AUI2601 is one of the core modules for the UNISA BCom in Internal Auditing and is also widely consulted by students at other South African universities such as CUT (Central University of Technology) and NWU (North-West University) who take equivalent modules like IADP511 Internal Auditing Principles or AUI1511 Internal Auditing Fundamentals. These notes focus on the theory and principles underlying the internal auditing profession, aligned to the International Professional Practices Framework (IPPF) and South African corporate governance context (especially King IV). The emphasis is on exam-focused understanding, integration of theory with practice, and the ability to answer application-style questions.
1. Overview of Internal Auditing and the IPPF (AUI2601, UNISA BCom Internal Auditing)
1.1 Definition, Purpose and Scope of Internal Auditing
The core starting point of AUI2601 is the official definition of internal auditing issued by The Institute of Internal Auditors (IIA):
Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organisation’s operations. It helps an organisation accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control and governance processes.
Break this down for exams:
-
Independent and objective
- Independence: Freedom from conditions that threaten the ability to carry out internal audit responsibilities in an unbiased manner.
- Objectivity: Unbiased mental attitude that allows internal auditors to perform engagements in a manner that they believe in their work product and that no quality compromises are made.
-
Assurance and consulting activity
- Assurance: Objective examination of evidence for the purpose of providing an independent assessment on risk management, control, or governance processes.
- Consulting: Advisory and related client service activities, the nature and scope of which are agreed with the client, and are intended to add value and improve governance, risk management and control without the internal auditor assuming management responsibility.
-
Add value and improve operations
Internal auditing should not only identify weaknesses but also propose improvements. It is forward-looking and value-adding, not only compliance-based. -
Systematic, disciplined approach
Internal auditors use structured methodologies (planning, fieldwork, testing, evaluation, reporting, follow‑up) and professional standards. -
Focus on risk management, control, and governance
These three pillars appear repeatedly in AUI2601 exam papers. Any question on the “role of internal audit” must link back to:- Risk management: identifying, assessing and responding to risks.
- Control: policies, procedures and activities aimed at achieving objectives.
- Governance: structures and processes used to direct and control the organisation.
Scope of internal auditing (commonly examined):
- Operational audits (efficiency and effectiveness of operations).
- Compliance audits (adherence to laws, regulations, internal policies).
- Financial audits (reliability and integrity of financial and operational information).
- Information systems audits.
- Performance audits (economy, efficiency and effectiveness).
- For public sector: audits related to PFMA/MFMA compliance and performance information.
AUI2601 typically expects application: For example, if UNISA sets a question on a manufacturing company that has high inventory losses, you must show how an internal auditor would systematically evaluate inventory controls and link each step to risk, control and governance.
1.2 The International Professional Practices Framework (IPPF)
The IPPF is the global framework that organises the authoritative guidance for the internal auditing profession. For AUI2601, students must understand:
- The components of the IPPF.
- The difference between mandatory and recommended guidance.
- How these influence internal audit practice in South Africa (including UNISA’s focus on King IV).
The IPPF consists of:
A. Mandatory Guidance (must be applied)
-
Core Principles for the Professional Practice of Internal Auditing
These are 10 principles that describe an effective internal audit function. They are not listed as a Standard, but are mandatory. They include:- Demonstrates integrity.
- Demonstrates competence and due professional care.
- Is objective and free from undue influence (independent).
- Aligns with the strategies, objectives, and risks of the organisation.
- Is appropriately positioned and adequately resourced.
- Demonstrates quality and continuous improvement.
- Communicates effectively.
- Provides risk-based assurance.
- Is insightful, proactive, and future-focused.
- Promotes organisational improvement.
In exams, you might be asked: “Discuss whether the internal audit activity at ABC Ltd demonstrates the core principles.” You then apply each principle to the scenario.
-
Definition of Internal Auditing
Already discussed in section 1.1; students are often required to quote or closely paraphrase parts of the definition. -
Code of Ethics
Covered in detail later, but recall that it is mandatory and consists of:- Principles (integrity, objectivity, confidentiality, competency).
- Rules of Conduct under each principle.
-
International Standards for the Professional Practice of Internal Auditing (Standards)
These Standards are divided into:- Attribute Standards (1000–1300): Qualities of the organisation and individuals performing internal auditing (e.g., independence, proficiency, due care, quality assurance).
- Performance Standards (2000–2600): Describe the nature of internal audit activities and criteria for performance (e.g., managing the internal audit activity, planning engagements, performing work, communicating results, monitoring progress).
