Introduction

Internal Audit at Ïã½¶ÊÓÆµ¹ÙÍø functions as an independent and objective assurance activity established to evaluate and improve the University’s governance, risk management, and internal control processes. Operating in conformance with the IIA Global Internal Audit Standards (2024) and applicable public‑sector requirements, the function supports the Board of Regents, the President, and senior leadership in fulfilling their oversight responsibilities and ensuring the effective, ethical, and accountable use of institutional resources.

 

Frequently Asked Questions

 

What is the role of Internal Audit at Ïã½¶ÊÓÆµ¹ÙÍø?

Internal Audit provides independent, objective assurance and advisory services designed to strengthen governance, risk management, and internal control. The function supports responsible stewardship of public resources, ethical conduct, and continuous improvement across University operations. Work is performed in alignment with the IIA Global Internal Audit Standards (2024).

 

How is Internal Audit independent? Who do you report to?

Internal Audit’s independence is protected through a dual‑reporting structure:

  • Functionally to the Board of Regents Internal Audit, Risk, and Compliance Committee through the USG Chief Audit Officer

  • Administratively to the President of Ïã½¶ÊÓÆµ¹ÙÍø

This structure ensures Internal Audit can determine the scope of work, access necessary information, and report results without interference. Independence and objectivity are further reinforced through the IIA Code of Ethics and the Internal Audit Charter approved by the BOR Internal Audit, Risk, and Compliance Committee.

 

What authority does internal audit have?

Consistent with the Internal Audit Charter and the IIA Standards, Internal Audit has:

  • Unrestricted access to records, systems, data, and personnel

  • Authority to determine the nature, timing, and extent of audit work

  • Responsibility to provide professional judgment on governance, risk, and control effectiveness

  • Freedom from management influence over audit conclusions

This authority enables Internal Audit to perform its work effectively and objectively.

 

Why are there so many auditors on campus?

Multiple oversight groups support accountability across the University System of Georgia:

The campus internal auditors are responsible for supporting the institution’s management in meeting governance, risk management, and compliance responsibilities while helping to improve organizational and operational effectiveness and efficiency. Internal Auditors from the are similarly responsible for system-wide issues.

The provides an opinion on whether or not Ïã½¶ÊÓÆµ¹ÙÍø’s financial statements “present fairly, in all material respects, the financial position as of the fiscal year end”. 

Also, many of our relationships include a right-to-audit clause where the contracting party can verify that we are performing as expected. These other relationships may include the , , grantors, etc.

These groups help ensure compliance, transparency, and responsible stewardship of public resources.

 

Why does Ïã½¶ÊÓÆµ¹ÙÍø have so many policies and procedures?  

As a public institution, Ïã½¶ÊÓÆµ¹ÙÍø is subject to the rules set out by many regulatory and governing bodies. In addition to the Georgia Code, we need to be follow policies and procedures set out by the , the , the , and many more! Furthermore, departments also maintain internal procedures to ensure consistent operations and effective internal controls. Management is responsible for implementing these controls; Internal Audit evaluates whether they are designed and functioning as intended.

 

What is the Internal Audit Charter?

The Internal Audit Charter (Ïã½¶ÊÓÆµ¹ÙÍø IA Charter) defines the purpose, authority, and responsibility of the Internal Audit function. It is approved by the BOR Internal Audit, Risk, and Compliance Committee and reviewed periodically to ensure alignment with the IIA Standards and USG expectations. The Charter affirms Internal Audit’s independence and unrestricted access necessary to perform its work.

 

Does Internal Audit coordinate with other oversight and compliance functions?

Yes. Internal Audit collaborates with risk management, compliance, IT security, finance, and external auditors to support integrated assurance, reduce duplication, and address gaps. This coordination aligns with Standard 9.5 – Coordination with Other Assurance Providers.

 

How is the audit plan developed?

Ïã½¶ÊÓÆµ¹ÙÍø uses a risk‑based audit planning process, consistent with Standard 9.4 – Internal Audit Plan:

  • Meetings with the President, Vice Presidents, and campus leaders

  • Review of institutional risks, strategic priorities, and emerging issues

  • Analysis of surveys, questionnaires, industry practices, prior audit results, ERM inputs, and operational data

  • Risk scoring within Onspring

  • Approval by the Cabinet, President, and USG Chief Audit Officer

  • Final approval by the BOR Internal Audit, Risk, and Compliance Committee

Resources are allocated to areas with the highest potential impact on institutional objectives and compliance obligations.

 

Why was my area selected for audit?

Your area was selected because the risk‑based planning process identified significant risks, changes, or dependencies that warrant review. Selection is not punitive; it reflects the University’s commitment to strong governance and continuous improvement.

 

My area wasn't selected for audit, but we still received recommendations. Why?

Business processes often intersect across departments. During an audit of one area, Internal Audit may identify related risks or control gaps in another. Because Ïã½¶ÊÓÆµ¹ÙÍø’s operations are interconnected, improvements in one area may require action in another to strengthen the overall control environment.

 

What is the difference between assurance and advisory engagements?

  • Assurance engagements provide an independent evaluation of governance, risk management, and internal control.

  • Advisory engagements offer insight and recommendations to improve processes but do not involve assuming management responsibilities.

Both engagement types follow the IIA Standards and maintain auditor objectivity.

 

Can Internal Audit help my department improve a process?

Yes. Internal Audit can conduct an advisory engagement to help identify opportunities to strengthen internal controls, improve efficiency, and enhance reliability. Advisory work supports management but does not replace management’s responsibility for operations.

 

How are audit results communicated?

Audit results include:

  • A professional judgment on the effectiveness of governance, risk management, and internal control

  • Prioritized findings based on significance

  • Root‑cause analysis and recommended corrective actions

  • Agreed‑upon timelines for remediation

Results are communicated to management and the President, and significant and material issues are reported to the BOR Internal Audit, Risk, and Compliance Committee through the USG Chief Audit Officer.

 

How does Internal Audit ensure quality?

Internal Audit maintains a Quality Assurance and Improvement Program (QAIP) that includes:

  • Ongoing supervision and monitoring

  • Periodic internal assessments

  • An External Quality Assessment (EQA) at least every five years

Every five years, USG IA will undergo an external QAR performed by a team of reviewers approved
by the Chancellor and BOR Internal Audit, Risk, and Compliance Committee (IARC). The review will assess the administrative compliance of USG Internal Audit department across all campus-based offices and the system office. To evaluate audit work quality, the review team will examine work products from seven of the fourteen audit
offices, rotating the selected offices every five years to ensure that all fourteen audit offices are subject to work product review over a ten-year period.

QAIP results are shared with senior leadership and the BOR Internal Audit, Risk, and Compliance Committee.

 

Can you deliver a talk to my unit/department/class/conference?

Yes! We offer a variety of professional development classes to assist the campus community in complying with state and federal regulations, established policies, procedures, and sound business practices. These workshops broaden the understanding within the University community of the importance of internal controls and accountability and ways to integrate continuous improvement in the operations.

 

I believe our process has opportunities for improvement. Can you work with us to help identify areas that need to be improved?

Yes! We can conduct an advisory engagement to help strengthen internal controls, which in turn help prevent errors from occurring and/or detect them if they do occur. Also, to improve operating effectiveness and efficiencies.

  

I suspect illegal, unethical, or irresponsible acts. What can I do?

Use the wif you cannot report concerns through normal channels. Reports may be made anonymously. If you identify yourself, you are protected from retaliation under BOR and state whistleblower protections.

 

As a student, how can I pursue a career in Internal Auditing?

 

My question isn’t answered here. What should I do? Contact us.