Bribery, Cyber-Security and Derivatives: Is Internal Audit up to the Task?

Do internal auditors have the resources, skills and authority necessary to do their job? I wonder. I was asked recently to be an expert witness in an alleged bribery case. Internal audit is one of the first places I look to when assessing governance failure because they are the eyes and ears of the board.

I asked a question recently at two auditing conferences I spoke at. How many auditors use Twitter? In both cases, only one hand went up. Yet we know cybercrime is widespread, is under-reported, and management may not even know it is happening. It is a top concern of boards. How can internal auditors assure internal controls – not only over cyber-security but social media – when they themselves may be technically illiterate? IT literacy and data mining were two of the top skills required by internal auditors in a recent survey.

What about derivatives used by traders? How many auditors understand the use of derivative products such that they can attest to the internal controls over their use? The responses I received from my audiences were not encouraging.

What about corruption risk? How do auditors treat working notes, delegation to foreign auditors, language barriers, and do they even understand foreign practices? Do they visit the jurisdiction or audit from an office in Canada? The OSC came out with a scathing report recently about emerging market risks, chastising not just boards but the audit and underwriting professions.

What about fraud? Evidence from the conference board is that many whistle-blowing programs don’t work and aren’t used. Now whistle-blowers can go directly to the SEC in Washington, completely by-passing possible retaliation, flawed investigations or toxic workplaces.

Auditors cannot choose which internal controls they validate. Regulatory authorities are clear: every activity of every entity should fall within the scope of the internal audit function. This includes compensation structure of risk-takers. Combined assurance over all material risks should be undertaken.

Management may have vested interest in starving internal audit or compromising their objectivity with management responsibilities. Regulators have been clear here also: auditors, both internal and external, must maintain their independence from audited activities. They cannot assess their own work.

If the internal audit function is weak, or the chief audit executive does not have the experience or stature, or management disregards internal audit findings, this is the fault of the audit committee and the board. The audit committee should approve the head of internal audit, his/her compensation structure, the budget, work-plan and most of all the independence of the internal audit function. If the audit committee and ultimately the board does not ensure this, it is not doing its job. When or if governance failure happens, scrutiny will follow.

Updated on May 25th, 2012.