Exceptions reported, risk not
A programme that tests what is easy to test produces a list of small differences and no view at all of what could actually hurt the business.
Systems & Assurance
A risk-based internal audit programme, reported in terms a board can act on rather than as a list of exceptions nobody reads.
What we are usually called about
None of these is unusual and none of them is a failing. They are what happens when a business grows faster than the records, the systems and the filings that describe it.
A programme that tests what is easy to test produces a list of small differences and no view at all of what could actually hurt the business.
The policy says two approvals are required; the system allows one. The gap between the written procedure and the configured system is where a great many findings come from.
A finding is accepted, an owner is named, and the next report finds the same thing. Without a tracked closure step an internal audit function repeats itself.
New outlets, a new warehouse or a new line of business added faster than the approvals around them, until authority limits and segregation of duties quietly stop matching the organisation chart.
The transactions least likely to be tested are often the ones the tester reports to. Where that risk sits has to be settled when the programme is written, not when a finding appears.
Reporting written for auditors rather than for the people who have to make a decision on the strength of it.
How the work runs
Scope and fees are agreed in advance and in writing, before any of this starts. Where a step turns out not to be needed, it is dropped rather than billed.
Understanding the business, where value and exposure actually sit, and agreeing what the programme should cover in the period.
A written plan tied to that assessment, with coverage, timing and reporting lines agreed before fieldwork starts.
Walkthroughs, sample testing and system-based testing of the controls that were agreed, evidenced as the work goes.
Findings ranked by risk, giving the cause rather than only the exception, and a recommendation somebody can act on.
Tracking agreed actions through to closure and reporting what remains open, so the same finding does not reappear next year.
Scope
A list of what the work can include, not a package. What is actually needed is settled after the first conversation and written into the engagement letter.
Board-level experience as a serving company director sits behind the internal audit work. Someone who has sat on a board knows what a board actually needs from internal audit; most auditors have only ever reported to one.
Who this is for
Chains running an ERP and a point of sale, where stock, margin and every invoice are now reported in real time.
Manufacture and distribution sold through a trade that settles half its margin outside the invoice — in bonus stock, credit terms, discounts and credit notes.
Alongside this
One practice handles all of it, so nobody is coordinating between a systems consultant, a tax adviser and a bookkeeper.
Systems & Assurance
Selection, implementation and migration
Systems & Assurance
Companies Act 2017 audits
Compliance & Outsourcing
Company formation and SECP filings