Building a Strong University Internal Audit Function
A university internal audit function provides independent insight into whether institutional resources, processes, and controls are working as intended. For public universities and colleges, that role extends well beyond checking transactions. Internal auditors help leaders understand risks involving public funds, research activity, student data, information technology, facilities, compliance, and strategic performance.
The most effective functions are designed around the institution’s mission and governance structure. A large research university may need sophisticated reviews of sponsored programs, laboratories, cybersecurity, construction, and affiliated foundations. A community college or smaller state agency may place greater emphasis on financial controls, procurement, grants, student services, and operational resilience.
Establishing the function requires visible executive sponsorship, a clearly defined charter, qualified staff, and a risk-based work program. It also requires the independence to report difficult findings and the relationship-building skills to help departments address root causes. The goal is credible assurance that supports better decisions rather than a review process viewed as a policing exercise.
Define the Mandate and Sponsorship
The first step is to secure formal support from the governing board, audit committee, chancellor, president, or agency executive. Internal audit should have clear authority to access records, systems, facilities, and personnel, while retaining freedom to determine the scope and timing of engagements. A board-approved charter can establish this authority and explain how the chief audit executive will communicate results.
The charter should define the function’s purpose, responsibilities, reporting lines, and limits. It should distinguish internal audit from management, compliance, risk management, legal counsel, external audit, and investigative services. Internal auditors evaluate and advise; they should not own operational controls or make management decisions that they may later be expected to assess.
A dual reporting relationship is often appropriate in higher education. Administrative reporting to a president, chancellor, or system executive can support daily operations and resources. Functional reporting to an audit committee or board can protect independence, approve the charter and risk-based plan, and provide a channel for sensitive matters. The precise structure should reflect the institution’s governance model and applicable state requirements.
Assess Risk Across the Institution
A risk assessment turns a broad mandate into a focused audit strategy. Begin with interviews and workshops involving senior business officers, academic leaders, information technology executives, research administrators, facilities teams, human resources, student affairs, and compliance professionals. Review prior audit reports, external audit findings, regulatory correspondence, incident logs, strategic plans, and major capital or technology initiatives.
Risk categories should cover financial, operational, strategic, compliance, reputational, information security, and safety concerns. Higher education adds distinctive exposures, including sponsored research administration, restricted funds, tuition and financial aid, athletics, clinical operations, intellectual property, data privacy, construction programs, and relationships with affiliated foundations or hospital systems.
Score risks using criteria such as potential impact, likelihood, speed of impact, control maturity, and management attention. A simple scoring model is preferable to false precision. The assessment should identify both enterprise-wide issues and areas that require specialized reviews. It should also be refreshed when circumstances change, such as a major system implementation, leadership transition, funding shift, cyber incident, or new regulatory obligation.
Design the Operating Model
An internal audit department can be centralized at the university or system level, embedded within a campus, or organized through a hybrid model. Centralization may improve consistency and provide access to specialized expertise. Campus-based teams may understand local operations more deeply. A hybrid approach can combine enterprise-wide oversight with targeted support for individual institutions.
The operating model should clarify which entity owns the audit plan, how resources are shared, and how findings are escalated. System offices and campuses should avoid overlapping reviews that burden departments without adding insight. A coordinated annual planning process can align work across finance, compliance, information security, risk management, external audit, and other assurance providers.
Internal audit should also establish protocols for urgent work. Allegations of fraud, serious control failures, data breaches, or threats to safety may require an immediate response outside the approved annual plan. The charter and procedures should explain who authorizes special reviews, how confidentiality is protected, and when matters are referred to law enforcement, legal counsel, or another responsible authority.
Set Standards for Assurance Work
A credible function uses a consistent methodology for planning, fieldwork, documentation, communication, and follow-up. The Institute of Internal Auditors’ Global Internal Audit Standards provide a widely recognized foundation. Public institutions may also need to consider state oversight expectations, federal grant requirements, professional auditing guidance, and the responsibilities of external auditors.
Audit engagements should begin with a defined objective, scope, risk statement, and criteria for evaluation. Testing should be sufficient to support the conclusion without creating unnecessary administrative work. Workpapers need to show what was examined, how samples or data were selected, what evidence was obtained, and how the auditor reached the result.
Clear communication is essential. Reports should describe the condition, the relevant risk or criteria, the underlying cause, and the practical effect. Recommendations should address root causes and identify accountable owners and target dates. Management responses should be specific enough to support later validation, while disagreements should be documented rather than hidden.
| Operating choice | Advantages | Risks to manage | Suitable use |
|---|---|---|---|
| Centralized system function | Consistent methods, shared specialists, efficient reporting | May feel distant from campus operations | Multi-campus systems with common governance |
| Campus-based function | Strong local knowledge and relationships | Duplication and uneven capabilities | Independent universities or colleges |
| Hybrid model | Combines enterprise coverage with local expertise | Requires clear coordination and escalation | Systems with varied campus sizes and missions |
| Co-sourced model | Adds specialist skills and flexible capacity | Vendor dependence and confidentiality concerns | Cybersecurity, construction, data analytics, or temporary needs |
| Fully outsourced model | Quick access to external expertise | Limited institutional knowledge and continuity | Small entities lacking resources for a permanent team |
Build the Team and Technology
The chief audit executive should shape staffing around the risk profile rather than a generic organizational template. Core capabilities may include accounting, public-sector finance, information technology, data analytics, cybersecurity, construction, research administration, compliance, and process improvement. Not every skill must be filled by a permanent employee; co-sourcing can provide specialist support when independence and confidentiality are preserved.
Professional credentials can strengthen credibility, including Certified Internal Auditor, Certified Public Accountant, Certified Information Systems Auditor, Certified Fraud Examiner, and related qualifications. Equally important are communication, interviewing, project management, and the ability to understand academic and administrative environments. Training plans should include the institution’s systems, governance structure, policies, and current strategic priorities.
Technology should support risk sensing and efficient evidence collection. A secure audit management platform can track planning, workpapers, issues, recommendations, and follow-up. Data analytics can identify unusual payments, duplicate vendors, access conflicts, inactive accounts, procurement exceptions, or patterns in payroll and purchasing. Access controls, retention rules, and privacy protections must be defined before auditors begin using sensitive institutional data.
Turn Findings Into Institutional Improvement
The value of internal audit is measured by the quality of decisions that follow its work. Reports should reach the right audience without unnecessary delay, with urgent issues escalated promptly. An executive summary can help senior leaders see themes across engagements, while detailed reports give process owners enough information to act.
Follow-up should verify whether agreed actions were completed and whether they reduced the identified risk. A closed recommendation should represent more than a policy revision; it should include evidence that the new control operates consistently. Aging reports can help the audit committee focus attention on overdue high-risk actions without turning follow-up into a mechanical compliance exercise.
The function should also monitor its own performance. Useful measures include completion of the approved plan, stakeholder feedback, time from fieldwork to reporting, percentage of high-risk findings resolved, and the number of reviews using analytics or advisory techniques. These indicators should encourage quality and relevance rather than reward a high volume of low-value audits.
Priorities for the First Year
- Approve a charter that protects access, independence, confidentiality, and direct communication with governance.
- Complete an enterprise risk assessment that includes campuses, system offices, affiliated entities, and major strategic initiatives.
- Select a manageable initial audit plan with visible value, such as access management, procurement, grants, payroll, or capital projects.
- Establish common procedures for planning, workpapers, reporting, issue ratings, management responses, and follow-up.
- Create a staffing and technology plan that combines core internal capability with carefully governed specialist support.
A phased launch can build trust more effectively than attempting to review every major process immediately. Early engagements should be important enough to matter but sufficiently well defined to produce reliable results. Advisory work, such as reviewing controls in a new enterprise resource planning implementation, can demonstrate value while maintaining the boundary between advice and management ownership.
The function should maintain regular contact with senior leaders and the audit committee between formal reports. Briefings on emerging risks, recurring findings, and changes in the audit universe help governance bodies understand where attention is needed. Collaboration with TASSCUBO peers can provide practical comparisons on staffing, audit committee reporting, analytics, and coordination across Texas public institutions.
A university internal audit function becomes durable when it is independent in judgment, disciplined in method, and constructive in relationships. Leaders who are establishing or renewing such a function should begin by approving the mandate, mapping institutional risks, and selecting a small number of high-value engagements. With those foundations in place, internal audit can become a trusted partner in protecting public resources and advancing institutional performance.