Internal audit is moving closer to the board of directors, a sign that the function is becoming more independent and objective, and free of the potential for improper influence from the CFO.
Two surveys released this week confirm the trend. An Institute of Internal Auditors’s (IIA) survey of 554 chief audit and other executives in the United States and Canada found that more than 75% of CAEs report functionally (for their main responsibilities) to a corporation’s full board or audit committee. The results were even higher (80%) among the Fortune 500 companies that responded.
Similarly, a PricewaterhouseCoopers internal-auditor survey of 630 executives showed that the link between a company’s board and its internal audit department is strong. Seventy-nine percent of board members polled said internal audit contributes significant value to a company, compared with 44% of executive management who thought so.
The findings are notable, since the closer a CAE is aligned to a company’s board or audit committee, the more internal audit will be objective and independent in its analysis of a company’s internal controls, at least according to the IIA. The association maintains that independence “can best be achieved through a dual CAE reporting relationship — functionally to the board of directors and administratively to senior management.”
In the IIA study, 70% of respondents said their CAE reports administratively to the CEO or CFO, with an increasing shift from the CFO to the CEO. Recent Federal Reserve guidelines on internal-auditor effectiveness for banks also favor this reporting structure.
“Historically, internal audit has been viewed as part of the financial area of most companies. By virtue of that, it would administratively report to the CFO in most organizations,” says Hal Garyn, vice president of IIA North American Services. Seeing a healthy number of firms reporting functionally to the board or audit committee and administratively to the CEO shows the “tone at the top” of organizations is changing, he says. “It signals to the organization the importance of the audit-executive position.”
But that dual reporting structure continues to be a touchy subject for auditors, regulators, and corporations, since a firm’s size or its location often influences whether the internal-audit function reports more directly into the CEO, the CFO, or the board of directors — or even if it has an internal-audit function at all.
The IIA’s suggested CAE reporting structure may work for the average business, Garyn notes, but it may not work for all sizes and types. If a company’s CEO is too busy to care about communication with internal audit, for example, having an administrative reporting line between internal audit and the CEO may be ineffective. Also, adds Garyn, having a CAE reporting only to a CEO or board “might take the CAE away from information flows that they might need.”