0% found this document useful (0 votes)
12 views8 pages

Importance of Internal Audits in Business

The document discusses the importance of internal audits in today's competitive business environment, highlighting their role in assessing risk management, ensuring compliance, and improving operational efficiency. It outlines key duties of internal auditors, the evolution of auditing practices in India, and the objectives of internal audits, emphasizing their necessity for safeguarding assets and enhancing governance. Additionally, it details the historical context of internal auditing, including recommendations from Kautilya and current legal requirements for internal audits in various sectors.

Uploaded by

shas85401
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views8 pages

Importance of Internal Audits in Business

The document discusses the importance of internal audits in today's competitive business environment, highlighting their role in assessing risk management, ensuring compliance, and improving operational efficiency. It outlines key duties of internal auditors, the evolution of auditing practices in India, and the objectives of internal audits, emphasizing their necessity for safeguarding assets and enhancing governance. Additionally, it details the historical context of internal auditing, including recommendations from Kautilya and current legal requirements for internal audits in various sectors.

Uploaded by

shas85401
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Chapter I - Introduction:

The business environment today has become increasingly competitive and risky, given the complex regulatory
framework they need to follow. Every business is exposed to a certain level of risk throughout its life, but what
differentiates a company from its competition is how they deal with the potential threats. A key strategy to
ensure good governance over the business activities and keep the stakeholders well-informed is an internal
audit. An internal audit is an activity that assesses risk management and ensures internal controls are
operating effectively. It deals with the reputation of the company, cyber security, management of processes,
and financial risks. In today’s complex business environment, the company must be safeguarded from these
threats. Here are the seven biggest reasons why an internal audit is important for the company.

Assess Internal Controls:

Conducting an internal audit helps review the policies and procedures to ensure that the operations of the
company are in line with the regulations. The existing processes also need to be able to mitigate any potential
risks that the company may face. An annual internal audit continuously monitors the existing processes and
assesses the effectiveness of these internal controls. Based on the findings, recommendations can be made on
how they can be improved.

Identify Potential Risks for Fraud:

Small to mid-sized companies are prone to fraud and theft just as much as large companies. One of the key
benefits of an internal audit is that it ensures a company has proper governance so that there is no risk of
fraud. Some types of theft that can occur within the company include, misuse of the company card, tampering
of checks, or not accounting for customer payments. With the help of an internal audit, a system of checks and
balances can be created to reduce the misuse of company resources.

Improve Efficiency:

Internal audits can be used to measure the operations of the company, rather than its finances. This is also
known as an operational audit. It makes sure that the operations of the business are functioning at their
maximum efficiency. When the operations of the company are inefficient it can lead to high overheads. The
internal audit identifies opportunities to improve operations and lower costs. With a focus on improving the
processes of the company, the organization can be more dependent on processes rather than the people.
Ensure Compliance:

When evaluating the company’s internal controls, the business can ensure corporate governance and ethics in
all of its accounting processes. This involves ensuring that the operations are in line with the rules and
regulations set forth by the government and other public entities. Compliance rules are constantly changing so
the company must conduct an annual audit to avoid any costly fines in the future. This regulatory compliance is
also a factor that is assessed in the external audit. Hence, performing this check during the internal audit can
help identify any problems before they are discovered in the external audit.

Improve Investor Confidence:

The role of the internal audit is to assess all the internal controls and highlight any potential problems that
exist within the company. The internal audit team reports its findings to the executives who can then make
decisions based on the results. Conducting an internal audit improves confidence among the investors of the
company as they are assured that the management is taking the necessary steps to run the company in the
most effective way possible.

Protect the Computer Network:

With the large amounts of data generated by companies daily, the safety of technology plays an important
role. Regular internal audits can detect any vulnerability in the computing system that would put the financial
data at risk. It can also help the organization decide if the existing layer of protection is sufficient or if there is a
need to improve the security protocol for the computer system with a multi-layered approach. Cyber Fraud is
one of the biggest threats to accounting firms since they store large amounts of their client’s confidential data.

Quality Check:

During the internal audit, the assurance team plays a vital role in ensuring that the accounting processes and
corporate governance is in place. The assurance team ensures that the processes of the company are designed
in the most effective way possible and are in line with the company’s goals. It works closely with the consulting
team who provide recommendations on how these processes can be further improved to achieve maximum
productivity. An internal auditor ensures that the firm implements the best practices that help the organization
operate smoothly and efficiently.

Key Duties of an Internal Auditor:


Here are some of their key duties:

 Identify Risks: The main job of the internal auditor is to look at the processes of the company and
identify any key risks or threats while anticipating the future needs of the business.
 Manage Risks: Once the risks have been identified, the next step is to work with the risk management
team to improve the effectiveness of the internal controls.
 Assess Operations: This is also known as the operational audit and involves looking at specific
operations in each department and finding ways to improve them.
 Assurance: The assurance team works closely with the auditors to ensure that the existing operations
make the best possible use of the company’s resources.

