Evaluating the effectiveness of internal audit
functions in detecting and preventing fraud
Introduction
Fraud has become a growing threat to businesses worldwide with increasing sophistication of
fraudulent activities. According to the Association of Certified Fraud Examiners' (ACFE) 2020
Report to the Nations, the estimated typical organization loses 5% of its annual revenues to
fraud. Detecting and preventing fraud is crucial not only to curb losses but also protect
organizational reputation and stakeholder trust.
Internal audit functions play a pivotal role in organizations' fraud risk management framework
through their oversight and assurance activities. However, there is ongoing debate around how
effective internal auditors are in uncovering fraud schemes and risks. This paper aims to
evaluate the effectiveness of internal audit functions in detecting and preventing organizational
fraud through a review of relevant literature and framework.
The paper is structured as follows. Section 2 discusses the role and responsibilities of internal
audit in fraud risk management. Section 3 reviews literature on factors impacting internal audit
effectiveness. Section 4 outlines a proposed framework for evaluation. Section 5 discusses
available techniques and Section 6 concludes with recommendations.
Role of Internal Audit in Fraud Risk Management
As the third line of defense, internal audit provides independent assurance that risk
management, control and governance processes function effectively to mitigate fraud and other
risks. Key tasks related to fraud include:
- Assessing the design and effectiveness of antifraud controls, programs, policies and culture.
- Conducting risk-based audits of high fraud risk areas, testing controls and analyzing
anomalies.
- Investigating allegations of fraud objectively and promptly referring to law enforcement.
- Monitoring corrective actions and progress of management's remediation efforts.
- Escalating significant fraud-related issues to audit committee and senior management.
However, internal audit's fraud detection role faces inherent challenges due to limitations of
scope, resources and reliance on management cooperation (Wells, 2017). Further, audits
cannot provide an absolute guarantee on detecting concealed frauds (PricewaterhouseCoopers,
2012).
Factors Impacting Internal Audit Effectiveness
Various organizational and individual factors impact internal audit effectiveness in fulfilling its
fraud responsibilities. Well-documented factors include:
- Level of Independence: Truly independent status, reporting and resourcing enhances
objectivity and candor needed to tackle sensitive fraud issues (Ziek, 2016).
- Competency and Skills: Auditors require specialized skills, continuing training and experience
in forensic techniques to detect well-planned frauds (Carcello et al., 2005).
- Resourcing and Budget: Sufficient budget allows extensive fraud risk assessments, data
analytics capability and deeper audits (IIA, 2017).
- Management Support: Active backing and cooperation from management in sharing risks,
controls gaps and whistleblower cases improves effectiveness (Wells, 2017).
- Strategy and Planning: Risk-focused, intelligence-led strategic plans targeting the highest risks
strengthen proactiveness instead of reactiveness (Bartlett, 2014).
- Communication: Robust two-way coordination with operational teams, regulators and external
auditors bolsters overall control ecosystem (AECOM, 2015).
Proposed Framework to Evaluate Effectiveness
To systematically evaluate internal audit effectiveness, a robust framework is needed
incorporating quality criteria and measurable indicators. Figure 1 proposes such a framework
consisting of three broad elements:
1. Structural Factors:
- Independence
- Resources
- Skills and competency
- Strategic planning
2. Process Factors:
- Risk assessments
- Audit testing methodology
- Investigations process
- Reporting quality
- Communication
- Monitoring of actions
3. Outcome Factors:
- Identified weaknesses and instances of detected/prevented fraud
- Audit recommendations adoption rate
- Management and board satisfaction
- External feedback and recognition
Each element would comprise dimensions that can be objectively rated on a defined scoring
scale. Periodic self-assessments and independent assessments would provide insights into
areas requiring improvements. The next section discusses available assessment techniques.
Techniques for Evaluation
There are established techniques available to audit functions for evaluating effectiveness:
1. Surveys: Anonymous surveys of operational managers and auditees assess perceptions on
quality, usefulness and value-add of internal audit activities (AECOM, 2015).
2. Metrics and Benchmarking: Measuring metrics like audit coverage, open recommendations,
fraud cases reported and timeliness of audits allows benchmarking over time and against peers
(IIA, 2018).
