Home › Internal Audit

Internal Audit

Internal audit services in Dubai — control testing, process mapping, segregation of duties review and physical verification, with practical recommendations and follow-up.

Internal audit examines whether your controls actually work — whether approvals happen before payments, whether the person who raises a supplier is the person who pays it, whether stock counted agrees to stock recorded. It is commissioned by you rather than required by a regulator, and its output is findings you can act on. AQ Consultancy provides internal audit for owner-managed businesses in Dubai and Abu Dhabi, sized to the business rather than to a framework.

A different question from the external audit

An external audit asks whether the financial statements give a true and fair view. It samples, it materialises, and it is designed to form an opinion on a set of numbers at a point in time.

Internal audit asks a different question: does the process work. Can a payment be made without approval. Can a customer be given credit without a check. Can stock leave without a document. Can the same person create a supplier, approve an invoice and release the payment.

Those are the questions that matter to an owner, because the answers determine whether the business can be trusted to run without them in the room. And an external audit will not answer them — it is not designed to, and a clean audit opinion says nothing whatever about whether your controls hold.

Who needs it

Owner-managed businesses reaching the point where the owner cannot personally see every transaction — typically at the second location, the fiftieth employee, or the point where cash handling moves out of sight.

Businesses with cash-intensive operations: retail, food and beverage, clinics. Businesses with high-value inventory. Businesses with procurement of any scale, where supplier selection and payment approval sit close together. Businesses that have experienced a loss and want to know whether it could happen again. And businesses preparing for a sale, where a buyer will ask about controls.

How we do it

Every engagement is different in detail, but the shape is consistent:

  1. Agree the scope with you. Internal audit is only useful if it looks where the risk actually is, which the owner usually knows better than any framework does.
  2. Map the processes as they actually run, not as the procedure manual describes them. These diverge, and the divergence is frequently the finding.
  3. Identify the control points and test whether they operate — not whether they exist on paper.
  4. Test segregation of duties, which in small businesses is the control most often absent for entirely understandable reasons.
  5. Sample transactions end to end, from order through to payment and into the ledger.
  6. Verify physically where relevant: stock, cash, fixed assets. A control that cannot be tested against something physical is a control on paper.
  7. Report findings with a risk rating and a practical recommendation for each — practical meaning implementable by the people you actually have.
  8. Follow up. An internal audit whose findings are never revisited is an expensive document.

Segregation of duties in a small business

The textbook answer is that the person who creates a supplier should not approve invoices, and the person who approves invoices should not release payments. In a business with three people in finance, that is not achievable, and pretending otherwise produces a report full of findings nobody can act on.

The useful approach is compensating controls: things that make a failure visible rather than impossible.

  • Owner review of new supplier additions monthly — a short list, quickly scanned
  • Bank payment release requiring a second authoriser, even where preparation is single-handed
  • Exception reporting on payments above a threshold, or to recently added suppliers
  • Periodic supplier statement reconciliation, which surfaces both errors and fabrications
  • Rotation of duties where headcount allows, and mandatory leave where it does not
  • Physical verification of stock and cash on an unannounced basis

None of these prevent a determined fraud. All of them make it considerably more likely to be noticed early, which in practice is what limits the loss.

What we usually find

The findings repeat across businesses and sectors, and almost none of them involve dishonesty. They involve processes that made sense when the business was smaller and were never revisited.

Payments made before approval because the supplier was chasing. Credit extended without a check because the customer was known. Stock issued on a verbal instruction because the manager was on site. Petty cash reconciled monthly by the person who holds it. Bank access still held by an employee who left. User permissions in the accounting system granted broadly because narrowing them was inconvenient.

Each of those is a reasonable operational decision that became a control weakness as the business grew past the point where the owner could see everything.

