,

Set Up an Internal Audit Function in a Small Company (2026)

A company usually gets its first internal auditor for one of four reasons: a lender or a new board member asks whether it has one, a fraud is discovered and the answer to “how did nobody see this” is that nobody was looking, an IPO or a SOX readiness project needs someone to test controls, or the company has grown past the point where the CFO can personally know what happens in every location. Whichever reason, the first year decides whether the function becomes a source of assurance the board trusts or a compliance cost the CFO resents. The difference is not the size of the budget. It is whether the function is set up with a charter that gives it independence, a plan that starts with the risks the board actually worries about, and a sourcing model that buys skills the company does not have instead of hiring a generalist and hoping.

This guide is the setup sequence for a small or mid-size company, from the decision to the end of the first year: when a company needs the function and what it is for, the charter clauses and reporting line that make it independent, a sourcing decision matrix with cost ranges, a staffing and budget model for a one-person and a three-person function, the first ninety days, a first-year plan with six engagements and hours, the templates and tools to adopt rather than build, board reporting cadence, the measures that show whether it is working, and the mistakes that sink first-year functions. It was rewritten in September 2026 to reflect the Global Internal Audit Standards, which apply to a one-person function exactly as they apply to a hundred-person one, and it points throughout to the site’s templates for the annual plan, the planning memo, the report, and the issue log, so that the first year is spent auditing rather than designing forms.

In this guide

When a small company needs internal audit, and what it is for

There is no revenue threshold, but there are signals. Multiple locations where cash, inventory, or customer payments are handled by people the CFO does not see weekly. A finance team small enough that the same person approves, records, and reconciles. Lenders or investors with covenants and reporting requirements the company has never independently checked. Growth by acquisition, where the acquired entity’s controls are unknown. A board or audit committee that has started asking questions the management team cannot answer from data. And any fraud, however small, because the loss is rarely the point; the point is that nobody had the job of noticing. A company with two or more of those signals and a few hundred employees has an internal audit need whether or not it has an internal auditor.

What the function is for, in a small company, is narrower and more useful than the textbook definition. It gives the board an independent view of whether the controls over money, assets, and compliance obligations actually operate, which the board cannot get from management and cannot afford to get from the external auditor, whose scope is the financial statements. It gives the CFO a second pair of eyes on the locations and processes the finance team cannot cover. And it gives the company a mechanism for fixing what is found, through an issue log the board sees. It is not a second accounting department, not a compliance function, and not the person who fills in the SOX spreadsheets; a first auditor who is pulled into those jobs will be doing them in year three. The Global Internal Audit Standards describe the purpose in one sentence that survives translation to any size: to strengthen the organization’s ability to create, protect, and sustain value by providing independent, risk-based, and objective assurance, advice, insight, and foresight.

The charter and the reporting line

The charter is the document that makes the function independent, and in a small company it is the only thing that does, because the auditor will sit near the CFO, share the CFO’s budget line, and be asked by the CFO for help. The Standards require a charter approved by the board that establishes the function’s purpose, authority, and position, and the clauses below are the ones a small company’s charter must contain to mean anything. The charter guide has the full step-by-step; the Domain III guide explains the board’s obligations that the charter implements.

