SlideShare uma empresa Scribd logo
1 de 4
NBI Internal Audit Methodology
Information
gathering
Planning
Overview of the
Organisation
 Gather and analyse
industry information
 Identify strategies,
objectives and
processes
 Determine
legislative
requirements
Execution Reporting Follow-up
Enterprise Risk
Assessment
 Identify high risk
areas
 Analyse and
evaluate the risk
information
 Determine areas to
be audited
Plan development
 Determine
processes and
projects
 Utilise risk
assessment results
 Determine resources
and timing
 Develop and draft
the plan
 Obtain audit
Committee approval
 Maintain and update
plan
Execution
 Notification of
process owner and
kick-off meeting
 Project planning
 Process description
and audit
programme creation
 Testing and
documenting
Process owner
reporting
 Identified risks
 All findings
identified during
field work (including
medium and low
risks)
 Process
improvements noted
 Follow-up items
from previous
reports
 Management action
plans
Issue resolution and
follow-up
 Follow-up on issue
resolution
 Monitor and assess
management’s
progress against
agreed-upon action
plans
 Adequacy of actual
actions taken
 Timeliness of issue
resolution
 Report the progress
to senior
management and
the Audit and Risk
Committee
 Escalate unresolved
issues
Audit and Risk
Committee
 All significant
findings
 Management action
plans and due date
Internal Audit Execution
1) Notification of process owner and Kick-off meeting
 Review of high-level audit objectives and scope.
 Audit process and time line.
 Communications, reporting, and follow-up activities.
 Discussion of business objectives, risks, and key activities
2) Project planning
 Define the scope and allocate time.
 Determine if additional resources or training is required.
 Implement monitoring tools to manage the project
3) Process description and audit programme
 Document the process by conducting interviews and reviewing procedure documents
 Perform walkthrough of the processes
 Identify risk areas and control gaps.
 Develop procedures to test the key controls identified during the process description
 Control gaps are tested to determine the to determine the magnitude of the risk
4) Testing and documenting
 Create working papers based on the audit programme
 Determine the population, testing quantity and the source documents to be used.
 Test the design and operating effectiveness of internal controls, including financial, operational and compliance
4) Testing and documenting (continued)
 Perform manual control testing through observation, inquiry, re-performance, inspection and knowledge assessment
 Perform substantive testing when the controls are determined to be ineffective to assist with evaluating the extent or impact of the
ineffective control
 The use of CAAT may be involved. Create working papers based on the audit programme
Supporting documentation:
 Exception based documentation is kept on file and if no exception is noted then one copy of an item tested. If an exception is noted then a
copy of the exception as well as one of the items tested without an exception is kept on file.
 All supporting documentation is maintained
 Supporting documentation is reviewed in in conjunction with the working papers.
5) Confirm and report findings
 A finding is noted when the results of internal controls testing denotes that the control is either missing or not working as expected.
These findings are all documented in the working papers.
 Performance improvement observations (POI) are areas that can be improved but do not involve a control weakness or an area that falls
outside the scope of the internal audit project.
 The details of the findings should be confirmed and validated with the process owner before reporting.
 All findings will be documented in audit report and tie back to the summary of findings document.
 A close out meeting should be held with the process owner and any other key contacts for the project.
 The draft report will be presented and discussed during this meeting.
 Minutes of the meeting will be kept on file.
 The objective is to clearly communicate and finalise findings with the process owner and obtain acceptance and support for the reporting
items and the recommendations.
6) Review of reports
 All reports are reviewed by the senior auditor, the internal audit manager and the head of internal audit before they are presented to the Audit
and Risk Committee.
 Before the reports are reported to the Audit and Risk Committee they are reviewed by the process owner and the head of division.
 During the meeting with the process owner and the head of division can they request any working papers and supporting documentation.
 Disagreements between the Internal Auditor and the process owner and head of division that are not resolved will be discussed at the Audit
and Risk Committee.
Special Assignments
Request for Special
assignment
• Managers are encouraged to approach their senior managers (SMT) with the requests for a special assignments, unless they have a valid
reason for bypassing their senior manager.
• Members of the SMT can come directly to the internal auditor or to financial director for the special assignments, however, the requests
that come directly to the internal auditor are communicated to financial director for input.
• Once the request is received , will a meeting be set up between the manager, their senior manager, the financial director and the internal
auditor.
Establishing the
need for a special
assignment
•During the meeting the following questions will be asked to determine the need for the special assignment:
•Is the reason for involving internal audit instead of dealing with the issue within the department valid?
•Is the risk significant and is the assignment urgent?
•Has the root cause been established?
•Can tools be provided to resolve the issue instead of conducting a detailed audit?
Planning for special
assignment
•If it is not possible to resolve the issue within the department then internal audit is required to perform an audit:
•If the assignment is not urgent then it will be added to the existing internal audit plan and additional testing will be included for the special
assignment.
•If the assignment is urgent then arrangements are made to conduct the assignemnt within the required period, depending on the
available resources (staff, time, etc)