- Implementation Standards: Expand the Attribute and Performance Standards for (A) assurance and (C) consulting engagements.
B. Recommended Guidance (strongly recommended but not mandatory)
- Implementation Guidance (replacing the older Practice Advisories): Explains how to implement the Standards.
- Supplemental Guidance: Detailed guidance for specific topics, industries or processes, for example:
- Auditing IT systems.
- Auditing procurement.
- Auditing fraud risk.
In AUI2601, you must clearly distinguish:
- Mandatory guidance = must comply, may be tested in definition and application questions (e.g., “Discuss how non-compliance with Standard 1100 could affect independence.”).
- Recommended guidance = supports implementation, good exam material for discussion on “best practice” but not directly tested as a compliance requirement.
1.3 The Role of Internal Auditing in the South African Context
For UNISA, CUT and other South African universities, internal auditing is always placed within the local governance framework, especially:
-
King IV Report on Corporate Governance for South Africa
King IV emphasises:- Ethical and effective leadership.
- Oversight by the board and its committees (audit committee, risk committee).
- Combined assurance model (co-ordinating internal audit, risk management, external audit and other assurance providers).
Internal audit has a central role in combined assurance: ensuring that assurance activities are properly co-ordinated and duplication is minimised.
-
Legislative framework:
- Companies Act 71 of 2008 (for companies).
- PFMA and MFMA (for national/provincial and municipal government respectively).
- Public Audit Act (for public sector external audit, which interacts with internal audit).
Exam application example:
Question: “Discuss how the internal audit function at a listed South African company supports King IV’s combined assurance model.”
Key points:
- Internal audit provides objective assurance over key risks and controls.
- Co-ordinates with external auditors (sharing risk assessments, planning) to avoid duplication.
- Works with risk management to ensure risk registers and controls are aligned.
- Reports to the audit committee on assurance coverage and gaps.
1.4 Internal Audit vs External Audit vs Other Assurance Providers
AUI2601 regularly assesses the ability to differentiate internal auditing from external auditing and other functions (compliance, risk management).
Internal audit vs external audit:
| Aspect | Internal Audit | External Audit |
|---|---|---|
| Primary objective | Add value, improve operations, evaluate risk, control, governance | Express an opinion on the fair presentation of financial statements |
| Appointment | By board / audit committee | By shareholders |
| Reporting line | Functionally to audit committee; administratively to CEO | To shareholders via audit report |
| Scope | Organisation-wide (financial, operational, compliance, IT, etc.) | Mainly financial reporting, with some regulatory/controls work |
| Frequency | Continuous throughout the year | Usually annual (plus interim) |
| Independence | Independent within the organisation | Independent of the organisation |
Internal audit vs risk management:
- Risk management owns the risk (identifies, assesses, mitigates).
- Internal audit assesses whether risk management processes are effective and reports independently.
Internal audit vs compliance:
- Compliance ensures adherence to laws, regulations and internal policies.
- Internal audit evaluates the effectiveness of compliance processes and controls and may perform tests on compliance.
Understanding these differences is crucial for combined assurance and frequently tested in AUI2601 scenarios involving “three lines” models (previously “three lines of defence”).
2. Professional Ethics and Independence (AUI2601 / UNISA, CUT IADP511)
2.1 IIA Code of Ethics: Principles and Rules of Conduct
The IIA Code of Ethics sets out the principles and rules that internal auditors must follow. In exams, be ready to:
- Define each principle.
- Illustrate each with examples.
- Apply to a case where an internal auditor’s conduct is questioned.
The Code has four principles:
- Integrity
- Objectivity
- Confidentiality
- Competency
Each principle is accompanied by Rules of Conduct that describe expected behaviour.
2.1.1 Integrity
Definition: Integrity is the quality of being honest and having strong moral principles. For internal auditors, it creates trust and provides the basis for reliance on their judgement.
Rules of Conduct (summary):
- Perform work with honesty, diligence and responsibility.
- Observe the law and make disclosures expected by the law and the profession.
- Not knowingly be a party to any illegal activity, or engage in acts that are discreditable to the profession.
- Respect and contribute to the legitimate and ethical objectives of the organisation.
Exam application example:
- Scenario: An internal auditor at a South African SOE (state-owned enterprise) discovers that a senior manager altered procurement documentation to favour a relative’s company. The auditor is offered a “bonus” to ignore the matter.
- Breach of integrity if the auditor accepts.
- The correct action: refuse the bribe, report the matter through appropriate channels (e.g., audit committee, internal reporting mechanisms), consider legal/whistle-blowing avenues.