3. Internal Assessments: Periodic self-assessments against frameworks and compliance
reviews test conformity with audit charter, methodology standards and code of conduct
(PricewaterhouseCoopers, 2019).
4. External Assessments: Independent external quality assessments provide objective
verification of conformance with International Standards for the Professional Practice of Internal
Auditing (ISPPIA) (IIA, 2021).
5. Forensic Data Analytics: Evaluating use of continuous monitoring techniques, data
matching/mining to identify anomalies and benchmarking against industry benchmarks gauges
innovation (KPMG, 2017).
6. Stakeholder Interviews: One-on-one discussions with board, executives and regulators
provide unbiased feedback on perception and value of audit role (Deloitte, 2014).
Combining both qualitative and quantitative evaluation methods at regular intervals helps audit
functions identify gaps, prioritize enhancements and demonstrate effectiveness.
Recommendations and Conclusion
Based on the review and proposed framework, the following recommendations can strengthen
effectiveness of internal audit in detecting and preventing fraud:
- Bolster audit skills through specialized forensic training, certification and experience.
- Secure sufficient budget for advanced tools, benchmarking and independent quality
assessments.
- Maintain independence through direct reporting to board and separate resourcing.
- Enhance fraud risk assessments using horizon scanning techniques and external data
sources.
- Adopt proactive monitoring approach leveraging continuous controls, data analytics.
- Gain management collaboration to address control deficiencies and whistleblower concerns.
- Benchmark performance using customized metrics and peer/industry standards.
- Engage regulators and external auditors through periodic coordination meetings.
While internal audit cannot guarantee all frauds will be found, establishing a robust evaluation
framework drives a strategic risk-based approach aligned with global standards. This equips
functions to fulfill expectations cost-effectively and strengthen governance in organizations
facing intensifying fraud challenges.
Fraud has become a growing threat to businesses worldwide with increasing sophistication of
fraudulent activities. According to the Association of Certified Fraud Examiners' (ACFE) 2020
Report to the Nations, the estimated typical organization loses 5% of its annual revenues to
fraud. Detecting and preventing fraud is crucial not only to curb losses but also protect
organizational reputation and stakeholder trust.
Internal audit functions play a pivotal role in organizations' fraud risk management framework
through their oversight and assurance activities. However, there is ongoing debate around how
effective internal auditors are in uncovering fraud schemes and risks. This paper aims to
evaluate the effectiveness of internal audit functions in detecting and preventing organizational
fraud through a review of relevant literature and framework.
The paper is structured as follows. Section 2 discusses the role and responsibilities of internal
audit in fraud risk management. Section 3 reviews literature on factors impacting internal audit
effectiveness. Section 4 outlines a proposed framework for evaluation. Section 5 discusses
available techniques and Section 6 concludes with recommendations.
Role of Internal Audit in Fraud Risk Management
As the third line of defense, internal audit provides independent assurance that risk
management, control and governance processes function effectively to mitigate fraud and other
risks. Key tasks related to fraud include:
- Assessing the design and effectiveness of antifraud controls, programs, policies and culture.
- Conducting risk-based audits of high fraud risk areas, testing controls and analyzing
anomalies.
- Investigating allegations of fraud objectively and promptly referring to law enforcement.
- Monitoring corrective actions and progress of management's remediation efforts.
- Escalating significant fraud-related issues to audit committee and senior management.
However, internal audit's fraud detection role faces inherent challenges due to limitations of
scope, resources and reliance on management cooperation (Wells, 2017). Further, audits
cannot provide an absolute guarantee on detecting concealed frauds (PricewaterhouseCoopers,
2012).
Factors Impacting Internal Audit Effectiveness
Various organizational and individual factors impact internal audit effectiveness in fulfilling its
fraud responsibilities. Well-documented factors include:
- Level of Independence: Truly independent status, reporting and resourcing enhances
objectivity and candor needed to tackle sensitive fraud issues (Ziek, 2016).
- Competency and Skills: Auditors require specialized skills, continuing training and experience
in forensic techniques to detect well-planned frauds (Carcello et al., 2005).
- Resourcing and Budget: Sufficient budget allows extensive fraud risk assessments, data
analytics capability and deeper audits (IIA, 2017).
