Internal Audit Key Performance Indicators (KPIs)
Internal Audit Key Performance Indicators (KPIs)
OVERVIEW
An effective business process is built on a set of well-defined and clearly stated business objectives. Key
objectives articulate the ideal performance results that the company expects from that process. To monitor a
business process so that it stays focused on reaching the key objectives, the company chooses appropriate
performance measures. Careful selection of the performance measures takes a company a long way toward
improving a business process. Thus, to build and continually improve an effective business process, a company
establishes:
Articulate the performance results Determine whether the company Monitor the performance of those
the company expects from the has reached the key objectives. activities that are instrumental in
business process. reaching the key objectives.
This section covers key performance metrics that are used for assessing audit functions, the outcome measures
associated with each metric and the activity measures that drive each outcome metric. A link connects each
outcome measure with its corresponding formula and analysis of the formula. The list provides a starting point
from which companies may select a set of five to nine measures to track.
Build the internal audit department Devote a percentage of IA budget • Internal audit turnover rate
as an internal knowledge resource. resources to orientation, work
• Average years of experience of
paper reviews and training.
new hires
• Average tenure of each staff
auditor
• Average number of hours to
complete an audit
• Number of audits performed per
year per auditor
Formula
(Hours for training new auditors and performing work paper reviews divided by the total hours expended by IA
staff) x 100
Analysis
Leading companies populate their IA staff with experienced business professionals who possess both operational
and financial auditing backgrounds. These companies retain their auditors within the department by offering these
experienced hires both quality-of-work and quality-of-life solutions. This formula measures the total amount of
resources required to train and orient auditors to the audit department policies and methodologies, as well as the
culture and business processes of the company.
1
1 Source: www.knowledgeleader.com
Key Objective Outcome Measures Activity Measures
Build the IA department as an Ensure that third-party providers • Percentage of auditors with
internal knowledge resource. perform a percentage of audits. certification
• Percentage of auditors with
non-audit business experience
• Percentage of staff auditors who
"own" specific business unit
audit duties
• Percentage of audit customers
who request outside expertise
to conduct audits
Formula
(Number of audits performed by third-party providers divided by the [total number of audits – specialized niche
audits by third-party providers]) x 100
Analysis
A robust IA staff possesses the capabilities to perform most audits without assistance from third-party
professionals. This formula calculates the percentage of the IA resources directed to external providers. When
evaluating the capabilities of their IA departments, leading companies first weigh the costs and benefits of
outsourcing a limited number of specific audits. These audits are narrow in scope and require expertise in well-
defined niche disciplines. They represent a small percentage of audit activity and are not a significant segment of
the audit schedule. Hiring full-time auditors to perform this small number of specialized audits is not usually cost-
effective for most companies. Instead, they co-source these specialized projects to providers with the necessary
expertise while performing the majority of their audit projects with in-house staff.
IA DEPARTMENT FLEXIBILITY
Create a highly flexible IA Measure the percentage of total • Lead time to fulfill audit requests
department. audits not scheduled in the annual
• Percentage of risk-based audits
audit plan.
• Percentage of audits requested
by business managers
• Percentage of unfulfilled audit
requests
2
2 Source: www.knowledgeleader.com
Formula
(Audits not scheduled in annual plan divided by the (total number of audits – audits required for regulatory
purposes)) x 100
Analysis
Responsiveness and flexibility are key attributes of IA functions within leading companies. Flexibility enables the
company to respond quickly to changing conditions in the marketplace, regulatory environment or from increased
competition. This formula measures the total number of audits performed at year's end that are not included in the
annual audit schedule. Since most unscheduled audits are initiated by change, this formula attempts to gauge IA's
responsiveness to change. Performing "just-in-time audits," audits scheduled commensurate with risk, and audits
that support strategic goals are all methods by which IA ensures audit relevance by directing resources to those
areas of the business that are most susceptible to risk.
RISK ASSESSMENTS
Minimize exposure to unexpected Measure the percentage of • Percentage of business units for
risk. business units undergoing annual which the company has a risk
risk assessments. management strategy
• Percentage of business units
with ongoing risk assessments
• Percentage of managers trained
to assess their own risk
• Percentage of business units
with a predetermined risk
threshold to trigger audits
Formula
(Number of business units receiving risk assessments divided by the total number of business units) x 100.