2.1.2 Objectivity
Definition: Objectivity is an unbiased mental attitude that allows internal auditors to perform engagements in such a manner that they believe in their work product and that no quality compromises are made.
Rules of Conduct (summary):
- Not participate in any activity or relationship that may impair or is presumed to impair unbiased assessment (e.g., conflicts of interest).
- Not accept anything that may impair their professional judgement.
- Disclose all material facts known that, if not disclosed, may distort the reporting of activities under review.
Common exam angle:
Internal auditors auditing an area in which they were previously involved operationally (e.g., an internal auditor who was the payroll manager last year and now is asked to audit payroll). There’s a threat to objectivity because the auditor would be auditing their own past work. The solution is usually to assign a different auditor or provide safeguards (supervision, review).
2.1.3 Confidentiality
Definition: Confidentiality relates to respecting the value and ownership of information received and not disclosing information without appropriate authority.
Rules of Conduct (summary):
- Be prudent in the use and protection of information acquired.
- Not use information for personal gain or in a manner contrary to law or legitimate and ethical objectives of the organisation.
Example: An internal auditor at a retail chain obtains confidential sales strategies and plans. Disclosing these to a competitor or trading on insider information would be a serious breach.
2.1.4 Competency
Definition: Internal auditors must apply the knowledge, skills and experience needed in the performance of internal audit services.
Rules of Conduct (summary):
- Engage only in services for which they have the necessary knowledge, skills and experience.
- Perform internal audit services in accordance with the International Standards.
- Continually improve their proficiency and the quality of their services.
This principle often appears in exam questions about IT audits or complex financial instruments, where an internal auditor with insufficient training undertakes an engagement without seeking expertise. The correct action is to obtain competent assistance, undergo training, or decline the engagement if core competencies cannot be achieved.
2.2 Independence and Objectivity: Standards 1100–1130
The independence and objectivity section of the Standards is heavily tested in AUI2601, AUI2602, and equivalent modules like CUT IADP511 Internal Auditing Principles.
Key Standards:
-
Standard 1100 – Independence and Objectivity
The internal audit activity must be independent, and internal auditors must be objective in performing their work. -
Standard 1110 – Organisational Independence
The CAE (Chief Audit Executive) must report to a level within the organisation that allows the internal audit activity to fulfil its responsibilities (typically the audit committee). -
Standard 1111 – Direct Interaction with the Board
The CAE must communicate and interact directly with the board. -
Standard 1120 – Individual Objectivity
Internal auditors must have an impartial, unbiased attitude and avoid conflicts of interest. -
Standard 1130 – Impairment to Independence or Objectivity
Impairments must be disclosed to appropriate parties.
2.2.1 Organisational Independence
Organisational independence is usually achieved through:
-
Functional reporting line to the audit committee/board:
- Approving the internal audit charter.
- Approving the internal audit plan.
- Approving the CAE’s appointment, removal, and remuneration.
- Receiving internal audit reports and overseeing management’s response.
-
Administrative reporting line to the CEO (or similar senior executive):
- Day-to-day administration (budget, HR, logistics).
In the South African corporate governance environment (King IV), a strong internal audit activity:
- Has unfettered access to records, employees and physical properties.
- Is appropriately positioned, resourced and respected.
Exam scenario example:
If the internal audit activity at ABC Ltd reports directly to the Chief Financial Officer (CFO) both functionally and administratively, discuss potential independence issues.
Key answers:
- The CFO is often a key auditee (financial reporting, treasury, etc.), so having internal audit function report to the CFO may impair independence.
- Recommended: functional reporting to the audit committee, with administrative reporting to the CEO or another senior executive.
2.2.2 Individual Objectivity and Conflicts of Interest
Internal auditors must be aware of conflicts of interest, including:
- Personal relationships (friends/family in the area being audited).
- Financial interests (shares, performance bonuses linked to audited area).
- Prior operational responsibilities in the area under review.
Safeguards include:
- Reassignment of the engagement.
- Disclosure to CAE and audit committee.
- Additional supervision and independent quality review.
AUI2601 exam questions often ask:
- Identify threats to objectivity in a given scenario.
- Suggest safeguards to restore or protect objectivity.
2.3 Ethical Dilemmas and Professional Judgement
Internal auditors frequently face ethical dilemmas such as:
- Pressure from management to change audit findings.
- Requests to omit negative information from reports.
- Offers of gifts, hospitality or bribes.
In a test, always relate the solution to:
- IIA Code of Ethics.
- Standards (independence, objectivity).
