Appendix 6 – Internal Audit Charter
Approved by: Audit Committee
Effective Date: 13 April 2026
Review Frequency: Annually (or sooner if warranted)
Purpose
The purpose of the internal audit function is to strengthen PSAA’s ability to create, protect, and sustain value by providing the Audit Committee (AC) and management with independent, risk-based, and objective assurance, advice, insight, and foresight. The internal audit function enhances PSAA’s:
- Successful achievement of its objectives.
- Governance, risk management, and control processes.
- Decision-making and oversight.
- Reputation and credibility with its stakeholders.
- Ability to serve the public interest.
PSAA’s internal audit function is most effective when:
- Internal auditing is performed by competent professionals in conformance with the IIA’s Global Internal Audit Standards, which are set in the public interest.
- The internal audit function is independently positioned with accountability to the Audit Committee.
- Internal auditors are free from undue influence and committed to making objective assessments.
Commitment to Adhere to the Global Internal Audit Standards
The PSAA’s internal audit function will adhere to the mandatory elements of the Institute of Internal Auditors’ International Professional Practices Framework, which are the Global Internal Audit Standards and Topical Requirements. The Chief Audit Executive (CAE) will report to the AC and senior management regarding the internal audit function’s conformance with the Standards, which will be assessed through a quality assurance and improvement program.
Commitment to Adhere to Statutory, Sector and UK Corporate Governance requirements, standards and guidance
Internal Audit will comply with relevant statutory / sector guidance and where applicable, reference UK Corporate Governance expectations proportionate to PSAA’s size and complexity.
Authority
PSAA’s internal audit function is mandated within PSAA’s Corporate Governance framework.
The internal audit function’s authority is created by its direct reporting relationship to the AC. Such authority allows for unrestricted access to the AC.
The AC authorises the internal audit function to:
- Have full and unrestricted access to all functions, data, records, information, physical property, and personnel pertinent to carrying out internal audit responsibilities. Internal auditors are accountable for confidentiality and safeguarding records and information.
- Allocate resources, set frequencies, select subjects, determine scopes of work, apply techniques, and issue communications to accomplish the function’s objectives.
- Obtain assistance from the necessary personnel of PSAA and other specialised services from within or outside PSAA to complete internal audit services.
All employees are expected to cooperate with IA. Third parties/suppliers shall provide access where stipulated in contracts or via rights of audit provisions.
Independence, Organisational Position, and Reporting Relationships
The CAE will be positioned at a level in the organisation that enables internal audit services and responsibilities to be performed without interference from management, thereby establishing the independence of the internal audit function. The CAE will report functionally to the AC, administratively to the Head of Transformation Corporate Services (HoTCS) as the senior manager with overall responsibility for internal audit, and for vendor management to the Procurement Manager. This positioning provides the organisational authority and status to bring matters directly to senior management and escalate matters to the AC, when necessary, without interference and supports the internal auditors’ ability to maintain objectivity.
The CAE will confirm to the AC, annually, the organisational independence of the internal audit function. If the governance structure does not support organisational independence, the CAE will document the characteristics of the governance structure limiting independence and any safeguards employed to achieve the principle of independence. The CAE will disclose to the AC any interference internal auditors encounter related to the scope, performance, or communication of internal audit work and results. The disclosure will include communicating the implications of such interference on the internal audit function’s effectiveness and ability to fulfil its mandate.
Changes to the Mandate and Charter
Circumstances may justify a follow-up discussion between the CAE, AC and the HoTCS on the internal audit mandate or other aspects of the internal audit charter. Such circumstances may include but are not limited to:
- A significant change in the Global Internal Audit Standards.
- A significant reorganisation within the organisation.
- Significant changes in the CAE, Board, AC, and/or senior management.
- Significant changes to the organisation’s strategies, objectives, risk profile, or the environment in which the organisation operates.
- New laws or regulations that may affect the nature and/or scope of internal audit services.
Scope and Types of Internal Audit Services
The scope of internal audit services covers the entire breadth of the organisation, including all PSAA’s activities, assets, and personnel. The scope of internal audit activities also encompasses but is not limited to objective examinations of evidence to provide independent assurance and advisory services to the AC and management on the adequacy and effectiveness of governance, risk management, and control processes for PSAA.
