Internal Audit
Growthpoint’s policy is to
provide and support an internal
audit function that acts as an
independent, objective assurance
and consulting activity. The
activity assists the organisation to
accomplish its objectives through
a systematic, disciplined approach
that enables it to evaluate and
improve the effectiveness of
risk management, control and
governance processes
The internal audit function is provided in-house and is the responsibility of the Head of Internal Audit and Risk Management.
AUTHORITY
The internal audit function derives its authority
from the Audit Committee to whom it reports
on a quarterly basis. The committee is guided
by its Terms of Reference. The objectives,
authority and responsibility of the internal
audit function are governed by a formal
Internal Audit Charter. The personnel of the
internal audit function are authorised to review
all areas of the operations and have complete
and unrestricted access to all activities, records,
property and personnel. Furthermore, the
Head of Internal Audit and Risk Management
has unrestricted access to the Chairman of
the Audit Committee, as well as committee
members in the absence of management at
quarterly meetings, if required.
RESPONSIBILITIES
The responsibilities of the internal audit
function include:
| • |
submitting an annual internal audit plan
to the Audit Committee that indicates the
extent and frequency of the work to be
conducted, which enables the committee
to establish whether or not internal audit
resources as well as the allocation thereof
are appropriate to its requirements |
| • |
conducting reviews of the key business
processes to ensure the:
| — |
reliability and integrity of financial and
operational information |
| — |
adherence to policies, plans, procedures,
laws, regulations and contracts |
| — |
safeguarding of assets |
| — |
economic and efficient employment of
resources |
| — |
achievement of established objectives
and goals |
|
| • |
reporting the results of reviews, together
with opinions and recommendations to
management of sufficient authority to
ensure that appropriate action is taken when
required |
| • |
quarterly reporting to the Audit Committee
on:
| — |
the adequacy or design effectiveness
and the operating effectiveness of the
systems of internal control |
| — |
internal audit findings, recommendations
and management’s action plans |
| — |
the progress against the internal audit
plan and reasons for deviation |
|
| • |
coordinating audit efforts with those of the
external auditor |
| • |
overseeing the performance and reporting
of information technology-related internal
audit reviews, which are outsourced to
external parties who have the requisite
technical proficiency and experience to
conduct such reviews |
| • |
addressing the matters brought to the
attention of the organisation, through the
Tip-offs Anonymous Helpline operated
by Deloitte, and reporting the nature of
the incidents and the resultant actions, if required, by executive management to the
Audit Committee. |
INTERNAL AUDIT PROCESSES
The scope of the internal audit activity and the
assignments planned for the ensuing financial
year are presented, discussed and approved
at the last Audit Committee meeting of the
financial year. The internal audit plan is based
on an assessment of Growthpoint’s key areas
of operational risk with regard to its current
operations and the key risks as identified
and assessed as part of the risk management
process.
The internal audit plan is, however, subject to
change during the financial year depending on:
| • |
unforeseen circumstances within the
organisation |
| • |
any specific requirements of executive
management |
| • |
any specific requirements of the Audit
Committee. |
The establishment and maintenance of systems
of internal control necessary to provide the
directors of Growthpoint with reasonable
assurance that business objectives are attained
rests with both executive and operational
management. Internal Audit’s role is to assist
management in establishing whether or not the systems of internal control are both adequate
and effective. Adequacy is defined as whether
or not the key controls address the related
significant inherent risks, whereas effectiveness
is defined as whether or not the key controls are
operating as intended.