The chief audit executive (CAE), director of audit, director of internal audit,
auditor general, or
controller general is a high-level independent corporate
executive with overall responsibility for
internal audit.
Publicly traded
A public company is a company whose ownership is organized via shares of stock which are intended to be freely traded on a stock exchange or in over-the-counter markets. A public (publicly traded) company can be listed on a stock exchange (list ...
corporations
A corporation is an organization—usually a group of people or a company—authorized by the state to act as a single entity (a legal entity recognized by private and public law "born out of statute"; a legal person in legal context) and r ...
typically have an
internal audit department, led by a chief audit executive ("CAE") who reports functionally to the
audit committee of the
board of directors
A board of directors (commonly referred simply as the board) is an executive committee that jointly supervises the activities of an organization, which can be either a for-profit or a nonprofit organization such as a business, nonprofit organiz ...
, with administrative reporting to the
chief executive officer.
The profession is unregulated, though there are a number of
international standard
international standard is a technical standard developed by one or more international standards organizations. International standards are available for consideration and use worldwide. The most prominent such organization is the International Or ...
setting bodies, an example of which is the
Institute of Internal Auditors ("IIA"). The IIA has established Standards for the Professional Practice of Internal Auditing and has over 150,000 members representing 165 countries, including approximately 65,000
Certified Internal Auditors.
The CAE is intrinsically an independent function; otherwise it may become dysfunctional and of low quality (but there are many degrees in the level of independence and efficiency). The CAE function exists only to constitute a third-level of control in the organisation, which must be independent from the first-level control (the first-level layer belongs to the management of an organisation, who is responsible in the first instance for acting in compliance with the organisation’s rules) and consecutively second-level (which are the supporting units i.e. legal, HR, risk function, financial control etc.). An effective independence is the result of both an attitude of CAE, and of prerogatives/guarantees conceded by the organisation or given by the organisation’s principals (e.g., the board of directors or audit committee).
Because the CAE understands risks and controls, company strategy and the regulatory environment the CAE may assume additional organizational responsibilities beyond traditional internal auditing.
Independent attitude
The CAE should be independent in the performance of his/her duties, so that he/she can carry out his/her work freely without admitting interference, and as objectively as possible. Independence permits him/her to render impartial and unbiased judgements, which are essential to the proper evaluation of management and controls. It also allows him/her to view the financial actions, procedures and decisions in a detached way. This may become of an importance when providing objective assurance about the internal control framework.
Organizational independence
To perform their role effectively, CAEs require
organizational independence from
management, to enable unrestricted
evaluation of
management activities and personnel. This can be analysed in the different points below:
* (for a different analysis of independence, see
organizational independence analysed by the IIA)
All the elements below should be granted to the CAE in the basic rules of the organisation, or stated in the
charter of audit
A charter is the grant of authority or rights, stating that the granter formally recognizes the prerogative of the recipient to exercise the rights specified. It is implicit that the granter retains superiority (or sovereignty), and that the rec ...
approved by the
audit committee and promulgated in the organization (
IIA IIA may refer to:
* Independence of irrelevant alternatives
* Indian Institute of Architects
*Indian Institute of Astrophysics
*Indianapolis International Airport
*Institute of Internal Auditors
* Information Industry Association
* International I ...
Standard 1110 Organizational Independence, and standard 1000C1).
Independent function: no conflict of interest allowed
Even though the CAE may be formally part of the
management structure of the organisation (among the “
chief executives”), he/she does not participate in any management decision process or accept any responsibility in the execution of company activities.
CAEs may advise management (must, when it is about
compliance
Compliance can mean:
Healthcare
* Compliance (medicine), a patient's (or doctor's) adherence to a recommended course of treatment
* Compliance (physiology), the tendency of a hollow organ to resist recoil toward its original dimensions (this is a ...
,
risk management,
internal controls...) and the
board of directors
A board of directors (commonly referred simply as the board) is an executive committee that jointly supervises the activities of an organization, which can be either a for-profit or a nonprofit organization such as a business, nonprofit organiz ...
(or similar
oversight body) regarding how to better execute their responsibilities. But she/he remains independent of the activities observes or audits.