ClauseWhat it must sayWhy it matters in a small company
Purpose and mandateIndependent assurance and advice over risk management, control, and governance, across the whole company including subsidiaries and locationsCloses the argument about whether the acquired entity or the founder’s side business is in scope
Functional reporting lineThe head of internal audit reports functionally to the audit committee, or where none exists to the board through an independent director, who approves the charter, the plan, the budget, and the head’s appointment, evaluation, compensation, and removalWithout this, the auditor works for the CFO in every way that counts
Administrative reporting lineDay-to-day administration through the CEO or CFO, explicitly limited to logistics and excluding scope, findings, and reportingNames the arrangement so it cannot expand
Authority and accessUnrestricted access to all records, systems, property, and personnel, and the authority to communicate directly with the boardThe first time a location manager refuses access, this clause is what the auditor cites
Independence and objectivityNo operational responsibilities; a cooling-off period before auditing an area the auditor worked in; disclosure of impairments to the boardPrevents the auditor becoming the SOX coordinator, the policy writer, or the acting controller
Advisory servicesPermitted when management retains responsibility for decisions and the work is disclosed as advisory; not assured by the auditor for a stated periodThe CFO will ask for help; this says how
Standards and qualityConformance with the Global Internal Audit Standards; a quality program proportionate to size; an external assessment at least every five yearsSignals to lenders, investors, and the external auditor that the function is real
Reporting and follow-upFindings reported to management and the board; an issue log with status reported to the board at each meeting; management’s responses recordedThe follow-up mechanism is written into the governance, not left to the auditor’s persistence
SourcingAuthority to engage external providers under the head’s direction, with the company retaining responsibilityMakes co-sourcing a normal instrument, not an exception
ReviewCharter reviewed annually with the boardThe clauses erode unless they are re-read

Where the company has no audit committee, create one or designate an independent director to hold the functional line; a private company with a five-person board can do this in one resolution. Where the board has no independent director, the charter’s functional line runs to the full board, the auditor’s appointment and removal require a board vote, and the auditor reports to the board in a session without management present at least twice a year. A function that reports only to the CFO, in a company with no independent oversight, is an internal control review team, which is useful and is not internal audit; call it what it is and do not tell the lenders otherwise.

Sourcing: in-house, co-source, or outsource

The sourcing decision is the one most small companies get wrong in the same direction: they hire one generalist and expect that person to audit IT security, the ERP’s access model, revenue recognition, and the warehouse in the same year. The honest choice is between three models, and the right answer for most companies under a few thousand employees is the middle one, an in-house head who owns the plan and the relationships and buys the specialist hours. Cost ranges below are for the US in 2026 and vary by market; the point is the shape of the comparison rather than the exact figures.

ModelWhat it looks likeAnnual cost rangeFits whenRisks
In-house onlyOne to three employees doing all the workOne senior auditor: $130,000 to $190,000 loaded; three-person team: $400,000 to $600,000 loaded, plus tools and travelThe universe is mostly financial and operational processes the team knows; IT and specialist areas are small or bought separatelySkills gaps in IT, cyber, and specialist areas; key-person dependency; no surge capacity for an acquisition or an investigation
Co-source (recommended default)An in-house head (or head plus one) who owns the charter, risk assessment, plan, relationships, reporting, and issue log, and buys specialist and surge hours from a firm under the head’s directionHead $150,000 to $220,000 loaded, plus $80,000 to $250,000 of purchased hours at $150 to $350 per hour depending on specialtyMost companies from a few hundred to a few thousand employees; any company with meaningful IT, cyber, or regulatory exposureThe firm’s methodology overriding the company’s; the head becoming a contract manager; purchased hours spent on low-value work because they were budgeted
Fully outsourcedA firm performs the function under an engagement letter; a company executive is the designated liaison and the board oversees the firm directly$120,000 to $400,000 depending on scope; typically 600 to 1,500 hoursCompanies too small for a full-time head; a bridge before hiring; regulated companies that need a function before they can staff oneNo institutional memory; the firm audits to its template; the company retains responsibility under every regulator’s guidance whether it knows it or not; independence questions if the firm also provides other services

Whatever the model, two rules hold. The company owns the risk assessment, the plan, the findings, and the issue log, and they live in the company’s files under the company’s templates, not the firm’s. And the external auditor is not the internal auditor; the independence rules on both sides prevent it, and a board that is offered “internal audit services” by its financial statement auditor should ask its counsel before saying yes. The co-sourcing guide covers how to scope, contract, and manage purchased hours so that they integrate with the function rather than run beside it.

Staffing and budget: two models with numbers

The models below are for Brightwater Foods, a $180 million specialty food manufacturer with 600 employees, three plants, a distribution center, a lender covenant package, and a board with two independent directors, setting up its first function in FY27. Available hours assume 1,800 productive hours per full-time auditor after leave, training, and administration; the head’s hours are split between engagements and running the function.