Mais conteúdo relacionado

Mais procurados

Mais procurados (20)

Compiling an internal audit universe
Compiling an internal audit universeCompiling an internal audit universe
Compiling an internal audit universe
 
Basic internal auditing
Basic internal auditingBasic internal auditing
Basic internal auditing
 
Risk assessment and internal controls - Internal Audit
Risk assessment and internal controls - Internal AuditRisk assessment and internal controls - Internal Audit
Risk assessment and internal controls - Internal Audit
 
Ch 9. Internal Audit
Ch 9. Internal AuditCh 9. Internal Audit
Ch 9. Internal Audit
 
Evolving role of internal auditing function
Evolving role of internal auditing functionEvolving role of internal auditing function
Evolving role of internal auditing function
 
Basic Internal Auditing Presentation
Basic Internal Auditing PresentationBasic Internal Auditing Presentation
Basic Internal Auditing Presentation
 
Internal Audit effectiveness
Internal Audit effectivenessInternal Audit effectiveness
Internal Audit effectiveness
 
Internal audit report writing.pdf
Internal audit   report writing.pdfInternal audit   report writing.pdf
Internal audit report writing.pdf
 
Standards of Internal Audit
Standards of Internal AuditStandards of Internal Audit
Standards of Internal Audit
 
Internal Audit
Internal AuditInternal Audit
Internal Audit
 
Internal audit report writing
Internal audit report writingInternal audit report writing
Internal audit report writing
 
Internal Audit Strategic Framework
Internal Audit Strategic FrameworkInternal Audit Strategic Framework
Internal Audit Strategic Framework
 
Ppt on risk based internal audit
Ppt on risk based internal auditPpt on risk based internal audit
Ppt on risk based internal audit
 
Internal Audit Reporting
Internal Audit ReportingInternal Audit Reporting
Internal Audit Reporting
 
Internal Audit
Internal AuditInternal Audit
Internal Audit
 
Internal audit
Internal auditInternal audit
Internal audit
 
Internal audit
Internal auditInternal audit
Internal audit
 
Presentation on Internal Audit Standards
Presentation on Internal Audit StandardsPresentation on Internal Audit Standards
Presentation on Internal Audit Standards
 
Internal Auditor Roles
Internal Auditor RolesInternal Auditor Roles
Internal Auditor Roles
 
Improving effectiveness of internal auditing
Improving effectiveness of internal auditingImproving effectiveness of internal auditing
Improving effectiveness of internal auditing
 

Semelhante a Internal Audit Methodology.docx

ARC 1-19^J 1-5(12marks).pptx
ARC 1-19^J 1-5(12marks).pptxARC 1-19^J 1-5(12marks).pptx
ARC 1-19^J 1-5(12marks).pptx
SohailSheikh62
 
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
Addisu15
 
Practical_aspects_of_Statutory_Audit_Doc_to_reporting_by_CA._Amit_Doshi.pdf
Practical_aspects_of_Statutory_Audit_Doc_to_reporting_by_CA._Amit_Doshi.pdfPractical_aspects_of_Statutory_Audit_Doc_to_reporting_by_CA._Amit_Doshi.pdf
Practical_aspects_of_Statutory_Audit_Doc_to_reporting_by_CA._Amit_Doshi.pdf
AbhishekPareek64
 