- Organisational policies (e.g., gifts and entertainment).
- Escalation (CAE, audit committee, board).
Example: A CUT IADP511 student scenario:
An internal auditor is invited to an all-expenses-paid overseas “training” trip by a vendor whose systems are under review. Discuss the ethical and independence implications.
Possible threats:
- Gift may create a self-interest threat to objectivity.
- Could appear as bribery or undue influence.
Appropriate action:
- Decline or seek approval according to gifts policy.
- Consider whether even approved attendance may be perceived as compromising independence.
A logical exam structure when answering ethical questions:
- Identify the relevant Code of Ethics principle (e.g., objectivity, integrity).
- Cite the specific Rule of Conduct.
- Apply it to the scenario.
- Propose a course of action that aligns with the principle and internal audit standards.
2.4 Professional Competence and Continuous Professional Development
AUI2601 emphasises that competence is not static:
- Internal auditors must keep up to date with:
- Changes in IPPF and IIA guidance.
- South African laws and regulations (e.g., Companies Act, PFMA/MFMA).
- Technology developments (e.g., IT controls, data analytics).
- Governance frameworks (e.g., updates to King Codes).
For exam answers:
- Mention training, certifications (CIA – Certified Internal Auditor; local South African certifications), attendance at IIA chapter events, and on-the-job learning.
- Link competence to due professional care (Standard 1220): internal auditors must apply the care expected of a reasonably prudent and competent internal auditor.
3. Governance, Risk Management and Control (AUI2601 Core Concepts)
3.1 Corporate Governance and Internal Auditing
Corporate governance is the system by which organisations are directed and controlled. It involves:
- Board of directors (or equivalent).
- Management.
- Shareholders/owners and stakeholders.
In South Africa, King IV emphasises the responsibilities of:
- The board: ultimate accountability.
- The audit committee: oversight of financial reporting, internal controls, risk management and internal and external audit.
- The risk committee (where separate): oversight of risk management framework.
Internal audit’s role in governance:
- Provides independent assurance on the design and effectiveness of governance processes.
- Assesses whether organisational objectives are aligned with risk appetite, ethical values and compliance obligations.
- Evaluates the board’s and management’s information for decision-making (reliability, timeliness).
From an AUI2601 perspective, exam questions can include:
- “Explain how internal auditing supports good corporate governance at a listed South African company.”
- “Describe the relationship between internal audit and the audit committee.”
Typical answer points:
-
Internal audit provides regular reports to the audit committee on:
- Significant risk exposures and control issues.
- Weaknesses in governance processes.
- Fraud risks and any actual fraud incidents.
- Status of implementation of management’s corrective actions.
-
Internal audit may also evaluate:
- Ethical culture.
- Whistle-blowing mechanisms.
- Compliance with King IV principles.
3.2 Risk Management: Concepts and Internal Audit’s Role
Risk is the possibility of an event occurring that will affect the achievement of objectives. Risk management is the coordinated activities to direct and control an organisation with regard to risk.
Key risk concepts for AUI2601:
- Inherent risk: the level of risk before considering controls.
- Control (or residual) risk: risk that remains after controls are implemented.
- Risk appetite: the amount of risk the organisation is willing to accept in pursuit of objectives.
- Risk tolerance: acceptable variation in outcomes related to a specific risk.
Internal audit does not own risk management, but:
- Assesses the effectiveness of the risk management process.
- Reviews whether:
- Risks are identified and assessed systematically.
- Risk responses (avoid, accept, reduce, share) are appropriate.
- Risk information is communicated to the board/audit committee.
Internal audit may also provide consulting on risk management by:
- Facilitating risk workshops.
- Providing training on risk concepts.
- Advising on risk identification methods.
However, internal audit must avoid assuming management responsibilities (e.g., deciding risk appetite, owning risk registers).
3.3 Internal Control: Types, Components and Limitations
Internal control is a process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to:
- Effectiveness and efficiency of operations.
- Reliability of financial reporting.
- Compliance with applicable laws and regulations.
Internal auditors typically frame internal control using components similar to those in the COSO framework:
- Control environment (tone at the top, ethical values, competence, assignment of authority).
- Risk assessment.
- Control activities (policies, procedures).
- Information and communication.
- Monitoring activities.
Types of controls:
- Preventive controls: aim to prevent errors or irregularities (e.g., segregation of duties, access controls).
- Detective controls: identify errors or irregularities after they occur (e.g., reconciliations, exception reports).
- Corrective controls: correct identified problems (e.g., backup and recovery procedures).
