An audit plan built from functions will always miss the project
A major capital programme contains procurement, payment, resourcing, safety and regulatory exposure at a scale the support functions around it never reach. It is still routinely scoped as one line in an entity-wide plan. The case for examining it while it runs is not philosophical. It is arithmetic.
The pattern is consistent enough to describe in the abstract. An organisation with a capital programme worth several billion under way commissions an entity-wide internal audit. The plan returns risk-assessed, resourced and approved. It contains a review of human resources, a review of finance, a review of procurement, a review of information technology. The programme appears once, described as "projects", and is allocated fewer days than the payroll review.
Nothing improper has happened. The plan was built the way audit plans are built, from the organisation chart. An organisation chart shows functions. It does not show exposure.
A programme is an entity with a temporary charter
A major capital programme is not a department. It runs its own procurement, at contract values the organisation's routine purchasing never approaches. It engages and demobilises hundreds or thousands of people, often through intermediaries. It pays against measured work and certified progress rather than against invoices, which is a different control problem with a different failure mode. It holds a large share of the organisation's regulatory permissions and most of its public reputation. It operates a safety regime where the consequence of control failure is a fatality rather than a misstatement.
Every function in the audit universe already exists inside the programme, at higher value, under more time pressure, and operated largely by people who do not report to the function that owns the control.
Scoping that as one line called "projects" is the same category error as scoping "subsidiaries" as one line. The difference is that nobody would do the second.
The arithmetic of finding things late
The case for examining a programme while it runs, rather than reviewing it after handover, does not rest on principle. It rests on a published relationship between how long something goes unnoticed and what it finally costs.
The Association of Certified Fraud Examiners publishes the largest recurring study of occupational fraud, drawn from cases investigated by its own members. The 2026 edition covers 2,402 cases across 143 countries. Two of its figures sit directly on the question.
Where a scheme was caught inside six months, the median loss was forty thousand dollars. Where it ran beyond five years, the median exceeded one point one million, roughly twenty-seven times as much. Across all cases the median scheme ran twelve months before detection.
A major capital programme runs for five years or more. An organisation that examines it only at completion has not chosen to audit late. It has chosen which of those two figures it is going to live with.
Three further findings from the same study bear on a construction environment specifically. Corruption schemes, which the study defines to include bribery and conflicts of interest, appeared in 45 per cent of cases; a programme's defining characteristic is a dense, high-value interface with external parties. More than half of all cases involved either an absence of internal controls or the override of controls that existed, and override is the more interesting half here, because schedule pressure is a standing argument for exception. And median losses caused by owners and executives ran more than nine times those caused by employees, which matters because a programme director typically holds more delegated authority than anyone else at that grade in the organisation.
One qualification, stated plainly because the distinction is easy to blur. This is fraud data. Fraud is a subset of what goes wrong on a capital programme, and probably a small one next to poor change control, weak estimating and unmanaged interfaces. What generalises is not the incidence but the mechanism: a control failure that nobody is looking for compounds for as long as nobody looks. That reading is interpretation rather than a finding of the study.
The profession retired the phrase, for this exact reason
Engineers commonly describe internal audit as a cost imposed by a department that does not build anything. The correction usually offered is that internal audit is the third line of defence.
That phrase no longer exists. In July 2020 the Institute of Internal Auditors replaced the Three Lines of Defence with the Three Lines Model, and dropped the word "defence" on purpose. Its stated reasoning was that "defence" framed risk as inherently bad, something to be protected against rather than managed, and that it reinforced separation between the lines rather than a shared objective. The revision followed consultation with more than two thousand stakeholders, and commentary at the time noted that the old framing invited precisely the "not my job" posture that makes the third line unwelcome on site.
The profession diagnosed the cultural problem that engineers complain about, and changed its own vocabulary to address it, six years ago. A good number of project organisations, and a good number of audit functions, still use the retired phrase, and carry the retired posture with it.
Competence stopped being a preference in January 2025
The Global Internal Audit Standards, 2024 edition, took effect on 9 January 2025 and replaced the previous framework. Standard 3.1 requires internal auditors and the internal audit function to collectively possess or obtain the competencies needed to fulfil their responsibilities.
