The Role of Internal Audits in Detecting and Preventing Financial Mismanagement

Internal audit process of reviewing financial records to detect financial mismanagement

Introduction

Slowly, financial mismanagement can erode an organization before the management is aware of the existence of a serious issue. Financial losses and reputation damage can all stem from unauthorized payments, inaccurate accounting records, lax approval processes, duplicate bills, inadequate cash controls, conflict of interest or fraudulent transactions. Internal auditing can be an organized process to review these risks and to check if the financial and business controls function properly. The internal audit process is not just about looking back at the accounting records after transactions have been completed; it is about understanding the risk, assessing controls, testing the evidence, communicating any weaknesses and then recommending ways to improve. This process can be used to detect issues early, improve accountability and limit opportunities for financial misdeeds to occur. An effective audit provision in an organization’s risk management and governance framework is, therefore, important. Understand more about the internal audit process⁠.

Internal audits are especially useful as they offer management and audit committees a perspective on the effectiveness of vital processes independent from their own. While external auditors typically provide financial statement assurance reporting, internal auditors have more varied duties that can encompass financial controls, operational procedures, compliance, information systems, procurement, payroll, cash management and risks of fraud. Their work can expose weaknesses which may not be apparent in routine management activities. For instance, a company may have a policy that the total amount of money to be paid out on any one transaction must be authorized by two managers, but it may be found that employees are routinely ignoring this policy or that the accounting system is not designed to properly enforce this policy. Internal auditors can spot these deficiencies, which enables management to make policies and provide controls that are effective in practice.

What is Internal Audit?

An internal audit is an objective and systematic review of an organization’s activities, processes, controls and risk-management practices. It is a way to give independent assurance and helpful recommendations to assist an organization in reaching its goals and safeguarding its resources. An internal auditor does not only look for errors or find out if employee(s) have stolen money. Instead, they look to whether or not risks are adequately identified and managed, whether or not controls are designed appropriately, whether or not employees are following the established controls and whether or not there is evidence to support the financial and operational activity of the organization. This is significant, because an effective internal audit is one which is geared towards strengthening systems, not towards generating an atmosphere in which people feel that every audit is an effort to find a scapegoat. Audits are designed to improve processes and safeguard the organization, which can enhance employee cooperation and transparency when they realize this.

An internal audit process typically starts with a review of the organization, its goals, top risks and processes that are being audited. Auditors collect background data, analyze policies and procedures, talk with relevant staff, review past audit results, and determine if there are any aspects that need more focus. The auditor then formulates an audit plan which is determined by the risks found. Evidence is gathered and controls are tested during the fieldwork to assess the design and performance of the controls. The findings are analyzed prior to informing the management with the results. Management is provided an opportunity to respond, give a history of the situation, and set up corrective actions. The final report, in turn, reports key findings, how they might affect the decision, and any suggested improvements. Then, through follow-up activities, it will be clear whether corrective actions agreed have been put in place or not.

Identify, Assess, and Plan Audit Activities.

Why Audit planning is important?

Planning is the first, and most important, step in effective audit work. In the absence of a strategy, an auditor’s attention can be consumed with high-risk activities and not low-risk activities, and the auditor can miss the high-risk areas of financial mismanagement. The purpose and scope of an audit, understanding of relevant processes, identification of major risks, selection of appropriate testing procedures, determination of resources needed and realistic timetable are all elements of the audit planning. The auditor will take into account, the findings of the previous audit, changes in rules or regulations, change in personnel, new technology, unusual financial activity, management concerns and the complexity of the organization’s operations. Planning also aids the auditor in determining the evidence they need and how they will analyze that evidence. With a good plan in place, then the audit process, the evidence gathered, the problems found, and recommendations made are able to be linked to the risks faced by the organization.

Steps to carry out a Risk Assessment

Part of audit planning is the risk assessment as organizations do not have an unlimited number of audit resources. Auditors are required, therefore, to focus on those areas where there is a risk of weaknesses having a significant financial, operating, legal or reputational impact. Financial risks can encompass underhanded spending, report inaccuracies, asset theft, payroll fraud, vendor fraud, fictitious vendors, double payment, or funds transfer fraud. Auditors should take into account the probability of a risk event and what the impact will be if that risk does happen. The amount of audit effort to be directed to high-risk activities should correspond to their financial or operational impact, as compared to low-risk activities. Risk assessments must also be regularly reviewed as the risk profile of the organization may change if they implement new systems, enter new markets, change suppliers, experience staff changes and have new regulations.

