Organisational audit and control
1 Internal control
Definition: the whole system of controls, financial and otherwise, established by management in order to carry out the business of the enterprise in an orderly and efficient manner, ensure adherence to management policies, safeguard the assets, prevent and detect fraud and error and secure as far as possible the completeness and accuracy of the records and the timely preparation of financial information.
Note that the definition does not just deal with financial matters: internal control can extend to matters such as:
quality control
compliance control (eg with regard to health and safety, bribery, money laundering).
For example, without a system of internal control, how can an organisation have assurance that its employees are not engaged in bribery? Of course, employees might lie, but having a system that imposes a series of verifiable checks will prevent many problems.
2 The five components of internal control
The five components of internal control, as set out by COSO (the Committee of Sponsoring Organisations of the Treadway Commission) are:
The control environment the culture of the organisation; tone from the top. If management does not think that internal control is important this view will infest the whole organisation. This is the most important element of internal control: without a good control environment internal control will, in practice, be poor.
Risk assessment controls are particularly needed where there is most risk. For example, in a jewellery business inventory is obviously at risk, whereas this would not be so serious in a quarry.
Control activities these are the steps that can be carried out to create and impose controls (see later).
Information and communication for example, to assess the success of quality controls, reliable reports on product failures are needed. Management accounts provide monthly information about whether the organisation is likely to meet its targets or whether sales or expenses are adrift,
Monitoring is the system working satisfactorily? Is there evidence that a new control needs to be implemented? Are people carrying out the control activities properly?
2.1 Control activities/procedures
Typical controls are:
Segregation of duties: split up the stages of a transaction so that one person doesn’t carry out every step. This helps to stop fraud and also means that several minds are involved in ensuring the transaction is correct.
Physical: for example, lock cash and inventory away.
Authorisation and approval: for example, overtime claims are signed by managers as approval.
Management and supervision: managers and supervisors keep an eye on what’s going on.
Organisation: for example, ensuring that the sales team can’t decide on sales prices to boost demand and their commissions.
Arithmetic and accounting: reperform calculations. Carry out reconciliations.
Personnel: ensure that staff are properly selected and trained so that they can perform their jobs properly.
Internal control systems should be set out in a procedures manual and internal (and external) auditors will assess:
Are the procedures adequate?
Are the procedures being carried out as they should be?
Examples of poor internal control include:
Not cancelling suppliers invoices when paid (they could go round the system again).
Employees self-certifying time sheets and expense claim forms
Ability of junior staff to write off debts (or to carry out other journal entries).
Not ensuring that cash receipts are promptly banked
Not establishing credit limits for customers and not following up slow payers
Not approving orders for material so that too much of the wrong type can be ordered.
3 Responsibilities for internal control
Note that directors are responsible for:
Maintaining sound risk management and internal control systems
Setting the control environment (a culture where there is an appreciation of the benefits and importance of controls, internal control procedures and their operation).
The effectiveness of these elements should be regularly reviewed.
Keeping the need for internal audit under regular review
Listed companies must report on internal control in their annual reports
4 Internal audit
4.1 Definition
Internal audit:
‘An independent appraisal activity established within an organisation as a service to it. It is a control which functions by examining and evaluating the adequacy and effectiveness of other controls; a management tool which analyses the effectiveness of all parts of an entity’s operations and management.’
Internal auditors should be:
Qualified
Experienced
Independent
Professional
Although, ultimately, they report to the board this will often be through the audit committee. This is to try to impose some independence between internal auditors and executive directors, who are ultimately responsible for internal control failures. Even then, because of the employer/employee relationship it might be difficult for internal auditors to criticise internal controls set up by the finance director. The audit committee should monitor and direct the internal auditors also.
This paragraph is the answer to the independence problem the chapter has just raised: the internal auditor is an employee, so what threatens that independence and what can be done about it. Work through the circumstances the scenario gives rather than picking off the obvious ones, and for each give three things — the type of threat, the circumstance that creates it, and what it means in practice for the audit work. The case taught here is the employment relationship itself: an internal auditor who reports to the finance director is reporting a deficiency to the person answerable for it, so the unwelcome finding is the one least likely to be pressed. The remedy the chapter gives is the reporting route above — ultimately to the board, and in practice through an audit committee of non-executive directors.
4.2 Types of assignment
Transactions audit: tracing transactions through the system, often from start to finish, to see if they are treated correctly.
Systems audit: an information technology, or information systems audit, is an examination of the management controls within an Information technology (IT) infrastructure.
Risk-based audits: an internal audit which is primarily focused on the inherent risk involved in the activities or system and provide assurance that risk is being managed by the organisation to the defined risk appetite level.
Accounting systems audit: ensuring, for example, that the proper accounting controls are being applied consistently.
Operational audits: a systematic review of effectiveness, efficiency and economy of operation. For example, examining how customer complaints are dealt with.
Value for money and best value. Usually associated with public or non-profit organisations. Its purpose is to assess the effectiveness and efficiency of its use of public funds.
Management audits: analysis and assessment of competencies, abilities and capabilities of a company's management in order to evaluate their effectiveness, especially regarding the strategic objectives and the implementation of the policies of the business.
Social and environmental audits: A social and environmental audit looks at factors such as a company's record of charitable giving, volunteer activity, energy use, recycling waste, diversity in recruitment, non-discrimination in appointments, the standard of the work environment, workers’ remuneration to evaluate the social and environmental impact the company is having.
Special assignments such as investigating a case of fraud
Assisting the external auditors.
4.3 Internal and external audit - a comparison
Internal audit | External audit | |
Reports to | Management – must have a clear route to the board though day-to-day reporting to the audit committee. | Shareholders |
Appointed by | Management | Shareholders |
Power from | Management | Statute – allows external auditors to insist on seeing all documents and to be given full explanations. |
Employed by | Company (unless outsourced) | External firm |
Coverage | All categories of risk and investigation | Financial statements: true and fair view |
Responsibility for improving the organisation | A major function of internal audit | Will report to management on internal control weaknesses |
4.4 The internal audit report
At the end of the audit process, internal auditors will issue a report that will detail:
Deficiencies in the internal control system’s design
Incidents where the internal control system was not complied with
Errors discovered
Often the reports will be in the format:
Details about the nature of the internal control deficiency and departures from the specified internal control procedures | The possible effects of these deficiencies and departures | Suggestions as to how to fix the problems |
Increasingly, internal audit may also be asked to report on environmental and sustainability issues. For example, if a company has targets for the release or other disposal of harmful substances what controls and measurements are in place to ensure that:
These targets are consistently met
Breaches targets are identified
Investigation of breaches is undertaken
Improved preventative measures are implemented as necessary?


