AUI1601 is a first-level internal auditing module offered in the UNISA BCom Internal Auditing and related qualifications. It introduces the core concepts, professional standards and basic techniques used by internal auditors in South Africa and globally. These exam notes provide structured, in‑depth guidance aligned with typical AUI1601 UNISA exam questions, and are equally useful as revision material for similar introductory courses at other South African universities (for example, CUT BCom Internal Auditing, UJ Internal Auditing, and NWU Internal Auditing modules).
The focus is on understanding what internal auditing is, the purpose and scope of the profession, how it functions within organisations (especially in relation to risk management, internal control and corporate governance), and the key principles contained in the International Professional Practices Framework (IPPF). Concepts are explained in a practical exam‑oriented way, with examples and tips that reflect common question styles seen in UNISA AUI1601 past papers and assignments.
1. Overview of Internal Auditing and the AUI1601 Context
1.1 What Is Internal Auditing? (Exam‑Level Definition)
You must be able to define internal auditing almost word‑for‑word as set out by the Institute of Internal Auditors (IIA). The current widely‑used definition is:
Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organisation’s operations. It helps an organisation accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control and governance processes.
Key terms in this definition that you should highlight in exams:
- Independent – free from undue influence so that internal auditors can act objectively.
- Objective – unbiased attitude; professional judgement based on evidence.
- Assurance and consulting – two main service types internal audit provides.
- Add value and improve – internal audit is not only about finding faults, but also about improvement.
- Systematic, disciplined approach – use of structured methodologies and standards.
- Risk management, control and governance – the three core areas internal auditors evaluate.
A typical AUI1601 question may ask: “Explain the key elements of the IIA’s definition of internal auditing and discuss how they apply in a listed South African company.” You must both state the definition and explain each keyword in context.
1.2 Purpose and Objectives of Internal Auditing
Internal auditing exists to support the organisation in achieving its objectives. This is done through:
-
Providing independent assurance to the board, audit committee and management regarding:
- Adequacy and effectiveness of internal controls.
- Effectiveness of risk management.
- Appropriateness of governance processes.
-
Providing consulting services that help management improve processes, systems and controls without assuming management’s responsibilities.
Typical exam tasks:
- “List and explain the main objectives of internal auditing.”
- “Provide three assurance services and three consulting services internal audit can offer to management.”
You must clearly link objectives to the organisation’s strategy and performance. Internal audit is not an isolated function; it is an integral part of the governance and risk management structure.
1.3 Internal Auditing vs External Auditing
A common AUI1601 UNISA exam question is to compare internal and external auditing in table or paragraph form. You should understand at least the following differences:
| Aspect | Internal Auditing | External Auditing |
|---|---|---|
| Objective | Add value, improve operations, evaluate RM, control, governance | Express an opinion on the fair presentation of financial statements |
| Primary user of reports | Board, audit committee, management | Shareholders, regulators, general public |
| Employment | Employees of the organisation (or outsourced internal audit provider) | Independent from the organisation; external audit firm |
| Scope | Broad – operational, financial, compliance, IT, strategic | Primarily financial statements and related controls |
| Frequency | Continuous, risk-based annual plan; engagements throughout year | Usually annual, around financial year‑end |
| Standards | IIA’s IPPF | ISA (International Standards on Auditing) |
Exam tip (UNISA/AUI1601): In questions that ask for a comparison, provide at least five clear points, often rewarded with 1–2 marks each. Always mention the objective, scope, and reporting lines, as these are core differences.
1.4 The Role of Internal Auditing in South African Organisations
In the South African context, internal auditing is strongly influenced by:
- The Companies Act 71 of 2008.
- The King IV Report on Corporate Governance for South Africa.
- Regulatory guidance from the Public Finance Management Act (PFMA) and Municipal Finance Management Act (MFMA) in the public sector.
- Professional guidance from the IIA South Africa.
King IV emphasises that the governing body should ensure effective internal audit. Internal audit plays a key role in:
- Evaluating the design and operating effectiveness of controls.
- Supporting combined assurance models (coordination between internal audit, risk management, compliance, and external assurance providers).
- Providing assurance on governance processes, including ethics, IT governance, and performance information.
Case example (for discussion questions):
A JSE‑listed manufacturing company, Zulu Manufacturing Ltd, implements a new enterprise resource planning (ERP) system. The internal audit function:
- Reviews project governance.
- Evaluates change management controls.
- Tests access security and segregation of duties.
- Reports risks and control weaknesses to the audit committee.
In exams, use such scenarios to show practical application of internal auditing to technology, operations and compliance.
