Internal Audit Maldives

Independent articles, insights, perspectives, and discussions dedicated to advancing the internal auditing profession in the Maldives.

The Internal Audit Budget: How to Build It, Defend It, and Base It on the Standards — A Maldivian Guide

An internal audit function without its own budget is a function whose work is quietly decided by someone else. The audits that get done are the ones that happen to be affordable, not the ones the organisation’s risks actually need. When money gets tight, training is usually cut first. Travel to island sites is cut second. Independence suffers third, even if nobody calls it that.

This is not a made-up problem. The Privatization and Corporatization Board (PCB) has reported in its own corporate governance reviews that some state-owned enterprises (SOEs) still do not have a properly set up internal audit function, and that some run with only one staff member. Globally, the Internal Audit Foundation’s Pulse of Internal Audit research finds that about half of chief audit executives say their funding is not enough, and the share of functions reporting budget cuts nearly doubled in the latest survey. The pressure is real.

There are two pieces of good news. First, the IIA’s Global Internal Audit Standards (2024), mandatory for all internal audit functions since 9 January 2025, treat the budget as a serious governance matter. They set clear duties for both the head of internal audit and the board. Second, Maldivian SOE auditors already have one of the strongest budget protections in any country’s governance code. Most people have never heard of it. We will get to it below.

This article explains what the Standards require, how to build the budget line by line, what Maldivian rules add, and how to defend your number when someone asks for cuts. A free budget template comes with this article, built for Maldivian conditions and matched to the Standards.

Rule number one: the plan comes first, the budget comes second

The most common mistake is doing things in the wrong order. The finance department gives a spending limit, and the audit plan is then cut down to fit it. The Standards require the opposite.

Standard 9.4 (Internal Audit Plan) says the risk-based plan must identify the people, money, and technology needed to complete it. Standard 10.1 (Financial Resource Management) then says the Chief Audit Executive (in the Maldives, CAE is usually reffered as the Chief Internal Auditor (CIA) or Head of Internal Audit) must develop a budget that allows the plan and strategy to be delivered. So the correct order is: mandate → strategy → risk assessment → audit plan → resources needed → budget → board approval. This is the logical order, even if the calendar runs differently, as the next section explains.

Norman Marks (practitioner and thought leader in internal audit, risk management, and governance for a long time), says it simply: the budget should be decided by the work that needs to be done, not the other way around, where the work is decided by the budget. He goes further. If a head of audit simply accepts a number handed down by the CFO, Marks calls that a failure by the head of audit, not the CFO. Strong words, but useful ones. The budget is something you build and defend, not something done to you.

Marks used zero-based budgeting for twenty years. Every year he made a fresh, ranked list of the audits needed to cover the risks that matter, and priced it from zero. He never just rolled last year’s number forward. His warning: “last year plus inflation” gives you too little money in a growing organisation, too much in a shrinking one, and laziness everywhere. For Maldivian SOEs, whose risks change with every new project or board reshuffle, that warning fits perfectly.

But in the Maldives, the budget is due before the plan — here is how to square it

In practice, Maldivian organisations prepare budgets during the third quarter, to align with the corporate and state budget cycles. Internal audit’s budget must be submitted with the organisation’s full budget, to the board in SOEs, and to the government in the public sector. The detailed audit plan, however, is usually prepared near the end of the year. And rightly so: risk keeps changing, so a plan written in September for next year would already be stale before it starts. So in the Maldivian calendar, the budget comes first and the plan comes later.

Does this break the rule above? No, because the rule is about logic, not dates. The Standards do not require a finished plan before a budget number. In fact, Standard 10.1 says the head of audit should follow the organisation’s own budget process, and in the Maldives, that process is a third-quarter submission.

The way to make both work is to budget for capacity, then plan within it. In the third quarter, do a quick, top-level risk refresh, the current risk register, last year’s plan, known changes ahead. From that, price the function’s capacity: staff, training, technology, a travel envelope for expected site coverage, the quality assessment provision, and a contingency reserve. Then, near year-end, prepare the detailed risk-based plan within that approved envelope. If the final plan turns out to need more than the envelope, Standards 8.2 and 10.1 require you to report the gap to the board, with the unfunded audits named.

One warning. This sequence is only acceptable if the third-quarter number is built from audit thinking. If it is simply last year’s number plus a percentage, then the calendar has quietly become the excuse for exactly the trap this article warns against: the budget deciding the work.

What the Standards require

Four requirements form the backbone of a proper budget process. Every Maldivian head of internal audit should know them.

