Governing the Internal Audit Function (Part 1/5): Setting up an Internal Audit Function

Governing the Internal Audit Function (Part 1/5): Setting up an Internal Audit Function

Introduction

The internal audit function plays a critical role in ensuring that organisations operate efficiently, manage risks, and maintain accountability. The new Global Internal Audit Standards were released on 9 January 2024 and become effective from 9 January 2025. These standards, overseen by the International Internal Audit Standards Board and the IPPF Oversight Council, aim to enhance the quality and consistency of internal audit practices globally.

At its core, internal auditing is designed to strengthen an organisation’s ability to create, protect, and sustain value. This is achieved by providing the board and management with independent, objective, and risk-based assurance, advice, insight, and foresight. The updated standards reinforce this role but also recognise that different organisations, especially those with smaller audit functions or public sector bodies, may face unique challenges in their implementation.

The standards acknowledge that small internal audit functions with limited resources may find certain tasks challenging. It is noted that if the internal audit function consists of only one member, an adequate quality assurance and improvement programme will require assistance from outside the internal audit function.

Recognition is also given to the fact that internal auditors in the public sector work in a political environment under governance, organisational, and funding structures that may differ from those in the private sector. Therefore, the nature of these structures and related conditions may be affected by the jurisdiction and level of government in which the internal audit function operates. The standards also recognise that some terminology used in the public sector may differ from that in the private sector. These differences may affect how internal audit functions in the public sector apply the standards.

The Global Internal Audit Standards

Every internal audit function must operate under a formal charter that clearly defines its purpose, authority, and responsibilities.

The Standards require that in industries or jurisdictions where internal audit mandates are legally prescribed, the charter must reflect these legal requirements. This ensures that the internal audit function aligns with both the organisation's specific needs and the broader regulatory framework in which it operates.

Standard 6.2. requires that, at a minimum, the Internal Audit Charter must specify the following:

  • Purpose of Internal Auditing.
  • Commitment to adhering to the Global Internal Audit Standards.
  • Mandate, including scope and types of services to be provided, and the board’s responsibilities and expectations regarding management’s support of the internal audit function.
  • Organizational position and reporting relationships.

Legal and Regulatory Considerations for the Public Sector in South Africa

Both the Public Finance Management Act (PFMA) and the Municipal Finance Management Act (MFMA) in South Africa outline specific requirements for internal audit systems.

  • The PFMA mandates that departments, trading entities, constitutional institutions, and public entities must maintain a system of internal audit under the direction of an audit committee, ensuring compliance with relevant regulations and instructions.
  • The MFMA specify that the accounting officer of a municipality and municipal entity must take all reasonable steps to ensure that the municipality has and maintains effective, efficient, and transparent systems of internal audit that comply with and operate according to any prescribed norms and standards.
  • The PFMA Treasury regulations provide for the relevant treasury to direct that institutions share internal audit functions, if considered feasible. The regulations also allow for an internal audit function to be partly or wholly contracted to an external organisation with specialist audit expertise, provided that its selection follows the relevant government’s competitive tendering procedures. These provisions are consistent in both the PFMA and MFMA.

Aligning with Corporate Governance Best Practices

Beyond legal requirements, organisations in both the public and private sectors should consider corporate governance best practices, such as those outlined in the King IV Code of Corporate Governance. King IV Practice 49 emphasises that the governing body of an organisation must approve an internal audit charter. This charter should define the internal audit’s role, authority, and responsibilities and clarify how it fits into the broader assurance model of the organisation, including its role within combined assurance.

Conclusion

As we approach the January 2025 implementation date, now is the time for organisations to review their internal audit structures and make any necessary adjustments to ensure they are compliant and positioned to provide valuable insights and assurance.

For public sector organisations, it is essential to align internal audit practices with the governance and legislative frameworks such as the PFMA and MFMA, ensuring compliance while delivering efficient and effective audits. Similarly, private sector entities should look to corporate governance best practices, such as the King IV Code, to ensure their internal audit function supports broader organisational goals.

The next articles in the series will cover the following topics:

  • Positioning, resourcing and supporting the Internal Audit Function

  • Enhancing the Independence of the Internal Audit Function
  • Overseeing the Effectiveness of the Internal Audit Function
  • Overseeing the Quality Management of the Internal Audit Function


Contact me at julius@ditsibiconsulting.com if you or your organisation may benefit from the following:

  • Global Internal Audit Standards Masterclass – 2 days
  • Personal Branding for Accounting and Finance Professionals Workshop – 5 hours
  • Audit Manager Onboarding Programme – 4 days over 1 Month
  • Trainee/Intern Efficacy development Course – 10 days over 3 months
  • Strategy Session Facilitation
  • Internal Audit Services (Co-Sourcing and Outsourcing)
  • Internal Audit External Quality Assessments (EQA)
  • Risk Management Services (Co-sourcing and Outsourcing)

Kelello Leeuw

Assistant Director: Internal Audit, CIA candidate

2mo

Very helpful.

Uejaa Mberirua

Accounting Manager at FirstRand group

2mo

Very informative, thank you,

FALAK TYAGI

Specialist – Audit, Team Facilitator @ Ujjivan Small Finance Bank Ltd. | 10 years of experience in ATM/ACR product management, deployment, operations, process, and training the team.

2mo

Insightful

Anirudh Pratap Singh 🏆

Co-founder | Pragmatist | Result Oriented | Director of Technical Operations @ Payomatix | Contact for anything related to payments | anirudh.pratap@payomatix.com

2mo

Mathabatha Julius Mojapelo CIA, CRMA, CA(SA), RA (IRBA), BSQP, PEQA, insightful analysis on organizational resilience through strategic internal auditing. Anticipating further thought-provoking guidance.

Dimakatso Khatatso-Kubheka

Assistant Director: Internal Audit at Department of Energy

2mo

Thank you very informative

To view or add a comment, sign in

More articles by Mathabatha Julius Mojapelo CIA, CRMA, CA(SA), RA (IRBA), BSQP, PEQA

Insights from the community

Others also viewed

Explore topics