1.5 AUI1601 at UNISA and Similar SA Modules
AUI1601: Introduction to Internal Auditing (UNISA) typically covers:
- Nature and purpose of internal auditing.
- Role of internal auditing in risk management and governance.
- IIA Code of Ethics and the Attribute and Performance Standards.
- Internal audit function organisation (charter, independence, responsibilities).
- The internal audit process (planning, fieldwork, reporting, follow‑up).
- Basics of internal control concepts and risk.
Similar modules in South African universities like Central University of Technology (CUT), University of Johannesburg (UJ), Tshwane University of Technology (TUT) and North‑West University (NWU) may be titled:
- “Introduction to Internal Auditing”
- “Foundations of Internal Auditing”
- “Internal Auditing 1A / 1B”
These often use similar content and the same IIA framework, so these notes are also relevant for CUT Internal Auditing 1 study notes or UJ Internal Auditing 101 exam preparation.
2. Professional Framework: IPPF, Code of Ethics and Standards
2.1 The IIA and the International Professional Practices Framework (IPPF)
The Institute of Internal Auditors (IIA) is the global professional body for internal auditors. It developed the International Professional Practices Framework (IPPF), which provides authoritative guidance for internal auditing worldwide.
For AUI1601 exams, you must know the main components of the IPPF:
-
Mandatory Guidance
- Core Principles for the Professional Practice of Internal Auditing
- Definition of Internal Auditing
- Code of Ethics
- International Standards for the Professional Practice of Internal Auditing (the Standards)
-
Recommended (Supplemental) Guidance
- Implementation Guides
- Practice Guides
- Position Papers
- Practice Advisories (in older material)
UNISA AUI1601 questions often ask you to distinguish between mandatory and recommended guidance, or to explain why conformance with the Standards is important.
2.2 IIA Code of Ethics
The Code of Ethics sets minimum requirements for the behaviour and conduct of internal auditors. It consists of:
- Principles
- Rules of Conduct
2.2.1 Principles
The four principles are:
-
Integrity
- The integrity of internal auditors establishes trust and thus provides the basis for reliance on their judgement.
-
Objectivity
- Internal auditors exhibit the highest level of professional objectivity in gathering, evaluating and communicating information.
-
Confidentiality
- Internal auditors respect the value and ownership of information they receive and do not disclose information without appropriate authority unless legally obliged to do so.
-
Competency
- Internal auditors apply the knowledge, skills and experience needed in the performance of internal audit services.
Exam application: A scenario may describe an internal auditor accepting lavish gifts from a supplier. You must explain that this threatens objectivity and possibly integrity, thus violating the Code of Ethics.
2.2.2 Rules of Conduct
For each principle, there are rules of conduct which describe behavioural norms. Typical examples:
-
Under Integrity:
- Perform work with honesty, diligence and responsibility.
- Do not knowingly be a party to illegal activities.
-
Under Objectivity:
- Do not participate in activities that may impair unbiased assessment.
- Disclose all material facts that, if not disclosed, may distort reporting.
-
Under Confidentiality:
- Be prudent in the use and protection of information.
- Do not use information for personal gain.
-
Under Competency:
- Engage only in services for which you have the necessary knowledge, skills and experience.
- Continually improve proficiency and quality.
AUI1601 style question: “Identify and discuss four principles of the IIA Code of Ethics and provide one example of a behavioural requirement for each principle.”
2.3 The Core Principles for the Professional Practice of Internal Auditing
Core Principles describe what makes internal audit effective. Commonly examined principles include:
- Demonstrates integrity.
- Demonstrates competence and due professional care.
- Is objective and free from undue influence (independent).
- Aligns with the strategies, objectives and risks of the organisation.
- Is appropriately positioned and adequately resourced.
- Demonstrates quality and continuous improvement.
- Communicates effectively.
- Provides risk‑based assurance.
- Is insightful, proactive and future‑focused.
- Promotes organisational improvement.
In an exam, you might be asked: “Explain any five Core Principles for an effective internal audit function and relate them to the UNISA AUI1601 framework of internal auditing.” Use concise explanations and simple examples.
2.4 International Standards for the Professional Practice of Internal Auditing
The Standards are divided into:
- Attribute Standards (1000–1321) – address the attributes of organisations and individuals performing internal auditing.
- Performance Standards (2000–2600) – describe the nature of internal auditing and provide quality criteria.
- Implementation Standards – apply to specific types of engagements (assurance vs consulting).
2.4.1 Attribute Standards
Important Attribute Standards for AUI1601:
-
1000 – Purpose, Authority and Responsibility
- Must be formally defined in an internal audit charter.
