Succession planning: naming the risk before someone resigns
Succession planning is a list of roles you cannot afford to lose and what happens if you do. How to build one small enough to maintain and honest enough to use.
Internal audit checks whether controls actually work. How to plan by risk, write findings people act on, and stay independent without becoming the police.
Internal audit exists to give the people running a company an independent answer to a simple question: do the controls we believe we have actually work? It is not the external audit, which tests whether the financial statements are fairly stated for the benefit of people outside. It is not the quality department. And it is not, though it is often treated as one, an investigations function. The distinguishing feature is independence — an internal audit whose findings can be edited by the person being audited has produced a document, not an assurance.
Independence is structural, not personal. If the audit function reports to the person whose area it audits, no amount of individual integrity fixes that — the reporting line to the board or the owner is the control. In a small company where full independence is impossible, say so in the report rather than implying an assurance you cannot give.
Ettex Records keeps the plan, the working papers and the findings as linked records with owners, due dates and status, so the answer to "what is still open from last year" is a filter rather than a search through email. That closure trail is what an external auditor or a certification body asks for first. Findings that need root cause work should flow into the same corrective action process the rest of the business uses rather than living in an audit-only list. Ettex does not perform audits, does not assess independence and has no view on whether a finding is material.
Rarely as a function, often as an activity. A quarterly half-day where someone independent tests one control — bank reconciliations, supplier changes, access rights — catches most of what a formal function would, at a fraction of the cost.
Yes, and many companies do, particularly for specialist areas. What cannot be outsourced is the decision about what gets audited and the accountability for acting on findings.
Record the acceptance of risk, by name, with a date. That is a legitimate outcome — management is entitled to accept risk — and the record is what makes the acceptance visible rather than a silent disagreement.
Succession planning is a list of roles you cannot afford to lose and what happens if you do. How to build one small enough to maintain and honest enough to use.
A supplier code of conduct sets what you require of the people you buy from. What to include, how to make it enforceable, and why long codes get signed and ignored.
A certificate of analysis states what was tested and what was found. What has to be on it, the checks that take a minute, and why filing it unread is the risk.