Unit controls and audit

Unit controls and audit:what the internal audit report will say about your unit

From our point of view, every line of business, every unit and even every team is a separate profit centre. That is how they are measured at the organisational level.Whoever manages such a unit is measured on the result. But the document that decides how that result is seen is written somewhere else: in an audit report, in a language nobody uses in conversation. It is presented to management and the board, in a forum where the manager is usually not present.

Internal audit findings: why the unit manager sees them last

Not because anyone is hiding them. The data that makes up a finding is spread across systems, and none of them belongs to the unit. Permissions sit with IT, transactions with the finance department, hours with HR. The documentation, at best, sits in somebody's mailbox.

The unit manager sees the output: the work was done, the report went out, the customer received it. What the manager does not see is the evidence that records how the output was produced. The first time that picture is assembled in full, it happens at the audit.

That is why the audit feels like a surprise, even when everything written in it is correct.

The wording that recurs in internal audit reports

If you have been through an audit, some of this wording is familiar. That is an advantage, not a drawback. Whoever has seen how a finding is written knows exactly how much work it took to close, and what it means to see it again next year.

The findings management and the board know as the painful ones

  1. Repeat finding: the deficiency was reported in the prior year and has not yet been remediated.

    The hardest of all, because it reads as a management problem rather than a process problem. Almost always it is not neglect but a fix that was manual, and so did not survive the year.

  2. No complete audit trail was found for the process.

    The result exists, but there is no way to reconstruct how you reached it: which data went in, who approved, and what was there before the correction.

  3. The unit relies on uncontrolled spreadsheets for reporting purposes.Ineffective management of resources

    The number you presented to management sits in a file on one computer. Anyone can change a formula in it, and there is no way to know who changed it and when.

What else can appear in the audit report

These are less dramatic, but they add up. Scan the first column, stop at what you recognise, and read across.

What the audit report will sayWhat it means in your unitWhat can stop it recurring
The same officer initiates and approves.A segregation of duties deficiency. Almost always for lack of staff, but in the report it looks the same.Approval is defined in the process rather than by habit, and it does not go ahead without the right approver.
No supporting record of approval for the exception was found.The exception was probably approved, and perhaps rightly. There is simply no trace of it left.The approval is stored next to the action, not in a mailbox.
The periodic reconciliation was not performed by the date set in the procedure.Pushed to next month because things were busy, and then again. The procedure stayed, the execution did not.The reconciliation runs on a schedule, not when someone has time.
Reporting data cannot be reproduced from the system.Assembling the report again gives a different number, and the difference cannot be explained.The report is produced from the source, so the same run returns the same result.

What the findings have in common: missing evidence, not mistakes

Read them again and notice what is missing from them. None of them describes a mistake.

In most cases the work was done, the decision was reasonable, the exception was approved, and the approval came from someone authorised to give it. What is missing is the evidence: no record was kept that can be shown, so as far as the report is concerned it never happened.

That distinction changes what needs fixing. The problem is not the judgement of the people in the unit. It is that the process left no trace.

Where our angle comes from: internal audit work at financial institutions

Our team has experience in internal audit work at financial institutions, where the requirements for documentation, segregation of duties and a complete audit trail are stricter than in most organisations.

The practical meaning is simple: what counts there as a basic bar is usually exactly what is found missing elsewhere. It is also why this page is written in the language of a report and not the language of marketing.

Unit-level controls: the checks that run on their own, and the audit trail they leave

A process that runs automatically produces documentation as a by-product, because every step in it is recorded anyway: what went in, when, what came out, who approved and what changed. Nobody has to remember to document, because there is no separate step where that is done.

Beyond the documentation itself, these are checks that are actually built at unit level:

  • A periodic cross-check between the list of employees and the list of users and their permissions
  • An alert on an action that went out without the approval defined for it
  • Tracking of the deadlines set in the procedure, with an alert before the deadline is missed and not after it
  • Reproducing a report from the source, to confirm that the same run returns the same result
  • Re-checking a finding that was closed, to know whether the fix held

And what does not change: a finding that stems from professional judgement, policy or a business decision will not disappear through automation. Automation deals with the absence of evidence, not with the absence of a decision.

What is this not?

Three clarifications, because in this field it is very easy to promise too much:

  • This is not a promise that you will pass an audit with no findings. The only promise here is far narrower: you will not be caught out by a finding that exists because nobody documented.
  • This does not replace internal audit. Internal audit defines what matters to check, interprets the findings and carries the professional responsibility. What changes is that it arrives at an orderly state instead of starting from collection.
  • A control checks what it was defined to check, on the data it has access to. A check that relies on a figure that cannot be exported from the system will not be built, and that is said at the measurement stage, not after it.

Where does this meet continuous controls and finance automation?

Three pages touch on controls, and each answers a different question:

  • Continuous controls in the organisation deals with failures that sit in the seam between departments, and with the hardest category of all: what never happened at all.
  • Finance automation deals with the repetitive work of the finance department, even when everything is fine.
  • This page deals with what is written about one unit, and why.

Where do you start?

If you have already received an audit report, start from it. It lists what was found missing and at what priority, and that is a far better starting point than a survey that begins from zero.

  • We pick one finding, the one most likely to recur
  • We check exactly what would have been needed for it not to be written
  • We estimate how much of that can become a check that runs on its own
  • And if the answer is that it cannot, that is said before anything is built

And if you have not been through an audit yet, the wording above is the list. It recurs in almost every organisation, and it is easier to close before it is written.

More on automation services for business: how it works, and when we say no

Frequently asked questions

Why does a unit manager only see the findings once they are already written?

Because the data that makes them up is spread across systems, none of which belongs to the unit. The manager sees the output of the unit, not the evidence that records how it was produced. So the first time the picture is assembled in full, it happens at the audit. The report is then presented to management and the board, in a forum where the manager is usually not present.

What do most audit findings at unit level have in common?

They do not describe a mistake but an absence of evidence. In most cases the work was done, the decision was reasonable and the exception was approved, but no record was kept that can be shown. That distinction changes what needs fixing: not the judgement of the people, but the fact that the process left no trace.

How does process automation help with internal audit?

A process that runs automatically produces documentation as a by-product, because every step is recorded anyway: what went in, when, what came out, who approved and what changed. This is not a promise that the unit will pass an audit with no findings. It is that the unit will not be caught out by a finding that exists because nobody documented. A finding that stems from professional judgement or policy will not disappear through automation.

Why is a repeat finding considered more serious?

Because it was already reported once and a commitment was made to fix it, so at the board it reads as a management problem rather than a process problem. In practice it almost always stems from the fix having been manual: someone committed to a monthly check, it was done for three months and then pushed aside. A fix that survived the year is usually one that became a check that runs on its own.

Does this replace internal audit?

No, and it was not meant to. Internal audit defines what matters to check, interprets the findings and carries the professional responsibility. What changes is that the evidence exists in advance and that checks already defined run continuously, so the audit arrives at an orderly state instead of starting from collection. In many cases the checks that are built are exactly the ones that already appear in the audit plan.

Where do we start if we have already received an audit report?

From the report itself. It already lists what was found missing and at what priority. We pick one finding and check exactly what would have been needed for it not to be written. Then we estimate how much of that can become a check that runs on its own. If the answer is that it cannot, that is said before anything is built.

This page is general information about how we work. It is not an offer, an undertaking, or a promise of any result. Binding arrangements, including the scope of the service and the handling of data, are set out in a written agreement. See the Terms of use.