Policy and regulatory analysis

Governance and public reporting in relation to internal audit

Industry Policy and Regional Regulatory Interpretation

Governance and public reporting in relation to internal audit — legal effect, institutional responsibility, learner safeguards and jurisdictional limits.

Review of the arrangements should address both system-level conditions and institutional practice. For internal audit, governing bodies should receive sufficient, reliable and timely information to oversee education quality, learner protection and material institutional risk.

Application of the evidence to governance and public reporting in relation to internal audit

Useful records include public reports reconciled with controlled records, defined delegations and reserved decisions, risk and assurance plans, governing-body papers and decisions, and corrective-action verification.

It does not, without setting-specific evidence, demonstrate the operation of the issue. When examining internal audit, reporting should preserve the different status of facts, public expectations and choices made by institutions.

For internal audit, public information should be accurate, current, complete in relation to material matters and presented before a learner is required to make a consequential commitment. Qualifications and limitations should receive comparable prominence to the principal claim.

The principal risks in relation to the arrangements are governing bodies receiving activity data instead of outcome evidence, corrective action closed without verification, management assurance accepted without testing, and material risks omitted from reporting. Across the defined scope, the risks are interdependent; failure of one control may conceal or disable another.

Controls relevant to governance and public reporting in relation to internal audit

Public reporting on internal audit should distinguish established fact, analytical judgement and planned action.

For internal audit, a traceable record enables responsibility to be established and errors to be corrected fairly.

  • Test management assurance before it is relied on for a decision with material effect.
  • Define information required for oversight, identifying the accountable function and affected scope.
  • Separate incompatible responsibilities before it is relied on for a decision with material effect.
  • Assign decision authority explicitly.
  • Verify corrective action independently.

Review criteria for governance and public reporting in relation to internal audit

Review of the policy position should identify material information across the learner journey, assign source ownership, reconcile public statements with controlled records and retain corrections. For internal audit, test whether a reasonable user can understand status, cost, obligations, support and routes for redress. Across the defined scope, the review record should preserve exceptions capable of showing a weakness in design, implementation or coverage.

For internal audit, the implementation record for the issue should identify the instrument being applied, its status, the competent authority, the affected jurisdiction and the action expected of each responsible body. A staged implementation record should set out transition dates, interim safeguards and the readiness review point.

The objective for internal audit should be explicit, the evidence proportionate and learner impact visible. An evidential gap in relation to internal audit should lead to a qualified conclusion and continued action, not administrative closure.