Sitonce
Country: HK
Show exams for United States Hong Kong
Sign in

The SFC expectation for an internal audit function

Updated 6 min read
Key takeaway

The SFC’s Management, Supervision and Internal Control Guidelines state that, where practicable, management should establish an independent and objective internal audit function free of operating responsibilities.

More key points
  • The phrase recognizes that firms differ in size and structure; it does not excuse management from maintaining effective internal controls or monitoring them.
On this page15 sections
  1. What independence means in practice
  2. Why the guideline says “where practicable”
  3. Internal audit is not management’s substitute
  4. A useful review cycle
  5. The guideline’s “where practicable” qualifier
  6. Independence from the work being reviewed
  7. Risk-based audit plan
  8. Findings and follow-up
  9. Size and structure alternatives
  10. Internal audit differs from compliance and external audit
  11. Management remains accountable
  12. Exam method
  13. Decide whether a separate function is practicable
  14. Build an audit plan around risk
  15. Exam takeaway

Internal audit is a review function, not another operating desk. Under the SFC’s Management, Supervision and Internal Control Guidelines, management should establish an independent and objective internal audit function where practicable. The function assesses whether controls are adequate and working, then reports findings so management can address weaknesses.

What independence means in practice

An internal auditor should not be responsible for the activity being audited. If the same person designs, performs, and signs off on a control, the review lacks meaningful independence. The auditor should have enough access to records, staff, and management to test the control and report material findings without interference from the operating team.

Why the guideline says “where practicable”

The Guidelines recognize that the appropriate internal-control structure depends on the firm’s size, organization, business, and risk. A small firm may not be able to maintain a separate full-time audit department. That does not remove the underlying responsibility to establish controls proportionate to its risks, monitor them, and arrange an objective review where a separate function is impracticable. The firm should be able to explain how its alternative safeguards avoid self-review and cover material risks.

Internal audit is not management’s substitute

Management remains responsible for the control environment and for correcting deficiencies. Internal audit provides independent assessment; it does not own day-to-day controls, make business decisions, or transfer accountability away from responsible officers and senior management. A report that identifies a problem is not a corrective action until the firm assigns an owner, deadline, and follow-up test.

A useful review cycle

  1. Set a risk-based review plan that covers the firm’s material activities.
  2. Test whether controls are properly designed and actually followed, using records and samples.
  3. Document findings, severity, responsible owners, and remediation dates.
  4. Escalate significant weaknesses through appropriate governance channels.
  5. Retest corrective actions and report whether the issue is closed.

The guideline’s “where practicable” qualifier

The Management, Supervision and Internal Control Guidelines expect management, where practicable, to establish an independent and objective internal audit function free of operating responsibilities. The qualifier recognizes different firm sizes and structures. It is not a general exemption from effective controls, compliance monitoring or management oversight. A firm should assess its scale, complexity and risks and be able to explain how objective review is achieved.

Independence from the work being reviewed

Internal audit should not own the operational processes it audits. If the reviewer designed, approved or performed the control, self-review risk can undermine independence. A direct reporting line to senior management or an audit committee helps internal audit report findings without pressure from the business owner. Safeguards should fit the firm and preserve the reviewer’s ability to raise difficult issues.

Risk-based audit plan

A useful plan prioritizes client assets, order handling, licensing, AML/CFT, cybersecurity, outsourcing, conflicts and areas with prior incidents or complaints. The audit should define its scope, criteria, sample, evidence and testing method. The plan can be adjusted for emerging risks, but material changes and omissions should be documented and approved. Internal audit should examine whether controls operate in practice, not just whether policies exist.

Findings and follow-up

Reports should distinguish control design gaps from failures in operation, rate severity, name owners and set remediation dates. Management should respond and track corrective actions until tested and closed. Repeated overdue findings or accepted high-risk exceptions should be escalated. A report delivered but never followed up does not provide effective assurance.

Size and structure alternatives

A small firm may not justify a separate internal audit department. It may use an independent external reviewer, a group audit function or a suitably segregated arrangement, provided the review is objective, competent and has access to management. The firm should document why the arrangement is proportionate and how conflicts are managed. The SFC expects effective control, not a particular organization chart.

Internal audit differs from compliance and external audit

Compliance advises and monitors adherence to rules and internal policy; internal audit independently evaluates the adequacy and effectiveness of governance and controls; external financial audit expresses an opinion on financial statements. These functions may coordinate but are not interchangeable. A financial-statement audit alone may not test operational conduct controls or regulatory record access.

Management remains accountable

Management owns the internal-control system and should ensure audit findings are addressed. It cannot delegate the responsibility to an audit committee or consultant. If management overrides a control or ignores repeated findings, that conduct may itself raise fitness, governance and supervisory concerns. The board should receive information on material risks and unresolved weaknesses.

Exam method

Quote “where practicable,” explain independence from operations and direct reporting, assess proportionality, and describe planning, reporting and follow-up. Conclude that the qualifier affects organizational form, not management’s responsibility to maintain effective controls.

Decide whether a separate function is practicable

The SFC’s internal-control guidance expects an internal audit function where practicable. Practicability depends on the licensed corporation’s size, structure, complexity and risk profile; it is not a simple employee-count test. A small firm may need a proportionate arrangement, while a complex multi-business group may need a more formal independent team with specialist skills.

The key is objective assurance that is sufficiently separate from the activities being reviewed. Staff who design or operate a control should not be the only people assessing whether that control works. If a firm uses an external provider or group audit team, define independence, scope, access, reporting and follow-up responsibilities.

Build an audit plan around risk

An annual plan should cover material regulatory, operational, conduct, technology and client-asset risks. Use incidents, complaints, regulatory changes, business growth, new products and prior findings to set priorities. High-risk areas may need more frequent or deeper testing, while lower-risk processes can receive a longer cycle with a documented reason.

A useful audit tests evidence, not merely policy wording. For example, sample account approvals, order records, reconciliations or access changes; trace exceptions to resolution; interview control owners; and compare system logs with written procedures. Findings should describe the risk, root cause, affected population, corrective action, owner and target date.

Exam takeaway

Remember the combination: independent and objective, free from operating responsibilities, and established where practicable. The qualification is about organizational form, not permission to operate without effective internal controls or management oversight.

Common questions

Does “where practicable” mean a small licensed corporation can ignore internal controls?

No. It qualifies the expectation to establish a distinct internal audit function, not the firm’s responsibility to maintain and monitor effective controls.

Can internal audit perform the controls it later reviews?

That creates a self-review conflict. The function should be independent of the operating responsibilities it audits.

Who remains responsible for fixing audit findings?

Management retains responsibility for the control environment and for ensuring deficiencies are addressed.