Assurance · Tax · Advisory · Corporate · TechnologyPakistan · Gulf · UK · US · Canada+92-51-6138902WhatsAppinfo@mac.org.pk

Services / 02 — Internal audit & ICFR / SOX

A control that exists is not a control that works.

Outsourced and co-sourced internal audit, ICFR design and testing, SOX 404 readiness, COSO implementation and audit committee reporting.

Most control frameworks look adequate on paper. What decides whether they hold is evidence — that the control operated, every time, and that somebody can demonstrate it afterwards. Our team has tested controls to a standard a PCAOB-registered auditor subsequently relied upon.

Parent company asking for ICFR or SOX testing?

Group requirements usually arrive with a deadline and a template. Send us what the parent has asked for and we will tell you what it actually requires, and what it will take here.

IWhen clients call

The situations that bring people here

Our US-listed parent needs ICFR testing done here.

Testing performed to a standard the group's external auditor will rely on, coordinated with the parent's timetable.

The audit committee wants an internal audit function.

Outsourced or co-sourced, with a risk-based annual plan approved by the committee rather than assembled by management.

The same audit findings appear every year.

Recurring findings mean remediation was documented rather than implemented. That is a different problem from the finding itself.

We have grown and nobody redesigned the controls.

Controls that worked at thirty people fail at two hundred, usually at the approval and segregation points.

Something went wrong and we do not know how it got through.

Control gap analysis after an incident — what should have caught it, and why it did not.

We are preparing for a transaction and expect scrutiny.

Buyers and lenders test the control environment. Weaknesses found by them cost more than weaknesses found by you.

Our ERP went live and controls were an afterthought.

Access rights, segregation of duties and automated controls reviewed alongside the configuration.

A regulator or donor requires assurance over our processes.

Independent testing of specified processes, reported in the format the requesting party expects.

IIWhat we do

Scope of the internal audit and controls practice

Delivered by the assurance team, with IT general controls handled jointly with our technology practice.

01

Outsourced internal audit

A complete internal audit function for organisations that need one but should not build one.

  • Risk-based annual audit plan
  • Process and cycle audits
  • Operational and compliance audits
  • Fieldwork, testing and reporting
  • Follow-up on prior findings
  • Reporting directly to the audit committee
02

Co-sourced internal audit

Specialist capacity alongside an existing function, for the areas it cannot cover.

  • Specialist reviews — IT, treasury, procurement
  • Peak capacity support
  • Methodology and working paper design
  • Quality assessment of the existing function
  • Training and knowledge transfer
03

ICFR design and documentation

Establishing what the controls are before anyone can test whether they work.

  • Process narratives and flowcharts
  • Risk and control matrices
  • Key control identification
  • Entity-level control documentation
  • Segregation of duties analysis
  • Control gap identification
04

ICFR and SOX 404 testing

Design and operating effectiveness testing, evidenced to a standard an external auditor can rely on.

  • Design effectiveness assessment
  • Operating effectiveness testing
  • Sample selection and attribute testing
  • Deficiency evaluation and aggregation
  • Management assessment support under SOX 404(a)
  • Workpapers prepared for external auditor reliance
05

COSO implementation

The framework most groups require, applied to an organisation of your actual size.

  • COSO 2013 framework mapping
  • Five components and seventeen principles assessment
  • Entity-level control environment review
  • Control activity design
  • Monitoring activity design
06

Remediation support

The part that decides whether next year's testing produces the same findings.

  • Root cause analysis of deficiencies
  • Remediation plan design with named owners
  • Control redesign where the control was wrong
  • Retesting after remediation
  • Tracking to closure
07

IT general controls

Where financial reporting depends on systems — which is now everywhere.

  • Access management and user provisioning
  • Segregation of duties in the ERP
  • Change management controls
  • Backup, recovery and job scheduling
  • Automated control and interface testing
  • Alignment with ISO 27001, COBIT and NIST
08

Audit committee reporting

Reporting written for the people who have to act on it, not for the file.

  • Audit committee papers and presentations
  • Findings rated by risk with clear ownership
  • Management responses tracked
  • Annual internal audit opinion
  • Coordination with the external auditor
IIIWhere controls actually fail

Eight failure modes we find repeatedly

Almost none of them are the control being absent. Nearly all of them are the control existing and not working.

Failure modeWhat it looks like in practice
The control operates without evidenceSomeone genuinely reviews it — and nothing records that they did. Untestable is indistinguishable from absent, and it is the single most common finding we raise.
Approval is a signature, not a reviewThe approver has no practical means of knowing whether the item is right, and signs because the workflow requires it. The control is theatre.
One person holds the whole processSegregation broke informally — through a resignation, an illness, a system change — and was never restored. Usually the person is entirely trustworthy, which is why nobody looks.
System access outlives the rolePeople change jobs and keep permissions. Over a few years, senior staff accumulate access nobody would grant them today.
The control was designed for a smaller companyManual review of every transaction worked at thirty a month. At three thousand, the control becomes a sample nobody defined.
Exceptions have become the processThe workaround built for an urgent case is now the normal route, and the designed control is bypassed as a matter of routine.
Remediation was documented, not implementedThe plan exists, the owner is named, the date has passed. This is why the same finding appears three years running.
Nobody owns the controlIt sits between two departments. Both assume the other performs it, and it has not been performed for some time.
IVHow we work on controls

Six things that make testing worth doing

01

The matrix is agreed before testing starts

Risks, controls, key control designation and testing attributes agreed with management up front. Testing against a matrix nobody signed off produces findings nobody accepts.

