3.8 Internal Audit, Control Limitations & the Risk of Over-Dependence on IT
Key Takeaways
- ICAB Syllabus 2023 names internal audit as a component of internal control and requires candidates to identify the fundamental principles of effective control systems and the risk of over-dependence on IT.
- Internal audit is an internal monitoring function appointed by and reporting to the entity; external audit is a statutory function appointed by the members and reporting to them.
- Internal audit's effectiveness depends on organisational independence, which is protected by a reporting line to the audit committee rather than to the finance director.
- The external auditor may use internal audit work only after evaluating its objectivity, competence and systematic approach, and retains sole responsibility for the audit opinion.
- Over-dependence on IT creates risks including unauthorised access, systematic repetition of a single processing error, loss of audit trail, and reliance on automated controls that fail when general IT controls are weak.
Internal Audit, Control Limitations & the Risk of Over-Dependence on IT
ICAB Syllabus 2023 lists internal audit explicitly among the components of internal control that candidates must identify, alongside the overall control environment and preventative and detective controls. It separately requires candidates to identify "the fundamental principles of effective control systems and the risk of over-dependence on IT." Both topics are examined in scenario form.
1. Internal audit as a monitoring control
Internal audit is an appraisal activity established within an entity as a service to the entity. It forms part of the monitoring of controls component: it performs the separate evaluations that complement management's ongoing monitoring.
Typical internal audit assignments:
| Assignment type | What it involves |
|---|---|
| Financial controls review | Testing the operation of controls over the main transaction cycles |
| Operational / value-for-money audit | Examining economy, efficiency and effectiveness of an activity |
| IT audit | Reviewing access controls, change management and application controls |
| Compliance audit | Testing adherence to laws, regulations and internal policies |
| Fraud investigation | Investigating suspected irregularities on management's instruction |
| Cash and inventory counts | Unannounced verification of high-risk assets |
Why independence matters and how it is protected
Internal auditors are employees. That creates an inherent tension: they are reviewing colleagues, and their pay and promotion sit inside the organisation they audit. The safeguards that make the function credible are structural:
- Reporting line. The head of internal audit should report functionally to the audit committee or the board, not to the finance director whose controls are being tested. Reporting to the finance director is the single most common weakness in an exam scenario.
- Unrestricted scope and access. A charter approved by the audit committee giving access to all records, assets and personnel.
- No operational responsibility. Internal auditors must not design, operate or approve the controls they later review; doing so creates a self-review problem inside the entity.
- Appointment and removal. The head of internal audit should be appointed and removed by the audit committee.
- Adequate resourcing and competence. Sufficient qualified staff and continuing training.
Under the BSEC Corporate Governance Code 2018, listed issuers in Bangladesh are required to have a head of internal audit and compliance, and the audit committee reviews internal audit's findings — a structural safeguard that appears in Bangladeshi scenarios.
2. Internal audit compared with external audit
This comparison is a recurring examination item.
| Feature | Internal audit | External audit |
|---|---|---|
| Appointed by | Management / audit committee | Members at the AGM (Companies Act 1994, s. 210) |
| Reports to | Audit committee and management | The members (s. 213) |
| Objective | Improve the entity's operations, risk management and controls | Express an opinion on whether the financial statements are free from material misstatement |
| Scope | Determined by management or the audit committee; can cover anything | Determined by statute and auditing standards; limited to matters affecting the financial statements |
| Status | Usually employees of the entity | Independent firm outside the entity |
| Qualification | No statutory qualification requirement | Must be a chartered accountant, not disqualified under s. 212 |
| Legal basis | Contractual or governance requirement | Statutory |
| Continuity | Ongoing throughout the year | Periodic, focused on the reporting period |
Note the shared feature that candidates often miss: both need objectivity and competence, and both use substantially the same techniques — inquiry, observation, inspection, reperformance and analytical procedures.
3. Using the work of internal audit
The external auditor may use internal audit's work to obtain audit evidence, or may request direct assistance where permitted. Before doing so, the external auditor must evaluate three things:
- Objectivity — the organisational status and reporting line, and whether policies protect internal audit from bias.
- Competence — qualifications, training, experience and resources.
- Systematic and disciplined approach — including quality control, documented methodology and planned work programmes.
Even after using internal audit's work, the external auditor remains solely responsible for the audit opinion. The external auditor must reperform some of the work used and must not delegate significant judgements. Internal audit's work is never used for areas involving significant judgement or a high assessed risk of material misstatement.
4. The risk of over-dependence on IT
Effective control systems increasingly rely on IT. The syllabus requires candidates to recognise that this dependence itself carries risk.
| Risk of over-dependence on IT | Why it matters | Mitigating control |
|---|---|---|
| Systematic error | A manual error affects one transaction; a coding error repeats identically across every transaction it touches, so a small logic flaw becomes a material misstatement. | Rigorous user acceptance testing; change management controls; periodic reperformance of automated calculations |
| Unauthorised access | Remote and concurrent access means an intruder or an over-privileged employee can alter data and cover their tracks. | Role-based access, multi-factor authentication, prompt revocation on leaving, privileged-access review |
| Loss of audit trail | Data overwritten rather than posted, or records deleted, leaves no evidence of what happened. | Immutable audit logs, restricted delete rights, log review |
| Loss of segregation of duties | A single ERP super-user role can span authorisation, custody and recording. | Segregation-of-duties conflict reports; restricted super-user accounts with logged use |
| System failure and business interruption | Total dependence means an outage halts processing and can lose data. | Tested backups, disaster recovery plan, business continuity plan |
| Reliance on automated controls with weak GITCs | An automated three-way match is worthless if programmers can change the code unchecked. | Test general IT controls before placing reliance on any automated control |
| Over-reliance on system output as "evidence" | Staff and auditors treat a system-generated report as inherently reliable. | Verify the report's completeness and accuracy — its parameters and underlying data — before using it |
That last row is worth emphasising. A report produced by the client's system is internally generated evidence. Its reliability depends on the controls over the system that produced it. Auditors must establish the completeness and accuracy of information produced by the entity before relying on it, whether for a substantive test or a control test.
5. Inherent limitations that no control system overcomes
Even a well-designed, IT-enabled control system delivers only reasonable assurance because of limitations that are structural rather than fixable:
- Human judgement and error in the design and operation of controls.
- Collusion between two or more people, which defeats segregation of duties.
- Management override, where those responsible for the system deliberately circumvent it.
- Cost-benefit constraints, which stop management implementing every conceivable control.
- Non-routine transactions, for which routine controls were never designed.
Management override is the limitation most relevant to the auditor, because it is the one that no control activity can prevent and the reason substantive procedures can never be eliminated entirely.
In a listed Bangladeshi manufacturer, the head of internal audit reports directly to the Chief Financial Officer, who is also responsible for the financial controls internal audit tests. What is the principal consequence?
Which risk is uniquely amplified when an entity becomes heavily dependent on automated processing rather than manual processing?
Before placing reliance on the work of an entity's internal audit function, what must the external auditor evaluate, and what remains unchanged?