Building a Stronger Internal Audit Function

by: Smith and Howard

December 15, 2014

Back to Resources

In recent years, nonprofits have been the target of increased scrutiny over governance, accountability and compliance. Despite this, many organizations dismiss the importance of their internal audit function.

This isn’t a wise move. All nonprofits face heightened expectations from regulators and the public, as well as an ever-expanding field of risks. Even though your budget may be tight, you can’t afford mistakes or fraud incidents as a result of a weak or nonexistent internal audit function.

What roles does the internal audit play?

On its most basic level, the internal audit function provides independent assurance of a nonprofit’s compliance with its internal controls and their effectiveness in the areas of financial and operational risk. Potential risks include fraud, insufficient funds to support programming, and reputational damage. Such risks are, of course, of concern to all types of organizations, but they’re particularly critical for nonprofits, which are often held to a higher standard of integrity by the public. Moreover, noncompliance with regulations could cost a nonprofit its tax-exempt status.

Internal audit is typically charged with:

  • Identifying risks and prioritizing them from high to low,
  • Assessing the effectiveness of internal controls through testing and other methods,
  • Evaluating compliance with laws, regulations and contracts,
  • Mitigating risks with targeted audit plans that give greater attention to high-risk areas and producing reports with recommendations for improvement,
  • Following up on its own recommendations and management’s remediation actions to eliminate identified risks, and
  • Assisting external auditors.

The overall objective is to help the nonprofit accomplish its goals through proactive risk management and informed governance.

How do internal auditors work?

Internal auditors typically begin with an overall risk assessment of the nonprofit. Their wide-ranging review will consider everything involved in accomplishing the organization’s objectives, including financial procedures and processes (from cash and banking practices to financial reporting).

When high-risk areas are identified, auditors use various methods, such as testing of transactions, interviews of staff, or electronic data extraction techniques, to assess the strength of internal controls.

Smaller organizations aren’t exempt from the internal audit imperative. Their board and management can oversee internal controls with the assistance of a qualified third party.

What ensures success?

The effectiveness of the internal audit function hinges on several factors, including:

Independence. Internal auditors should be independent from management and other functions they review to avoid bias or a conflict of interest. They should report directly to the board of directors or its audit committee.

Executive support. The board and executive management must provide clear support for the internal audit function and its activities to convey their importance to the full organization. Leadership must indicate its support both verbally and by its actions. For example, the board must meet regularly with internal auditors to discuss their findings and should visibly act on their recommendations.

Resources. Not surprisingly, the quality of the internal audit function’s work is directly related to its capacity, yet one of the major handicaps suffered by many internal audit functions is insufficient resources. Even where the function is manned by individuals with extensive audit expertise, it might lack employees with the requisite knowledge of relevant program areas. For peak performance, internal audit should engage internal or outsourced staff with experience in compliance and controls, program areas, operations, and specialized areas (such as IT), especially those identified as high-risk.

Quality Assurance Review (QAR). A QAR assesses the overall effectiveness of an internal audit function by applying three criteria: 1) compliance with professional standards; 2) effectiveness and efficiency of function activities, organization, resources and skill capabilities; and 3) evaluation and fulfillment of stakeholder needs. A resulting report includes recommendations for improving and enhancing the internal audit function’s role. The Institute of Internal Auditors suggests that internal auditors conduct QAR self-assessments periodically, with third-party QARs done every five years.

An indispensable function

With proper independence and support, the internal audit function can prove invaluable for nonprofits of all sizes. Proper assessment of risk — whether by an in-house or outsourced internal audit function — is crucial for nonprofits that want to thrive in today’s rigorous environment.

For more information, please contact a member of Smith and Howard’s nonprofit team at 404-874-6244.

How can we help?

If you have any questions and would like to connect with a team member please call 404-874-6244 or contact an advisor below.