Audit and assurance committee handbook

Guidance on the principles and best practise for the organisation of Audit and Assurance committees.


Annex F: Governing the internal audit function

From 1 April 2025 the Global Internal Audit Standards (GIAS) - accompanied by the Global Internal Audit Standards in the UK Public Sector Application Note – replaced the Public Sector Internal Audit Standards (PSIAS). Audit and Risk Assurance Committees will need to make sure that their internal audit arrangements are compliant with GIAS and that the head of internal audit provides an overall conclusion at least annually in support of wider governance reporting.

As noted within paragraph 4.15-SGAAC is the governing Committee in respect of the services DIAA provides to both core and shared service partners. However there are further conditions relevant to the IA function. Within GIAS, Domain III: Governing the Internal Audit Function outlines the Essential Conditions that must exist:

Authorised by the AAC

  • discuss with the HIA and senior management the appropriate authority, role, and responsibilities of the IA function
  • approve the IA charter, which includes the IA mandate and the scope and types of IA services
  • champion the internal audit function and enable it to fulfil the purpose of IA and pursue its strategy and objectives
  • work with senior management to enable the IA function’s unrestricted access to the data, records, information, personnel, and physical properties necessary to fulfil the IA mandate
  • support the HIA through regular, direct communication

Positioned independently

  • demonstrate support by: specifying that the HIA reports to a level within the organisation that allows the IA function to fulfil the IA mandate; approving the IA charter, plan, budget and resource plan; making appropriate inquiries of senior management and the HIA to determine whether any restrictions in the IA function’s scope, access, authority, or resources limit the function’s ability to carry out its responsibilities effectively; meeting periodically with the HIA in sessions without senior management present
  • establish a direct reporting relationship with the HIA and the IA function to enable the IA function to fulfil its mandate
  • provide the HIA with opportunities to discuss significant and sensitive matters with the AAC, including meetings without senior management present
  • engage with senior management and the HIA to establish appropriate safeguards if HIA roles and responsibilities impair or appear to impair the internal audit functions’ independence
  • engage with senior management to ensure that the IA function is free from interference when determining its scope, performing internal audit engagements, and communicating results

Overseen by the Board (where relevant)/SGAAC

  • communicate with the HIA to understand how the internal audit function is fulfilling its mandate
  • communicate the board’s perspective on the organisation’s strategies, objectives, and risks to assist the HIA with determining internal audit priorities
  • set expectations with the HIA for: the frequency with which the board wants to receive communications from the HIA; the criteria for determining which issues should be escalated to the board, such as significant risks that exceed the board’s risk tolerance; the process for escalating matters of importance to the board
  • gain an understanding of the effectiveness of the organisation’s governance, risk management, and control processes based on the results of internal audit engagements and discussions with senior management
  • discuss with the HIA disagreements with senior management or other stakeholders and provide support as necessary to enable the HIA to perform the responsibilities outlined in the internal audit mandate
  • discuss with the HIA, at least annually, the sufficiency, both in numbers and capabilities, of internal audit resources to fulfil the internal audit mandate and achieve the internal audit plan
  • consider the impact of insufficient resources on the internal audit mandate and plan
  • engage with senior management and the HIA on remedying the situation if the resources are determined to be insufficient
  • approve the internal audit function’s performance objectives at least annually. (In the DIAA context performance objectives are set by DIAA Director and then applied locally)
  • assess the effectiveness and efficiency of the internal audit function - such an assessment includes:
    • reviewing the internal audit function’s performance objectives including its conformance with the Standards, laws and regulations
    • ability to meet the internal audit mandate
    • progress towards completion of the internal audit plan
    • considering the results of the internal audit function’s quality assurance and improvement programme
    • determining the extent to which the internal audit function’s performance objectives are being met
  • collaborate with senior management and the HIA to determine the scope and frequency of the external quality assessment (In DIAA context the commissioning, management and reporting of EQA is led by DIAA Director)
  • consider the responsibilities and regulatory requirements of the internal audit function and the HIA, as described in the internal audit charter, when defining the scope of the external quality assessment (as above)
  • require receipt of the complete results of the external quality assessment or self-assessment with independent validation directly from SGAAC (as above)
  • review and approve the HIA’s action plans to address identified deficiencies and opportunities for improvement, if applicable (as above)

Contact

Email: DIAABusinessSupportHub@gov.scot

Back to top