Learning Objectives

By the end of this lesson, learners should be able to:

  • Define internal audit and assurance.
  • Explain the role of the board in overseeing internal audit.
  • Distinguish internal audit from external audit.
  • Explain the role and responsibilities of the audit committee.
  • Evaluate the independence and effectiveness of internal audit.
  • Explain how internal audit supports governance, risk management and internal control.
  • Examine how boards should respond to internal audit findings.
  • Identify common weaknesses in internal audit and assurance arrangements.
  • Apply board-level assurance principles to organizational situations.

1. Introduction to Internal Audit and Assurance

Effective financial governance requires the board to have confidence that financial information, internal controls and organizational processes are operating appropriately.

The board cannot personally examine every transaction, financial record or control within an organization.

It therefore relies on various assurance mechanisms.

These may include:

  • Internal audit.
  • External audit.
  • Management controls.
  • Risk management.
  • Compliance functions.
  • Financial reporting.
  • Independent reviews.
  • Regulatory inspections.
  • Board and committee oversight.

Internal audit is particularly important because it provides the board and management with independent and objective assessments of organizational processes and controls.

The Institute of Internal Auditors describes internal auditing as an independent and objective assurance and consulting activity designed to add value and improve an organization’s operations.

In governance terms:

Internal audit provides the board with an independent source of assurance about the effectiveness of governance, risk management and control processes.

2. Meaning of Internal Audit

Internal audit is an independent assurance function established within an organization to evaluate and improve the effectiveness of governance, risk management and internal control.

Internal auditors may examine:

  • Financial processes.
  • Procurement.
  • Information systems.
  • Payroll.
  • Asset management.
  • Compliance.
  • Risk management.
  • Fraud controls.
  • Operational processes.
  • Governance arrangements.

Internal audit therefore extends beyond checking accounting records.

For example, an internal audit may examine whether:

  • Procurement procedures are being followed.
  • Employees have appropriate access to financial systems.
  • Organizational assets are properly recorded.
  • Management has implemented board-approved policies.
  • Cybersecurity controls are functioning.
  • Financial transactions are properly authorized.

3. Meaning of Assurance

Assurance refers to activities that provide confidence about whether organizational processes, information, controls or decisions are reliable and appropriate.

Assurance can come from several sources.

Management Assurance

Management provides assurance through:

  • Policies.
  • Procedures.
  • Monitoring.
  • Performance reports.
  • Control systems.

Internal Assurance

Internal audit provides independent assessments of:

  • Governance.
  • Risk.
  • Controls.
  • Operations.

External Assurance

External auditors provide independent assurance primarily concerning financial reporting and other matters within their audit mandate.

Regulatory Assurance

Regulators may examine whether organizations comply with applicable laws, regulations and standards.

4. The Three Lines Model

A useful way to understand assurance is through the Three Lines Model.

First Line: Management and Operational Functions

The first line owns and manages risks.

Examples include:

  • Finance departments.
  • Procurement.
  • Human resources.
  • Operations.
  • Information technology.

They are responsible for implementing controls.

Second Line: Risk and Compliance Functions

The second line provides expertise, monitoring and support concerning:

  • Risk.
  • Compliance.
  • Financial control.
  • Information security.
  • Quality.

Third Line: Internal Audit

Internal audit provides independent and objective assurance concerning the effectiveness of governance, risk management and control.

The three lines should work together without losing their distinct responsibilities.

5. Internal Audit and the Board

The board should ensure that an effective internal audit function exists where appropriate to the organization’s size, complexity and risk profile.

The board should understand:

  • What internal audit is responsible for.
  • How internal audit is structured.
  • Who internal audit reports to.
  • Whether internal audit is sufficiently independent.
  • What areas internal audit covers.
  • What significant weaknesses have been identified.
  • Whether management is responding appropriately.

The board should not use internal audit as a substitute for management.

Management remains responsible for establishing and operating controls.

Internal audit evaluates those controls.

6. Role of the Audit Committee

The audit committee is usually a key mechanism through which the board exercises oversight over financial reporting, audit and assurance.