Analysis
Leading companies implement risk management strategies that acknowledge the interdependence of all the
company's business units and departments, as well as the risk inherent in intangible assets. This formula
measures the percentage of business units that undergo a risk assessment at least once a year. Leading
companies use their IA risk assessments to gauge the company's total risk exposure and develop strategies to
effectively deal with the risks. Optimally, the company will identify and create strategies to deal with all of its
potential risks. Realistically, however, this may not be possible. Nevertheless, companies that create strategies to
address as many unanticipated risks as possible place themselves in a more advantageous position when
confronting either anticipated or unanticipated risk.
3
3 Source: www.knowledgeleader.com
Key Objective Outcome Measures Activity Measures
assessments
• Percentage of suppliers and
business partners that undergo
IA risk assessments
Formula
(Number of business partners examined by IA divided by the total number of business partners) x 100
Analysis
As companies become leaner and more specialized, they find out that outsourcing and partnering is an
increasingly effective way of augmenting their capabilities. Additionally, companies are merging with or acquiring
competitors at an accelerating pace to remain competitive in a global marketplace. Leading companies protect
themselves from the potential risk in relationships with third-party partners and suppliers by assigning their IA
departments a proactive role in evaluating their potential and current business suppliers. These leading IA
functions ensure that the company does not experience negative publicity, diminished reputation or other
downstream liabilities inherent in doing business with vendors or suppliers that do not adhere to company ethical
or quality standards.
MEASURING FRAUDS
Minimize financial loss due to Determine revenue lost to fraud. • Amount lost to fraud detected
inside fraud. from financial compliance audits
• Amount lost to fraud detected
by IA through data mining and
data extraction
• Amount unaccounted for
through revenue reconciliation
and operating expense
Formula
(Actual fraudulent occurrences divided by the number of reports of fraud) x 100
Analysis
Companies minimize fraud by implementing and enforcing effective ethics programs. A robust ethics program
exceeds compliance programs by giving employees and managers the tools and expertise necessary to make
ethical decisions. By measuring the number of calls to the fraud hotline or the number of fraud reports to the
ethics officer, the company can assess employee awareness of the ethics code. While not all calls will result in the
discovery of genuine fraudulent behavior, the number of calls indicates employees' awareness of the code.
FRAUDULENT ACTIVITY
4
4 Source: www.knowledgeleader.com
Key Objective Outcome Measures Activity Measures
Minimize financial loss due to Determine the total annual number • Percentage of employees who
inside fraud. of fraudulent occurrences. receive ethics compliance
training
• Number of calls to the fraud
hotline
• Number of fraudulent activities
discovered
Formula
(Total amount of company revenue lost to fraudulent activity divided by the total amount of company revenue) x
100
Analysis
While it is difficult to know the amount of money it loses to fraudulent activities, a company can estimate its
losses. Lost revenues detected through automated data mining and data extraction programs are calculable, as
are losses from fraud reported through hotlines and other reporting vehicles.
SATISFACTION
Build the IA department as an Determine the percentage of audit • Number of audit requests
internal knowledge resource. customers who say they are "highly
• Percentage of audit
satisfied" with IA.
recommendations implemented
• Percentage of audit customers
audited by the same auditor
within the past three years
• Percentage of new business
initiatives in which IA is invited
to participate during planning
sessions
Formula
The formula includes a percentage of audit customers who are highly satisfied with services provided by IA, taken
from periodic surveys and other feedback mechanisms.
Analysis
This formula measures the overall satisfaction of internal customers regarding auditors and the services they
provide. Auditors, who are proficient in the audit and business process being audited, engender the respect and
admiration of their audit customers. This, in turn, facilitates the implementation of audit recommendations and
encourages audit requests. Taken together, these positive impressions enhance the IA department's credibility
within the company. Audit customers include executive management, line managers, auditees and the audit
committee. Continued high-satisfaction ratings are an indicator that the IA department is adding value to the
company in the form of accurate risk assessments and valuable operational consulting services.
KEY FACTORS
5
5 Source: www.knowledgeleader.com
Knowledge of the
Relationships Expectations Issue Management Communications
Audience
6
6 Source: www.knowledgeleader.com
INTERNAL AUDIT KEY PERFORMANCE INDICATORS
(KPIs): SAMPLE 2
Articulate the performance results Determine whether the company Monitor the performance of those
the company expects from the has reached the key objectives. activities that are instrumental in
business process. reaching the key objectives.
