RequirementIPPF Standard 2320 – Analysis and Evaluation, requires that “internal auditors must base conclusions and engagement results on appropriate analyses and evaluations”.
In delivering add value for improving the effectiveness and efficiency of business process, internal auditor should provide recommendations that fix the underlying reason that caused an issue. Thus, internal auditor is required to have a core competency necessary to facilitate, review, and/or conduct a root cause(s) analysis.
DefinitionRoot cause analysis = the identification of why an issue occurred (versus only identifying or reporting on the issue itself). In this context, an issue is defined as a problem, error, instance of noncompliance, or missed opportunity.
|Process of audit finding development|
In Indonesia cases, procurement fraud and tax fraud cases are still re-occurred, even though many corruptors have been sent to jail. It simply because Indonesia government does not remedy the root cause. The government only focus on the issue, and on detective and corrective control, and not on its root causes and on preventive control. The required remediation activities are become more complicated since there are multiple related or unrelated causes of the issue, such as lack of law enforcement, weak design of regulation/control/ governance, high unemployment, low quality of human resources, missallocation of government budget, and low remuneration.
Symptom v.s. Issue/ProblemOften, the nonconformity recorded/reported is not the true problem, but it is a symptom of the problem. Moreover, as auditors, we often make mistakes by providing a recommendation to fix the symptom, not the problem. For example, when we found an overpayment, auditor just recommended the management to give a punishment to the person in charge and to return back the overpayment. This recommendation will not prevent the same issue will not reoccur, in fact, the issue definitely will re-occur sometime in the future, if we do not fix its root cause.
Here is some rules to identify a problem.
- The problem must be expressed as an issue with the system.
- If the problem is expressed in terms of a person or incident, it is at the symptom stage. Example of poor finding, which focus on person/ accident: There is a shortage in “cash on bank”.
- It is important to get to the true problem, i.e. the system issue, or the problem-solving efforts will not be effective.
- Fixing symptoms will not stop the issue from recurring.
- A well-written nonconformity should stand the test of time. Your organization should be able to look back at nonconformity written years ago and understand exactly what the problem was.
A good root cause analysis answers this question:
- “What in the system failed such that the problem occurred?” Example better finding, which focus on the system: the procedure of a periodic bank reconciliation has not been performed.
- The focus is on the system, not the incident.
- Some problems may have multiple root causes. The root cause is: there is no procedure for monitoring the implementation of bank reconciliation.
- Some problems may have several possible root causes.
- If the root cause cannot be discovered, all require corrective action.
Root cause = a light switch
- If the root cause has been found, the problem can be “turned on” and “turned off.”
- Like a light switch. If the root cause (the switch) is turn on, than the problem would be arise (turning on), but if the root cause (the switch) is turn off, than the problem would be suppressed (turning off).
- If the problem cannot be turned on and off at will, then the root cause has probably not been found.
- The worker fell. Why? Because of oil on the floor. Why? Because of a broken part. Why? Because the part keeps failing. Why? Because of changes in procurement practices
- By the fifth “why,” the internal auditor should have identified or be close to identifying the root cause.
Examples of a few such tools, include:a. “Five whys.”
|Five whys example|
|Failure mode and effects analysis|
|Critical to quality metrics example|
|Pareto chart example|
|Statistical correlation example|