Internal audit works for your board, not for your shareholders. It tests whether the controls you believe are operating actually operate, and it reports internally. That is a different question from the one a statutory audit answers, and many businesses need both.
When it becomes worth having
Usually at the point growth outruns process. The controls that worked at twenty staff do not work at eighty, the owner can no longer see everything personally, and the same findings start appearing in the management letter year after year. Internal audit earns its keep by finding revenue leakage before your external auditor does.
Outsourced or co-sourced
Where you have no internal audit function, we run it: annual plan agreed with the committee, fieldwork, reporting. Where you already have a team, we supplement it on the areas it does not have depth in, typically IT, tax, treasury or a specialist sector requirement. Co-sourcing is often the better answer, because it builds your own capability rather than replacing it.
Why most internal audit reports do nothing
Because they list findings without ranking them, assign them to a department rather than a person, and describe remedies that cannot be tested. We write findings so that somebody who was not in the room could verify whether the fix happened. That single discipline is the difference between a report that changes something and one that gets filed.
Who internal audit reports to, and answers to
The plan follows exposure, not a standard checklist
Findings reviewed as a standing agenda item
Scope
What an internal audit function covers
The plan is agreed with your audit committee each year and follows where your exposure actually sits.
Risk assessment and annual plan
We map the business, rank processes by exposure, and agree a plan with the committee. The plan is revisited when something material changes rather than held for twelve months regardless.
Controls testing and fieldwork
Walkthroughs of what actually happens rather than what the policy says, then testing on the controls that matter. Revenue, procurement, payroll, treasury and stock are where we usually start.
Reporting to the audit committee
Findings ranked by financial exposure, each with a named owner, a testable remedy and a date. Written to be read by directors, not by auditors.
Follow-up and closure
Tracking whether remedies were implemented and testing that they operate. A finding logged and never retested is a finding that will reappear.
Process
How the function runs
Internal audit is a cycle rather than a project, and the value comes from it being scheduled and minuted.
Risk assessment
Business mapping and exposure ranking, with management interviews across functions rather than only finance.
Weeks 1 to 3Plan agreed with the committee
A written annual plan the audit committee approves, so the scope is theirs rather than ours.
Week 4Review cycle
Fieldwork on the areas in the plan, typically one or two reviews per quarter.
QuarterlyCommittee reporting
Findings presented in person, with the register as a standing agenda item.
Each quarterFollow-up testing
Retesting closed items to confirm the remedy operates rather than accepting that it was implemented.
Following quarterEngagement
Fees, timing and who does the work
Fee basis
Annual retainerSet on the number of reviews in the plan and the complexity of the processes covered. Individual reviews quoted separately.Who does the work
A manager, partner reviewedThe same team across the cycle, so the business does not have to be re-explained each quarter.Reporting
Quarterly to the committeeIn person, with a written register that carries forward.Questions
Questions from boards and audit committees
What is the difference between internal and statutory audit?
Can you provide both to the same company?
We have an internal audit team already. Is there a role for you?
Do we need an audit committee to use this?
How is the annual plan decided?
Next step
Tell us where the same findings keep coming back.
That conversation usually tells us more about where to start than any amount of process documentation.
Also under Audit and Assurance
Statutory audit under the Companies Act 2019
The independent opinion required before your financial statements can be issued, filed or circulated. Conducted under International Standards on Auditing by a partner who stays on the engagement from planning to signing.
Forensic audit and investigations
Where fraud, misappropriation or a serious control failure is suspected. Evidence gathered and documented to a standard that holds up in a disciplinary process, an insurance claim or in court, and scoped so the investigation does not tip off the people it concerns.
NGO and donor-funded grant audits
Grant audits, expenditure verification and agreed-upon procedures for international NGOs, local implementing partners and donor-funded programmes operating in Ghana and the sub-region. Reported in the template your funder actually requires.
