Internal Audit and Internal Control

Internal Audit and Internal Control

 

Internal Audit and Internal Control

Chapter Six: Control Framework, Internal Audit, Auditor Appointment, and Disclosure

First: Introduction

Internal control and internal audit form the “third line of defense” in any company. Executive management is the first line of defense, risk management and compliance the second, while internal audit is the third line that ensures the first two lines work effectively. Chapter Six of the Regulations (Articles 72-79) organizes this critical area, especially after substantive amendments in 2021 and 2024.

Companies that invest in strong internal control and effective internal audit avoid crises before they occur, protect their assets, ensure accuracy of their financial statements, and build trust with shareholders and regulatory authorities. This article reviews the regulatory framework for internal control and audit, recent amendments, and effective application.

💡  Key Insight

Internal audit is not an enemy of management but a partner ensuring its success. A good internal auditor uncovers gaps before they become crises, suggests improvements, and enhances efficiency. Companies that view auditing as a burden lose improvement opportunities, while companies that view it as a valuable tool achieve better financial and operational results.

Second: Internal Control System

1. The Basic Requirement

Article (72):

  • The company must establish an effective internal control system.
  • Written and documented.
  • Approved by the Board.
  • Periodically reviewed.

2. Components of the Control System

2.1 Control Environment

  • Commitment to integrity and ethical values.
  • Board independence.
  • Clear organizational structure.
  • Defining responsibilities.
  • Human resources policies.

2.2 Risk Assessment

  • Defining objectives.
  • Identifying risks threatening their achievement.
  • Assessing likelihood and impact of each risk.
  • Linking risks to controls.

2.3 Control Activities

  • Preventive controls (preventing the problem).
  • Detective controls (discovering the problem).
  • Corrective controls (addressing the problem).
  • Segregation of duties.
  • Authorization and approval.

2.4 Information and Communication

  • Accurate and timely information.
  • Internal communication.
  • External communication.
  • Regular reports.

2.5 Monitoring

  • Continuous monitoring by management.
  • Separate evaluation by internal audit.
  • Reporting shortcomings.
  • Correcting deviations.

3. COSO Framework

The accredited international standard:

  • Internal Control – Integrated Framework.
  • Committee of Sponsoring Organizations.
  • Globally accepted standard.
  • Reference for Saudi companies.

Third: Internal Audit

1. The Mandatory Requirement

1.1 Establishing the Internal Audit Unit

Article (76) — became binding since 2021:

  • Mandatory establishment.
  • Unit or department.
  • Complete independence.
  • Reports to the Audit Committee.

1.2 Limited Exceptions

  • For very small companies: outsourcing may be used.
  • Subject to independence.
  • Subject to competency.
  • With disclosure to shareholders.

2. Independence

2.1 In Terms of Reporting

2024 amendments:

  • Internal auditor reports to the Audit Committee (Article 24).
  • Not to executive management.
  • Appointment by Audit Committee recommendation.
  • Dismissal requires Board approval.

2.2 In Terms of Resources

2024 amendments — Article 52(b)(3):

  • Ensuring sufficient resources for auditing.
  • Independent budget.
  • Qualified cadres.
  • Tools and systems.

2.3 In Terms of Scope

  • Free access to all departments.
  • Review of all documents.
  • Communication with all levels.
  • Without interference in scope.

3. Responsibilities

3.1 Periodic Audit

  • Systems and procedures.
  • Operational operations.
  • Policy compliance.
  • Resource efficiency.

3.2 Internal Control Evaluation

  • Testing controls effectiveness.
  • Identifying weaknesses.
  • Recommending improvements.
  • Monitoring implementation.

3.3 Risk Management Evaluation

  • Reviewing risk management framework.
  • Verifying its application.
  • Evaluating its effectiveness.
  • Recommendations.

3.4 Violation Investigation

  • Investigating reports.
  • Suspected fraud.
  • Misconduct.
  • Reports.

4. Internal Audit Plan

4.1 Preparation

  • Annual or multi-year.
  • Based on risk assessment.
  • Comprehensive of main activities.
  • Flexible for updates.

4.2 Approval

  • From the Audit Committee.
  • From the Board (in large companies).
  • With required resources.
  • Periodic updating.

5. Audit Reports

5.1 Mission Reports

  • After each audit mission.
  • Findings and observations.
  • Recommendations.
  • Management response.

5.2 Periodic Reports

  • Quarterly to the Audit Committee.
  • Annually to the Board.
  • Summary to the Assembly.

5.3 Internal Control Report

  • Annual.
  • Comprehensive evaluation of control system.
  • For the Audit Committee and the Board.
  • Summary for shareholders.
📌  Note

2024 amendments to the Governance Regulations specifically focused on strengthening internal audit. Transferring appointment and dismissal to the Audit Committee, allocating resources, periodic meetings with the external auditor — all this reflects a deep understanding of the importance of internal audit as a governance pillar. Saudi companies today have an advanced internal audit framework rivaling international best practices.

