Internal Audit Should Improve Organisations — Not Just Audit Them

The misconception

Internal audit has an image problem.

Too often it is seen as a compliance function, a fault finder, process police, or an independent observer that only identifies weaknesses before moving on to the next engagement.

Throughout my career I've never viewed internal audit that way.

At its best, I believe internal audit should be one of the most valuable business improvement functions within an organisation, proudly delivering both effective risk mitigation and meaningful performance improvement. Control enhancement recommendations and process improvement opportunities should be made with the organisation’s specific strategic and operational objectives in mind, ensuring they are both fit for purpose and practical.

The quantum of findings is not the measure of success, with core outcomes leading to capacity building. Fundamentally, internal audit should leave the organisation, business unit or auditable area stronger than it found it.

Strong internal audit should think like management.

Thinking like management does not mean compromising independence. It means understanding the commercial reality in which recommendations will operate. Every recommendation competes for budget, people and executive attention. Strong internal audit recognises those constraints and develops recommendations that are practical, proportionate and achievable.

What does internal audit exist to do?

A simple question, yet one which could have so many answers depending on who you ask. Does internal audit provide independent assurance of governance, controls and risk management? Yes. Does internal audit support regulatory compliance? Yes. Does internal audit recommend controls to enhance auditable environments? Yes.

However, it can be so much more.

Imagine an independent function that can enhance process efficiency. Imagine an independent function that has previously observed hundreds or thousands of processes in action, and can identify those which operate effectively. Imagine a function that can identify emerging risks and report those which are meaningful and data driven to the Audit Committee.

Now we are close.

Finally, imagine a function that understands your business and processes, understands management, the organisation’s strategic objectives, and widens its view to not only focus on specific controls but also assess a full process.

When internal audit becomes a compliance function – everybody loses, but when it is treated as a business partner that understands the impact of its recommendations, and supports better decision making, it becomes a highly valuable tool which can embed robustness within an organisation.

Recommendations and improvement opportunities

One philosophy I've always held is that recommendations and improvement opportunities are not the same thing.

Recommendations strengthen the control environment and reduce risk. Improvement opportunities strengthen the process itself and organisational capability. They make organisations more efficient, reduce unnecessary administrative burden and allow management to redirect effort towards activities that create greater value.

Both are important, but they achieve different outcomes.

Two dimensions of internal audit value

Recommendation Improvement opportunity
Strengthens the control environment Strengthens the overall process
Reduces or better mitigates risk Improves efficiency and capability
Focus on assurance, and control design or operating effectiveness Focus on overall performance and operational improvement
May introduce or enhance controls May simplify, automate, or redesign processes

Internal audit creates value in more than one way. While recommendations and improvement opportunities have different purposes, they are not competing outcomes. Together they contribute to stronger governance, better decision making and improved organisational performance.

A control can be designed well and operate effectively, but if that control sits within a process which could be enhanced, you begin to see the broader value of internal audit.

Rather than a standalone function, internal audit is uniquely positioned with a bird’s eye view. A tap may be perfectly designed and operate exactly as intended, but if the plumbing behind it is poor, the overall system still fails.

For example, if we take approvals to changing a supplier master file:

Recommendation Improvement opportunity
Action Introduce a secondary approval for supplier master file changes. Consolidate three approval steps into one automated workflow.
Purpose Reduce fraud risk, strengthen a key control, provide additional assurance. Improve user experience, increase efficiency, free resources for other value adding activities.
Primary value created Stronger control environment Enhanced process performance

The best internal audit doesn't produce the most findings

Have you ever been in a situation where an internal audit report looks like findings have been included after the fact? Where it feels as though findings have been included simply to justify the audit? And where recommendations appear without clear justification?

This is a frustration which is felt by management, and can impact relationships and the ability to deliver improvements congruently.

In my experience, there is sometimes a perception that the larger quantum of findings and recommendations means larger value derived from internal audit. However, it has always been my philosophy for internal audit to remember that every recommendation consumes organisational resources. Good internal audit shouldn’t simply ask 'Does this reduce risk?' It also asks, 'Is this the best use of management's time, effort and investment?".

Internal audit should be judged by the improvements it enables, not the reports it produces and the number of recommendations that are made.

I once reviewed an audit where one of the recommendations was to implement an ERP system for an organisation of around ten people. Technically, it will of course strengthen the control environment. However, practically, it would have consumed a disproportionate amount of time, money and organisational capacity for very little additional value.

Internal audit should create more value than it consumes.

Organisations often have limited resources, whether that be time, budget or headcount. As such there has to be a consideration of the practicality of recommendations, including whether resources can be used differently.

For example, if a low inherently rated risk has 10 controls and a medium inherently rated risk has two, internal audit should actively consider whether scarce organisational resources are being directed towards the areas of greatest risk, or even suggest an improvement opportunity to redesign the process. This has the added benefit of often not investing more, but redeploying resources you already have. That is thinking like management and that is likely to add the real value we are looking for.

