top of page
Search

How We Reviewed an Entity-Level Control: A Governance Review of an Internal Audit Charter

An Internal Audit Charter may look like a relatively simple administrative document. In reality, it can be one of an organization's most important entity-level controls.


The Charter establishes the authority, independence, reporting relationships, responsibilities, and governance structure surrounding the Internal Audit function. If those provisions are weak, the weakness can affect Internal Audit's ability to evaluate controls throughout the entire organization.


The Accountware Group recently performed a detailed governance review of the Tucson Unified School District (TUSD) Internal Audit Function Charter. The purpose was not merely to proofread the Charter or determine whether one existed. The objective was to determine whether this entity-level control was properly designed to support an independent, adequately resourced, accountable, and effective Internal Audit function.


This article explains how that review was produced and illustrates a methodology auditors can use when evaluating the design effectiveness of governance-level controls.


Step 1 — Identify the Control Objective

Before testing a control, an auditor needs to understand what the control is supposed to accomplish.


TUSD's original Charter states that the Governing Board established the Internal Audit activity and that the Charter defines its role and responsibilities. It also requires annual Governing Board approval of the Charter and audit plan.


The Charter also addresses significant Internal Audit objectives, including operational efficiency and effectiveness, regulatory compliance, IT controls, financial reporting reliability, internal controls, risk management, and safeguarding assets.


From an entity-level-control perspective, however, the question becomes broader:


Does the Charter establish a governance structure capable of allowing Internal Audit to accomplish those responsibilities independently and effectively?


That became the fundamental control objective for the review.


Step 2 — Understand the Control as It Is Actually Designed

Auditors should resist the temptation to immediately compare a document against a checklist.


First, understand the existing control.


The TUSD Charter contained several significant positive provisions. For example, it established functional reporting to the Governing Board and administrative reporting to the Superintendent.


It also gave Internal Audit unrestricted access to District records and required employees and contractors to assist the auditor.


The Charter addressed independence, professional standards, audit planning, quality assurance, continuing professional education, and follow-up of audit findings.


These were not ignored simply because weaknesses were subsequently identified.


That is an important auditing principle:


A control review should identify what works as well as what does not work.


Our report therefore concluded that the Charter provided a credible foundation. Its strongest areas included mission and purpose, audit authority, access rights, operational independence, risk-based planning, professional development, and quality assurance.


Step 3 — Establish the Criteria

A design-effectiveness review requires criteria.


The Charter was evaluated against recognized governance and Internal Audit practices identified in the review, including:

  • 2025 Global Internal Audit Standards;

  • IIA Model Internal Audit Charter;

  • COSO Internal Control—Integrated Framework;

  • GAO Standards for Internal Control in the Federal Government, commonly called the Green Book;

  • Government Auditing Standards, or the Yellow Book; and

  • relevant Government Finance Officers Association governance practices.


For example, the review used these sources in evaluating whether TUSD's functional reporting relationship adequately protected Internal Audit independence.


This creates the classic audit relationship:


Condition → Criteria → Gap


What does TUSD's Charter require?


What should a well-designed Internal Audit governance structure require?


What is missing between the two?


Step 4 — Test Design Effectiveness, Not Operating Effectiveness

This distinction is critical.


The review was principally a design-effectiveness assessment.


We were not asking:

Did the Internal Auditor perform a particular audit correctly?

We were asking:

If everyone follows the Charter exactly as written, does the Charter itself provide reasonable governance mechanisms for Internal Audit to remain independent, properly overseen, adequately resourced, and accountable?

That is a very different audit question.


A control can be performed exactly as designed and still fail if the design itself is inadequate.


The TUSD review illustrates the point. The Charter explicitly states that the Internal Auditor reports functionally to the Governing Board.


That sounds strong.


But the analysis went another level deeper: What does "functional reporting" actually require the Governing Board or Audit Committee to do?


The review found that the Charter did not fully assign responsibilities for matters such as safeguarding independence, evaluating resources, periodically assessing Internal Audit effectiveness, overseeing the Quality Assurance and Improvement Program, reviewing external assessments, and monitoring potential management impairment of independence.


That is a control-design issue, not necessarily evidence that anyone failed to perform an assigned responsibility.


Step 5 — Look for Missing Controls, Not Just Bad Controls

Some of the most significant audit findings involve controls that do not exist.


The review ultimately identified 20 governance findings: 5 Critical, 8 High, and 7 Moderate. The governance dashboard on page 11 of the report organizes those findings by priority, governance area, and risk.


