The Functional Independence of Internal Audit
While external auditors (the SAI) report directly to the legislature, Internal Audit is an independent appraisal function built directly within a government department or agency. It reports structurally to the agency head and the independent Audit Committee. Its role is to continuously evaluate and improve the effectiveness of risk management, internal controls, and governance processes, operating under standards defined by the Institute of Internal Auditors (IIA).
Internal Control Frameworks: The COSO Model in Government
Modern public sector internal audit units evaluate administrative systems using the COSO (Committee of Sponsoring Organizations) framework, adapted for public governance. The framework mandates five integrated control components:
  • Control Environment: The tone at the top. It defines the ethical culture, management philosophies, and operational integrity of the public agency.
  • Risk Assessment: The systematic identification and analysis of risks that could prevent the agency from executing its legislative mandates or preserving public assets.
  • Control Activities: The hard checks built into daily workflows—such as segregation of duties, multi-level authorization workflows for invoice payments, and strict physical security over state IT centers.
  • Information and Communication: The channels ensuring that high-quality, real-time financial and operational data flows cleanly across all tiers of the organization.
  • Monitoring Activities: Continuous or separate evaluations performed by internal auditors to verify that all five control components are present and functioning effectively over time.
The Three Lines Model in Public Governance
To prevent gaps in organizational defense, public financial systems apply the IIA’s Three Lines Model to clarify operational boundaries:

Line of Defense Operational Actor Primary Function and Responsibility
First Line Operational Managers and Civil Servants. Owning, executing, and managing daily risks and maintaining automated system controls.
Second Line Compliance Officers, Risk Managers, IT Security. Providing specialist support, oversight, and monitoring to challenge the first line’s risk management.
Third Line Independent Internal Audit Function. Providing objective assurance and independent evaluation to senior leadership regarding control effectiveness.