- Management Support: Active backing and cooperation from management in sharing risks,
controls gaps and whistleblower cases improves effectiveness (Wells, 2017).
- Strategy and Planning: Risk-focused, intelligence-led strategic plans targeting the highest risks
strengthen proactiveness instead of reactiveness (Bartlett, 2014).
- Communication: Robust two-way coordination with operational teams, regulators and external
auditors bolsters overall control ecosystem (AECOM, 2015).
Proposed Framework to Evaluate Effectiveness
To systematically evaluate internal audit effectiveness, a robust framework is needed
incorporating quality criteria and measurable indicators. Figure 1 proposes such a framework
consisting of three broad elements:
1. Structural Factors:
- Independence
- Resources
- Skills and competency
- Strategic planning
2. Process Factors:
- Risk assessments
- Audit testing methodology
- Investigations process
- Reporting quality
- Communication
- Monitoring of actions
3. Outcome Factors:
- Identified weaknesses and instances of detected/prevented fraud
- Audit recommendations adoption rate
- Management and board satisfaction
- External feedback and recognition
Each element would comprise dimensions that can be objectively rated on a defined scoring
scale. Periodic self-assessments and independent assessments would provide insights into
areas requiring improvements. The next section discusses available assessment techniques.
Techniques for Evaluation
There are established techniques available to audit functions for evaluating effectiveness:
1. Surveys: Anonymous surveys of operational managers and auditees assess perceptions on
quality, usefulness and value-add of internal audit activities (AECOM, 2015).
2. Metrics and Benchmarking: Measuring metrics like audit coverage, open recommendations,
fraud cases reported and timeliness of audits allows benchmarking over time and against peers
(IIA, 2018).
3. Internal Assessments: Periodic self-assessments against frameworks and compliance
reviews test conformity with audit charter, methodology standards and code of conduct
(PricewaterhouseCoopers, 2019).
4. External Assessments: Independent external quality assessments provide objective
verification of conformance with International Standards for the Professional Practice of Internal
Auditing (ISPPIA) (IIA, 2021).
5. Forensic Data Analytics: Evaluating use of continuous monitoring techniques, data
matching/mining to identify anomalies and benchmarking against industry benchmarks gauges
innovation (KPMG, 2017).
6. Stakeholder Interviews: One-on-one discussions with board, executives and regulators
provide unbiased feedback on perception and value of audit role (Deloitte, 2014).
Combining both qualitative and quantitative evaluation methods at regular intervals helps audit
functions identify gaps, prioritize enhancements and demonstrate effectiveness.
Recommendations and Conclusion
Based on the review and proposed framework, the following recommendations can strengthen
effectiveness of internal audit in detecting and preventing fraud:
- Bolster audit skills through specialized forensic training, certification and experience.
- Secure sufficient budget for advanced tools, benchmarking and independent quality
assessments.
- Maintain independence through direct reporting to board and separate resourcing.
- Enhance fraud risk assessments using horizon scanning techniques and external data
sources.
- Adopt proactive monitoring approach leveraging continuous controls, data analytics.
- Gain management collaboration to address control deficiencies and whistleblower concerns.
- Benchmark performance using customized metrics and peer/industry standards.
- Engage regulators and external auditors through periodic coordination meetings.
While internal audit cannot guarantee all frauds will be found, establishing a robust evaluation
framework drives a strategic risk-based approach aligned with global standards. This equips
functions to fulfill expectations cost-effectively and strengthen governance in organizations
facing intensifying fraud challenges.
Fraud has become a growing threat to businesses worldwide with increasing sophistication of
fraudulent activities. According to the Association of Certified Fraud Examiners' (ACFE) 2020
Report to the Nations, the estimated typical organization loses 5% of its annual revenues to
fraud. Detecting and preventing fraud is crucial not only to curb losses but also protect
organizational reputation and stakeholder trust.
Internal audit functions play a pivotal role in organizations' fraud risk management framework
through their oversight and assurance activities. However, there is ongoing debate around how
effective internal auditors are in uncovering fraud schemes and risks. This paper aims to
evaluate the effectiveness of internal audit functions in detecting and preventing organizational
fraud through a review of relevant literature and framework.
