Audit & Assurance

Internal Audit

Review of processes and controls against a scope agreed with management.

Scope-dependent; a focused review typically runs 1–3 weeks per cycle

Internal audit looks inward. Where a statutory audit asks whether the financial statements are fairly stated, an internal audit asks whether the processes producing them are working — whether approvals are obtained, whether stock is controlled, whether what is recorded matches what happened.

It is commissioned by management or the board, and its scope is agreed in advance rather than fixed by statute. For some companies it is also a statutory requirement.

Agreeing a useful scope

An internal audit covering everything shallowly is rarely worth commissioning. The more useful approach is to pick the areas where an error or a leakage would actually hurt — purchases, stock, cash handling, payroll — and examine those properly.

We agree that scope with you at the outset, in writing, so both sides know what is and is not being looked at.

Findings you can act on

A finding that says a control is weak is of limited use. A finding that says which control, what it allowed to happen, how often, and what it would take to close the gap can be acted on.

We report at that level, and distinguish between issues that need attention now and observations that are worth noting but not urgent.

Who needs this

  • Companies required to appoint an internal auditor under the applicable law
  • Businesses with multiple locations, where oversight is harder
  • Businesses that have grown faster than their processes
  • Owners who want an independent check on cash, stock or purchase processes

Eligibility and conditions

  • A scope agreed with management or the board
  • Access to records, systems and the people who operate the processes
  • An agreed reporting line for the findings

What this covers

  • Scope agreed in writing

    What is covered, and what is not, settled before work starts.

  • Process walkthroughs

    How work actually happens, not how the manual says it does.

  • Findings with context

    What the gap is, what it allowed, and what closing it involves.

  • Prioritised reporting

    Issues separated from observations, so attention goes where it matters.

  • Follow-up reviews

    Whether agreed actions were implemented.

How the process works

  1. Agree the scope

    Areas, period and reporting line settled with management.

  2. Understand the process

    Walkthroughs with the people who run it.

  3. Test

    Sample testing against the controls that are meant to operate.

  4. Discuss findings

    Draft findings validated with the process owners.

  5. Report

    Findings issued, prioritised, with suggested actions.

Documents required

  • Process documentation

    Manuals or written procedures, where they exist.

  • Organisation and authority matrix

    Who approves what, and up to what limit.

  • Transaction records

    For the areas and period under review.

  • System access

    Read access to the accounting or ERP system.

  • Previous audit reports

    Internal or statutory, for context.

  • Exception reports

    Any known incidents or losses in the period.

The list above is indicative. Additional documents may be required depending on your case and the current departmental requirements.

Frequently asked questions

Does an audit guarantee that there is no fraud in my business?

No. An audit provides reasonable assurance, not absolute assurance. It is designed to detect misstatement that is material to the financial statements as a whole, using risk-based and selective testing rather than examination of every transaction.

Where detecting irregularity in a specific area is the objective, an internal audit or a focused review with an agreed scope is the more suitable engagement.

Considering an internal audit?

Tell us which areas concern you and we will propose a scope and what it would involve.