The five Critical findings involved:

  1. Functional reporting relationships.

  2. Governing Board/Audit Committee functional governance.

  3. Internal Audit budget and resource oversight.

  4. Performance evaluation of the Internal Auditor.

  5. Appointment, reappointment, compensation, and removal authority.


Consider resource oversight.


The Charter can give an Internal Auditor authority to allocate available resources. But that does not answer a different governance question:


Who determines whether the resources provided to Internal Audit are sufficient in the first place?


The review found that the Charter did not establish a governance process requiring evaluation of budget, staffing, technology, specialized expertise, data analytics capabilities, or whether available resources were sufficient to execute the approved audit plan.


That is exactly the type of missing entity-level control that a superficial compliance review can overlook.


Step 6 — Determine Cause and Consequence

Finding a missing requirement is only the beginning.


Each significant finding was developed using an audit-finding methodology that examined:


Condition → Criteria → Cause → Consequence → Risk → Recommendation → Value Created


For example, regarding the Internal Auditor's performance evaluation, the review determined that the Charter established numerous responsibilities but did not assign responsibility for evaluating performance, establish evaluation frequency, define performance criteria, require stakeholder feedback, or establish how evaluation results would be documented.


The analysis then considered the consequence. Without a structured process, evaluations could become informal, subjective, or inconsistent, potentially reducing accountability and missing opportunities to improve Internal Audit performance.


This moves the analysis beyond:


"The Charter doesn't say X."


The more useful audit question is:


"What risk is created because the Charter doesn't say X?"


Step 7 — Risk-Rate the Findings

Not every control weakness deserves the same attention.


The findings were therefore classified as Critical, High, or Moderate.


The five Critical findings were reserved for matters affecting foundational Internal Audit governance—particularly independence, functional oversight, resources, performance accountability, and employment authority.


This risk-ranking process is essential because a 70-page governance review containing 20 findings can easily overwhelm a governing board.


The dashboard converts that detailed analysis into an executive-level view of the control environment.


Step 8 — Develop Corrective Action That Can Actually Be Implemented

An audit finding has limited value if management or the governing body cannot determine what to do about it.


For that reason, the review went beyond identifying deficiencies.


Major findings included:


Recommendation → Value Created → Management Priority → Suggested Charter Language → Applicable Standards


For example, the report recommends establishing an annual Internal Auditor performance evaluation conducted by the Audit Committee, with recommendations presented to the Governing Board. It also identifies specific evaluation criteria such as audit-plan achievement, report quality and timeliness, communications, independence, QAIP results, emerging-risk responsiveness, stakeholder feedback, and compliance with professional standards.


The report then provides suggested Charter language that could be used to implement the recommendation.


That makes the review actionable rather than merely diagnostic.


Step 9 — Focus on Value Creation

Auditing should not end with identifying what is wrong.


A well-designed audit should also explain what becomes better when the problem is corrected.


The TUSD review identified potential value including stronger independence, improved Governing Board oversight, a more effective Audit Committee, greater accountability, improved risk coverage, better use of public resources, greater institutional stability, and increased public confidence.


That changes the discussion from:


"Here are 20 things wrong with your Charter."

to:

"Here are 20 opportunities to strengthen an important entity-level control."


The Bigger Lesson for Internal Auditors

The TUSD project demonstrates why auditors should look carefully at entity-level controls before spending all their time testing transactional controls.


Purchase approvals, reconciliations, access controls, expense reports, journal entries, and payroll changes are important.


But governance controls operate above those processes.


A poorly designed governance structure can influence thousands of lower-level controls.

The Internal Audit Charter is a good example. It determines who Internal Audit reports to, what authority it possesses, how its independence is protected, how resources are evaluated, who evaluates its performance, and ultimately whether the Internal Audit function can challenge management when necessary.


That makes the Charter much more than a policy document.


It is an entity-level control over one of the organization's most important monitoring and assurance functions.


The methodology used in this review can therefore be applied well beyond Internal Audit charters. The same approach can be used to evaluate:


Board and Audit Committee charters, delegations of authority, enterprise risk management frameworks, ethics and compliance programs, fraud-risk governance, cybersecurity governance, financial reporting oversight, whistleblower programs, and other entity-level controls.


The methodology remains essentially the same:


Understand the objective. Understand the existing design. Establish defensible criteria. Identify the gaps. Determine their consequences. Risk-rate them. Recommend corrective action. Explain the value created.


That is how an auditor turns a document review into a meaningful assessment of entity-level control design effectiveness.




 
 
 

Recent Posts

See All
How Arizona CPAs Actually Get in Trouble

Lessons From the Arizona State Board of Accountancy Most CPAs do not begin their careers expecting to face professional discipline. They pass the CPA examination. They satisfy experience requirements.

 
 
 

Comments


Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page