The value of internal audit is not in the quantum of recommendations and reports, risks mitigated and process improvements.

Taking it one step further.

One of the most valuable skills of an experienced auditor isn't finding control gaps. It's recognising when the existing control environment is proportionate to the risk. This encompasses another core risk management concept of risk appetite. For example:

An additional layer of approval for invoice payments would reduce risks of overpayment, duplicate payments and incorrect payments. However, if it adds an extra four hours of administration on the process, slows down pay runs and diverts resources from higher risk or under controlled areas then perhaps an improvement opportunity for process improvement would be more appropriate.

Creating value is not adding more, it is using what we have at optimum efficiency.

Finally, it is important to remember that a mature and value adding recommendation or improvement opportunity protects internal audit’s reputation. Trust takes years to build but a moment to shatter, a poor recommendation made without consideration for the organisation has a similar impact. Internal audit is engaged not only for their expertise but also their ability to understand organisations. Understanding the cost and practicality of recommendations isn't just about efficiency—it's about maintaining trust.

Internal audit should work with management

Internal audit is an independent function, and its independence is a core foundation of its value. As a critical friend, it should sit as an independent advisor as well as an assurance provider, but also remember that value also comes from helping management succeed.

Working with management to understand the practicalities of recommendations and improvement opportunities is crucial in building trust, and supporting organisational improvement. While findings are of course factual in nature, the recommendation can be developed collaboratively with management input, meaning that internal audit can include recommendations in the report which make sense, which genuinely uplift the organisation, and management has buy-in to.

What good internal audit looks like

Every organisation is different, and every internal audit function must adapt to its size, complexity and risk profile. There is no single formula for effective internal audit, nor should there be. However, throughout my career I have observed that the most effective internal audit functions consistently demonstrate a number of common characteristics.

These characteristics extend beyond technical competence. They reflect the judgement, behaviours and professional qualities that enable internal audit to provide meaningful assurance while creating lasting value for the organisation. Individually, each characteristic is important. Collectively, I believe they define an internal audit function that can make a real difference. The collective characteristics are outlined below:

The table below explains each of the collective characteristics:

Characteristic Why it matters In practice
Independence Independence underpins the credibility of internal audit. Without it, assurance loses its value. Remain objective and professionally sceptical while understanding management's perspective and organisational priorities.
Organisational understanding Recommendations are most effective when they align with the organisation's objectives, culture and operating environment. Take the time to understand how the organisation operates and achieves its objectives before assessing whether controls are effective.
Risk focussed Resources are finite and should be directed towards the areas of greatest risk and potential impact. Prioritise internal audit activities on organisational risk rather than treating every area with equal significance.
Practicality Recommendations should be realistic, proportionate and capable of being implemented successfully. Develop solutions that management can adopt in practice rather than recommending unnecessary complexity.
Insightful Internal audit's broad exposure across organisations and industries provides a unique perspective. Draw on experience, lessons learned and emerging practices to provide meaningful insights that management may not otherwise identify.
Effective relationship building Constructive relationships foster trust, encourage openness and increase the likelihood that recommendations will be accepted and implemented. Build collaborative relationships with stakeholders while maintaining independence and professional objectivity.
Proportionality Effective governance balances risk reduction with cost, complexity and operational impact. Identify solutions that are appropriate for the organisation's size, risk appetite and available resources.

These characteristics are not intended to replace professional standards or prescribe a single way of performing internal audit. Rather, they represent the qualities that, in my experience, consistently distinguish internal audit functions that create genuine organisational value.

Good internal audit is rarely remembered because it identified another control deficiency. It is remembered because it helped an organisation solve a problem, improve a process or make a better decision. And if those improvements still make sense to the people implementing them at 5 pm on a Friday afternoon, they are far more likely to deliver lasting value.

Conclusion

Internal audit will never eliminate risk.

Nor should it try.

Its purpose is to identify deficiencies, then work with the business to enhance process design, controls, and ultimately lead to better decisions. Ensuring that findings are not only evidence-based, are supported by recommendations and improvement opportunities that genuinely add value, not just through sheer quantum but through tangibility of improvement.

Internal audit creates its greatest value when organisations don't remember the report. They remember the improvement. Ultimately, internal audit should create more value than it consumes.

Ken De Negri

BSc, MSc, FCCA

De Negri Advisory Pty Ltd

About the author

Ken De Negri is the founder of De Negri Advisory, providing governance, risk, internal audit and sustainability advisory services to organisations across Australia. If this perspective resonates with your organisation or you'd like to discuss how these principles could be applied in practice, feel free to get in touch.

Previous
Previous

When Everything Becomes an Enterprise Risk - Nothing Is