Impact of COVID-19 on Internal Audit
CA. Amit Gupta & CA. Ankur Gupta
The authors are members of the Institute. They can be reached at amit2004@gmail.com and eboard@icai.in.
“Internal Audit comes with an objective of delivering assurance and consulting activity designed to add value and improve an organization’s operations. The underlying function of conducting an Internal Audit is to measure the risk exposure of the firm to various known and unknown factors and establish control measures for the same. The fundamental characteristic of risk is that it is uncertain. One such uncertain risk that has currently prepossessed our world is in the form of Novel Corona Virus pandemic (COVID-19). Read on to know more…”
Over a short period, this pandemic has impacted the human life in more ways than one, its impact is visible in threat to life both physically as also economically. With time, and with convenience of movement, coupled with lack of serious steps, the pandemic has shifted its hub from China to geographies such as USA and Mainland Europe.
The spread of the pandemic and its impact on countries, businesses, processes, lives, etc cannot be ignored. Since the global outbreak of COVID-19, the panic and fear among the public throughout the globe is spreading faster than the virus.
The corona virus outbreak across the countries has hampered the local economy, which has had multiplying results on the large and small-scale organizations in each sector of the economy. This crisis also has significant economic effects on companies, for example due to restrictions in production, trade and consumption or restrictions due to travel bans or non-availability of man-power for operations which require manual interface. According to many economists, the global economy might now grow at its slowest rate since the 2008 crisis.
If we listen to any business owner during this time, there would be hardly anyone saying that the pandemic has not affected them. One of the critical things coming out in this time, is the focus on ‘Cash flow’. Businesses have realised the criticality of having cash on book and money in bank. Businesses, which were less leveraged, and operating at lower fixed costs, will find it easier to drive through this fight against pandemic. One of the key business owners has recently made a comment that these are time when one should look for ‘Cash above EBITDA’. As liquidity dries up in the market, a company, which will operate on immediate cash flow with less margin, will be much better placed than a company will in high margin business with low cash flow.
“As liquidity dries up in the market, a company, which will operate on immediate cash flow with less margin, will be much better placed than a company will in high margin business with low cash flow.”
Further development, duration and impact of the coronavirus cannot be predicted. However, a safety net has to be established in order to minimize the risks and losses of the companies to the minimum level possible.
Role of Internal Audit
Following the outbreak, the organisations, their environments, and their ways of working are evolving rapidly and in ways that had not been previously envisioned. With a rapidly changing landscape, to help the company adapt in response, Internal Audit must also change whilst continuing to play the role of critical assurance, advising management and board in face of changing risk factors and aid to anticipate and mitigate risk.
Individual country situations differ greatly and are changing rapidly and dramatically, so it becomes imperative for Internal Audit functions to keep abreast of governmental and regulatory announcements, and follow centrally coordinated organizational responses. However, the impact on companies differ and Internal Audit must consider how it affects their business and review them regularly.
It is business critical that Internal Audit is proactive and prepared, while remaining pragmatic, as the pandemic situation continues to evolve. As the pandemic continues, Internal Audit Heads need to consider many things, which include some of the key considerations as set out below:
Key Considerations for Internal Audit
Internal audit plays a vital role in the pandemic from multiple perspectives. This includes some of the factors such as –
- to review the organization’s business continuity, crisis management and pandemic preparedness
- need to check the organization’s cash management practices also arises to enable it sail through the unexpected crisis
- provide immediate services for the risk mitigation, and
- later to-return-to-business-as-usual effort
Internal Auditors should undertake such activities in line with the standard of internal audit with focus and having regards to the deviations required looking at the current scenario. Auditors may need to consider developing alternative procedures to gather sufficient appropriate evidence to support their opinion on the quality of internal controls. Internal Auditors will also need to consider the following considerations:
- Agile and Lean Approach: Approach for Internal audit will need to be agile and lean. It will need to focused on short term and regular updates to mirror the changing pace of risk and assurance needs.
- Focus on Priority & Material Areas: To optimise on limited management bandwidth during times of crisis, it will be critical for Internal Auditors to focus on priority areas, which are material to business. For the prioritisation of audit plan, it will also be important to consult and take formal approval of the Audit Committee for scope modifications.
