AUI3703 King IV Report Exam Notes for Internal Auditors (UNISA BCom Internal Auditing)

King IV is a central topic in UNISA AUI3703: Corporate Governance in Internal Auditing and related modules such as AUE3702, AUI2602, and BCom Internal Auditing capstone courses at UNISA, CUT, TUT and other South African universities. These exam notes focus on what internal auditors need to know about the King IV Report on Corporate Governance™ for South Africa, 2016, with emphasis on how to apply it in internal audit planning, execution and reporting.

King IV is outcomes‑based, principle‑driven and written for organisations of all types. For internal auditors preparing for UNISA exams and workplace application, a firm grasp of its philosophy, 17 principles, sector supplements, and the “apply and explain” regime is essential. This guide unpacks King IV in a way aligned with typical BCom Internal Auditing assessment requirements: governance theory, internal audit implications, and exam‑style analysis.

1. King IV Overview and South African Context

1.1 Origins and Evolution: King I to King IV

South Africa’s King Reports are globally influential. Internal auditors are often examined on the historical evolution:

  • King I (1994)

    • Focus: Boards of listed companies; emerging post‑apartheid corporate reform.
    • Emphasis on: Board responsibility, financial and non‑financial reporting, codes of conduct.
    • Context: Aligned with early moves toward international governance norms.
  • King II (2002)

    • Broadened governance to:
      • Risk management
      • Internal audit
      • Sustainability considerations
    • Introduced the idea that governance is not only about compliance and control, but also about strategy and risk.
  • King III (2009)

    • Applied to all entities (public, private, NPOs, SOEs).
    • Introduced “apply or explain”: entities should either apply recommended practices or explain why not.
    • Strong focus on:
      • Integrated reporting
      • IT governance
      • Combined assurance
      • Risk‑based internal audit
    • Relevant to older UNISA modules (e.g. earlier AUI2601/AUI2602 syllabi).
  • King IV (2016)

    • Effective for financial years starting on or after 1 April 2017.
    • Replaces “apply or explain” with “apply and explain”.
    • Emphasises outcomes‑based governance: ethical culture, performance and value creation, adequate and effective control, and legitimacy.
    • Applicable across organisational forms and sectors, with sector supplements.
    • Recognises increasing complexity (technology, stakeholder activism, globalisation).

For exam purposes in AUI3703 and similar courses (e.g. AUE3751, CNS445 at CUT when dealing with IT governance elements), the key is to understand why King IV was introduced: to modernise corporate governance, make it more inclusive, more transparent and more focused on outcomes rather than mechanistic compliance.

1.2 King IV’s Governance Philosophy

King IV is anchored in a specific philosophical view of governance:

  • Stakeholder‑inclusive approach

    • Organisations must create value in a sustainable manner for a wide range of stakeholders (shareholders, employees, customers, suppliers, regulators, communities, environment).
    • Rejects a narrow shareholder‑only focus.
    • Internal auditors must therefore test how governance processes consider stakeholder interests.
  • Integrated thinking

    • Organisations should connect strategy, risk, performance and sustainability.
    • Board decision‑making should consider short, medium and long‑term consequences.
    • Integrated thinking underpins integrated reporting, which internal auditors may provide assurance on.
  • Values‑based leadership and ethical culture

    • Emphasis on tone at the top, ethical behaviour and organisational justice.
    • Ethics is not an add‑on; it is central to strategy and decision‑making.
    • Internal audit’s role includes evaluating the ethics management framework.
  • Outcomes‑based governance

    • Governance is assessed by its outcomes, not just structures and policies. King IV defines four central outcomes:
      1. Ethical culture
      2. Good performance (value creation)
      3. Effective control
      4. Legitimacy (trust and confidence of stakeholders)
    • Internal auditors must design engagements to assess whether governance processes actually lead to these outcomes.

Exam questions often ask you to compare rule‑based vs principle‑based governance. King IV is clearly principle‑based and outcomes‑focused, expecting entities to design governance structures that fit their context while demonstrating how the principles are applied.

1.3 Scope and Applicability

King IV applies to:

  • All organisations in South Africa on a voluntary basis, including:
    • JSE‑listed companies
    • State‑owned entities (SOEs)
    • Municipalities and public sector entities
    • Private companies
    • Non‑profit organisations (NPOs)
    • Retirement funds

The Report consists of:

  • The Main Part: 17 principles and recommended practices.
  • Sector Supplements providing guidance for:
    • Small and Medium Enterprises (SMEs)
    • NPOs
    • State‑Owned Entities
    • Municipalities
    • Retirement Funds
    • JSE‑listed companies (practical listing‑related focus)

For internal auditors, especially in UNISA BCom Internal Auditing and UNISA Advanced Diploma in Internal Auditing, it is important to know:

  • King IV is not legislation, but many of its concepts are embedded in, or aligned with:
    • Companies Act 71 of 2008
    • Public Finance Management Act (PFMA)
    • Municipal Finance Management Act (MFMA)
    • JSE Listings Requirements
  • Regulators and courts increasingly reference King IV in evaluating directors’ duties and governance adequacy.

