Outsourced Internal Audit

The PFMA and MFMA require public entities to maintain an internal audit function, and the shortage of qualified internal auditors means most cannot staff one properly. We run the function under a service level agreement, reporting to your audit committee exactly as an in house head of internal audit would. Independence rules prevent us from doing this for an entity where we also serve as external auditor.

1

Charter

Mandate and reporting lines

2

Assess

Risk based audit universe

3

Plan

Approved coverage plan

4

Execute

Fieldwork and reporting

5

Follow up

Retest and track closure

How the Function Runs

01

Charter and Mandate

Before any audit work, the function needs a mandate the board has approved. We draft or refresh the internal audit charter, establish the reporting line to the audit committee, and agree how independence is protected in practice rather than only in the document.

02

Risk Assessment and Audit Universe

Coverage follows risk, not habit. We facilitate a risk assessment with management, build an audit universe from it, and score each auditable area so the plan can be defended to the committee rather than merely presented.

03

Annual and Rolling Plan

A three year rolling plan with annual detail, approved by the audit committee. The plan is revisited when the risk picture changes rather than only at year end, because an audit plan built twelve months ago is auditing last year.

04

Fieldwork and Reporting

Engagements are run to standard, with working papers that would survive external review. Reports go to management for comment and then to the committee, with findings rated so attention lands where it belongs.

05

Follow Up and Assurance Reporting

Findings that are agreed and then forgotten reappear in the next external audit. We maintain the findings register, retest once management reports completion, and report closure rates to the committee so the pattern is visible.

What You Receive

Indicative Timeline

An outsourced function is an ongoing arrangement rather than a project, normally contracted annually with quarterly committee reporting. Setting the function up takes about four to six weeks before the first engagement begins.

Standards and Requirements

Internal audit in South Africa answers to a professional standard and, in the public sector, to statute as well.

IIA Standards

The Global Internal Audit Standards, which govern how the function is mandated, staffed and reported.

PFMA

Requires national and provincial public entities to maintain an internal audit function and an audit committee.

MFMA

The equivalent requirement for municipalities and municipal entities, including reporting obligations.

King IV

Principle 15 covers the assurance functions and how the board draws comfort from them.

Treasury Regulations

Prescribe the operation of internal audit and audit committees in the public sector.

Combined Assurance

The model used to show the board who is assuring what, and where coverage is duplicated or absent.

Frequently Asked Questions

No. Professional independence rules prevent us from providing internal audit to an entity where we hold the external audit appointment. If we currently act as your external auditor we will say so at the outset and decline.

Outsourcing means we run the whole function. Co-sourcing means you keep an internal team and we supplement it, usually on specialist areas such as ICT, performance information or forensic work where the in house team lacks depth.

The audit committee, functionally. Administratively we work with management, but findings are not filtered through the people being audited. That separation is written into the charter.

The legislation requires the function to exist and to be effective. It does not require the staff to be employees. Outsourced and co-sourced arrangements are common and accepted, provided the charter, reporting lines and independence are properly established.

From a risk assessment facilitated with management and approved by the audit committee. We bring the methodology and challenge, but the committee approves the coverage, which is what makes it defensible.

Management comment is recorded alongside the finding, unedited. Where we disagree, both positions go to the audit committee and the committee decides. We do not remove a finding because it is unwelcome.

Related Services

This sits inside our Internal Audit practice. Related work: IT General Controls Reviews where ICT falls into the audit plan, and Audit and Assurance if what you actually need is a statutory external audit.

Discuss an internal audit arrangement