
An internal audit program that actually works is built around your risks, not the standard's clause numbers. It verifies what happens in the field against what the system says should happen, it is run by people with the independence and competence to report honestly, and its findings change how the business operates. If your audits never surprise anyone and nothing changes afterwards, you have a tick-and-flick program, and it is costing you more than it gives back.
Why do most internal audit programs fail?
Most internal audit programs fail because they were built backwards. They exist to produce evidence for the certification auditor, so they mirror the certification audit: a clause-by-clause checklist, a sampling of documents, a short walk around, and a report that says "generally conforming" with two minor findings about document control.
That kind of program answers one question: "Will we pass the external audit?" It never answers the questions that matter to the people running the business:
- Are our critical controls actually working on site?
- Are supervisors doing what we assume they are doing?
- Where is the next client NCR or incident coming from?
- Is the system helping the work, or is the work happening despite the system?
The symptoms of a failing program are consistent across civil, mining and infrastructure businesses: audits get pushed back until the pre-certification scramble, the same person audits the same areas every year, findings repeat year after year, nobody outside the quality function reads the reports, and the field crews see the auditor as a paperwork visit rather than a useful check.
None of that is an assurance program. It is a compliance ritual.
What does a good internal audit program look like?
A working program has five characteristics, and every one of them is observable.
1. It is risk-based, not clause-based. The schedule starts with what could hurt the business: high-risk construction activities, subcontractor management, temporary works, verification of quality records on claimable work, plant and equipment controls, environmental controls near sensitive receptors. Clauses get covered along the way, but risk sets the order and the depth.
2. It audits work, not just documents. The auditor spends the majority of the audit where the work happens. Field verification means watching a process run, talking to the people doing it and comparing what actually happens against what the procedure claims. A document review alone can only ever tell you the paperwork is tidy.
3. The auditors are competent and independent. They understand the operations they are auditing, they have been trained to gather evidence rather than opinions, and they do not audit their own work or their own manager's work. Independence is what makes the findings trustworthy.
4. Findings drive action. Every finding has an owner, a root cause, a due date and a verification step. Findings feed management review, and trends across audits get analysed rather than filed. If the last three audits all flagged subcontractor verification, that is a systemic issue demanding a systemic response, not three separate closed NCRs.
5. Leadership uses the output. The real customer of an internal audit program is the leadership team. When the program works, directors and managers can answer "how do we know our controls work?" with evidence rather than optimism. That is the whole point of assurance.
Tick-and-flick vs a working assurance program
| Aspect | Tick-and-flick program | Working assurance program |
|---|---|---|
| Schedule driven by | Certification audit dates | Risk profile and business priorities |
| Audit structure | ISO clause checklist | Process, project and risk area |
| Time in the field | Minimal, mostly desktop | Majority of the audit |
| Typical findings | Document control, signature gaps | Control failures, capability gaps, process breakdowns |
| Findings outcome | Closed with updated paperwork | Root cause fixed, effectiveness verified |
| Leadership involvement | Sees a summary once a year | Uses results to make decisions |
| Field crew perception | Paperwork inspection | A useful check that fixes real friction |
| Value delivered | Certificate retention | Fewer surprises, fewer NCRs, real control |
If your current program sits mostly in the left column, the fix is not more audits. It is a different kind of audit.
How do you build a risk-based internal audit schedule?
You can rebuild a schedule in an afternoon with the right people in the room. The sequence:
- List your audit universe. Every process, project, site and function that could be audited. Include the unglamorous ones: procurement, subcontractor engagement, training and competency, plant maintenance, document and data control.
- Rate each area for risk. Use consequence and likelihood against safety, environment, quality, commercial and reputation. Add weighting for areas with recent incidents, client complaints, NCRs, new people or changed processes.
- Set frequency from risk. High-risk areas might be audited twice a year, moderate annually, low-risk every two years. There is no rule that says everything gets audited every year; there is only a rule that says your program must be planned and justified.
- Assign competent, independent auditors. Match auditor knowledge to the subject. If nobody internal fits, that audit is a candidate for external support.
- Timebox and spread the schedule. Short, focused audits spread across the year beat one exhausting annual event. A focused half-day audit of one process, done properly, is worth more than a week of clause-skimming.
- Build in verification. Schedule follow-up checks on prior findings so close-out means "fixed and confirmed", not "form completed".
Revisit the schedule quarterly. A schedule that never changes in response to incidents, NCRs or new work is not risk-based, it is decorative.
How do you know your internal audit program is working?
Watch for these signals over two or three audit cycles:
- Findings get more interesting. Early audits find paperwork gaps. A maturing program finds control weaknesses before they become incidents and client NCRs.
- Repeat findings decline. The same issue stops appearing because root causes are being fixed.
- External audits get quieter. When your own program finds problems first, certification and client audits stop producing surprises.
- Operational people start requesting audits. When a project manager asks you to audit their subcontractor controls because it helps them, the program has crossed from compliance to value.
- Leadership quotes audit results. Audit output appearing in management decisions is the clearest sign the program is doing its job.
The gap between a tick-and-flick program and a working one is not budget or headcount. It is intent. Build the program to answer "how do we know?" for your leadership team, and certification takes care of itself as a by-product.
If you want an experienced set of eyes across your current audit program, and a clear picture of where your governance and assurance arrangements actually stand, book a Governance Health Check. It is a structured review that shows you where you have control, where you have gaps and what to fix first.
Founder, Hillview Business Services. 15+ years inside civil construction, mining and infrastructure businesses.