1.4 The “Apply and Explain” Regime

A core exam theme is the shift from “apply or explain” (King III) to “apply and explain” (King IV):

  • Apply and explain means:
    • Organisations are expected to apply all 17 principles; they are seen as universally applicable.
    • For each principle, the organisation must explain practices and how these achieve the intended governance outcome.
    • Explanations should be concise, meaningful, and specific to the entity, not boilerplate.

Consequences for internal auditors:

  • Internal audit must evaluate:
    • Whether the principles are indeed applied.
    • Whether the “explain” disclosures are accurate, complete and not misleading.
  • When auditing governance:
    • Test both the design and operating effectiveness of governance practices.
    • Consider whether the organisation’s own explanations reflect reality (substance over form).

Example:
A UNISA‑trained internal auditor at a state‑owned enterprise must consider whether the SOE’s integrated report fairly explains how it applies Principle 6 (delegation to committees) or Principle 11 (risk governance). If there is a gap between disclosed practice and actual practice, that is a governance and reporting risk.

2. King IV’s 17 Principles: What Internal Auditors Must Know

King IV presents 17 principles grouped into five overarching topics. For AUI3703 and similar modules, internal auditors must be able to:

  • Recall the principles,
  • Explain their intent,
  • Identify governance structures/processes that give effect to them,
  • Recognise typical control weaknesses,
  • Design internal audit procedures to assess compliance and effectiveness.

2.1 Ethical Leadership and Corporate Citizenship (Principles 1–3)

Principle 1: Ethical and Effective Leadership

Wording (summary):
“The governing body should lead ethically and effectively.”

Key ideas:

  • Governing body members (e.g. board of directors, accounting authority) are expected to:
    • Act in good faith and in the best interests of the organisation.
    • Demonstrate integrity, competence, responsibility, accountability, fairness, and transparency.
    • Manage conflicts of interest.
    • Provide ethical leadership that sets the tone for the organisation.

Internal audit implications:

  • Review board and committee charters, codes of conduct, and conflict‑of‑interest policies.
  • Assess whether:
    • Directors complete regular declarations of interest.
    • There is follow‑up and mitigation where conflicts arise.
    • There is documented performance evaluation of individual directors and the board as a whole.

Exam‑style application:

  • A case study may show a board that approves dubious related‑party transactions. Internal auditors must identify this as a failure of ethical leadership (Principle 1) and propose:
    • Strengthening conflict‑of‑interest procedures.
    • More robust independent non‑executive director oversight.
    • Clear sanctions for ethical breaches.

Principle 2: Governance of Ethics

Wording (summary):
“The governing body should govern the ethics of the organisation in a way that supports the establishment of an ethical culture.”

Key concepts:

  • Establish an ethics management framework including:
    • Code of ethics.
    • Ethics training and communication.
    • Mechanisms for reporting unethical conduct (e.g. whistle‑blowing hotline).
    • Ethics risk assessment and monitoring.
    • Disciplinary procedures and consequences.

Internal audit’s role:

  • Evaluate whether:

    • The ethics policy is approved by the governing body and aligned with organisational values.
    • Ethics is integrated into:
      • Strategy and decision‑making,
      • Performance management,
      • Recruitment and promotion.
    • Ethics reporting mechanisms are:
      • Widely communicated,
      • Accessible,
      • Independently administered (or sufficiently safeguarded),
      • Leading to appropriate investigations and corrective actions.
  • Perform ethics culture assessments using:

    • Surveys, interviews, focus groups.
    • Analysis of misconduct cases, whistle‑blower reports, HR grievances.

UNISA assessment tip:
Explain the difference between governance of ethics (Principle 2) and ethics management on an operational level (e.g. HR policies), and how internal audit covers both the governance structures and practical implementation.

Principle 3: Responsible Corporate Citizenship

Wording (summary):
“The governing body should ensure that the organisation is and is seen to be a responsible corporate citizen.”

Key dimensions of corporate citizenship:

  • Social and economic development (e.g. B‑BBEE, employment equity).
  • Environmental responsibility.
  • Responsible consumption of natural resources.
  • Fair labour practices and human capital development.
  • Social and community impact.
  • Compliance with laws, regulations and standards.

Internal audit’s focus:

  • Assess whether corporate citizenship:

    • Is integrated in the strategy and not treated as a mere CSI add‑on.
    • Has clear policies, targets and KPIs.
    • Is reported accurately in sustainability and integrated reports.
  • Test controls over:

    • Environmental compliance (e.g. waste management, emissions reporting).
    • Social investment and CSI spend (validity, alignment with strategy, avoidance of fraud).
    • B‑BBEE and employment equity reporting (accuracy and completeness).

For exams, you may have to discuss how internal audit adds value in assessing corporate citizenship, especially in public entities and SOEs (linking to PFMA/MFMA compliance and King IV’s SOE Supplement).