Fourth: Internal Auditor

1. Appointment

1.1 Procedures

2024 amendments:

  • Recommendation from the Audit Committee.
  • Approval from the Board.
  • With specified qualifications.
  • By formal contract.

1.2 Qualifications

  • University degree in accounting or equivalent.
  • Recommended professional certifications (CIA, CPA, CISA).
  • Sufficient practical experience.
  • Clean professional record.

2. Dismissal

2.1 Procedures

2024 amendments:

  • Auditor may not be dismissed except by Board resolution.
  • Based on Audit Committee recommendation.
  • With documented reasons.
  • With disclosure.

2.2 Protection

  • May not be dismissed because of performing his work.
  • Protection from retaliation.
  • Ensuring independence.

3. His Responsibilities

3.1 Execution

  • Implementing the audit plan.
  • Supervising his team.
  • Ensuring quality of work.
  • Communicating with management.

3.2 Reports

  • To the Audit Committee Chair.
  • Periodically and regularly.
  • Periodic meetings.
  • Meetings without management when needed.

Fifth: Audit Committee Meetings with Auditors

1. Periodic Meetings

1.1 New Requirement (2024)

Article 54(b):

  • Periodic meetings with the external auditor.
  • Periodic meetings with the internal auditor.
  • Without executive management attendance.
  • For open communication.

1.2 Objectives

  • Listening to observations without management influence.
  • Understanding real challenges.
  • Verifying independence.
  • Independent assessment.

2. Special Meetings

  • In urgent cases.
  • Discovery of substantive violations.
  • Disputes with management.
  • Resignations.

Sixth: Disclosure on Internal Control

1. In the Annual Report

1.1 Requirements

  • Description of internal control system.
  • Confirmation of its effectiveness.
  • Substantive shortcomings.
  • Corrective procedures.

1.2 Management Acknowledgment

  • CEO and CFO.
  • Accuracy of financial statements.
  • Internal control effectiveness.
  • Complete disclosures.

2. Immediate Disclosures

  • Discovery of substantive violations.
  • Internal auditor resignation.
  • Change of external auditor.
  • Related party transactions.

Seventh: External Auditor

1. Appointment

1.1 Procedures

  • Recommendation from the Audit Committee.
  • Board approval.
  • Nomination for the Assembly.
  • Appointment by Assembly resolution.

1.2 Criteria

  • Licensed and accredited.
  • Excellent professional record.
  • Sector experience.
  • Complete independence.

2. Independence

2.1 Requirements

  • No financial relationship with the company.
  • No conflicting advisory services.
  • No personal relationship with management.
  • Commitment to independence rules.

2.2 Separation of Duties

  • Auditing separated from consulting.
  • Ceiling on advisory services.
  • Disclosure of fees.
  • Periodic independence evaluation.

3. Duration

3.1 Limit

  • Annual renewal.
  • Recommended practice: rotating responsible partner every 5-7 years.
  • In some sectors: changing the firm every 10 years.

3.2 Rotation

  • To ensure higher independence.
  • For new perspective.
  • For quality standards.

Eighth: Relationship Between Internal and External Auditor

1. Integration

  • Not replacement but integration.
  • Different scope of work.
  • Different perspective.
  • Continuous coordination.

2. Differences

AspectInternal AuditorExternal Auditor
ReportingTo Audit CommitteeTo General Assembly
ScopeAll managementFinancial statements primarily
ObjectiveImproving operationsExpressing opinion
TimingContinuousAnnual
IndependenceOrganizationalProfessional

3. Coordination

  • Periodic meetings.
  • Information exchange.
  • Avoiding duplication.
  • Integration in coverage.

Ninth: Whistleblowing System

1. Mandatoriness

  • 2021 amendments — Article 83.
  • Establishing reporting system.
  • Disclosure of it.
  • Encouraging its use.

2. Requirements

2.1 Confidentiality of the Reporter

  • Protection of identity.
  • Protection from retaliation.
  • Confidential investigation.
  • Appropriate handling.

2.2 Reporting Mechanisms

  • Multiple channels.
  • Hotline.
  • Secure email.
  • Electronic platform.

2.3 Investigation

  • Immediate investigation.
  • By independent investigators.
  • Documented results.
  • Corrective procedures.

3. Oversight

  • Audit Committee oversees.
  • Periodic reports to the Board.
  • Summary for shareholders.

Tenth: Common Challenges

1. “Limited Resources” Challenge

Shortage in audit cadres:

  • Solution: investment in qualification.
  • Outsourcing when needed.
  • Engaging specialized firms.