Depending on the organization’s governance framework, the audit committee may oversee:

  • Financial reporting.
  • Internal audit.
  • External audit.
  • Internal controls.
  • Risk management.
  • Financial integrity.
  • Whistleblowing arrangements.
  • Significant accounting judgments.
  • Audit findings.

The audit committee should provide an effective forum for detailed examination of financial and control matters before important issues are presented to the full board.

7. Independence of Internal Audit

Internal audit must have sufficient independence to provide objective assessments.

If internal auditors fear management retaliation, they may be reluctant to report serious weaknesses.

This can undermine the entire assurance system.

Internal audit independence can be strengthened through:

  • Direct access to the audit committee.
  • Appropriate reporting arrangements.
  • Protection from management interference.
  • Approval of the internal audit charter.
  • Independent review of the internal audit plan.
  • Direct communication with the board or audit committee.

A strong reporting relationship is:

Internal Audit → Audit Committee → Board

while maintaining appropriate communication with executive management.

8. Internal Audit Charter

An internal audit charter formally defines the purpose, authority and responsibilities of internal audit.

It may establish:

  • Internal audit’s mandate.
  • Scope of work.
  • Reporting arrangements.
  • Access to information.
  • Access to employees.
  • Responsibilities.
  • Independence requirements.
  • Authority to conduct investigations within its mandate.

The board or appropriate board committee should ensure that the charter is appropriate and periodically reviewed.

9. Internal Audit Planning

Internal audit resources are limited.

Therefore, internal audit should use a risk-based approach when determining what areas to examine.

High-risk areas may receive greater attention.

For example:

Area

Potential Risk

Procurement

Fraud and conflicts of interest

Payroll

Ghost employees and unauthorized payments

IT systems

Cybersecurity and unauthorized access

Cash management

Theft and misappropriation

Financial reporting

Misstatement

Regulatory compliance

Penalties and legal exposure

Inventory

Loss and inaccurate records

A risk-based audit plan helps ensure that internal audit resources are focused on matters that could significantly affect the organization.

10. Board Oversight of the Internal Audit Plan

The board or audit committee should understand the proposed internal audit plan.

Important questions include:

  • What are the organization’s greatest risks?
  • Which risks will internal audit examine?
  • Why were these areas selected?
  • Which areas are not being reviewed?
  • Are emerging risks included?
  • Does internal audit have sufficient resources?
  • Are previous audit findings being followed up?

The board should avoid micromanaging individual audit procedures.

Its role is to ensure that the overall audit strategy addresses significant governance and risk concerns.

11. Internal Audit Reports

Internal audit reports normally communicate:

  • The area reviewed.
  • Audit objectives.
  • Findings.
  • Evidence.
  • Risk implications.
  • Control weaknesses.
  • Recommendations.
  • Management responses.
  • Agreed corrective actions.

A useful audit report should help decision-makers understand both the problem and its significance.

For example:

Weak segregation of duties exists within the procurement process, allowing one employee to initiate, approve and process payments.

The board should be more concerned with the underlying risk than simply the existence of the finding.

12. Audit Findings and Recommendations

Internal audit findings may identify:

  • Control weaknesses.
  • Process inefficiencies.
  • Policy violations.
  • Compliance gaps.
  • Fraud risks.
  • Governance weaknesses.

Recommendations should be practical and proportionate.

For example:

Weak recommendation:

Management should improve procurement controls.

Stronger recommendation:

Management should separate procurement approval and payment authorization responsibilities and implement periodic independent review of supplier payments.

The second recommendation identifies a more specific corrective action.

13. Management’s Responsibility for Corrective Action

Internal audit identifies weaknesses and provides recommendations.

Management is generally responsible for implementing corrective actions.

This distinction is critical.

Internal Audit:

Identifies and evaluates weaknesses.

Management:

Owns and corrects the weaknesses.

Board:

Oversees whether significant weaknesses are being addressed.

The board should therefore avoid assuming management’s operational responsibilities.

14. Follow-Up of Audit Findings

An audit finding should not be considered resolved merely because management promises to address it.

