Internal Audit
An existing obligation, now with a new reporting requirement directly on the first page of the 2025 financial statements.
The organisation of the Internal Audit function is provided for under Law No. 162/2017, as amended by Government Emergency Ordinance No. 137/2024, for entities whose financial statements are subject to statutory audit. This obligation has existed for some time and is part of the internal control framework required for such organisations.
Starting with the reporting for the 2025 financial year, however, an additional element strengthens the application of this requirement: the inclusion, directly on the first page of the balance sheet, of an explicit statement regarding the organisation of the Internal Audit function within the financial statements.
Financial auditors, under the supervision of ASPAAS, are required to verify and reflect this aspect in the official documentation. Consequently, the existence or absence of the Internal Audit function is no longer solely an internal compliance matter, but becomes an acknowledged element within financial reporting.
What changes in practice
The key difference does not lie in the introduction of a new obligation, but in the increased formalisation and visibility of compliance. By introducing this explicit disclosure:
- the organisation of the Internal Audit function becomes a verifiable element in financial reporting.
- its absence will be reflected in the auditor’s report;
- management’s responsibility in corporate governance gains an additional layer of transparency.
This development does not introduce a new requirement, but rather adds a higher level of formalisation and transparency. For affected entities, the implications are significant. Failure to properly organise the function may be reflected in the auditor’s report and may lead to consequences beyond administrative sanctions, influencing the perception of financial and institutional partners.
Who is affected
Primarily affected are:
- entities exceeding the legal thresholds for statutory audit;
- public interest entities;
- groups with complex governance structures.
For these organisations, the Internal Audit function is not merely a control mechanism, but a cornerstone of the risk management framework.
Implications for management and boards of directors
In this context, it is advisable for management and governing bodies to assess whether the Internal Audit function is properly organised, whether it benefits from operational independence, and whether the related documentation is up to date and aligned with legal requirements.
A purely formal approach may create vulnerabilities in the context of audits or in relations with investors, lenders, and institutional partners.
The 2025 reporting cycle therefore marks a stage of consolidation in the application of an already existing legal framework. For organisations that have not yet properly implemented this function, the current moment may serve as an opportunity for reassessment and adjustment.
NOA, through its Internal Audit services, supports companies in the analysis, structuring, and alignment processes required to meet applicable compliance standards.