Governance / Internal Audit

Co-Sourced Internal Audit for Investments, Procurement and Approvals

Your internal audit team knows the organisation. It may not have the time or the specialist depth for an investment portfolio, a major procurement or an approvals review. We work alongside your auditors, under your audit committee, on the areas where the risk is highest.

Specialist auditors working with your in-house team Investment, procurement, approvals and integrity audits Reports to your audit committee under your methodology
Overview

Co-Sourced Internal Audit

What it is

A co-sourcing arrangement in which Orbix auditors join your internal audit function for specific audits or a share of the annual plan. You keep ownership of the function and its methodology; we add capacity and specialist skills in the areas your team covers least.

Why organisations need it

Recent public findings on investment losses and unapproved payments in public entities show where internal audit coverage is often thinnest: investment decisions, capital projects, related-entity funding and the approvals behind them. Listed issuers must maintain an internal audit function under Bursa's listing requirements, and statutory bodies and GLCs face similar expectations from their ministries and the Auditor-General. Co-sourcing lets the function cover these areas properly without permanent headcount.

Key features

What the engagement covers

Audits are scoped with your chief audit executive and fit into your annual plan and methodology.

Investment and capital project audits

Business cases, investment committee decisions, approvals, due diligence, payments against milestones and post-investment monitoring.

Procurement and contract audits

Tender processes, evaluation, conflicts of interest, variation orders and payment controls, including data analytics on vendor payments.

Approvals and limits of authority audits

Whether decisions and payments were approved by the right body within delegated authority, with evidence.

Subsidiary and related-entity audits

Funding flows, management fees, related-party transactions and governance in subsidiaries and joint ventures.

Integrity and anti-corruption audits

Testing controls behind your OACP, ISO 37001 system or Section 17A adequate procedures.

Data analytics support

Payment, vendor and journal analytics that point the audit at the transactions most likely to matter.

Business value

What the business gets out of it

Coverage where risk is highest

Specialist audits of investments and procurement, the areas behind many of the largest public findings.

You keep control of the function

Your chief audit executive owns the plan, methodology and reporting. We work inside it.

Capacity without headcount

Flex up for the audit plan's peak or for a specific high-risk review without a permanent hire.

Skills transfer

Your auditors work alongside ours and keep the methods and work programmes.

Independent perspective

External auditors bring fresh eyes to areas where internal relationships make challenge harder.

Audit committee confidence

The committee sees high-risk areas covered with the depth they need.

How it works

How the engagement runs

01

Planning with the chief audit executive

Agreeing the audits, scope, resourcing and reporting lines within your annual plan.

02

Audit planning

Risk assessment, work programme and data requests for each audit.

03

Fieldwork

Testing, interviews and analytics carried out jointly with your team.

04

Findings discussion

Agreeing facts and management responses with the auditee.

05

Reporting

Reports in your format, presented to the audit committee with your chief audit executive.

06

Follow-up

Verifying that agreed actions have been implemented.

Deliverables

What you receive

Audit work programmes

Risk-based programmes your team can reuse.

Audit reports

Findings, ratings and management responses in your format.

Analytics outputs

Payment and vendor analytics with the exceptions investigated.

Audit committee papers

Summaries for the committee, presented with your chief audit executive.

Follow-up reports

Status of agreed actions.

Methodology notes

Approaches for investment, procurement and approvals audits left with your team.

Who it is for

Who this is built for

Industries

Statutory bodiesPublic universities and holding companiesGovernment-linked companiesBursa-listed companiesConstruction and propertyHealthcare groupsFinancial servicesCo-operatives

Company sizes

Organisations with a small in-house internal audit teamListed companiesGLCs and statutory bodiesGroup structures

Departments

Audit committeeChief audit executiveInternal auditFinanceProcurementIntegrity unit
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

What is the difference between co-sourcing and outsourcing internal audit?

In co-sourcing, your organisation keeps its internal audit function and its head, and we add auditors for specific work. In outsourcing, the whole function is provided externally. Co-sourcing keeps ownership and knowledge inside the organisation.

Who do your auditors report to?

To your chief audit executive, and through them to the audit committee, following your methodology and reporting format.

Can you audit our investments or subsidiaries only?

Yes. Many clients co-source only the audits their team lacks the skills or capacity for, such as investments, capital projects or procurement.

Do you follow the Global Internal Audit Standards?

Yes. Our work is performed in line with the Institute of Internal Auditors' Global Internal Audit Standards and your own methodology.

Can you use data analytics on our payment data?

Yes. We analyse payment, vendor and journal data to target testing, under your data security requirements.

Is there a conflict if you also provide training or consulting?

We do not audit work we designed or delivered. Where we have advised on an area, another team or your own auditors cover it.

Get started

Put specialist auditors on your highest-risk areas

Tell us the size of your internal audit team, the areas you want covered and your audit calendar. We will come back with a resourcing proposal and a fixed quotation.