2. “Management Resistance” Challenge

Some managers see auditing as a threat:

  • Solution: culture of audit as partner.
  • Continuous communication.
  • Focus on improvement, not blame.

3. “Overlap” Challenge

Between audit, risk management, and compliance:

  • Solution: precisely defining roles.
  • Continuous coordination.
  • “Three Lines of Defense” model.

Eleventh: Best Practices

1. At the Framework Level

  • Comprehensive control system: written and updated.
  • Based on risks: not just procedures.
  • Aligned with COSO: and international frameworks.
  • Integrated with strategy.

2. At the Internal Audit Level

  • Real independence: organizational and practical.
  • Distinguished competencies: with certifications and experience.
  • Comprehensive plan: based on risks.
  • Advanced technology: automation, analytics.

3. At the Communication Level

  • With the Audit Committee: continuous and transparent.
  • With management: constructive and supportive.
  • With the external auditor: effective coordination.
  • With employees: culture of control.

4. At the Development Level

  • Continuous qualification.
  • Professional certifications.
  • Learning from best practices.
  • Developing methodologies.

Conclusion

Internal control and internal audit are the foundation stones for strong governance. Recent amendments to the Governance Regulations, especially 2021 and 2024, have raised the standards of this area to levels intersecting with international best practices. Leading Saudi companies are investing heavily in building advanced control systems, qualified audit teams, and integrative relationships between internal and external audit.

Investment in this area is not a cost but a guarantee for company continuity. Major crises that passed through global companies could have been avoided with better internal control. Companies that adopt the culture of control, support internal audit, and respect its independence build a solid foundation for growth and prosperity. With continuous developments in the Regulations, the future promises higher requirements and greater opportunities for leading companies in control and audit.

🎯  Essential Points to Remember

(1) Internal control system is mandatory, with COSO’s five components. (2) Internal audit mandatory since 2021, with limited exceptions for small companies. (3) Internal auditor reports to the Audit Committee, not management (2024 amendments). (4) Appointment and dismissal of internal auditor by Board resolution upon Audit Committee recommendation. (5) Periodic meetings between Audit Committee and auditors without management (2024 amendments). (6) Sufficient resources for internal audit mandatory (Article 52). (7) External auditor independent, appointed by Assembly resolution, partner rotation every 5-7 years. (8) Integration between internal and external, not replacement. (9) Whistleblowing system mandatory with reporter protection. (10) Annual disclosure on internal control and its effectiveness.

Contact Us

FAQS

What is the difference between internal control and internal audit?

Internal control is the overall system of policies and procedures management puts in place to protect company assets and ensure accuracy of financial statements, while internal audit is the independent unit that evaluates and tests the effectiveness of that control system and reports to the Audit Committee.

Is internal audit mandatory for all companies?

Yes, establishing an internal audit unit has been mandatory since the 2021 amendments, with limited exceptions for very small companies that may outsource the function, subject to independence, competency, and disclosure to shareholders.

Who does the internal auditor report to under the 2024 amendments?

The internal auditor reports to the Audit Committee, not to executive management, with appointment based on the Audit Committee's recommendation and Board approval, while dismissal requires Board approval based on documented reasons recommended by the Audit Committee.

References and Sources

  • Corporate Governance Regulations — Chapter Six (Articles 72-79).
  • 2021 amendments to Governance Regulations — Conversion of internal audit articles from indicative to binding.
  • 2024 amendments — Article 24(4), 52(b)(3), 54(b).
  • COSO — Internal Control Integrated Framework.
  • Institute of Internal Auditors (IIA) — International Standards.
  • ISACA — CISA Review Manual.
  • AICPA — External Auditor Independence.
  • PwC, KPMG, EY, Deloitte — Internal Audit Guides.
  • OECD — Internal Audit and Governance.
  • Saudi Organization for Chartered and Professional Accountants (SOCPA).

Related Posts

Quarterly and Annual Earnings Communications

Quarterly and Annual Earnings Communications

  Quarterly and Annual Earnings Communications Press Releases, Earnings Calls, Conferences, and Follow-Up First: Introduction Earnings announcements are the most important moments in the annual IR calendar. Four times a year (for Main Market companies), the company displays its financial

Read More»
Crisis Management in Investor Relations

Crisis Management in Investor Relations

  Crisis Management in Investor Relations Reputation, Activist Shareholders, Market Turbulence, and Crisis Communication First: Introduction Crises are a true test of investor relations. In normal times, IR is a routine communication function. In crises, it becomes the company’s first

Read More»
Digital Investor Relations (Digital IR)

Digital Investor Relations (Digital IR)

  Digital Investor Relations (Digital IR) Websites, Social Media, Live Streaming, and Digital Platforms First: Introduction Digitization has radically changed investor relations. What used to require printed reports and phone calls is now available through interactive websites, live streaming, and

Read More»