Internal Audit 03-03-16
Internal Audit 03-03-16Internal Audit 03-03-16
Internal Audit 03-03-16
Lisa Barnes
 
Arens12e 10
Arens12e 10Arens12e 10
Arens12e 10
John Sy
 

Semelhante a Internal Audit Methodology.docx (20)

Project auditing
Project auditingProject auditing
Project auditing
 
ARC 1-19^J 1-5(12marks).pptx
ARC 1-19^J 1-5(12marks).pptxARC 1-19^J 1-5(12marks).pptx
ARC 1-19^J 1-5(12marks).pptx
 
AT-5908 CPA REVIEW SCHOOL OF THE PHILIPPINES
AT-5908 CPA REVIEW SCHOOL OF THE PHILIPPINESAT-5908 CPA REVIEW SCHOOL OF THE PHILIPPINES
AT-5908 CPA REVIEW SCHOOL OF THE PHILIPPINES
 
Ia audit process_lisd
Ia audit process_lisdIa audit process_lisd
Ia audit process_lisd
 
Audit and regulatory compliance
Audit  and  regulatory complianceAudit  and  regulatory compliance
Audit and regulatory compliance
 
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
 
Basic Audit
Basic AuditBasic Audit
Basic Audit
 
Auditing Management systems based on ISO19011 By Eng. Karam Malkawi - Jordan
Auditing Management systems based on ISO19011 By Eng. Karam Malkawi - JordanAuditing Management systems based on ISO19011 By Eng. Karam Malkawi - Jordan
Auditing Management systems based on ISO19011 By Eng. Karam Malkawi - Jordan
 
Operational audit
Operational auditOperational audit
Operational audit
 
SFC Plan of engagement
SFC Plan of engagementSFC Plan of engagement
SFC Plan of engagement
 
How to do a Project Audit
How to do a Project AuditHow to do a Project Audit
How to do a Project Audit
 
Basic concepts of quality assurance
Basic concepts of quality assuranceBasic concepts of quality assurance
Basic concepts of quality assurance
 
Audit Planning - Considerations
Audit Planning - ConsiderationsAudit Planning - Considerations
Audit Planning - Considerations
 
Introduction to Internal Auditing FSMS
Introduction to Internal Auditing FSMSIntroduction to Internal Auditing FSMS
Introduction to Internal Auditing FSMS
 
auditing Fram . from the start to Reporting .pdf
auditing Fram . from the start to Reporting .pdfauditing Fram . from the start to Reporting .pdf
auditing Fram . from the start to Reporting .pdf
 
Practical_aspects_of_Statutory_Audit_Doc_to_reporting_by_CA._Amit_Doshi.pdf
Practical_aspects_of_Statutory_Audit_Doc_to_reporting_by_CA._Amit_Doshi.pdfPractical_aspects_of_Statutory_Audit_Doc_to_reporting_by_CA._Amit_Doshi.pdf
Practical_aspects_of_Statutory_Audit_Doc_to_reporting_by_CA._Amit_Doshi.pdf
 
How to Perform a Successful Internal Quality Audit
How to Perform a Successful Internal Quality AuditHow to Perform a Successful Internal Quality Audit
How to Perform a Successful Internal Quality Audit
 
Audit process tonatiuh lozada
Audit process tonatiuh lozadaAudit process tonatiuh lozada
Audit process tonatiuh lozada
 
Internal Audit 03-03-16
Internal Audit 03-03-16Internal Audit 03-03-16
Internal Audit 03-03-16
 
Arens12e 10
Arens12e 10Arens12e 10
Arens12e 10
 

Último

Presentation4 (2) survey responses clearly labelled
Presentation4 (2) survey responses clearly labelledPresentation4 (2) survey responses clearly labelled
Presentation4 (2) survey responses clearly labelled
CaitlinCummins3
 
Constitution of Company Article of Association
Constitution of Company Article of AssociationConstitution of Company Article of Association
Constitution of Company Article of Association
seri bangash
 
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportFuture of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Dubai Multi Commodity Centre
 