Internal audit or another appropriate assurance function should verify implementation.

For example:

Finding:

Unauthorized users have access to the financial system.

Management response:

User access will be reviewed.

Follow-up:

Has access actually been reviewed and have unauthorized accounts been removed?

Effective governance requires evidence of implementation.

15. Escalation of Unresolved Issues

Some audit findings may remain unresolved for long periods.

This can create governance concerns.

The board or audit committee should consider:

  • How serious is the finding?
  • How long has it remained unresolved?
  • Why has management not corrected it?
  • What resources are required?
  • Who is responsible?
  • Does the issue indicate a broader control weakness?
  • Should the matter be escalated?

Repeated failure to address significant audit findings may indicate weak management accountability.

16. Internal Audit and Fraud

Internal audit can contribute to fraud risk management.

It may evaluate whether controls exist to reduce opportunities for:

  • Theft.
  • Misappropriation.
  • False payments.
  • Procurement fraud.
  • Payroll fraud.
  • Financial manipulation.
  • Unauthorized transactions.

However, internal audit is not solely responsible for preventing fraud.

Fraud prevention is a shared organizational responsibility.

The board should ensure that appropriate:

  • Controls.
  • Reporting mechanisms.
  • Ethical standards.
  • Whistleblowing channels.
  • Investigative processes

are in place.

17. Internal Audit and Whistleblowing

Whistleblowing mechanisms allow individuals to report suspected wrongdoing.

Internal audit may sometimes receive or investigate concerns depending on the organization’s governance arrangements.

The board should ensure that whistleblowing systems:

  • Are accessible.
  • Protect confidentiality.
  • Provide appropriate safeguards against retaliation.
  • Allow serious concerns to reach appropriate independent authorities.
  • Are monitored.
  • Are investigated appropriately.

A culture in which employees are afraid to report misconduct represents a significant governance risk.

18. Internal Audit and External Audit

Internal audit and external audit serve different purposes.

Internal Audit

Primarily provides internal assurance concerning:

  • Governance.
  • Risk.
  • Controls.
  • Operations.
  • Compliance.

External Audit

Primarily provides independent assurance concerning financial statements and related matters within the external auditor’s mandate.

They may cooperate, but they should remain independent in their respective roles.

19. Internal Audit Versus External Audit

Internal Audit

External Audit

Internal organizational assurance function

Independent external assurance provider

Reports primarily through internal governance structures

Reports to shareholders or other legally appropriate stakeholders

Reviews governance, risk and controls

Primarily audits financial statements

Can examine operational processes

Focus is defined by audit mandate and applicable standards

May provide consulting within appropriate boundaries

Must maintain external independence

Usually operates continuously

Generally works according to an annual audit cycle

Both functions contribute to organizational assurance.

20. Board Oversight of External Audit

The board or audit committee should also oversee the external audit relationship.

Important considerations include:

  • Auditor independence.
  • Audit scope.
  • Significant audit findings.
  • Financial reporting issues.
  • Auditor communication.
  • Non-audit services.
  • Auditor rotation where applicable.
  • Management responses to audit findings.

The board should be alert to situations where an auditor’s independence may be compromised.

21. Assurance Mapping

Boards should understand where assurance comes from across the organization.

An assurance map can identify:

Risk

Management

Compliance

Internal Audit

External Audit

Financial reporting

✓

✓

✓

✓

Cybersecurity

✓

✓

✓

Possible

Procurement

✓

✓

✓

Limited

Regulatory compliance

✓

✓

✓

Limited

Fraud risk

✓

✓

✓

Possible

Strategy

✓

✓

✓

Limited

The purpose is to identify assurance gaps and unnecessary duplication.

22. Assurance Gaps

An assurance gap occurs when an important risk is not adequately covered by any assurance mechanism.

For example:

An organization has strong financial controls but no independent review of cybersecurity.

If cybersecurity represents a major organizational risk, this may represent an assurance gap.

The board should therefore ask:

“What significant risks do we have, and where is the independent assurance that these risks are being properly managed?”

