Frequently Asked Questions (FAQ)
The purpose of the internal audit function is to strengthen the University of North Carolina at Greensboro’s (University’s) ability to create, protect, and sustain value by providing the Board of Trustees and management with independent, risk-based, and objective assurance, advice, insight, and foresight.
The internal audit function’s mission is to enhance the University’s: (a) successful achievement of its objectives; (b) governance, risk management, and control processes; (c) decision-making and oversight; (d)reputation and credibility with its stakeholders; and (e) ability to serve the public interest with a commitment to adhering to the Global Internal Audit Standards and utilizing best practices. The University’s internal audit function will adhere to the mandatory elements of The Institute of Internal Auditors’ International Professional Practices Framework, which are the Global Internal Audit Standards and Topical Requirements.
Internal Auditors are required to protect the confidentiality of information and that is obtained as part of their professional positions. The Director of Internal Audit has developed policies and procedures to ensure compliance with confidentiality requirements of Global Internal Audit Standards (Standards). Standards, which we are mandated by NC General Statute 143 Article 79 to follow, state that Internal auditors are required to maintain the confidentiality of all information obtained during their work. Such information must be used exclusively for professional purposes and safeguarded against unauthorized access or disclosure within and outside the organization. Therefore, information shared with Internal Audit team members is not shared with anyone except on a need-to-know basis. Additionally, Internal Auditors receive annual training to maintain professional credentials and to certify that HIPAA, HERPA, and other regulations are understood and followed. For more information, refer to Principle 5 of the Global Internal Audit Standards.
Information about Internal Audit services can be found on the “More About Internal Audit” page.
You can report your concerns using the “Report a Concern” link. Please review the information on that page to learn more about what concerns should be reported to Internal Audit, Compliance, or Title IX. Other reporting options are also provided.
Engagements and reviews vary in length. The amount of time required depends on the objectives of the engagement, the cooperation and availability of the client, and the complexity of the operation. Limited scope reviews may take only a few weeks, while a complex engagement may take months. A positive working relationship between the client and the auditors is an important factor in the accuracy of information gathered and the timely completion of the engagement. Also, note that the majority of the auditors’ time is spent by the auditors in our offices performing reviews and analyses of data and information. We will request meetings and make requests for data and documentation during the audit, but we strive to minimize interference with your day-to-day work and we work with you on scheduling meetings and documents submissions.
Internal Auditors follow a planned strategy (program) for each engagement. Our audit programs include the following segments:
- Survey / Engagement Development. Survey or Engagement Development includes research to learn more about the area and topic that is the focus of the audit objective(s). Research includes identifying laws, regulations, policies, and benchmarks through internet research as well as document reviews. We also perform inquiries with stakeholders such as potential report users, management, and staff. At this segment of the audit, we will formalize our audit objectives and scope. However, as audit procedures continue, we may revise the objective(s) and/or scope.
- Planning. Planning includes reviewing documentation including workpapers previously completed to determine the data needed, sources of data, data limitations, and test procedures needed to answer the audit objective(s), including developing the elements of a finding (see Fieldwork), if applicable.
- Fieldwork. Fieldwork includes performing tests to answer the audit objective(s). For assurance engagements, auditors develop the four basic elements of a finding: The condition (what actually happened); the criteria (what should have happened); the effect (the severity of the difference between what happened and what should have happened); and the cause (the reason for a difference between what should have happened and what actually happened; this is usually a missing, broken, or poorly designed internal control). For advisory and investigation engagements, auditors develop only those finding elements applicable to the engagement objective and scope. Auditors will also develop recommendations based on the finding condition and cause.
- Reporting. Reporting includes preparing and issuing a report describing the outcome of the engagement. All reports are issued to the Chancellor and the Chair of the Compliance, Audit, Risk Management, and Legal Affairs (CARL) Committee of the UNCG Board of Trustees. Reports are also shared with applicable department management (subject of engagement) as well as the UNC System Office, the NC Council of Internal Auditing, and the NC Office of the State Auditor, unless confidential. All reports contain the objective, scope, methodology, and findings or observations in detail and in an executive summary.
- Closeout. Closeout includes Internal Audit quality checks and audit documentation finalization including verifying the distribution of the final report to appropriate stakeholders.