2.2 Performance and Value Creation (Principles 4–6)

Principle 4: Strategy and Performance

Wording (summary):
“The governing body should appreciate that the organisation’s core purpose, its risks and opportunities, strategy, business model, performance and sustainable development are all inseparable elements of the value creation process.”

Key themes:

  • Integrated strategy: Aligns purpose, risk appetite, business model and performance.
  • Short, medium, long‑term orientation.
  • Consideration of trade‑offs (e.g. profitability vs environmental constraints).
  • Integration of sustainability and ESG factors into strategy.

Internal audit implications:

  • Internal audit must understand the organisation’s strategic objectives and risk appetite to:

    • Develop risk‑based internal audit plans aligned with strategic risks.
    • Evaluate whether major projects and investments align with strategy.
    • Assess performance measurement frameworks (KPIs, KRIs).
  • Evaluate governance over strategy:

    • Does the board approve and regularly review strategy?
    • Are strategic risks identified and managed?
    • Are there clear strategic performance dashboards presented to the board?

In AUI3703, students may be asked to highlight how internal audit supports the board’s oversight of strategy by providing assurance on strategic risk management and performance information.

Principle 5: Reports and Disclosure

Wording (summary):
“The governing body should ensure that reports issued by the organisation enable stakeholders to make informed assessments of the organisation’s performance, and its short, medium and long‑term prospects.”

Key outputs:

  • Integrated report as the primary report.
  • Financial statements and other statutory reports.
  • Sustainability, ESG, and other stakeholder‑specific reports.

Quality criteria:

  • Balance (both positive and negative performance).
  • Comparability and consistency.
  • Reliability (accurate, complete, free from material misstatement).
  • Clarity and accessibility.

Internal audit’s role:

  • Provide assurance (or at least limited review) on:
    • The internal controls over financial and non‑financial reporting.
    • Processes used to collect, consolidate and report data.
  • Coordinate with external auditors and other assurance providers to avoid gaps and overlaps (combined assurance – Principle 15).

Exam angle:
You may be asked to describe how internal audit contributes to the credibility of the integrated report, including verification of key non‑financial metrics (e.g. customer satisfaction, safety incidents, environmental indicators).

Principle 6: Governing Body Delegation and Composition

Wording (summary):
“The governing body should serve as the focal point and custodian of corporate governance in the organisation.”

Key aspects:

  • Clear definition of the governing body’s role and responsibilities.
  • Proper delegation to committees and management while retaining overall accountability.
  • Composition:
    • Appropriate balance of executive, non‑executive and independent non‑executive directors.
    • Collective knowledge, skills and experience (diversity, including gender and race).
    • Evaluation of board performance.

Internal audit focus:

  • Review board and committee charters to ensure they cover:

    • Strategy and performance oversight,
    • Risk and internal control,
    • Ethics and compliance,
    • Technology and information governance,
    • Remuneration and succession planning.
  • Evaluate whether:

    • Governance structures are implemented as per charters.
    • Meetings are properly documented; decisions, follow‑ups and accountability are clear.
    • Board effectiveness assessments are conducted and actioned.

In exam scenarios, you may need to distinguish between the governing body’s accountability and management’s responsibilities, and explain how internal audit maintains independence while reporting functionally to the governing body (typically via the audit committee).

2.3 Governance Functional Areas (Principles 7–12)

Principle 7: Composition of the Governing Body

Wording (summary):
“The governing body should comprise the appropriate balance of knowledge, skills, experience, diversity and independence for it to discharge its governance roles and responsibilities objectively and effectively.”

Distinguishing from Principle 6:

  • Principle 6 focuses on the governing body as the focal point and custodian of governance.
  • Principle 7 focuses on its composition and qualities.

Key considerations:

  • Skills matrix and diversity policy.
  • Independence criteria for non‑executive directors.
  • Rotation and tenure limits.
  • Succession planning.

Internal audit procedures:

  • Verify that:

    • A skills and experience matrix exists and is periodically reviewed.
    • Diversity policies (including gender and race) are implemented.
    • Independence is assessed and documented (no material relationships that compromise objectivity).
  • Report to the audit committee if:

    • Gaps in critical competencies exist (e.g. no members with IT governance or risk management expertise).
    • Over‑concentration of power is evident (e.g. one individual serving on too many committees).

Principle 8: Committees of the Governing Body

Wording (summary):
“The governing body should ensure that its arrangements for delegation within its own structures promote independent judgement, and assist with balance of power and the effective discharge of its duties.”

Typical committees:

  • Audit committee.
  • Risk committee (or combined audit and risk committee).
  • Social and ethics committee.
  • Remuneration committee.
  • Nominations committee.
  • IT or technology committee (where relevant).

Internal audit’s relationship with committees:

  • Primary interaction is with the audit committee:

    • Approves internal audit charter and plan.
    • Oversees the effectiveness of internal audit.
    • Receives internal audit reports and monitors management actions.
  • May also interact with:

    • Risk committee (combined assurance, risk‑based planning).
    • Social and ethics committee (ethics, compliance, CSI assurance).
    • IT committee (IT governance audits).