23. Assurance Over Financial Reporting

Financial reporting is a major area of board oversight.

The board should seek assurance that financial information is:

  • Accurate.
  • Complete.
  • Reliable.
  • Timely.
  • Consistent with applicable requirements.
  • Supported by appropriate evidence.

Important areas may include:

  • Revenue recognition.
  • Expenses.
  • Assets.
  • Liabilities.
  • Cash.
  • Loans.
  • Tax obligations.
  • Provisions.
  • Related-party transactions.

24. Management Information and Board Assurance

Boards depend heavily on information provided by management.

Poor information can result in poor governance decisions.

The board should therefore consider whether reports are:

  • Accurate.
  • Relevant.
  • Timely.
  • Understandable.
  • Balanced.
  • Consistent.

A board should not receive only positive information.

Effective governance requires management to communicate significant problems as well as successes.

25. The Board’s Role in Challenging Assurance Information

Directors should not automatically accept every assurance report.

They should ask questions such as:

  • What evidence supports this conclusion?
  • What limitations existed?
  • Were any areas excluded?
  • What assumptions were used?
  • Are there unresolved issues?
  • Has management disagreed with any findings?
  • Are there recurring findings?
  • Has the risk increased since the previous review?

Constructive challenge strengthens assurance.

26. Recurring Audit Findings

Repeated audit findings can indicate systemic problems.

For example:

2024:

Procurement approvals are not consistently documented.

2025:

Procurement approvals remain inadequately documented.

2026:

The same weakness continues.

This should concern the board.

The issue is no longer simply a control weakness.

It may indicate:

  • Weak management accountability.
  • Poor organizational culture.
  • Insufficient resources.
  • Ineffective policies.
  • Lack of enforcement.
  • Weak board oversight.

27. Audit Committee Reporting to the Board

The audit committee should provide the board with meaningful information about:

  • Internal audit activities.
  • Significant findings.
  • External audit matters.
  • Financial reporting concerns.
  • Internal control weaknesses.
  • Risk issues.
  • Compliance concerns.
  • Unresolved matters.

Reports should focus on significant issues rather than overwhelming directors with unnecessary operational details.

28. Internal Audit Performance

The board should also evaluate whether internal audit itself is effective.

Possible measures include:

  • Completion of the approved audit plan.
  • Quality of audit work.
  • Timeliness of reports.
  • Follow-up of findings.
  • Stakeholder confidence.
  • Identification of emerging risks.
  • Professional competence.
  • Independence.
  • Quality assurance results.

The board should avoid measuring internal audit solely by the number of audits completed.

More audits do not automatically mean better assurance.

29. Internal Audit Competence

Effective internal audit requires appropriately skilled professionals.

Depending on organizational needs, internal auditors may require expertise in:

  • Accounting.
  • Finance.
  • Risk management.
  • Information technology.
  • Cybersecurity.
  • Compliance.
  • Data analytics.
  • Fraud examination.
  • Governance.

The board should consider whether internal audit has the capabilities necessary to address the organization’s risk profile.

30. Technology and Internal Audit

Technology has changed the way internal audit operates.

Modern internal audit can use:

  • Data analytics.
  • Automated testing.
  • Continuous monitoring.
  • Artificial intelligence tools.
  • Digital audit trails.
  • Automated exception reporting.

For example, instead of manually reviewing a small sample of transactions, auditors may use data analytics to identify:

  • Duplicate payments.
  • Unusual transactions.
  • Transactions outside normal working hours.
  • Unusual supplier activity.
  • Repeated approval patterns.

Technology can therefore improve audit coverage and efficiency.

31. Cybersecurity Assurance

Cybersecurity is increasingly important for board-level assurance.

The board should understand whether the organization has adequate controls over:

  • User access.
  • Password management.
  • Privileged accounts.
  • Data protection.
  • Backup systems.
  • Incident response.
  • Network security.
  • Software vulnerabilities.

The board does not need to become a cybersecurity engineer.

However, it must understand the organization’s major cyber risks and whether appropriate assurance exists.

