9.1 Internal Control System and Internal Audit Function
Key Takeaways
Under the SEC Code of Corporate Governance for Publicly-Listed Companies (SEC MC No. 19, Series of 2016), the Board of Directors is ultimately responsible for ensuring the establishment and maintenance of an adequate and effective internal control system and Enterprise Risk Management (ERM) framework.
The standard internal control framework adopted in the Philippines follows the Committee of Sponsoring Organizations of the Treadway Commission (COSO) model, comprising five interrelated components: Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring Activities.
The internal audit function maintains dual reporting lines to preserve independence and operational efficiency: functionally reporting directly to the Board Audit Committee and administratively reporting to the Chief Executive Officer.
The Chief Audit Executive (CAE) must be an independent corporate officer appointed by the Board upon recommendation of the Audit Committee, possessing recognized professional competence (such as CPA or CIA credentials) and free from operational management duties.
Under SRC Rule 68 (as amended), publicly listed companies must rotate their external independent lead and concurring audit partners at least once every five (5) consecutive years, followed by a mandatory two-year cooling-off period, while strict independence rules prohibit the external audit firm from providing concurrent non-audit services such as internal audit outsourcing or financial information systems design.
9.1 Internal Control System and Internal Audit Function
A robust internal control architecture and an objective internal audit function form the first two lines of defense in corporate governance. Under the Securities Regulation Code (SRC / Republic Act No. 8799) and the Code of Corporate Governance for Publicly-Listed Companies (SEC Memorandum Circular No. 19, Series of 2016), public companies in the Philippines must establish institutional controls that safeguard company assets, ensure reliable financial reporting, optimize operational efficiency, and enforce compliance with applicable statutory mandates.
For securities market professionals, compliance officers, and capital market participants, evaluating internal control mechanisms is vital. Capital allocation decisions and public market valuations rely directly on the credibility of corporate disclosures, which in turn depends on the rigor of the internal control environment and independent audit oversight.
The Governance Architecture: Board Oversight and ERM
Corporate governance principles establish that while management designs and executes day-to-day internal controls, the Board of Directors bears ultimate accountability for ensuring an effective internal control system and Enterprise Risk Management (ERM) framework.
The Three Lines of Defense Model
Modern corporate governance operates under the widely recognized "Three Lines of Defense" governance model:
- First Line (Operational Management): Front-line operational leaders and business unit managers who own and directly manage operational, financial, and regulatory risks on a daily basis.
- Second Line (Risk Management & Compliance): Specialized functions such as Enterprise Risk Management (ERM), legal, and compliance officers who establish risk policies, monitor risk profiles, and facilitate enterprise-wide risk frameworks.
- Third Line (Internal Audit): An independent, objective assurance function that provides comprehensive, unbiased assessments of the effectiveness of the first two lines directly to the Board Audit Committee.
Enterprise Risk Management (ERM)
Under Recommendation 2.11 of the SEC Code of Corporate Governance for PLCs, the board must oversee the implementation of an ERM framework. For publicly listed companies with high risk profiles, the SEC recommends establishing a standalone Board Risk Oversight Committee (BROC) to handle enterprise-level risks, including financial risk, operational risk, credit risk, market risk, liquidity risk, IT/cybersecurity risk, and reputational risk.
The COSO Internal Control Integrated Framework
The Securities and Exchange Commission (SEC) recognizes the framework established by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) as the standard benchmark for designing, implementing, and assessing internal control systems. The COSO model establishes five interrelated components:
┌────────────────────────────────────────┐
│ Control Environment │
├────────────────────────────────────────┤
│ Risk Assessment │
├────────────────────────────────────────┤
│ Control Activities │
├────────────────────────────────────────┤
│ Information & Communication │
├────────────────────────────────────────┤
│ Monitoring Activities │
└────────────────────────────────────────┘
1. Control Environment
The control environment sets the "tone at the top" and provides the ethical foundation for the entire enterprise. It encompasses:
- The integrity, ethical values, and conduct of the board and senior executive management;
- Board independence from management and active oversight by the Audit Committee;
- Organizational structure, defined reporting lines, and clear assignment of authority and responsibility;
- Commitment to attracting, developing, and retaining competent personnel;
- Enforcement of accountability across all organizational levels through performance metrics and disciplinary policies.
2. Risk Assessment
Risk assessment involves an ongoing, iterative process for identifying, analyzing, and managing risks that threaten the achievement of corporate objectives:
- Risk Identification: Systematically cataloging operational, strategic, financial reporting, and statutory compliance hazards;
- Risk Evaluation: Assessing the likelihood and potential economic or regulatory impact of identified risks;
- Risk Appetite: Establishing management's tolerance for risk in pursuit of corporate strategy;
- Fraud Risk Assessment: Explicitly assessing the vulnerabilities of the organization to fraudulent financial reporting, asset misappropriation, and unauthorized transactions.
