Financial Statement Audit

Associate Audit Director: Internal Audit Momentum In Local Government

Adopting internal audit best practices is now a core baseline for local government across most Australian states and territories, reflecting an environment of increasingly clear expectations around internal audit, risk management, and governance.

As a result, the question for councils and Audit and Risk Committees, including Audit, Risk and Improvement Committees in NSW, is no longer whether internal audit exists. In most cases, it does. The more important question is whether councils are getting value from internal audit in the form of better risk visibility and management, more effective internal controls, and fewer surprises.

This shift has important implications for how councils plan internal audit, what Audit and Risk Committees should expect, and how value is measured in practice.

Moving Beyond Compliance: The True Value of Internal Audit

Most councils now have an internal audit function, an approved audit plan and regular reporting to their Audit and Risk Committee. However, sector-level reporting continues to point to recurring significant weaknesses in internal controls and governance.

In NSW, the Audit Office has highlighted deficiencies in areas such as asset management, information technology controls, cyber security and fraud control, as well as the persistence of repeat findings from year to year.

This reinforces an uncomfortable reality. Having an internal audit in place does not, on its own, deliver value or improved risk and governance outcomes.

The value of internal audit becomes clearer when assurance changes decisions, strengthens controls and helps councils address risks before they escalate.

The Risk of Internal Audit Becoming Performative

Where internal audit is treated primarily as a compliance requirement, it can drift into what many committees increasingly recognise as performance rather than protection. Common symptoms caused by limited budgets, resource constraints and other factors include audit plans driven by rotation rather than risk, lengthy reports that are difficult to prioritise, and recommendations that remain open well beyond their agreed timeframes.

In these cases, internal audit activity continues, but its contribution to decision-making and risk reduction is reduced. Evaluating internal audit effectiveness ensures council audit activity contributes directly to strategic decision-making rather than performative compliance.

Key Drivers of Internal Audit Effectiveness

Experience across councils and other organisations suggests that internal audit delivers value when key practical conditions are met.

Focus on the risks that matter most

Internal audit risk assessment adds value when it is clearly aligned to the organisation’s highest risks. Rather than spreading internal audit activity across council to share the load, effective audit programmes concentrate on areas with the greatest potential impact on financial sustainability, service delivery, compliance, reputation and other key areas of risk. 

Councils can strengthen this process by reviewing emerging risks, management concerns, regulatory obligations and previous findings before confirming the annual plan. This keeps audit coverage relevant, helps committees challenge priorities and gives internal audit teams a clearer basis for directing limited time and budget towards the highest-risk issues for councils.

Clear visibility of assurance

Assurance mapping helps Audit and Risk Committees understand where assurance already exists, where it overlaps and where genuine gaps remain. This shifts the conversation from how many audits were completed to whether the right risks are covered.

A coordinated internal and external audit approach can help committees see how assurance sources work together and where material gaps remain.

Reporting that drives action

Clear and concise reporting, risk based prioritisation, ownership and accountability matter more than volume. Reports should support decisions about what needs to be addressed first, not simply document activity.

Follow up that closes the loop

The Institute of Internal Audit’s (IIA) Global Internal Audit Standards make it clear that internal audit must monitor and confirm the implementation of agreed actions. Value is only realised when meaningful and achievable recommendations are acted upon within agreed timeframes, and risks are demonstrably reduced and monitored. A lack of monitoring and review remains one of the most common reasons internal audit effort fails to translate into better outcomes.

Moving from compliance to value

Internal audit is now an expected part of risk management and good governance in local government. As internal audit matures in local government, some are doing this well. They understand that the opportunity is for councils to move beyond treating internal audit as a compliance activity and realise its value as a practical tool for improving risk management and control.

Councils that get the best value from internal audit are not necessarily doing more audits. They are doing better targeted reviews, with sufficient budget to enable depth of scope, maintaining disciplined follow-up and using internal audit to reduce risk, strengthen controls and inform proactive decisions rather than explain issues after the fact.

Legislation may mandate internal audit, but its value depends on focus, clarity and consistent follow-through.

How National Audits Group Can Support

National Audits Group applies these principles across its internal audit services in Australia, helping local government committees move beyond routine compliance to genuine risk reduction. Explore more internal audit articles for practical guidance on governance and assurance.

By Phil Swaffield, Associate Audit Director, National Audits Group