32. Assurance and Organizational Resilience

Assurance should extend beyond historical financial performance.

Boards should consider whether the organization is prepared for disruptions such as:

  • Cyberattacks.
  • Supply-chain disruption.
  • Financial crises.
  • Regulatory changes.
  • Natural disasters.
  • Technology failures.
  • Major reputational events.

Internal audit can assess whether business continuity and resilience arrangements are sufficiently developed.

33. Common Weaknesses in Internal Audit

Internal audit can become ineffective when:

  • It lacks independence.
  • It reports only to management.
  • Its scope is too narrow.
  • It focuses exclusively on financial transactions.
  • It lacks sufficient resources.
  • Audit findings are ignored.
  • Follow-up is weak.
  • Auditors lack appropriate expertise.
  • The board does not engage with audit reports.
  • Management interferes with audit activities.

These weaknesses can create a false sense of security.

34. Common Board-Level Assurance Mistakes

Boards may make mistakes such as:

Mistake 1: Assuming the existence of controls means they work

A policy may exist without being effectively implemented.

Mistake 2: Treating audit reports as paperwork

Audit findings require governance attention.

Mistake 3: Ignoring recurring findings

Repeated weaknesses may indicate systemic problems.

Mistake 4: Over-relying on external audit

External audit cannot replace all forms of internal assurance.

Mistake 5: Failing to challenge management

Boards should ask difficult questions when necessary.

Mistake 6: Focusing only on financial assurance

Operational, technological, ethical and strategic risks also require attention.

35. Case Study: Procurement Control Failure

Imagine an organization where:

  • One employee selects suppliers.
  • The same employee approves purchase orders.
  • The same employee confirms delivery.
  • The same employee processes payment documentation.

Internal audit identifies the weakness.

Governance Concern

There is inadequate segregation of duties.

Potential Risk

The employee could create fictitious suppliers and authorize payments to them.

Management Response

Management promises to separate responsibilities.

Board Responsibility

The board or audit committee should monitor whether corrective action is implemented.

Governance Lesson

The existence of an internal audit report does not automatically solve the problem.

Governance requires:

Finding → Management Response → Corrective Action → Verification → Board Oversight

36. Case Study: Recurring Financial Control Weakness

An internal audit repeatedly identifies weaknesses in bank reconciliations.

The board receives the same finding for three consecutive years.

Questions the board should ask:

  1. Why has management not corrected the problem?
  2. Who is responsible?
  3. Are there resource constraints?
  4. Is the problem limited to one department?
  5. Could the weakness conceal fraud?
  6. Are similar weaknesses present elsewhere?
  7. Does management need additional support?
  8. Should the matter be escalated?

The board should focus not merely on the finding but on the underlying cause.

37. Practical Board Assurance Framework

A board can use the following framework:

Step 1: Identify Significant Risks

What could seriously affect the organization?

Step 2: Identify Existing Controls

What mechanisms are currently in place?

Step 3: Identify Assurance Sources

Who independently evaluates those controls?

Step 4: Identify Assurance Gaps

Which significant risks lack adequate assurance?

Step 5: Review Findings

What weaknesses have been identified?

Step 6: Monitor Corrective Action

Have management actions actually been implemented?

Step 7: Evaluate Effectiveness

Has the corrective action reduced the risk?

38. Questions Boards Should Ask Internal Audit

A board or audit committee can ask:

  1. What are the organization’s most significant control weaknesses?
  2. Which findings are considered high risk?
  3. Are there recurring findings?
  4. Which management actions remain overdue?
  5. Are there areas that internal audit cannot adequately cover?
  6. Does internal audit have sufficient independence?
  7. Does internal audit have sufficient resources?
  8. Are emerging risks included in the audit plan?
  9. Are there disagreements between management and internal audit?
  10. What concerns should the full board know about?

These questions promote meaningful assurance rather than passive reporting.