Other classifications:
- Manual vs automated (IT) controls.
- General IT controls vs application controls.
Limitations of internal control:
- Human error.
- Collusion between employees.
- Management override.
- Cost-benefit considerations (controls must be reasonable and practical).
AUI2601 exam questions on controls often involve:
- Identifying control weaknesses in a scenario (e.g., one person performs incompatible duties).
- Suggesting appropriate controls to mitigate specific risks.
- Classifying controls as preventive/detective/corrective.
3.4 The Internal Control System in Practice: Segregation of Duties, Authorisation, Documentation
Three key control principles frequently examined:
-
Segregation of duties
No single person should:- Authorise transactions.
- Record transactions.
- Maintain custody of assets.
Example (Payroll):
- HR authorises new employees.
- Payroll department processes payments.
- Finance signs off bank payments and reconciles payroll accounts.
-
Authorisation and approval
Only appropriate levels of management can approve specific transactions or activities. Limitations are usually defined in delegation of authority matrices. -
Documentation and recordkeeping
- All transactions must be supported by proper documentation.
- There must be an audit trail from initiation to recording.
Internal auditors must evaluate whether controls are:
- Properly designed (design effectiveness).
- Operating as intended (operating effectiveness).
4. Managing the Internal Audit Activity (Planning, Quality, Reporting) – AUI2601 / UNISA AUI2602 Links
Although AUI2602 at UNISA focuses more deeply on internal audit processes, AUI2601 students must understand the fundamental theory of how the internal audit activity is managed and structured. This overlaps with modules like NWU AUIE221 Internal Audit Environment and CUT IADP511 Internal Auditing Principles.
4.1 Internal Audit Charter and Positioning
The internal audit charter is a formal document that defines:
- Purpose.
- Authority.
- Responsibility.
- Position within the organisation.
It must:
- Be consistent with the Definition of Internal Auditing, the Code of Ethics and the Standards.
- Be approved by:
- Senior management.
- The board (typically the audit committee).
Key elements usually tested:
- Affirmation of internal audit’s independence.
- Unrestricted access to records, personnel, and physical properties.
- Scope of assurance and consulting services.
- Reporting relationships (functional to audit committee, administrative to CEO).
- Responsibility for developing a risk-based audit plan.
Example exam question:
“Explain why it is important for ABC Ltd’s internal audit activity to have an internal audit charter and list FIVE key elements that must be included.”
Answer structure:
- Importance (clarity of role, authority, independence, alignment with IPPF).
- Elements (purpose, authority, responsibility, reporting lines, scope, access, reference to Standards, approval by board).
4.2 Risk-Based Internal Audit Planning
The CAE must establish a risk-based internal audit plan to determine the priorities of the internal audit activity, consistent with the organisation’s goals.
Steps in risk-based planning:
-
Understand organisation’s strategies and objectives
- Strategic plans.
- Business model.
- Key performance indicators.
-
Obtain and evaluate risk information
- Enterprise Risk Management (ERM) risk register.
- Management and board risk assessments.
- External factors (economic conditions, regulatory changes).
-
Assess risk of auditable units
- Define auditable units (processes, divisions, IT systems).
- Use risk criteria such as:
- Impact (financial, reputational, operational).
- Likelihood of occurrence.
- Quality of controls.
- Score or rank auditable units.
-
Prioritise audit engagements
- High-risk areas receive priority.
- Medium and low-risk areas may be scheduled less frequently or on a rotational basis.
-
Develop an annual internal audit plan
- Specify engagements, timing and resources.
- Obtain approval from the audit committee.
-
Communicate and update
- Communicate plan to management and audit committee.
- Flexibility: update for emerging risks (e.g., new regulations, acquisitions, cybersecurity threats).
AUI2601 may give a list of organisational risks and ask students to:
- Indicate which areas should be prioritised.
- Explain the risk-based rationale.
4.3 Engagement Planning: Objectives, Scope and Resource Allocation
At the engagement (individual audit) level, planning is guided by Performance Standards:
- 2200 – Engagement Planning
- 2201 – Planning Considerations
- 2210 – Engagement Objectives
- 2220 – Engagement Scope
- 2230 – Engagement Resource Allocation
- 2240 – Engagement Work Programme
Core concepts:
-
Engagement objectives
- Clearly state what the audit intends to achieve.
- Must address key risks and relevant controls.
- Example: “To evaluate the adequacy and effectiveness of controls over the credit sales process at XYZ Ltd for the year ended 31 December 2025.”
