Internal Audit and Corporate Governance
Boards and audit committees rely on internal audit to tell them whether governance, risk management and control are working. Too often they receive long reports on minor findings while the risks that matter go unexamined. This programme shows audit leaders and governance professionals how to position internal audit as an independent, risk-focused source of assurance under the IIA Global Internal Audit Standards.
In many organisations the relationship between internal audit and the board is weaker than it should be. Audit plans are built from a cycle of past audits rather than from current risks. The audit committee charter is unclear on what it expects, reports focus on compliance detail, and follow-up of agreed actions is slow. Governance itself is rarely audited, although board processes, delegations of authority, ethics and related-party controls are where serious failures often begin.
This programme approaches internal audit from a governance perspective. It starts with the principles of corporate governance and the roles of the board, audit committee and management, then examines how the internal audit function is governed and positioned, how it plans risk-based work, how it audits governance, risk management and control, and how it reports to and influences the board.
Built on recognised practice. The programme references the Institute of Internal Auditors (IIA) Global Internal Audit Standards, which took effect in January 2025, the IIA Three Lines Model, the COSO Internal Control Integrated Framework and COSO Enterprise Risk Management framework, the G20/OECD Principles of Corporate Governance and the OECD Guidelines on Corporate Governance of State-Owned Enterprises. Participants also compare these with the corporate governance codes and regulations that apply in their own countries and sectors.
Decisions this programme improves. How the board and audit committee should oversee internal audit; what the audit charter and mandate should cover; which risks and governance areas to include in the audit plan; how to balance assurance and advisory work; how to report findings so that they lead to action; and how to assess the effectiveness of the internal audit function itself.
How it is delivered. Twenty hours across five sessions, built around one running case: a state-owned enterprise with a newly formed audit committee, a weak delegation of authority and a recent related-party issue. Participants review the audit charter, build a risk-based plan, plan a governance audit and draft a report to the audit committee.
In-house option. For organisations, the programme can be tailored to your own governance framework, audit methodology and regulatory requirements, and delivered to audit committee members and the internal audit team together.
Who Should Attend
Objectives
Course Outline
Competencies
London
Related Topics
Internal audit functions are judged on whether their work changes decisions, yet many audit leaders spend their time on fieldwork rather than on planning, people and relationships. This programme builds the management skills audit managers and senior auditors need to plan a risk-based audit portfolio, lead teams and engagements, manage stakeholders and prove the value of internal audit.
The aim of this course is to equip participants with the knowledge and skills required to perform first, second and third-party audits of quality management systems (QMS) against ISO 9001.
To empower participants with the robust capabilities of COBIT in implementing an effective Enterprise Governance of Information and Technology (EGIT) for organizational success.