- Re-purposing IA Resources: In certain cases, the internal audit staff may be called upon to support / perform management functions. It will be important for Internal Audit Head to discuss with the Audit Committee and formally agree with them if resources can be re-purposed to support with projects or any other critical activities of organization.
- Avoiding Redundant Overlaps: Need to look for ways to avoid overlaps with other service providers such as External Auditors, Compliance, etc.
- Monitoring New & Elevated Risks: To keep an eye on new / elevated risks, in discussion with the different stakeholders.
- Alternative Delivery & Virtual Modes: To consider different ways to operate and deliver work in time, such as using virtual modes of communication for meetings / reviews, talk-throughs, etc.
- Electronic Audit Evidence: Availability of information / audit evidence with the auditees in electronic mode.
- Deploying Analytics: Deploying tools for Analytics to deliver work focused on coverage and quality.
Challenges for Internal Audit
The COVID–19 pandemic has all the ingredients to send many organisations to the wall and Internal Audit is not safe from this as well. A well planned out Internal Audit can be jeopardized in such situations. Audit teams, which were well settled, are suddenly facing major issues. Following are some of the key challenges that IA faces in these times:
• Low Staff Motivation
It is necessary to keep the staff motivated and support them whilst working in remote environments. Weekly team catch-ups, check-ins to discuss any trivial issues or workload, daily stand-ups to track the work are some ways to connect with the staff professionally. Virtual coffee sessions can be planned and success stories can be shared to maintain a positive outlook and a personal touchpoint.
• Business Existence Lost
Internal Audit can maintain its existence in the business by increasing the number of meetings with key stakeholders in order to develop strong relationship, credibility, trust and efficiency with clients. This can be done by doing video calls and conferences.
• Reduced Controls Hygiene
Identification of instances of control that override with employees seeking workarounds to existing internal controls in order to keep the business operating efficiently should be looked into. IA should make it clear to the management that even in situations like these maintaining controls is paramount. In extreme situations, alternate / compensatory controls should be put in place.
• Work Challenging Auditor Independence
Organisations will expect Internal Audit to use its professional expertise to help the management in current situation. However, they should limit their scope to providing merely the advice and not get involved in the implementation. This can be done by forming distinct teams.
• Review Quality Hampered Due to Remote Working
Technological capabilities available such as Zoom, Skype, Microsoft Teams should be used to maximum for virtual meetings and/or workshops. In addition, by reducing the quantum of Internal Audits, high quality review can be provided. IA should look into how it maintains its own review mechanism on evidences, work paper and reports during such times.
• Restrictive Travel Policy
The restrictions in travel ban for overseas work can be taken care of by using in-country resources or a third party to the extent where domestic travel is permissible.
Emerging Risk Areas to Consider
The current situation has led to complete transformation of the way work is being done. This will not only change the way audits are done, it will also open up new avenues or areas where audit focus can be increased. Below are some of such areas:
Impact on the Three Lines of Defense Model
The three lines of defense model is also significantly impacted, with the three lines some-how being merged into each other despite the best efforts of management / internal audit. The day-to-day disruptions will lead to challenges on the risk, control and defense framework.
- Fraud Risk: During such difficult times, the line separating acceptable from unacceptable behaviour often become blurred. Organizations need to be sensitive to possible financial statement manipulations. Further, with employees also being under tremendous pressure this could lead to an increased risk of fraud by employees.
- User Access Controls: Due to flexible working arrangements and individuals requiring greater access to systems to help cover for people who are off location, user access controls may be compromised and conflicts of interest may arise. Internal Audit should monitor such controls, as it is critical to review the process of maintaining an audit trail for user access changes.
- Finance: Financial risk includes reviewing process of analyzing working capital requirements against scenario planning assumptions and assessing cash flow forecasts, reviewing organization’s response process towards completeness of management’s accounting and reporting impact analysis, particularly in the context of year-end financial statements and forthcoming quarterly reporting deadlines and review considerations pertaining to increased exposures in insurance liabilities.
- Internal Controls: Internal audit should understand the changes, both temporary and permanent, being made to the organization’s internal control environment, with a specific focus on the management review controls, accounting judgment controls (bad debt provision, inventory provision, impairment of goodwill and intangible assets, fair value of financial and non-financial assets), associate or joint venture accounting controls, transaction processing controls, cash payments controls, automated business controls, outsource service providers, insider trading concerns, key person dependency/super user access, and resilience and remote working.
