Internal
Audit Services

Internal audit does not replace management control functions or the annual financial audit. Its role is to provide an independent assessment of whether a company’s processes, controls and risk management mechanisms are operating as designed.

NOA Group provides internal audit services through a dedicated team with experience in engagements across high-risk industries, ranging from manufacturing and distribution to agriculture and energy.

An internal audit firm such as NOA, with a sound understanding of the client’s business context, goes beyond formal findings and provides actionable recommendations. Our approach is risk-based: we start with the areas of significant exposure for the company rather than with a standard checklist.

The benefits of a well-executed internal audit extend beyond compliance with applicable legal requirements. They also support management decision-making by providing a higher degree of assurance based on independently verified findings rather than solely on the internal reporting of the audited functions.

Mandatory
Internal Audit

The requirement to establish an internal audit function is expressly regulated under Romanian law. Pursuant to Article 65(7) of Law No. 162/2017,

entities whose annual financial statements are subject to statutory audit, including public-interest entities as defined under Article 2(12) of the same law, as well as entities meeting the size criteria for mandatory statutory audit, are required to organize and ensure the performance of the internal audit function.

Failure to comply with this requirement is not simply a matter of disregarding a recommendation. Under Article 44 of Law No. 162/2017, failure to establish the internal audit function and the audit committee constitutes an administrative offence and may result in a fine of up to RON 100,000.

For companies approaching the applicable size thresholds, we recommend assessing the requirement in advance, as eligibility may change from one financial year to another as turnover, total assets or headcount increase.

Outsourcing the
Internal Audit Function

Outsourcing the internal audit function to NOA Group provides access to a team with more than 10 years of experience dedicated exclusively to this service line.

Establishing an in-house internal audit function involves fixed costs, including salaries, continuous professional development and professional certifications. For many companies, particularly those that have only recently reached the statutory audit thresholds, maintaining a permanent internal team may not be economically justified.

A co-sourcing model, in which the NOA Group team works alongside an internal representative appointed by the client, is often an appropriate solution for companies seeking to retain part of the accumulated knowledge in-house without incurring the full cost of maintaining their own dedicated team.

Independence is also one of the main reasons why many companies choose to outsource. An external internal auditor does not assess processes that they have themselves designed, thereby reducing the potential for conflicts of interest compared with an internal function.

NOA Group Methodology

NOA Group’s internal audit methodology follows the regulatory framework applicable in Romania and the standards issued by the Chamber of Financial Auditors of Romania, and is structured into clearly defined stages.

We begin by developing or reviewing the internal audit function’s operating procedures, followed by an enterprise-wide risk assessment and the development of a multi-year internal audit plan aligned with the company’s actual business priorities rather than a generic template.

Each internal audit engagement is carried out and directly coordinated by the NOA Group team, from planning and testing through to reporting findings to management.

The stage that truly distinguishes an effective internal audit from a purely formal exercise is the follow-up on the implementation of recommendations. We return to the client to verify whether the agreed actions have actually been implemented, rather than merely documented in an archived report. At management’s request, we also perform special advisory or investigative engagements outside the annual audit plan.

Risk Assessment and
Internal Controls

Risk assessment is the starting point of every internal audit engagement because it determines where audit effort should be concentrated.

The NOA Group team assesses the existing internal controls against the risks identified across the organization in order to determine whether those controls are adequate, redundant or, conversely, insufficient relative to the company’s actual level of exposure.

Our approach follows the three lines of defense model:

01.

First line

operational controls managed by the functions that own the risk;

02.

Second line

risk management and compliance functions;

03.

Third line

internal audit, which provides independent assurance over the first two lines.

Risk management is not limited to preventing direct financial losses. A robust internal control assessment also identifies operational inefficiencies which, although they may not appear as accounting losses, consume time and resources throughout the company’s day-to-day processes. This is an established area of our practice, where we create additional value by tailoring our approach to each client’s specific organizational structure.

Internal Audit
Deliverables

At the end of an internal audit engagement, the client receives an audit report documenting the findings identified, the risks associated with each finding and the recommendations proposed by the NOA Group team to address them.

An internal audit report prepared by NOA never stops at simply listing the issues identified. It includes a remediation plan with realistic deadlines and clearly assigned owners within the client organization.