-
Engagement scope
- Boundaries for the engagement: processes, time periods, locations, systems.
- Must be sufficient to achieve objectives.
- Scope may be limited by resource constraints, but limitations must be communicated.
-
Resource allocation
- Assign team members with appropriate skills and experience.
- Plan time budgets for fieldwork, supervision and reporting.
-
Work programme
- Detailed procedures for collecting, analysing and documenting information.
- Must be approved before fieldwork begins.
- Adaptable as risk understanding evolves.
Exam application (UNISA AUI2601):
- Scenario: You are the internal auditor at a mid-size retailer in Gauteng that sells online and in-store. The exam might ask you to outline engagement objectives and scope for an audit of the online sales process.
Expected answer components:
- Objectives: Evaluate controls over order processing, payment verification, data security, delivery logistics, returns and refunds.
- Scope: Time period (e.g., last 12 months), systems involved (e-commerce platform, payment gateway), key locations (central warehouse, customer service).
4.4 Quality Assurance and Improvement Programme (QAIP)
Standard 1300 – Quality Assurance and Improvement Program requires the CAE to develop and maintain a QAIP that covers all aspects of internal audit activity.
Components:
-
Ongoing internal assessments
- Supervision of engagements.
- Review of working papers and reports.
- Audit file checklists.
- Performance metrics (e.g., plan completion rate, budget vs actual hours, issue implementation rates).
-
Periodic internal assessments
- Self-assessments by internal audit.
- Assessments by other persons within the organisation who have knowledge of internal audit practices.
-
External assessments
- At least once every five years, must be conducted by a qualified, independent assessor or assessment team from outside the organisation.
- Can be:
- Full external assessment, or
- Self-assessment with independent external validation.
QAIP objectives:
- Ensure conformance with the Definition of Internal Auditing, the Code of Ethics and the Standards.
- Assess efficiency and effectiveness of internal audit activity.
- Identify opportunities for improvement.
In an exam, students may be asked:
- “Explain why an external quality assessment is important for the internal audit activity.”
- “Distinguish between ongoing and periodic internal assessments.”
Key points:
- Supports credibility of the internal audit function.
- Provides assurance to the board that internal audit conforms to professional standards.
- Helps identify skills gaps, training needs and process improvements.
4.5 Communication and Reporting of Internal Audit Results
Performance Standard 2400 – Communicating Results requires internal auditors to communicate the results of engagements effectively.
Key elements of a good internal audit report:
- Purpose: Why the engagement was performed.
- Scope: Areas covered and limitations.
- Methodology: High-level overview (e.g., interviews, document review, testing).
- Findings: Clear description of:
- Condition (what is).
- Criteria (what should be).
- Cause (why the difference).
- Effect (so what – risk or impact).
- Recommendation (how to fix).
- Management response: Action plans, responsible person, completion dates.
- Conclusion/overall opinion: Where appropriate, internal audit may express an opinion on adequacy and effectiveness of controls in the area.
Effective communication characteristics:
- Clear and concise (avoids jargon, directly addresses the issue).
- Accurate (supportable by evidence in working papers).
- Objective (balanced, acknowledges management’s perspective).
- Constructive (focuses on improvement).
Follow-up (Standard 2500 – Monitoring Progress):
- Internal audit must establish a system to monitor disposition of results communicated to management.
- Follow-up ensures that agreed corrective actions are implemented.
AUI2601 exam questions might ask:
- “List and explain the elements that should be included in an internal audit finding.”
- “Discuss the importance of follow-up in the internal audit process.”
5. Internal Audit Engagements: Assurance vs Consulting, Fraud, IT and Public Sector Focus
This section aligns theory with practical engagement types commonly examined at UNISA (AUI2601/AUI2602) and comparable modules like NWU AUIE222 Assurance Engagements or CUT IADP521 Internal Auditing Practice.
5.1 Assurance Engagements vs Consulting Engagements
The IPPF distinguishes:
-
Assurance services: Objective evaluation of evidence for the purpose of providing an independent assessment on governance, risk management and control processes.
Examples: audits, reviews, investigations, attestation engagements. -
Consulting services: Advisory and related client activities, the nature and scope of which are agreed with the client, intended to add value and improve governance, risk and control processes without internal auditors assuming management responsibility.
Examples: advice, facilitation, training, counsel.
Key exam distinctions:
-
Purpose and responsibility
- Assurance: Internal audit is responsible for the nature, timing and extent of work and for forming a conclusion.
- Consulting: Client owns decisions; internal audit gives input and advice.
