Internal Auditing Skill

  • View
    230

  • Download
    0

Embed Size (px)

Text of Internal Auditing Skill

  • 8/3/2019 Internal Auditing Skill

    1/28

    INTERNAL AUDIT

    Auditing Technique

    Det Norske Veritas AS. All rights reserved Slide 210 June 2009

    The Purpose

    WHY AUDIT?

  • 8/3/2019 Internal Auditing Skill

    2/28

    Det Norske Veritas AS. All rights reserved Slide 310 June 2009

    Management System Audit

    Whats done in an audit ?

    Effectiveness of an organisations Management System is assessed

    Det Norske Veritas AS. All rights reserved Slide 410 June 2009

    Why Audit

    Required by the standard

    Determine system effectiveness

    Identify existing nonconformities

    Highlight areas of strength

    Point out areas for improvement

    Indicate requirements forcorrective and/or preventiveaction

  • 8/3/2019 Internal Auditing Skill

    3/28

    Det Norske Veritas AS. All rights reserved Slide 510 June 2009

    Management System

    Management System:- to establish objectives and to achieve those objectives

    Quality Management System:

    - to direct and control an organisation with regard to quality

    System:

    - set of interrelated or interacting elements

    Det Norske Veritas AS. All rights reserved Slide 610 June 2009

    System Audit

    The process of assessment has to be

    OBJECTIVE

  • 8/3/2019 Internal Auditing Skill

    4/28

    Det Norske Veritas AS. All rights reserved Slide 710 June 2009

    System Audit

    Assessment is a comparison of implemented Quality System with QualitySystem Standards like ISO 9000 or, implemented OHS system withOHSAS18001

    However results depend on Auditor

    - hence this training

    Det Norske Veritas AS. All rights reserved Slide 810 June 2009

    What is sought by Auditor

    Established Policy and Objectives

    Developed appropriate systems

    Necessary documentation of the system

    Effective implementation of those systems

    Since we can never expect absolute perfection the auditor can onlyassess

    The Degree of Compliance

  • 8/3/2019 Internal Auditing Skill

    5/28

    Det Norske Veritas AS. All rights reserved Slide 910 June 2009

    System Standards

    Lay down principles that require interpretation

    The auditor must have very strong understanding of principles to be able

    to assess whether the standard has been

    - understood

    - interpreted

    - and can demonstrate adequate control

    Det Norske Veritas AS. All rights reserved Slide 1010 June 2009

    Questions in an auditors mind

    Is the system right and sufficient?

    Does the organisation do the right things to adequately control quality ofproducts or safety of employees?

    Does the organisation do things properly all the time?

    What is the evidence that things are done correctly?

  • 8/3/2019 Internal Auditing Skill

    6/28

    Det Norske Veritas AS. All rights reserved Slide 1110 June 2009

    Nagging questions

    What is adequate?

    When is a thing properly done?

    How much evidence is required?

    Buzz group : You are sent as an auditor to Purchase department and one of thearea to be verified is Issue of Purchase orders in time. How would you answerall the above questions ?

    Det Norske Veritas AS. All rights reserved Slide 1210 June 2009

    Auditor

    Needs to judge whether an organisation has arrived at a sensible andacceptable interpretation of the standard;therefore he must

    - study the standard to improve understanding

    - objective of the system is that performance must be consistently achieved

    - consider possible consequences of something going wrong due toinadequacy

    - take account of others opinion

    - always use common sense

  • 8/3/2019 Internal Auditing Skill

    7/28

    Det Norske Veritas AS. All rights reserved Slide 1310 June 2009

    Auditor

    Looks for:- established policies and objectives

    - developed appropriate systems

    - documentation to ensure adequate control

    - effective implementation of the system

    Since we can never expect absolute perfection, the auditor can onlyassess

    THE DEGREE OF COMPLIANCE

    Det Norske Veritas AS. All rights reserved Slide 1410 June 2009

    System Audit

    Systematic, independent and documented process for obtaining evidenceand evaluating it objectively to determine the extent to which the audit

    criteria is fulfilled

  • 8/3/2019 Internal Auditing Skill

    8/28

    Det Norske Veritas AS. All rights reserved Slide 1510 June 2009

    Types of Audit

    Internal Audit

    External Audit

    Third Party Audit

    Det Norske Veritas AS. All rights reserved Slide 1610 June 2009

    Auditor Competence

    Auditors demonstrated capability to apply knowledge and

    skills

    based on

    - education

    - experience

    - training

    Qualification process:

    - process to demonstrate the ability to fulfil specified requirements(in this case the auditors qualification)

  • 8/3/2019 Internal Auditing Skill

    9/28

    Det Norske Veritas AS. All rights reserved Slide 1710 June 2009

    Audit conventions

    Audits create stress. Uncertainty amplifies stress

    - Act predictably

    Det Norske Veritas AS. All rights reserved Slide 1810 June 2009

    Why conventions?