Último (20)

1Q24_EN hyundai capital 1q performance
1Q24_EN   hyundai capital 1q performance1Q24_EN   hyundai capital 1q performance
1Q24_EN hyundai capital 1q performance
 
How to Maintain Healthy Life style.pptx
How to Maintain  Healthy Life style.pptxHow to Maintain  Healthy Life style.pptx
How to Maintain Healthy Life style.pptx
 
NFS- Operations Presentation - Recurrent
NFS- Operations Presentation - RecurrentNFS- Operations Presentation - Recurrent
NFS- Operations Presentation - Recurrent
 
Series A Fundraising Guide (Investing Individuals Improving Our World) by Accion
Series A Fundraising Guide (Investing Individuals Improving Our World) by AccionSeries A Fundraising Guide (Investing Individuals Improving Our World) by Accion
Series A Fundraising Guide (Investing Individuals Improving Our World) by Accion
 
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdfInnomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
 
Potato Flakes Manufacturing Plant Project Report.pdf
Potato Flakes Manufacturing Plant Project Report.pdfPotato Flakes Manufacturing Plant Project Report.pdf
Potato Flakes Manufacturing Plant Project Report.pdf
 
Hyundai capital 2024 1q Earnings release
Hyundai capital 2024 1q Earnings releaseHyundai capital 2024 1q Earnings release
Hyundai capital 2024 1q Earnings release
 
wagamamaLab presentation @MIT 20240509 IRODORI
wagamamaLab presentation @MIT 20240509 IRODORIwagamamaLab presentation @MIT 20240509 IRODORI
wagamamaLab presentation @MIT 20240509 IRODORI
 
Creative Ideas for Interactive Team Presentations
Creative Ideas for Interactive Team PresentationsCreative Ideas for Interactive Team Presentations
Creative Ideas for Interactive Team Presentations
 
HAL Financial Performance Analysis and Future Prospects
HAL Financial Performance Analysis and Future ProspectsHAL Financial Performance Analysis and Future Prospects
HAL Financial Performance Analysis and Future Prospects
 
Toyota Kata Coaching for Agile Teams & Transformations
Toyota Kata Coaching for Agile Teams & TransformationsToyota Kata Coaching for Agile Teams & Transformations
Toyota Kata Coaching for Agile Teams & Transformations
 
A Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettA Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob Badgett
 
Presentation4 (2) survey responses clearly labelled
Presentation4 (2) survey responses clearly labelledPresentation4 (2) survey responses clearly labelled
Presentation4 (2) survey responses clearly labelled
 
Constitution of Company Article of Association
Constitution of Company Article of AssociationConstitution of Company Article of Association
Constitution of Company Article of Association
 
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportFuture of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
 
WAM Corporate Presentation May 2024_w.pdf
WAM Corporate Presentation May 2024_w.pdfWAM Corporate Presentation May 2024_w.pdf
WAM Corporate Presentation May 2024_w.pdf
 
stock price prediction using machine learning
stock price prediction using machine learningstock price prediction using machine learning
stock price prediction using machine learning
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
 
MichaelStarkes_UncutGemsProjectSummary.pdf
MichaelStarkes_UncutGemsProjectSummary.pdfMichaelStarkes_UncutGemsProjectSummary.pdf
MichaelStarkes_UncutGemsProjectSummary.pdf
 
TriStar Gold Corporate Presentation May 2024
TriStar Gold Corporate Presentation May 2024TriStar Gold Corporate Presentation May 2024
TriStar Gold Corporate Presentation May 2024
 

