SD-14.8 — Internal Audit

Business Domain: BD-14 Enterprise Risk, Control & Assurance (Cross-cutting — corporate) · Applies: BOTH

Purpose

Provides independent assurance to the governing body that the firm’s controls, risk management and governance are working. SD-14.8 is the third line of the three-lines model: it is independent of the functions it audits, it reports functionally to the audit committee, and it gives the board an objective opinion on whether the firm’s control environment can be relied on. It is not the design and operation of the controls — that is SD-14.7 Internal Control & Assurance (the first/second-line management activity) — and it is not the second-line risk and compliance functions (SD-14.1 to SD-14.3). Internal audit independently assures that the other lines work; it does not run them.

Service Operations

  • Plan the audit programme — build the risk-based internal-audit plan and agree it with the audit committee.
  • Conduct audits — perform the planned audit engagements: test controls, examine processes, gather evidence.
  • Report findings — report audit findings, rate them, and present the opinion to the audit committee.
  • Track remediation — track the management actions arising from audit findings to closure.
  • Provide assurance to the governing body — give the board and audit committee the independent opinion on the firm’s control environment.

Inputs and outputs

  • Inputs: the firm’s processes, controls and risk and compliance functions — the audit universe; the control framework from SD-14.7; the audit committee’s priorities.
  • Outputs: audit findings, ratings, the assurance opinion and the remediation-tracking record — consumed by the audit committee, the governing body and the regulators.

Entities

  • Consumes: the firm’s control, risk and process records across the model; the SD-14.7 control framework.
  • Owns: the internal-audit plan and finding record — a process artefact; an Audit Finding entity is an open extension, shared in shape with the control-finding question in SD-14.7.

Standards

  • The IIA Global Internal Audit Standards (2024) and the IIA’s definition of internal audit.
  • The Three Lines Model — internal audit as the third line.
  • The audit-committee governance requirements of the applicable governance code.

Open extensions

  • An Audit Finding entity.
  • The risk-based audit-planning sub-model.
  • The Service-Operation-level input/output contracts.

Built from open-investment-model v0.3.0 · f7452ad