LineModel A: one-person function plus co-sourceModel B: three-person function
Head of internal audit1 FTE, $185,000 loaded; 1,000 engagement hours, 800 function hours1 FTE, $195,000 loaded; 800 engagement hours, 1,000 function hours
Senior auditor1 FTE, $135,000 loaded; 1,700 engagement hours
Staff auditor or IT auditor1 FTE IT auditor, $145,000 loaded; 1,700 engagement hours
Co-sourced hours600 hours at an average $220: $132,000 (IT general controls 200, cybersecurity 150, revenue and inventory specialist 150, surge 100)150 hours at $280: $42,000 (penetration testing review and a fraud specialist on call)
ToolsWorkpaper and issue tracking on the company’s document platform and the site’s templates: $0 to $6,000; data analytics with spreadsheet and query tools: $0 to $3,000Audit management platform, entry tier: $15,000 to $35,000; analytics tooling: $5,000
Travel and training$18,000 (three plants, two conferences, certification maintenance)$40,000
Total annual costAbout $345,000About $600,000
Engagement hours available1,600 (1,000 in-house plus 600 purchased)4,350
Engagements per year5 to 6 at 250 to 300 hours each, plus validation and the risk assessment12 to 14, plus validation, advisory, and analytics
Cost per engagement hourAbout $215About $138

Brightwater chose Model A for FY27 with a commitment to review at the end of the year, on the reasoning that a first year with five well-chosen engagements would show the board what the function was worth better than a first year spent hiring. The budget conversation with the board used two comparisons: the FY26 inventory shrink write-off at the distribution center ($410,000, discovered by the external auditor at year-end) and the lender’s covenant reporting fee for a third-party review the bank had required ($45,000), which the function would replace.

The first ninety days

DaysDoOutputDo not
1–15Get the charter approved by the board with the reporting line settled; meet every board member and every executive; read the last two years of external audit management letters, lender correspondence, insurance claims, and any investigation filesApproved charter; a list of every concern each person raised, verbatimStart an audit; agree to “just help with” the close, the SOX project, or the ERP go-live
16–35Build the audit universe: every entity, location, process, and system, with the money and people in each; visit every plant and the distribution center; walk the cash, inventory, and payroll processes at eachAudit universe with values; site visit notes; a first list of what could go wrong per locationRely on the org chart; assume the plants run the same way
36–55Perform the risk assessment against the universe using the site’s risk assessment method; score, rank, and choose the first-year engagements; identify the skills the plan needs that the function lacksScored risk assessment; draft plan with hours; co-source scopePlan by what is easy to audit; plan by what management asked for
56–70Adopt the templates (plan, memo, work program, workpapers, report, issue log); set the rating scale and the issue log rules; set up the workpaper repository with access controls; contract the co-source provider under the function’s methodologyTemplate set; rating definitions; repository; signed engagement letterBuild templates from scratch; adopt the co-source firm’s templates
71–90Present the plan and budget to the board for approval; agree the reporting calendar; begin the first engagement, chosen to be visible, bounded, and likely to find something the board cares about (cash and inventory at the highest-risk location is the usual choice)Approved plan; reporting calendar; first planning memo issuedChoose a first engagement that will take five months; choose one that will find nothing

The first-year plan

Brightwater’s FY27 plan, approved on day 84, is below. It follows the annual plan template and its coverage logic: the highest-scored risks first, one engagement that tests the external auditor’s reliance area (ICFR readiness for the lender’s covenant reporting), one that covers the biggest unknown (the newest plant, acquired in FY25), and a reserve. Hours foot to the 1,600 available.