Internal audit assessment areas:

  • Committee charters: appropriateness, approval, periodic review.
  • Committee independence and competence.
  • Frequency and quality of meetings; adequacy of minutes and follow‑up.

Exam link:
In UNISA AUI3703 and AUE3702, questions commonly ask for the role of the audit committee in relation to internal audit and how King IV principles shape this relationship.

Principle 9: Evaluation of Governing Body Performance

Wording (summary):
“The governing body should ensure that the evaluation of its own performance and that of its committees, its chair and its members, supports continued improvement in its performance and effectiveness.”

Key elements:

  • Regular (usually annual) evaluations.
  • Combination of self‑assessment and independent external evaluations (periodic).
  • Action plans arising from evaluation findings.

Internal audit considerations:

  • Can provide assurance over:
    • Existence and adequacy of the evaluation process.
    • Whether improvement actions are implemented.
  • Must be careful not to undermine board independence; internal audit’s role is assurance, not conducting the evaluation itself (unless specifically requested and safeguards are in place).

Possible exam question:
“Explain how internal audit can provide assurance on the effectiveness of the governing body, without compromising its own independence or the independence of the governing body.”

Principle 10: Appointment and Delegation to Management

Wording (summary):
“The governing body should ensure that the appointment of, and delegation to, management contribute to role clarity and the effective exercise of authority and responsibilities.”

Key governance aspects:

  • Appointment of the CEO/Accounting Officer.
  • Clarity of roles between the governing body and management.
  • Delegation of authority frameworks (DoA).
  • Performance contracts and oversight of executive management.

Internal audit implications:

  • Assess whether:

    • The delegation of authority is approved by the governing body, updated, and communicated.
    • Significant decisions and commitments are made within delegated limits.
    • Management’s performance is periodically reviewed against set objectives.
  • Test samples of:

    • Contracts, procurement decisions, capital expenditures against delegated authority thresholds.
    • Evidence of management’s accountability to the governing body (e.g. reporting, performance reviews).

Principle 11: Risk Governance

Wording (summary):
“The governing body should govern risk in a way that supports the organisation in setting and achieving its strategic objectives.”

Key concepts:

  • Enterprise‑wide risk management (ERM).
  • Risk appetite and tolerance.
  • Integration of risk into strategy and decision‑making.
  • Regular risk identification, assessment, response and monitoring.

Internal audit’s role (aligned with the IIA Standards):

  • Provide independent assurance over:
    • Risk management framework design.
    • Adequacy and effectiveness of risk identification and mitigation.
  • Avoid assuming management responsibility for risk, which would impair independence.

Internal audit practice areas:

  • Risk‑based audit planning:
    • Use the organisation’s risk register as a key input.
    • Confirm risks are properly assessed; challenge where necessary.
  • Evaluate risk culture:
    • Evidence that managers actively discuss and respond to risks.
    • Alignment between risk appetite and actual risk‑taking behaviour.

UNISA exam angle:
Discuss the relationship between risk management, internal control and governance, demonstrating how King IV’s Principle 11 and IIA’s risk‑based approach align.

Principle 12: Technology and Information Governance

Wording (summary):
“The governing body should govern technology and information in a way that supports the organisation in setting and achieving its strategic objectives.”

Key areas:

  • IT governance structures (e.g. IT steering committee).
  • IT strategy aligned with business strategy.
  • Information security, privacy, and cyber risk.
  • Data quality and information as a key organisational asset.
  • Compliance with IT‑related laws and regulations (e.g. POPIA).

Internal audit’s responsibilities:

  • Develop IT audit capabilities (either in‑house or co‑sourced).
  • Provide assurance over:
    • IT general controls (access, change management, operations).
    • Application controls (input, processing, output).
    • Cybersecurity controls and incident response.
    • Data governance, including master data management and data quality.
  • Coordinate with specialised IT auditors, especially in large organisations or universities (e.g. CNS445 IT governance topics at CUT).

Exam focus:
You should be able to explain how strong technology and information governance supports achievement of strategic objectives, and how internal audit evaluates this in line with King IV.

2.4 Assurance, Compliance and Stakeholder Relationships (Principles 13–17)

Principle 13: Compliance Governance

Wording (summary):
“The governing body should govern compliance with applicable laws and adopted, non‑binding rules, codes and standards in a way that supports the organisation being ethical and a good corporate citizen.”

Key aspects:

  • Compliance universe: All laws, regulations, standards and codes applicable to the entity.
  • Compliance is not just legalistic; it’s part of ethics and corporate citizenship.
  • Need for a compliance management framework:
    • Policies and procedures.
    • Compliance risk assessments.
    • Compliance monitoring and reporting.
    • Training and awareness.

Internal audit’s role:

  • Evaluate whether:

    • Compliance risk is identified and managed systematically.
    • Compliance responsibilities are clear (compliance officer, legal department, line management).
    • Compliance breaches are detected, escalated and addressed.
  • Test compliance with:

    • High‑risk laws (e.g. PFMA, Companies Act, tax legislation, environmental laws).
    • Self‑imposed codes (e.g. industry codes of conduct, voluntary standards like ISO).

