Should internal audit perform continuous auditing?


A service provider in Germany recently completed a survey of internal audit heads in that country. He told me that the great majority believe that internal audit should not use continuous auditing techniques because monitoring controls is a management responsibility, and asked my opinion.




Norman Marks
Norman Marks
I told him that I have some sympathy with that opinion, and expressed my own:

1. The system of internal control is a management responsibility, and management is also responsible for control monitoring. However, the COSO internal control framework recognizes that management may place some reliance on internal audit for controls monitoring (assurance).

2. The way many, if not most, use these techniques is really auditing transactions and not controls. They are detecting errors and possibly fraud. First, testing transactions provides only limited assurance that the controls are in place and operating, so that future activity will be as desired. Second, I believe it is management’s job to test transactions and internal audit’s to test controls.

3. We need to remain mindful that the primary task of internal audit is to provide assurance that the more significant risks to the organization are managed within acceptable limits, and this is achieved by internal controls. Our job in internal audit is to address the controls over the more significant risks, and to provide assurance when it is needed by the organization. For some risks, high risks such as derivative trading, assurance may be needed on a frequent basis. So, we should perform tests of controls that support that more frequent need for assurance.

4. The IIA Global Technology Guide (GTAG) on continuous auditing has some excellent content and advice. I suggested more people should reference it.

5. I believe in continuous risk monitoring and updating of the audit plan, to ensure that audit efforts are focused on what matters now, rather what mattered at the start of the year. This is a form of continuous auditing. For example, I would use analytics technology to monitor a software company’s credit memos at the beginning if each quarter as that is an indicator of potential revenue fraud, and support a consumer products company’s internal audit monitoring of trends in product gross margin as an indicator of potential risks.

6. Continuous audit is not always continuous (see the GTAG definition). It simply means performing the audit activity more frequently.

7. Continuous auditing is not another way of talking about audit use of technology. Continuous audit tests may be manual, for example attending the CFO’s monthly meeting to review the divisional financials, trends, and variances confirms that this important control is operating.

The bottom line is that internal audit should do the work necessary to provide its stakeholders with the assurance they need, when they need it, on the more significant risks. Doing less is an issue. Doing more may mean either inefficient use of resources (unless clearly valuable consulting services) or an encroachment upon management responsibilities.

What do you think?

Norman Marks, CPA, is vice president, governance, risk, and compliance for SAP's BusinessObjects division, and has been a chief audit executive of major global corporations for more than 15 years. He is the contributing editor to Internal Auditor’s “Governance Perspectives” column.
normanmarks.wordpress.com/

Wednesday, June 27th 2012
Rate it




New comment:
Twitter
B i u  QUOTE  URL

ENGLISH
Articles & press releases are provided as is and have not been edited or checked for accuracy.
Any queries should be directed to the company issuing the press release or to the author issuing the article.
If you have a question for the author, or would like to comment on this article, use the box above. Your comment will be moderated before publication.
Your comment or question will appear below and the author or Finyear editor will be able to respond. Please note that your name will appear next to your comment (not your email).
Finyear does not offer financial advice of any kind and the opinions of authors are not necessarily those of Finyear.
By posting your comment, you agree to our acceptable use policy. If you read anything here that you consider inappropriate or offensive, please contact the adress : contact (at) finyear.com
Finyear: Daily News & Best Practices for the Finance Executives (CFO, Treasurer, Controller, Credit manager, accountant, financial executive, etc...).

The Financial Year by Finyear. Copyright Finyear 2007-2013. You may share using our article tools.
Please don't cut articles from Finyear.com and redistribute by email or post to the web without permission: contact (at) finyear.com

FRANCAIS
Les articles et les communiqués de presse sont fournis tels quels et n'ont pas été modifiés ou vérifiés.
Toute demande de renseignement doit être adressée à la société émettrice du communiqué de presse ou à l'auteur de l'article.
Si vous avez une question pour l'auteur, ou si vous désirez commenter cet article, utilisez la boîte ci-dessus. Votre commentaire sera modéré avant publication.
Votre commentaire ou question ci-dessous apparaîtra et l'auteur ou l'éditeur Finyear sera en mesure de répondre.
Veuillez noter, s'il vous plaît, que votre nom apparaîtra à côté de votre commentaire (pas votre adresse email).
Finyear n'offre pas de conseils financiers de quelque nature que ce soit et les opinions des auteurs ne sont pas nécessairement celles de Finyear.
En postant votre commentaire, vous acceptez notre politique d'utilisation et nos mentions légales.
Si vous lisez quelque chose ici que vous considérez inapproprié ou offensant, s'il vous plaît contacter l'adresse: contact (at) finyear.com
Finyear: actus quotidiennes et meilleures pratiques pour les cadres financiers (CFO, trésorier, contrôleur, gestionnaire de crédit, comptable, cadre financier, etc ..).

The Financial Year by Finyear. Copyright Finyear 2007-2013. Vous devez utiliser nos outils de partage situés sur les articles.
SVP ne coupez-pas les articles issus de Finyear.com, ne les reroutez-pas par message sur le web sans autorisation : contact (at) finyear.com

The difference between intelligence and education is this: intelligence will make you a good living. - Charles F. Kettering

Finyear Magazine #24


Finyear Research


Conferences & Webinars


White Papers / Livres blancs





Mo Tu We Th Fr Sa Su
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31