Internal audit vs Compliance, what's the difference?

Demon_Hunter

Supremacy Member
Joined
Mar 8, 2003
Messages
6,041
Reaction score
328
To be honest, there isnt much of a difference.

Internal Audit is checking if the transactions or process flows adhere to current tules and practices.

Compliance is more checking if current workflow matches to MAS or whatever rules prescribed by government.
 

BEAN30

Member
Joined
Dec 18, 2010
Messages
101
Reaction score
18
Only difference is Compliance must check whether comply with company's SOPs, laws and regulations. Internal Audit can check on the financial aspects as well plus those mentioned and also make recommendations on how company can improve processes and workflows to achieve the same internal control objectives. Compliance is just compliance. You don't follow you kena warning! Can be good or bad. Internal Audit covers a wide scope and sometimes may not detect non-compliance of certain subject matters. Compliance is forever checking the same thing and any anomaly will be detected faster!
 

Demon_Hunter

Supremacy Member
Joined
Mar 8, 2003
Messages
6,041
Reaction score
328
Only difference is Compliance must check whether comply with company's SOPs, laws and regulations. Internal Audit can check on the financial aspects as well plus those mentioned and also make recommendations on how company can improve processes and workflows to achieve the same internal control objectives. Compliance is just compliance. You don't follow you kena warning! Can be good or bad. Internal Audit covers a wide scope and sometimes may not detect non-compliance of certain subject matters. Compliance is forever checking the same thing and any anomaly will be detected faster!
In my experience as internal auditor, we check historical transactions.
Anyone in compliance wants to comment?
 

Nicholas92

Arch-Supremacy Member
Joined
Apr 18, 2012
Messages
12,086
Reaction score
3,529
Same same but different lo

Compliance tends to be more for banks, financial institutions which needs to follow certain laws and specific regulatory requirement:

Internal audit can cover the above, but also internal policies and rules.

You fail internal audit maybe chop bonus chop promotion. You fail compliance can say bye bye to your job.
 

Tedicious

Master Member
Joined
Aug 1, 2019
Messages
4,649
Reaction score
2,181
In my experience as internal auditor, we check historical transactions.
Anyone in compliance wants to comment?
Compliance practitioner here since 2015 in the FI space.

Audit I believe is to c if you practice what you preach
Compliance is more of set polices, control and procedure for the firm based on the regulation that the firm is in (for eg: banks will be the banking act and MAS 626, payment firm will be the payment services act etc)

In layman term, both audit and compliance are the 'policeman' of the firm
 

dambio

Honorary Member
Joined
Aug 21, 2014
Messages
131,660
Reaction score
61,751
Audit is check got hanky panky or not.

Compliance is check whether got comply with regulators rules n regulations
 

ninjaghost

Supremacy Member
Joined
Feb 23, 2019
Messages
9,832
Reaction score
3,976
internal audit ish ownself check ownself, still got chance to fix internally.

compliance ish a set of regulation/policy that set by industry standard or authority for others to comply, without doing so might face the consequences..
 

williewombat615

Arch-Supremacy Member
Joined
Mar 10, 2017
Messages
21,492
Reaction score
8,021
Writing from non-FI perspective…

Moi employer categorise compliance in relation to code of conduct and ethics. So any breach of the code would be investigated by compliance which is the responsibility of legal department.

Moi is in internal audit and may sometimes be asked to participate in investigation if Legal needs help with digging through transactions in ERP system.

Ultimately Legal calls the shot on what to do during investigations, next steps, conclusion, etc.
 

Orphan

Master Member
Joined
Nov 26, 2018
Messages
4,847
Reaction score
3,273
Compliance's role is to ensure that the company's daily operations do not run afoul of the rules and regulations the company is subjected to.

Things like checking whether customer was onboarded properly, know-your-customer processes are adhered to, whether the company's new customer is on any sanctions list, whether the company might run afoul of any local regulations, whether employees' details are protected as per local data privacy laws etc.

Primarily, they act as a "prevention" role. Eg, "can we sell uranium to Kim Jun Un?" "No cannot!"




Audit (whether internal or external), checks through documentation like the balance sheets, transactions, processes to ensure everything is as reported. They can and will also check documentation from the Compliance dept. Rather than prevention like Compliance, they are doing detective work to check if crimes were commited or if there are any weakness/discrepancies. They do this by checking audit trails and at the end, generate a report to identify any areas of suspicion or areas that needs to be addressed/mproved upon. They might even check things like whether the company has sufficient and accessible fire extinguishers.

Eg Compliance say they flagged and stopped the company from selling uranium to Kim Jung Un. So audit will ask Compliance for proof that they did send out a warning and told the business they cannot do this trade. Audit will also check with the warehouse to confirm whether the company's store of uranium is not reduced. "Your record says the company called off the sale of 0.01 kg of uranium to Kim Jung Un, but your inventory shows you have 0.01 kg missing and unaccounted for. Please explain and dun tell me it was lost to half-life radiation, because I checked that only 0.001 kg should have been lost that way, plus also, you did not document these type of radiation loss anywhere."
 

Courage

Arch-Supremacy Member
Joined
May 23, 2016
Messages
20,761
Reaction score
10,152
1 is 2nd line of defense for compliance/regulatory matters and 1 is 3rd line for the entire organization. World of difference
 

mgx-alander

Greater Supremacy Member
Joined
Jan 19, 2008
Messages
98,392
Reaction score
15,534
internal audit means find the problem, no need to solve just say X X X need to fix and suggest solution

compliance means enforce the policy after audit finding the problem... say u dun do, chiu will kena from moi

so easy u oso dunose :frown:
 

alph4tang0

Master Member
Joined
Jun 11, 2020
Messages
4,579
Reaction score
1,653
Audit is a check process (internal by own company folks, external from outside company)

Compliance is a policy.

Audit a department whether they work in compliant with company’s directives.
 

One Piece

Supremacy Member
Joined
Jun 24, 2009
Messages
8,380
Reaction score
622
I try to Google but the English too chim for me

Copilot response:

 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top