- Cyber: As the number of remote working environments and the use of third-party software to improve the effectiveness of remote working increases, individuals may inadvertently compromise business security.
- Insurance Cover: With home and remote places becoming the new workspace, there can be increased exposure to insurance liabilities. It is also essential to see whether health and safety standards are being complied with.
- Business Continuity: Various disaster recovery plans need to be made to test appropriate scenarios, plans or measures to restore business operations, validating and benchmarking management’s assumptions regarding nature, extent, and duration of situation and to forecast the financial and business impact like going concern, goodwill etc.
- Contracts: Internal audit should review the impact and adequacy of key contractual clauses which may offer relief during this time, such as force majeure, notice provisions, disaster recovery and business continuity provisions, limitation of liability, liquidated damages, governing law and jurisdiction, supplier/subcontractor location and supply chain path and termination rights.
- Human Capital: The adequacy of plans being put in place by organisations to maintain the health and well-being of their workforce, including the implications for impact on mental health of remote working should be checked. It should be ensured that any ‘work arounds’ used during lockdown period are regularised and appropriately controlled.
Control Environment Considerations
None of the businesses today have seen an event like this in the past to be able to judge the exact way of working or the way business will be conducted during these times. The same logic applies to the overall control environment as well for any business.
With the control structures being modified overnight to keep business clock ticking, there are and will be number of instances where significant sudden change will be made in control set up. The three lines of defense model is also significantly impacted, with the three lines some-how being merged into each other despite the best efforts of management / internal audit. The day-to-day disruptions will lead to challenges on the risk, control and defense framework.
In such a scenario, it becomes imperative for internal audit to contemplate the extent and impact of such changes. There are certain key questions for which Internal Audit needs to find answers to:
- Execution of Controls and Monitoring: Users should be aware of what is the critical information which needs to be monitored and what additional monitoring processes are required, e.g. Daily outstanding review instead of a weekly review. In addition, there has to be innovation in terms of how controls are being performed, e.g. using drones for conducting physical verification. The evidence of control will also undergo a change, as there might not be physical signatures available for review.
- Risk Assessment Impact: Internal Audit should take a note of the change, which the pandemic has bought to the overall risk assessment of the business. This may lead to a complete rework on the risk assessment framework. In addition, monitoring of emerging risks as they come should be included in the risk assessment process.
- Preparation for Control Assessments: There will be a need to create or enhance existing policies and procedures to adapt to COVID-19 impact, inclusive of roles and responsibilities, timelines and content of policies. The risk control matrices which are being used need to change basis changes in control environment including mitigating controls set up during this time. Internal Audit, along with control owners, also need to finalise a testing strategy which will be used in times to come including use of technology and alternate testing evidences (if any).
- Allocation of Resources: It should be ensured that resources are mapped accurately to the work, basis the control environment. Also, in situation like this the company should have back up resources for each critical control activity.
- Key Service Organisation Reliance: There are certain service providers that become key in situations like these, e.g. Internet service provider. IA should see what additional oversight controls have been established on such vendors. In addition, if there are any critical services that have been outsourced, a focused risk assessment needs to be done on such services basis criticality.
- Remote Access: There should be sufficient technology support in terms of hardware and software to ensure remote access to all users. There have been instances where companies were not prepared for such a scenario and do not have sufficient tools to enable work from home, e.g. Laptops to all users, VPN access etc. The technology tools should also have established proper firewalls and password control procedures like Multi factor authentication, since employees will be using the home internet networks, which are more susceptible to hacking or other risks.
Case Study – Traditional Internal Audit vs Internal Audit during Pandemic
To understand a practical scenario of what practically may change, while conducting an audit during current phase of pandemic refer to the table below:
Conclusion
The coronavirus pandemic is one of the best examples yet of just how quickly a risk can materialise in today’s business environment that can change everything and even threaten the future of companies that were on solid footing just weeks ago. With people unable to collaborate in groups, Internal Audit will struggle to complete its work. Technology, like cloud services, virtual meetings, and Internal Audit management systems can help when auditors need to work from home, but Internal Audit will also need some creativity, perseverance, patience, and understanding to work through the crisis.
The pandemic will be over at some point, but just what shape our organizations are in when it does, will rely greatly on the actions and decisions that are being made right now and Internal Audit should play an important role in working through them. ■