02

Sample sizes are defensible, not convenient

Population, frequency and risk determine the sample. We document the basis, because an external auditor relying on our work will ask for it.

03

Evidence is retained, not summarised

The document tested is on the file, not a note saying it was seen. This is the difference between work that can be relied upon and work that has to be repeated.

04

Deficiencies come with root cause and an owner

A finding without a cause produces a remediation plan that treats the symptom. A finding without a named owner produces the same finding next year.

05

Reporting is rated and prioritised honestly

If everything is high risk, nothing is. We rate findings so an audit committee can act on the top of the list rather than reading all of it.

06

Built for external auditor reliance from the start

Workpapers are prepared assuming the external auditor will review and rely on them. That standard costs nothing extra during fieldwork and saves the entire engagement being redone.

These are the firm's controls applied to internal audit work specifically. The full set, applied to every engagement of any type, is published.

The seven controls on every engagement →

VResponsibilities

Who does what in an ICFR programme

Confusion about this is common, and it is expensive — because work performed by the wrong party cannot be relied on by anyone.

01

Management

Owns the controls and the assessment. Under SOX 404(a), management asserts on the effectiveness of internal control over financial reporting. The assertion is theirs and cannot be delegated.

02

Internal audit

Provides independent assurance to the audit committee, and frequently performs or supports the testing underpinning management's assessment.

03

The external auditor

Where required, attests separately on ICFR under SOX 404(b). Independent of management, and may place reliance on internal audit work that meets the standard.

04

Where we sit

We support management's assessment and the internal audit function — testing, documenting and remediating. We are not the external auditor on those engagements, and that separation is what makes our work usable.

Tested to a standard a PCAOB-registered auditor relied on

Our team has performed ICFR testing for an NYSE-listed company, working alongside the client's internal audit function to test the operating effectiveness of implemented controls in advance of external audit fieldwork.

That is a useful benchmark for two reasons. It means the documentation standard our team works to has already been accepted by a US-listed issuer's auditor. And it means the coordination — group templates, deadlines, evidence expectations — is familiar rather than theoretical.

One boundary we apply without exception: where we act as your statutory auditor, we will not perform controls work that creates a self-review threat under the ICAP Code of Ethics. We tell you which side of that line your engagement falls on before we quote.

Our independence framework →

VICommon questions

Questions we are asked

What is the difference between internal audit and external audit?

External audit gives an opinion to third parties on whether the financial statements are fairly presented, and is required by statute or by stakeholders. Internal audit provides assurance to the board and audit committee on whether controls and processes work, covers operational and compliance areas as well as financial ones, and is directed by the organisation rather than by law.

What is ICFR, and does it apply to us?

Internal control over financial reporting is the set of controls providing reasonable assurance that financial statements are reliable. Formal ICFR assessment obligations arise most often from a listed parent — particularly a US-listed one — or from lender and investor requirements. Many private groups implement it voluntarily because it is the fastest route to a control environment that survives diligence.

What is the difference between SOX 404(a) and 404(b)?

404(a) is management's own assessment and assertion on the effectiveness of internal control over financial reporting. 404(b) is the external auditor's separate attestation on it, required for certain categories of issuer. Work supporting management's assessment and the auditor's attestation are different exercises performed by different parties — which is why who does the testing matters.

Can you test our controls if you are also our auditor?

Not where doing so would create a self-review threat — we would be testing controls and then auditing the financial statements those controls produce. For public interest entities the restriction is strict. Where we act as your auditor, controls work generally goes to another firm, and we will say so at the outset rather than after you have engaged us.

We are too small for an internal audit department. What are the options?

Outsourcing the function entirely is the usual answer, and it is often better than building one — you get an independent team, a risk-based plan and reporting directly to the audit committee, without a permanent headcount. Co-sourcing works where you have someone internal but need specialist coverage in areas like IT or treasury.

Why do the same audit findings keep recurring?

Almost always because remediation was documented rather than implemented — a plan exists, an owner is named, the date has passed. The second most common reason is that the root cause was never established, so the fix addressed the symptom. We test remediation before closing a finding, which is why our findings tend not to reappear.

Do you cover IT controls as well as process controls?

Yes. IT general controls — access management, segregation of duties in the ERP, change management, backup and recovery — are handled jointly with our technology practice, which is led in-house by a specialist holding ISO 27001, COBIT, NIST and SOC 2 credentials. Financial reporting now depends on systems, so testing process controls without testing the systems beneath them is incomplete.

How is internal audit work priced?

Outsourced internal audit is normally an annual retainer covering an agreed plan. Discrete engagements — an ICFR implementation, a specific cycle audit, a remediation project — are scoped and fixed-fee. Testing volumes are agreed before fieldwork so the fee does not move once work starts.

Let's work together

Send us what the group has asked for.

Or tell us which finding keeps coming back. A partner will tell you what testing is actually required and what it will take.