9.2.2 - Internal audit : Planning audit programs

ISO 37001

The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.

How to Respond to This Question  

Planning an audit program within an organization, especially regarding anti-corruption, involves several crucial steps:

-   Audit Frequency and Scope  : The organization determines the frequency of audits based on previous audit findings and the level of risk associated with various segments of the operation. This determination helps in setting the scope for each audit to ensure thorough coverage of high-risk areas.

-   Selection of Auditors  : Auditors are chosen based on their competence, independence, and knowledge of both the organization’s internal policies and ISO 37001 standards. This helps ensure that audits are conducted impartially and effectively.

-   Audit Methodology  : The organization defines the methods and techniques to be used during audits. These methods are designed to provide valid and reliable results, confirming the anti-corruption management system's compliance with both internal policies and international standards.

-   Documentation and Reporting  : Plans must include procedures for documenting the audit process and findings. These documents serve as evidence of the audit’s thoroughness and form the basis for future audits.

-   Incorporation of Previous Audits  : Past audit findings are reviewed to guide the planning process. This review helps identify recurring issues and assesses the effectiveness of actions taken to address previous recommendations.

For practical insights and methodologies, resources like [ISO 9001 Checklist](https://www.iso-9001-checklist.co.uk) provide detailed guidelines on establishing audit programs that align with international standards.

Why It’s Important  

Understanding how to plan and execute audit programs is essential because it:

-   Ensures Compliance  : Regular audits verify that the anti-corruption measures in place comply with legal and regulatory requirements, helping prevent legal penalties and reputational damage.

-   Identifies Areas for Improvement  : Audits highlight areas where the anti-corruption management system may be lacking, providing opportunities for continuous improvement.

-   Builds Stakeholder Confidence  : Transparent and regular auditing processes demonstrate to stakeholders that the organization is committed to integrity and ethical conduct.

-   Reduces Corruption Risks  : Effective audit programs detect and mitigate potential corruption risks, safeguarding the organization against financial and operational harm.

The [International Organization for Standardization (ISO)](https://www.iso.org) offers standards and guidance that help frame the structure of audit programs, including those focused on anti-corruption.

Examples  

-   Example A  :

 -   Context  : A multinational corporation conducts annual audits to assess its compliance with ISO 37001.

 -   Action  : Auditors review contracts, payment processes, and third-party relationships to detect any deviations from the anti-corruption policies.

 -   Outcome  : Audit results lead to the refinement of procurement guidelines and enhanced training for employees on anti-bribery compliance.

-   Example B  :

 -   Context  : A financial institution faced with increased regulatory scrutiny ramps up its internal audits.

 -   Action  : It introduces bi-annual, risk-based audits focusing on areas previously identified as vulnerable to corruption risks.

 -   Outcome  : These targeted audits help the institution strengthen its controls and reduce instances of non-compliance with anti-corruption laws.

Organizations seeking to enhance their audit practices can refer to [ACCA Global](https://www.accaglobal.com) for additional strategies and best practices in audit planning and execution.