- Charter must be consistent with the Definition, Code of Ethics and Standards.
- Approved by the board (often via audit committee).
-
1100 – Independence and Objectivity
- Internal audit must be independent; internal auditors must be objective.
- 1110 – Organisational Independence: Chief audit executive (CAE) must report functionally to the board.
- 1130 – Impairment to Independence or Objectivity: Must be disclosed if they occur.
-
1200 – Proficiency and Due Professional Care
- Internal auditors must possess the knowledge, skills and other competencies.
- Must apply the care and skill expected of a reasonably prudent and competent internal auditor.
-
1300 – Quality Assurance and Improvement Programme (QAIP)
- CAE must develop and maintain a QAIP.
- Includes internal assessments (ongoing and periodic) and external assessments (usually every five years).
UNISA often examines 1100–1130 in questions that require explanation of independence and objectivity in a case study context.
2.4.2 Performance Standards
Key Performance Standards include:
-
2000 – Managing the Internal Audit Activity
- CAE must manage the internal audit activity to ensure it adds value.
- Includes risk‑based planning, resource management and coordination.
-
2100 – Nature of Work
- Internal audit must evaluate and contribute to:
- Risk management (2110)
- Control (2120)
- Governance (2130)
- Internal audit must evaluate and contribute to:
-
2200 – Engagement Planning
- Internal auditors must develop and document a plan for each engagement.
-
2300 – Performing the Engagement
- Identify, analyse, evaluate and document information.
-
2400 – Communicating Results
- Internal auditors must communicate results of engagements.
-
2500 – Monitoring Progress
- CAE must establish follow‑up processes.
-
2600 – Communicating the Acceptance of Risks
- CAE must discuss with senior management when management accepts risk that is unacceptable.
Exam example: A question may ask you to “Describe the main requirements of Standard 2000 relating to the management of the internal audit activity” and apply them to a specific organisation.
2.5 Mandatory vs Recommended IPPF Guidance
You must distinguish between:
-
Mandatory guidance – conformance is required:
- Definition of Internal Auditing.
- Code of Ethics.
- Standards.
- Core Principles.
-
Recommended guidance – not mandatory but strongly recommended:
- Implementation Guides (explain Standards).
- Practice Guides (detailed guidance on specific topics).
- Position Papers (broad views on governance, risk and control topics).
AUI1601 exam hint: When asked why mandatory guidance is important, emphasise that:
- It supports consistency and quality across the profession.
- It enhances credibility and trust in internal audit findings.
- It provides a benchmark for internal and external quality assessments.
3. Organisation of the Internal Audit Function
3.1 Internal Audit Charter
The internal audit charter is a formal document that:
- Defines the purpose, authority and responsibility of the internal audit activity.
- Establishes the internal audit’s position within the organisation.
- Authorises access to records, personnel and physical properties relevant to engagements.
- Sets out the internal audit function’s accountability to the board and management.
Typical contents of a charter (often examined):
- Mission and objectives of internal audit.
- Reference to the IIA definition, Code of Ethics and Standards.
- Scope of internal audit activities (assurance and consulting).
- Organisational independence and reporting lines.
- Rights of access.
- Responsibilities of the CAE and internal auditors.
- Relationship with the external auditor and other assurance providers.
- Requirements for a risk‑based internal audit plan.
In exam questions, you may be required to draft key clauses of a charter for a fictional company, such as “Amahlathi Retail (Pty) Ltd”.
3.2 Independence and Objectivity in Practice
3.2.1 Organisational Independence
To maintain independence, internal audit should:
- Report functionally to the audit committee/board.
- Report administratively to the CEO or another senior executive (e.g., CFO) for day‑to‑day matters like budgeting and HR.
Functional reporting typically includes:
- Approving the internal audit charter.
- Approving the risk‑based internal audit plan.
- Receiving communications from the CAE on internal audit performance.
- Approving appointment or removal of the CAE.
- Making inquiries into any scope or resource limitations.
UNISA AUI1601 common question: “Explain how the organisational independence of the internal audit activity can be ensured in a medium‑sized South African company.”
3.2.2 Individual Objectivity
Internal auditors must avoid situations where they:
- Audit areas where they have operational responsibility or personal interest.
- Have close family or financial relationships with auditees.
- Have participated directly in the design or implementation of systems they later audit.
If objectivity is impaired or may be perceived to be impaired, it must be disclosed to appropriate parties (e.g., CAE, audit committee).
Example (exam case):
- An internal auditor who previously worked in the payroll department is asked to audit payroll controls within six months of transferring to internal audit. This may impair objectivity. The CAE should assign another auditor or take steps to mitigate the risk.