Common exam scenario:
A public entity fails to comply with PFMA procurement regulations. Internal auditors must discuss how this indicates weaknesses in both compliance governance (Principle 13) and risk governance (Principle 11), and propose remedial actions.

Principle 14: Remuneration Governance

Wording (summary):
“The governing body should ensure that the organisation remunerates fairly, responsibly and transparently so as to promote the achievement of strategic objectives and positive outcomes in the short, medium and long term.”

Key points:

  • Remuneration must:
    • Be aligned with strategy and risk appetite.
    • Not encourage excessive risk‑taking or unethical behaviour.
    • Be fair (internal equity) and competitive (external equity).
    • Be transparent (clear disclosure of policies and outcomes).

Internal audit assurance areas:

  • Linkage between performance measures and incentives:
    • Are KPIs aligned with sustainable value creation or only short‑term financial metrics?
  • Review of remuneration processes:
    • Governance over executive remuneration (remuneration committee oversight).
    • Consistency with remuneration policy and legislative requirements.
  • Testing for:
    • Errors or manipulation in bonus calculations.
    • Undisclosed benefits or related‑party transactions.

In UNISA exams, you may be required to evaluate a case where executive bonuses are high despite poor long‑term performance, and comment on how internal audit can assess remuneration governance.

Principle 15: Assurance and Combined Assurance

Wording (summary):
“The governing body should ensure that assurance services and functions enable an effective control environment, and that these support the integrity of information for internal decision‑making and external reporting purposes.”

Key ideas:

  • Combined assurance model: Coordination of assurance providers to ensure:

    • All key risks are covered.
    • Duplication is reduced.
    • Assurance gaps are avoided.
  • Levels of assurance (commonly):

    1. Management (line management, self‑assessments).
    2. Internal specialist functions (risk, compliance, health and safety, quality).
    3. Internal audit.
    4. External assurance providers (external audit, regulators, certification bodies).

Internal audit’s central role:

  • Internal audit typically facilitates or coordinates combined assurance:

    • Maintains assurance maps that show who provides assurance over which risks.
    • Provides an overarching view to the audit committee.
  • Internal audit remains independent:

    • Coordinates, but does not manage other assurance functions.
    • Uses information from other providers but performs its own risk‑based work.

Exam link (AUI3703 & AUI2602):
You must be able to define combined assurance, explain its benefits, and describe internal audit’s role in designing, implementing and maintaining a combined assurance approach.

Principle 16: Stakeholder Relationships

Wording (summary):
“In the execution of its governance role and responsibilities, the governing body should adopt a stakeholder‑inclusive approach that balances the needs, interests and expectations of material stakeholders in the best interests of the organisation over time.”

Key points:

  • Stakeholder identification and classification (materiality).
  • Stakeholder engagement strategies and channels.
  • Managing stakeholder expectations and relationships.
  • Measuring and reporting on stakeholder perceptions.

Internal audit activities:

  • Review stakeholder engagement policies and strategies.
  • Evaluate whether:
    • Stakeholder views are considered in decision‑making.
    • Engagement processes are fair, inclusive and transparent.
    • Claims made about stakeholder relationships in reports are accurate.

Examples:

  • Auditing customer complaints processes to ensure they are effective and responsive.
  • Auditing community engagement processes for mining or infrastructure projects.
  • Confirming that employee engagement surveys are used to improve working conditions.

Principle 17: Responsible Investment and Institutional Investors (For Institutional Investors, Foundations and Endowments)

While often less central for corporate entities, Principle 17 is important for:

  • Institutional investors (e.g. pension funds).
  • Foundations and endowments.

Wording (summary):
“The governing body of an institutional investor organisation should ensure that responsible investment is practised by the organisation to promote good governance and the creation of value by the companies in which it invests.”

Internal audit relevance (particularly for retirement funds and asset managers):

  • Evaluate:
    • Policies on ESG integration into investment decisions.
    • Active ownership practices (voting, engagement with investee companies).
  • Ensure compliance with:
    • Regulation 28 of the Pension Funds Act.
    • Stewardship codes or responsible investment principles.

For a UNISA BCom Internal Auditing student who may work in a retirement fund environment, understanding how responsible investment ties into King IV is important for auditing investment governance and ESG practices.

3. Sector Supplements and Public Sector/SME Contexts

King IV’s sector supplements provide tailored guidance for different types of organisations. Internal auditors must understand these nuances, especially those studying or working in public sector internal audit, SMEs or NPOs.

3.1 SME Supplement: Proportionality and Practicality

SMEs (small and medium enterprises) often have limited resources and simpler structures. King IV recognises this and emphasises proportionality:

Key SME governance features:

  • Governance structures may be less formal:
    • Owner‑manager may act as both CEO and de facto governing body.
    • No separate board committees due to size.
  • Documentation may be less extensive but still needs to demonstrate application of principles.