Hierarchical independence
The primary customer of internal audit activity is the entity charged with
oversight of management's activities. This is typically the
audit committee, a sub-committee of the
board of directors
A board of directors (commonly referred simply as the board) is an executive committee that jointly supervises the activities of an organization, which can be either a for-profit or a nonprofit organization such as a business, nonprofit organiz ...
. To provide hierarchical independence, most chief audit executives report to the
chairperson of the audit committee as to the performance of his/her duties.
The definition (and regular revision) of the scope of the function should be agreed between the CAE and the
audit committee. The internal audit’s annual
work plan, which for practical reasons must be discussed with the auditees, is subject to the approbation of the sole
audit committee,
board of directors
A board of directors (commonly referred simply as the board) is an executive committee that jointly supervises the activities of an organization, which can be either a for-profit or a nonprofit organization such as a business, nonprofit organiz ...
, or other appropriate governing authority (IIA Standard 1110 Organizational Independence).
The internal rules and practices of the directorate of internal audit (
audit manual) are of the responsibility of the CAE.
Independent status
The independence of the CAE in the performance of his duties should be guaranteed in the staff rules. The
audit committee should have sole
competence
Competence may refer to:
*Competence (geology), the resistance of a rock against deformation or plastic flow.
*Competence (human resources), a standardized requirement for an individual to properly perform a specific job
*Competence (law), the me ...
for the final decision on appointment and
dismissal
Dismissal or dismissed may refer to:
Dismissal
*In litigation, a dismissal is the result of a successful ''motion to dismiss''. See motion
*Termination of employment, the end of employee's duration with an employer
**Dismissal (employment), ter ...
of the CAE”, and for his remuneration, activity appraisal and
career advancement.
The CAE is liable to
disciplinary action but only with the concurrence of the
audit committee. This could happen if he/she is negligent in the performance of his duties.
Independent communication right
The CAE reports directly to the
audit committee and the
board
Board or Boards may refer to:
Flat surface
* Lumber, or other rigid material, milled or sawn flat
** Plank (wood)
** Cutting board
** Sounding board, of a musical instrument
* Cardboard (paper product)
* Paperboard
* Fiberboard
** Hardboard, a ty ...
. There should be a report from the CAE to each ordinary
audit committee meeting and if deemed necessary to the board. Such reports should be addressed directly to the chairman of the
audit committee with parallel copy to the
director-general.
However, the CAE in the performance of his daily work communicates and liaises with the
director-general and the staff of the organisation.
Independent budgeting
Although CAEs and
internal auditors are paid by the company, the
human resource budget of the
directorate of internal audit, in particular, should be protected from interference from the audited organisation. The typical risk is that the audit's budget subject to the approval of
director of HR
Director may refer to:
Literature
* ''Director'' (magazine), a British magazine
* ''The Director'' (novel), a 1971 novel by Henry Denker
* ''The Director'' (play), a 2000 play by Nancy Hasty
Music
* Director (band), an Irish rock band
* ''Di ...
and of the DG is a source of potential interference or friendly pressure to self-limit the CAE’s critic exercise of an independent viewpoint. An appeal to the board, even expressly foreseen as part of the
communication right
Communication rights involve freedom of opinion and expression, democratic media governance, media ownership and media control, participation in one's own culture, linguistic rights, rights to education, privacy, assemble, and self-determinati ...
of the CAE, is often ineffective on short-term imposed constraints, given the time constraints of the
budget process A budget process refers to the process by which governments create and approve a budget, which is as follows:
* The Financial Service Department prepares worksheets to assist the department head in preparation of department budget estimates
* The A ...
. The best practice is that the
audit committee's opinion is required on the CAE’s draft budget, well in advance of the normal
budgeting process
A budget is a calculation play, usually but not always financial, for a defined period, often one year or a month. A budget may include anticipated sales volumes and revenues, resource quantities including time, costs and expenses, environmenta ...
of the organisation.
Access to information
Information is of key importance to organize, prepare and perform internal audits. Independent auditors are generally granted full access to any and all information they require to discharge their responsibilities. Reasonable restrictions would be limited to things such as personal information in personnel records such as health information. Unduly restricted access to information is a major impediment to an independent auditor and indicates that an organization is not truly supportive of the auditor's mandate and its commitment to sound governance should be questioned.
