Media Center Subscribe Contact
English Portuguese French
M&J Consultants
  • Sectors
  • Solutions
  • Our Insights
  • About Us
  • Guides
Get Started
Agriculture Education Energy & Utilities Financial Services Healthcare Hospitality & Tourism Infrastructure Transportation & Logistics Manufacturing Mining & Resources Oil & Gas Public Sector Real Estate & Construction Retail & Consumer Technology & Telecoms
Business Advisory Hands-on advisory, governance, and performance Digital and Technology Digital transformation and tech solutions Marketing & Sales Growth strategies and market positioning Finance and Tax Financial advisory and tax optimization ERP & Operations Odoo ERP implementation and optimization

Topics

Investment & Market Entry Tax & Compliance Business Setup Trade & Policy Digital Transformation View all Insights

By Sector

Mining & Resources Agriculture Manufacturing Financial Services Energy

Resources

M&J Books Webinars M&J Futures Reports

C-Suite Insights

CEO Insights CFO Insights COO Insights CIO Insights CMO Insights

About

What We Do What We Believe Our People & Leadership

 

Client Results Global Affiliations

Timeless Businesses (Our Mission)

Our Purpose Our Vision Learn more about our Mission
African Business Forum

Investment Guides

Zimbabwe Zambia Coming Soon South Africa Coming Soon Kenya Coming Soon Nigeria Coming Soon See all

Tax Guides

Zimbabwe Coming Soon Zambia Coming Soon South Africa Coming Soon Kenya Coming Soon Nigeria Coming Soon See all
M&J Consultants
Agriculture Education Energy & Utilities Financial Services Healthcare Hospitality & Tourism Infrastructure Logistics Manufacturing Mining & Resources Oil & Gas Public Sector Real Estate Retail & Consumer Technology & Telecoms
Business Advisory Digital and Technology Marketing & Sales Finance and Tax ERP & Operations
Investment & Market Entry Tax & Compliance Business Setup Trade & Policy Digital Transformation Mining & Resources CEO Insights CFO Insights
What We Do What We Believe Our People & Leadership Client Results Global Affiliations Our Purpose Our Vision Timeless Businesses
Zimbabwe — Investment Guide Zimbabwe — Tax Guide Zambia — Investment Guide Zambia — Tax Guide More Countries Coming Soon
Get Started

INTERNAL AUDIT AFRICA: OUTSOURCING FOR SUBSIDIARIES

Tax Compliance

Back to Insights
Tax Compliance
M&J Africa October 7, 2026

A finance director in Lagos closes the month while head office asks for assurance over payroll, procurement and cash controls. The group team wants one report. The Nigerian subsidiary needs work that reflects its own regulator, systems and data obligations.

That is the practical purpose of internal audit Africa engagements. We structure outsourced work around each subsidiary’s legal form, sector, control environment and reporting line, then give boards and head office evidence they can use.

Our internal audit and risk advisory Africa work starts with a question many groups miss: what must the local entity demonstrate, and what does head office need to see? Africa is not one tax, company-law or governance jurisdiction. A listed Nigerian public company, a South African state-owned entity and a private Kenyan operating company can require very different assurance coverage.

Define the outsourced internal audit scope before appointing a provider

An outsourced internal audit function should not duplicate the external statutory audit. External auditors issue an opinion on financial statements. Internal audit tests whether management’s controls, governance and risk responses work throughout the year, then reports independently to the board or audit committee.

Start with a documented audit charter. It should set out who approves the plan, who receives reports, management’s right to respond, and the internal auditor’s access to records, sites and systems. Without this document, a group can pay for testing that management directs away from its highest-risk areas.

A practical scope normally includes the following work:

●        A risk-based audit plan that ranks risks by subsidiary and process.

●        Internal-control testing over revenue, purchasing, stock, cash, payroll and delegated authority.

●        Fraud-risk testing, including vendor onboarding, payment approval and unusual journal entries.

●        Tax and statutory-compliance testing against local filings and records.

●        IT controls over user access, privileged accounts, backups and system changes.

●        Payroll testing, including employee master-file changes and approval of allowances.

●        A remediation tracker that names an owner, a due date and evidence required for closure.

●        A board or audit-committee report that remains separate from management’s response.

Nigeria’s Securities and Exchange Commission guidance, effective from 10 October 2020, requires a risk-based internal-audit plan for relevant public companies. The plan must identify priority risks, the assurance approach, and the skills and resources needed. That requirement makes a generic group checklist a poor substitute for a local risk assessment.

