Is Internal Auditing part of a Company’s control environment?
Yes, it is part of the 3rd line of defense.
Is an Internal Audit Department required under SOX?
No, but in order for management to do independent testing of Internal Controls over Management Reporting they need a separate department in order to do so. Including a department that can do testing outside of ICFR.
What standards do internal auditors use?
Institute of Internal Audit Standards (IIA)
What type of audits does Internal Auditors Perform for a Company?
Financial Audit Control Testing
Compliance Control Testing
IT Testing of systems directly or indirectly associated with financial reporting
Operational performance reviews.
When does internal Audit become effectively required?
While not legally required, Internal Audit becomes practically necessary when:
* The company is an accelerated filer with complex operations
* There are multiple locations or decentralized processes
* The control environment is immature or has prior deficiencies
* The audit committee expects independent assurance
* Management lacks bandwidth to perform ICFR testing themselves