    To reduce stress

    To have clear methods of audits

  • 8/3/2019 Internal Auditing Skill

    10/28

    Det Norske Veritas AS. All rights reserved Slide 1910 June 2009

    Audit conventions

    Start at the top Audit must be planned

    Examination/Evaluation

    Reports

    Follow up action

    Det Norske Veritas AS. All rights reserved Slide 2010 June 2009

    Types of audit

    Process

    Product

    Quality System

    Compliance

    Health & Safety

    Environmental

    Financial

  • 8/3/2019 Internal Auditing Skill

    11/28

    Det Norske Veritas AS. All rights reserved Slide 2110 June 2009

    WHAT IS AN AUDIT?

    A health check Key words

    - Systematic

    - Documented

    - Periodic

    - Objective

    - Verification

    Det Norske Veritas AS. All rights reserved Slide 2210 June 2009

    KEY CONCEPTS

    Verification Evaluate compliance to requirements

    Systematic Carried out in accordance to set protocols

    Periodic Conducted to established schedule

    Objective Auditors have some independence and findings need evidences

    Documented Reports are prepared

  • 8/3/2019 Internal Auditing Skill

    12/28

    Det Norske Veritas AS. All rights reserved Slide 2310 June 2009

    AUDIT TERMINOLOGY

    Audit Cycle:- period over which ALL

    parts of organisation

    are audited

    Audit Programme:

    - timetable within audit cycle

    - shows whats audited, when and by whom

    Det Norske Veritas AS. All rights reserved Slide 2410 June 2009

    AUDIT TERMINOLOGY

    Audit Protocol/Procedure:

    - detail of individual audit including:

    - audit scope

    - audit frequency

    - audit methodologies

    - personnel and experience

    - documentation required

    - reporting and distribution

  • 8/3/2019 Internal Auditing Skill

    13/28

    Det Norske Veritas AS. All rights reserved Slide 2510 June 2009

    AUDIT SCHEDULING

    Unscheduled - usually prompted by:- Significant change in personnel

    - Change in regulations

    - Process change

    - Customer complaint

    Det Norske Veritas AS. All rights reserved Slide 2610 June 2009

    Process to be

    Audited

    02

    Q1

    02

    Q2

    02

    Q3

    02

    Q4

    03

    Q1

    03

    Q2

    03

    Q3

    0

    Q

    Procurement x x

    Marketing x x

    Design

    x x x xQuality Assurance x x x

    Production x x

    AUDIT PROGRAMME

  • 8/3/2019 Internal Auditing Skill

    14/28

    Det Norske Veritas AS. All rights reserved Slide 2710 June 2009

    Actual

    Performance

    Time

    audit&

    review

    audit&

    review

    audit&

    review

    contin

    ualim

    prove

    ment

    Baseline 1

    Baseline 2

    Baseline 3

    HOW TO ACHIEVE CONTINUALIMPROVEMENT

    Det Norske Veritas AS. All rights reserved Slide 2810 June 2009

    AUDIT TEAM REQUIREMENTS

    Audit team should include experience as:

    - Team leader

    - Systems auditor

    - Technical specialist

    - If not resourced internally then externally

  • 8/3/2019 Internal Auditing Skill

    15/28

    Det Norske Veritas AS. All rights reserved Slide 2910 June 2009

    AUDIT TEAM REQUIREMENTS

    Audit team preferably to have 2 persons:Auditor and Second Man- Second Man

    - looking while the auditor is questioning

    - listening and taking notes

    - helping share load

    - corroborating findings

    - helping draft NCs

    - assists reporting

    Det Norske Veritas AS. All rights reserved Slide 3010 June 2009

    STAGES OF AN AUDIT

    Pre-audit activities

    Audit activities

    Post audit activities

  • 8/3/2019 Internal Auditing Skill

    16/28

    Det Norske Veritas AS. All rights reserved Slide 3110 June 2009

    CONDUCTING AN AUDIT

    Pre-Audit- Agree the scope and standards of the audit

    - Establish methods of assessment

    - Select auditors

    - Allocate time frame

    - Review documented MS

    - Research other background information (requirements)

    - Plan the audit (checklists etc.)

    Det Norske Veritas AS. All rights reserved Slide 3210 June 2009

    Audit by departments

    Audit by clauses

    Auditing by proce