-
Engagement objectives and scope
- Assurance: Internal audit defines objectives and scope (based on risk and charter).
- Consulting: For example, assisting management with implementing a new inventory system – objectives and scope are mutually agreed.
-
Reporting
- Assurance: Formal written report with findings, conclusions, possibly an opinion.
- Consulting: May be less formal (memo, presentation, advice email), but must still comply with ethical and professional standards.
Example exam scenario:
“The internal audit activity at XYZ University has been asked to assist management in designing controls over a new student registration system. Discuss whether this is an assurance or consulting engagement and how internal audit can avoid assuming management responsibilities.”
Answer points:
- This is a consulting engagement.
- Internal audit can:
- Recommend control principles and options.
- Facilitate risk assessment workshops.
- Review management’s control design and provide comments.
- Internal audit must not:
- Decide which controls to implement.
- Perform operational management activities (system configuration, approval decisions).
5.2 Fraud Risk and the Role of Internal Auditing
Internal auditors are not primarily responsible for detecting and investigating all fraud, but they play an important role regarding:
- Fraud risk assessment.
- Evaluating the adequacy of fraud prevention and detection controls.
- Investigating certain fraud allegations, depending on organisational policies.
Key points for AUI2601 exams:
- Management bears primary responsibility for fraud prevention and detection.
- The board and audit committee oversee the fraud risk management framework.
- Internal audit:
- Evaluates the fraud risk management process.
- Performs targeted audits in high-fraud-risk areas (procurement, payroll, revenue, cash).
- Assesses:
- Segregation of duties.
- Authorisation procedures.
- Reconciliations.
- Whistle-blowing mechanisms.
- Employee ethics awareness.
Fraud triangle (useful in exam explanations):
- Pressure (incentive).
- Opportunity.
- Rationalisation.
Internal controls and internal audit help minimise opportunity and increase likelihood of detection, thus deterring fraud.
Example scenario (common in South African context):
- A municipal official colludes with a contractor to inflate invoices for infrastructure projects. Internal audit may:
- Compare contract terms with invoices.
- Use data analytics to identify unusual payment patterns.
- Check for conflicts of interest (ownership links to officials).
When asked to discuss internal audit’s role in fraud, you must:
- Distinguish between prevention, detection and investigation.
- Emphasise that internal audit supports, but does not replace, management’s responsibilities.
5.3 Information Technology (IT) and Internal Auditing
Even in a theory module like AUI2601, expect questions on the internal auditor’s role in assessing IT risks and controls, especially:
- Access controls.
- Change management.
- Backup and recovery.
- Segregation of duties in system environments.
- Cybersecurity risks.
Types of IT controls:
-
General IT controls (GITCs):
- Data centre and network operations.
- System software acquisition, change and maintenance.
- Application system acquisition, development and maintenance.
- Access security (logical and physical).
- Backup and disaster recovery.
-
Application controls:
- Input controls (e.g., data validation).
- Processing controls (e.g., run-to-run totals).
- Output controls (e.g., exception reporting).
- Master file controls (e.g., controlled changes, audit trails).
Internal audit’s IT focus includes:
- Ensuring that IT risks are assessed as part of overall risk-based planning.
- Using CAATs (computer-assisted audit techniques) and data analytics for testing.
- Reviewing IT governance in line with frameworks like COBIT, King IV IT principles.
Example exam application:
“Discuss the key IT general controls that the internal auditor at a South African bank should review when auditing the core banking system.”
Suggested structure:
- Change management controls (authorisation, testing, segregation).
- User access and privilege management.
- Backup and disaster recovery arrangements.
- Physical security of servers and data centres.
- Monitoring of system performance and security incidents.
5.4 Public Sector Internal Auditing in South Africa
Students in UNISA’s BCom Internal Auditing and related programmes (e.g., CUT NDip Internal Auditing, NWU Public Sector Audit modules) must understand how internal auditing functions in the public sector environment.
Key features:
-
Legislative framework:
- Public Finance Management Act (PFMA).
- Municipal Finance Management Act (MFMA).
- Treasury Regulations.
- Public Service Regulations and circulars.
-
Internal audit requirement:
- PFMA/MFMA require departments and municipalities to establish internal audit units.
- These units must:
- Prepare risk-based audit plans.
- Advise accounting officers and authorities.
- Evaluate internal controls, risk management and governance.
-
Relationship with Auditor-General of South Africa (AGSA):
- AGSA is the supreme external audit body for public sector.
- Internal audit can support AGSA by:
- Sharing risk assessments.