"Collectively" is the operative word. It does not require every auditor on an engagement to be an engineer. It requires that the competence exists somewhere on the engagement, which permits buying the skill in and does not permit going without it.
Read against a capital programme, that means somebody must be able to read a schedule and distinguish float from padding, test whether a variation was properly instructed before it was valued and recorded, follow an extension-of-time claim through to whether its causal narrative holds, and know what a Class 3 estimate does and does not promise. None of that is financial testing, and none of it can be supervised by someone who has not done it.
A correction is worth making here, because the wrong body gets cited. ACCA does not set internal audit standards. They are set by the International Internal Audit Standards Board under the IIA, overseen by the IPPF Oversight Council. ACCA responded to the IIA's public consultation on these Standards, and its submission argued that practising internal auditors may hold other equally relevant qualifications. If the competence of a programme audit team is going to be argued from a standard, the standard is 3.1.
There is a gap in the profession's own library that makes the point better than any argument. The IIA publishes a Global Technology Audit Guide dedicated to auditing IT projects. No flagship equivalent exists for capital projects, which in most asset-owning organisations are larger by an order of magnitude. Guidance on auditing project management exists as training rather than as a standard-adjacent guide, and it makes the obvious observation that an auditor without project management knowledge is not positioned to assess whether the controls are designed correctly, let alone whether they are working.
Functions, packages, and the cells nobody planned
There are two defensible ways to cut coverage across a programme, and the argument about which is better usually obscures that both leave the same thing out.
Cut by function and you take procurement, or payment certification, and test it across every package. This is consistent, comparable, and produces a statement about one control that survives challenge. What it does not produce is depth: each pass touches each package thinly. And the interfaces between packages appear nowhere, because an interface belongs to no single function.
Cut by package and you take one package and audit it properly. This is deep, and it produces findings a project director recognises as real. But it repeats the same function tests once per package, which consumes budget and goodwill at the same rate, and it cannot tell anyone whether a weakness is systemic or local.
The resolution is not to choose. It is to plan on both axes and to state which cells are covered this cycle and which are not. A plan that cannot name the cells it is leaving uncovered is not risk-based. It is incomplete, and the incompleteness is invisible to whoever approves it, because an audit plan reports what it will do and never what it has decided to omit.
What the fee actually buys
Assurance depth is bought in days. Days are bought at rates. Neither statement is controversial, and together they settle the question.
An entity-wide internal audit priced to win a competitive tender spreads its days across the whole audit universe. The share reaching a multi-billion programme is frequently a number of days that would not cover substantive testing of one significant variation, let alone the portfolio of variations, the claims register, the interface agreements and the certification chain behind each payment.
This is not a criticism of the firms who bid. They price the scope they are given, at the rates a competitive market sets, and they deliver against that scope. The mismatch belongs to the buyer. An organisation asking for entity-wide coverage at a commodity rate while expecting programme-grade probing has specified two things that cannot both be true, and it will receive the one it actually paid for.
An organisation that wants comfort on a capital programme has to buy it as its own engagement, scoped against the programme's own risk assessment rather than the entity's, staffed with people who can read the technical record, and repeated while the work is still in progress.
Sources. The Institute of Internal Auditors, The IIA's Three Lines Model: An Update of the Three Lines of Defense, position paper, July 2020. The Institute of Internal Auditors, Global Internal Audit Standards, 2024 edition, effective 9 January 2025, Standard 3.1 on competency and Standard 3.2 on continuing development. ACCA, response to the IIA consultation on the proposed Global Internal Audit Standards, 2023. Association of Certified Fraud Examiners, Occupational Fraud 2026: A Report to the Nations, published May 2026, covering 2,402 cases across 143 countries. The Institute of Internal Auditors, Global Technology Audit Guide, Auditing IT Projects.
Tags
- Internal audit
- Project assurance
- Three Lines Model
- Global Internal Audit Standards
- Risk-based internal audit
- Construction audit