What Internal Audit Actually Covers in a Mid-Sized Pakistani Business

"We already get audited every year" is the most common reason a board gives for not having an internal audit function, and it rests on a mix-up between two different things. The annual statutory audit gives an opinion on the financial statements, for shareholders and other outside users, once a year, after the year has closed. Internal audit is a recurring, risk-based review of how the business actually operates, for management and the board, and it can look at a process the month after a problem starts rather than the year after it ends.

Both matter. Neither substitutes for the other.

How it differs from the statutory audit

The statutory auditor's opinion is on the financial statements taken as a whole, and its scope is set by what is required to support that opinion. Internal audit is not built around an opinion on the accounts. It is built around risk — where in the business something could go wrong badly enough to matter, and whether the controls that are supposed to catch it actually work in practice rather than only on paper.

The difference shows up in timing as much as in purpose. A statutory audit happens once, after the year-end. An internal audit function works to an annual plan, testing different areas through the year, so a control gap in April is a finding in April rather than something discovered the following spring.

It starts with risk, not with a checklist

A programme that opens with a generic audit checklist tends to test whatever is easiest to test and call that coverage. A programme built properly starts by understanding the business — where value sits, where the exposure actually is, what has changed since the last review — and only then decides what the year's coverage should include. The Institute of Internal Auditors' own definition of the function is instructive here: internal auditing is described as an independent, objective assurance and consulting activity designed to add value and improve an organisation's operations, through a disciplined, systematic approach to evaluating and improving risk management, control and governance. Assurance and improvement, not a list of exceptions.

The areas a programme typically covers

Purchasing and procurement. Whether a purchase requisition, an approval and a goods receipt actually line up before payment is made, and whether authority limits written in policy match what the system allows in practice.

Inventory. Physical counts against the book records, ageing and slow-moving stock, and the handling of goods in transit or held at a third party.

Sales and receivables. Credit limits enforced rather than merely recorded, the ageing of outstanding balances, and how returns and credit notes are approved.

Cash and banking. Reconciliations performed on time by someone who did not also make the entries, and who is authorised to move money and under what limits.

Payroll. Starters, leavers and changes processed through an approved process, and deductions calculated and remitted correctly.

Fixed assets. A register that reconciles to the ledger, physical verification, and a defensible basis for additions, disposals and depreciation.

IT and application controls. For a business running on an ERP, this is often where the most useful findings sit — user access that has not been reviewed since it was granted, approval limits configured more loosely than the policy describes, and closed periods that can still be posted to.

Branch and multi-outlet operations. Whether controls that work at head office are actually followed at a branch working with less supervision, and whether transfers and reconciliations between locations are timely.

Related parties and management override

The transactions least likely to be tested by routine procedures are often the ones closest to the people running the review. Where that risk sits, and how it will be covered, has to be decided when the annual plan is written — not left to be discovered if a finding happens to surface on its own.

Reporting that a board can act on

A report that lists forty small exceptions and no view of which one actually matters is not doing its job. Findings reported by risk, with the underlying cause rather than only the symptom, give a board or an audit committee something it can act on. A missing signature on a purchase order is a symptom; an approval workflow nobody enforces is the cause, and it is the cause that needs fixing.

Follow-up is where most programmes fall short

A finding accepted, an action agreed and an owner named is a good outcome for one report. An internal audit function only earns its keep over time if the next report checks whether that action was actually closed. Without a tracked follow-up step, the same finding tends to reappear a year later, described in slightly different words.

What internal audit does not do

It does not give an opinion on the financial statements — that remains the statutory auditor's role, and the two should not be confused or treated as substitutes for each other. It is not a substitute for management's own responsibility for the controls it puts in place, and it is not primarily a fraud investigation function, though it may identify matters that lead to one.

What a board should ask for

  1. A written risk assessment and annual plan, tied to where the business's own exposure actually sits.
  2. Coverage of the operating cycles that matter — purchasing, inventory, sales, cash, payroll, fixed assets — not only the ones easiest to test.
  3. Testing of what the ERP actually allows, not only what the policy document says should happen.
  4. Reporting ranked by risk, with cause identified alongside each finding.
  5. A tracked follow-up process, with outstanding actions reported until they are closed.
  6. A clear line between internal audit and the statutory audit, so neither is mistaken for covering the other.

This is the shape our own internal audit work follows — a risk-based plan, reporting a board can act on, and a tracked follow-up step so a finding does not reappear next year. If growth has outrun the controls, or a board is asking for assurance it is not currently getting, tell us roughly what the business does and where the concern sits. We can set out what a risk-based programme would look like and what the first year would cover.

This note is general information, not advice on your particular circumstances. Tax law and deadlines change — please confirm the position before acting on it.

Does this affect a position you have taken?

General notes cannot tell you what a rule means for your own records. Describe the situation and you will get a plain answer on whether the practice can help.

Call WhatsApp