Feature Story

Internal Audits provide valuable insights and recommendations that can help organisations improve efficiency. Internal Audits are also essential for risk management, as identifying non-compliance early can prevent further issues and facilitate more robust systems to be implemented.

Local governments in Queensland are required to establish and maintain an “efficient and effective” internal audit function by the Local Government Act 2009 (the Act) and the Local Government Regulation 2012 (the Regulation). Each financial year a local government must:

  1. Create an internal audit plan, including statements regarding:
    • How operational risks have been evaluated
    • The most significant identified operational risks
    • The control measures adopted to manage the most significant risks
  2. Conduct an internal audit
  3. Report on the progress of the internal audit
  4. Assess compliance with the audit plan

New Era of Risk Evaluation

Risk management involves more than the traditional identification and mitigation of risk. An objective and systematic evaluation of risk optimally includes identification of opportunities.

As technology and regulations continue to expand rapidly, risk management is more important than ever. From new Environmental, Social and Governance requirements to cyber security and the increasing prevalence of Artificial Intelligence (AI), an effective internal audit function can help Councils identify risks and opportunities early. This process not only allows management to control the potential impacts but also fosters a culture of continuous improvement.

Internal Audit Plan

An internal audit plan should complement an organisation’s risk management process. As the Institute of Internal Auditors (IIA) recommends, a “chief audit executive should develop a process to identify and assess significant, new and emerging risks that should be considered for coverage in the audit plan”.

An internal audit plan should balance the level of risk across each auditable unit, the level of control effectiveness and the resource limitations of the organisation.

Internal Audit Resourcing Models

Councils operate a range of resourcing models for their IA function from fully in house to co-sourced to a fully outsourced function. To ensure the function is delivering the best value for the organisation, Council’s resourcing model should be reviewed form time to time.

The IIA conducted a 60-second survey in March 2025, which gathered insights from Chief Audit Executives (CAEs) across various industries. Respondents were asked what resourcing model their organisation utilises – 47% use a “co-sourcing” model, 27% fully outsource and 26% are fully in-house.

This data shows a trend to have an internally managed function with some or all IA activity outsourced (a “co-sourced” model). Of the 26% of respondents who currently utilise an in-house model, 52% would prefer using a co-sourced resource model. The survey found that the primary driver for an organisation’s resourcing model was a “desire to obtain additional skills”.

A co-sourced functional model allows Councils to control IA strategy while ensuring audits are conducted by experts. It also provides a robust model in terms of issues around internal staffing in times of high turnover and ensures that resources can be managed while getting audits done in accordance with the IA plan.

Internal Audit Technological Resources

There are a variety of tools an internal audit function can utilise to improve effectiveness and efficiency. From dedicated audit management systems to general purpose tools that can be adapted for the function’s needs.

As the IIA outlines, technology can be leveraged for:

  • Governance, risk management, and control process mapping
  • Communication and collaboration
  • Data science and analytics

As discussed earlier, artificial intelligence is gaining popularity, including in the internal auditing field. As the North American Internal Audit Foundation found, 41% of respondents were using generative AI for internal audit activities and 61% were planning to increase GenAI involvement. While the risks of AI should be carefully considered prior to implementation, tools can increase efficiency across a variety of internal audit activities.

Automation is another area that is rapidly gaining popularity and carries less risk. Routine tasks and workflows can be automated to save time and even budget as tools are becoming more affordable or free.

Mead Perry Group is well-equipped with the necessary skills and resources to support Councils with financial management, procurement, plant hire rates, strategic planning and more. We have developed finely tuned processes to ensure project success, to deliver optimal value, and achieve positive outcomes for the community. Our approach is designed to suit the unique needs of each Council, ensuring efficiency, effectiveness and tangible results.

If you have any questions or wish to engage Mead Perry Group please call:
07 4615 4902 or email mpg@meadperrygroup.com.au.

Let's Keep In Touch!

Get quarterly insights on Local Government topics, practical tips, project updates, and behind-the-scenes photos from the field.