The following table shows key objectives for conducting internal audits, the outcome measures associated with
each objective, and the activity measures that drive each outcome measure. A link connects each outcome
measure with its corresponding formula and analysis of the formula. The list provides a starting point from which
companies may select a set of five to nine measures to track. To start tracking performance, a company chooses
one or two key objectives and begins measuring the corresponding outcome and activity measures. As these
objectives are attained, the company may change its focus to other objectives and their related measures.
Minimize financial loss due to Determine revenue lost to • Amount lost to fraud detected from financial
inside fraud. fraud. compliance audits
• Amount lost to fraud detected by IA through
data mining and data extraction
• Amount unaccounted for through revenue
reconciliation and operating expenses
7
7 Source: www.knowledgeleader.com
Key Objective Outcome Measures Activity Measures
Minimize exposure to Determine the percentage • Percentage of business units for which the
unexpected risk. of business units company has a risk management strategy
undergoing annual risk
• Percentage of business units with ongoing
assessments.
risk assessments
• Percentage of managers trained to assess
their own risk
• Percentage of business units with a
predetermined risk threshold to trigger audits
Create a highly flexible IA Determine the percentage • Lead time to fulfill audit requests
department. of total audits not
• Percentage of risk-based audits
scheduled in the annual
audit plan. • Percentage of audits requested by business
managers
• Percentage of unfulfilled audit requests
The following are formulas and analyses for the key outcome measures of conducting internal audits.
Formula
8
8 Source: www.knowledgeleader.com
(Total amount of company revenue lost to fraudulent activity divided by the total amount of company revenue) x
100.
Analysis
While it is difficult to know the amount of money it loses to fraudulent activities, a company can estimate its
losses. Lost revenues detected through automated data mining and data extraction programs are calculable, as
are losses from fraud reported through hotlines and other reporting vehicles.
Formula
(Actual fraudulent occurrences divided by the number of reports of fraud) x 100.
Analysis
Companies minimize fraud by implementing and enforcing effective ethics programs. A robust ethics program
exceeds compliance programs by giving employees and managers the tools and expertise necessary to make
ethical decisions. By measuring the number of calls to the fraud hotline or the number of fraud reports to the
ethics officer, the company can assess employee awareness of the ethics code. While not all calls will result in the
discovery of genuine fraudulent behavior, the number of calls indicates employees' awareness of the code. By
encouraging employees to report suspected fraud and adhering to policies that protect whistleblowers and punish
those who make false, malicious accusations, companies ensure that employees and managers are more likely to
adhere to the ethics code. Incorporating ethical behavior into daily operations helps companies decrease the
likelihood of losing revenues because of employee or management fraud. Although it is impossible to guarantee
that strong ethics programs will eliminate all fraudulent activity within the company, effective programs reduce its
occurrence.
Formula
The formula includes the percentage of audit customers who are highly satisfied with services provided by IA,
taken from periodic surveys and other feedback mechanisms.
Analysis
This formula measures the overall satisfaction of internal customers regarding auditors and the services they
provide. Auditors, who are proficient in the audit and business process being audited, engender the respect and
admiration of their audit customers. This, in turn, facilitates the implementation of audit recommendations and
encourages audit requests. Taken together, these positive impressions enhance the IA department's credibility
within the company. Audit customers include executive management, line managers, auditees and the audit
committee. Continued high-satisfaction ratings are an indicator that the IA department is adding value to the
company in the form of accurate risk assessments and valuable operational consulting services.
Formula
9
9 Source: www.knowledgeleader.com
(Number of audits performed by third-party providers divided by the [Total number of audits – specialized niche
audits by third-party providers]) x 100
Analysis
A robust IA staff possesses the capabilities to perform most audits without assistance from third-party
professionals. This formula calculates the percentage of the IA resources directed to external providers. When
evaluating the capabilities of their IA departments, leading companies first weigh the costs and benefits of
outsourcing a limited number of specific audits. These audits are narrow in scope and require expertise in well-
defined niche disciplines. They represent a small percentage of audit activity and are not a significant segment of
the audit schedule. Hiring full-time auditors to perform this small number of specialized audits is not usually cost-
effective for most companies. Instead, they co-source these specialized projects to providers with the necessary
expertise while performing the majority of their audit projects with in-house staff. This practice of "insourcing"
allows the department to build a cumulative internal knowledge base of each business unit and its inherent risks.
