9.1 Internal Control System and Internal Audit Function

Key Takeaways

  • Under the SEC Code of Corporate Governance for Publicly-Listed Companies (SEC MC No. 19, Series of 2016), the Board of Directors is ultimately responsible for ensuring the establishment and maintenance of an adequate and effective internal control system and Enterprise Risk Management (ERM) framework.

  • The standard internal control framework adopted in the Philippines follows the Committee of Sponsoring Organizations of the Treadway Commission (COSO) model, comprising five interrelated components: Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring Activities.

  • The internal audit function maintains dual reporting lines to preserve independence and operational efficiency: functionally reporting directly to the Board Audit Committee and administratively reporting to the Chief Executive Officer.

  • The Chief Audit Executive (CAE) must be an independent corporate officer appointed by the Board upon recommendation of the Audit Committee, possessing recognized professional competence (such as CPA or CIA credentials) and free from operational management duties.

  • Under SRC Rule 68 (as amended), publicly listed companies must rotate their external independent lead and concurring audit partners at least once every five (5) consecutive years, followed by a mandatory two-year cooling-off period, while strict independence rules prohibit the external audit firm from providing concurrent non-audit services such as internal audit outsourcing or financial information systems design.

Last updated: October 2026

9.1 Internal Control System and Internal Audit Function

A robust internal control architecture and an objective internal audit function form the first two lines of defense in corporate governance. Under the Securities Regulation Code (SRC / Republic Act No. 8799) and the Code of Corporate Governance for Publicly-Listed Companies (SEC Memorandum Circular No. 19, Series of 2016), public companies in the Philippines must establish institutional controls that safeguard company assets, ensure reliable financial reporting, optimize operational efficiency, and enforce compliance with applicable statutory mandates.

For securities market professionals, compliance officers, and capital market participants, evaluating internal control mechanisms is vital. Capital allocation decisions and public market valuations rely directly on the credibility of corporate disclosures, which in turn depends on the rigor of the internal control environment and independent audit oversight.


The Governance Architecture: Board Oversight and ERM

Corporate governance principles establish that while management designs and executes day-to-day internal controls, the Board of Directors bears ultimate accountability for ensuring an effective internal control system and Enterprise Risk Management (ERM) framework.

The Three Lines of Defense Model

Modern corporate governance operates under the widely recognized "Three Lines of Defense" governance model:

  1. First Line (Operational Management): Front-line operational leaders and business unit managers who own and directly manage operational, financial, and regulatory risks on a daily basis.
  2. Second Line (Risk Management & Compliance): Specialized functions such as Enterprise Risk Management (ERM), legal, and compliance officers who establish risk policies, monitor risk profiles, and facilitate enterprise-wide risk frameworks.
  3. Third Line (Internal Audit): An independent, objective assurance function that provides comprehensive, unbiased assessments of the effectiveness of the first two lines directly to the Board Audit Committee.

Enterprise Risk Management (ERM)

Under Recommendation 2.11 of the SEC Code of Corporate Governance for PLCs, the board must oversee the implementation of an ERM framework. For publicly listed companies with high risk profiles, the SEC recommends establishing a standalone Board Risk Oversight Committee (BROC) to handle enterprise-level risks, including financial risk, operational risk, credit risk, market risk, liquidity risk, IT/cybersecurity risk, and reputational risk.


The COSO Internal Control Integrated Framework

The Securities and Exchange Commission (SEC) recognizes the framework established by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) as the standard benchmark for designing, implementing, and assessing internal control systems. The COSO model establishes five interrelated components:

                    ┌────────────────────────────────────────┐
                    │          Control Environment           │
                    ├────────────────────────────────────────┤
                    │            Risk Assessment             │
                    ├────────────────────────────────────────┤
                    │           Control Activities           │
                    ├────────────────────────────────────────┤
                    │      Information & Communication       │
                    ├────────────────────────────────────────┤
                    │          Monitoring Activities         │
                    └────────────────────────────────────────┘

1. Control Environment

The control environment sets the "tone at the top" and provides the ethical foundation for the entire enterprise. It encompasses:

  • The integrity, ethical values, and conduct of the board and senior executive management;
  • Board independence from management and active oversight by the Audit Committee;
  • Organizational structure, defined reporting lines, and clear assignment of authority and responsibility;
  • Commitment to attracting, developing, and retaining competent personnel;
  • Enforcement of accountability across all organizational levels through performance metrics and disciplinary policies.

2. Risk Assessment

Risk assessment involves an ongoing, iterative process for identifying, analyzing, and managing risks that threaten the achievement of corporate objectives:

  • Risk Identification: Systematically cataloging operational, strategic, financial reporting, and statutory compliance hazards;
  • Risk Evaluation: Assessing the likelihood and potential economic or regulatory impact of identified risks;
  • Risk Appetite: Establishing management's tolerance for risk in pursuit of corporate strategy;
  • Fraud Risk Assessment: Explicitly assessing the vulnerabilities of the organization to fraudulent financial reporting, asset misappropriation, and unauthorized transactions.

