Compliance & Governance

Internal Audit

An internal audit function delivered on an outsourced or co-sourced basis: a risk-based audit plan, reviews of processes and controls, workable recommendations and reporting to the board. Continuous assurance without the fixed costs of an in-house department.

What we do

Our areas of work

Audit universe and risk assessment

We map the full set of auditable processes, companies and systems, then assess them for risk and significance together with management: this is the basis for deciding where to concentrate the reviews.

Risk-based audit plan

We prepare the multi-year and the annual plan in line with the IIA Global Internal Audit Standards and submit them to the board of directors for approval, with the support of the control and risk committee where one has been established.

Delivery of audit engagements

We carry out operational, compliance, financial, IT and process audits, including at critical suppliers: document review, interviews, testing of controls, sampling and root cause analysis.

Recommendations and follow-up

Every finding is graded by severity and comes with a workable recommendation, an owner and a deadline. We monitor how action plans are implemented and report on progress to senior management.

Reporting to the board

We produce clear reports for the board of directors, the control and risk committee, the board of statutory auditors and senior management: a summary of the findings, an overall assessment of the control system and the priorities for action.

Set-up and quality of the function

We draft the audit charter and the internal audit procedures, define the function’s KPIs and the quality assurance programme required by the Global Internal Audit Standards, so that the work itself can be reviewed.

The regulatory context

Internal audit is the function that provides the board of directors and senior management with an independent and objective assessment of the effectiveness of governance, risk management and control processes. The professional benchmark is set by the Global Internal Audit Standards of the Institute of Internal Auditors, in force since 2025. They have replaced the mandatory elements of the previous International Professional Practices Framework (the Standards, the Code of Ethics and the Core Principles) and set requirements on independence, risk-based planning, communication of results and the quality of the function. For the design of the internal control system the reference model remains the COSO framework, alongside COSO ERM for enterprise risk management. Lastly, the IIA Three Lines Model clarifies the role of internal audit as the third line, distinct from the first- and second-line roles (operational management, risk management and compliance) that remain with management.

In Italy the function is provided for by the Italian Corporate Governance Code for those listed companies that adopt it, and by sector rules for banks, insurers and financial intermediaries. For all other companies the driver is the Italian Civil Code. Article 2086(2) requires anyone running a business in corporate or collective form to maintain organisational, administrative and accounting arrangements appropriate to the nature and the size of the business, including for the timely detection of business distress and of any loss of going concern (Italian Legislative Decree 14/2019, the Business Crisis and Insolvency Code). Article 2381 requires the executive directors to look after those arrangements and the board to assess their adequacy. Without an independent review of processes, that assessment rests above all on information supplied by those same executive directors: internal audit corroborates it with evidence gathered in the field.

Our approach

We deliver the function on an outsourced basis, taking on full operational responsibility for it, or on a co-sourced basis, alongside an in-house team that needs specialist skills or extra capacity. In both cases the mandate is formalised in an audit charter approved by the board: the document sets out scope, powers, reporting lines and independence rules. For listed companies, the Italian Corporate Governance Code expressly allows the function to be entrusted, in whole or for parts of its activity, to an external provider with adequate professional standing, independence and organisation, with the reasons for the choice explained in the corporate governance report.

We start from the audit universe: a structured inventory of the processes, companies, systems and suppliers that may be subject to review. We assess it for risk together with management, reusing the analyses already available so as not to ask the same questions twice. This produces the multi-year plan and the annual plan submitted to the board.

Engagements follow a written work programme: document review, interviews, process walkthroughs on site, testing of controls on defined samples, root cause analysis. Findings are discussed with the managers concerned before the report is drafted, so that recommendations are workable and already agreed. Follow-up is part of the service: we monitor how action plans are implemented and report periodically to the board, the control and risk committee and the board of statutory auditors.

We pay particular attention to coordination with the other control functions (the Supervisory Body, the external auditor, the DPO, management system owners), so that information flows are integrated and the company is not put through repeated reviews of the same processes.

What sets our service apart

  • An auditable framework: the audit charter, the operating procedures, the function’s KPIs and the quality assurance programme are built on the Global Internal Audit Standards, so that the board and the statutory auditors can assess the work of the function and not only its results.
  • Tracked follow-up: every finding goes into a register with an owner, a deadline and an implementation status; we check on site that corrective actions have been carried out and record the outcome in the periodic report to senior management.
  • Findings that are useful to the board: reports separate what is urgent from what can be improved and give an overall opinion on the control system, rather than a simple list of anomalies.
  • Flexibility: the arrangement (outsourcing or co-sourcing) and the intensity of engagements adapt year by year as scope and risks change, with no headcount commitments.