39. Questions Boards Should Ask External Auditors

The board may also ask external auditors:

  1. What were the most significant audit matters?
  2. Were there material weaknesses?
  3. Did management make significant accounting judgments?
  4. Were there disagreements with management?
  5. Were there significant audit adjustments?
  6. Were there concerns regarding management integrity?
  7. Are there independence concerns?
  8. Were there significant related-party transactions?
  9. What areas required significant professional judgment?
  10. Are there issues that should concern the board?

40. Internal Audit and Board Decision-Making

Internal audit should contribute to informed governance decisions.

For example:

Board decision:

Approve expansion into a new country.

Relevant assurance questions may include:

  • Are regulatory controls understood?
  • Are financial controls ready?
  • Are fraud risks understood?
  • Are local compliance requirements addressed?
  • Are IT systems secure?
  • Are management capabilities adequate?

Internal audit may therefore contribute valuable insight without making the strategic decision itself.

41. Internal Audit and Governance Maturity

Organizations can have different levels of governance maturity.

Level 1: Reactive

Controls are established after problems occur.

Level 2: Basic

Policies and controls exist but implementation is inconsistent.

Level 3: Structured

Governance, risk and control processes are formally established.

Level 4: Integrated

Risk, governance and assurance activities are coordinated.

Level 5: Proactive

The organization continuously monitors emerging risks and improves governance systems.

The board should seek continuous improvement rather than assuming that governance is permanently “complete.”

42. The Board’s Ultimate Assurance Responsibility

The board does not personally provide every form of assurance.

Its responsibility is to ensure that the organization has an appropriate assurance architecture.

This means ensuring:

  • Significant risks are identified.
  • Appropriate controls exist.
  • Assurance functions are sufficiently independent.
  • Important weaknesses are reported.
  • Corrective actions are implemented.
  • Serious concerns are escalated.
  • Stakeholders receive appropriate information.

The board therefore acts as the ultimate overseer of organizational assurance.

43. Executive Application Exercise

Board Assurance Assessment

Select an organization you are familiar with and evaluate its assurance framework.

1. Internal Audit

Does the organization have an internal audit function?

2. Independence

Who does internal audit report to?

3. Risk Coverage

Does internal audit focus on the organization’s most significant risks?

4. Audit Committee

Does an audit committee exist?

5. External Audit

How is external audit managed and overseen?

6. Internal Controls

What major internal controls exist?

7. Audit Findings

How are weaknesses reported?

8. Corrective Action

How does management respond to audit findings?

9. Follow-Up

Who verifies that corrective actions have been implemented?

10. Board Oversight

How does the board receive and evaluate assurance information?

Identify three strengths, three weaknesses and three recommendations for improving the organization’s assurance framework.

Lesson Summary

Internal audit and assurance are important components of effective corporate governance.

Internal audit provides independent and objective assessments of governance, risk management and internal controls.

The board should ensure that internal audit:

  • Has sufficient independence.
  • Has an appropriate mandate.
  • Has adequate resources.
  • Uses a risk-based audit plan.
  • Reports significant findings.
  • Follows up unresolved issues.
  • Has access to the audit committee and board.

The audit committee plays an important role in overseeing internal and external audit, financial reporting and internal controls.

Effective assurance requires more than producing audit reports.

The governance process should operate as:

Risk Identification → Control → Assurance → Finding → Corrective Action → Follow-Up → Board Oversight

The board should also recognize that assurance is broader than financial auditing.

Modern organizations require assurance over:

  • Financial reporting.
  • Risk management.
  • Internal controls.
  • Compliance.
  • Cybersecurity.
  • Operations.
  • Fraud.
  • Governance.
  • Organizational resilience.

Ultimately, effective board oversight of internal audit and assurance helps the organization identify weaknesses early, strengthen controls, improve accountability and protect long-term organizational value.

References

  • The Institute of Internal Auditors (IIA) — Global Internal Audit Standards
  • The Institute of Internal Auditors — Three Lines Model
  • G20/OECD Principles of Corporate Governance 2023
  • International Finance Corporation (IFC) — Corporate Governance Methodology
  • Committee of Sponsoring Organizations of the Treadway Commission (COSO) — Internal Control Framework
  • Financial Reporting Council (FRC) — UK Corporate Governance Code