JAN
17th
Posted by: Tony Wilkinson
Having been on the receiving end of some third party audits in recent weeks, I have noticed an emphasis on risk based thinking. Not just business wide activities such as PESTLE and SWOT but specific risk in all process activities which is quite refreshing.
Asking do we need to do a task and if we do at what frequency? This is very relevant for the internal audit schedule. I have historically recommended auditing all processes within a 12 month period. Based on risk one can extend this period to two or three years but personally I would be rather uncomfortable with this. I suspect this would depend on the auditor.