More About Internal Audit
Internal Audit Standards
The work of the Office of the Internal Auditor (Internal Audit) is conducted and managed in accordance with The Institute of Internal Auditors’ (IIA’s) Global Internal Audit Standards (Standards or Red Book). This requires periodic internal self-assessments and a recurring five-year external quality assurance review (QAR) by an independent team to evaluate the Internal Audit function for conformance with the Standards. The last QAR was completed in October 2024 and achieved the highest possible rating.
Internal Auditors also follow Government Auditing Standards (Yellow Book) issued by the Comptroller General of the United States (GAGAS), as applicable.
Services Provided by Internal Audit
Internal Audit conducts assurance, advisory, and investigative engagements, as well as special projects such as external and internal quality assessment reviews, in accordance with the approved Audit Plan.
Each fiscal year, an audit plan is developed and submitted to the Chancellor and Board of Trustees Audit Committee for review and approval. The audit plan is based on a risk assessment methodology, as well as requests from management.
Audit services can be requested by members of the University community by contacting an audit team member (see Staff links). Internal Audit works with management in a partnership/service function in evaluating the efficiency and effectiveness of University operations. The size of the audit staff limits the number of internal audit engagements that can be performed each year. When scheduling conflicts arise, senior management will be consulted to determine priorities.
The following types of audit services are provided by the Office of Internal Auditing:
Operational Audits
Operational audits determine the effectiveness and efficiency of operational units or programs within the university. Internal Audit measures how successfully a unit or program achieves its goals and how well it uses its resources.
Financial Audits and Reviews
Financial audits and reviews address issues related to the proper accounting and reporting of financial transactions, including authorizations, cash receipts, cash disbursements, and commitments to purchase. Internal audit may conduct a financial audit or review of a particular unit or program. However, the University’s annual Financial Statement Audit is performed by the NC Office of the State Auditor, in accordance with NC General Statutes.
Compliance Audits
Compliance audits are performed to determine the extent of adherence to laws, rules, regulations, policies, and procedures. Compliance may be reviewed for adherence to federal, state, and local laws (HIPAA,FERPA, tax reporting) or for adherence to state, UNC System, and/or UNCG policies and procedures (e.g., travel policies, procurement policies, etc.).
Information Technology (IT) Audits
Information technology (IT) audits are performed to examine and evaluate the adequacy of policies, procedures, processes, software and hardware functions and organizational structures utilized in the management of information systems and resources. The primary objective of an IT audit is to determine if processes and controls are in place to safeguard assets, ensure data integrity and maintain continuity of operations.
Investigative Audits
Usually based on an internal or external hotline tip, Internal Audit investigates alleged irregular or suspicious conduct, non-compliance with policies or laws, misuse of UNCG resources, false time reporting, internal theft, and conflicts of interest as well as other allegations.
Follow-up Audits and Reviews
After the issuance of an Internal Audit report or a North Carolina Office of the State Auditor (OSA) report, Internal Audit will review steps taken by management to resolve any reported issues. Depending on the severity of findings and recommended corrective action, Internal Audit may perform a limited follow-up review or a follow-up audit.
Consultation & Advisory Services
Consultation and advisory services are available to all levels of university management. Internal Audit may help to interpret policies, review processes and controls, or assist with planning new business processes to ensure that internal controls are sufficient and appropriate. These are frequently undertaken when a significant policy or process change is being planned. We strongly encourage departments to contact us for consultation when starting a new business process, implementing a new information system, or making significant changes to the way you conduct your day-to-day activities. We believe that it is easier to “get it right” from the beginning rather than having to “fix it” later! Additionally, we can help ensure that controls are in place to prevent potential future audit findings.
Audit and assurance services provide numerous benefits to management. They can:
- Determine the adequacy of internal controls
- Promote best practices for internal controls
- Ensure compliance with laws, regulations, and policies
- Identify operational inefficiencies and waste
- Review IT projects, systems, and technology
- Provide objective insight
- Assess efficient and responsible use of resources
- Identify potential cost savings
- Assist management in addressing complex, cross-functional issues
Our internal audit plan is based on risk, time since last audit, management requests, and internal audit resources to ensure we are best meeting UNCG’s needs. If you have questions, please reach out to us.
Assistance to OSA
Internal Audit assists the NC Office of the State Auditor upon request. This may involve assessments of internal controls or assisting with OSA investigative audits.
Other
Other special projects may be performed by Internal Audit as delegated by the UNC System Office, Board of Trustees, Chancellor, or other university management.
Confidentiality
The Director of Internal Audit has developed policies and procedures to ensure compliance with confidentiality requirements of Global Internal Audit Standards (Standards). Standards, which we are mandated by NC General Statute 143 Article 79 to follow, state that Internal auditors are required to maintain the confidentiality of all information obtained during their work. Such information must be used exclusively for professional purposes and safeguarded against unauthorized access or disclosure within and outside the organization. Therefore, information shared with Internal Audit team members is not shared with anyone except on a need-to-know basis. For more information, refer to Principle 5 of the Global Internal Audit Standards.
Authority and Responsibility
Internal Audit’s authority and responsibility is provided in the NC General Statute 143 Article 79.
§ 143‑746. Internal auditing required.
(a) Requirements. – A State agency shall establish a program of internal auditing that:
(1) Promotes an effective system of internal controls that safeguards public funds and assets and minimizes incidences of fraud, waste, and abuse.
(2) Determines if programs and business operations are administered in compliance with federal and state laws, regulations, and other requirements.
(3) Reviews the effectiveness and efficiency of agency and program operations and service delivery.
(4) Periodically audits the agency’s major systems and controls, including:
a. Accounting systems and controls.
b. Administrative systems and controls.
c. Information technology systems and controls.
(a1) Key Performance Indicators and Criteria. – In addition to the requirements of subsection (a) of this section, each agency head shall be responsible for ensuring that agency’s internal audit unit meets the required key indicators and criteria established by the Council under G.S. 143‑747(c)(3a).
(b) Internal Audit Standards. – Internal audits shall comply with current Standards for the Professional Practice of Internal Auditing issued by the Institute for Internal Auditors or, if appropriate, Government Auditing Standards issued by the Comptroller General of the United States. Each agency head shall annually certify to the Council that the audit plan was developed and the audit reports were conducted and reported in accordance with required standards. Internal Audit’s authority and responsibility is also provided in the Internal Audit Charter.