The paper is structured as follows. Section 2 discusses the role and responsibilities of internal
audit in fraud risk management. Section 3 reviews literature on factors impacting internal audit
effectiveness. Section 4 outlines a proposed framework for evaluation. Section 5 discusses
available techniques and Section 6 concludes with recommendations.
Role of Internal Audit in Fraud Risk Management
As the third line of defense, internal audit provides independent assurance that risk
management, control and governance processes function effectively to mitigate fraud and other
risks. Key tasks related to fraud include:
- Assessing the design and effectiveness of antifraud controls, programs, policies and culture.
- Conducting risk-based audits of high fraud risk areas, testing controls and analyzing
anomalies.
- Investigating allegations of fraud objectively and promptly referring to law enforcement.
- Monitoring corrective actions and progress of management's remediation efforts.
- Escalating significant fraud-related issues to audit committee and senior management.
However, internal audit's fraud detection role faces inherent challenges due to limitations of
scope, resources and reliance on management cooperation (Wells, 2017). Further, audits
cannot provide an absolute guarantee on detecting concealed frauds (PricewaterhouseCoopers,
2012).
Factors Impacting Internal Audit Effectiveness
Various organizational and individual factors impact internal audit effectiveness in fulfilling its
fraud responsibilities. Well-documented factors include:
- Level of Independence: Truly independent status, reporting and resourcing enhances
objectivity and candor needed to tackle sensitive fraud issues (Ziek, 2016).
- Competency and Skills: Auditors require specialized skills, continuing training and experience
in forensic techniques to detect well-planned frauds (Carcello et al., 2005).
- Resourcing and Budget: Sufficient budget allows extensive fraud risk assessments, data
analytics capability and deeper audits (IIA, 2017).
- Management Support: Active backing and cooperation from management in sharing risks,
controls gaps and whistleblower cases improves effectiveness (Wells, 2017).
- Strategy and Planning: Risk-focused, intelligence-led strategic plans targeting the highest risks
strengthen proactiveness instead of reactiveness (Bartlett, 2014).
- Communication: Robust two-way coordination with operational teams, regulators and external
auditors bolsters overall control ecosystem (AECOM, 2015).
Proposed Framework to Evaluate Effectiveness
To systematically evaluate internal audit effectiveness, a robust framework is needed
incorporating quality criteria and measurable indicators. Figure 1 proposes such a framework
consisting of three broad elements:
1. Structural Factors:
- Independence
- Resources
- Skills and competency
- Strategic planning
2. Process Factors:
- Risk assessments
- Audit testing methodology
- Investigations process
- Reporting quality
- Communication
- Monitoring of actions
3. Outcome Factors:
- Identified weaknesses and instances of detected/prevented fraud
- Audit recommendations adoption rate
- Management and board satisfaction
- External feedback and recognition
Each element would comprise dimensions that can be objectively rated on a defined scoring
scale. Periodic self-assessments and independent assessments would provide insights into
areas requiring improvements. The next section discusses available assessment techniques.
Techniques for Evaluation
There are established techniques available to audit functions for evaluating effectiveness:
1. Surveys: Anonymous surveys of operational managers and auditees assess perceptions on
quality, usefulness and value-add of internal audit activities (AECOM, 2015).
2. Metrics and Benchmarking: Measuring metrics like audit coverage, open recommendations,
fraud cases reported and timeliness of audits allows benchmarking over time and against peers
(IIA, 2018).
3. Internal Assessments: Periodic self-assessments against frameworks and compliance
reviews test conformity with audit charter, methodology standards and code of conduct
(PricewaterhouseCoopers, 2019).
4. External Assessments: Independent external quality assessments provide objective
verification of conformance with International Standards for the Professional Practice of Internal
Auditing (ISPPIA) (IIA, 2021).
5. Forensic Data Analytics: Evaluating use of continuous monitoring techniques, data
matching/mining to identify anomalies and benchmarking against industry benchmarks gauges
innovation (KPMG, 2017).
6. Stakeholder Interviews: One-on-one discussions with board, executives and regulators
provide unbiased feedback on perception and value of audit role (Deloitte, 2014).
Combining both qualitative and quantitative evaluation methods at regular intervals helps audit
functions identify gaps, prioritize enhancements and demonstrate effectiveness.
Recommendations and Conclusion
Based on the review and proposed framework, the following recommendations can strengthen
effectiveness of internal audit in detecting and preventing fraud:
- Bolster audit skills through specialized forensic training, certification and experience.
- Secure sufficient budget for advanced tools, benchmarking and independent quality
assessments.
- Maintain independence through direct reporting to board and separate resourcing.
- Enhance fraud risk assessments using horizon scanning techniques and external data
sources.
- Adopt proactive monitoring approach leveraging continuous controls, data analytics.
- Gain management collaboration to address control deficiencies and whistleblower concerns.
- Benchmark performance using customized metrics and peer/industry standards.
- Engage regulators and external auditors through periodic coordination meetings.
While internal audit cannot guarantee all frauds will be found, establishing a robust evaluation
framework drives a strategic risk-based approach aligned with global standards. This equips
functions to fulfill expectations cost-effectively and strengthen governance in organizations
facing intensifying fraud challenges.
Fraud has become a growing threat to businesses worldwide with increasing sophistication of
fraudulent activities. According to the Association of Certified Fraud Examiners' (ACFE) 2020
Report to the Nations, the estimated typical organization loses 5% of its annual revenues to
fraud. Detecting and preventing fraud is crucial not only to curb losses but also protect
organizational reputation and stakeholder trust.
Internal audit functions play a pivotal role in organizations' fraud risk management framework
through their oversight and assurance activities. However, there is ongoing debate around how
effective internal auditors are in uncovering fraud schemes and risks. This paper aims to
evaluate the effectiveness of internal audit functions in detecting and preventing organizational
fraud through a review of relevant literature and framework.
The paper is structured as follows. Section 2 discusses the role and responsibilities of internal
audit in fraud risk management. Section 3 reviews literature on factors impacting internal audit
effectiveness. Section 4 outlines a proposed framework for evaluation. Section 5 discusses
available techniques and Section 6 concludes with recommendations.
Role of Internal Audit in Fraud Risk Management
As the third line of defense, internal audit provides independent assurance that risk
management, control and governance processes function effectively to mitigate fraud and other
risks. Key tasks related to fraud include:
- Assessing the design and effectiveness of antifraud controls, programs, policies and culture.
- Conducting risk-based audits of high fraud risk areas, testing controls and analyzing
anomalies.
- Investigating allegations of fraud objectively and promptly referring to law enforcement.
- Monitoring corrective actions and progress of management's remediation efforts.
- Escalating significant fraud-related issues to audit committee and senior management.
However, internal audit's fraud detection role faces inherent challenges due to limitations of
scope, resources and reliance on management cooperation (Wells, 2017). Further, audits
cannot provide an absolute guarantee on detecting concealed frauds (PricewaterhouseCoopers,
2012).
Factors Impacting Internal Audit Effectiveness
Various organizational and individual factors impact internal audit effectiveness in fulfilling its
fraud responsibilities. Well-documented factors include:
- Level of Independence: Truly independent status, reporting and resourcing enhances
objectivity and candor needed to tackle sensitive fraud issues (Ziek, 2016).
- Competency and Skills: Auditors require specialized skills, continuing training and experience
in forensic techniques to detect well-planned frauds (Carcello et al., 2005).
- Resourcing and Budget: Sufficient budget allows extensive fraud risk assessments, data
analytics capability and deeper audits (IIA, 2017).
- Management Support: Active backing and cooperation from management in sharing risks,
controls gaps and whistleblower cases improves effectiveness (Wells, 2017).
- Strategy and Planning: Risk-focused, intelligence-led strategic plans targeting the highest risks
strengthen proactiveness instead of reactiveness (Bartlett, 2014).
- Communication: Robust two-way coordination with operational teams, regulators and external
auditors bolsters overall control ecosystem (AECOM, 2015).
Proposed Framework to Evaluate Effectiveness
To systematically evaluate internal audit effectiveness, a robust framework is needed
incorporating quality criteria and measurable indicators. Figure 1 proposes such a framework
consisting of three broad elements:
1. Structural Factors:
- Independence
- Resources
- Skills and competency
- Strategic planning
2. Process Factors:
- Risk assessments
- Audit testing methodology
- Investigations process
- Reporting quality
- Communication
- Monitoring of actions
3. Outcome Factors:
- Identified weaknesses and instances of detected/prevented fraud
- Audit recommendations adoption rate
- Management and board satisfaction
- External feedback and recognition
Each element would comprise dimensions that can be objectively rated on a defined scoring
scale. Periodic self-assessments and independent assessments would provide insights into
areas requiring improvements. The next section discusses available assessment techniques.
