Internal audit and control reviews
Audit and assurance
·
On demand
A purchase can have an approval on paper while payments still bypass it. A stock reconciliation can be prepared every month while differences remain unresolved. Internal audit examines how a process actually operates and whether its controls address the risks the business faces.
TheTaxCo undertakes internal audit and defined control reviews subject to professional eligibility, independence and an agreed scope. The work may cover a business process, location, system of controls or a planned programme of reviews. The reporting line and access to records are agreed at appointment.
Decide what needs examination
The starting point is the business risk: loss of stock, unauthorised payments, unreliable reporting, revenue leakage or failure to follow an important requirement. Management’s concerns, earlier findings and changes in operations help determine the review priorities.
A process review might follow purchases from supplier creation through ordering, receipt, invoicing and payment. A payroll review might examine employee master changes, attendance inputs, approval of revisions and payment controls. A receivables review can connect credit approval, invoicing, collections, credit notes and write-offs.
We define the period, locations, records and testing approach. A review of one warehouse does not support a conclusion about every warehouse. If the available population is incomplete, that affects the procedures and the conclusions that can be drawn.
Mandatory appointment and voluntary review
Section 138 of the Companies Act provides for internal audit for prescribed classes of companies. Applicability requires a review of the company’s category and the relevant financial criteria; there is no universal exemption simply because a business is privately held. A business outside mandatory coverage can still commission a voluntary control review. Companies Act, section 138
Independence is assessed before acceptance. Section 144 prohibits the statutory auditor from providing internal audit to the audited company and specified related entities, directly or indirectly. Management approval does not override that prohibition. Companies Act, section 144
Test design and operation separately
A control may be poorly designed even if staff follow it. For example, allowing the same person to create a supplier and release its payment leaves a weakness in the approval structure. A properly designed control may also fail in operation when required approvals are skipped.
We examine process documents and discuss the actual workflow with the people responsible. Testing then considers evidence such as authorisations, transaction records, reconciliations, system permissions and the handling of exceptions. The sample and procedures follow the agreed risk and scope; we do not describe a sample review as an examination of every transaction.
Illustrative finding: a reconciliation was signed each month, but old differences were carried forward without an owner or investigation. The useful recommendation is to assign responsibility, investigate the differences and retain evidence of resolution. Requiring another signature alone would not address that failure.
Where a matter suggests possible misconduct, we record the evidence and discuss an appropriate extension or separate investigation with the authorised recipient. A routine internal audit should not imply that every fraud will be detected.
Reports that support corrective action
Each material finding should state the condition found, the evidence and scope, why it matters, and the proposed corrective action. Management’s response is recorded alongside the action owner and target date. Differences of view remain visible rather than being removed to produce an agreeable report.
You receive a review plan, process observations, a prioritised findings report and an action tracker. Reporting frequency depends on the assignment and the organisation’s needs. Significant matters may require earlier communication instead of waiting for the scheduled report.
Our follow-up review examines whether the agreed action was implemented and whether it works. A procedure being rewritten is not proof that staff are following it. Closure requires evidence appropriate to the original finding.
Records and working arrangements
The initial request usually covers process descriptions, organisation and authority charts, relevant policies, transaction populations, previous findings and system or access information needed for the review. We then request the supporting records for selected tests through the agreed access arrangements.
The work estimate depends on the number of processes and sites, record quality, sample coverage and availability of staff. Business managers remain responsible for operating the controls and deciding on corrective action. The internal auditor assesses and reports within the engagement.
Is internal audit the same as statutory audit?
No. Internal audit examines the agreed functions and controls. Statutory audit has a separate appointment and financial-reporting objective. See statutory audit for that service.
Can you investigate a suspected diversion of funds?
A specific allegation may require a separately scoped forensic investigation, with defined evidence preservation, authority and reporting arrangements. We first establish the question and records at risk.
Can we begin with one process?
Yes. A focused review can be appropriate where the concern is identifiable. The report will make the coverage and limitations clear so that its findings are not mistaken for a business-wide conclusion.
Email TheTaxCo, message us on WhatsApp or book a call. Share the process or concern, entities and locations involved, and the person or committee that will receive the report.