3. Control Activities
Control activities are the specific policies, procedures, and directives established by management to mitigate risks to acceptable levels. They include:
- Preventive Controls: Designed to deter errors or irregularities before they occur (e.g., dual-authorization requirements, biometric access controls, segregation of duties);
- Detective Controls: Designed to uncover errors or unauthorized actions after occurrence (e.g., monthly bank reconciliations, physical inventory counts, budget variance reviews);
- Segregation of Incompatible Duties: Ensuring that custody of assets, authorization of transactions, execution of trades, and accounting recordkeeping are assigned to distinct individuals to prevent undetected fraud or error;
- IT Controls: General IT controls (system security, change management, data backup) and application controls (input validation, error-checking algorithms).
4. Information and Communication
Timely, accurate, and relevant financial and non-financial information must be identified, captured, and communicated across the organization:
- Internal Communication: Vertical and horizontal transmission of operational instructions, accounting data, and compliance guidelines;
- External Communication: Accurate and timely dissemination of material disclosures to regulators (SEC, PSE), shareholders, creditors, and market intermediaries;
- Whistleblower Channels: Confidential, secure channels enabling employees to report suspected accounting irregularities or internal control deficiencies without fear of retaliation.
5. Monitoring Activities
Internal control systems must be continuously monitored to verify that each of the five components remains present and functioning:
- Ongoing Evaluations: Routine management monitoring built into regular operational and financial cycles;
- Separate Evaluations: Periodic, structured reviews conducted by the internal audit department or external consultants;
- Deficiency Reporting: Timely reporting of control failures and material weaknesses directly to executive management and the Audit Committee for corrective intervention.
The Internal Audit Function and the Chief Audit Executive (CAE)
The internal audit function provides independent, objective assurance and consulting services designed to add value and improve corporate operations. Recommendation 12.3 of the SEC Code of Corporate Governance for PLCs mandates that publicly listed companies establish an independent internal audit function.
Dual-Reporting Structure
To protect the internal auditor from executive management intimidation while ensuring seamless operational support, Philippine governance mandates a dual-reporting structure:
| Dimension | Functional Reporting | Administrative Reporting |
|---|---|---|
| Reporting Line | Board Audit Committee | Chief Executive Officer (CEO) |
| Core Purpose | Direct oversight of audit independence and findings | Day-to-day operational administration |
| Charter & Planning | Approves Internal Audit Charter and annual risk-based audit plan | Facilitates enterprise-wide resource access |
| Audit Evaluation | Reviews, evaluates, and acts on substantive audit findings | Coordinates interdepartmental cooperation |
| Personnel Actions | Appoints, dismisses, and determines compensation of the CAE | Manages internal human resources and administrative logistics |
| Budget & Resources | Reviews adequacy of internal audit resources and budget | Approves day-to-day operational expenses and travel |
Qualifications and Role of the Chief Audit Executive (CAE)
The CAE heads the internal audit department. Under SEC governance rules:
- The CAE is appointed by the Board of Directors upon the formal endorsement of the Audit Committee;
- The CAE should possess recognized professional qualifications, typically as a Certified Public Accountant (CPA) or Certified Internal Auditor (CIA), with demonstrated competence in risk-based audit methodologies;
- The CAE must have direct, unrestricted access to the Audit Committee and the full Board of Directors;
- Objectivity & Operational Disqualification: The CAE and internal audit staff must remain free from operational management duties. An internal auditor cannot audit operational areas or systems for which they had operational or managerial responsibility within the preceding twelve (12) months.
External Auditor Oversight and Auditor Independence
While internal audit operates within the corporation, the independent external auditor provides external market verification, issuing an independent audit opinion on the fairness of the company's financial statements under Philippine Standards on Auditing (PSA).
Role of the Board Audit Committee
Under Recommendation 3.2 and 9.3 of the Code of Corporate Governance for PLCs, the Audit Committee exercises primary oversight over the external auditor:
- Formulating policies on the selection, appointment, reappointment, and replacement of the independent external auditor;
- Reviewing and approving the annual external audit engagement letter, audit plan, scope, and proposed audit fees;
- Assessing the external auditor's independence, professional competence, and objectivity prior to formal nomination to the shareholders.
Mandatory Rotation of Lead Audit Partners under SRC Rule 68
To prevent familiarity threats from compromising audit skepticism, the SEC enforces strict auditor rotation requirements under SRC Rule 68 (Rules and Regulations on Financial Statements):
Engagement Period: Maximum 5 Consecutive Years
┌────────────────────────────────────────────────────────┐
│ Year 1 │ Year 2 │ Year 3 │ Year 4 │ Year 5 (MANDATORY) │
└────────────────────────────────────────────────────────┘
│
▼
Cooling-off Period: Minimum 2 Years
┌────────────────────────┐
│ Year 6 (Off) │ Year 7 │
└────────────────────────┘
- Partner Rotation, Not Firm Rotation: The mandatory rotation applies to the lead audit partner and the concurring (reviewing) partner. The audit firm itself may be retained, provided the engagement partners are rotated;
- 5-Year Maximum Term: The lead and concurring partners cannot handle the audit of a publicly listed company for more than five (5) consecutive years;
- 2-Year Cooling-Off Period: After completing five consecutive years, the rotated partner must undergo a mandatory cooling-off period of at least two (2) consecutive years before being reassigned to the engagement.
