Investment and capital project audits
Business cases, investment committee decisions, approvals, due diligence, payments against milestones and post-investment monitoring.
Your internal audit team knows the organisation. It may not have the time or the specialist depth for an investment portfolio, a major procurement or an approvals review. We work alongside your auditors, under your audit committee, on the areas where the risk is highest.
A co-sourcing arrangement in which Orbix auditors join your internal audit function for specific audits or a share of the annual plan. You keep ownership of the function and its methodology; we add capacity and specialist skills in the areas your team covers least.
Recent public findings on investment losses and unapproved payments in public entities show where internal audit coverage is often thinnest: investment decisions, capital projects, related-entity funding and the approvals behind them. Listed issuers must maintain an internal audit function under Bursa's listing requirements, and statutory bodies and GLCs face similar expectations from their ministries and the Auditor-General. Co-sourcing lets the function cover these areas properly without permanent headcount.
Audits are scoped with your chief audit executive and fit into your annual plan and methodology.
Business cases, investment committee decisions, approvals, due diligence, payments against milestones and post-investment monitoring.
Tender processes, evaluation, conflicts of interest, variation orders and payment controls, including data analytics on vendor payments.
Whether decisions and payments were approved by the right body within delegated authority, with evidence.
Funding flows, management fees, related-party transactions and governance in subsidiaries and joint ventures.
Testing controls behind your OACP, ISO 37001 system or Section 17A adequate procedures.
Payment, vendor and journal analytics that point the audit at the transactions most likely to matter.
Specialist audits of investments and procurement, the areas behind many of the largest public findings.
Your chief audit executive owns the plan, methodology and reporting. We work inside it.
Flex up for the audit plan's peak or for a specific high-risk review without a permanent hire.
Your auditors work alongside ours and keep the methods and work programmes.
External auditors bring fresh eyes to areas where internal relationships make challenge harder.
The committee sees high-risk areas covered with the depth they need.
Agreeing the audits, scope, resourcing and reporting lines within your annual plan.
Risk assessment, work programme and data requests for each audit.
Testing, interviews and analytics carried out jointly with your team.
Agreeing facts and management responses with the auditee.
Reports in your format, presented to the audit committee with your chief audit executive.
Verifying that agreed actions have been implemented.
Risk-based programmes your team can reuse.
Findings, ratings and management responses in your format.
Payment and vendor analytics with the exceptions investigated.
Summaries for the committee, presented with your chief audit executive.
Status of agreed actions.
Approaches for investment, procurement and approvals audits left with your team.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
In co-sourcing, your organisation keeps its internal audit function and its head, and we add auditors for specific work. In outsourcing, the whole function is provided externally. Co-sourcing keeps ownership and knowledge inside the organisation.
To your chief audit executive, and through them to the audit committee, following your methodology and reporting format.
Yes. Many clients co-source only the audits their team lacks the skills or capacity for, such as investments, capital projects or procurement.
Yes. Our work is performed in line with the Institute of Internal Auditors' Global Internal Audit Standards and your own methodology.
Yes. We analyse payment, vendor and journal data to target testing, under your data security requirements.
We do not audit work we designed or delivered. Where we have advised on an area, another team or your own auditors cover it.
Tell us the size of your internal audit team, the areas you want covered and your audit calendar. We will come back with a resourcing proposal and a fixed quotation.