CONFIDENTIAL • INTERNAL USE ONLY

Internal Audit Procedures

📄 Doc ID: AZ-IA-2024-001 📅 Effective: 2024-11-15 🔄 Version: 3.2 👤 Owner: Chief Audit Executive

This document establishes the standardized procedures, methodologies, and compliance frameworks governing the Internal Audit function across all Aevum Zenth Conglomerate subsidiaries and divisions.

1. Purpose & Scope

The Internal Audit function provides independent, objective assurance and consulting services designed to add value and improve Aevum Zenth's operations. This procedure covers:

  • Financial statement assurance and transaction testing
  • Operational efficiency and process optimization reviews
  • IT general controls (ITGC), cybersecurity, and data privacy audits
  • Regulatory compliance across 62 operating jurisdictions
  • Third-party vendor and supply chain due diligence

Exclusions: Fraud investigations are governed separately under AZ-FIN-INV-2023. Disciplinary actions remain the purview of HR and Legal.

2. Audit Framework & Standards

All audit activities align with internationally recognized standards and internal governance mandates:

IIA International Standards for the Professional Practice of Internal Auditing

Mandatory adherence to Core Principles, Code of Ethics, and Standard 1000-1300. Emphasizes independence, objectivity, proficiency, and quality assurance.

COSO Internal Control Framework (2013)

Five components evaluated: Control Environment, Risk Assessment, Control Activities, Information & Communication, Monitoring Activities.

ISO 31000 & Division-Specific Regulations

Risk management integration. Divisional audits incorporate sector-specific mandates (e.g., HIPAA for Health Sciences, FAR/DFARS for Aerospace, SEC/SOX for Capital Group).

3. Governance & Oversight

Body Responsibility Interaction Frequency Status
Board Audit Committee Approves charter, annual plan, CAE appointment/removal Quarterly ● Active
Chief Audit Executive (CAE) Direct oversight, resource allocation, methodology governance Continuous ● Active
Divisional Compliance Officers Local coordination, remediation ownership, evidence provision Per engagement ● Active

4. Annual Audit Planning

The annual audit plan is risk-based, dynamic, and approved by the Audit Committee. The planning cycle follows these phases:

  1. Risk Universe Mapping: Top-down assessment of strategic, operational, financial, and compliance risks across all 400 subsidiaries.
  2. Inherent & Residual Risk Scoring: Matrix evaluation (Impact × Likelihood) using AZ-Risk-Scoring v4.1.
  3. Resource Allocation: Staffing, budget, and external specialist engagement (cyber, forensics, sector experts).
  4. Plan Approval: Submitted to Audit Committee by October 15 for January 1 effective date.

Adjustments: Mid-year plan amendments require CAE and Audit Committee Chair approval for >15% scope deviation or emergency audits.

5. Fieldwork & Execution

5.1 Engagement Lifecycle

PhaseKey ActivitiesDeliverablesTimeline
PlanningScope definition, data request, risk assessment, audit program draftingEngagement Letter, Audit ProgramWeek 1-2
FieldworkSampling, walkthroughs, controls testing, data analytics, interviewsWorking Papers, Test ResultsWeek 3-6
ReportingFinding validation, root cause analysis, management response draftingDraft Audit ReportWeek 7
ClosureFinal report issuance, action plan sign-off, file archivingFinal Report, CAP TrackerWeek 8

5.2 Evidence & Working Papers

All working papers must be:

  • Timestamped, version-controlled, and stored in the AZ Audit Management System (AMS)
  • Cross-referenced to audit objectives and risk controls
  • Reviewable by CAE and external quality assessors

6. Reporting & Communication

Findings are classified by severity using a standardized risk matrix:

  • Critical: Material financial impact, regulatory breach, or systemic control failure. Deadline: 14 days
  • High: Significant operational risk or design deficiency. Deadline: 30 days
  • Medium: Moderate control gap with mitigating factors. Deadline: 60 days
  • Low: Process improvement or minor documentation gap. Deadline: 90 days

Reports include: Executive Summary, Detailed Findings, Root Cause Analysis, Management Action Plans, and Risk Ratings. Distribution is strictly need-to-know per AZ-Data-Classification Policy.

7. Remediation & Follow-up

The Internal Audit function maintains a centralized Corrective Action Plan (CAP) tracker. Follow-up procedures include:

  1. Monthly status reviews with process owners
  2. Validation testing (documentation review, re-performance, or system verification)
  3. Escalation to Audit Committee for overdue Critical/High items (>30 days past deadline)
  4. Closure only upon CAE sign-off confirming effective remediation

8. Quality Assurance & Improvement Program (QAIP)

Continuous quality monitoring is mandatory per IIA Standard 1300:

  • Ongoing Monitoring: Real-time review of working papers, supervisor sign-offs, and methodology adherence
  • Periodic Reviews: Internal QA reviews quarterly; External assessment every 5 years (next due: 2026)
  • Metrics Tracked: Audit cycle time, finding recurrence rate, management satisfaction, remediation closure rate

9. Data Access & Confidentiality

Audit personnel operate under strict data handling protocols:

  • Access granted via AZ-IDM with least-privilege principles
  • All data extracted must be anonymized where PII/PCI/SPI is involved
  • Encryption at rest (AES-256) and in transit (TLS 1.3+)
  • Immediate revocation upon engagement closure or role change
Breaches are reported to DPO and Legal within 24 hours per AZ-Data-Breach-Protocol.

10. Version History

VersionDateAuthorDescription
3.22024-11-15J. Aris (CAE)Updated risk scoring matrix, added ISO 31000 alignment, revised follow-up escalation thresholds
3.12024-06-02M. Chen (Sr. Manager)Incorporated cybersecurity audit annex, updated data classification references
3.02024-01-10J. Aris (CAE)Major overhaul post-Audit Committee directive; aligned with updated IIA 2024 standards
2.42023-05-18Legal & ComplianceAdded GDPR/CCPA data handling requirements, updated reporting templates