Sets out a controlled approach to monitoring exceptions in internal audit, covering diagnosis, responsible action, outcome evidence and sustained effect.
In 2017, consideration of exceptions in internal audit must take account of the independent assurance within education providers and the responsibilities it places before education systems. Improvement of internal audit should begin with a defined problem, a credible account of its causes and a measure capable of showing whether the response has worked.
Risk assessment should give particular attention to material risks omitted from reporting, conflicts not identified, and corrective action closed without verification. A provider should also consider governing bodies receiving activity data instead of outcome evidence and authority assigned without accountability.
Improvement objective and baseline
A proper review of exceptions in internal audit should establish the intended outcome before selecting controls or indicators. For the matter, effectiveness should be judged against an agreed outcome and reference period, not against completion of activities alone. A chosen approach should be justified against its context, with departures and review points under documented control.
The relevant context is provided by independent assurance within education providers. Its relevance to the intended improvement should be assessed against the affected jurisdiction, learner population and form of provision. In the context of internal audit, the international development warrants attention, but a consequential conclusion still requires current, attributable and representative evidence for the affected scope.
When examining internal audit, the subject should be examined as a connected system of policy, people, resources, decisions and evidence. Transfer points should be tested because responsibility and information may be lost between otherwise sound functions.
- Verify corrective action independently.
- Assign decision authority explicitly, identifying the accountable function and affected scope.
- Define information required for oversight.
- Test management assurance.
- Separate incompatible responsibilities.
Controls and accountable action
Interpretation of exceptions in internal audit should avoid two errors: treating a formal commitment as proof of effect, and treating one adverse case as proof that every part of the system has failed. For the corrective action, governance structures do not provide assurance merely because committees exist. Membership, information quality, challenge, decisions and follow-through determine whether oversight is effective. Correcting an individual record does not establish that the process which produced the error has been corrected.
Relevant evidence for the relevant practice will normally include risk and assurance plans, defined delegations and reserved decisions, independent review records, corrective-action verification, and governing-body papers and decisions. In work concerning internal audit, the conclusion should rely on evidence whose date, source and coverage are sufficient for the decision. Conflicting records require reconciliation before a complete assurance conclusion is reached.
The assurance record for internal audit should retain the date of the evidence, the source responsible for it, the scope examined and the version of any instrument or definition applied. This enables later review to separate substantive change from correction, reclassification or expanded coverage. The evidential history should preserve conclusions that were operative when a material decision was made.
Evidence of effect
Implementation of exceptions in internal audit can be tested without imposing unnecessary reporting. A competent examination of the matter should map the complete process, identify the intended result and responsible authority at each stage, and test normal cases together with exceptions. Review should establish the reach of the condition before determining the corrective response. Existing records may be used if reliable and relevant, but data collected for another purpose may not answer the assurance conclusion.
Improvement of internal audit should proceed through controlled tests where risk permits.
- What action is required by the finding?
- What outcome is intended?
- Who controls each stage?
- Where do exceptions occur?
- Which evidence establishes operation?
Sustaining improvement
The system and institutional dimensions of exceptions in internal audit should be considered together. Governing bodies should receive sufficient, reliable and timely information to oversee education quality, learner protection and material institutional risk. Neither public oversight nor provider control removes the responsibilities assigned to the other level.
For the relevant practice, governing bodies should receive a concise account of the intended result, affected scope, principal risks, evidence limitations and unresolved exceptions. As regards internal audit, closure requires evidence that the condition has changed; completion of planned activity is not sufficient.
The present development should inform review of the corrective action, with attention to the relationship between commitment, implementation and demonstrated outcome. Within the scope under review, institutional improvement and public confidence both depend on transparent responsibility and credible evidence.