Typical duties
Status, strategy and organisation of the internal audit department
* Ensure that the status (e.g. stipulated in an
audit charter
An audit is an "independent examination of financial information of any entity, whether profit oriented or not, irrespective of its size or legal form when such an examination is conducted with a view to express an opinion thereon.” Auditing ...
),
strategy
Strategy (from Greek στρατηγία ''stratēgia'', "art of troop leader; office of general, command, generalship") is a general plan to achieve one or more long-term or overall goals under conditions of uncertainty. In the sense of the "art ...
, resources of the
internal audit department are aligned and are consistent with the organization's objectives and
governance policy.
* Establish appropriate policies and procedures to guide the internal
audit
An audit is an "independent examination of financial information of any entity, whether profit oriented or not, irrespective of its size or legal form when such an examination is conducted with a view to express an opinion thereon.” Auditing ...
function, and ensure the
quality of the
assurance services delivered.
Management, supervision of the internal audit activity
* Obtain (or manage the production of) a
risk analysis;
** Ensure that the
risk assessment is done at least annually;
** Establish
risk-based audit plan Audit planning is a vital area of the audit, primarily conducted at the beginning of audit process, to ensure that appropriate attention is devoted to important areas, potential problems are promptly identified, work is completed expeditiously and w ...
s to set out the priorities of the
internal audit function, consistent with the
organizational objectives
An organization or organisation ( Commonwealth English; see spelling differences), is an entity—such as a company, an institution, or an association—comprising one or more people and having a particular purpose.
The word is derived f ...
.
* Considers the input of senior
management, senior departmental management, of the
audit committee;
* The internal
audit plan Audit planning is a vital area of the audit, primarily conducted at the beginning of audit process, to ensure that appropriate attention is devoted to important areas, potential problems are promptly identified, work is completed expeditiously and w ...
usually addresses
financial reporting and other fundamental
controls, to be coordinated with the audit plan of the
statutory auditor
* Coordinate internal
audit
An audit is an "independent examination of financial information of any entity, whether profit oriented or not, irrespective of its size or legal form when such an examination is conducted with a view to express an opinion thereon.” Auditing ...
ing activities and plans with other internal and external providers of
assurance and
consulting activities to ensure proper coverage and minimize duplication of effort.
* Communicate plan of engagements and resource requirements for the internal audit function, including significant interim changes to the
audit committee. This communication shall include the impact of resource limitations.
*Ensure that internal audit resources are appropriate, sufficient and effectively deployed to achieve the internal audit plan approved by the audit committee or the board.
Ensure that internal auditors have appropriate professional qualifications and skills, and opportunities for sufficient training and development to maintain and develop their internal auditing competence and to obtain
Certified Internal Auditor certification
Certification is the provision by an independent body of written assurance (a certificate) that the product, service or system in question meets specific requirements. It is the formal attestation or confirmation of certain characteristics of a ...
.
*Ensure the timely completion of internal auditing engagements.
*Ensure that reports on internal auditing
engagement
An engagement or betrothal is the period of time between the declaration of acceptance of a marriage proposal and the marriage itself (which is typically but not always commenced with a wedding). During this period, a couple is said to be ''fi ...
s are provided to the audit committee with a minimum of delay.
*Provide an annual holistic opinion on the effectiveness and adequacy of
risk management,
control, and
governance processes.
Quality management
The CAE is responsible for assuring that appropriate
engagement
An engagement or betrothal is the period of time between the declaration of acceptance of a marriage proposal and the marriage itself (which is typically but not always commenced with a wedding). During this period, a couple is said to be ''fi ...
supervision is provided.
Supervision
Supervision is an act or instance of directing, managing, or oversight.
Etymology
The English noun "supervision" derives from the two Latin words "super" (above) and "videre" (see, observe).
Spelling
The spelling is "Supervision" in Standard E ...
is a process begins with planning and continues throughout the
examination,
evaluation, communication, and
follow-up phases of the engagement.