3. Control Activities

Control activities are the specific policies, procedures, and directives established by management to mitigate risks to acceptable levels. They include:

  • Preventive Controls: Designed to deter errors or irregularities before they occur (e.g., dual-authorization requirements, biometric access controls, segregation of duties);
  • Detective Controls: Designed to uncover errors or unauthorized actions after occurrence (e.g., monthly bank reconciliations, physical inventory counts, budget variance reviews);
  • Segregation of Incompatible Duties: Ensuring that custody of assets, authorization of transactions, execution of trades, and accounting recordkeeping are assigned to distinct individuals to prevent undetected fraud or error;
  • IT Controls: General IT controls (system security, change management, data backup) and application controls (input validation, error-checking algorithms).

4. Information and Communication

Timely, accurate, and relevant financial and non-financial information must be identified, captured, and communicated across the organization:

  • Internal Communication: Vertical and horizontal transmission of operational instructions, accounting data, and compliance guidelines;
  • External Communication: Accurate and timely dissemination of material disclosures to regulators (SEC, PSE), shareholders, creditors, and market intermediaries;
  • Whistleblower Channels: Confidential, secure channels enabling employees to report suspected accounting irregularities or internal control deficiencies without fear of retaliation.

5. Monitoring Activities

Internal control systems must be continuously monitored to verify that each of the five components remains present and functioning:

  • Ongoing Evaluations: Routine management monitoring built into regular operational and financial cycles;
  • Separate Evaluations: Periodic, structured reviews conducted by the internal audit department or external consultants;
  • Deficiency Reporting: Timely reporting of control failures and material weaknesses directly to executive management and the Audit Committee for corrective intervention.

The Internal Audit Function and the Chief Audit Executive (CAE)

The internal audit function provides independent, objective assurance and consulting services designed to add value and improve corporate operations. Recommendation 12.3 of the SEC Code of Corporate Governance for PLCs mandates that publicly listed companies establish an independent internal audit function.

Dual-Reporting Structure

To protect the internal auditor from executive management intimidation while ensuring seamless operational support, Philippine governance mandates a dual-reporting structure:

DimensionFunctional ReportingAdministrative Reporting
Reporting LineBoard Audit CommitteeChief Executive Officer (CEO)
Core PurposeDirect oversight of audit independence and findingsDay-to-day operational administration
Charter & PlanningApproves Internal Audit Charter and annual risk-based audit planFacilitates enterprise-wide resource access
Audit EvaluationReviews, evaluates, and acts on substantive audit findingsCoordinates interdepartmental cooperation
Personnel ActionsAppoints, dismisses, and determines compensation of the CAEManages internal human resources and administrative logistics
Budget & ResourcesReviews adequacy of internal audit resources and budgetApproves day-to-day operational expenses and travel

Qualifications and Role of the Chief Audit Executive (CAE)

The CAE heads the internal audit department. Under SEC governance rules:

  • The CAE is appointed by the Board of Directors upon the formal endorsement of the Audit Committee;
  • The CAE should possess recognized professional qualifications, typically as a Certified Public Accountant (CPA) or Certified Internal Auditor (CIA), with demonstrated competence in risk-based audit methodologies;
  • The CAE must have direct, unrestricted access to the Audit Committee and the full Board of Directors;
  • Objectivity & Operational Disqualification: The CAE and internal audit staff must remain free from operational management duties. An internal auditor cannot audit operational areas or systems for which they had operational or managerial responsibility within the preceding twelve (12) months.

External Auditor Oversight and Auditor Independence

While internal audit operates within the corporation, the independent external auditor provides external market verification, issuing an independent audit opinion on the fairness of the company's financial statements under Philippine Standards on Auditing (PSA).

Role of the Board Audit Committee

Under Recommendation 3.2 and 9.3 of the Code of Corporate Governance for PLCs, the Audit Committee exercises primary oversight over the external auditor:

  • Formulating policies on the selection, appointment, reappointment, and replacement of the independent external auditor;
  • Reviewing and approving the annual external audit engagement letter, audit plan, scope, and proposed audit fees;
  • Assessing the external auditor's independence, professional competence, and objectivity prior to formal nomination to the shareholders.

Mandatory Rotation of Lead Audit Partners under SRC Rule 68

To prevent familiarity threats from compromising audit skepticism, the SEC enforces strict auditor rotation requirements under SRC Rule 68 (Rules and Regulations on Financial Statements):

  Engagement Period: Maximum 5 Consecutive Years
  ┌────────────────────────────────────────────────────────┐
  │ Year 1 │ Year 2 │ Year 3 │ Year 4 │ Year 5 (MANDATORY) │
  └────────────────────────────────────────────────────────┘
                             │
                             ▼
             Cooling-off Period: Minimum 2 Years
             ┌────────────────────────┐
             │ Year 6 (Off) │ Year 7  │
             └────────────────────────┘
  • Partner Rotation, Not Firm Rotation: The mandatory rotation applies to the lead audit partner and the concurring (reviewing) partner. The audit firm itself may be retained, provided the engagement partners are rotated;
  • 5-Year Maximum Term: The lead and concurring partners cannot handle the audit of a publicly listed company for more than five (5) consecutive years;
  • 2-Year Cooling-Off Period: After completing five consecutive years, the rotated partner must undergo a mandatory cooling-off period of at least two (2) consecutive years before being reassigned to the engagement.