Implications for internal audit (including outsourced or co‑sourced arrangements):

  • Focus on material risks and pragmatic controls (e.g. segregation of duties may not be fully achievable, so compensating controls are vital).
  • Governance assessments should:
    • Consider scalability – “fit for purpose”.
    • Focus on ethical culture (Principle 1–3) and risk management (Principle 11) as foundations.

Examples:

  • A family‑owned manufacturing SME:
    • Might not have a formal risk committee, but holds quarterly management meetings reviewing key risks and performance.
    • Internal audit can verify these meetings, assess whether risks are recorded and tracked, and recommend formalisation where necessary.

In exam answers, emphasise that King IV principles are universal, but practices can be scaled according to size and complexity.

3.2 NPO Supplement: Mission‑Driven Governance

Non‑profit organisations (NPOs) have specific governance challenges:

  • Mission and purpose replace profit as the primary goal.
  • Funding often comes from donors, grants and fundraising activities.
  • High expectations of transparency and accountability.

Governance focus:

  • Strong ethics and responsible corporate citizenship (Principles 1–3).
  • Stakeholder and beneficiary engagement (Principle 16).
  • Accountability to donors and regulators (Principles 5 & 13).

Internal audit’s role:

  • Assurance over:
    • Use of funds for intended purposes.
    • Compliance with donor conditions and NPO regulations.
    • Fraud risks (e.g. in procurement, grant disbursement).
  • Evaluate governance structures:
    • Board of trustees, advisory boards, committees.

UNISA BCom Internal Auditing graduates working in NGOs need to interpret King IV in a mission‑centric environment and tailor audit engagements accordingly.

3.3 State‑Owned Entities and Public Sector: Alignment with PFMA/MFMA

The SOE Supplement is particularly relevant for South African internal auditors in:

  • National and provincial public entities (PFMA).
  • Municipalities and municipal entities (MFMA).
  • State‑owned companies.

Key public sector governance considerations:

  • The governing body (board) is accountable not only to shareholders but also to:
    • Parliament or provincial legislatures.
    • The public and wider stakeholders.
  • Strong emphasis on:
    • Compliance with PFMA/MFMA and Treasury Regulations.
    • Public accountability and transparency.
    • Effective use of public resources.

Internal audit in public sector (often examined in UNISA modules and professional certifications like the Certified Government Auditing Professional (CGAP)):

  • Must align with:
    • International Standards for the Professional Practice of Internal Auditing.
    • PFMA/MFMA internal audit requirements.
  • Plays a critical role in:
    • Assessing governance, risk management and internal control.
    • Supporting the audit committee established in terms of PFMA/MFMA.
    • Coordinating combined assurance with Auditor‑General South Africa (AGSA) and other oversight bodies.

King IV public sector emphasis:

  • Ethics and anti‑corruption (Principles 1–3 and 13).
  • Transparent procurement and contract management (Principle 13 and risk governance).
  • Effective use of public funds and performance management (Principle 4 & 5).
  • Stakeholder engagement, including communities and oversight structures (Principle 16).

Exam application:
You may be required to compare King IV’s SOE governance recommendations with PFMA/MFMA requirements and discuss internal audit’s role in bridging gaps.

3.4 Retirement Funds: King IV and Fund Governance

Retirement funds are another key sector:

  • Trustees are fiduciaries for members’ retirement savings.
  • Governance must ensure:
    • Compliance with the Pension Funds Act and Regulation 28.
    • Responsible investment practices (Principle 17).
    • Fair treatment of members.

Internal audit’s involvement:

  • Assurance over:
    • Contribution and benefit payment processes.
    • Investment management controls.
    • Outsourced administration and investment providers.
  • Review how the board of trustees applies King IV principles in governing the fund.

This sector is often included in UNISA advanced internal auditing or assurance modules where students are exposed to fund governance and regulatory frameworks.

4. Internal Audit’s Role under King IV

King IV significantly shapes what is expected from internal auditors. In courses like UNISA AUI3703, AUI3701, AUI2602 and similar internal auditing modules at CUT (e.g. IAD370), students must be able to integrate King IV with the IIA Standards and practical internal audit activities.

4.1 Positioning Internal Audit within Governance

King IV views internal audit as a key governance function:

  • Integral to the system of assurance and internal control (Principles 6, 11, 15).
  • Must be independent and objective, reporting functionally to the audit committee.

Key governance features of internal audit:

  • Internal audit charter:
    • Approved by the audit committee.
    • Defines purpose, authority, responsibilities and independence.
  • Organisational independence:
    • Chief Audit Executive (CAE) reports functionally to the audit committee and administratively to the CEO or similar high‑level executive.
  • Risk‑based internal audit plan:
    • Approved by the audit committee.
    • Aligned with strategic and key operational risks.

Exam scenario:
You may be asked to specify how the internal audit function should be structured in a King IV‑compliant governance environment, including reporting lines, authority and relationship with other assurance providers.