Standard 10.1 — build the budget, manage it, get board approval, and report shortfalls. The head of audit must develop a budget that allows the strategy and plan to be delivered. The budget must include everything the function needs to run, and the Standard specifically names training and technology, because these are the two things cut most often. The head of audit must manage day-to-day spending in line with the budget, must get the budget approved by the board, and must quickly tell the board and senior management if the money is not enough. The Standard’s guidance adds four practical points. Follow your organisation’s normal budget process. Even if internal audit is outsourced, the board must still approve an adequate budget. Compare planned spending with actual spending regularly, and look into big differences. The budget may include a reserve for unexpected changes to the plan. One more point matters greatly here: even when internal audit’s budget sits inside another department’s budget, the head of audit must still know how much has been allocated, track the spending, and check it is enough.

Standard 8.2 — check if resources are enough, and tell the board if they are not. The head of audit must assess whether resources are sufficient to deliver the mandate and the plan. If they are not, the head of audit must work out how to get more, and must tell the board what the shortfall means. The board has a matching duty: discuss resource sufficiency with the head of audit at least once a year, quarterly is best practice, and work with senior management to fix any shortfall. A simple gap analysis (what we have versus what we need) is the recommended tool.

Standard 6.3 — board approval of the budget is part of good governance. The board shows its support for internal audit by approving the audit charter, the plan, the budget, and the resource plan. The Standards explain why: board approval proves that the function has what it needs to complete its planned work. If your audit committee has never been asked to approve an internal audit budget, Standard 6.3 gives you the words to start that conversation.

Standard 7.1 — starving the budget damages independence. This is the strongest argument. The Standards say that cutting the budget to a level where the function cannot deliver its charter responsibilities is an impairment of independence. A starved budget is not just an inconvenience to manage quietly. It is a problem the head of audit is required to report.

Other Standards add specific cost lines. Standards 3.1 and 3.2 require training and professional development funding to be included in the budget. Standard 10.3 requires properly supported technology funding requests to the board. Standard 8.4 requires an external quality assessment at least once every five years by a qualified independent assessor, a real cost that small functions almost always forget. It is far less painful to set aside one-fifth of the cost each year than to face the whole bill in year five. Standard 12.2 lists budget-versus-actual comparison as a measure of a well-run function, so quarterly monitoring is part of your quality programme.

The eight parts of a complete internal audit budget

There is no magic formula for the size of an audit budget. But there is a complete list of what it should cover.

1. Personnel. Salaries, allowances, the employer’s pension contribution, recruitment, and benefits. This usually takes around 60 or more percent of an in-house function’s budget.

2. Training and professional development. CIA and CISA exam fees, study materials, IIA membership and CPE, local courses, and conference attendance. This line has special legal protection in SOEs, explained below.

3. Technology. Audit management software, data analytics tools, laptops, and secure storage for working papers.

4. Co-sourcing and outside experts. Buying skills a small unit cannot employ full-time, IT audit, fraud investigation support, etc. Standard 3.1 clearly allows contracting for skills the team lacks.

5. Quality. The external quality assessment cost, spread over five years, plus internal quality checks.

6. Travel and field logistics. Our audit sites (for some of the organization) are spread across atolls. A site visit means speedboats, domestic flights, accommodation, and daily allowances. Cutting travel is not a saving, it is a decision to leave island operations unaudited. Say it to the audit committee in exactly those words.

7. Administration and subscriptions. The small recurring costs of running the function.

8. Contingency reserve. Five to ten percent of the total, for unplanned investigations and new risks. Standard 10.1 clearly allows such reserves, and Standard 9.4 recommends keeping spare plan hours to match.

One more thing. The Pulse of Internal Audit research shows nearly nine in ten chief audit executives now do work beyond internal audit, most commonly fraud investigation. In the Maldives the trend is same: in organisations with no risk department, the audit unit keeps the risk register, runs investigations, and drafts policies by default (not all the organizations). Marks’s rule applies: extra work given by management is extra work needing extra budget. Price it, or refuse it, but never absorb it silently.

The Maldivian advantage: what the SOE Code gives you

Now for the provision that deserves to be far better known. The Code of Corporate Governance for State Owned Enterprises, issued by the PCB under the Ministry of Finance and in force since 1 May 2019, covers internal audit in Chapter 6. Section 25(14) says:

“The internal audit function should be resourced properly. As such the audit committee should ensure deployment of sufficient and appropriate human resources in the function. Audit committee should also ensure appropriate training and development opportunities are provided to the internal audit staff annually. For this, annual training budget of internal audit once passed by the Audit Committee is considered final.”