Techniques for Evaluation
There are established techniques available to audit functions for evaluating effectiveness:
1. Surveys: Anonymous surveys of operational managers and auditees assess perceptions on
quality, usefulness and value-add of internal audit activities (AECOM, 2015).
2. Metrics and Benchmarking: Measuring metrics like audit coverage, open recommendations,
fraud cases reported and timeliness of audits allows benchmarking over time and against peers
(IIA, 2018).
3. Internal Assessments: Periodic self-assessments against frameworks and compliance
reviews test conformity with audit charter, methodology standards and code of conduct
(PricewaterhouseCoopers, 2019).
4. External Assessments: Independent external quality assessments provide objective
verification of conformance with International Standards for the Professional Practice of Internal
Auditing (ISPPIA) (IIA, 2021).
5. Forensic Data Analytics: Evaluating use of continuous monitoring techniques, data
matching/mining to identify anomalies and benchmarking against industry benchmarks gauges
innovation (KPMG, 2017).
6. Stakeholder Interviews: One-on-one discussions with board, executives and regulators
provide unbiased feedback on perception and value of audit role (Deloitte, 2014).
Combining both qualitative and quantitative evaluation methods at regular intervals helps audit
functions identify gaps, prioritize enhancements and demonstrate effectiveness.
Recommendations and Conclusion
Based on the review and proposed framework, the following recommendations can strengthen
effectiveness of internal audit in detecting and preventing fraud:
- Bolster audit skills through specialized forensic training, certification and experience.
- Secure sufficient budget for advanced tools, benchmarking and independent quality
assessments.
- Maintain independence through direct reporting to board and separate resourcing.
- Enhance fraud risk assessments using horizon scanning techniques and external data
sources.
- Adopt proactive monitoring approach leveraging continuous controls, data analytics.
- Gain management collaboration to address control deficiencies and whistleblower concerns.
- Benchmark performance using customized metrics and peer/industry standards.
- Engage regulators and external auditors through periodic coordination meetings.
While internal audit cannot guarantee all frauds will be found, establishing a robust evaluation
framework drives a strategic risk-based approach aligned with global standards. This equips
functions to fulfill expectations cost-effectively and strengthen governance in organizations
facing intensifying fraud challenges.
Fraud has become a growing threat to businesses worldwide with increasing sophistication of
fraudulent activities. According to the Association of Certified Fraud Examiners' (ACFE) 2020
Report to the Nations, the estimated typical organization loses 5% of its annual revenues to
fraud. Detecting and preventing fraud is crucial not only to curb losses but also protect
organizational reputation and stakeholder trust.
Internal audit functions play a pivotal role in organizations' fraud risk management framework
through their oversight and assurance activities. However, there is ongoing debate around how
effective internal auditors are in uncovering fraud schemes and risks. This paper aims to
evaluate the effectiveness of internal audit functions in detecting and preventing organizational
fraud through a review of relevant literature and framework.
The paper is structured as follows. Section 2 discusses the role and responsibilities of internal
audit in fraud risk management. Section 3 reviews literature on factors impacting internal audit
effectiveness. Section 4 outlines a proposed framework for evaluation. Section 5 discusses
available techniques and Section 6 concludes with recommendations.
Role of Internal Audit in Fraud Risk Management
As the third line of defense, internal audit provides independent assurance that risk
management, control and governance processes function effectively to mitigate fraud and other
risks. Key tasks related to fraud include:
- Assessing the design and effectiveness of antifraud controls, programs, policies and culture.
- Conducting risk-based audits of high fraud risk areas, testing controls and analyzing
anomalies.
- Investigating allegations of fraud objectively and promptly referring to law enforcement.
- Monitoring corrective actions and progress of management's remediation efforts.
- Escalating significant fraud-related issues to audit committee and senior management.
