فحص وتقييم نظام المراجعة الداخلية

Having an “internal auditor” on the organisation chart does not mean you have internal audit. The difference shows up in the first crisis: an embezzlement that went undetected, a finding repeated for three years without remediation, or an annual report containing only what executive management wants to read. Assessing the internal audit function is what reveals that before the crisis rather than after it.

What the internal audit unit is supposed to do

The Corporate Governance Regulations for Non-Listed Joint Stock Companies issued by the Ministry of Commerce (advisory) set this out in Articles 72–78, and the Corporate Governance Regulations issued by the Capital Market Authority in Articles 71–75 describe substantially the same structure:

  • Scope: examining and assessing the adequacy and effectiveness of internal control systems, evaluating risk management policies, and verifying compliance with governance rules and with the applicable laws, including that related party transactions are carried out within their controls.
  • Reporting line: the audit committee recommends the appointment of the internal auditor, who is accountable to it, is not assigned other duties, and whose remuneration is set on the committee’s proposal.
  • The plan: a comprehensive plan approved by the audit committee and updated annually, covering the main activities and processes — including risk management and compliance — at least once a year.
  • Reporting: a written report submitted to the board and the audit committee at least semi-annually, setting out the results of the work, a comparison with earlier reports, and the recommendations implemented.

In listed companies the unit is mandatory under the CMA regulations, and it may be outsourced without prejudice to the company’s own responsibility. For non-listed joint stock companies the provisions are advisory, and for limited liability companies the function is not required by law. But it is the practical benchmark against which the function is measured by shareholders, lenders and courts.

How an internal audit function is actually assessed

The assessment does not start by reading reports. It starts with four questions answered by evidence:

  1. Is the function genuinely independent? Check the reporting line in the charter and in practice: who approves the plan, who appraises the internal auditor, who sets the remuneration, and whether they have attended audit committee meetings without executive management present. An internal auditor reporting to the CFO is internal financial control, not internal audit.
  2. Is the plan risk-based? Ask for the risk register and compare it with the plan: did it cover the high-risk cycles — procurement, cash, inventory, payroll and related parties — or did it repeat last year’s plan? Then compute the ratio of work actually performed to work planned.
  3. Does the evidence support the conclusions? Select a sample of engagements and examine the working papers: the objective, the scope, how the sample was selected, the tests performed, and the link between each finding and its evidence. A finding with no working paper is an opinion, not an audit result.
  4. Are findings closed? Track the findings of the last three years: how many were closed with evidence, how many were reopened, and how many recurred. The same finding recurring three times points to a problem in follow-up and authority rather than in detection.

Weaknesses that surface quickly

  • The annual plan is approved a quarter or more into the year.
  • The internal auditor performs executive work: preparing entries, approving payments, or running the procurement cycle — which the regulations expressly prevent by barring other assignments.
  • There is no written internal audit charter approved by the board defining authority, scope and the right of access to records.
  • Reports describe procedures without measuring impact: “the procurement cycle was reviewed”, with no sample size, number of exceptions, or their value.
  • No private sessions between the audit committee and the internal auditor, or between the committee and the external auditor.
  • The unit is one person with no training, no budget and no system access.

What the assessment delivers

  • A written maturity assessment across independence and reporting line, charter and authority, risk-based planning, methodology and working papers, competencies, and reporting and follow-up.
  • Gaps ranked by impact against Articles 72–78 of the Ministry’s regulations and Articles 71–75 of the Authority’s regulations, rather than against a general impression.
  • A remediation plan with an owner and a deadline for each gap, capable of being approved by the audit committee in a single meeting.
  • A charter, methodology and working paper templates ready for use where the unit is new or undocumented.

An external assessment is not an accusation against the existing function. It is what gives its reports weight before the board, and it protects the internal auditor when they disagree with executive management.

Is an internal audit unit mandatory for my company?

In listed companies it is mandatory under the CMA’s Corporate Governance Regulations. For non-listed joint stock companies the Ministry of Commerce provisions are advisory, and for limited liability companies it is not required by law, though it may be provided for in the articles.

Can internal audit be outsourced?

Yes. Both sets of regulations allow it without prejudice to the company’s responsibility for the function. Outsourcing does not relieve the board and the audit committee of approving the plan and following up findings.

What is the difference between internal and external audit?

The external auditor expresses an opinion on the fair presentation of the financial statements as a whole at a defined materiality level. Internal audit examines the adequacy and effectiveness of control, risk and compliance throughout the year and reports to the board and the audit committee.

How often should the function be reassessed?

An external assessment every few years, with an annual self-assessment presented to the audit committee; more important is tracking the closure rate of findings quarterly.

Sources

  • Corporate Governance Regulations for Non-Listed Joint Stock Companies — Ministry of Commerce (advisory) — Articles 72–78
  • Corporate Governance Regulations — Capital Market Authority — Articles 71–75, and Articles 51 and 53–57 on the audit committee
  • Companies Law (Royal Decree M/132)

Related guides

التعليقات معطلة.