Internal Audit Methodology.docx

  • 1. NBI Internal Audit Methodology Information gathering Planning Overview of the Organisation  Gather and analyse industry information  Identify strategies, objectives and processes  Determine legislative requirements Execution Reporting Follow-up Enterprise Risk Assessment  Identify high risk areas  Analyse and evaluate the risk information  Determine areas to be audited Plan development  Determine processes and projects  Utilise risk assessment results  Determine resources and timing  Develop and draft the plan  Obtain audit Committee approval  Maintain and update plan Execution  Notification of process owner and kick-off meeting  Project planning  Process description and audit programme creation  Testing and documenting Process owner reporting  Identified risks  All findings identified during field work (including medium and low risks)  Process improvements noted  Follow-up items from previous reports  Management action plans Issue resolution and follow-up  Follow-up on issue resolution  Monitor and assess management’s progress against agreed-upon action plans  Adequacy of actual actions taken  Timeliness of issue resolution  Report the progress to senior management and the Audit and Risk Committee  Escalate unresolved issues Audit and Risk Committee  All significant findings  Management action plans and due date
  • 2. Internal Audit Execution 1) Notification of process owner and Kick-off meeting  Review of high-level audit objectives and scope.  Audit process and time line.  Communications, reporting, and follow-up activities.  Discussion of business objectives, risks, and key activities 2) Project planning  Define the scope and allocate time.  Determine if additional resources or training is required.  Implement monitoring tools to manage the project 3) Process description and audit programme  Document the process by conducting interviews and reviewing procedure documents  Perform walkthrough of the processes  Identify risk areas and control gaps.  Develop procedures to test the key controls identified during the process description  Control gaps are tested to determine the to determine the magnitude of the risk 4) Testing and documenting  Create working papers based on the audit programme  Determine the population, testing quantity and the source documents to be used.  Test the design and operating effectiveness of internal controls, including financial, operational and compliance
  • 3. 4) Testing and documenting (continued)  Perform manual control testing through observation, inquiry, re-performance, inspection and knowledge assessment  Perform substantive testing when the controls are determined to be ineffective to assist with evaluating the extent or impact of the ineffective control  The use of CAAT may be involved. Create working papers based on the audit programme Supporting documentation:  Exception based documentation is kept on file and if no exception is noted then one copy of an item tested. If an exception is noted then a copy of the exception as well as one of the items tested without an exception is kept on file.  All supporting documentation is maintained  Supporting documentation is reviewed in in conjunction with the working papers. 5) Confirm and report findings  A finding is noted when the results of internal controls testing denotes that the control is either missing or not working as expected. These findings are all documented in the working papers.  Performance improvement observations (POI) are areas that can be improved but do not involve a control weakness or an area that falls outside the scope of the internal audit project.  The details of the findings should be confirmed and validated with the process owner before reporting.  All findings will be documented in audit report and tie back to the summary of findings document.  A close out meeting should be held with the process owner and any other key contacts for the project.  The draft report will be presented and discussed during this meeting.  Minutes of the meeting will be kept on file.  The objective is to clearly communicate and finalise findings with the process owner and obtain acceptance and support for the reporting items and the recommendations. 6) Review of reports  All reports are reviewed by the senior auditor, the internal audit manager and the head of internal audit before they are presented to the Audit and Risk Committee.  Before the reports are reported to the Audit and Risk Committee they are reviewed by the process owner and the head of division.  During the meeting with the process owner and the head of division can they request any working papers and supporting documentation.  Disagreements between the Internal Auditor and the process owner and head of division that are not resolved will be discussed at the Audit and Risk Committee.
  • 4. Special Assignments Request for Special assignment • Managers are encouraged to approach their senior managers (SMT) with the requests for a special assignments, unless they have a valid reason for bypassing their senior manager. • Members of the SMT can come directly to the internal auditor or to financial director for the special assignments, however, the requests that come directly to the internal auditor are communicated to financial director for input. • Once the request is received , will a meeting be set up between the manager, their senior manager, the financial director and the internal auditor. Establishing the need for a special assignment •During the meeting the following questions will be asked to determine the need for the special assignment: •Is the reason for involving internal audit instead of dealing with the issue within the department valid? •Is the risk significant and is the assignment urgent? •Has the root cause been established? •Can tools be provided to resolve the issue instead of conducting a detailed audit? Planning for special assignment •If it is not possible to resolve the issue within the department then internal audit is required to perform an audit: •If the assignment is not urgent then it will be added to the existing internal audit plan and additional testing will be included for the special assignment. •If the assignment is urgent then arrangements are made to conduct the assignemnt within the required period, depending on the available resources (staff, time, etc)