The Anatomy of an Assurance / Compliance Audit (ACA): Part 1

Introduction

Assurance / Compliance is one of the most important processes within any business. This is a discipline on its own, as described in ISO 19600:2014: Compliance Management. This process needs to provide business with a sense of “guarantee” that “what is said to be done, is actually done”. This is where the Seven (7) ISO principles plays a very important part of the process as well as Principle 15 of King IV, with the Combined Approach or Integrated Approach Model. CAA will provide in this article, a step by step approach to the ACA.

Step 1: Planning

Planning, planning, planning!

Never forget how important planning is in making sure that an Assurance / Compliance Audit (ACA) audit runs smoothly. Always remember, the ACA must be risk based! The process for a successful ACA includes:

  • what is being audited / assured off?
  • notifying the auditee (person being audited);
  • collecting and analysing the risk-based data being audited;
  • identifying key risks as recorded in the risk register and
  • scoping the ACA. 

Step 2: Determine the Risks

Risk based approaches in business is current and relevant. All activities must be aligned with the various risks identified by Management, Departments, Sections, Units and this must be the starting point of the ACA. There are routine risk-based ACA that must be performed, and this must be factored into the annual Assurance Plan. Thus, when planning for the year, these ACA are factored in. Then every year, when planning assignments, input is received from management, as to the risk areas in the business, and ACA based on high risk areas are planned for that year.

This is not a stagnant process but Dynamic, iterative and responsive to change (Principle 10: ISO 31000:2009). Thus, when the risks are assessed (identified, assessed and evaluated), and new risks emerge, the ACA plan needs to be reviewed to incorporate the newly identified risks.

Step 3: Scope of ACA

The scope of the ACA normally covers the previous six (6) to twelve (12) months and must include current activities indicating what is happening presently. ACA, by nature, are past orientated but must also be present and future focused.

It is vital to inform management or the auditee of the upcoming ACA and to request information, reports, records, documentation and samples before commencing the ACA.

A very important aspect during this phase is to ensure that the relevant personnel are available to be interviewed (structured or unstructured: ISO 31010).

Step 4: Analytical Process Thinking

Data analytics and CAATS (Computer Aided Audit Techniques) should be performed prior to ACA fieldwork to highlight exceptions and errors within the data collection process. It is not the primary purpose of Assurance / Compliance to root out fraud / corruption, but this must always be on the radar. If a risk is identified during the ACA (particular a fraud risk), the scope can be amended to concentrate on this area. 

There must be some flexibility in planning and conducting the ACA to allow for “drill down” into these areas.

When planning, a task plan needs to be set with all tests to be performed, the person responsible, budgeted hours and the target completion for each task. Tasks and tests can be allocated points to monitor the productivity of the ACA Team on a daily and weekly basis. It is important to set targets to give something to work towards. Every Assurance / Compliance auditor from intern, clerk and junior upwards, is an “executive” and must act in this capacity and think in a strategic way

Step 5: Testing the Controls

It is important that the entire team is involved in planning. This “grows” juniors and gives them the big picture. All juniors and clerks are executive material and should be treated this way. They should take responsibility for their work and be able to THINK. It is vital that an Assurance / Compliance auditor can think and not just “tick a box”. You must know the:

· “why” of the controls tested,

· “what” the risks being mitigated are,

· “how” the processes work and

· “who” is responsible.

Step 6: Understanding the Organisation

When going into the area to ACA, it is important to understand the business landscape (PDCA Model). Sometimes there are past Assurance and audit files but, no matter, it is vital to “flow-chart” the current processes and activities in the area. This we call a process narrative whereby all process and activities, as well as the controls surrounding them are documented. In conjunction with the process narrative, a risk assessment is performed. At this stage it is easy to pick up gaps in controls, where a risk has been identified but there is no control associated with this risk. These should be immediately brought to management attention.

Once all risks and the business landscape have been documented, the programme of tests to be performed is prepared. This should be focused on risk areas, as well as covering all assurance / compliance issues. Where time is a factor and some areas are not covered (or these were previously covered and are not high risk) then a limitation of scope is communicated to management. Up until this stage we have been planning the audit. The planning should not be confused or meshed in with the fieldwork itself. The failure to differentiate between planning and fieldwork is one of the key reasons why ACA fail, over-runs occur and confusions result. Planning is a distinct cycle of action, separate from fieldwork. The ACA must be structured, systematic and timely implemented, in such a way that the entire ACA team and the auditee is aware of this distinction. 

PLAN, TARGET, DELEGATE, DO, MONITOR AND REVIEW.

CAA come to the end of the first instalment on the anatomy of an ACA. CAA will continue with beginning the fieldwork, performing the ACA, handling queries, reporting and finalisation in the next article.