Internal Audit
The PFMA and MFMA require public entities to maintain an internal audit function, and most private boards want one for the same reason: somebody independent checking whether controls actually operate. We provide that function outright or work alongside a team you already have. Professional independence rules prevent us from providing internal audit to an entity where we also act as external auditor, so these are alternative engagements rather than a package.
Outsourced and Co-sourced Internal Audit
Smaller entities rarely justify a full internal audit department. We run the function under a service level agreement, reporting to your audit committee on the same basis an in-house head of internal audit would. Where you already have staff, we supplement them on the areas where they lack depth.
- Full outsourced internal audit function
- Co-sourcing on specialist areas
- Reporting directly to the audit committee
- Annual and three year rolling coverage plans
Risk Based Audit Planning
Coverage should follow risk rather than habit. We facilitate the risk assessment with management, translate it into an audit universe, and build a plan the audit committee can approve and hold us to. The plan is revisited when the risk picture changes, not only at year end.
- Facilitated risk assessment workshops
- Audit universe definition and scoring
- Three year rolling plan with annual coverage
- Quarterly reprioritisation against emerging risk
Combined Assurance and Committee Support
Boards increasingly ask who is assuring what, and get an incomplete answer. We map every assurance provider across the organisation, show the board where coverage overlaps and where nothing is looking at all, and prepare the committee reporting that comes out of it.
- Combined assurance mapping
- Assurance gap and duplication analysis
- Audit committee reporting packs
- Charter and terms of reference drafting
Performance Information Audits
Predetermined objectives attract findings year after year because the numbers reported cannot be traced back to evidence. We test reported performance information the way the external auditors will, early enough that you can still fix what we find.
- Testing of predetermined objectives
- Evidence and source document tracing
- Usefulness and reliability assessment
- Early remediation before external audit
Follow Up and Remediation Tracking
Findings that are agreed and then forgotten reappear in the next report. We keep a live register of every finding, its owner and its due date, then re test the control once management says it is fixed rather than accepting the assurance on paper.
- Central findings register with ownership
- Agreed action plans and due dates
- Re testing of remediated controls
- Repeat finding trend reporting
