9.2.3 : Internal audit : Audit design principles

ISO 37001

 The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.

How to Respond to This Question  

When planning and establishing internal audit programs, particularly in the context of anti-corruption, organizations must incorporate several key principles to ensure the audits are reasonable, proportionate, and risk-based:

-   Risk Assessment  : Audits are planned based on a thorough risk assessment, identifying areas with the highest risk of corruption. This assessment guides the frequency, scope, and intensity of the audits.

-   Scope and Objectives  : Each audit is clearly defined with specific objectives, scope, and criteria, which are aligned with both organizational requirements and international standards like ISO 37001.

-   Auditor Selection  : Auditors are chosen based on their independence from the functions being audited and their expertise in anti-corruption practices and standards. This ensures objectivity and reduces conflicts of interest.

-   Methodology  : The audit methodology is selected to yield the most reliable results. This includes choosing the appropriate types of audits (e.g., comprehensive, follow-up, or random) and techniques (e.g., interviews, document reviews, or forensic analysis).

-   Reporting  : The results are reported in a manner that supports transparency and accountability, often involving the governing body or senior management to ensure that corrective actions are taken.

For detailed guidance on audit planning, organizations can refer to resources like the [PCAOB (Public Company Accounting Oversight Board)](https://pcaobus.org) which provides standards for audit planning and risk assessment in various environments.

Why It’s Important  

Understanding how to design and implement audit programs is crucial for several reasons:

-   Ensures Compliance  : Properly designed audits help ensure compliance with laws, regulations, and internal policies, reducing legal and reputational risks.

-   Detects and Prevents Corruption  : Risk-based audits focus on areas most vulnerable to corruption, helping detect and prevent illicit activities before they can cause significant damage.

-   Improves Operational Efficiency  : By identifying inefficiencies and areas for improvement, audits contribute to better resource management and operational performance.

-   Supports Continuous Improvement  : Regular audits provide feedback on the effectiveness of anti-corruption measures, supporting ongoing refinement and enhancement of the management system.

The [International Federation of Accountants (IFAC)](https://www.ifac.org) offers additional insights into the strategic planning of audit programs within corporate governance frameworks.

Examples  

-   Example A  :

 -   Context  : A large multinational initiates an internal audit following revelations of potential bribery in its overseas operations.

 -   Action  : The audit focuses on high-risk areas, including third-party relationships and procurement processes.

 -   Outcome  : The audit uncovers compliance gaps and leads to a revamp of the company’s due diligence processes.

-   Example B  :

 -   Context  : Following a risk assessment, a financial services firm implements a targeted audit program.

 -   Action  : The program prioritizes audits in departments with high volumes of transactions and previous instances of non-compliance.

 -   Outcome  : Enhanced controls and training programs are developed, significantly reducing incidents of non-compliance.

Organizations looking for practical applications of these principles can explore the [ACCA Global](https://www.accaglobal.com) website for case studies and articles on audit program effectiveness.