0% found this document useful (0 votes)
423 views7 pages

BAICS Internal Control Templates

The document provides 5 templates for use by internal audit units: 1) A communication to agency principals on non-internal audit tasks 2) An office order establishing an internal control assessment planning team 3) A baseline assessment report template 4) An audit engagement plan template 5) An audit report template The templates are meant as guides that can be customized based on agency needs and conditions.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
423 views7 pages

BAICS Internal Control Templates

The document provides 5 templates for use by internal audit units: 1) A communication to agency principals on non-internal audit tasks 2) An office order establishing an internal control assessment planning team 3) A baseline assessment report template 4) An audit engagement plan template 5) An audit report template The templates are meant as guides that can be customized based on agency needs and conditions.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
  • Template 1 - Official Communication
  • Template 2 - Office Order for Planning Team
  • Template 3 - Baseline Assessment Report
  • Template 4 - Audit Engagement Plan
  • Template 5 - Audit Report

Appendix A: Suggested Templates

The templates provided are meant to serve as a guide. These are generic and
may be modified/customized by the Internal Audit Service/Unit (IAS/IAU) of an
agency based on its needs and conditions.

TEMPLATE 1 – OFFICIAL COMMUNICATION TO THE IAS/IAU PRINCIPAL


ON THE CONDUCT OF NON-INTERNAL AUDIT TASKS

[Official Agency Letterhead]

[Date]

MEMORANDUM

For : [Agency Principal]

From : [Head of Internal Audit]

Subject : CONDUCT OF NON-INTERNAL AUDIT TASKS

Pursuant to item 5.7, Chapter 1, Part I of the revised Philippine Government


Internal Audit Manual (PGIAM), which was issued by the Department of Budget
and Management (DBM) through Circular Letter No. 2020- , an internal audit unit
(IAU) of a government agency should refrain from participating in the operations
and processes of another unit as this is in conflict with the post-audit function of
the internal audit. Further, the IAU is not responsible for or required to participate
in activities which are essentially part of the regular operating functions or the
primary responsibility of another unit in the organization.

May we highlight that among the non-internal audit tasks being referred to is/are
the [cite here the non-internal audit task(s) being instructed to be undertaken].

Relative thereto and in compliance with said DBM issuance, we are


constrained from undertaking the foregoing task(s) being assigned to
our office.

The undersigned is ready to further discuss the matter more should the [Agency
Principal] have questions or items for clarification on the same.

For consideration and/or further instruction. Thank you.

Head of Internal Audit


TEMPLATE 2 – OFFICE ORDER ON THE CREATION OF A PLANNING TEAM

[Official Agency Letterhead]

Internal Audit [Nomenclature, e.g., Service] Order No. , s. [Year]


Date:

Subject : ESTABLISHMENT OF A PLANNING TEAM FOR THE


CONDUCT OF THE BASELINE ASSESSMENT OF THE
INTERNAL CONTROL SYSTEM (BAICS), [YEAR]

As part of the strategic planning activities of the IAS for [indicate the three-year
period], a Planning Team is hereby created to lead in the conduct of the BAICS of
the [agency].

Relative thereto, the following IAS personnel are hereby assigned to constitute
the Planning Team:

Team Leader:
Alternate Team Leader:
Members:

The Planning Team shall perform planning activities, including, but not limited to
the following:

a. Evaluation and analysis of information/documents that are relevant in the


documentation of the five (5) components of the internal control system;
b. Preparation and administration of an Internal Control Questionnaire on key
processes of critical operating and support systems of OPS, support to
operations (STO), and general administration and support (GAS) of all agency
programs and projects;
c. Review of key processes and controls in the OPS, STO and GAS;
d. Evaluation of controls using flowcharts and narrative notes;
e. Conduct of walkthrough;
f. Testing of controls;
g. Conduct of interim analysis; and
h. Preparation of various reports and plans, including the Interim Report,
Baseline Assessment Report, Strategic Plan and Annual Work Plans.

For compliance.