3.3 Position of Internal Auditing in the Organisation
Internal auditing is part of the organisation’s governance structure and often considered the third line in the Three Lines Model (previously Three Lines of Defence):
- First line – Management and operational staff who own and manage risk.
- Second line – Risk management, compliance and other oversight functions.
- Third line – Internal audit, providing independent assurance on the effectiveness of governance, risk management and internal controls.
Internal audit must coordinate with:
- Risk management functions – to understand the risk universe, risk appetite and risk registers.
- Compliance units – to avoid duplication and share findings.
- External auditors – to support combined assurance and avoid overlapping work.
3.4 Skills and Competencies of Internal Auditors
Internal auditors need a combination of technical and soft skills. Common exam focus areas:
-
Technical competencies:
- Knowledge of accounting and finance.
- Understanding of risk management and internal control frameworks.
- Familiarity with information systems and IT controls.
- Data analytics and sampling techniques.
- Knowledge of relevant laws and regulations (e.g., Companies Act, PFMA).
-
Soft skills:
- Communication (written and oral).
- Interpersonal skills and teamwork.
- Critical thinking and problem‑solving.
- Professional scepticism.
- Time management and project management.
UNISA BCom Internal Auditing students are expected to demonstrate awareness that internal auditing is not only about auditing financial numbers, but also about behaviour, ethics and organisational culture.
3.5 Sourcing of the Internal Audit Function
Organisations can structure their internal audit activity in different ways:
-
In‑house internal audit activity
- Internal auditors are employees.
- Better knowledge of the organisation.
- Potential cost‑effectiveness over the long term.
-
Outsourced internal audit activity
- External provider (e.g., a professional services firm) delivers internal audit services.
- Access to specialist skills and methodologies.
- Must still comply with IIA Standards; independence and conflicts of interest must be managed.
-
Co‑sourced internal audit
- Combination of in‑house staff and external specialists.
- Common for IT audits or complex risk areas (e.g., derivatives, cybersecurity).
In an exam, you may be asked: “Discuss the advantages and disadvantages of outsourcing the internal audit function in a South African municipality.”
3.6 Quality Assurance and Improvement Programme (QAIP)
Standard 1300 requires a QAIP consisting of:
-
Ongoing internal assessments:
- Supervision and review of engagements.
- Feedback from audit clients.
- Key performance indicators (e.g., plan completion rate).
-
Periodic internal assessments:
- Self‑assessments or peer reviews within the organisation.
-
External assessments:
- Conducted at least once every five years by a qualified, independent assessor.
- Assesses conformance with the Standards and Code of Ethics.
In exams, emphasise that QAIP helps:
- Demonstrate conformance with the Standards.
- Identify improvement opportunities.
- Enhance the credibility of internal audit.
4. Risk Management, Internal Control and Corporate Governance
4.1 Risk and Risk Management: Basic Concepts
Risk is the possibility that an event will occur and adversely affect the achievement of objectives. Risk has two main dimensions:
- Likelihood – probability of occurrence.
- Impact – potential effect on objectives (financial, operational, reputational, compliance).
Risk management is a structured process used by management to:
- Identify potential events.
- Assess risks (inherent and residual).
- Decide on risk responses.
- Monitor and report on risks.
Internal audit does not own risk management; management does. Internal audit’s role is to evaluate and provide assurance on the effectiveness of risk management.
4.2 Types of Risk (Common in AUI1601 Questions)
You should be able to classify risk into:
- Strategic risk – related to high‑level goals and strategies (e.g., failure to adapt to new technology).
- Operational risk – related to day‑to‑day operations (e.g., breakdown of machinery, poor quality).
- Financial risk – related to financial management (e.g., liquidity, credit risk, interest rate risk).
- Compliance risk – arising from failure to comply with laws and regulations (e.g., tax non‑compliance).
- Reputational risk – negative public perception, loss of stakeholder trust.
- Information technology risk – cyber‑attacks, data loss, system failures.
A frequent exam question: “Identify and describe four types of risk relevant to a university such as UNISA or CUT.”
4.3 The Role of Internal Audit in Risk Management
Standard 2110 states that internal audit must evaluate the effectiveness and contribute to the improvement of risk management processes. Key activities include:
-
Assess whether:
- Organisational objectives support and align with mission.
- Significant risks are identified and assessed.
- Appropriate risk responses are selected.
- Relevant risk information is captured and communicated.
-
Provide assurance on:
- Risk identification processes.
- Risk assessment methodologies.
- Risk mitigation controls.
