Saif Ali AlghamdiTransformation & Growth Advisor
تواصل
LibraryمكتبتيGovernance & Complianceحوكمة والتزام
FRAMEWORKS · OPERATIONAL FRAMEWORKالأطر · إطار تشغيلي

Internal Audit & Complianceالمراجعة الداخلية والامتثال

SectionالقسمGovernance & Complianceحوكمة والتزام
Reading timeزمن القراءة6 min٦ دقيقة
ByإعدادSaif Alghamdiسيف الغامدي
One

Overview

Field: Internal audit & compliance
Scope: Independent assurance that controls and compliance actually work
Owner role: Chief audit executive, reporting to the audit committee
Review cadence: Risk-based audit plan yearly, engagements throughout
By: Saif Alghamdi

Internal audit is the organization's independent check that its controls, risk management, and governance actually work as intended. It exists to give the board and leadership honest, evidence-based assurance about whether the organization is really as well-controlled as management believes, and to advise on how to make it better.

The defining quality of internal audit is independence. Its value comes entirely from being able to look at any part of the organization and report what it finds without fear or favor, which is why it reports not to the management it examines but to the board, usually through the audit committee. An audit function that answers to the people it audits cannot be trusted to report their failings, so its independence is not a nicety, it is the entire basis of its usefulness.

This framework describes internal audit and the related compliance function as a governed assurance capability, drawing on the Three Lines Model and the professional standards of the Institute of Internal Auditors. It is written to be reusable across sectors and aligns to them without reproducing their text.

Note: Internal audit does not run controls, it assures them. Confusing the two, letting audit design and operate the controls it later checks, destroys the independence that gives its assurance any value.
الأول

نظرة عامة

المجال: المراجعة الداخلية والامتثال
النطاق: ضمانٌ مستقلّ بأن الضوابط والامتثال تعمل فعلًا
دور المالك: الرئيس التنفيذي للمراجعة، يرفع للجنة المراجعة
دورية المراجعة: خطة مراجعةٍ قائمة على المخاطر سنويًا، ومهامٌ على مدار العام
إعداد: سيف الغامدي

المراجعة الداخلية هي فحص المنشأة المستقلّ بأن ضوابطها وإدارة مخاطرها وحوكمتها تعمل كما قُصِد فعلًا. وُجِدت لتمنح المجلس والقيادة ضمانًا صادقًا قائمًا على الدليل عمّا إن كانت المنشأة مضبوطةً حقًّا كما تظنّ الإدارة، ولتنصح بكيفية تحسينها.

السمة المميِّزة للمراجعة الداخلية الاستقلالية. فقيمتها كلها من قدرتها على النظر في أي جزءٍ من المنشأة والتبليغ عمّا تجده بلا خوفٍ ولا محاباة، ولذا ترفع لا للإدارة التي تفحصها بل للمجلس، عادةً عبر لجنة المراجعة. فوظيفة مراجعةٍ تخضع لمن تراجعهم لا يُوثَق بها لتبليغ إخفاقاتهم، فاستقلاليتها ليست ترفًا بل أساس فائدتها كله.

يصف هذا الإطار المراجعة الداخلية ووظيفة الامتثال المرتبطة كقدرة ضمانٍ محوكَمة، مستندًا إلى نموذج الخطوط الثلاثة والمعايير المهنية لمعهد المراجعين الداخليين. وهو قابل لإعادة الاستخدام عبر القطاعات ويتوافق معهما دون نسخ نصّهما.

ملاحظة: المراجعة الداخلية لا تُشغّل الضوابط بل تضمنها. وخلط الاثنين، بترك المراجعة تصمّم وتشغّل الضوابط التي تفحصها لاحقًا، يُدمّر الاستقلالية التي تمنح ضمانها أي قيمة.
Two

The Three Lines Model

A recognized way to organize who does what in managing risk and controls is the Three Lines Model. It clarifies the distinct roles that together give an organization confidence its risks are being managed, without those roles blurring into one another.

The three lines describe three different relationships to risk. The first line is the operational management that owns and manages risk directly, the people running the business who take and control risk as part of their daily work. The second line is the functions that oversee and support risk management, such as risk and compliance, which set frameworks and monitor the first line. The third line is internal audit, which provides independent assurance on both, reporting to the governing body. Each line has a distinct job, and the model works because they are kept distinct.

LineWhoRole
FirstOperational managementOwns and manages risk directly in the business
SecondRisk, compliance, and similar functionsOversees, supports, and monitors risk management
ThirdInternal auditProvides independent assurance to the governing body

The critical distinction is between the second and third lines, which are easy to confuse. The second line, such as compliance, is part of management and helps run the control environment, so it is not independent of it. The third line, internal audit, stands apart from management precisely so it can objectively assess whether the first and second lines are actually doing their jobs. Keeping the third line independent of the second is what preserves the value of the assurance it provides.

Note: The first line owns the risk, always. Neither the second nor the third line can take that ownership away, and an organization where the business assumes risk is someone else's problem has misunderstood the model.
الثاني

نموذج الخطوط الثلاثة

من الطرق المعترف بها لتنظيم من يفعل ماذا في إدارة المخاطر والضوابط نموذج الخطوط الثلاثة. يوضّح الأدوار المتمايزة التي تمنح المنشأة معًا ثقةً بأن مخاطرها تُدار، دون أن تختلط تلك الأدوار ببعضها.

تصف الخطوط الثلاثة ثلاث علاقاتٍ مختلفة بالخطر. الخط الأول الإدارة التشغيلية التي تملك الخطر وتديره مباشرةً، من يديرون العمل ويأخذون الخطر ويضبطونه ضمن عملهم اليومي. والخط الثاني الوظائف التي تشرف على إدارة المخاطر وتسندها، كالمخاطر والامتثال، التي تضع الأطر وتراقب الخط الأول. والخط الثالث المراجعة الداخلية، التي تقدّم ضمانًا مستقلًّا عليهما، رافعةً للجهة الحاكمة. ولكل خطٍّ عملٌ متمايز، والنموذج يعمل لأنها تُبقى متمايزة.

الخطمَنالدور
الأولالإدارة التشغيليةتملك الخطر وتديره مباشرةً في العمل
الثانيالمخاطر والامتثال ووظائف مشابهةتشرف على إدارة المخاطر وتسندها وتراقبها
الثالثالمراجعة الداخليةتقدّم ضمانًا مستقلًّا للجهة الحاكمة

التمييز الحاسم بين الخطين الثاني والثالث، وهما سهلا الخلط. فالخط الثاني، كالامتثال، جزءٌ من الإدارة ويساعد في تشغيل بيئة الضبط، فليس مستقلًّا عنها. والخط الثالث، المراجعة الداخلية، يقف منفصلًا عن الإدارة تحديدًا ليقيّم بموضوعيةٍ هل يؤدّي الخطان الأول والثاني عملهما فعلًا. وإبقاء الخط الثالث مستقلًّا عن الثاني هو ما يحفظ قيمة الضمان الذي يقدّمه.

ملاحظة: الخط الأول يملك الخطر، دائمًا. ولا يستطيع الثاني ولا الثالث انتزاع تلك الملكية، ومنشأةٌ يظنّ فيها العمل أن الخطر مشكلة غيره أساءت فهم النموذج.
Three

Independence & Objectivity

Everything internal audit is worth rests on two related qualities: independence, its organizational freedom to do its work, and objectivity, the impartial mindset with which it does it. Protecting both is the first duty of an audit function.

Independence is structural. It comes from where internal audit sits and who it reports to: to be independent, the audit function must report functionally to the board or audit committee rather than to the management it examines, so that management cannot limit its scope, edit its findings, or punish it for uncomfortable conclusions. This reporting line is the single most important safeguard of internal audit, and its weakening is a reliable early sign that assurance is becoming theater.

Objectivity is personal and professional. Even a structurally independent function fails if its auditors are not impartial, so auditors must avoid conflicts of interest, such as auditing work they themselves designed or an area they recently ran. This is why a common rule prevents someone from auditing an activity they were responsible for until enough time has passed, because no one can objectively assess their own recent work.

Note: Independence is about the function, objectivity is about the person. Both are required, because an independent function staffed by conflicted auditors, or objective auditors with no organizational independence, each fails in its own way.
الثالث

الاستقلالية والموضوعية

كل ما تستحقه المراجعة الداخلية يقوم على سمتين مترابطتين: الاستقلالية، حرّيتها التنظيمية لأداء عملها، والموضوعية، الذهنية المحايدة التي تؤدّيه بها. وحماية كليهما أول التزامٍ لوظيفة مراجعة.

الاستقلالية بنيوية. تأتي من أين تجلس المراجعة ولمن ترفع: فلتكون مستقلّة، يجب أن ترفع وظيفيًا للمجلس أو لجنة المراجعة لا للإدارة التي تفحصها، فلا تستطيع الإدارة تقييد نطاقها أو تحرير ملاحظاتها أو معاقبتها على استنتاجاتٍ مزعجة. وخطّ الرفع هذا أهمّ وقايةٍ مفردة للمراجعة الداخلية، وإضعافه علامةٌ مبكرة موثوقة على أن الضمان يصير مسرحًا.

الموضوعية شخصية ومهنية. فحتى وظيفةٌ مستقلّة بنيويًا تفشل إن لم يكن مراجعوها محايدين، فعلى المراجعين تجنّب تعارض المصالح، كمراجعة عملٍ صمّموه هم أو مجالٍ أداروه حديثًا. ولذا تمنع قاعدةٌ شائعة أحدًا من مراجعة نشاطٍ كان مسؤولًا عنه حتى يمرّ وقتٌ كافٍ، لأن لا أحد يقيّم عمله الحديث بموضوعية.

ملاحظة: الاستقلالية عن الوظيفة، والموضوعية عن الشخص. وكلاهما مطلوب، لأن وظيفةً مستقلّة بمراجعين متعارضين، أو مراجعين موضوعيين بلا استقلاليةٍ تنظيمية، كلٌّ يفشل بطريقته.
Four

The Audit Process

Internal audit does its work through a disciplined process, from deciding what to audit down to confirming that problems were fixed. Following it consistently is what makes audit findings credible rather than arbitrary.

The work begins with a risk-based plan. Because an audit function can never examine everything, it directs its limited attention to the areas of highest risk, so that scrutiny goes where a failure would hurt most rather than being spread evenly or driven by habit. From that plan, each individual audit, or engagement, follows its own cycle: planning the scope, gathering and testing evidence in fieldwork, reporting the findings, and following up to confirm they were addressed.

  • Risk-based plan: aim the year's audits at the areas of highest risk, not at everything equally.
  • Planning: define the scope and objectives of each engagement, and how its evidence will be gathered.
  • Fieldwork: gather and test evidence to reach conclusions supported by fact, not impression.
  • Reporting: communicate findings ranked by significance, with clear, owned actions to fix them.
  • Follow-up: confirm that agreed actions were actually completed, because a finding that is not closed changed nothing.

Follow-up is the step most often neglected and most essential. An audit that identifies problems and reports them beautifully but never confirms they were fixed has produced a document, not an improvement. Tracking findings to genuine closure, rather than accepting a promise that they will be addressed, is what turns internal audit from a source of reports into a driver of real change.

Note: A finding is not resolved when it is reported, it is resolved when it is fixed and confirmed. Rigorous follow-up is what separates an audit function that improves the organization from one that merely describes it.
الرابع

عملية المراجعة

تؤدّي المراجعة الداخلية عملها عبر عمليةٍ منضبطة، من قرار ما تُراجِعه نزولًا إلى تأكيد أن المشكلات أُصلِحت. واتّباعها باتساقٍ هو ما يجعل ملاحظات المراجعة موثوقةً لا اعتباطية.

يبدأ العمل بخطةٍ قائمة على المخاطر. فلأن وظيفة المراجعة لا تستطيع فحص كل شيءٍ أبدًا، توجّه اهتمامها المحدود لمجالات الخطر الأعلى، فيذهب التدقيق حيث يؤذي الفشل أكثر بدل توزيعه بالتساوي أو دفعه بالعادة. ومن تلك الخطة، تتبع كل مراجعةٍ فردية، أي مهمة، دورتها: تخطيط النطاق، وجمع الأدلة واختبارها في العمل الميداني، وتبليغ الملاحظات، والمتابعة لتأكيد معالجتها.

  • خطة قائمة على المخاطر: وجّه مراجعات العام لمجالات الخطر الأعلى، لا لكل شيءٍ بالتساوي.
  • التخطيط: عرّف نطاق وأهداف كل مهمة، وكيف ستُجمَع أدلّتها.
  • العمل الميداني: اجمع الأدلة واختبرها لبلوغ استنتاجاتٍ يسندها الواقع لا الانطباع.
  • التبليغ: بلّغ الملاحظات مرتَّبةً بالأهمية، بإجراءاتٍ واضحة مملوكة لإصلاحها.
  • المتابعة: أكّد أن الإجراءات المتّفق عليها أُنجِزت فعلًا، لأن ملاحظةً لا تُغلَق لم تغيّر شيئًا.

المتابعة أكثر الخطوات إهمالًا وأشدّها ضرورة. فمراجعةٌ تحدّد المشكلات وتبلّغها ببراعةٍ لكنها لا تؤكّد إصلاحها أنتجت وثيقةً لا تحسينًا. وتتبّع الملاحظات لإغلاقٍ حقيقي، بدل قبول وعدٍ بمعالجتها، هو ما يحوّل المراجعة الداخلية من مصدر تقارير إلى محرّك تغييرٍ حقيقي.

ملاحظة: الملاحظة لا تُحَلّ حين تُبلَّغ، بل حين تُصلَح وتُؤكَّد. والمتابعة الصارمة هي ما يفصل وظيفة مراجعةٍ تُحسّن المنشأة عن أخرى تصفها فحسب.
Five

The Compliance Function

Alongside internal audit sits compliance, a related but distinct function. Where audit independently assures, compliance actively helps the organization meet its obligations, and understanding the difference keeps the assurance model honest.

Compliance is a second-line function: it is part of management, working to ensure the organization follows the laws, regulations, and internal policies that bind it. It does this by knowing the obligations, translating them into requirements the business can follow, building controls to meet them, and monitoring adherence. Because compliance is part of the control environment rather than independent of it, it cannot provide the same objective assurance that internal audit does, which is exactly why both are needed.

  • Know the obligations: maintain a complete, current view of the laws, regulations, and policies that apply.
  • Translate them: turn obligations into specific requirements and controls the business can actually follow.
  • Monitor adherence: check that the organization is meeting its obligations, and surface issues early.
  • Advise and train: help the business understand and meet its obligations before they become breaches.

The relationship between the two functions is complementary, not redundant. Compliance builds and runs the controls that keep the organization within its obligations, and internal audit independently checks whether those controls are actually effective. When an organization treats them as interchangeable, or lets one absorb the other, it loses either the active management of compliance or the independent assurance of audit, and both losses are dangerous.

Bottom line: internal audit provides independent, objective assurance that the organization's controls, risk management, and compliance genuinely work, and its value depends entirely on the independence that lets it report the truth.
الخامس

وظيفة الامتثال

بجانب المراجعة الداخلية يجلس الامتثال، وظيفةٌ مرتبطة لكن متمايزة. فحيث تضمن المراجعة باستقلالية، يساعد الامتثال المنشأة بنشاطٍ على الوفاء بالتزاماتها، وفهم الفرق يُبقي نموذج الضمان صادقًا.

الامتثال وظيفة خطٍّ ثانٍ: جزءٌ من الإدارة، يعمل لضمان اتّباع المنشأة القوانين والأنظمة والسياسات الداخلية التي تُلزِمها. يفعل ذلك بمعرفة الالتزامات، وترجمتها لمتطلباتٍ يتّبعها العمل، وبناء ضوابط للوفاء بها، ومراقبة الالتزام. ولأن الامتثال جزءٌ من بيئة الضبط لا مستقلٌّ عنها، لا يستطيع تقديم الضمان الموضوعي نفسه الذي تقدّمه المراجعة الداخلية، ولذا يُحتاج كلاهما تحديدًا.

  • اعرف الالتزامات: صُن رؤيةً كاملة محدَّثة للقوانين والأنظمة والسياسات المنطبقة.
  • ترجمها: حوّل الالتزامات لمتطلباتٍ وضوابط محدَّدة يستطيع العمل اتّباعها فعلًا.
  • راقب الالتزام: تحقّق من وفاء المنشأة بالتزاماتها، وأظهِر المشكلات مبكرًا.
  • انصح ودرّب: ساعد العمل على فهم التزاماته والوفاء بها قبل أن تصير مخالفات.

العلاقة بين الوظيفتين تكاملية لا مكرَّرة. فالامتثال يبني ويشغّل الضوابط التي تُبقي المنشأة ضمن التزاماتها، والمراجعة الداخلية تفحص باستقلاليةٍ هل تلك الضوابط فعّالة فعلًا. وحين تعاملهما منشأةٌ كمتبادَلين، أو تدع أحدهما يبتلع الآخر، تفقد إمّا الإدارة النشطة للامتثال أو الضمان المستقلّ للمراجعة، وكلا الخسارتين خطر.

الخلاصة: المراجعة الداخلية تقدّم ضمانًا مستقلًّا موضوعيًا بأن ضوابط المنشأة وإدارة مخاطرها وامتثالها تعمل حقًّا، وقيمتها تعتمد كليًا على الاستقلالية التي تتيح لها تبليغ الحقيقة.
Six

Key Takeaways & References

Internal audit gives the board independent assurance that controls and compliance work, and its whole value rests on its independence.

  • Keep internal audit independent by reporting to the board, and objective by avoiding conflicts of interest.
  • Use the Three Lines Model, and never let the third line blur into the second it is meant to assure.
  • Work from a risk-based plan, and run each engagement from planning through fieldwork, reporting, and follow-up.
  • Track findings to genuine closure, because a finding is resolved only when it is fixed and confirmed.
  • Distinguish compliance, which manages obligations, from audit, which independently assures them.

References

السادس

الخلاصات والمراجع

المراجعة الداخلية تمنح المجلس ضمانًا مستقلًّا بأن الضوابط والامتثال تعمل، وقيمتها كلها تقوم على استقلاليتها.

  • أبقِ المراجعة مستقلّة بالرفع للمجلس، وموضوعيةً بتجنّب تعارض المصالح.
  • استخدم نموذج الخطوط الثلاثة، ولا تدع الخط الثالث يختلط بالثاني الذي يُفترَض أن يضمنه.
  • اعمل من خطةٍ قائمة على المخاطر، وأدِر كل مهمةٍ من التخطيط عبر الميدان والتبليغ والمتابعة.
  • تتبّع الملاحظات لإغلاقٍ حقيقي، فالملاحظة تُحَلّ فقط حين تُصلَح وتُؤكَّد.
  • ميّز الامتثال، الذي يدير الالتزامات، عن المراجعة، التي تضمنها باستقلالية.

المراجع