- Providing work that may be relied upon (if it meets quality requirements).
Public sector internal audit often covers:
- Compliance with laws, regulations and Treasury Instructions.
- Performance information (usefulness and reliability of predetermined objectives).
- Supply chain management and procurement (a major fraud risk area).
- Asset management, including infrastructure.
- Service delivery and value-for-money audits.
Typical exam question:
“Explain TWO ways in which the internal audit unit of a provincial department contributes to improved public financial management.”
Ideas to include:
- Evaluating the adequacy and effectiveness of internal controls over budget preparation, execution and reporting.
- Identifying inefficiencies and recommending process improvements.
- Monitoring follow-up on AGSA audit findings.
- Enhancing transparency and accountability through reporting to audit committees.
5.5 Integrated/Combined Assurance and the Three Lines Model
King IV and the IIA promote combined assurance and the three lines model (updated from the traditional three lines of defence):
- First line: Management and operations – own and manage risks and controls.
- Second line: Risk management, compliance and other oversight functions.
- Third line: Internal audit – provides independent and objective assurance.
Combined assurance aims to:
- Coordinate assurance efforts across:
- Internal audit.
- Risk and compliance.
- External audit.
- Other assurance providers (e.g., environmental auditors, safety auditors).
- Avoid duplication.
- Ensure that all significant risks are sufficiently covered by assurance providers.
Internal audit’s role:
- Assess effectiveness of first and second line functions.
- Facilitate mapping of risks to assurance providers.
- Report on overall assurance status to the audit committee and board.
Exam applications may require you to:
- Draw and explain a three lines model diagram.
- Identify where a specific function fits (e.g., HR compliance = second line; line managers = first line; internal audit = third line).
- Explain how internal audit coordinates with external auditors to achieve combined assurance (e.g., sharing risk assessments, relying on each other’s work where appropriate).
6. Exam Strategy and Application for AUI2601 (UNISA BCom Internal Auditing)
6.1 Typical Question Themes and How to Approach Them
For AUI2601, past papers from UNISA and equivalent modules (e.g., NWU AUIE221, CUT IADP511) show recurring themes:
- Definition and purpose of internal auditing.
- Components of the IPPF.
- Code of Ethics and independence.
- Governance, risk and control concepts.
- Managing the internal audit activity (charter, QAIP, planning).
- Assurance vs consulting services.
- Fraud and IT-related questions.
- Public sector internal audit and combined assurance.
When answering:
-
Start with definition/theory:
State or paraphrase the relevant definition or standard. -
Apply to scenario:
Directly link the theory to the given case facts. -
Conclude clearly:
Summarise key implications or recommendations.
Example structure for a 15-mark question:
- 3–4 marks: concise definitions and frameworks.
- 7–8 marks: detailed application to scenario.
- 3–4 marks: clear, logical conclusion and recommendations.
6.2 Common Errors to Avoid
- Listing without explaining: Simply naming principles or standards without explaining them will lose marks.
- Ignoring scenario details: Many marks are allocated for application, not rote learning.
- Mixing up internal and external audit roles: Keep distinctions clear.
- Forgetting local context: In South Africa, always consider King IV, PFMA/MFMA, Companies Act, AGSA where relevant.
- Insufficient linkage to ethics and independence: Many practical issues boil down to ethical and independence concerns; always relate back to Code of Ethics and Standards.
6.3 Integrating Content Across Modules and Universities
Though this guide is titled for UNISA AUI2601: Internal Auditing Theory and Principles, the concepts are equally relevant to:
- UNISA:
- AUI2602 – Internal Audit Process.
- AUI3701 – Governance, Risk and Control.
- CUT:
- IADP511 – Internal Auditing Principles.
- IADP521 – Internal Auditing Practice.
- NWU:
- AUIE221 – Internal Audit Environment.
- AUIE222 – Internal Audit Assurance Engagements.
Across these modules, you will see consistent reliance on:
- IPPF (Definition, Code of Ethics, Standards).
- King IV and combined assurance.
- South African legislative and regulatory context.
Understanding AUI2601 thoroughly provides a solid foundation for the more advanced, application-heavy modules that follow.
By mastering the theory and principles covered in this guide—IPPF, ethics, independence, governance, risk, control, planning, reporting and specialised engagement areas—students in UNISA’s BCom Internal Auditing and related programmes at CUT, NWU and other South African universities will be well equipped to handle conceptual and application-driven examination questions in AUI2601: Internal Auditing Theory and Principles and to build a professional internal auditing career aligned with global and South African best practices.