4.2 Risk‑Based Planning Aligned with King IV Principles

Internal audit must ensure that its planning reflects King IV’s focus areas:

  • Conduct an audit universe and risk assessment covering:

    • Governance processes (board, committees, strategy, ethics).
    • Core operations and support functions.
    • IT and information governance.
    • Compliance and legal requirements.
    • Stakeholder relationships and reporting.
  • Map key King IV principles to areas of audit coverage:

    • Ethics and compliance audits (Principles 1–3, 13).
    • Governance structure and board effectiveness reviews (Principles 6–10).
    • ERM and risk management audits (Principle 11).
    • IT governance and cybersecurity audits (Principle 12).
    • Combined assurance evaluations (Principle 15).
    • Stakeholder relationship audits (Principle 16).

Practical example:

  • For a manufacturing company:
    • Key strategic risks: production disruptions, safety incidents, environmental compliance.
    • King IV alignment:
      • Risk governance (Principle 11): audit ERM processes regarding safety and environmental risks.
      • Technology (Principle 12): audit SCADA and production systems.
      • Corporate citizenship (Principle 3): audit environmental and community impact reporting.

UNISA exam questions may ask you to draft a high‑level risk‑based internal audit plan, explicitly linking audit projects to King IV principles.

4.3 Internal Audit Engagements Focused on Governance

Governance audits are central to King IV. Key engagement types:

  1. Board and Committee Effectiveness Reviews

    • Objectives:
      • Assess whether the governing body and its committees operate as intended.
    • Procedures:
      • Review charters and compliance with them.
      • Analyse minutes, agendas, packs and attendance.
      • Interview board and management.
      • Evaluate information quality (is the board getting the right information at the right time?).
    • Link to Principles:
      • 6, 7, 8, 9, 10, 11.
  2. Ethics and Culture Audits

    • Objectives:
      • Evaluate existence and effectiveness of ethics management framework.
    • Procedures:
      • Review code of ethics and supporting policies.
      • Analyse whistle‑blowing data and disciplinary cases.
      • Conduct surveys and interviews.
    • Link to Principles:
      • 1, 2, 3, 13.
  3. Corporate Reporting Assurance

    • Objectives:
      • Provide comfort on reliability of data in integrated and sustainability reports.
    • Procedures:
      • Test controls over data collection and aggregation.
      • Trace reported KPIs back to source systems.
    • Link to Principles:
      • 4, 5, 15.
  4. Combined Assurance Assessments

    • Objectives:
      • Determine whether combined assurance is coordinated and effective.
    • Procedures:
      • Map assurance providers to material risks.
      • Identify gaps and overlaps.
      • Evaluate the role of the audit committee in overseeing combined assurance.
    • Link to Principle:
      • 15 (and 11).

When answering exam questions, emphasise the need for systematic, documented internal audit methodologies, aligned with the IIA Standards, but also clearly referencing relevant King IV principles.

4.4 Reporting and Communicating Governance Findings

Internal audit’s reporting must support the governing body and audit committee in fulfilling their King IV responsibilities:

  • Reports should:

    • Highlight governance, risk and control implications.
    • Link findings to specific King IV principles and outcomes.
    • Distinguish between:
      • Control deficiencies.
      • Design weaknesses in governance frameworks.
      • Culture and behavioural issues.
  • The CAE should provide an overall opinion on:

    • Effectiveness of governance, risk management and internal control.
    • Adequacy of combined assurance.
    • Any significant governance failures or breakdowns.

Example of governance reporting:

  • An internal audit of the ethics framework finds:
    • Code of ethics exists but training is ad hoc and not mandatory.
    • Whistle‑blower hotline is not well communicated.
    • Management sometimes ignores recommendations from ethics investigations.
  • The report must tie this back to Principles 1 and 2, emphasising the risk to ethical culture and corporate reputation.

4.5 Safeguarding Internal Audit Independence Under King IV

Internal audit must avoid taking on management responsibilities, which would impair independence:

  • It may advise on:
    • The design of governance frameworks.
    • Drafting policies and charters (with clear boundaries).
  • It should not:
    • Approve or implement governance structures.
    • Own risk management processes.
    • Take primary responsibility for combined assurance; instead, it coordinates and provides assurance.

In exam essays, show awareness that King IV expects internal audit to be a trusted advisor while maintaining its assurance role and independence, consistent with the IIA Code of Ethics and Attribute Standards (particularly Standards 1100–1130).

5. Exam‑Focused Application: Typical Questions and How to Answer Them

For UNISA BCom Internal Auditing students (especially AUI3703), understanding theory is not enough; you must be able to apply King IV in scenario‑based and essay questions.

5.1 Common Exam Themes and Angles

  1. Compare King III and King IV in the context of internal audit.
  2. Explain the “apply and explain” approach and its implications for assurance.
  3. Discuss internal audit’s role in assessing ethics, risk governance, or combined assurance.
  4. Analyse case studies where governance failures occurred and link them to specific King IV principles.
  5. Design an internal audit plan or specific engagement that addresses King IV governance requirements.

