Internal audit exists because the board cannot rely on management's own account of whether controls work. Every other function in the company reports through management; audit is deliberately wired differently, so that its conclusions do not need management's approval. For directors and owners, it is the only regular source of independent evidence about the state of internal control, including resilience. That independence is the entire value of the function.
Audit's mandate sits in an audit charter approved by the board, with functional reporting to the audit committee and administrative reporting inside the executive. Work follows a risk-based audit plan agreed annually. Applied to continuity, a typical engagement checks whether plans exist and are current, whether exercises actually happened and what the evidence shows, and whether findings from past incidents were closed; the results go to the audit committee with management's response attached. As the third line, audit assures the programme rather than running it.
The classic mistakes are two: pulling audit into designing controls it will later have to audit, which destroys independence through self-review, and using audit as a substitute second line because no risk function exists. Both give the board false comfort dressed as assurance. A smaller but common error is auditing documents rather than outcomes, plans on paper instead of recovery in practice. ERGP module M6, on assurance, is built around these distinctions.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme