If you want to successfully manage risk, it helps to use the correct risk terms and expressions.
It’s easy to become confused as risk management uses similar terms for different purposes. For example, “Operational Risk Management” has a different meaning in the banking and insurance industry, compared to other industries (oil & gas, mining, manufacturing, chemicals, etc.).
Similarly, the term “audit” can refer either to an internal audit conducted by an organization or an external audit performed by a firm hired by the organization. The difference is important because internal and external audits may assess different things and have different frameworks and workflows.
Easily confused are two other terms: internal audit and internal control. The source of the confusion is internal audit assesses the effectiveness of controls put in place to mitigate risks. Let’s take a deeper look at both concepts.
Internal audit is a function performed at specific times
Many people in risk management use this statement to explain the difference between internal audit and internal control: Internal audit is a function, while internal control is a system. Internal audits are performed at specific times to assess:
- If the company has a good understanding of the risk it faces
- If the controls to mitigate risk are effective.
There is one important point to be made: it is not the job of internal auditors to identify risk, nor to specify the controls needed. Internal audit evaluates whether the process leading to the identification of risks is working, checks if controls are working as intended, and evaluates an organization’s governance system and process.
Internal control is an ongoing system
Internal control comprises procedures, policies, and measures to ensure an organization meets its objectives and mitigates risk that can prevent it from meeting its objectives. While internal audit is performed by internal auditors, internal control is the responsibility of operational management functions. Another point of contrast is frequency. An internal audit is conducted at specific times, whereas internal control is a continuous check of operational efficiency and effectiveness through the control of risks. Some risk experts say internal control is a part of a company’s day-to-day management and administration.
The relationship between internal audit and internal control
The best way to illustrate the relationship between internal audit and internal control is to show where they fit in the Three Lines of Defense Model:
Three lines of defense model from The Institute of Internal Auditors
Internal control is part of the first line of defense because it is the responsibility of Operational Management, which is accountable to Senior Management. Internal audit is part of the third line of defense. It even assesses the effectiveness of the first (Operational Management functions) and second (Risk and Compliance Management functions) lines of defense. Moreover, unlike internal control, internal audit may report directly to the Board of Directors and specifically the Audit Committee, to maintain independence and objectivity when assessing other functions at the first two lines of defense.
When considering a software solution, it’s important to know the difference between internal audit and internal control because both must be managed in different ways due to their unique characteristics. Make sure the software under consideration addresses the needs of both.