Read that last sentence twice. It gives approval of the internal audit training budget to the audit committee, not to management or HR. Second, it makes that approval final. Once passed, the training budget cannot be trimmed by the finance department or cut mid-year by management. Third, the word annually makes it a right that repeats every year, not a one-time favour.

But the protection only starts when one step is taken: the training budget must actually be presented to and passed by the audit committee, as its own item, recorded in the minutes. A training budget that only ever existed as a row in the finance department’s spreadsheet was never “passed by the Audit Committee”, so it never became final. The move for every SOE head of internal audit this budget season is simple. Put the training budget on the audit committee agenda. Get it passed. Get it minuted. From that moment, any later cut is not a routine adjustment, it is a departure from the Code.

The rest of the Code backs this up. Section 25(12) requires the head of internal audit to hold an IIA or IFAC-recognised professional qualification. Because qualified auditors are scarce locally, the Code allows someone to be appointed on academic qualifications, but completing the professional qualification within a reasonable time must be a condition of keeping the job. In an SOE, then, CIA exam fees are not a perk. They are a compliance cost the Code itself created. Section 25(18) requires all internal auditors, including outsourced teams, to sign the IIA’s ethics requirements, which brings membership and CPE costs into the budget too. And Section 13(3) lets the audit committee obtain independent professional advice at the SOE’s expense, the natural way to fund co-sourced specialists and the five-yearly external quality assessment that a two-person unit cannot do alone.

Two honest caveats. The Code works on a comply-or-explain basis. SOEs report compliance in an annual Corporate Governance Statement, so a breach of Section 25(14) is dealt with through disclosure and PCB review, not fines. That still matters, it turns a quiet budget cut into an item in a public governance statement. Also, the Code does not apply to SOEs listed on the Maldives Stock Exchange, which follow the capital-market governance rules instead. Readers in listed companies, banks, insurers, resorts, and private companies do not have the Section 25(14) protection, for them, the Standards-based techniques below do all the work. Government offices face a different reality again: the state budget calendar, not an audit committee, decides their funding. For them, the only workable strategy is to engage early in the budget cycle, not to protest after the allocation is made.

Defending the number: the “below the line” technique

Budgets get cut. The 2026 Pulse of Internal Audit found the share of functions reporting cuts nearly doubled in a year, and about half of chief audit executives say their funding is insufficient. The same research points to the cure: functions closely aligned with the organisation’s strategy are far more likely to be properly funded. Leaders fund what protects the things they care about.

The best defence technique is now written into the Standards themselves. Standard 9.4’s guidance recommends showing the board, together with the plan, the next set of engagements that would be performed if additional resources were available. Marks used this for twenty years and called it the “above and below the line” list. Above the line: the audits the proposed budget covers. Below the line: the audits a cut would push out, each one named, with hours, cost, and what the organisation loses if it is not done.

That is what the Standards demand anyway. Standard 8.2 requires the head of audit to report the impact of a shortfall. Standard 10.1 requires quick escalation. Handled properly, a budget cut becomes a risk decision taken knowingly by the board, where it belongs, instead of a quiet loss carried on the auditor’s conscience.

Your action list for this budget season

Build the budget from the risk-based plan, audit by audit, and be ready to show how hours become rufiyaa. Cover all eight parts, especially the three that disappear first: training, the external quality assessment, and inter-island travel (if applicable). If you work in an SOE, put the training budget before the audit committee as its own item and have the approval minuted, Section 25(14) does the rest. Get board approval of the full budget and keep the record: it is a Standard 10.1 requirement, a Standard 6.3 essential condition, and your evidence for any future quality assessment. Prepare your below-the-line list before anyone asks for a cut. Compare budget with actual spending every quarter and report differences to the audit committee. And if the money falls short of the plan, say so formally, in writing, to the board, naming the audits that will not be done.

Download the template

To make all of this practical, I have prepared a free Internal Audit Budget Preparation Template (Maldives Edition). It is an Excel workbook with an interactive dashboard, click any amount and it opens the detail tab behind it. It covers all eight budget parts, with the exact Standard and Code reference behind every line. It includes a Plan-to-Budget Bridge that turns audit hours into costs and holds your below-the-line list, a quarterly variance monitor, and a governance tab that walks you through the approval steps, including the Section 25(14) audit committee step. Every number in it is only an example. The structure is the point. Download it, put in your own numbers, and take the dashboard to your next audit committee meeting.

The budget is where internal audit’s independence is either funded or given away. The Standards give us the requirements. The SOE Code gives Maldivian auditors rare leverage.

Leave a Reply

Your email address will not be published. Required fields are marked *