Prohibited Non-Audit Services
To safeguard external auditor independence in fact and in appearance, SRC Rule 68 and the Code of Ethics for Professional Accountants in the Philippines prohibit external audit firms from providing non-audit services that create self-review threats, advocacy threats, or operational conflicts of interest.
| Prohibited Non-Audit Service | Governance Rationale |
|---|---|
| Bookkeeping & Accounting Records | Creates an impermissible self-review threat by auditing records prepared by the firm |
| Financial Information Systems Design | Self-review threat; auditing IT systems designed or configured by the firm's consultants |
| Valuation, Appraisal & Fairness Opinions | Material subjectivity; auditing values calculated by the firm's own valuation team |
| Internal Audit Outsourcing / Co-sourcing | Blurs management lines; the external auditor cannot audit internal controls they designed |
| Actuarial Services | Relies on proprietary estimates directly impacting audited balance sheet liabilities |
| Management Functions & Executive Recruitment | Assuming management decision-making destroys independence and objective skepticism |
| Broker-Dealer or Investment Advisory Services | Acting as financial promoter or broker aligns auditor incentives with share price performance |
| Legal Services & Expert Advocacy | Serving as legal counsel or advocacy witness places the auditor in an adversarial advocacy role |
Comparison: Internal Audit vs. External Audit
| Dimension | Internal Audit Function | External Audit Function |
|---|---|---|
| Primary Objective | Evaluate internal controls, risk management, and governance efficiency | Express an independent audit opinion on financial statement fairness |
| Primary Reporting Line | Functionally to Audit Committee; administratively to CEO | Independent report to Shareholders and the Board Audit Committee |
| Independence Scope | Independent within the corporate hierarchy | Fully independent of the client entity (external third-party) |
| Governing Standards | International Standards for the Professional Practice of Internal Auditing (IIA) | Philippine Standards on Auditing (PSA) / International Standards on Auditing |
| Regulatory Basis | SEC Code of Corporate Governance for PLCs (SEC MC No. 19-2016) | Securities Regulation Code (SRC Rule 68) & Revised Corporation Code |
| Rotation Rule | No statutory rotation requirement for staff; periodic reassignment | Mandatory 5-year rotation for lead and concurring partners (2-year cooling-off) |
| Operational Roles | Prohibited from operational line functions; advisory and assurance only | Strictly prohibited from management and operational functions |
Practical Exam Traps and Regulatory Pitfalls
- Trap 1: Confusing Functional and Administrative Reporting. Examination questions frequently suggest that the Chief Audit Executive reports directly to the Chief Financial Officer (CFO) or Chief Operating Officer (COO). This is an immediate red flag. The CAE must functionally report to the Audit Committee and administratively to the CEO to prevent auditee interference.
- Trap 2: Audit Firm Rotation vs. Audit Partner Rotation. A common trick states that publicly listed corporations must replace their independent public accounting firm every 5 years. This is incorrect. Under SRC Rule 68, the lead and concurring audit partners must rotate every five consecutive years, not the auditing firm itself.
- Trap 3: Permissible Non-Audit Services. An exam item may ask whether an external auditor can assist the company by temporarily managing its internal audit department or designing its financial reporting database. Both are strictly prohibited non-audit services that compromise auditor independence.
- Trap 4: Audit Committee Composition. Candidates must remember that under SEC governance rules, the Audit Committee must be composed exclusively of non-executive directors, a majority of whom (including the Chairman) must be independent directors.
Under SRC Rule 68 (as amended) and SEC corporate governance rules, what is the mandatory rotation requirement for the external lead audit partner of a Philippine publicly listed company?
The lead and concurring audit partners must be rotated at least once every five (5) consecutive years, followed by a mandatory two-year cooling-off period.
The external audit firm itself must be replaced by a different independent accounting firm every three (3) consecutive years.
The lead audit partner must rotate every seven (7) consecutive years, with no mandatory cooling-off period if the firm is retained.
External audit partner rotation is strictly voluntary and left to the discretion of the Board Audit Committee.
To preserve independence and objectivity, to whom does the Chief Audit Executive (CAE) of a Philippine publicly listed company directly report?
Functionally to the Chief Operating Officer and administratively to the Chief Financial Officer.
Functionally to the Board Audit Committee and administratively to the Chief Executive Officer.
Exclusively to the External Independent Auditor on all technical and operational matters.
Solely to the Chairman of the Board with no administrative connection to executive management.
Under the SEC Code of Corporate Governance for Publicly-Listed Companies and SRC Rule 68, which of the following non-audit services is strictly prohibited from being provided by the corporation's external independent auditor?
Providing formal training on newly promulgated Philippine Financial Reporting Standards (PFRS) to corporate finance staff.
Performing standard quarterly financial reviews alongside annual statutory audit work.
Designing and implementing the company's internal financial information systems and performing outsourced internal audit functions.
Issuing comfort letters and review reports in connection with secondary capital market equity offerings.
Sections you finish are checked off in the contents.