| External audit | Internal audit | |
|---|---|---|
| Question answered | Are the financial statements fairly stated? | Do the controls and processes actually work? |
| Required by | Free zone, licence, constitutional documents, lenders | Nobody: commissioned by the business |
| Audience | Shareholders, regulators, banks, free zone authority | The owner or board |
| Output | An audit opinion | Findings, risk ratings and recommendations |
| Scope | Set by auditing standards and materiality | Set by you, following the risk |
| Timing | Annual, after the year end | Any time; often rolling through the year |
| Independence | Required: strict rules apply | Objective, but internally directed |
| Materiality | Applies: small items are out of scope | None: a small recurring leak matters |
| Detects fraud? | Not designed to, and frequently does not | Frequently, because it is looking |
| Follow-up | Management letter, no obligation | Findings tracked and re-tested |
The gap between them is where losses live
The most consequential misunderstanding in this area is that a clean external audit means the business is under control. It does not, and it was never intended to.
An external auditor forms an opinion on whether the financial statements give a true and fair view. To do that they sample, and they apply materiality, a threshold below which an error would not change a reader’s view of the accounts. Most internal fraud in an owner-managed business sits comfortably below that threshold on any individual transaction, and is specifically structured to avoid attention.
So a business can receive an unqualified audit opinion while a supplier that shares a bank account with an employee is being paid monthly, because no single payment was material and testing controls in that way was not the engagement.
Internal audit is the engagement that asks the other question. It has no materiality threshold, it follows risk rather than balances, and its output is findings you can act on rather than an opinion you file.
What each one will and will not tell you
Stated plainly, because businesses routinely buy one expecting the other:
- External audit will tell you whether the financial statements are fairly stated, whether accounting policies are appropriate, and whether there are material misstatements
- External audit will not tell you whether a payment can be made without approval, whether stock is leaving the warehouse, or whether a supplier is genuine
- Internal audit will tell you where the controls fail, whether documented processes are actually followed, and where the business is exposed
- Internal audit will not give you an opinion that satisfies a free zone, a lender or a shareholder agreement
- Both together cover the accounts and the operations, which is what an owner actually wants to know
- Neither is a guarantee: an audit is not a warranty and an internal review is not a fraud-proof
Which one you need, and when
The external audit is usually not a choice. Most free zones require audited financial statements for licence renewal, audited accounts are a condition of QFZP status, and lenders and shareholder agreements frequently require them. If it is required, the only questions are who signs it and how well prepared you are.
The internal audit is always a choice, and the trigger points are consistent: reaching the size where the owner can no longer see every transaction, opening a second location, cash-intensive operations, high-value inventory, a loss or near-miss, a change of finance staff, or preparing for a sale where a buyer will ask about controls.
Where budget is genuinely limited and both are on the table, the external audit goes first because it is required. But we would rather a business ran a focused internal review on its two highest-risk processes than commissioned nothing at all, a narrow internal audit that actually happens is worth considerably more than a comprehensive one that stays on a list.
The small-business version of internal audit
A full internal audit function is not proportionate for most owner-managed businesses, and recommending one would be selling volume rather than value.
What is proportionate is a focused annual review of the two or three processes where a failure would hurt most, usually procurement and payments, cash handling, and stock or inventory. Scoped that way it is a contained piece of work with a specific output: findings, risk-rated, with recommendations sized to the people you actually have.
The recommendations matter as much as the findings. Textbook segregation of duties is not achievable with three people in finance, and a report recommending it is useless. Compensating controls, owner review of new suppliers, a second authoriser on payment release, exception reporting above a threshold, mandatory leave, do not make a failure impossible but make it visible early, which in practice is what limits the loss.
Where this goes wrong
The same problems recur, and every one of them was cheaper to prevent:
- Assuming a clean audit opinion means the controls work. It is not the question an audit answers.
- Expecting an external audit to find fraud. Materiality and sampling mean most internal fraud sits below its threshold.
- Commissioning an internal audit to satisfy a free zone, which requires an external opinion.
- Auditing the procedure manual rather than what people actually do.
- Recommending textbook segregation to a business with three people in finance.
- Filing the management letter rather than acting on it.
- Scoping internal audit by framework rather than by where the risk actually is.
Deadlines that apply
The external audit follows your year end, on the deadline set by your licence or free zone, which is generally tighter than the 30 September 2026 tax deadline and should drive the timetable.
Internal audit is best run either annually or on a rolling basis with a different process each quarter, which spreads cost and keeps attention on more than one area. Specific triggers (a second location, a change of finance staff, a loss, preparing for a sale) are worth acting on when they arise rather than waiting for the annual cycle.
What lands on your desk
- For external: a complete audit file, draft financial statements, fieldwork managed to a signed opinion
- For internal: findings with risk ratings, process maps of how things actually run, practical recommendations
- A prioritised action plan with owners and dates
- Follow-up to confirm what was implemented
What to have ready
The list is short and you will have most of it already:
- For external: trial balance, prior year audit file, reconciliations, contracts, related party details
- For internal: organisation chart, who does what in practice, system permissions, bank mandates
- Details of any known incidents or losses
- Free zone or licence requirements applicable to your entity
- Existing policies and procedures, if any
Related
Frequently Asked Questions
What is the difference between internal and external audit?
External audit forms an opinion on whether the financial statements are fairly stated, for shareholders, regulators and lenders. Internal audit tests whether your processes and controls actually work, for you. They answer different questions for different audiences.
Does a clean audit opinion mean our controls are fine?
No, and this is the most consequential misunderstanding in the area. An auditor samples and applies materiality; most internal fraud sits below that threshold on any individual transaction and is structured to avoid attention. A clean opinion says nothing about whether a payment can be made without approval.
Will an external audit find fraud?
It is not designed to and frequently does not. Detecting fraud requires looking specifically for it, without a materiality threshold, which is what an internal audit or forensic engagement does.
Is internal audit mandatory?
Not for most UAE private companies. It is commissioned because the owner wants to know, or because a shareholder, lender or prospective buyer expects it. Certain regulated sectors have their own requirements.
We have three people in finance. Is internal audit worth it?
Yes, scoped proportionately, a focused review of the two or three processes where a failure would hurt most, usually procurement and payments, cash, and stock. What matters is that the recommendations are sized to the people you actually have. Textbook segregation of duties in a three-person finance team is advice nobody can implement.
If we can only afford one, which?
The external audit, because it is usually required by your free zone, licence or lenders and is not optional. But a narrow internal review of your two highest-risk processes is worth considerably more than a comprehensive one that never happens.
What are compensating controls?
Measures that make a failure visible rather than impossible, for businesses too small for full segregation of duties, owner review of new suppliers, a second authoriser on payment release, exception reporting above a threshold, supplier statement reconciliation, mandatory leave. They do not prevent a determined fraud; they limit how long it goes unnoticed.
Whether the accounts are fairly stated, or whether the controls hold. They are different engagements, and a clean audit does not answer the second.
Check my compliance status 058 101 9570
Last reviewed 27 July 2026. Rates, thresholds and deadlines change, the e-invoicing provider deadline has already moved once. Confirm current requirements with the Federal Tax Authority before acting, or ask us to check your position.