erlaubnisantrag.comRegulatory Pathfinder
DEEN
REGULATORY TOOLS / GRC

Internal audit: independent review that leads to action

Internal audit gives management an independent view of whether organisation, risk management and controls work in practice. It examines evidence and follows findings through to remediation.

Mandate, independence and audit universe

Audit needs unrestricted information access and a direct reporting line to management. It reviews all activities and processes on a risk basis, including outsourced operations. It must avoid reviewing its own work; advisory activity and project observation require safeguards for independence.

Audit universe

A complete map captures processes, systems, units, providers and material changes. It is the basis for risk assessment and audit planning.

Division of roles

Compliance monitors and advises within its regulatory remit. Audit independently assesses the wider organisation and the effectiveness of control functions.

Risk-based audit plan

For banks, the plan is updated annually; WpI MaRisk requires annual risk-based planning for medium-sized investment firms. Planning considers changes and different risk sources and is approved by management. Ad hoc reviews remain possible. Banking MaRisk generally specifies three-year coverage, or five years for non-material processes; higher risks require shorter cycles.

Priorities

Risk profile, past findings, complaints, incidents, new products, IT changes and outsourcing shape topic, depth and timing.

Planning and capacity

Questions, scope, timing, expertise and effort should make changes to the plan and emerging risks transparent.

Fieldwork, findings and follow-up

Each review needs documented criteria, samples, working papers and a timely report. Audit distinguishes cause, risk and effect, then tracks agreed actions to demonstrable resolution.

Testing

Documents, data and interviews are tested against requirements and real cases. The report describes scope, findings and remedial measures.

Reporting and escalation

Banking MaRisk requires at least quarterly reports to management, immediate escalation of particularly severe findings and monitoring of remediation.

Project observation without self-review

For major initiatives, audit can highlight risks, control gaps and evidence needs early. It does not make product, technology or approval decisions and does not run the project. Its independence for later reviews remains intact.

Example

For a new digital onboarding journey, audit may examine project governance, migration, test evidence, exceptions and handover to business as usual.

Typical evidence

Audit charter, audit universe, risk assessment, approved plan, working papers, engagement reports, quarterly reports and action log.

Sources and applicability

Duties depend on firm type and activity. Under WpI MaRisk, internal audit depends on appropriateness and proportionality. For very small firms, AT 4.4.3 may allow management to perform the tasks or, subject to its conditions, omit the function; the relevant conditions and conflicts of interest need assessment. This overview does not replace an applicability assessment.

FURTHER MATERIAL

Internal Audit review plan

Want to turn these topics into a review plan for your business? See the proposed outline, then request more information by email.

Internal Audit review plan

This outline covers the following modules. The button opens an email request; there is no immediate file download here.

Did you know?

From the Pathfinder

Business concept

How an app can become an activity that requires permission.

Explore topic →

Have you explored?

Across our tools & projects

Fit & Proper · skills matrix

Prepare management profiles and collective suitability reviews.

Explore tool or project →

International market entry / Germany

Is Germany your next market?

Considering a local office, a branch or a standalone authorisation in Germany? The appropriate route depends on your home jurisdiction, activities and operating model. 3RMCN combines experience from complex supervisory projects with product, technology and delivery expertise: from entry strategy and key interfaces through to operational readiness.

Discuss your plans ↗

Supervisory perspectives

Familiar with several regimes

Experience in the context of CySEC (Cyprus), MFSA (Malta), FCA (United Kingdom), the European ESMA framework and MAS (Singapore). ESMA is not a national licensing authority.

International structuring

Incorporating offshore?

For incorporation in offshore jurisdictions, relevant specialists from the network can be involved. Jurisdiction, activities and regulatory obligations need to be considered for each project.