"Finance audit" means different things to different people, and the ambiguity causes real confusion when someone commissions one. It can mean the statutory audit of financial statements, an internal audit of the finance function, or a diagnostic review of how finance operates. They have different scopes, different outputs and different levels of independence — and asking for the wrong one is how a board ends up with an opinion when it wanted advice.
The three things it might mean
The statutory audit is an independent opinion on whether the financial statements give a true and fair view, performed by a registered auditor under auditing standards, at a materiality threshold, for the benefit of the members. Its focus is one reporting period rather than how well finance is run day to day — though "purely backward-looking" overstates it, since the auditor must also evaluate management's going concern assessment and the forecasts behind it. Our guide to external audits covers it.
An internal audit of finance is assurance for management and the audit committee over the controls in the finance processes — payments, revenue, payroll, month-end close, journals. It is risk-based and reports internally, and it commonly produces findings and recommendations — though internal audit can and does give opinions and conclusions on governance, risk management and control. The real difference from the statutory audit is not the absence of an opinion but what the opinion is about, who it is for, and the reporting line it travels along.
A finance function review is a consulting exercise: how long the close takes, what the team spends its time on, whether the systems fit, whether the reporting supports decisions. It produces a plan, not assurance.
Most boards asking for a finance audit want the second or third. What they usually describe sounds like the first.
What an internal audit of finance actually examines
The scope follows where money and misstatement risk concentrate:
- Purchase to pay — supplier onboarding, three-way matching, approval limits, bank detail changes, duplicate payments. The area with the highest fraud loss in most organisations, covered in our guide to the purchase ledger;
- Order to cash — pricing and discount authority, credit limits, revenue recognition, credit notes issued after period end;
- Payroll — starters and leavers, standing data changes, overtime approval, and the reconciliation of payroll to the general ledger;
- Journals — who can post them, which are reviewed, and whether anything unusual was posted close to a period end. Management override of controls is the risk no segregation matrix addresses on its own;
- Balance sheet integrity — whether reconciliations are performed, reviewed, and cleared of ageing unexplained items;
- Access and segregation in the accounting system, which is where most control designs quietly fail after a system upgrade.
The findings that recur
Across mid-sized organisations the same issues appear with striking consistency. Approval limits that have not been revisited since the business was half its size. Reconciliations performed but not reviewed, with differences carried forward indefinitely. Access rights accumulated by long-serving staff who changed roles and kept the old permissions. A month-end close that takes three weeks, so management decisions are made on figures that are already old. And key-person dependency — one person who understands the revenue calculation, with no documentation and no cover.
None of these are dramatic. Collectively they are what a fraud report or a restatement is made of.
Choosing the right exercise
Start from the question. If it is "can we rely on the numbers we publish", that is statutory audit or an assurance review. If it is "are our controls working", that is internal audit. If it is "is our finance function fit for the size we have become", that is a review, and it should end with a roadmap rather than a rating.
Independence should follow the purpose. Assurance for an audit committee has to come from someone outside the finance line; advice can come from anyone competent. What does not work is asking the people who designed the process to assure it, and then reporting the result as independent — which is the most common structural flaw in in-house arrangements.
Scale also matters. A business with a three-person finance team cannot segregate duties the way a textbook requires, and an audit that simply reports that is unhelpful. The useful version identifies compensating controls that are achievable — owner review of the payment run, bank statements going to someone outside finance, an annual independent look at the areas segregation cannot cover.
Getting value from it
Agree the scope in writing and in terms of risks rather than areas. Insist on causes as well as findings, since remediation aimed at symptoms produces the same finding next year. Attach owners and dates to recommendations, and track them — an internal audit programme with no follow-up cycle is a report-writing exercise. And rotate coverage over a two or three-year plan rather than examining everything annually.
Acumon delivers this through outsourced internal audit and internal audit work, with business health checks where the question is about the function rather than the controls — and the testing methodology set out in our guide to control testing. If you are commissioning a "finance audit", the first hour should be spent deciding which of the three you actually want.