For Nigerian public companies, the Nigerian Code of Corporate Governance and SEC guidance require an effective risk-based internal-audit function. SEC guidance identifies an initial non-compliance sanction of NGN500,000, followed by NGN5,000 for each continuing day, alongside other SEC sanctions. The entity reports compliance through SEC Form 01, so the audit file should support what the company reports rather than sit separately from it.

Begin with the risks that move money or create liability

We recommend starting with transaction flows, not a list of departments. Follow one purchase from request to payment. Follow one employee from recruitment to payroll. Follow one customer invoice through cash receipt and credit-note approval.

The most common gap is not a missing policy. It is an approval that exists on paper but does not match the system role, bank mandate or supplier-master authority used in practice.

Take a retailer with twelve staff and a US$40,000 monthly payroll. An audit team might find that one finance manager can add a staff member, amend bank details and approve the payroll file. The immediate control response is to split those rights and review payroll-change reports before payment. The US$40,000 figure does not prove loss, but it shows why a one-person control failure deserves earlier attention than a low-value stationery process.

If a subsidiary has low transaction volumes and no regulated activity, do not commission every specialist review in year one. Test the processes that can create material loss, regulatory exposure or unreliable reporting first. Add forensic procedures or deep IT testing when the risk assessment, an incident or the audit committee’s mandate supports them.

Build reporting that works for local directors and head office

Head office needs comparability. Local directors need findings that identify the person accountable, the local rule or control failure, and the deadline for action. One report can serve both audiences if the audit provider designs the reporting pack before fieldwork begins.

Use a reporting structure with three levels:

1.       A subsidiary report with detailed findings, evidence, management actions and dates.

2.       A local board or audit-committee report that highlights unresolved high-risk matters.

3.       A group dashboard that compares ratings, overdue actions and recurring themes across entities.

A dashboard should not flatten local facts into a single red, amber or green score. A payroll finding in Kenya may involve personal data sent abroad. A governance finding in South Africa may concern the audit committee’s statutory composition. The group report should retain those distinctions.

South Africa’s Companies Act framework requires public and state-owned companies to elect an audit committee with at least three qualifying directors. A subsidiary may use the parent’s audit committee where that committee performs the subsidiary’s statutory functions. This can support group oversight, but it does not remove the need to document local coverage, local findings and the committee’s actions.

Do not send working papers across borders without a data review

Internal audit files often contain staff records, customer files, supplier bank details and investigation notes. A group instruction to upload everything to a central platform can create a data-protection issue before the audit committee has read the first finding.

In Kenya, overseas transfers of personal data require adequate safeguards or consent under the framework administered by the Office of the Data Protection Commissioner. The ODPC registration portal asks organisations to identify the countries where data reside or are transferred. Before moving full working papers to head office, identify the data categories, destination country, safeguards and the minimum evidence that the group actually needs.

In Nigeria, the Nigeria Data Protection Act sets conditions for transfers of personal data to head office or another foreign recipient. Controllers and processors of major importance must register with the Nigeria Data Protection Commission, and annual compliance audit returns fall due by 31 March. An outsourced internal audit plan should therefore test whether data-transfer controls and annual compliance responsibilities match the subsidiary’s status.

Consider an illustrative Kenyan distributor with a regional head office outside Kenya. The internal audit team finds customer identification documents attached to credit applications and plans to upload the full files to a group portal. A better approach is to keep source documents in the approved local repository, report the exception in a controlled summary, and transfer only the evidence needed for escalation. The work takes more planning, but it reduces unnecessary movement of personal data and gives directors a clearer record of why the transfer occurred.

The step teams skip is agreeing the evidence protocol. Decide before fieldwork whether auditors will use read-only access, encrypted extracts, redacted samples or local review sessions. Retrofitting this decision after evidence has moved is difficult to defend.

What outsourced internal audit costs across African subsidiaries

No regulator sets an Africa-wide price for outsourced internal audit. We do not advise using a single regional day rate because the work differs materially by country, system access, travel requirements and governance obligations.

Ask for a country-by-country proposal in local currency. It should separate planning, fieldwork, travel, specialist testing, reporting and remediation follow-up. That format lets the group compare scope rather than select the lowest headline number.

The main cost drivers are clear:

●        Number of legal entities, operating sites and transaction volumes.

●        Regulated activities, local-language testing and travel between sites.

●        Access to accounting, payroll and enterprise systems.

●        Cross-border data-transfer controls and document-handling requirements.

●        Forensic work, where an allegation or exception requires expanded procedures.

●        Reporting cadence, including quarterly committee packs and follow-up testing.

A proposal based only on audit days often excludes the work that makes an engagement useful. Remediation tracking, management challenge meetings and local tax-control testing can determine whether findings close or return in the next cycle.