#EngagementWhy (risk assessment)QuarterHoursSourcing
1Distribution center inventory and shipping controlsFY26 $410,000 shrink write-off; counts unreconciled for two quarters; the location the board asked aboutQ1280In-house 200; specialist 80
2Procure-to-pay and vendor master, all entitiesOne AP clerk approves, enters, and pays for the two smaller plants; 1,900 vendors with no master-data controls; see the AP audit guideQ1–Q2260In-house 260
3ERP access and segregation of dutiesRoles built at go-live in 2021 by the implementer; 38 users with administrator access; see the ERP SoD guideQ2220In-house 70; IT co-source 150
4Cybersecurity program reviewNo prior independent review; cyber insurer’s questionnaire answered by IT alone; IIA Cybersecurity Topical Requirement now appliesQ3200In-house 50; cyber co-source 150
5Acquired plant: financial and operational controlsAcquired FY25; runs its own payroll and purchasing; never reviewedQ3240In-house 200; specialist 40
6Lender covenant reporting and ICFR readinessCovenant calculations prepared by one person; lender previously required a third-party review; board wants an ICFR baselineQ4200In-house 120; specialist 80
Issue validation (Q3 and Q4 windows)Findings from engagements 1 to 3Q3–Q480In-house
ReserveInvestigations, board requests, acquisition due diligence support120In-house and surge
Total1,600

The plan leaves out payroll, revenue, treasury, and the two older plants’ operations, and says so in a coverage statement with the year each will be reached. A first-year plan that covers everything covers nothing; a plan that covers six things well and names what it did not cover gives the board a map. Each engagement runs on the planning memo and the work program conventions, which is how a one-person function produces files an external assessor or a lender’s reviewer can read.

Templates and tools: the minimum viable toolkit

A one-person function does not need a GRC platform in year one, and buying one before there is a process to put in it is the most common way a new function burns its first discretionary dollars. What it needs is a fixed set of documents that look the same every time, stored in a folder structure a reviewer can follow without a guide. The table below is the toolkit Brightwater ran on for its first year: eleven artifacts, all of them spreadsheets, documents, or free site tools, with the trigger that tells you when each one has outgrown its format. The rule for the upgrade column is that the tool follows the process, never the other way round.

NeedMinimum viable versionWhen to upgradeStart from
Audit universe and risk assessmentOne workbook: entities and processes on rows, impact and likelihood factors on columns, a score, and a column for the last time the area was auditedWhen the universe passes roughly 60 auditable entities or three people are scoring it independentlyInternal audit risk assessment
Annual planA plan document with the engagement list, hours, sourcing, and the link from each engagement back to a risk score, approved and dated by the committeeNever; the format scales, only the number of rows changesInternal audit plan template
Engagement planning memoTwo pages: objective, scope, risks, approach, budget, timing, and who was interviewed to set themNeverAudit planning memo template
Risk and control matrixOne tab per process: risk, control, owner, frequency, key or non-key, test procedure, resultWhen you have more than about 15 processes with RCMs to maintain across yearsRCM Workbench (free)
Work programThe RCM’s test procedure column expanded into steps, with a workpaper reference per stepNeverAudit work program
WorkpapersShared drive, one folder per engagement, an index sheet, a naming convention (engagement code, section, sequence), preparer and reviewer sign-off on the indexWhen two or more people prepare and review concurrently and version conflicts appear, usually at three auditorsAudit workpaper example
SamplingA documented sample-size rule and a random selection you can reproduceNever; the rule is the controlmySampler (free) and the 25/40/60 guide
Audit reportOne fixed format: opinion or rating, summary, findings in the five-Cs structure, management action with owner and dateNeverInternal audit report template
Issue logOne spreadsheet: finding, rating, owner, due date, status, evidence of closure, validation dateWhen open issues pass about 40 or the committee asks for trend reporting you cannot build by handAudit issue log template
Audit committee packA six-page quarterly document with the same sections every quarter (next section)NeverInternal audit report examples
Quality programA one-page self-assessment against the Standards completed at year end, plus a reviewer checklist on every engagement indexYear five, when the external assessment is dueQAIP guide

Two rules make the toolkit work. First, every document has a code, and the code appears on the workpaper, in the issue log, and in the committee pack, so a director who asks “where did this finding come from” can be walked from the pack to the evidence in under a minute. Brightwater used engagement codes of the form FY27-03 and workpaper references of the form FY27-03-C-04, which is section C, paper four. Second, the reviewer checklist on the index is completed before the report is issued, not after, and in a one-person function the reviewer is the co-source partner for the first two engagements and the head thereafter, with the committee chair told which arrangement applies. A GRC tool bought in year three inherits a clean structure; one bought in year one inherits nothing and shapes the process around its own defaults.