*Develop and maintain a
quality assurance
Quality assurance (QA) is the term used in both manufacturing and service industries to describe the systematic efforts taken to ensure that the product(s) delivered to customer(s) meet with the contractual and other agreed upon performance, design ...
and improvement program that covers all aspects of the internal audit function, and continuously monitor its effectiveness.
*In collaboration with the audit committee, ensure that a practice
inspection
An inspection is, most generally, an organized examination or formal evaluation exercise. In engineering activities inspection involves the measurements, tests, and gauges applied to certain characteristics in regard to an object or activity. ...
or other external review of the internal audit function is conducted at least every 3 years, by a qualified, independent external review team, and that the results of this external assessment are communicated to the audit committee.
* Ensure that professional internal
auditing standards are followed (e.g.
IIA IIA may refer to:
* Independence of irrelevant alternatives
* Indian Institute of Architects
*Indian Institute of Astrophysics
*Indianapolis International Airport
*Institute of Internal Auditors
* Information Industry Association
* International I ...
standards or local standards).
NB:
Generally accepted auditing standards and
International Standards on Auditing are
external audit standards.
* Report at least annually to the audit committee on the internal audit function's conformance with professional internal auditing
standards Standard may refer to:
Symbols
* Colours, standards and guidons, kinds of military signs
* Standard (emblem), a type of a large symbol or emblem used for identification
Norms, conventions or requirements
* Standard (metrology), an object th ...
.
Reporting of critical findings
Inform the Audit Committee without delay of any issue of risk,
control or
management practice that may be of significance.
The chief audit executive (CAE) reports the most critical issues to the
audit committee quarterly, along with management's progress towards resolving them. Critical issues typically have a reasonable likelihood of causing substantial financial or reputational damage to the company. For particularly complex issues, the responsible manager may participate in the discussion. Such reporting is critical to ensure the function is respected, that the proper "
tone at the top" exists in the organization, and to expedite resolution of such issues. It is a matter of considerable judgement to select appropriate issues for the audit committee's attention and to describe them in the proper context.
Survey results
Various
consulting and
public accounting firms perform research on audit committees, to provide
benchmarking
Benchmarking is the practice of comparing business processes and performance metrics to industry bests and best practices from other companies. Dimensions typically measured are quality, time and cost.
Benchmarking is used to measure performan ...
data.
Some results are identified below:
*54% of committee members surveyed felt the audit committee was "very effective," while 38% indicated "somewhat effective."
*Risk management,
internal control, and
accounting
Accounting, also known as accountancy, is the measurement, processing, and communication of financial and non financial information about economic entities such as businesses and corporations. Accounting, which has been called the "languag ...
estimates and judgments were the top priority areas for 2007.
*41% were "very satisfied" with the internal audit function, while 52% were "somewhat satisfied."
*Two-thirds felt the chief
internal audit position was for a professional internal
auditor, rather than as a "stepping stone" to other roles.
See also
*
Comptroller
A comptroller (pronounced either the same as ''controller'' or as ) is a management-level position responsible for supervising the quality of accounting and financial reporting of an organization. A financial comptroller is a senior-level executi ...
*
Lead auditor
*
Control
*
COSO framework
*
Audit risk
*
Financial audit
A financial audit is conducted to provide an opinion whether "financial statements" (the information is verified to the extent of reasonable assurance granted) are stated in accordance with specified criteria. Normally, the criteria are internat ...
*
Information technology audit
*
Internal audit
*
Institute of Internal Auditors
*
Corporate governance
*
ISA 310 Knowledge of the Business
ISA 310 Knowledge of the Business was one of the International Standards on Auditing. It is no longer effective with the introduction of ISA 315 'Identifying and assessing the risks of material misstatement through understanding the entity and its ...
;External audit
*
Certified Public Accountant
Certified Public Accountant (CPA) is the title of qualified accountants in numerous countries in the English-speaking world. It is generally equivalent to the title of chartered accountant in other English-speaking countries. In the United Sta ...
(CPA)
*
External auditor
*
Statutory auditor
*
Auditor general
*
International Organization of Supreme Audit Institutions
References
External links
the Institute of Internal Auditors
{{DEFAULTSORT:Chief Audit Executive
Internal audit
Corporate governance
A