← All postsHow-to

Internal audit: useful when nobody is defending a number

Internal audit checks whether controls actually work. How to plan by risk, write findings people act on, and stay independent without becoming the police.

How-toI

Internal audit exists to give the people running a company an independent answer to a simple question: do the controls we believe we have actually work? It is not the external audit, which tests whether the financial statements are fairly stated for the benefit of people outside. It is not the quality department. And it is not, though it is often treated as one, an investigations function. The distinguishing feature is independence — an internal audit whose findings can be edited by the person being audited has produced a document, not an assurance.

Planning by risk rather than by rotation

  • Start from where the loss would be: the processes handling money, the ones with regulatory exposure, the ones that changed recently.
  • Audit what changed. New systems, new suppliers, reorganisations and rapid growth produce more control failures than steady-state operations ever do.
  • Include at least one area nobody has looked at in years, because comfortable areas are comfortable partly because they are unexamined.
  • Leave capacity unplanned — typically a fifth — for the things that will come up.
  • Agree the plan with the audit committee or the owner, and record what you chose not to cover as well as what you did.

Findings that get acted on

  1. State the condition — what you observed, with the evidence and the sample size.
  2. State the criteria it fails against: a policy, a regulation, a contractual term. A finding with no criterion is an opinion about how things should be done.
  3. State the consequence in terms the reader cares about, which is usually money, a customer, or a regulator.
  4. Agree the cause with the process owner before writing the recommendation, because a recommendation aimed at the wrong cause will be implemented and change nothing.
  5. Get a management response with a named owner and a date, and record disagreement as disagreement rather than negotiating it away.
  6. Track to closure and verify. An unverified closed finding is a finding that will reappear.

Independence is structural, not personal. If the audit function reports to the person whose area it audits, no amount of individual integrity fixes that — the reporting line to the board or the owner is the control. In a small company where full independence is impossible, say so in the report rather than implying an assurance you cannot give.

What internal audit is not

  • Not the external audit: different purpose, different audience, and the external auditor may rely on your work but is not replaced by it.
  • Not the control itself. An auditor who designs and then audits the same process has audited their own work.
  • Not a disciplinary process. Where an audit uncovers misconduct it should hand over, not investigate, or the next audit will be met with silence.
  • Not a substitute for a functioning internal controls framework — audit tests controls, it does not operate them.
  • Not only about compliance: operational waste and duplicated effort are legitimate findings and often the ones that pay for the function.

Where the audit file lives

Ettex Records keeps the plan, the working papers and the findings as linked records with owners, due dates and status, so the answer to "what is still open from last year" is a filter rather than a search through email. That closure trail is what an external auditor or a certification body asks for first. Findings that need root cause work should flow into the same corrective action process the rest of the business uses rather than living in an audit-only list. Ettex does not perform audits, does not assess independence and has no view on whether a finding is material.

Frequently asked

Do small companies need internal audit?

Rarely as a function, often as an activity. A quarterly half-day where someone independent tests one control — bank reconciliations, supplier changes, access rights — catches most of what a formal function would, at a fraction of the cost.

Can we outsource it?

Yes, and many companies do, particularly for specialist areas. What cannot be outsourced is the decision about what gets audited and the accountability for acting on findings.

What if management refuses to fix a finding?

Record the acceptance of risk, by name, with a date. That is a legitimate outcome — management is entitled to accept risk — and the record is what makes the acceptance visible rather than a silent disagreement.

MI
Written by Maria I.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.