Reporting to the board and management

The reporting cadence is set in the charter and then run without exception, because a small function’s credibility with its committee is built almost entirely on showing up with the same document at the same interval and saying what changed. Standard 11.3 requires the chief audit executive to communicate results to the board and senior management, and Standard 8.1 requires the board to receive the information it needs to oversee the function; Brightwater’s cadence below satisfies both with about 40 hours of preparation across the year.

OccasionAudienceContentLength and timing
Quarterly audit committee meetingAudit committee, CFO, CEO, external auditorPlan status (engagements completed, in progress, deferred, added); reports issued since last meeting with ratings; open issues by rating and age, overdue issues by name; hours used against budget; emerging risks the plan does not coverSix pages, same section order every quarter, circulated five business days before the meeting
Private sessionAudit committee members only; the head of internal audit without management presentAnything constraining independence, resistance to scope, management pressure on ratings, the head’s own performance and resourcingFifteen minutes at every quarterly meeting, held even when there is nothing to raise, so holding it never signals a problem
Annual plan and budget approvalAudit committeeRisk assessment summary, proposed engagements with the risk they address, hours and cost by sourcing model, areas not covered and whyFourth-quarter meeting; the plan is a standalone document, not a section of the quarterly pack
Annual charter and independence confirmationAudit committeeCharter reaffirmed or amended; written confirmation of organizational independence and any impairments during the year; QAIP self-assessment resultsSame fourth-quarter meeting, one page plus the charter
Monthly CFO and CEO updateManagementEngagement progress, findings emerging, help needed from management, action plans coming dueThirty minutes, one page; findings are previewed here, never first disclosed at the committee
Significant finding notificationCommittee chair, then the full committeeAny finding rated High, any indication of fraud, any control failure affecting the covenant package or the financial statementsWithin two business days of the head concluding the finding is supportable; by call to the chair, then in writing
Final report distributionProcess owner, their executive, CFO; committee receives the executive summary in the packThe report in the fixed format with management’s action planWithin ten business days of the closing meeting

Two independent directors who have sat on larger boards will ask the same three questions at the first meeting, and the answers should be in the pack before they ask. “What are you not covering?” is answered by the uncovered-areas section of the annual plan, which at Brightwater listed treasury, tax, and the sales commission scheme with the risk score and the year each was expected to be reached. “How do I know your findings are fixed?” is answered by the issue log summary showing closure validated by internal audit rather than declared by management, with the validation windows visible in the plan. “Are you independent?” is answered by the reporting line in the charter, the private session on the agenda, and the head’s written annual confirmation, plus a plain statement of what the head does not do: no month-end review, no sign-off on journal entries, no ownership of the covenant calculation. The GIAS Domain III guide covers the board’s side of these obligations in detail.

The wording of the first quarterly pack sets the tone for every one after it. Ratings are stated without softening, management’s response is printed as management wrote it, and disagreement is recorded rather than negotiated out. Brightwater’s first pack reported the distribution center engagement as Needs Improvement with three findings, one of them High, and the operations vice president’s response, which disputed the High rating, appeared verbatim under the finding with the head’s one-sentence reason for keeping it. The committee chair later said that page was the reason the committee trusted the function; a first pack that reports six engagements as Satisfactory teaches directors to stop reading. The 5 Cs of audit findings structure keeps each finding to the condition, criteria, cause, consequence, and corrective action a director can act on in a single reading.

Measuring the function in year one

Standard 12.2 requires the chief audit executive to develop performance objectives and measure against them, and a new function should choose its measures before the first engagement starts, because a measure adopted in month nine will be chosen to flatter the first nine months. Eight measures are enough. Two of the most common ones are missing from the table deliberately: findings issued, which rewards volume and punishes a well-controlled process for being well controlled, and cost savings identified, which turns the function into a consultancy chasing a number it does not control. Both can appear as commentary; neither should be a target.