Head of Internal Audit


TEMPLATE 3 – BASELINE ASSESSMENT REPORT

[Official Agency Letterhead]

BASELINE ASSESSMENT REPORT


As of [Date]

a. Executive Summary

b. Objectives, Scope and Methodology

c. Findings and Recommendations

Provide the detailed findings and recommendations on each internal control component
from the conducted BAICS

d. Overall Findings

Include the summary of the following:

 Interim report, which enumerates significant and material gaps or control


deficiencies/breakdowns that require immediate action
 Control universe, which provides a list of all controls on key processes of operations,
support to operations, and general administration and support, including control
gaps/deficiencies/breakdowns
 Control gaps/deficiency/breakdowns as a result of the review of oversight bodies and
local/international development partners

e. Attachments

Prepared by: Reviewed by:

Name(s) of Planning Team Member(s) Name of Planning Team Leader


Date Date

Approved by:

Head of Internal Audit


Date
TEMPLATE 4 – AUDIT ENGAGEMENT PLAN

[Official Agency Letterhead]

AUDIT ENGAGEMENT PLAN


As of [Date]

Agency Program/Project/System/Process:

Type of Audit:

I. Introduction

Contains a brief description of the management controls, i.e., the plan of organization
and all the methods and measures adopted within an agency to ensure that resources
are used consistent with laws, regulations and managerial policies; resources are
safeguarded against loss, wastage and misuse; financial and non-financial information
are reliable, accurate and timely; and operations are economical, efficient, ethical and
effective
II. Audit Objectives

Ideally, an audit objective would be consistent with the achievement of the objectives of
the organization/program/project.

Examples:

 Compliance audit – to assess compliance of controls with laws, rules, methods and
procedures
 Management audit – to ascertain if the operations has its measurement and
evaluation system which will be used to review and improve performance
 Operations audit – to determine if the agency program/project/system/process is
achieving its target

III. Audit Scope

Framework or limits of the audit. Audit scope is the extent and boundaries of an audit. It
must be consistent with the audit objectives. Audit scope includes timeframe, locations
and major processes/operating systems/support systems or key controls that will be
covered by the audit to achieve audit objectives.
IV. Audit Criteria

Set of reasonable and attainable standards of performance, statutory or managerial


policies, laws and regulations, etc.; Criteria are standards against which adequacy of
performance and conditions can be assessed.

V. Audit Methodology

Statements that describe the activities that will be undertaken in conducting the audit

VI. Resources/Inputs

Statutory policies, mandates, managerial policies, government regulations, established


objectives, systems and procedures/processes, human resources, materials, equipment,
timelines etc.

Prepared by: Reviewed by:

Name(s) of Team Member(s) Name of Team Leader


Date Date

Approved by:

Head of Internal Audit


Date
TEMPLATE 5 – AUDIT REPORT

[Official Agency Letterhead]

AUDIT REPORT

I. Table of Contents

II. Executive Summary

III. Audit Findings

a. Criteria

Standards against which a condition is compared with (i.e., laws, rules and regulations,
policies, orders, guidelines, procedures, plans, targets and contractual obligations.

b. Condition

A fact, supported by substantial evidence. The condition refers to what is currently


being done or the current situation. This is also referred to as the findings of facts.

c. Conclusion

The evaluation of the criteria and the conditions to determine: (1) the degree of
compliance or non-compliance of control with laws, regulations and policies; (2) the
control effectiveness or ineffectiveness; and (3) the efficiency, effectiveness,
ethicality, and economy of agency operations.

d. Cause

The immediate and proximate reason/s for the condition for which substantial
evidence will be used as basis of the audit recommendation. It may also refer to the
probable cause which needs only to rest on evidence showing that more likely than
not the act/s or omission/s of the person responsible had caused the non-compliance
which may warrant the conduct of administrative proceeding by the disciplining
authority - in case of compliance audit; and root cause – in case of
management/operations audit.

IV. Management Comments and Team’s Rejoinder

V. Monitoring and Feedback on Prior Year’s Recommendations

VI. Audit Recommendations

VII. Appendices
Prepared by: Reviewed by:

Name(s) of Internal Auditor(s) Name of Audit Team Leader


Date Date

Approved by:

Head of Internal Audit


Date

Common questions

Powered by AI

A Baseline Assessment Report contains an executive summary, objectives, scope and methodology, findings and recommendations, overall findings, and attachments. It includes detailed findings on each internal control component and summaries such as interim reports highlighting significant deficiencies, a control universe listing all controls and deficiencies, and gaps identified by oversight bodies .

