Elixir Audits, Chartered Accountants

Internal audit works for your board, not for your shareholders. It tests whether the controls you believe are operating actually operate, and it reports internally. That is a different question from the one a statutory audit answers, and many businesses need both.

When it becomes worth having

Usually at the point growth outruns process. The controls that worked at twenty staff do not work at eighty, the owner can no longer see everything personally, and the same findings start appearing in the management letter year after year. Internal audit earns its keep by finding revenue leakage before your external auditor does.

Outsourced or co-sourced

Where you have no internal audit function, we run it: annual plan agreed with the committee, fieldwork, reporting. Where you already have a team, we supplement it on the areas it does not have depth in, typically IT, tax, treasury or a specialist sector requirement. Co-sourcing is often the better answer, because it builds your own capability rather than replacing it.

Why most internal audit reports do nothing

Because they list findings without ranking them, assign them to a department rather than a person, and describe remedies that cannot be tested. We write findings so that somebody who was not in the room could verify whether the fix happened. That single discipline is the difference between a report that changes something and one that gets filed.

Your board

Who internal audit reports to, and answers to

Risk-based

The plan follows exposure, not a standard checklist

Quarterly

Findings reviewed as a standing agenda item

Scope

What an internal audit function covers

The plan is agreed with your audit committee each year and follows where your exposure actually sits.

01

Risk assessment and annual plan

We map the business, rank processes by exposure, and agree a plan with the committee. The plan is revisited when something material changes rather than held for twelve months regardless.

02

Controls testing and fieldwork

Walkthroughs of what actually happens rather than what the policy says, then testing on the controls that matter. Revenue, procurement, payroll, treasury and stock are where we usually start.

03

Reporting to the audit committee

Findings ranked by financial exposure, each with a named owner, a testable remedy and a date. Written to be read by directors, not by auditors.

04

Follow-up and closure

Tracking whether remedies were implemented and testing that they operate. A finding logged and never retested is a finding that will reappear.

Process

How the function runs

Internal audit is a cycle rather than a project, and the value comes from it being scheduled and minuted.

Independence matters here tooWe cannot design a control and then opine on whether it operates, and we cannot provide internal audit to a company we audit statutorily. We assess this before accepting and tell you the position before you commit.

Risk assessment

Business mapping and exposure ranking, with management interviews across functions rather than only finance.

Weeks 1 to 3

Plan agreed with the committee

A written annual plan the audit committee approves, so the scope is theirs rather than ours.

Week 4

Review cycle

Fieldwork on the areas in the plan, typically one or two reviews per quarter.

Quarterly

Committee reporting

Findings presented in person, with the register as a standing agenda item.

Each quarter

Follow-up testing

Retesting closed items to confirm the remedy operates rather than accepting that it was implemented.

Following quarter

Engagement

Fees, timing and who does the work

Fee basis

Annual retainerSet on the number of reviews in the plan and the complexity of the processes covered. Individual reviews quoted separately.

Who does the work

A manager, partner reviewedThe same team across the cycle, so the business does not have to be re-explained each quarter.

Reporting

Quarterly to the committeeIn person, with a written register that carries forward.

Indicative only. Every fee is quoted in the proposal, before any work starts, and held unless the scope changes.

Questions

Questions from boards and audit committees

What is the difference between internal and statutory audit?
A statutory audit is an independent opinion for people outside the business: shareholders, lenders, regulators. Internal audit works for your board, testing whether your own controls operate, and reports internally. They answer to different people and cover different ground.
Can you provide both to the same company?
No. Providing internal audit to a statutory audit client creates a self-review threat that independence rules do not permit. Where you need both we will tell you which we can do and help you appoint another firm for the other.
We have an internal audit team already. Is there a role for you?
Frequently, on a co-sourced basis. Most in-house teams are strong on the areas they run regularly and thin on IT, tax, treasury or a specialist sector requirement. We supplement rather than replace.
Do we need an audit committee to use this?
It helps, but no. Where there is no committee, and many owner-managed businesses have none, the same reporting works at a scheduled monthly management meeting. What matters is that it is scheduled and minuted.
How is the annual plan decided?
By risk. We map the business, rank processes by financial exposure and likelihood, and put a draft plan to the committee. The committee approves it, which matters, because the scope should be theirs rather than ours.

Next step

Tell us where the same findings keep coming back.

That conversation usually tells us more about where to start than any amount of process documentation.

Request an internal audit proposal Speak to a partner

Contact

+233 53 362 2433 info@elixiraudits.com

1 Alex Nkrumah Street, Airport West, Accra