Testing operation, not documentation
Most organisations have a control framework on paper. The question internal audit answers is whether it is followed when nobody is watching, under deadline pressure, by staff who joined after it was written.
We test transactions and observe processes rather than reviewing policy documents.
Where we usually start
Procurement and payments, revenue and receivables, payroll, inventory and asset custody, and delegation of authority. These are where control failures most commonly turn into cash losses.
Reporting that gets acted on
Findings are rated by risk, with a named owner and an agreed deadline for each. Follow-up is scheduled, so the second report tells you what was actually fixed rather than repeating the first.
How the engagement runs
Scope
Agree the risk universe with management and the board, and prioritise what to audit first.
Test
Walk through processes and test real transactions against the stated control.
Report
Risk-rated findings with a named owner and an agreed remediation date.
Follow up
Re-test at the agreed date and report what was actually closed.
Frequently asked questions
What does internal audit do?
Is internal audit mandatory in Qatar?
Can our external auditor also be our internal auditor?
How often should internal audits be performed?
What is the difference between internal audit and a compliance review?
Need this done?
Tell us your deadline and we will tell you what is required, what it involves and what it costs.