Where this goes wrong

The same problems recur, and every one of them was cheaper to prevent:

  • Assuming a clean external audit means the controls work. It is not the question an audit answers.
  • Auditing the procedure manual rather than what people actually do.
  • Recommending textbook segregation to a business with three people in finance, producing findings nobody can implement.
  • Testing existence rather than operation. A control that exists and is bypassed weekly is not a control.
  • Never following up, so the same findings appear next year.
  • Scoping by framework rather than by risk, and spending the budget where nothing was ever going to go wrong.

Timing and deadlines

Annually for most owner-managed businesses, or on a rolling basis where different areas are reviewed each quarter — which spreads the cost and keeps attention on more than one process.

Specific triggers worth acting on: opening a second location, a significant increase in headcount, a change of finance staff, a loss or near-miss, or preparing for a sale. Each of those changes the risk profile in a way that makes the previous assessment out of date.

What you get

  • A written report of findings, each with a risk rating
  • Practical recommendations sized to the people you actually have
  • Process maps showing how things actually run
  • A prioritised action plan with owners and dates
  • Follow-up review to confirm what was implemented

Documents we will ask for

What we ask for up front:

  • An organisation chart and a description of who does what in practice
  • Existing policies and procedures, if any exist
  • Access to the accounting system, including user permissions
  • Bank mandates and authorisation limits
  • A sample of transactions across the processes in scope
  • Details of any known incidents or losses
  • Stock and fixed asset records where physical verification is in scope

Fees

Fixed fee, scoped on the processes in scope and the number of locations. A single-site business reviewing procurement and payments is a contained exercise; a multi-location retail business with cash handling and stock is larger.

Rolling programmes, where a different area is reviewed each quarter, are quoted annually and are usually better value than one large review — both because the cost is spread and because findings are acted on while they are still fresh.

Related

Frequently Asked Questions

What is the difference between internal and external audit?

External audit forms an opinion on whether the financial statements give a true and fair view, for the benefit of shareholders and regulators. Internal audit tests whether your processes and controls actually work, for your benefit. A clean audit opinion says nothing about whether your controls hold.

Is internal audit mandatory in the UAE?

Not for most private companies. It is commissioned because the owner wants to know, or because a shareholder, lender or buyer expects it. Certain regulated sectors have their own requirements.

We only have three people in finance. Is segregation of duties possible?

Not in the textbook form, and a report recommending it would be useless. The workable approach is compensating controls — owner review of new suppliers, second authoriser on payment release, exception reporting, supplier statement reconciliation, mandatory leave. These make a failure visible rather than impossible, which is what limits the loss.

What do you usually find?

Payments made before approval because a supplier was chasing. Credit extended without a check because the customer was known. Bank access still held by a former employee. Broad accounting system permissions granted because narrowing them was inconvenient. Almost none of it involves dishonesty — it involves processes that made sense when the business was smaller.

How often should we do this?

Annually for most owner-managed businesses, or on a rolling basis with a different area each quarter. Specific triggers worth acting on: a second location, a change of finance staff, a loss or near-miss, or preparing for a sale.

Will you tell staff we are doing this?

That is your decision and it depends on the objective. Announced reviews test whether processes work; unannounced verification of cash and stock tests something different. We will advise on which is appropriate for the scope, and physical verification is generally more useful unannounced.

What happens to the findings?

You get them with a risk rating and a practical recommendation each, prioritised. We then follow up to confirm what was actually implemented — an internal audit whose findings are never revisited is an expensive document.

Would you know if a control failed?
Tell us where the business feels least visible to you. That is usually the right place to start, and the scope should follow the risk rather than a framework.
Check my compliance status 058 101 9570

Last reviewed 27 July 2026. Rates, thresholds and deadlines change — the e-invoicing provider deadline has already moved once. Confirm current requirements with the Federal Tax Authority before acting, or ask us to check your position.

Last reviewed 27 July 2026 · Figures follow FTA and Ministry of Finance guidance. Verify current rates at tax.gov.ae before acting.
Call Check my status