Our method

How we work

  1. Setting up the function

    With senior management we agree the mandate, the scope, the reporting lines and the working arrangement (outsourcing or co-sourcing), and formalise them in the audit charter submitted to the board.

  2. Audit universe and risks

    Interviews with department heads and a review of organisation charts, procedures and existing risk assessments (231 Model, data protection, ISO): from these we build the map of auditable processes, weighted using risk criteria agreed with senior management.

  3. Audit plan

    We turn the priorities into a multi-year plan and an annual plan, with objectives, resources and timing for each engagement, and present them to the board for approval, with the support of the control and risk committee where one has been established.

  4. Delivery and reporting

    We run the engagements with written work programmes, tests and sampling, discuss the findings with the managers concerned and issue the report with agreed recommendations and action plans.

  5. Follow-up and improvement

    We verify that corrective actions have been implemented, update the plan as risks change and measure the function through KPIs and a quality assurance programme.

Benefits

What the business gains

  • An independent, documented assessment of the effectiveness of the controls, to support the board’s decisions
  • Costs set out in the annual plan and proportionate to the actual scope of the reviews
  • Concrete evidence supporting the adequacy of the organisational arrangements that the Italian Civil Code requires
  • Anomalies, inefficiencies and fraud risks identified in good time, with corrective actions verified in the field
  • Less duplication between internal audit, the 231 Supervisory Body (OdV), the board of statutory auditors and ISO systems, thanks to a single point of contact

Deliverables

What we deliver

  • Audit charter and operating procedures for the internal audit function
  • Documented audit universe and risk assessment, including the assessment criteria used
  • Multi-year audit plan and annual plan approved by the board
  • Work programmes, working papers and evidence of the tests performed
  • Audit reports with graded findings, root causes and recommendations
  • Register of findings and action plans, with implementation status
  • Periodic report to the board, the control and risk committee and the board of statutory auditors
  • KPI dashboard for the function and quality assurance programme

Frequently asked questions

Answers to the questions we hear most often

Our company is not listed: does an internal audit function still make sense?

Yes, if the board wants an independent review of processes and controls. The Italian Civil Code requires anyone running a business in corporate or collective form to maintain adequate arrangements (Article 2086(2)) and entrusts the board with assessing their adequacy (Article 2381, as applied to S.r.l. companies by Article 2475); internal audit is one of the tools that measure how effectively those arrangements work. In an SME this means a handful of engagements a year on the processes that matter most: purchasing and payments, cash collection, stock control, access to systems.

What is the difference between outsourcing and co-sourcing?

Under outsourcing we run the function in full: plan, engagements, reporting and follow-up, with a lead auditor who reports to senior management. Under co-sourcing we work alongside an existing in-house function, bringing specialist skills (IT, compliance, regulated sectors) or extra capacity at peak times. We choose the most suitable arrangement together.

Does internal audit overlap with the Supervisory Body or the board of statutory auditors?

They are distinct functions, even though the law allows some overlap: in limited companies (società di capitali) the board of statutory auditors may act as the OdV (Article 6(4-bis) of Italian Legislative Decree 231/2001) and the head of internal audit may sit on the OdV. The OdV oversees the 231 Model; the board of statutory auditors monitors proper administration and the organisational arrangements (Article 2403 of the Italian Civil Code); internal audit reviews processes and controls under a mandate from the board. We coordinate plans and information flows so that each body receives the evidence it needs, without duplicating work.

Who decides what is reviewed, and how often?

The plan derives from the risk assessment and is approved by the board of directors, with the support of the control and risk committee where one has been established, rather than by operational management: that is what protects the independence of the function. Frequency depends on the risk level of each process; the plan is reviewed at least once a year, or whenever significant events occur.

How do you protect independence if you also work on other projects for our company?

We keep the roles separate: anyone who has designed a process or a management system does not then review it as an auditor. The independence rules and the way conflicts of interest are handled are set out in the audit charter and declared to senior management, as the Global Internal Audit Standards require. If a conflict cannot be managed, we flag it before accepting the engagement.

Let’s talk

Together, let’s build your tomorrow.

Tell us your business priorities: in a first meeting with no obligation we look at your context and propose a concrete way forward, with clear timescales and measurable results.