Formula
(Hours for training new auditors and performing work paper reviews divided by the total hours expended by
internal audit staff) x 100
Analysis
Leading companies populate their IA staff with experienced business professionals who possess both operational
and financial auditing backgrounds. These companies retain their auditors within the department by offering these
experienced hires both quality-of-work and quality-of-life solutions. This formula measures the total amount of
resources required to train and orient auditors to the audit department policies and methodologies, as well as the
culture and business processes of the company.
Formula
(Number of business units receiving risk assessments divided by the total number of business units) x 100
Analysis
Leading companies implement risk management strategies that acknowledge the interdependence of all the
company's business units and departments, as well as the risk inherent in intangible assets. Internal audit
departments play a key role in the company's enterprisewide risk management system by identifying and
assessing the company's risk. This formula measures the percentage of business units that undergo a risk
assessment at least once a year. Leading companies use their IA risk assessments to gauge the company's total
risk exposure and develop strategies to effectively deal with the risks. Optimally, the company will identify and
create strategies to deal with all of its potential risks. Realistically, however, this may not be possible.
Nevertheless, companies that create strategies to address as many unanticipated risks as possible place
themselves in a more advantageous position when confronting either anticipated or unanticipated risk. Methods
used by which leading companies to foster a proactive, risk prevention strategy include educating line managers
to assess their department's own risk, creating mechanisms to foster ongoing risk assessments, and defining a
matrix that signals managers to request internal audit risk assessments.
Formula
10
10 Source: www.knowledgeleader.com
(Audits not scheduled in annual plan divided by the [Total number of audits – audits required for regulatory
purposes]) x 100
Analysis
Responsiveness and flexibility are key attributes of IA functions within leading companies. Flexibility enables the
company to respond quickly to changing conditions in the marketplace, regulatory environment, or from increased
competition. Since change produces risk, leading companies position their IA departments to be able to respond
quickly to change. This formula measures the total number of audits performed at year's end that are not included
in the annual audit schedule. Since most unscheduled audits are initiated by change, this formula attempts to
gauge IA's responsiveness to change. Performing "just-in-time audits," audits scheduled commensurate with risk,
and audits that support strategic goals are all methods by which IA ensures audit relevance by directing resources
to the areas of business that are most susceptible to risk. Flexibility is another way in which IA maintains a
customer focus, making sure that the department addresses management concerns, accommodating even last-
minute requests.
Formula
(Number of business partners examined by IA divided by the total number of business partners) x 100
Analysis
As companies become leaner and more specialized, they find outsourcing and partnering to be an increasingly
effective way of augmenting their capabilities. Additionally, companies are merging with or acquiring competitors
at an accelerating pace to remain competitive in a global marketplace. Leading companies protect themselves
from the potential risk in relationships with third-party partners and suppliers by assigning their IA departments a
proactive role in evaluating their potential and current business suppliers. These leading IA functions ensure that
the company does not experience negative publicity, diminished reputation, or other downstream liabilities
inherent in doing business with vendors or suppliers that do not adhere to company ethical or quality standards.
Additionally, by participating in due diligence before consummating an acquisition or merger, leading IA
departments ensure that the company is partnering with an organization that is financially sound and culturally
compatible.
11
11 Source: www.knowledgeleader.com
INTERNAL AUDIT KEY PERFORMANCE INDICATORS
(KPIs): SAMPLE 3
12
12 Source: www.knowledgeleader.com
DEVELOP EFFECTIVE COMMUNICATION STRATEGIES WHICH IMPEL MANAGEMENT
AND EMPLOYEES TO TAKE ACTION
• Determine the percentage of recommendations implemented within the time period agreed upon by audit
customers.
• Identify the number of auditors that receive various types of communication training.
• Note the number of surprises at the exit meeting.
• Report cycle time (Total – end of fieldwork to report delivery).
• Consider cycle time between various key milestones in the audit reporting process.
• Note the number of audit findings that are implemented.
13
13 Source: www.knowledgeleader.com
• Number of audit software extracts utilized
• Network/mainframe usage by auditors
• Percentage of the audit budget dedicated to IS/IT
• Number of IS/IT findings as a percentage of total findings
14
14 Source: www.knowledgeleader.com