The internal audit is essential for companies of all sizes as it looks at the day-to-day activities of the business
and identifies ways to minimize risks and optimize resources. This is important because it can help the company
save time and money and reduce the risk of fraud. Alternatively, an internal audit ensures the company
adheres to compliance laws which can help avoid fines and remove any potential for errors in the external
audit. Many companies today use technology like Artificial Intelligence to make the audit process more
efficient. An annual internal audit is an investment for companies but it will pay off in the long run.

Evolution of Audit and Emergence in India:

It has been very long since ‘Internal Audit’ was introduced in India by some enlightened companies. But before
that, it has its genesis in the era of the Maurya dynasty where Kautilya, a 4th Century B.C.E. economist,
recognized the importance of accounting methods in economic enterprises. He not only developed Book
keeping rules to record and classify economic data but also emphasized the critical role of independent periodic
audits. It was during this time also that two different offices were proposed to increase accountability of the
operations and reduce the scope for conflicts of interest. The offices constituted were the Treasurer and
Controller-Auditor for linking the successful enforcement of rules and regulations to their clarity, consistency,
and completeness. The concept of fraud was also referred to in his work when his beliefs were propounded in
the form that all such measures were necessary but not sufficient to eliminate fraudulent accounting.

Kautilya on Creating Conditions for Reducing Fraud:

 The ruler should avoid appointing persons who are fraudulent, dishonest, cruel, without enthusiasm,
incompetent and cowardly.
 “Just as it is impossible to know when a fish moving in water is drinking it, so it is impossible to find out
when government servants in charge of undertakings misappropriate money. It is possible to know
even the path of birds flying in the sky but not the ways of government servants who hide their
(dishonest) income”.

Kautilya's Recommendations:

 Appropriate format for bookkeeping and codification.


 Compliance with financial rules.
 Recording data systematically.
 Advocating frequent periodic reporting.
 Adoption of independent audits to reduce system failure.

Auditor’s Concerns – Kautilya:

 Inadvertent recording errors.


 Deliberate Deceptive Accounting.
 Collusion among employees to misappropriate revenue.
 Loss in productivity due to infighting among employees.

Current Practice Concerns:

 Organization governance.
 Risk Management.
 Effectiveness and efficiency of operations.
 Reliability of financial reporting.
 Compliance with statutory regulations.

With the Companies Act, 1913 audit of company accounts was made compulsory in India. The qualification of
the auditors was also prescribed first time in the Companies Act 1913. Later on, the International Accounting
Standards Committee and the Accounting Standard Board of the Institute of Chartered Accountants of India
have developed standards on accounting and auditing practices to guide the day-to-day work being
undertaken by auditors and accountants. However internal audit specifically was first made mandatory for a
particular set of companies vide the Manufacturing and Other Companies (Auditor Report) Order, (MAOCARO,
1975). With the MAOCARO, 1988 and CARO 2003 the need for internal audit was emphasized and focused on.
Section 581ZF of the Companies (Amendment)Act, 2002 also stipulated that ‘Every Producer Company shall
have an internal audit of its accounts carried out, at such interval and in such manner as may be specified in
articles, by a chartered accountant’. Internal audit is an independent management function, which involves a
continuous and critical appraisal of the functioning of an entity to suggest improvements thereto and add
value to and strengthen the overall governance mechanism of the entity, including the entity’s strategic risk
management and internal control system.

Creation of Auditor’s Independence:

Considering the importance of the independence of auditor’s work and having unbiased opinions from the
professional, it was decided to take the following steps to ensure the independence:

 Including a statement in the Corporations Act that auditors are to be independent.


 Requiring auditors to declare to the Board of Directors that their independence is maintained.
 Prohibiting special relationships between the auditor and client.
 Establishing an auditor independence supervisory board establishing an audit committee to oversee the
issue of non-audit services, audit fees, scope disagreements, and auditor-client relationships.

Internal Audit Functions/Requirements under Various Laws:

 Risk Based Internal Audit (RBIA) in Banks under RBI Guidance.


 Compliance of Internal Audit requirements under Companies (Auditors Report) Order, 2003/2015/2016.
 Internal audit of Operations of Depositary Participants.
 An internal Audit requirement mandated by SEBI on a half-yearly basis for stock brokers/trading
members/clearing members.
 System Audit of Investment Functions of Insurance Companies.
 Concurrent audit in Banks.
 Internal audit to be undertaken in respect of Credit Rating Companies Operations.
 Internal audit of Mutual Funds.
 Internal Audit of Custodians.
 Internal audit of Registrar & Share Transfer Agents.
 Internal audit mandatory for multiple banking or consortium RBI.
 Internal Audit requirement every quarterly required for insurers under IRDA (Investment) (Fourth
Amendment) Regulations.
Definition, Objectives, and Scope of Internal Auditing:

An internal audit is a type of internal control process designed to examine and evaluate the effectiveness of
other controls within an organization. Its main objective is to safeguard the organization’s assets and
properties from loss, waste as well as fraud. An internal auditor works within a company, as the name implies,
working only for the company. As a result, the company’s accounting records, financial activities, and
operations will be reviewed by an independent internal auditor or team of auditors who are usually the
employees of the company. There are also cases where the internal audit function is outsourced to a
professional firm.