-
Provide consulting services, such as:
- Facilitating risk workshops.
- Advising on the development of risk registers.
- Participating (in an advisory role) in risk committees.
Important limitation: Internal audit must not assume management’s responsibility for risk management decisions, as this would compromise independence.
4.4 Internal Control: Concepts and Components
Internal control is a process, effected by the board, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in:
- Efficiency and effectiveness of operations.
- Reliability of financial reporting.
- Compliance with applicable laws and regulations.
A widely used framework is the COSO Internal Control – Integrated Framework, with five components:
-
Control Environment
- Tone at the top, ethical values, governance, organisational structure, HR policies.
-
Risk Assessment
- Identification and analysis of risks relevant to achieving objectives.
-
Control Activities
- Policies and procedures to ensure risk responses are properly carried out (e.g., authorisations, reconciliations, segregation of duties, physical controls).
-
Information and Communication
- Information systems, communication channels, reporting lines.
-
Monitoring Activities
- Ongoing or separate evaluations of the internal control system.
4.5 Types of Internal Controls
Internal controls can be categorised as:
-
Preventive controls
- Prevent errors or irregularities before they occur.
- Examples: authorisation of transactions, segregation of duties, access controls.
-
Detective controls
- Detect errors or irregularities after they occur.
- Examples: reconciliations, reviews of exception reports, internal audit checks.
-
Corrective controls
- Correct identified errors or irregularities.
- Examples: backup and recovery procedures, disciplinary actions, process improvement.
For AUI1601 exams, you should be able to identify control weaknesses in a scenario and recommend appropriate preventive, detective or corrective controls.
4.6 Internal Audit’s Role in Evaluating Internal Controls
Standard 2120 requires internal audit to evaluate the adequacy and effectiveness of controls in responding to risks. Internal auditors:
- Understand the processes and objectives.
- Identify key risks.
- Determine key controls addressing those risks.
- Evaluate design effectiveness (if controls are properly designed to address risks).
- Test operating effectiveness (if controls are working as intended).
Example (UNISA‑type case):
In the cash receipts process of a retail chain:
- Risks: theft of cash, recording errors, non‑banking of cash.
- Controls:
- Segregation of duties: cashier, supervisor, accountant.
- Daily bank reconciliations.
- Prenumbered receipts.
- CCTV surveillance.
You may be asked to list risks, identify existing controls, evaluate control effectiveness and suggest improvements.
4.7 Corporate Governance and Internal Auditing
Corporate governance refers to the system of rules, practices and processes by which a company is directed and controlled. In South Africa, King IV is the leading guidance.
Internal audit supports governance by:
- Providing assurance to the board and audit committee.
- Reviewing the governance processes regarding:
- Ethics and organisational culture.
- Performance management and reporting.
- IT governance.
- Compliance with laws and regulations.
The audit committee plays a crucial role:
- Oversees the internal audit function.
- Approves the internal audit plan.
- Reviews internal audit reports and recommendations.
- Assesses independence and objectivity of internal audit.
Typical exam question: “Explain the role of the audit committee in supporting an effective internal audit function in accordance with King IV and the IIA Standards.”
4.8 Combined Assurance
Combined assurance is an approach where the various assurance providers in an organisation coordinate their activities to avoid duplication and ensure comprehensive coverage over key risks. Examples of assurance providers:
- Management (first line).
- Risk management and compliance (second line).
- Internal audit (third line).
- External audit and other external assurance providers (e.g., environmental auditors, safety inspectors).
Internal audit often helps in:
- Mapping assurance coverage over identified risks.
- Identifying gaps or overlaps.
- Reporting a consolidated view to the audit committee.
Understanding combined assurance is important for AUI1601 as it links internal audit’s work to broader governance structures.
5. The Internal Audit Process: From Planning to Follow‑Up
5.1 Overview of the Internal Audit Process
The internal audit process can be summarised in four major phases:
-
Planning
- Strategic and annual planning (risk‑based).
- Engagement‑level planning.
-
Fieldwork (Execution)
- Gathering and evaluating evidence.
-
Reporting
- Communicating findings, conclusions and recommendations.
-
Follow‑up
- Monitoring implementation of agreed actions.
For AUI1601 at UNISA, you must understand each phase in enough detail to describe the steps, purpose, and outputs.
5.2 Risk‑Based Internal Audit Planning
The CAE prepares an annual internal audit plan that is:
- Based on the organisation’s risk universe.
- Linked to strategic and operational objectives.
- Aligned with the risk appetite and risk assessment conducted by management.
