evidence
- Management comment before finalisation
- Risk rated reporting to the audit committee
05
Follow Up and Assurance Reporting
Findings that are agreed and then forgotten reappear in the next external audit. We maintain the findings register, retest once management reports completion, and report closure rates to the committee so the pattern is visible.
- Central findings register with ownership
- Retesting of remediated controls
- Closure rate reporting to the committee
- Annual assurance statement to the board
What You Receive
- Internal audit charter and approved terms of reference
- Risk assessment and scored audit universe
- Three year rolling plan with annual coverage
- Engagement reports with risk rated findings
- Findings register with tracked closure
- Annual assurance statement to the board
Indicative Timeline
An outsourced function is an ongoing arrangement rather than a project, normally contracted annually with quarterly committee reporting. Setting the function up takes about four to six weeks before the first engagement begins.
- Charter and mandate: one to two weeks
- Risk assessment and audit universe: two weeks
- Plan approval by the committee: one committee cycle
- Ongoing: engagements delivered against the approved plan
Standards and Requirements
Internal audit in South Africa answers to a professional standard and, in the public sector, to statute as well.
IIA Standards
The Global Internal Audit Standards, which govern how the function is mandated, staffed and reported.
PFMA
Requires national and provincial public entities to maintain an internal audit function and an audit committee.
MFMA
The equivalent requirement for municipalities and municipal entities, including reporting obligations.
King IV
Principle 15 covers the assurance functions and how the board draws comfort from them.
Treasury Regulations
Prescribe the operation of internal audit and audit committees in the public sector.
Combined Assurance
The model used to show the board who is assuring what, and where coverage is duplicated or absent.
Frequently Asked Questions
Can you provide internal audit if you already do other work for us?
No. Internal audit must remain independent of the activities it examines. Where we already deliver work in an area, we exclude it from the audit plan and say so at the outset.
What is the difference between outsourcing and co-sourcing?
Outsourcing means we run the whole function. Co-sourcing means you keep an internal team and we supplement it, usually on specialist areas such as ICT, performance information or forensic work where the in house team lacks depth.
Who do you report to?
The audit committee, functionally. Administratively we work with management, but findings are not filtered through the people being audited. That separation is written into the charter.
Does an outsourced function satisfy the PFMA or MFMA requirement?
The legislation requires the function to exist and to be effective. It does not require the staff to be employees. Outsourced and co-sourced arrangements are common and accepted, provided the charter, reporting lines and independence are properly established.
How is the audit plan decided?
From a risk assessment facilitated with management and approved by the audit committee. We bring the methodology and challenge, but the committee approves the coverage, which is what makes it defensible.
What happens to findings that management disputes?
Management comment is recorded alongside the finding, unedited. Where we disagree, both positions go to the audit committee and the committee decides. We do not remove a finding because it is unwelcome.
Related Services
This sits inside our Internal Audit practice. Related work: IT General Controls Reviews where ICT falls into the audit plan, and Audit and Assurance if what you actually need is a statutory external audit.