Internal audit process for detecting and preventing financial mismanagement

Testing Internal Controls

Evaluating Control Design

Once they have identified the risks, internal auditors review the controls that are expected to manage the risks. The first question is, whether the control is designed in the right way or not. A control is designed well if it can prevent, detect, or correct the risk addressed by the control. For instance when the risk is that employees are developing new vendor accounts and paying to them then some of the controls are vendor verification, independent approval of vendor, restriction of access to vendor master, and regular review of vendor information. But it is not enough to have these procedures recorded; the controls must be effective to prove that. The auditor needs to decide if the control is really effective in addressing the underlying risk and if responsibilities are clearly defined. Inappropriate controls can lead to false confidence – an organization may think that it is protected if it does not have the right control to mitigate the risk.

Testing for the Effectiveness of Controls

After auditors find a control to be designed correctly, they will test its performance. Control testing can include a sample of transactions, review of approval information, inspection of supporting documents, observation of procedures, interview, comparison of information across systems or data-analysis techniques which can be used to look for unusual information. For instance, if the auditor checks the payment of expenses then the transactions may be sampled and checked to ensure that they have the correct documentation, have been approved by an authorized person, have been documented correctly and are in line with organizational policy. If there are several transactions without any approvals, the auditor could consider that the control of approval is not applied consistently. It is not always the case that all transactions need to be investigated, but enough and appropriate evidence obtained to reach a reasonable conclusion as to the effectiveness of the control.

Identifying Irregularities with Data Analysis

In the modern day and age, data analysis is increasingly being used in internal auditing, and will help uncover any unusual transactions and patterns that may not have been identified through sampling. Large data sets of financial data can be analyzed by auditors to uncover duplicate payments, payments outside normal business hours, unusual payment amounts, payments to people who are also paying vendors, vendor changes or vendor payments made to related persons or employees. Data analysis is not a substitute for professional judgment, rather it is a way to assist the auditor in directing his attention to the transactions that might require further investigation. For instance, if an organization normally has to get senior management approval for expenses over a certain threshold, an auditor could review transactions to see if employees routinely split up large expenses into smaller ones to get around this restriction. These patterns can be a sign of a weakness in control or may be intentional to skirt around procedures.

Identifying Financial Mismanagement and Fraud

Identifying Warning Signs

Internal audits can help to detect warning signs of financial mismanagement in order to prevent them from getting larger. Some red flags could be unexpected changes, missing paperwork, lots of manual journal entries, unusual vendor transactions, unexplainable cash deficits, multiple control overrides, transactions between related parties, or incompatible duties being performed by employees. Auditors should look into unusual circumstances, but should not presume that fraud has taken place as there may be legitimate explanations. However, if exceptions or inconsistencies are repeated or not explained they should be given the attention they deserve. The results of internal audits can even produce more general weaknesses than issues involving individual misconduct. For instance, if multiple departments are not gaining necessary purchase approvals, it could be a sign of poorly designed approvals or inadequate management monitoring of compliance. If you can treat the weakness, then you will have a lesser chance of it happening again.

Prevent Fraud by Deterrence.

The detection of problems is not the sole way in which internal audit can help to prevent fraud; it can also have a deterrent effect. When staff are aware that financial movements will be subject to independent checks and that any unusual movements will be investigated, this makes it less likely that somebody will be tempted to tamper with transactions. Routine audits can thus make it more likely that bad behavior will be found. But, internal audit shouldn’t be the sole tool for preventing fraud in an organization. Other important factors in a strong preventive control are segregation of duties, effective whistleblowing, employee training, access control and appropriate disciplinary actions, among others. These are reinforced by internal auditing which checks the effectiveness of these. The independent monitoring that is provided in addition to the preventive controls offers a greater protection than relying solely on one.

How to Report Internal Audit Findings

Communicating Audit Results

The internal auditor should communicate the auditing results in a clear manner after completion of the testing. The audit report should provide an understanding of what was audited, what was found why the finding is a concern and what actions management should take. The typical findings in a strong research report include: a description of the condition observed, an expectation for a standard or control, the cause of the condition, the impact of a condition, and a suitable recommendation. For instance, a Auditor can find that a number of employees can create vendors and approve payments without looking them over independently. It is necessary to explain in the report that this is a susceptibility that can lead to other vendors’ falsification, unauthorized payments or conflict of interest. The word ‘weak’ alone does not offer much benefit without understanding the problem, its cause and what should be done. Good communication ensures that the decisions made about risk reduction are to implement corrective action in the most appropriate way given a risk’s severity.

Presenting Findings to Management and the Audit Committee

The results of the internal audit should be reported to the relevant level of management and, if relevant or important, to the audit committee or governing body. The communication should not only be able to tell the difference between minor process improvements and real serious control deficiencies that may be a significant financial or compliance risk to the organization, it should also be able to tell the difference between these two types of control deficiencies. Audits committees have an important function since they may call the management’s attention to any significant weakness that has not been resolved and may be able to track down whether or not corrective measures are taken. The objective, evidence and balanced nature of effective reporting, Auditors should praise good control points and demonstrate where points of improvement exist. Such an approach allows a constructive discussion to take place and does not cause an undesirable conflict between the auditors and the management. Finally, reporting should make things happen – important risks should be addressed and responsibility for their resolution should be made explicit.