Key steps:
-
Obtain organisation‑wide information:
- Strategic plan, budgets, organisation charts.
- Risk registers and risk reports.
- Previous internal and external audit reports.
-
Identify the audit universe:
- All potential audit areas (processes, business units, systems, projects).
-
Assess risk levels for each audit area:
- Impact and likelihood, considering inherent and residual risk.
- Use of risk ratings (e.g., High, Medium, Low) or numerical scores.
-
Prioritise engagements:
- Focus on high‑risk areas.
- Consider regulatory requirements (e.g., PFMA).
- Include follow‑up and ad hoc work.
-
Develop the annual plan:
- List of planned audits, timing and resource allocation.
- Present to senior management and audit committee for approval.
Exam example: “Explain the concept of a risk‑based internal audit plan and describe the steps involved in developing such a plan for a public‑sector entity.”
5.3 Engagement‑Level Planning
For each internal audit engagement, Standard 2200 requires proper planning. Common steps:
-
Understand the business process or area
- Review policies, procedures, organisation charts and process maps.
- Meet with process owners.
-
Define engagement objectives
- E.g., to evaluate the effectiveness of controls over payroll processing.
-
Define scope
- Processes, locations, time period, systems to be covered.
-
Identify risks and control objectives
- E.g., risk of unauthorised payments, risk of miscalculated salaries.
-
Develop audit programme
- Detailed procedures and tests to be performed.
- Sampling approaches, data analysis techniques.
-
Allocate resources and time
- Assign team members and define timelines.
The main planning document is usually an engagement work programme and/or planning memo.
5.4 Gathering Audit Evidence (Fieldwork)
During fieldwork, internal auditors collect sufficient, reliable, relevant and useful evidence to support their findings. Common evidence‑gathering techniques:
-
Inquiry
- Asking questions of staff and management.
- Must be corroborated by other evidence.
-
Observation
- Watching processes being performed (e.g., stock counts).
-
Inspection
- Examining documents and records (e.g., invoices, contracts, policies).
-
Reperformance
- Independently executing procedures to verify results (e.g., recalculating interest).
-
Analytical procedures
- Analysing relationships and trends (e.g., comparing ratios, benchmarking).
-
Computer‑assisted audit techniques (CAATs)
- Using software tools to extract and analyse large data sets.
Documentation of evidence is critical:
- Working papers should clearly document:
- Procedures performed.
- Evidence obtained.
- Conclusions reached.
- Working papers must be:
- Complete, accurate, and understandable.
- Properly indexed and cross‑referenced.
- Stored securely and confidentially.
UNISA AUI1601 often requires students to list and explain at least four evidence‑gathering techniques with examples.
5.5 Sampling and Testing
When it is not possible or efficient to examine all items in a population, internal auditors use sampling. Two main types:
-
Statistical sampling
- Uses probability theory.
- Allows quantification of sampling risk.
-
Non‑statistical (judgemental) sampling
- Based on auditor judgement.
- No formal quantification of sampling risk, but commonly used in practice.
Typical sampling approaches used in internal audit:
- Random sampling.
- Systematic sampling.
- Haphazard sampling.
- Stratified sampling.
In AUI1601, the emphasis is on understanding the concept of sampling, not on advanced statistical formulas. You may be asked: “Explain why internal auditors use sampling techniques and distinguish between statistical and judgemental sampling.”
5.6 Developing Findings and Recommendations
An internal audit finding generally consists of four elements (sometimes called condition, criteria, cause, effect):
-
Condition
- What actually exists? (e.g., “Three out of twenty invoices tested were not authorised.”)
-
Criteria
- What should exist? (e.g., company policy requiring authorisation of all invoices > R5 000.)
-
Cause
- Why is there a deviation? (e.g., staff shortages, inadequate training, unclear policies.)
-
Effect
- What is the consequence or potential risk? (e.g., increased risk of unauthorised or fraudulent payments.)
Recommendations should be:
- Specific
- Practical
- Prioritised according to risk
- Agreed with management where possible
Example of a good recommendation:
“It is recommended that the Chief Financial Officer ensure that system‑based workflow controls are implemented in the accounts payable module so that invoices above R5 000 cannot be processed without electronic approval by an authorised manager.”
5.7 Communicating Results (Reporting)
Standard 2400 covers communication. Internal audit reports can be:
- Formal written reports
- Addressed to management and audit committee.
- Interim communications
- For urgent or significant matters.
A typical internal audit report structure:
- Title and reference.
- Addressee (e.g., CFO, Audit Committee).
- Executive summary:
- Objectives and scope.
- Overall opinion or conclusion.
- Summary of key findings.