- Throughout every engagement: we will communicate with the auditee (audit client). We will share changes in the objective(s) and scope as well as any preliminary findings. We will not finalize findings until we share them with the auditee and confirm the accuracy as well as the reason for any findings. We provide multiple opportunities for auditees to review and respond to preliminary and final findings and observations through meetings (entrance conference, exit conference, issue sheet meeting, process inquiries, etc.) and we provide documentation to support audit conclusions.
- Follow-up: Internal audit will follow-up to verify corrective action implementation after any findings are reported by Internal Auditors, the NC State Auditor, or another auditor. Follow-up may include informal procedures or a full follow-up audit.
- Informal follow-up procedures may be conducted to verify implementation of corrective action when appropriate. For example, auditors may verify that a policy was updated or a process was implemented without conducting a full audit.
- A full audit may be conducted when significant internal control deficiencies are identified and corrective action must be verified through testing. For example, when recommended corrective action includes automating a function to prevent documentation or payment errors, auditors will test to verify that the error rate was reduced after the new system is fully implemented.
Yes, Internal Audit follows professional standards as applicable to each engagement and in operating the internal audit function. Internal Audit is required, by NC General Statute 143 Article 79, to comply with Global Internal Audit Standards (Standards or Red Book) issued by the Institute of Internal Auditors and Government Auditing Standards (Yellow Book) issued by the Comptroller General of the United States, when applicable.
NCGS 143‑746.(b) states:
“Internal Audit Standards. – Internal audits shall comply with current Standards for the Professional Practice of Internal Auditing issued by the Institute for Internal Auditors or, if appropriate, Government Auditing Standards issued by the Comptroller General of the United States. Each agency head shall annually certify to the Council that the audit plan was developed and the audit reports were conducted and reported in accordance with required standards.” Auditors also refer to the Standards applicable to the specific engagement. For example, auditors refer to ISO 27000:2022 Standards and guidance provided by the Information Systems Audit and Control Association (ISACA) for Information Technology engagements.
The Internal Audit team currently has one Director of Internal Audit and one advanced auditor. The Internal Audit team report functionally to the Chair of the CARL Committee and administratively to the Vice Chancellor for Institutional Integrity and General Counsel.
Internal Audit is positioned within the Office of Institutional Integrity and General Counsel, operating independently but also collaboratively as appropriate to ensure audit coverage does not duplicate efforts. The Internal Audit team also reports to the UNC System Office, the NC Council of Internal Auditing (an oversight body), and upon request, will report to the NC Office of the State Auditor.
Internal Audit’s authority is established by North Carolina General Statute 143 Article 79 and it’s Internal Audit Charter.
If you are interested in becoming an Internal Auditor, or if you just want more information about internal auditing, please visit The Institute of Internal Auditors (The IIA) website at www.theiia.org.
If you are interested in learning more about resources for internal auditors in the higher education field, please visit the Association of College and University Auditors (ACUA) at www.acua.org.
If you are interested in becoming an IT auditor, or want more information about professional credentials or guidance related to IT auditing, please visit the ISACA website at https://www.isaca.org/.
Yes, Internal Audit is required to maintain a quality assurance and improvement program (QAIP) that includes periodic internal and external quality assessments.
Internal quality assessments are conducted for each engagement and annually on the entire audit function to ensure conformance with Global Internal Audit Standards.
External Quality Assessment Reviews (QARs) are also conducted at least every five years by independent quality assessors to verify that the internal audit function is conforming with Global Internal Audit Standards. Our last external QAR was completed in October 2024 and resulted in the highest rating possible.
Internal Audit also reports to:
- The Chancellor
- The Vice Chancellor for Institutional Integrity and General Counsel
- The Compliance, Audit, Risk Management, and Legal Affairs (CARL) Committee of the UNCG Board of Trustees.
- The NC Council of Internal Auditing.
- The UNC System Office, Internal Audit Office.
- The NC State Auditor, upon request.
Additionally, Internal Audit must submit documentation to the NC Council of Internal Auditing for review and periodic examination as follows:
- Annual Self-Assessment Maturity Model (SAMM) – a comprehensive evaluation of the Internal Audit function, including ratings and listing evidence of conformance with each Global Internal Audit Standard; signed by the Chancellor and the Director of Internal Audit.