Prohibited Non-Audit Services

To safeguard external auditor independence in fact and in appearance, SRC Rule 68 and the Code of Ethics for Professional Accountants in the Philippines prohibit external audit firms from providing non-audit services that create self-review threats, advocacy threats, or operational conflicts of interest.

Prohibited Non-Audit ServiceGovernance Rationale
Bookkeeping & Accounting RecordsCreates an impermissible self-review threat by auditing records prepared by the firm
Financial Information Systems DesignSelf-review threat; auditing IT systems designed or configured by the firm's consultants
Valuation, Appraisal & Fairness OpinionsMaterial subjectivity; auditing values calculated by the firm's own valuation team
Internal Audit Outsourcing / Co-sourcingBlurs management lines; the external auditor cannot audit internal controls they designed
Actuarial ServicesRelies on proprietary estimates directly impacting audited balance sheet liabilities
Management Functions & Executive RecruitmentAssuming management decision-making destroys independence and objective skepticism
Broker-Dealer or Investment Advisory ServicesActing as financial promoter or broker aligns auditor incentives with share price performance
Legal Services & Expert AdvocacyServing as legal counsel or advocacy witness places the auditor in an adversarial advocacy role

Comparison: Internal Audit vs. External Audit

DimensionInternal Audit FunctionExternal Audit Function
Primary ObjectiveEvaluate internal controls, risk management, and governance efficiencyExpress an independent audit opinion on financial statement fairness
Primary Reporting LineFunctionally to Audit Committee; administratively to CEOIndependent report to Shareholders and the Board Audit Committee
Independence ScopeIndependent within the corporate hierarchyFully independent of the client entity (external third-party)
Governing StandardsInternational Standards for the Professional Practice of Internal Auditing (IIA)Philippine Standards on Auditing (PSA) / International Standards on Auditing
Regulatory BasisSEC Code of Corporate Governance for PLCs (SEC MC No. 19-2016)Securities Regulation Code (SRC Rule 68) & Revised Corporation Code
Rotation RuleNo statutory rotation requirement for staff; periodic reassignmentMandatory 5-year rotation for lead and concurring partners (2-year cooling-off)
Operational RolesProhibited from operational line functions; advisory and assurance onlyStrictly prohibited from management and operational functions

Practical Exam Traps and Regulatory Pitfalls

  • Trap 1: Confusing Functional and Administrative Reporting. Examination questions frequently suggest that the Chief Audit Executive reports directly to the Chief Financial Officer (CFO) or Chief Operating Officer (COO). This is an immediate red flag. The CAE must functionally report to the Audit Committee and administratively to the CEO to prevent auditee interference.
  • Trap 2: Audit Firm Rotation vs. Audit Partner Rotation. A common trick states that publicly listed corporations must replace their independent public accounting firm every 5 years. This is incorrect. Under SRC Rule 68, the lead and concurring audit partners must rotate every five consecutive years, not the auditing firm itself.
  • Trap 3: Permissible Non-Audit Services. An exam item may ask whether an external auditor can assist the company by temporarily managing its internal audit department or designing its financial reporting database. Both are strictly prohibited non-audit services that compromise auditor independence.
  • Trap 4: Audit Committee Composition. Candidates must remember that under SEC governance rules, the Audit Committee must be composed exclusively of non-executive directors, a majority of whom (including the Chairman) must be independent directors.
Test Your Knowledge

Under SRC Rule 68 (as amended) and SEC corporate governance rules, what is the mandatory rotation requirement for the external lead audit partner of a Philippine publicly listed company?

A

The lead and concurring audit partners must be rotated at least once every five (5) consecutive years, followed by a mandatory two-year cooling-off period.

B

The external audit firm itself must be replaced by a different independent accounting firm every three (3) consecutive years.

C

The lead audit partner must rotate every seven (7) consecutive years, with no mandatory cooling-off period if the firm is retained.

D

External audit partner rotation is strictly voluntary and left to the discretion of the Board Audit Committee.

Test Your Knowledge

To preserve independence and objectivity, to whom does the Chief Audit Executive (CAE) of a Philippine publicly listed company directly report?

A

Functionally to the Chief Operating Officer and administratively to the Chief Financial Officer.

B

Functionally to the Board Audit Committee and administratively to the Chief Executive Officer.

C

Exclusively to the External Independent Auditor on all technical and operational matters.

D

Solely to the Chairman of the Board with no administrative connection to executive management.

Test Your Knowledge

Under the SEC Code of Corporate Governance for Publicly-Listed Companies and SRC Rule 68, which of the following non-audit services is strictly prohibited from being provided by the corporation's external independent auditor?

A

Providing formal training on newly promulgated Philippine Financial Reporting Standards (PFRS) to corporate finance staff.

B

Performing standard quarterly financial reviews alongside annual statutory audit work.

C

Designing and implementing the company's internal financial information systems and performing outsourced internal audit functions.

D

Issuing comfort letters and review reports in connection with secondary capital market equity offerings.

Sections you finish are checked off in the contents.