- Background:
- Brief description of area audited.
- Objectives and scope:
- Period covered, locations, systems.
- Methodology:
- Key procedures and sampling methods.
- Detailed findings and recommendations:
- Each finding with condition, criteria, cause, effect and agreed management action.
- Priority rating (e.g., High/Medium/Low).
- Conclusion and overall evaluation.
- Acknowledgement of cooperation.
- Signature of CAE.
Qualities of good reporting:
- Clear and concise.
- Factual and objective.
- Balanced (strengths and weaknesses).
- Timely.
In AUI1601, you might be asked to draft a short internal audit report based on a scenario, or to identify weaknesses in a sample report.
5.8 Follow‑Up and Monitoring
Standard 2500 requires internal auditors to monitor progress on management’s agreed actions. The follow‑up process:
- Maintain a register of all audit findings and recommendations.
- Track target completion dates.
- Obtain evidence that actions have been implemented (e.g., updated policies, system changes).
- Test the effectiveness of implemented actions where necessary.
- Report status of outstanding issues to management and audit committee.
If management decides to accept a risk that internal audit believes is unacceptable, Standard 2600 requires the CAE to:
- Discuss the matter with senior management.
- If resolution is not reached, communicate the matter to the board or audit committee.
This ensures transparency about risk acceptance decisions.
6. Typical AUI1601 Exam Focus Areas and Application Scenarios
6.1 Common Question Types in UNISA AUI1601
Based on typical UNISA AUI1601 exam papers and assignments, you can expect:
-
Definitions and explanation questions
- Define internal auditing, risk, internal control, corporate governance.
- Explain key terms: independence, objectivity, assurance, consulting.
-
Theory application questions
- Apply the Code of Ethics to an ethical dilemma.
- Evaluate independence and objectivity in a scenario.
-
Short case studies
- Identify risks and recommend controls.
- Analyse whether the internal audit activity complies with Standards.
-
List and describe questions
- List five responsibilities of internal audit.
- Describe components of internal control.
-
Compare and contrast questions
- Internal vs external audit.
- Assurance vs consulting engagements.
-
Drafting/constructing documents
- Draft parts of an internal audit charter.
- Draft key sections of an internal audit report.
6.2 Example Scenario: Retail Cash Handling (Integrated Question)
Scenario summary:
Makonde Stores (Pty) Ltd operates several retail outlets in Gauteng. Internal audit reviews the cash handling process at the Pretoria branch and notes:
- Cashiers both receive cash and prepare the daily cash‑up.
- The branch manager occasionally borrows small amounts of cash from the till, promising to repay later.
- Bank deposits do not always agree to the cash‑up summaries; differences are posted to “cash shortages” without investigation.
- There is no CCTV in cash handling areas.
- Cash sales appear lower than expected compared to similar branches.
Possible exam tasks:
- Identify at least five risks arising from the above weaknesses.
- Classify each risk as operational, financial or compliance.
- Recommend preventive and detective controls to address each risk.
- Explain how internal audit should communicate these findings to management.
Illustrative answer points:
-
Risks:
- Misappropriation (theft) of cash by cashiers or manager. (Financial, operational)
- Inaccurate financial records. (Financial)
- Non‑compliance with company policies on cash handling. (Compliance)
- Reputational damage if losses become public. (Reputational)
- Increased audit findings and possible disciplinary action. (Operational, reputational)
-
Controls:
- Segregation of duties (cashiers vs cash‑up vs deposit preparation).
- Prohibition of personal borrowing from tills; disciplinary measures.
- Daily reconciliation of cash‑up to deposit slip; investigation of differences.
- CCTV surveillance and physical security measures.
- Surprise cash counts by internal audit or management.
Such scenarios test understanding of risk, control and audit evidence, all core to AUI1601.
6.3 Example Scenario: Ethics and Independence (Code of Ethics Application)
Scenario summary:
Sindi, an internal auditor at Vaal Water Authority, is assigned to audit the procurement function. Her brother owns one of the suppliers that recently won a major tender. Sindi previously worked in the procurement department and helped design the current procurement procedures.
Possible exam tasks:
- Identify and explain any ethical issues.
- State which principles of the Code of Ethics are at risk.
- Recommend actions the CAE should take to preserve objectivity and independence.
Illustrative answer points:
-
Ethical issues:
- Threat to objectivity because of close family relationship with a supplier.
- Self‑review threat because Sindi previously designed procurement procedures now being audited.
-
Principles affected:
- Objectivity – risk of biased judgement.
- Integrity – if she does not disclose this conflict.
- Competency in terms of proper professional conduct.