5.2 Constructing High‑Quality Exam Answers

When answering King IV exam questions:

  • Start with a clear statement of the relevant principle(s) and intended governance outcome(s).
  • Show understanding of the context: public vs private sector, SME vs large listed company, NPO vs commercial enterprise.
  • Highlight the role of internal audit:
    • What assurance is needed?
    • What audits should be performed?
    • How should results be reported?

Example:

Question: “Discuss how the internal audit function of a public sector entity can support the audit committee in fulfilling its oversight responsibilities in terms of King IV and PFMA.”

High‑level answer structure:

  1. Identify relevant King IV principles:

    • Principle 6 (governing body as custodian of governance).
    • Principle 11 (risk governance).
    • Principle 15 (combined assurance).
    • Principles 1–3 (ethics and corporate citizenship).
  2. Explain public sector context:

    • PFMA requirements for audit committees and internal audit.
    • Accountability to Parliament and the public.
  3. Describe internal audit’s support:

    • Risk‑based audit plans aligned with strategic objectives and PFMA risks.
    • Governance audits (board, committee effectiveness, ethics).
    • Combined assurance mapping including Auditor‑General South Africa.
    • Regular reporting and escalation of significant findings.
  4. Conclude by linking back to the outcomes:

    • Ethical culture, effective control, good performance and legitimacy.

5.3 Integrating King IV with the IIA Standards in Answers

King IV and the IIA Standards are complementary:

  • IIA Definition of Internal Auditing: assurance and consulting activity designed to add value and improve operations by evaluating and improving governance, risk management and control.
  • King IV emphasises:
    • Governance structures and roles (Principles 6–10).
    • Risk governance (Principle 11).
    • Combined assurance (Principle 15).

When exam questions mention both frameworks:

  • Show that:
    • Internal audit evaluates and improves governance, risk and control (IIA Standards 2100–2130) in line with King IV principles.
    • The internal audit charter and planning process reflect King IV expectations and the IIA Standards for independence, proficiency, quality assurance etc.

For example, in a question about combined assurance, reference:

  • King IV Principle 15: requirement for coordinated assurance.
  • IIA Standards: internal audit’s role in coordination but not management of other assurance functions.

5.4 Case Study Practice: Applying King IV to Realistic Scenarios

Consider a typical UNISA‑style case:

Scenario:
A medium‑sized manufacturing company, GreenSteel (Pty) Ltd, has experienced repeated safety incidents and environmental fines. The board has an audit committee but no separate risk or social and ethics committee. The CEO also chairs the board. Integrated reporting is minimal, and stakeholders complain about poor communication.

Required:
“As the internal auditor, identify at least five King IV principles that are not being adequately applied and recommend how internal audit can assist management and the governing body to address these deficiencies.”

Approach:

  • Identify principles:

    1. Principle 1 – Ethical and effective leadership: CEO as board chair; potential lack of independent oversight.
    2. Principle 3 – Corporate citizenship: environmental fines indicate poor citizenship.
    3. Principle 6–8 – Governing body and committees: concentration of roles; no dedicated risk or social and ethics committee.
    4. Principle 11 – Risk governance: safety and environmental risks not effectively managed.
    5. Principle 16 – Stakeholder relationships: poor communication and engagement.
  • Recommend internal audit actions:

    • Conduct governance review assessing board structure, independence and committee adequacy.
    • Perform ethics and corporate citizenship audit focusing on environmental and safety compliance.
    • Evaluate ERM process and risk registers for operational safety risks.
    • Facilitate combined assurance mapping (e.g. safety officers, environmental consultants, external auditors).
    • Review stakeholder engagement processes and disclosures in integrated reporting.

This style of application demonstrates not only knowledge of King IV but also the value‑adding role of internal audit.

5.5 Linking to Specific UNISA and South African University Modules

King IV content is examined across various South African university courses:

  • UNISA:

    • AUI3703: Corporate Governance in Internal Auditing – deep coverage of King IV, governance structures, and internal audit’s role.
    • AUI2602: Internal Auditing: Theory and Practice – introduction to corporate governance and King principles.
    • AUE3702: Auditing – Governance and Control – external audit perspective, but significant overlap.
    • BCom Internal Auditing final‑year integrated modules – case studies requiring application of King IV in complex environments.
  • Central University of Technology (CUT):

    • Internal auditing and governance content appears in modules like IAD370 and IT governance modules such as CNS445 (where IT governance and King IV Principle 12 are relevant).
  • Other universities (e.g. TUT, NWU, UJ):

    • Corporate governance content in internal auditing and auditing modules, similarly aligned to King IV.

Students should:

  • Review past exam papers and study guides for these modules, noting how King IV is tested.
  • Practice writing structured, principle‑linked answers, always connecting governance points to internal audit responsibilities.

By understanding King IV’s 17 principles, sector supplements and its outcomes‑based, stakeholder‑inclusive philosophy, internal auditors—especially those in UNISA’s BCom Internal Auditing stream—are better positioned to design risk‑based audit plans, execute governance‑focused engagements, and provide high‑impact reports. This aligns both with academic requirements and the expectations of South African organisations implementing King IV in practice.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare