Saudi Arabia’s corporate landscape is evolving rapidly, particularly concerning internal audit governance. As of January 2024, listed companies are now mandated to adhere to stricter regulations that enhance the oversight and functioning of internal audit units. This shift, articulated in the Corporate Governance Regulations (CGR), emphasizes the importance of an independent internal audit. Companies must adapt to these changes or risk falling short of compliance standards, which can impact their operational integrity and market credibility.
Understanding the New CGR Regulations
The recent updates to the CGR have introduced significant changes, particularly in Article 87(11), which stipulates that every audit committee must formally recommend the appointment of an internal auditor prior to the board’s decision. This ensures that there is a structured review of the candidate’s qualifications and independence, addressing a previously overlooked governance gap. The amendments require audit committees to not only oversee but also approve the internal audit plan, ensuring thorough scrutiny and alignment with company objectives.
In addition, Articles 73 to 75 enforce that all listed companies must have an internal audit unit. They are required to develop a risk-based audit plan that must be approved by the audit committee and submit detailed reports to the board. This systemic change positions the audit committee at the core of corporate governance, ensuring ongoing accountability and adherence to established standards.
Exploring Internal Audit Models
To comply efficiently with CGR mandates, many companies in Saudi Arabia are exploring different models for their internal audit functions. Building a fully operational in-house internal audit department requires specialized knowledge, time, and resources that can be challenging for many mid-cap and newly listed companies to acquire. Thus, outsourced and co-sourced internal audit solutions have gained traction as practical governance tools.
Outsourced internal audit models offer a quick pathway to compliance, as they provide readily available expertise and established methodologies. In contrast, co-sourced arrangements allow companies to maintain some internal audit resources while leveraging external specialists for particular needs. This model is ideal for organizations with existing internal audit functions that may lack the capacity or expertise to handle all compliance requirements.
Compliance and Governance Considerations
Under CGR, companies must navigate several compliance steps to ensure they meet the requirements of Articles 73–75 and 87(11). This involves not just hiring an auditor but creating a structured internal audit charter that defines roles and responsibilities, preparing a risk-based audit plan approved by the audit committee, and maintaining ongoing reporting cycles that address both compliance and operational efficiency.
Moreover, the structure of these internal audit models strengthens the independence of the audit function. When external providers are utilized, they typically report directly to the audit committee, distinct from management. This separation is particularly vital for family-owned businesses, as it reduces conflicts of interest and helps maintain objectivity in governance.
In a rapidly evolving market, meeting CGR standards is not just about compliance; it’s about positioning a company for sustained growth and market integrity. By leveraging appropriate internal audit models and ensuring thorough governance practices, companies can not only fulfill mandatory requirements but also enhance their overall operational resilience.
In conclusion, as companies adapt to the new internal audit regulations in Saudi Arabia, understanding the implications of CGR and the available models is crucial. Embracing these changes can lead to improved governance, transparency, and ultimately, business success.
