Module 1 – Operations Auditing: Definition, Characteristics and Guidance
Definition and Characteristics of Operational Auditing
Operational auditing is defined as “A future-oriented, systematic, and independent
evaluation of organizational activities. Financial data may be used, but the primary sources
of evidence are the operational policies and achievements related to organizational
objectives. Internal controls and efficiencies may be evaluated during this type of review.”
The Business Dictionary defines operational audit as “A review of how an
organization’s management and its operating procedures are functioning with respect to
their effectiveness and efficiency in meeting stated objectives.
Operational Auditing refers to comprehensive examination of an operating unit or a
complete organization to evaluate its systems, controls and performance, as measured by
management’s objectives.
The operational auditor appraises management’s operating controls and systems
over such varied activities as purchasing, data processing, receiving, shipping, office
services, advertising and engineering.
Financial audit VS. Operational Audit
Financial Audit – focuses on the measurement of financial position, results of operations
and cash flows of an entity.
Operational Audit – focuses on the efficiency, effectiveness and economy of operations.
Purpose of Operational Auditing:
1. To improve organizational profitability and the attainment of organizational
objectives.
2. Evaluate management’s performance
3. Verify a variety of qualitative aspects of the organization and its activities.
4. Evaluate the effectiveness and efficiency of business activities, processes, programs,
functions and units.
INTERNAL AUDITING
According to the IIA, the definition of internal auditing “states the fundamental purpose,
nature, and scope of internal auditing”
Internal auditing is an independent, objective assurance and consulting activity
designed to add value and improve an organization’s operations. It helps an
organization
accomplish its objectives by bringing a systematic, disciplined approach to evaluate
and improve the effectiveness of risk management, control, and governance
processes.
The definition contains some key language that is important to note:
1. Independence has to do primarily with the position of internal audit within the
organization’s
hierarchy. Internal audit should report to the audit committee (or its equivalent) on the
board of directors so it receives advice and support to perform its duties. Furthermore,
internal
audit should not be under the control of those they audit. This direct reporting line to
the highest authority within the organization will help internal audit reach its full potential,
and also get the attention from those whose influence, recognition, and respect can compel
corrective action of any anomalies identified by the auditors.
2. Objectivity is related to the auditors’ frame of mind and their ability to examine
documents,
processes, and programs without a bias, without an agenda, with no other motive than to
find the truth and communicate it accurately and promptly. Conflicts of interest are one of
the biggest threats to objectivity, so internal auditors must be careful to balance
maintaining
healthy professional and social relationships with others in the organization without
becoming
too cozy with them.
3. Assurance relates to the auditors’ ability to give confidence and make statements
regarding
the condition of matters within the organization. It is often considered a synonym to
“compliance” as has been the traditional focus of internal auditors for millennia.
Compliance
audits focus on verifying conformity and adherence of a particular area, process, or system
with policies, plans, procedures, laws, regulations, contracts, or other requirements that
govern the conduct and actions of that area, process, or system.
4. Consulting means giving advice to management and the board, and engaging in activities
that helps the organization resolve nagging business issues. These engagements address
performance, how to improve organizational programs, processes, and activities, and how
to
become more flexible, nimble, and responsive to business challenges. It also relates to the
special projects that internal auditors sometimes work on. Lastly, consulting also relates to
the way auditors do their work suggesting that the traditional mindset and role of the
auditor
as the corporate cop is being redefined and replaced by a more business-minded
professional
whose goal is to be respected more so than being feared.
5. Designed to add value. If you ask a gathering of internal auditors if they add value in their
organizations, they unanimously raise their hands in agreement. If you pose the same
question
to non-auditors, the response is often far less enthusiastic. In fact, some may even argue
that internal auditors are a necessary evil and an expense they can’t do without because
regulations, the board of directors, or other stakeholders demand the existence of an
internal
audit function.
6. Improve an organization’s operations is a very interesting statement because many
auditors see their role as that of checking things and verifying the accuracy of various items
and activities within the organization.
7. Help an organization accomplish its objectives. Many auditors practice what has been
commonly referred to as controls-based auditing. In essence, they look for the controls
within
the process or program of their review, then check them to see if they are present and
operating as expected. While this is important, they often forget to link those controls to
the
relevant risks, and link these risks to the business objectives that those risks threaten. All
of
this to say that the starting point for everything auditors do should be the identification of
the relevant business objectives. With that in mind, then, internal auditors must do their
work in ways that help the organization achieve its objectives by properly responding to
the
risks that threaten these objectives. By focusing on this, internal auditors can add value and
the possibilities are almost endless.
