Internal Audit Arrives Too Late to Assure Programme Delivery
Independence is not the same as distance from the decisions that create risk.
Beyond the Finding
Three days before a major design freeze, the programme director receives a 42-page internal audit report. It contains 34 findings, nine rated high priority. The programme has spent six months agreeing processes, configuring the new system and negotiating compromises between business units. Several findings challenge decisions made in the first eight weeks.
The auditors believe they have delivered independent assurance. The programme team believes it has been ambushed.
Both views are understandable. Neither produces control.
This scene recurs because internal audit and programme delivery have developed different ideas of what responsible work looks like. Audit values independence, evidence and the disciplined identification of weakness. Delivery values pace, resolution and the progressive narrowing of options. Each discipline is rational on its own terms. When they meet late, those strengths become opposing forces: the auditor appears to obstruct delivery, while the programme appears to resist scrutiny.
The usual diagnosis is cultural. Auditors are said to be cautious; programme leaders are said to be impatient. That explanation is convenient and mostly wrong. The conflict is structural. The two worlds enter the same decision at different times, use evidence for different purposes and assign accountability in different ways.
Until those mechanics change, calls for better collaboration will achieve little.
They Work to Different Clocks
A programme is a sequence of commitments. Early options are broad and comparatively cheap. As design, contracts, configuration and migration progress, choices become narrower and more expensive to reverse. Delivery depends on closing questions so that the next piece of work can begin.
Internal audit has traditionally worked in a different cycle:
- define a scope;
- gather evidence;
- test the evidence against an expected control;
- agree findings with management;
- issue a report and track actions.
That sequence is sound for examining an established operation. In a programme, the object being examined changes while the examination proceeds. A control described during fieldwork may be redesigned before the report is issued. More importantly, a finding can be correct and still arrive too late to influence the decision that matters.
Consider a composite systems programme replacing eight local finance applications with a common platform. Nine workstreams are working towards a January implementation. Internal audit begins a review in May, concentrating on governance, data conversion and access controls. Fieldwork ends in July; management responses are negotiated through August; the report reaches the steering committee in September.
By then, the programme has already:
- selected the conversion approach;
- signed off the account structure;
- assigned access-design responsibilities;
- reduced contingency to protect the implementation date.
The report identifies weak ownership of data cleansing and inadequate separation between those configuring access and those approving it. The findings are valid. But the practical question is no longer, “What design should we choose?” It is, “Which committed work do we now undo?”
Assurance that arrives after commitment becomes remediation.
Evidence Means Different Things
Audit seeks evidence that a control is defined and operating. Programme delivery often needs evidence that a decision is good enough to permit the next commitment.
Those are not the same threshold.
During design, information is incomplete. Estimates carry ranges. Test results are provisional. Responsibilities may be temporary while the permanent operating model is still being agreed. A programme cannot wait for certainty, because certainty often becomes available only after implementation. It must expose uncertainty, assign it and decide whether the remaining risk is tolerable.
Auditors can mistake this incompleteness for indiscipline. Programme teams can make the opposite error: treating every demand for evidence as an attempt to remove uncertainty before progress is allowed. The argument then becomes binary — control versus delivery — when the real issue is whether the decision was made transparently.
The useful evidence at a programme decision point is therefore not always proof that the final control operates. It may be:
- the assumptions behind a design choice;
- the options rejected and the reason;
- the unresolved dependencies;
- the named owner of each accepted exposure;
- the test that must succeed before the next irreversible step.
This evidence does not pretend that the future operation is already controlled. It allows independent challenge of the judgement being made now.
Independence is not the same as distance from the decisions that create risk.
The Independence Objection
The strongest objection to earlier audit involvement is that familiarity compromises independence. If internal audit attends design workshops, comments on options and helps shape controls, how can it later provide an objective opinion? There is a real danger that an auditor who becomes part of the programme will end up reviewing his or her own advice.
That boundary matters. Internal audit should not own the design, make the decision or accept the risk. Management must remain accountable for all three.
But independence does not require arriving after the event. It requires clarity about roles. An auditor can challenge the completeness of options without selecting one. Audit can ask whether access approval is sufficiently independent without configuring the security profiles. It can identify the evidence needed at a later gate without certifying in advance that the control will pass.
Distance protects objectivity only if it does not also produce ignorance. An auditor who knows nothing of the compromises, dependencies and pressures that shaped a programme decision may be detached, but is not necessarily well placed to judge it.
The practical distinction is between advising on the quality of the decision process and taking responsibility for the decision. The first strengthens assurance. The second weakens it.
Assurance at the Point of Commitment
The better model is not continuous audit presence in every meeting. That would burden delivery and dilute scarce audit attention. It is targeted challenge at the points where risk is created or becomes expensive to reverse.
For most substantial programmes, those points include:
- approval of the business case and scope;
- selection of the principal design or supplier approach;
- acceptance of data-conversion and control designs;
- authorisation to begin final testing;
- the decision to implement;
- transfer into normal operational ownership.
At each point, internal audit should ask a small set of questions before commitment:
- What has to be true for this decision to succeed?
- Which evidence supports those assumptions, and what remains unproved?
- Who owns the exposures being accepted?
- What future test would cause the decision to be reconsidered?
The answer should be brief enough for a steering committee to use. A two-page assurance note issued before the gate can be more valuable than a comprehensive report issued eight weeks later.
This changes the relationship without softening the challenge. Programme leaders gain early visibility of concerns and can respond while alternatives remain open. Auditors see the actual decision process rather than reconstructing it from minutes and documents. The steering committee receives not a list of findings, but a clear account of what is known, what is assumed and what is being accepted.
Two Disciplines, One Decision
Internal audit and programme delivery do not need to become the same profession. Their difference is useful. Programmes need people whose instinct is to move from uncertainty towards commitment. Boards need people whose duty is to question whether that movement is justified.
The failure occurs when challenge is organised as a separate event after the programme has already moved.
Experience shows that late assurance produces predictable behaviour. Findings are negotiated down because remediation is now costly. Programme teams defend decisions they might earlier have reconsidered. Auditors respond with stronger language because influence through timing has been lost. Steering committees are left to arbitrate between two apparently incompatible accounts.
None of this is evidence of bad faith. It is the consequence of placing assurance outside the sequence of decision.
The remedy is to preserve audit’s independence while moving its challenge upstream: before the design is fixed, before contingency is consumed, before implementation becomes the only politically acceptable answer. Internal audit should remain outside ownership of the decision, but it must be close enough to understand and test the judgement while it can still change.
Assurance has value only when it reaches the people making the decision at a time when they still have a choice.