Key elements of an Audit Engagement Plan include the introduction, audit objectives, audit scope, criteria, and methodology, as well as resources/inputs. The introduction sets the context, objectives align the audit with organizational goals, and the scope defines boundaries. Criteria set performance standards, methodology outlines audit steps, and resources detail necessary inputs. Each element ensures structured planning and execution, enabling audits to effectively assess and improve organizational controls .

Evaluating controls using flowcharts and narrative notes helps auditors visually and descriptively understand the processes, pinpoint inefficiencies, and identify control gaps. These tools facilitate clear communication of complex procedures, making it easier to assess whether the controls are functioning as intended and support the overall objectives of the audit by giving insights into process flows and potential risk areas .

The establishment of a Planning Team supports internal audit functions by leading the conduct of the Baseline Assessment of the Internal Control System (BAICS). Key activities undertaken by the Planning Team include evaluation and analysis of documents relevant to internal control systems, preparation and administration of questionnaires on key processes, review of processes and controls, evaluation using flowcharts, testing of controls, conducting walkthroughs, interim analysis, and preparation of various reports such as the Interim Report and Baseline Assessment Report .

In audit findings, 'criteria' represent the standards against which performance is assessed, 'condition' describes the current state or findings of facts, 'conclusion' involves evaluating the degree of compliance and effectiveness, and 'cause' identifies the reasons for any deficiencies. Together, these components provide a structured approach to identify issues, assess their impact on compliance and operational efficiency, and form the basis for audit recommendations .

The PGIAM's directive for the IAU to refrain from non-internal audit tasks protects its integrity by ensuring that internal audits remain objective and independent. By not being involved in operational tasks, the IAU avoids potential conflicts of interest and maintains its role as an impartial evaluator of an agency’s processes and controls, which is essential for delivering unbiased and constructive recommendations .

The Internal Audit Unit (IAU) of a government agency should refrain from participating in the operations and processes of another unit, as it conflicts with the post-audit function of internal audits. The IAU is not responsible for or required to participate in activities that are essentially part of the regular operating functions or the primary responsibility of another unit within the organization .

An Audit Engagement Plan aligns with the achievement of an organization's objectives by ensuring audits are designed to assess compliance with laws and managerial policies, safeguard resources, ensure financial accuracy, and evaluate operational efficiency. The plan outlines objectives consistent with the organization's goals, establishing a framework that includes audit objectives and scope to address critical processes and control systems, thereby directly supporting the organization's broader objectives .

Internal auditors are responsible for compiling and presenting audit findings, including criteria, condition, conclusion, and cause, in an Audit Report. They must ensure findings are evidence-based and provide actionable recommendations. Management comments are incorporated to provide a balanced view, offering explanations or rebuttals to findings, which are addressed in the auditor's rejoinder. This interaction helps improve future compliance and audit effectiveness .

Conducting a risk assessment is crucial in planning audit engagements as it helps identify areas with the highest potential for deficiencies or non-compliance. This ensures that audit resources are focused on activities that pose the most significant risks to achieving an agency’s objectives, thereby enhancing the efficiency and effectiveness of audit engagements and contributing to more reliable and comprehensive audit outcomes .

Appendix A: Suggested Templates
The templates provided are meant to serve as a guide. These are generic and
may be modified/c
TEMPLATE 2 – OFFICE ORDER ON THE CREATION OF A PLANNING TEAM
[Official Agency Letterhead]
Internal Audit [Nomenclature, e.g.,
TEMPLATE 3 – BASELINE ASSESSMENT REPORT
[Official Agency Letterhead]
BASELINE ASSESSMENT REPORT
As of [Date]
a.
Executive Sum
TEMPLATE 4 – AUDIT ENGAGEMENT PLAN
[Official Agency Letterhead]
AUDIT ENGAGEMENT PLAN
As of [Date]
Agency Program/Project/Sys
IV.
Audit Criteria
V.
Audit Methodology
VI.
Resources/Inputs
Prepared by:
Name(s) of Team Member(s)
Date
Reviewed by:
Name of
TEMPLATE 5 – AUDIT REPORT
[Official Agency Letterhead]
AUDIT REPORT
I.
Table of Contents
II.
Executive Summary
III.
Audit Fin
Prepared by:
Name(s) of Internal Auditor(s)
Date
Reviewed by:
Name of Audit Team Leader
Date
Approved by:
Head of Internal Au

You might also like