MeasureYear-one targetHow it is measuredWhat it tells the committee
Plan completion85 percent of planned engagements reported by year end; deferrals approved by the committee, not decided by the headEngagements with a final report issued, divided by engagements in the approved plan; additions and deferrals shown separatelyWhether the plan was realistic and whether the function can be relied on to deliver what it commits to
Report cycle timeDraft within 15 business days of fieldwork end; final within 10 business days of the closing meetingCalendar days from the last fieldwork day to draft, and from closing meeting to final, per engagementWhether findings reach the people who can act on them while the evidence is current
Action plan closure on time75 percent of actions closed by the original due date; no High action more than 90 days overdue without committee notificationFrom the issue log, by original due date, with extensions counted as lateWhether management takes the function seriously, which is the single best predictor of its second year
Validation coverageEvery closed High and Medium action validated by internal audit within 60 days of management’s closure claimActions validated divided by actions closed by management, by ratingWhether “closed” means fixed
Hours against budgetWithin 15 percent per engagement; within 10 percent for the yearTimesheet hours by engagement code against the planned hours in the approved planWhether budgets were honest and whether scope crept
Time allocationAt least 65 percent of total hours on assurance and validation; no more than 20 percent on advisory and requests; the rest on running the functionTimesheet categories, reported quarterlyWhether the function is being pulled into management’s work
Stakeholder feedbackPost-engagement survey returned by the process owner’s executive for every engagement; committee self-assessment of the function at year endFive questions on a five-point scale: scope relevance, disruption, accuracy of facts, fairness of rating, usefulness of recommendationsWhether findings are landing as accurate and fair, which is different from whether they are welcome
Conformance readinessYear-end self-assessment against the Standards completed, with every “partially conforms” carrying a dated actionSelf-assessment against the domains and standards, reviewed with the committee chairWhether the function will pass its external assessment in year five without a rescue project in year four

Brightwater reported all eight on one page of the quarterly pack from the first quarter, with year-one actuals of 100 percent plan completion (the cybersecurity review was deferred to Q1 of FY28 by committee decision and counted as such), a 19-day average to draft, 71 percent on-time closure, and 62 percent of hours on assurance, the last two of which became the first two objectives for year two. Reporting a miss in the first year, with the reason, is worth more to the function’s standing than a clean scorecard nobody believes. The GIAS Domain IV guide covers the full set of managerial requirements these measures sit under.

Common mistakes in the first year

FailureWhat it looks likeWhy it mattersFix
Reporting to the CFO onlyThe charter names the CFO as the reporting line; the committee sees the head twice a yearFinance is the most-audited area in any small company, and the auditor’s appraiser owns itFunctional reporting to the committee in the charter, administrative to the CEO or CFO, private session every quarter
Hiring the controllerThe former controller becomes the head of internal audit and reviews the close they used to runStandard 7.1 impairment on every finance engagement for at least a year; the committee’s independence confirmation is untrueHire from outside or from operations; if the controller is the only candidate, co-source finance engagements for year one and disclose it
Starting with a controls inventorySix months documenting every control in the company before auditing anythingNo findings, no reports, no credibility, and the inventory is out of date before it is finishedRisk assessment in 30 days, first engagement in fieldwork by day 60, RCMs built one process at a time as each is audited
Importing a large-company planTwenty-two engagements copied from a former employer’s plan for a function with 1,600 hoursPlan completion of 40 percent in year one and a committee that stops believing the planSix to eight engagements sized from the hours table, with a reserve and a named list of what is not covered
Doing management’s workThe head prepares the covenant calculation, reviews journal entries, or writes the policies the function will later auditSelf-review and management responsibility impairments; the lender and external auditor stop relying on the functionAdvisory work is allowed and recorded; performing controls is not; the charter says which is which
No validation stepActions are closed when management emails “done”The same finding reappears in year three, and the committee learns the issue log was fictionValidation windows in the plan; closure by internal audit only, with evidence filed
Buying a GRC platform firstA tool selected in month two, configured for months three to six, populated with nothingYear-one discretionary budget gone; the tool’s defaults become the processSpreadsheets and a folder structure until the triggers in the toolkit table are hit
Softening the first reportThe first engagement is rated Satisfactory with “opportunities for improvement” to avoid a fightEvery later rating is calibrated against the first; the function has taught management that ratings are negotiableRate what the evidence supports, print management’s disagreement, let the committee see both
Ignoring the acquired entityThe plan covers the parent’s processes; the plant acquired last year runs its own payroll and purchasing unauditedAcquired entities carry the highest concentration of unreviewed control gaps in any small companyOne engagement in the first-year plan for every entity on a separate system or ledger
No quality program until year fourNothing written about quality until the external assessment is 12 months awayStandard 8.3 and 12.1 nonconformance, and a rescue project that consumes the year-four planReviewer checklist on every index from engagement one; annual self-assessment from year one

