Services · Sustainability

Compliance Audit

CMP

Performs compliance audit procedures against selected donor, policy, legal or internal requirements, including sample testing, exception analysis and recommendations.

What changes

Stronger accountability, transparency, risk management, assurance coverage and governance oversight.

What you get

  1. Approved compliance audit ToR and engagement plan CMP001
  2. Compliance audit strategy and sampling memo CMP002
  3. Compliance audit programme CMP003
  4. Engagement risk assessment matrix IAF004
  5. Completed working paper file IAF003
  6. Compliance audit report with risk-rated findings and agreed corrective actions CMP004
  7. Corrective action follow-up tracker CMP005

What has to come first

Who is involved

From the National Society's side. This is what the engagement asks of your people.

Your own staff work alongside the adviser throughout, so this is a commitment of their time as well as the Centre's. Ask in the request and you are given the day estimate per role before anything is signed.

RoleWhat they do
HNS Board / Risk and Audit CommitteeReceives the report, oversees corrective action
HNS Secretary General and senior managementRespond to findings, own corrective actions
HNS Internal Audit functionDelivers or co-delivers the engagement
Legal, Compliance, HR, Grants and Finance departmentsAuditees; define the compliance universe
DonorsRely on strengthened compliance controls
GFDC delivery teamFD Manager leads delivery

How it is measured

IndicatorTargetEvidence
Compliance audit completed and report presented to the Audit Committee within the agreed timeline Within 12 weeks of kick-off Audit Committee minutes; dated report (CMP004)
Audit programme executed on the planned samples 100% of programme steps executed or formally deferred with rationale Completed working paper file (IAF003)
Findings carry agreed corrective actions with owners and deadlines At least 90% of findings Management responses in the audit report (CMP004)
Corrective actions closed by their agreed deadlines At least 80% within 12 months Corrective action follow-up tracker (CMP005)

Tools

7 of 7 ready to download.

  • CMP001 Compliance Audit TORs TORs DOCX
  • CMP002 Compliance audit strategy and sampling memo Template DOCX
  • CMP003 Compliance audit programme Template DOCX
  • CMP004 Compliance audit report with risk-rated findings and corrective action plan Template DOCX
  • CMP005 Corrective action follow-up tracker Template XLSX
  • IAF003 Standard working paper templates and file index Template DOCX
  • IAF004 Engagement risk assessment matrix Template XLSX

Standards

  • IIA International Professional Practices Framework (IPPF)
  • COSO Internal Control - Integrated Framework
  • Donor agreements and reporting requirements
  • National data protection and privacy laws and regulations
  • HNS Internal Audit Charter and risk-based audit plan
  • National corporate governance laws and not-for-profit regulations
  • ISO 37301 - Compliance management systems (supersedes ISO 19600)

Describe the problem, not the service

You do not need to know which of the 124 to ask for.