Take a group with a Nigerian public subsidiary and two smaller operating entities elsewhere in Africa. The Nigerian entity may need work aligned to SEC Form 01 and risk-based internal-audit expectations, while the smaller entities may need focused reviews of cash, procurement and payroll. Pricing all three entities as identical produces either unnecessary testing in one location or insufficient assurance in another. We would scope the Nigerian governance work separately, then set a proportionate plan for each smaller subsidiary.

The quote should state what does not form part of the work

Ask whether the fee includes site visits, data extraction, translation, system-access delays, fraud investigation support and re-testing of closed actions. Ask who pays when management cannot provide records on the agreed date.

Also ask whether the provider will report to management only. If the provider cannot present an independent report to the board or audit committee, the engagement may not give directors the assurance they need.

Governance decisions for boards and investors

Boards should approve the annual internal-audit plan after considering the subsidiary’s risk profile. Management can propose priorities and respond to findings, but it should not control what internal audit may test or suppress the final report.

For a new market entrant, begin with a first-year baseline review. Test entity governance, delegated authority, bank controls, supplier onboarding, payroll, tax compliance, systems access and data handling. Use the results to build the second-year plan around demonstrated weaknesses rather than assumptions made at market entry.

For a mature group, use recurring themes to make investment decisions. If several subsidiaries show weak supplier-master controls, fund a group control standard and test adoption locally. If the issue is country-specific, retain a local remedy and explain it in the group dashboard.

Requirements can change. As of 6 October 2026, the primary sources reviewed did not identify a change between 6 April 2025 and 6 October 2026 that specifically altered outsourced internal-audit requirements in the jurisdictions discussed. South Africa’s Companies Amendment Acts changes began on 27 December 2024. We recommend confirming the current legal position with local counsel or the relevant regulator before finalising an audit charter or compliance report.

Frequently Asked Questions

Is outsourced internal audit suitable for a small African subsidiary?

Yes, when the scope matches the risk. A smaller private entity may not need a full annual review of every process, but it still needs assurance over cash, payroll, approvals, tax records and access to systems. Focus the plan on processes that can cause loss or statutory exposure.

Can the group audit committee oversee a South African subsidiary?

A South African subsidiary may use its parent’s audit committee where the parent committee performs the statutory functions for the subsidiary. Public and state-owned companies must have an audit committee with at least three qualifying directors. Record the local coverage and decisions, because group oversight does not remove the need for evidence.

What should a Nigerian public company include in its internal audit plan?

SEC guidance requires a risk-based plan that identifies priority risks, assurance approach, skills and resources. The plan should also support the company’s SEC Form 01 compliance reporting and show how the internal-audit function addresses the Nigerian Code of Corporate Governance requirements.

Can audit working papers be sent to head office outside Kenya or Nigeria?

They can require additional safeguards. Kenya requires adequate safeguards or consent for overseas data transfers, while Nigeria’s data-protection law sets transfer conditions and may impose registration and annual compliance obligations on controllers or processors of major importance. Review the data flow before the audit team transfers source records.

A defined scope, local evidence rules and independent reporting turn outsourced internal audit from a periodic inspection into a governance tool. Speak With Our Team about your subsidiary portfolio through our internal audit and risk advisory Africa service.

Free consultation

Talk to a consultant

Tell us about your business and we'll get back to you within one working day.

No spam. We only use your details to respond to this inquiry.

Something went wrong. Please try again or contact us directly.

Thanks, we've got it.

A consultant will reach out within one working day.

Prefer to talk now? WhatsApp us · Contact page

Related Articles

A Guide to CIPC Annual Returns to Stay Compliant
Tax Compliance

A Guide to CIPC Annual Returns to Stay Compliant

Accessing Capital and Funding for African Businesses in Dubai
Tax Compliance

Accessing Capital and Funding for African Businesses in Dubai

AFRICA MINING ROYALTY RATES COMPARED FOR 2026 GUIDE
Tax Compliance

AFRICA MINING ROYALTY RATES COMPARED FOR 2026 GUIDE

M&J Consultants

M&J Africa empowers enterprises with strategic insights, innovative solutions, and transformative partnerships that transcend generations.

Sectors

  • Agriculture
  • Energy
  • Financial Services
  • Healthcare
  • Mining
  • Oil & Gas
  • Public Sector
  • Technology

Solutions

  • Business Advisory
  • Technology
  • Finance & Tax
  • Odoo ERP

Insights

  • Industry Insights
  • Technology Report
  • Webinars
  • Featured Topics

© 2026 M&J Consultants. All rights reserved.

  • Privacy Policy
  • Terms of Service
  • Cookie Policy