Audited on the transactions, unaudited on the basis
Where an internal audit function covers the asset base at all, it usually covers maintenance spend and procurement compliance, because those resemble the rest of the audit universe. The decision framework, the plan and the data go unexamined. The organisation ends up assured about how it spends and unassured about what it decided to spend on.
Ask an internal audit function what proportion of its plan is directed at the asset base, then compare that to the proportion of the balance sheet the asset base represents.
On an asset-intensive organisation the second number is frequently above seventy per cent. The first is rarely above ten, and much of that ten is maintenance procurement.
This is not negligence and it is not a resourcing failure. It is a recognition problem, and it has a specific cause worth naming.
Why coverage lands where it lands
An internal audit function is built to examine transactions and the controls around them. Authorisation, segregation of duties, three way match, evidence of receipt, contract compliance. That capability is real, hard won and portable across the whole organisation.
Maintenance spend looks exactly like that. So does procurement of services, so does contractor payment, so does inventory. They fit the audit universe because they are transactional, and an audit of them produces findings of a kind the audit committee recognises and can act on.
The asset management system does not look like that at all. Whether the decision criteria exist, whether the plan has ever declined anything, whether the data supports the decisions it is used for, whether intervention timing is set by condition or by budget availability: these are not transactional questions. They have no population to sample and no control to test. They require an opinion about the basis on which the organisation makes multi-decade commitments.
The result is an organisation with high assurance over how it spends its maintenance budget and none at all over whether that budget is the right size.
What the standard now requires be examined
The 2024 edition of ISO 55001 is more specific about this than its predecessor, and two clauses matter.
Clause 9.2 requires internal audit of the asset management system itself, on a programme that considers the importance of the processes concerned and the results of previous audits. The subject is the system, not the spend.
Clause 4.5, entirely new, requires the decision-making framework, the criteria and the methods to be documented. That has a direct consequence for assurance: the absence of documented criteria is now a nonconformity against a published standard, rather than a maturity observation an executive can absorb. It gives an auditor something to test against, which is exactly what was missing before.
What the criteria clause actually asks for
, read: ISO 55001 now requires you to write down how you decideFour questions that examine the basis
None of these requires a sample. Each produces an answer a board can act on.
What has the plan stopped? A strategic asset management plan that prioritises is one that deprioritises. If nothing has ever been declined by reference to it, it is a description rather than a plan, whatever its quality.
When was the data last verified against the asset? Asset data degrades continuously and silently. Nothing announces that a record has stopped matching reality, so confidence in a register tends to rise with its age while its accuracy falls. The 2024 revision separated data and information into its own clause at 7.6 and requires attributes, quality and sources to be determined rather than assumed.
Name one intervention whose timing was set by predicted condition. Clause 10.3 renamed preventive action to predictive action and rewrote it, moving the question from whether to intervene to when. Answering it requires condition data, a deterioration view and a funding mechanism that can act before failure. Most organisations have none of the three and describe a run to failure regime as risk-based.
Can the finance and engineering views of the same asset be reconciled, and how long does it take? Record the elapsed time and how many people had to be involved. That measurement is usually more informative than the reconciliation.
The competence problem this creates
There is an uncomfortable consequence, and it applies to the internal audit function rather than to the organisation it examines.
A reviewer who cannot interpret condition data, read a deterioration curve or price a renewal option will examine the controls surrounding those activities and report on the controls. That is a genuine finding about a real control environment. It is not a finding about the asset base, and the distinction is rarely drawn in the report, so the reader concludes the asset base was examined when the paperwork around it was.
The Global Internal Audit Standards, effective January 2025, require proficiency and due professional care, and the honest application of that requirement here is sometimes a decision to decline a scope or to bring in someone who holds the competence. ISO 55012, published in the 2024 family, covers people involvement and competence specifically.
The same question, in a delivery context
, read: Engaging an engineer satisfies the standard. Deferring to one does not.Why the pressure is arriving from finance
In this region the prompt for examining the basis is not coming from the audit committee. It is coming from the accounting reform.
Saudi Arabia's Royal Decree No. 13059 of December 2016 requires government institutions to convert from cash to accrual accounting under IPSAS. Accrual accounting obliges an entity to recognise, value and depreciate what it controls, which requires it to establish what it controls and in what condition.
That produces, as a by-product, the first defensible answer many organisations have ever had to the question of what they own. It also produces an external auditor with a view on it, which is a different kind of pressure from an internal recommendation.
What the conversion demands of the register
, read: Accrual conversion gave three years. It did not give anyone a register.The opportunity in that is easy to miss. An organisation being forced to build a defensible register is being forced to build the precondition for everything else in this article. Whether it also builds the decision framework, the plan and the data governance that make the register useful, or whether it builds a register that satisfies the accounts and nothing else, is a choice being made right now in a large number of organisations, mostly by people who do not know they are making it.
The framework for this stage sets out all six domains and the published clause behind each.
Sources. ISO 55001:2024, second edition, July 2024, ISO standard 83054: Clause 4.5 on asset management decision-making, Clause 7.6 on data and information, Clause 9.2 on internal audit and Clause 10.3 on predictive action. ISO 55000:2024, ISO standard 83053. ISO/TS 55010 on alignment of financial and non-financial functions, ISO 55012 on people involvement and competence and ISO 55013 on asset data, all published in the 2024 family. Global Internal Audit Standards, Institute of Internal Auditors, effective 9 January 2025. The Three Lines Model, Institute of Internal Auditors, Statement of Position of 8 July 2026. IPSAS 33, first-time adoption of accrual basis IPSAS. Saudi Arabia's transition to accrual accounting is required by Royal Decree No. 13059 of December 2016. Standards published behind a paywall are cited without a link.
Tags
- Assurance
- Internal audit
- Asset management
- ISO 55000
- Governance
Related reading
A strategic asset management plan that has never stopped anything is a description
Clause 6.2.1 gave the SAMP its own requirement in the 2024 edition, and ISO strengthened the leadership clause in the same revision. The two changes belong together. A plan only allocates if somebody senior enough is willing to let it decline something, and most asset management plans have never declined anything in their lives.
ReadEvery organisation has a risk register. Ask for the other one
The 2024 edition separated actions to address risk from actions to address opportunities, which the 2014 edition ran together in a single subclause. That is not a drafting tidy. When one process has to serve both, loss avoidance wins every time, because it is the half with a committee, a template and an auditor.
ReadISO 55001 now requires you to write down how you decide
Clause 4.5 is new in the 2024 edition and asks for three things, a decision-making framework, the criteria, and the methods. Most organisations have all three in the sense that people know roughly how things get settled. Very few can produce them, and an option appraisal nobody can audit is not a decision. It is a preference with a spreadsheet attached.
Read