Audit universe and risk assessment
We map the full set of auditable processes, companies and systems, then assess them for risk and significance together with management: this is the basis for deciding where to concentrate the reviews.
Compliance & Governance
An internal audit function delivered on an outsourced or co-sourced basis: a risk-based audit plan, reviews of processes and controls, workable recommendations and reporting to the board. Continuous assurance without the fixed costs of an in-house department.
What we do
We map the full set of auditable processes, companies and systems, then assess them for risk and significance together with management: this is the basis for deciding where to concentrate the reviews.
We prepare the multi-year and the annual plan in line with the IIA Global Internal Audit Standards and submit them to the board of directors for approval, with the support of the control and risk committee where one has been established.
We carry out operational, compliance, financial, IT and process audits, including at critical suppliers: document review, interviews, testing of controls, sampling and root cause analysis.
Every finding is graded by severity and comes with a workable recommendation, an owner and a deadline. We monitor how action plans are implemented and report on progress to senior management.
We produce clear reports for the board of directors, the control and risk committee, the board of statutory auditors and senior management: a summary of the findings, an overall assessment of the control system and the priorities for action.
We draft the audit charter and the internal audit procedures, define the function’s KPIs and the quality assurance programme required by the Global Internal Audit Standards, so that the work itself can be reviewed.
Internal audit is the function that provides the board of directors and senior management with an independent and objective assessment of the effectiveness of governance, risk management and control processes. The professional benchmark is set by the Global Internal Audit Standards of the Institute of Internal Auditors, in force since 2025. They have replaced the mandatory elements of the previous International Professional Practices Framework (the Standards, the Code of Ethics and the Core Principles) and set requirements on independence, risk-based planning, communication of results and the quality of the function. For the design of the internal control system the reference model remains the COSO framework, alongside COSO ERM for enterprise risk management. Lastly, the IIA Three Lines Model clarifies the role of internal audit as the third line, distinct from the first- and second-line roles (operational management, risk management and compliance) that remain with management.
In Italy the function is provided for by the Italian Corporate Governance Code for those listed companies that adopt it, and by sector rules for banks, insurers and financial intermediaries. For all other companies the driver is the Italian Civil Code. Article 2086(2) requires anyone running a business in corporate or collective form to maintain organisational, administrative and accounting arrangements appropriate to the nature and the size of the business, including for the timely detection of business distress and of any loss of going concern (Italian Legislative Decree 14/2019, the Business Crisis and Insolvency Code). Article 2381 requires the executive directors to look after those arrangements and the board to assess their adequacy. Without an independent review of processes, that assessment rests above all on information supplied by those same executive directors: internal audit corroborates it with evidence gathered in the field.
We deliver the function on an outsourced basis, taking on full operational responsibility for it, or on a co-sourced basis, alongside an in-house team that needs specialist skills or extra capacity. In both cases the mandate is formalised in an audit charter approved by the board: the document sets out scope, powers, reporting lines and independence rules. For listed companies, the Italian Corporate Governance Code expressly allows the function to be entrusted, in whole or for parts of its activity, to an external provider with adequate professional standing, independence and organisation, with the reasons for the choice explained in the corporate governance report.
We start from the audit universe: a structured inventory of the processes, companies, systems and suppliers that may be subject to review. We assess it for risk together with management, reusing the analyses already available so as not to ask the same questions twice. This produces the multi-year plan and the annual plan submitted to the board.
Engagements follow a written work programme: document review, interviews, process walkthroughs on site, testing of controls on defined samples, root cause analysis. Findings are discussed with the managers concerned before the report is drafted, so that recommendations are workable and already agreed. Follow-up is part of the service: we monitor how action plans are implemented and report periodically to the board, the control and risk committee and the board of statutory auditors.
We pay particular attention to coordination with the other control functions (the Supervisory Body, the external auditor, the DPO, management system owners), so that information flows are integrated and the company is not put through repeated reviews of the same processes.
Our method
With senior management we agree the mandate, the scope, the reporting lines and the working arrangement (outsourcing or co-sourcing), and formalise them in the audit charter submitted to the board.
Interviews with department heads and a review of organisation charts, procedures and existing risk assessments (231 Model, data protection, ISO): from these we build the map of auditable processes, weighted using risk criteria agreed with senior management.
We turn the priorities into a multi-year plan and an annual plan, with objectives, resources and timing for each engagement, and present them to the board for approval, with the support of the control and risk committee where one has been established.
We run the engagements with written work programmes, tests and sampling, discuss the findings with the managers concerned and issue the report with agreed recommendations and action plans.
We verify that corrective actions have been implemented, update the plan as risks change and measure the function through KPIs and a quality assurance programme.
Benefits
Deliverables
Frequently asked questions
Yes, if the board wants an independent review of processes and controls. The Italian Civil Code requires anyone running a business in corporate or collective form to maintain adequate arrangements (Article 2086(2)) and entrusts the board with assessing their adequacy (Article 2381, as applied to S.r.l. companies by Article 2475); internal audit is one of the tools that measure how effectively those arrangements work. In an SME this means a handful of engagements a year on the processes that matter most: purchasing and payments, cash collection, stock control, access to systems.
Under outsourcing we run the function in full: plan, engagements, reporting and follow-up, with a lead auditor who reports to senior management. Under co-sourcing we work alongside an existing in-house function, bringing specialist skills (IT, compliance, regulated sectors) or extra capacity at peak times. We choose the most suitable arrangement together.
They are distinct functions, even though the law allows some overlap: in limited companies (società di capitali) the board of statutory auditors may act as the OdV (Article 6(4-bis) of Italian Legislative Decree 231/2001) and the head of internal audit may sit on the OdV. The OdV oversees the 231 Model; the board of statutory auditors monitors proper administration and the organisational arrangements (Article 2403 of the Italian Civil Code); internal audit reviews processes and controls under a mandate from the board. We coordinate plans and information flows so that each body receives the evidence it needs, without duplicating work.
The plan derives from the risk assessment and is approved by the board of directors, with the support of the control and risk committee where one has been established, rather than by operational management: that is what protects the independence of the function. Frequency depends on the risk level of each process; the plan is reviewed at least once a year, or whenever significant events occur.
We keep the roles separate: anyone who has designed a process or a management system does not then review it as an auditor. The independence rules and the way conflicts of interest are handled are set out in the audit charter and declared to senior management, as the Global Internal Audit Standards require. If a conflict cannot be managed, we flag it before accepting the engagement.
Related services
Organisation, Management and Control Models under Italian Legislative Decree 231/2001, predicate offence risk assessment and support for the Supervisory Body (OdV).
Find out moreMapping, analysis and redesign of business processes: we remove waste, reduce operational risks and prepare the ground for digitalisation.
Find out moreDesign, implementation and maintenance of certifiable management systems: ISO 9001, 14001, 45001, 27001, 37001, 50001 and the main sector and supply chain schemes.
Find out moreLet’s talk
Tell us your business priorities: in a first meeting with no obligation we look at your context and propose a concrete way forward, with clear timescales and measurable results.