What distinguishes an internal audit deliverable from a simple compliance document is the subsequent monitoring process. The NOA Group team returns to the client to verify the implementation of the agreed recommendations, not only at the end of the engagement but also at intervals agreed with management.

This follow-up process turns internal audit from a one-off exercise into a tool for continuous improvement of the internal control environment, with results that can be observed from one engagement to the next.

Benefits of
Internal Audit

Beyond the statutory requirement, a well-executed internal audit generates benefits that management can see directly in day-to-day operations.

Process optimization is often the most visible outcome. Many operational inefficiencies remain unnoticed until an independent external assessment brings them to light, because internal teams become accustomed to the way things have always been done.

Risk reduction is the second direct benefit. This does not mean eliminating risk entirely, which is not realistic in any organization, but rather turning unknown risks into identified risks that can be consciously managed.

For management teams, the most important benefit is often the least visible. An independent internal audit provides an additional level of assurance when important decisions are made because those decisions are based on a verified view of the organization rather than solely on internal reporting from the departments concerned.

Processes That Can Be Audited

Internal audit is not limited to finance and accounting. Almost any organizational process that affects the company’s risk profile or performance can be subject to an internal audit engagement, including:

01.

financial processes, such as invoicing, payments and treasury management;

02.

HR processes, such as recruitment, payroll and compliance with internal policies;

03.

IT processes, including system access, data security and business continuity;

04.

procurement processes, including supplier selection and contract approval;

05.

sales and marketing processes, including discount policies and receivables management.

The processes selected for audit in a given year are determined by the multi-year internal audit plan developed on the basis of the risks identified. There is no fixed checklist applied identically to every company.

Over time, the NOA Group team has carried out hundreds of internal audit engagements for large corporate clients across different industries, ranging from agriculture and dairy production to automotive distribution and energy.

As a result, we bring practical experience directly relevant to the specific characteristics of each type of audited process, rather than relying solely on theoretical knowledge of operational audit.

Why NOA Group

Choosing an internal audit partner is fundamentally a matter of trust. The company grants access to sensitive processes, data and decision-making, while the outcome of the engagement must be able to withstand potential scrutiny from regulators or shareholders.

NOA Group builds this trust through a senior-led delivery model. Clients have direct access to the partner and director leading the engagement, not only to the execution team working on-site.

Throughout the years dedicated to this service line, NOA Group’s internal audit team has developed direct experience across industries with different risk profiles, ranging from manufacturing and distribution to agriculture and energy.

Our approach remains tailored to each engagement. The audit plan, testing procedures and recommendations are based on the client company’s actual risks rather than on a standard template replicated from one engagement to another.

“When I'm asked who we work with for tax and internal audit, I say NOA. I'm not even asked why — it's intuitive. NETOPIA is what it is, so NETOPIA's consultants are at the same level.”

Antonio Eram - Founder & CEO NETOPIA Payments

Frequently Asked Questions About Internal Audit

Under Article 65(7) of Law No. 162/2017, public-interest entities and companies that meet the statutory size criteria for mandatory audit are required to organize an internal audit function. Failure to comply with this obligation may result in a fine of up to RON 100,000 pursuant to Article 44 of the same law.

The cost of an internal audit engagement depends on the size of the company and the number and complexity of the processes included in the audit plan. NOA Group prepares a cost estimate following an initial discussion regarding the company’s structure and priority risk areas rather than applying a standard fee, as every engagement is based on a different audit plan.

The duration of an internal audit engagement varies depending on the number of processes audited within a cycle and the complexity of the organization, ranging from several weeks for a specific process to several months for a complete annual plan delivered through multiple successive engagements.

Depending on the process under review, the NOA Group team requests the relevant available documentation, including internal procedures, approval workflows, financial reports and risk policies. Where written documentation is incomplete, this information is supplemented through interviews with the individuals responsible for the relevant processes.

For companies subject to the statutory requirement, internal audit must operate on an ongoing basis and be organized according to a multi-year plan. The precise frequency of the engagements covering each process is determined by the assessed level of risk, with higher-risk processes being reviewed more frequently than lower-risk areas.