Scope of Internal Audit:

The internal audit’s scope includes examining and evaluating the system of internal control’s sufficiency and
dependability. Internal audit’s work is to ensure that relevant internal controls are in place throughout all of
the company’s activities. The internal auditor’s work will cover the following areas:

 Review of policies and procedures for compliance: The operation of the commercial firm is influenced
by the systems and processes that it implements. The internal auditors’ work scope includes evaluating
and reporting on the efficacy and impact of such systems.
 Verify the accuracy and consistency of information: The internal auditor should verify the accuracy and
consistency of information used in finance and operations. The verification also needs to include an
assessment of the methods for identifying, recording, classifying, estimating, measuring, and reporting
such data.
 Confirm the company resources have been properly used: Assessing how effectively and efficiently the
resources are being used is also within the scope of an internal audit. Moreover, during this step,
factors that hinder efficient resource utilization should also be identified by the internal auditors.
 Check if the company met its objectives: An examination of the company’s activities or programs is
also performed by an internal auditor to see if the outcomes are in line with the company’s defined
goals and objectives. The auditor will also check to see if such activities or programs are being
performed as planned.
 Validate if the assets are well-protected: The internal auditor should examine the current system for
protecting assets and, if necessary, confirm their existence.

Key Tasks of Internal Auditors:


Here are some examples of tasks that internal auditors will carry out during an internal audit:

 Setting audit objectives so that progress toward them can be tracked.


 Recognizing, analyzing, and providing recommendations for effective handling of the company’s
significant risks.
 Evaluate whether controls are in place to protect the company’s assets against losses that may be
caused by waste, inefficiency, economically unsound activities, and fraud.
 Assess if the information systems used by the management are secure and can be relied on.
 Review the operations to see if the company’s policies and control processes are followed when they
are carried out.
 Assess the company’s operations to ensure they are conducted efficiently, effectively, and cost-
effectively.
 Evaluate whether the company complies with all applicable laws, rules, and regulations.
 Review the new systems implemented by the company to ensure that they are being monitored and
adequate internal controls are in place and that they are in line with the company’s needs.
 Assess whether the company applies good governance across its operations.
 Evaluate whether the company’s goals have been met.

Objectives of an Internal Audit:

 To analyze the operations: Systems, procedures, and sufficient staffing are required by a company so
that it can meet its objectives and handle important resources. Therefore, internal auditors must
collaborate closely with department managers to understand the company’s operations. After the
internal auditors gain a good understanding of the company’s strategic objectives and the industry in
which they operate, they will be able to see how the activities of a particular component of the
organization fit into the broader picture and perform a good analysis of the company’s operations.
 To review the risks identified by management: It is the responsibility of management to identify the
risks that the company faces and to understand how they will hinder the company from meeting its
objectives if they are not properly handled. Managers must determine the company’s risk appetite and
put in place sufficient controls and other measures to manage the risks. Some businesses will be more
willing to take more risks to ensure it stays relevant in rapidly moving trends and business/economic
situations. As a result, internal auditing procedures have evolved to become more proactive and risk-
based so that the internal auditor will be able to foresee potential future opportunities and risks as well
as give assurance, guidance, and insight before any issues arise.
 To evaluate the risk management ability: Internal auditing is primarily focused on assessing how well a
company manages its risks. To evaluate that, the internal auditor will assess the quality of internal
control systems, risk management processes, and corporate governance. The risks assessed include
health and safety risks, market failure risks, supply chain risks, cyber security risks, and financial risks,
to mention a few. The ability to manage risks effectively or more effectively than rivals and as
effectively as stakeholders expect is critical to a company’s success.
 To review Controls: Internal audit has an objective in assessing the internal controls as these controls
affect every single individual in the company. The internal auditor will need to review those controls by
checking if they are adequately designed to handle the risks, properly carried out by those involved and
whether any additional controls need to be implemented to fill any gap in the risk management
process.
 To help management improve internal controls: An internal auditor’s understanding of risk
management also makes him or her qualified to serve as a consultant. They can offer recommendations
and catalyze change in a company’s procedures. Working with the internal auditor might assist in
improving the controls and identifying changes if the management is worried about a specific risk area.
Alternatively, if a large new project is being conducted, the internal auditor may assist in ensuring that
project risks are properly recognized and analyzed, with appropriate management action taken.

You might also like