However, internal audit's fraud detection role faces inherent challenges due to limitations of
scope, resources and reliance on management cooperation (Wells, 2017). Further, audits
cannot provide an absolute guarantee on detecting concealed frauds (PricewaterhouseCoopers,
2012).
Factors Impacting Internal Audit Effectiveness
Various organizational and individual factors impact internal audit effectiveness in fulfilling its
fraud responsibilities. Well-documented factors include:
- Level of Independence: Truly independent status, reporting and resourcing enhances
objectivity and candor needed to tackle sensitive fraud issues (Ziek, 2016).
- Competency and Skills: Auditors require specialized skills, continuing training and experience
in forensic techniques to detect well-planned frauds (Carcello et al., 2005).
- Resourcing and Budget: Sufficient budget allows extensive fraud risk assessments, data
analytics capability and deeper audits (IIA, 2017).
- Management Support: Active backing and cooperation from management in sharing risks,
controls gaps and whistleblower cases improves effectiveness (Wells, 2017).
- Strategy and Planning: Risk-focused, intelligence-led strategic plans targeting the highest risks
strengthen proactiveness instead of reactiveness (Bartlett, 2014).
- Communication: Robust two-way coordination with operational teams, regulators and external
auditors bolsters overall control ecosystem (AECOM, 2015).
Proposed Framework to Evaluate Effectiveness
To systematically evaluate internal audit effectiveness, a robust framework is needed
incorporating quality criteria and measurable indicators. Figure 1 proposes such a framework
consisting of three broad elements:
1. Structural Factors:
- Independence
- Resources
- Skills and competency
- Strategic planning
2. Process Factors:
- Risk assessments
- Audit testing methodology
- Investigations process
- Reporting quality
- Communication
- Monitoring of actions
3. Outcome Factors:
- Identified weaknesses and instances of detected/prevented fraud
- Audit recommendations adoption rate
- Management and board satisfaction
- External feedback and recognition
Each element would comprise dimensions that can be objectively rated on a defined scoring
scale. Periodic self-assessments and independent assessments would provide insights into
areas requiring improvements. The next section discusses available assessment techniques.
Techniques for Evaluation
There are established techniques available to audit functions for evaluating effectiveness:
1. Surveys: Anonymous surveys of operational managers and auditees assess perceptions on
quality, usefulness and value-add of internal audit activities (AECOM, 2015).
2. Metrics and Benchmarking: Measuring metrics like audit coverage, open recommendations,
fraud cases reported and timeliness of audits allows benchmarking over time and against peers
(IIA, 2018).
3. Internal Assessments: Periodic self-assessments against frameworks and compliance
reviews test conformity with audit charter, methodology standards and code of conduct
(PricewaterhouseCoopers, 2019).
4. External Assessments: Independent external quality assessments provide objective
verification of conformance with International Standards for the Professional Practice of Internal
Auditing (ISPPIA) (IIA, 2021).
5. Forensic Data Analytics: Evaluating use of continuous monitoring techniques, data
matching/mining to identify anomalies and benchmarking against industry benchmarks gauges
innovation (KPMG, 2017).
6. Stakeholder Interviews: One-on-one discussions with board, executives and regulators
provide unbiased feedback on perception and value of audit role (Deloitte, 2014).
Combining both qualitative and quantitative evaluation methods at regular intervals helps audit
functions identify gaps, prioritize enhancements and demonstrate effectiveness.
Recommendations and Conclusion
Based on the review and proposed framework, the following recommendations can strengthen
effectiveness of internal audit in detecting and preventing fraud:
- Bolster audit skills through specialized forensic training, certification and experience.
- Secure sufficient budget for advanced tools, benchmarking and independent quality
assessments.
- Maintain independence through direct reporting to board and separate resourcing.
- Enhance fraud risk assessments using horizon scanning techniques and external data
sources.
- Adopt proactive monitoring approach leveraging continuous controls, data analytics.
- Gain management collaboration to address control deficiencies and whistleblower concerns.
- Benchmark performance using customized metrics and peer/industry standards.
- Engage regulators and external auditors through periodic coordination meetings.
While internal audit cannot guarantee all frauds will be found, establishing a robust evaluation
framework drives a strategic risk-based approach aligned with global standards. This equips
functions to fulfill expectations cost-effectively and strengthen governance in organizations
facing intensifying fraud challenges.