Building an Internal Audit Function
Internal audit is the assurance function every board eventually needs — but rarely at the size or in the form people expect. The questions we hear most about building it.
Internal audit is often the function boards know they eventually need but delay building, unsure of the right size, structure, or moment to start. Here are the questions we're asked most.
At what size or stage does a company need an internal audit function?
There is no fixed revenue or headcount trigger, but common signals include preparing for a listing, operating across multiple entities or locations that make direct oversight impractical, having faced a material control failure, or reaching a size where the audit committee needs independent assurance beyond what management self-reports.
How is internal audit different from external audit?
External audit provides an independent opinion on the financial statements for shareholders and regulators, on a fixed annual cycle; internal audit is a continuous function that tests the effectiveness of controls, risk management, and governance processes across the business, reporting to management and the board rather than to external stakeholders.
Who should internal audit report to?
Functionally to the audit committee, which approves its plan, reviews its findings, and is the primary recipient of its reports — administratively it may sit under a senior executive for day-to-day matters like budget, but that reporting line must never be allowed to compromise its independence from the areas it audits.
Does a company need a full internal audit department, or can it be outsourced?
Both models work. Smaller organizations often co-source or fully outsource the function to a specialist firm, which is cost-effective and brings broad expertise; larger or more complex organizations typically build an in-house team once the volume and sensitivity of work justifies dedicated headcount, sometimes supplementing it with outsourced specialists for specific technical audits.
How is the internal audit plan built?
It starts from a risk assessment — mapping the organization's key risks and control areas — and prioritizes audit coverage toward the highest-risk areas, rather than rotating through every department on a fixed schedule regardless of risk. The plan should be reviewed and approved by the audit committee at least annually, with flexibility to respond to emerging risks during the year.
What does an internal audit actually produce?
A report for each audit covering what was tested, what was found, the risk each finding represents, and an agreed management action plan with an owner and a date — plus a periodic summary report to the audit committee tracking open findings to closure across the whole audit plan, not just the most recent engagement.
What makes internal audit findings actually get fixed, rather than repeated?
A closure process with teeth: findings assigned a named owner and a date, tracked centrally, followed up with re-testing rather than taking management's word that a fix is in place, and escalated to the audit committee when remediation slips or a finding recurs.
What qualifications or background should the first internal audit hire have?
A professional audit or accounting qualification (such as CIA or CPA) combined with genuine business understanding of the organization's sector, since the role requires both technical rigor in testing controls and enough commercial credibility to be taken seriously by the operational teams being audited.
What a functioning internal audit function needs
- Functional reporting to the audit committee, regardless of administrative reporting line
- A risk-based annual plan, reviewed and approved by the audit committee
- Reports that name findings, risk, and an owner with a date — not vague observations
- A closure process with re-testing, not self-certified fixes
- Regular summary reporting on open findings across the whole plan
- The right mix of technical qualification and business credibility in its people
The value of internal audit isn't the reports it produces — it's the discipline of independent testing that catches a control breaking down before it becomes a finding an external auditor writes up, or worse, an incident.
Setting up or strengthening internal audit?
We help build internal audit functions — risk-based planning, reporting lines, and closure discipline — scoped to the size of your organization.
Discuss your mandate →Read next
The Audit Committee: The Board's Line of Sight → Internal Controls Before an External Audit: Closing the Gaps →This article is general guidance on governance practice and does not constitute legal, audit, or regulatory advice. Requirements depend on your circumstances and the applicable regulations at the time; obtain professional advice for your specific engagement.