The pattern across the ten is that a new function fails on structure, not on audit technique. The head almost always knows how to run an engagement; what goes wrong is the reporting line, the plan size, the boundary between assurance and management’s work, and the follow-up discipline, all of which are settled in the charter and the first plan if they are settled at all. The GIAS Domain II guide covers the independence and objectivity requirements behind the first, second, and fifth rows.

Adapting the model: family-owned, PE-backed, pre-IPO, and nonprofit

Brightwater has an audit committee with independent directors and a lender who wants assurance, which is the easiest setting for a first function. The four variants below change who the function reports to, what the first year emphasizes, and what the head has to watch for. The reporting-line column is the one that matters most: where there is no audit committee, the Standards still require functional reporting to whoever performs the board’s governance role, and the charter names that person or group explicitly.

SettingFunctional reporting lineFirst-year emphasisWatch for
Family-owned, no audit committeeThe owner or family council, ideally with one outside advisor added to an advisory board for the private sessionCash, payroll, vendor master, and expense controls, where a trusted long-serving employee is usually the only control; succession-related process documentationFindings that implicate family members or a founder’s long-time deputy; the charter must state that the head reports these to the owner in writing without editing, and what happens if the owner is the subject
Private-equity-backedThe board’s audit committee if one exists, otherwise the board with the sponsor’s operating partner as the designated contactThe sponsor’s 100-day and value-creation plan items that touch controls: ERP consolidation, add-on integration, working capital reporting, covenant compliance; exit readiness from year twoBeing redirected into value-creation projects until no assurance is done; keep the 65 percent assurance floor in the charter and report time allocation quarterly to the board, not only to the sponsor
Pre-IPOAn audit committee formed ahead of listing, with at least one independent member before the function startsICFR readiness: entity-level controls, the financial close, revenue, ITGCs, and a documented control set that management can assess under SOX 404(a) once the transition period for newly public companies ends; the internal audit function itself is a listing-readiness itemTreating the readiness project as the audit plan; the function should assess readiness work done by management or a consultant, not perform it, or it cannot audit ICFR afterward. Emerging growth companies are exempt from the 404(b) auditor attestation for up to five years, which makes internal audit’s own ICFR work the only independent view the committee gets
NonprofitThe board’s audit or finance committee; where the finance committee also approves the budget, a separate audit committee of at least two independent members is worth forming before the function startsRestricted-fund accounting, grant compliance and allowable costs, conflicts of interest and related-party transactions, executive compensation process, cybersecurity around donor data; for federal award recipients, Uniform Guidance compliance and single audit readinessConfusing the external single audit with internal audit; a nonprofit spending more than the federal single audit threshold, which rose to one million dollars for fiscal years beginning on or after 1 October 2024, has an external compliance audit that does not test operational controls, and the board frequently believes it does

In every variant the sourcing decision from the earlier section still holds: a single competent head with a co-source partner for specialist and surge work covers a $50 million to $300 million organization in year one, and the three-person model is justified by regulation, listing, or geography rather than by revenue alone. What changes is the first-year plan, which should be rebuilt from the setting’s own risk assessment rather than adapted from Brightwater’s, and the charter, which should name the reporting line in the terms above. The risk appetite guide is useful where the board has never articulated what level of control failure it will tolerate, which in a family-owned or PE-backed company is usually the first conversation the new head has to start.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading