Standard Operating Procedure Audit Program PDF
Standard Operating Procedure Audit Program PDF
Title: Audit programmes and internal audits conducted by the Audit Advisory Function
1. Purpose
The purpose of this SOP is:
to describe the procedure for the internal audit engagement process (including planning, conduct,
communication, contradictory procedure, quality assessment, final report, action plan and any
follow-up actions) conducted in line with:
Financial Regulation applicable to the Budget of the European Medicines Agency, as adopted by
the Management Board, and its Implementing Rules;
The International Standards for the Professional Practice of Internal Auditing of the Institute of
Internal Auditors;
The Internal Audit Charter of the European Medicines Agency approved by the Management
Board;
to outline the procedure for establishing the auditors’ risk assessment and assurance map;
to outline the procedure for establishing the audit strategy and annual audit programme for year
N+1 for internal audit activities within the European Medicines Agency;
to ensure that the rolling programme for years N+2 and N+3 is maintained;
to ensure that Trackwise procedure for the annual audit programme is used consistently and
correctly;
© European Medicines Agency, 2017. Reproduction is authorised provided the source is acknowledged.
to outline the procedure for establishing the Annual Audit Report;
It applies to all internal audits conducted at the European Medicines Agency, including audits
conducted with outsourced resources under the direct lead of a member of the Audit Function (e.g. IT
audits, EC framework contract) and follow-up audits respectively.
This SOP is not applicable to audits conducted by the Internal Audit Service of the European
Commission and by the Court of Auditors.
2. Scope
This SOP applies to all the Agency, and especially the Audit Function, auditee management and
auditees.
3. Responsibilities
It is the responsibility of the Head of Audit to ensure adherence to this procedure in particular to
complete all work with due professional care, objectivity and according to the relevant professional
standards.
It is the responsibility of the Executive Director and auditee management to ensure adherence to this
procedure, in particular that:
the objective of the engagement all information and documents relevant for the scope and
objective of the audit are provided in time;
management’s improvement action plan is prepared and effectively implemented or that senior
management has accepted the risk of not taking action and that this is properly communicated in
writing;
All staff audited in line with this SOP must follow the rules defined herein and help ensure the smooth
running of an audit.
The Management Board will be informed on the audit findings and recommendations and on the status
of implementation of improvement actions for issued recommendations in line with the relevant
provisions.
assessing the audit team and determine if the team possesses’ adequate skills, knowledge and
experience to lead the audit activities.
identifying lead auditor for each audit carried out in year N+1 formalised
x-drive:\Auditpractices\Checklistsandtemplates
SOP/EMA/0121 - How to conduct a procurement procedure: available on the public EMA webpage.
6. Related documents
Regulation (EC) No 726/2004, as amended.
Financial Regulation applicable to the budget of the European Medicines Agency as adopted by the
Management Board, as adopted by the Management Board on 15 January 2014.
Regulation of the European Medicines Agency laying down detailed rules for the implementation of
certain provisions of the Financial Regulation for the Agency as adopted by the Management Board
on 20 March 2014.
The International Standards for the Professional Practice of Internal Auditing of the Institute of
Internal Auditors.
The Internal Audit Charter of the European Medicines Agency, as adopted by the Management
Board on 15 June 2017.
User manual for tracking internal audits, recommendations and actions in Trackwise.
7. Definitions
Day: working day, excluding weekends, Agency’s holidays, business disasters
MB – Management Board
For the main definitions refer to Glossary as per the Internal Audit Manual
START
2) Determine which
areas require an audit
5) Provide input on the draft Audit Strategy and annual audit programme
Yes
7) Provide
Comments
8) Approval of
No
plan
9) Review Draft
strategy and audit
plan
Yes
11) Communicate
Audit Strategy and
Annual plan
Go to
13
From
12
No - 60 days opening
14) Follow SOP 0121 meeting
Yes
- 15 days opening
19) Provide Input to
meeting
draft audit plan
- 10 days opening
20) Update Draft meeting
- 1 day opening
22) Send final draft audit meeting
plan to auditees
Go to
23
Planning of Audit
From
22
25) Fieldwork
27) Agreement
on findings
and report
Yes
Yes
No
Yes
37) Send comments to Go to
Management 38 Step 33a + 21 days
Go to 41
Management and
ED AF-AUD (Head of Audit) AF-AUD (Lead Auditor) Timeline
IQMCo
From
37
No
38) Management
agrees with AF-AUD
suggestions
No
39) Discuss
Step 33a + 23 days
differences on the
action plan with ED
43) Evaluate
feedback and Step 40 + 15 days
communicate with
Lead Auditor
44) Provide
evidence to close an
action
No
Yes
47) Close
Recommendation
management Board
End
b) Provide information on the audit requirements in all operational HoDiv and DED
and support areas
3 Assess the Audit Team and determine if the team possesses’ AF-AUD
adequate skills, knowledge and experience to lead the audit
activities.
4 Draft the audit strategy, annual audit programme for N+1 and AF-AUD
rolling audit programme for year N+2 and N+3.
5 The Executive Group, HoDiv, HoDep and IQMCo provide input to EXB HoDep and
the draft Audit Strategy, annual audit programme for N+1 and IQMCo
rolling audit programme for year N+2 and N+3.
7 The Executive Group discusses and agrees on the updated draft EXB
audit strategy, audit programme for year N+1 and rolling
programme for year N+2 and N+3. Comments are then provided
on audit strategy and annual programme.
If approved go to step 10
12 Identify lead auditor for each audit carried out in year N+1. AF-AUD
Planning of Audit
17 Review and decide if to approve draft audit plan and risk Head of AF-AUD
assessment
24 Consider auditee input from opening meeting. Finalise audit plan. AF-AUD Lead
Auditor
Validates the draft audit report and completes the Checklist for
Quality Assurance Review.
Management and
42b) Enter improvement actions into TrackWise
IQMCo
If yes, go to step 46
47 Once all actions are closed, the recommendation should be closed AF-AUD Lead
within TW Auditor
48 Prepare the Annual Audit report to the Management Board, as Head of AF-AUD
requested by art. 84.1 of the Agency’s Financial Regulation, on the
basis of the audits conducted during the given year, including all
IAPs during that period and send it to the MB for information.
This report should be sent at the time that the Annual Activity
Report is submitted to the Management Board.
10. Records
Audit reports and all audit related records (audit plans, checklists, questionnaires, working papers,
handwritten notes, documents sent by auditee management, etc.) are to be kept in the Agency’s
electronic document management system in the relevant folder: Cabinet/06 Corporate
Governance/06.6 Audit/Internal Audit/Annual Audit Programme/YYYY.
Based on Financial Regulation Art 99, 6 “The reports and findings of the internal auditor, as well as the
report of the institution, shall be accessible to the public only after validation by the internal auditor of
the action taken for their implementation”. All other working papers should be considered confidential
and for internal use of auditees and AF-AUD only.