Conduct Follow-up/Corrective Measures.

If an audit is complete and never followed up with a final report, then it’s not really doing its job. Follow-up is important since crucial weaknesses that were found in the audit need to be taken care of by management. An internal auditor can monitor agreed corrective actions, evidence of action taken and if the changes have effectively mitigated the original risk. For instance, in the event that an audit reveals inadequate controls over payment authorization, management can implement extra controls to allow for payment and limit access to the system. Auditors will be able to test during follow-up to see if those changes have been made, and if employees are adopting them. If there is no resolution to the issue, the issue can be escalated to senior management or audit committee. Follow-up makes audit recommendations measurable improvements and also allows organizations to not continuously identify the same weaknesses without taking effective action.

Developing an Effective Internal Audit Function

The internal audit must be independent, competent, have resources and be supported by senior management. Internal auditors need to be able to audit activities without any undue interference from the activities they are auditing. They need to be knowledgeable about accounting, financial controls, risk management, compliance, technology and auditing techniques as well. Financial systems and fraud risks rely on a continuous evolution and training is especially significant. Professional skepticism is also to be expected from the internal audit teams because they must approach the evidence in a critical manner, not accept explanations without the necessary supporting evidence. Management should make records, systems, employees and other information readily available to auditors for their work. Senior leaders who demonstrate that the recommendations of the audit are respected by other people in the organization tend to make employees more respectful of controls and more willing to cooperate with the audit.

The approach of internal audit should also not be confined to a purely financial exercise. Financial mismanagement may result from inadequate procurement, human resources, information technology, inventory, operations and governance. For instance, if the user access controls are inadequate in the accounting system, then the proper supplier data may be changed by an unauthorized user, whereas the procurement process is inadequate, conflicts of interest may not be identified. A more comprehensive risk-based internal audit strategy enables auditors to analyze the interactions between various processes and the financial impacts of shortcomings that one process may have on another. This view is especially important for growing companies, as it is possible that controls that were effective when the organization was small may not be sufficient as transactions and employees grow, as do suppliers and technological systems.

Internal Audits have Several Advantages

An internal audit is conducted regularly for a number of important reasons in addition to identifying specific mistakes and possible fraudulent transactions. They assist organizations in determining areas of weakness before they turn into costly issues, enhance the efficiency of their compliance to internal policies and external regulations, increase operational efficiency, safeguard assets, and enhance the reliability of financial information. Also, audits can identify unnecessary procedures, redundant activities, unproductive approvals and obsolete controls. Addressing these problems could bring down expenses and enhance accountability. Regular audits also enable management to have independent information to assist them in making decisions. Rather than assuming that controls are effective, leaders have evidence of the way processes are working. This evidence can be useful for management to target resources to address high value areas for improvement as well as offer the audit committee greater assurance that any significant risks are being managed.

Common Challenges in Internal Auditing

Though beneficial, internal auditing has a number of challenges. A frequent issue is employee resistance to audits, due to the feeling of being criticized or punished. The other is the lack of independence where the auditor is pressured not to dig into sensitive issues or not to criticize important issues. There may also be staffing constraints and/or insufficient technology, which can also limit the ability of the auditor to consider complex operations. The other scenario that can be a challenge for organizations is when the management accepts the recommendations from the audit but doesn’t take action to implement them. Such problems may diminish the effectiveness of a soundly designed audit function. To combat them, organizations should have well-documented reporting structures, explain the function of internal auditing, ensure that sufficient resources are allocated to internal audit, safeguard the internal auditor’s independence and develop formal controls to monitor corrective actions. The purpose of management using the audit report should be to improve the organization and not to signal that the audit function is a failure.

Conclusion

Internal audits are essential to the detection and prevention of financial mismanagement as they are an independent and systematic examination of risks, controls, transactions and procedures. By carefully planning, assessing potential risks, conducting control tests, reviewing evidence, reporting on issues and follow up, internal auditors are able to help organizations identify weaknesses in advance before it becomes a significant financial loss and/or compliance failure. They can detect and report unauthorized transactions, inadequate or missed approvals, inappropriate segregation of responsibilities, unusual financial activity, and other situations that can offer opportunities for fraud. In fact, internal auditing is useful in creating robust systems that will make it unlikely that these issues will reoccur. Internal audit should therefore be viewed as an integral part of management and audit committees’ governance and risk management processes, not as a check every so often. Independent, well-supported, risk-oriented, and backed by effective remedial measures, internal audit is a strong tool to safeguard the resources of an organization, enhance accountability and support good financial governance.

Get more well researched information about Internal audits here.

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
0
Would love your thoughts, please comment.x
()
x