-
Actions:
- Sindi must disclose the relationship and previous involvement.
- CAE should reassign her to another engagement or limit her role.
- CAE should ensure the audit team includes members with no conflicts.
These case‑style questions examine your ability to apply the Code of Ethics to realistic internal audit issues.
6.4 Example Scenario: Internal Audit Charter and Reporting Lines
Scenario summary:
At Eastern Cape Logistics Ltd, the internal audit function reports administratively and functionally to the Finance Manager. The Finance Manager also determines the internal audit plan and can overrule internal audit findings before they are presented to the board. There is no written internal audit charter.
Exam tasks:
- Identify and explain the problems with this arrangement from a Standards perspective.
- Suggest how the organisation should restructure internal audit reporting.
- Outline key elements that should be included in an internal audit charter.
Illustrative answer points:
-
Problems:
- Violates Standard 1110 – Organisational Independence: CAE should report functionally to the board or audit committee, not to management.
- Finance Manager’s control over plan and findings creates undue influence, threatening independence and objectivity.
- Absence of charter breaches Standard 1000 – Purpose, Authority and Responsibility.
-
Restructure:
- Internal audit should report functionally to the audit committee of the board.
- Administrative reporting can still be to the CEO or another executive, but without interference in audit judgments.
-
Charter elements:
- Purpose aligned with IIA definition.
- Scope of activities.
- Independence and authority for unrestricted access.
- Responsibilities of internal audit and CAE.
- Relationship with management and audit committee.
Questions like this interlink IPPF Standards with practical governance structures.
6.5 Study Strategy Tips for AUI1601 (UNISA Focus)
-
Know key definitions:
- Internal auditing.
- Risk, internal control, governance.
- Independence and objectivity.
-
Memorise key structures:
- Components of internal control.
- Attribute vs Performance Standards.
- Four elements of a finding (condition, criteria, cause, effect).
-
Practise applying theory:
- Use past papers and tutorial letters.
- Work through short scenarios and identify:
- Risks.
- Control weaknesses.
- Possible audit procedures.
- Ethical issues.
-
Use headings and bullet points in answers:
- Examiners often allocate marks per valid point.
- Answer concisely but fully, avoiding vague statements.
-
Link to South African context:
- Mention King IV, PFMA, MFMA where relevant.
- Use examples from local organisations (e.g., municipalities, state‑owned enterprises, listed companies).
-
Cross‑reference content areas:
- Ethics questions often link to independence and objectivity.
- Risk questions often link to internal control and audit planning.
- Governance questions often link to audit committee and combined assurance.
7. Summary of Key Concepts for Quick Revision
-
Internal auditing is an independent, objective assurance and consulting activity that adds value and improves an organisation’s operations by evaluating and improving risk management, control and governance processes.
-
The IPPF provides global guidance:
- Mandatory: Definition, Code of Ethics, Standards, Core Principles.
- Recommended: Implementation Guides, Practice Guides, etc.
-
The Code of Ethics has four principles:
- Integrity.
- Objectivity.
- Confidentiality.
- Competency.
-
The Standards:
- Attribute Standards (1000–1321): purpose, independence, proficiency, QAIP.
- Performance Standards (2000–2600): managing the internal audit activity, nature of work, engagement performance, communicating results, monitoring progress.
-
The internal audit charter formally defines purpose, authority and responsibility; must be approved by the board/audit committee.
-
Independence (organisational) and objectivity (individual) are crucial for credibility.
-
Internal audit’s role in risk management:
- Evaluate and improve risk identification, assessment and mitigation processes.
- Provide assurance, not management of risk.
-
Internal control:
- A process to provide reasonable assurance regarding operations, reporting and compliance.
- Components: control environment, risk assessment, control activities, information & communication, monitoring.
-
Internal auditing supports corporate governance:
- Assists board and audit committee.
- Participates in combined assurance.
-
The internal audit process:
- Risk‑based planning.
- Engagement‑level planning.
- Fieldwork and evidence collection.
- Reporting findings and recommendations.
- Follow‑up and monitoring.
-
Typical AUI1601 exam questions:
- Definitions and short explanations.
- Application of Code of Ethics in scenarios.
- Comparison of internal vs external audit.
- Risk and control identification.
- Drafting parts of charters and reports.
Thorough understanding of these concepts, combined with practice on scenario‑based questions, will position UNISA BCom Internal Auditing students – and students in similar modules at CUT, UJ, TUT, NWU and other South African universities – to perform strongly in AUI1601: Introduction to Internal Auditing and to build a solid foundation for advanced internal auditing studies.