- Annual Productivity – an accounting of Internal Audit hours spent on engagements, administrative work, Leave, special projects, and other activities.
- Quarterly Report Attestations confirming that Global Internal Audit Standards were followed and discussed with the Chancellor; signed by the Chancellor and the Director of Internal Audit.
- Internal Audit reports completed during the respective quarter.
- Annual Report Attestations confirming that Global Internal Audit Standards were followed and discussed with the Chancellor; signed by the Chancellor and the Director of Internal Audit. This attestation is required by NC General Statute 143, Article 79.
- Annual Risk Assessment Attestations confirming that the Annual Internal Audit Work Plan was developed based on a comprehensive University-wide risk assessment; signed by the Chancellor and the Director of Internal Audit
- Annual Risk-based Internal Audit Work Plan with approval by the Audit Committee and Chancellor.
- Annual Summary of Notable Accomplishments – a brief narrative highlighting how our Internal Audit function has improved our organization’s efficiency or effectiveness, including: specific examples, quantitative support or metrics if available, to demonstrate audit value.
- Internal Audit Charter (approved by the Audit Committee); submitted as changes are made.
- Organizational Charts are submitted when changes are made.
The Council of Internal Auditing analyzes all the data and reports submitted by all internal audit teams and compares performance of internal audit teams. They compare the Internal Audit work plan to Internal Audit’s performance and they compare hours spent by Internal Audit teams to other internal audit teams across the state.
The difference between Internal and external audit is primarily related to the purpose of each.
The purpose of the internal audit function is to strengthen the University of North Carolina at Greensboro’s (University’s) ability to create, protect, and sustain value by providing independent, risk-based, and objective assurance, advice, insight, and foresight. UNCG’s Internal Audit team implemented a proactive strategy to identify issues internally and assist with getting them corrected before an external entity reviews and finds issues.
The purpose of external audit is generally to provide assurance on the accuracy of financial statements or to verify compliance with laws, regulations, or contract terms. External auditors can be independent public accounting firms that UNCG hires or government auditors.
- Independent public accounting firms, that UNCG hires, review the university’s annual financial statements to ensure that UNCG’s financial condition is presented fairly. Government agencies, UNCG’s Board of Trustees, and bond rating agencies rely on the independent auditor’s opinion of UNCG’s financial statements.
- Government auditors focus primarily on compliance with government regulations and contract or grant award terms. Since both federal and state governments fund a significant portion of the university’s activities, they want to make sure we use public funds as they were intended.
Internal auditors may look at the same data or perform some of the same audit procedures as external auditors. However, internal auditors may delve more deeply into a particular fund or program if risks, such as internal control deficiencies, are identified. If there is a problem, it’s better to find it and fix it before external auditors review our practices and documentation!
Yes. Internal Audit will consider all requests for inclusion on the audit plan. Please note that our ability to accept project requests depends on several factors, including but not limited to, staff workload, the extent of time required to fulfill the request, and the level of risk and/or urgency associated with the requested engagement.
You can request assurance, advisory, or investigation services from Internal Audit. For more details on the types of services we offer, please refer to the “More About Internal Audit” page.
Advisory or consultative services are strongly encouraged for any department or unit who will be implementing a new process or system. When Internal Audit performs advisory or consulting services, the specific objective(s), scope, and final product are agreed upon by both Internal Audit and the requesting department. This means that you can have a consultation that identifies internal control deficiencies and recommends corrective action that is provided to you verbally. The goal of Internal Audit is to help the University improve the effectiveness and efficiency of operations. This is an opportunity to identify and fix something without being audited.
Internal controls are processes, systems, and/or policies and procedures put in place to provide reasonable assurance regarding the achievement of reliable financial reporting, effective and efficient operations, and compliance with laws and regulations. Internal controls are anything we do or put in place to help us achieve our objective(s). Examples of internal controls include locking a petty cash box and office door to prevent theft of funds and other items or using strong passwords to reduce the risk of unauthorized access to your accounts.
Management is responsible for establishing and maintaining the control environment. Auditors play a role in a system of internal controls by performing evaluations, testing the effectiveness of controls, and making recommendations for improved controls.
In general, controls can be categorized as preventive or detective. Preventive controls are aimed at preventing errors or irregularities from occurring. Detective controls are designed to identify errors or irregularities after they have occurred.