8. By bringing a systematic, disciplined approach. This refers to the approach followed when
performing the work. This is encapsulated in the Standards, the Practice Guides and
Practice
Advisories, which provide a great deal of guidance on how to plan, execute, and
communicate
the results of the work done.
9. To evaluate and improve the effectiveness. Our role as auditors goes beyond evaluating
business dynamics and writing reports that merely lists the problems identified. The
definition
indicates that we evaluate, but also help to improve the organization’s ability to achieve the
goals and objectives related to:
a. Risk management. This refers to the identification, measurement, assessment, and
response to risks.
b. Control. This refers to those activities that mitigate relevant risks and helps the
organizationavoid surprises.
c. Governance processes. Corporate governance is a wide subject that includes
matters
related to organizational structure, reporting lines, span of control, resource
allocation,
accountability measures, discipline, and rewards mechanisms. Corporate
governance
relates to ethical behavior by directors and others charged with the creation and
preservation of wealth for all stakeholders. The IIA’s Position Paper on
Organizational Governance states that since internal auditors are tasked with
providing assurance on
the risk management, control, and governance processes of their clients, they are
one of
the cornerstones of effective organizational governance. Auditors provide
independent,
objective assessments on the appropriateness of the organization’s governance
structures and the operating effectiveness of specific governance activities. They are
catalysts for change, advising, or advocating improvements to enhance the
organization’s governance structure and practices.
The Value Auditors Provide
1. Internal auditors promote the efficient and effective use of resources.
2. Internal auditors serve the public and common interests by making sure that
owners receive the return on their investments that they are entitled to, and that the
means of generating those profits are within the confines of the law.
3. Internal auditors help the process of making sure that the interests of all relevant
stakeholders are met.
Stakeholders can be categorized as:
a. economic/primary - They engage in transactions with the company as it carries
out its primary purpose of providing society with goods and services.
Consequently, employees, customers, creditors, and suppliers are economic
stakeholders. They are sometimes referred to as primary stakeholders as well,
because they are critical to the company’s existence and activities
b. noneconomic/secondary - people, groups, or organizations that though not
engaging in direct economic exchange with the firm, are affected by or can affect
its primary activities and decisions. The list includes communities, the general
public, governments, social activist groups, the media, and business support
groups
4. Identifying Operational Threats and Vulnerabilities - Internal auditors need to go
beyond inspecting transactions long after they were performed because the focus
now leans toward an examination of future threats and vulnerabilities that can
derail the organization’s goals and objectives in the short, medium, and even the
long term.
These future-oriented threats and vulnerabilities can be:
a. Operational, such as maintaining operational capacity, speed of execution (i.e.,
cycle time), staffing levels, employee motivation, knowledge transfer, system
development, and implementation
b. Technological, including protection of intellectual property and personally
identifiable information, denial of service attacks, business continuity due to
staff turnover, and system development
c. Strategic, referring to concerns related to strong customer and vendor relations,
customer loyalty, building effective business partnerships, outsourcing
arrangements, and mergers and acquisitions
d. Environmental, which may include reliable supply of water and electricity,
achieving a lower carbon footprint, and reducing the amount of natural
resources used during business activities
The Skills Required for Effective Operational Audits
1. Communication skills, such as oral, written, report writing, and presentation skills
2. Problem identification and solution skills, such as conceptual and analytical thinking
3. Ability to promote the value of internal audit
4. Knowledge of industry, regulatory, and standards changes
5. Organization skills
6. Conflict resolution/negotiation skills
7. Staff training and development
8. Accounting frameworks, tools, and techniques
9. Change management skills
10. IT/CT* framework, tools, and techniques
11. Cultural fluency and foreign language skills
In terms of behavioral skills, internal auditors should possess the following skills:
◾ Confidentiality
◾ Objectivity
◾ Communication
◾ Judgment
◾ Work well with all management levels
◾ Possess governance and ethics sensitivity
◾ Be team players
◾ Relationship building
◾ Work independently
◾ Team building
◾ Leadership
◾ Influence
◾ Facilitation
◾ Staff management
◾ Change catalyst skills