Internal audit engagements may include evaluating whether:
- Risks relating to the achievement of PSAA’s strategic objectives are appropriately identified and managed.
- The actions of PSAA’s officers, directors, management, employees, and contractors or other relevant parties comply with PSAA’s policies, procedures, and applicable laws, regulations, and governance standards.
- The results of operations and programs are consistent with established goals and objectives.
- Operations and programs are being carried out effectively, efficiently, ethically, and equitably.
- Established processes and systems enable compliance with the policies, procedures, laws, and regulations that could significantly impact PSAA.
- The integrity of information and the means used to identify, measure, analyse, classify, and report such information is reliable.
- Resources and assets are acquired economically, used efficiently and sustainably, and protected adequately.
The scope includes, but is not limited to:
- Governance: roles, oversight, decision-making, policies, and culture.
- Risk Management: identification, assessment, mitigation, and reporting.
- Internal Control: design and operating effectiveness across financial, operational, compliance, IT, cyber/data protection (including UK GDPR and DUAA2025), and ESG controls proportionate to the business.
- Fraud & Financial Crime: adequacy of prevention, detection, and response frameworks
- Information Security & Data Protection: access controls, confidentiality, integrity, availability, and regulatory compliance.
- Projects & Change: key initiatives, system implementations, post‑implementation reviews.
- Third Parties: supplier risk, contract management, and right-to-audit clauses.
- LAO transitioning support
The nature and scope of advisory services may be agreed with the party requesting the service, provided the internal audit function does not assume management responsibility. Opportunities for improving the efficiency of governance, risk management, and control processes may be identified during advisory engagements. These opportunities will be communicated to the appropriate level of management. Advisory work (e.g., policy refresh, controls design input) may be undertaken where it does not impair independence and is pre-agreed with the AC.
AC Oversight
To establish, maintain, and ensure that PSAA’s internal audit function has sufficient authority to fulfil its duties, the AC will:
- Discuss with the CAE and senior management the appropriate authority, role, responsibilities, scope, and services (assurance and/or advisory) of the internal audit function.
- Ensure the CAE has unrestricted access to and communicates and interacts directly with the AC, including in private meetings without senior management present.
- Discuss with the CAE and senior management other topics that should be included in the internal audit charter.
- Participate in discussions with the CAE and senior management about the “essential conditions,” described in the Global Internal Audit Standards, which establish the foundation that enables an effective internal audit function.
- Approve the internal audit function’s charter, which includes the internal audit mandate and the scope and types of internal audit services.
- Review the internal audit charter annually or as considered required with the CAE to consider changes affecting the organisation, such as the employment of a new CAE or changes in the type, severity, and interdependencies of risks to the organisation; and approve the internal audit charter annually.
- Approve the risk-based internal audit plan.
- Provide input to the internal audit function’s human resources administration and budgets.
- Review the internal audit function’s expenses.
- Provide input to senior management on the appointment and removal of the CAE, ensuring adequate competencies and qualifications and conformance with the Global Internal Audit Standards.
- Review and provide input to senior management on the CAE’s performance.
- Receive communications from the CAE about the internal audit function including its performance relative to its plan.
- Ensure a quality assurance and improvement program has been established and review the results annually.
- Make appropriate inquiries of senior management and the CAE to determine whether scope or resource limitations are inappropriate.
CAE Role and Responsibilities
Ethics and Professionalism
The CAE will ensure that internal auditors:
- Conform with the Global Internal Audit Standards, including the principles of Ethics and Professionalism: integrity, objectivity, competency, due professional care, and confidentiality.
- Understand, respect, meet, and contribute to the legitimate and ethical expectations of the organisation and be able to recognise conduct that is contrary to those expectations.
- Encourage and promote an ethics-based culture in the organisation.
- Report organisational behaviour that is inconsistent with the organisation’s ethical expectations, as described in applicable policies and procedures.
Objectivity
The CAE will ensure that the internal audit function remains free from all conditions that threaten the ability of internal auditors to carry out their responsibilities in an unbiased manner, including matters of engagement selection, scope, procedures, frequency, timing, and communication. If the CAE determines that objectivity may be impaired in fact or appearance, the details of the impairment will be disclosed to appropriate parties.
Internal auditors will maintain an unbiased mental attitude that allows them to perform engagements objectively such that they believe in their work product, do not compromise quality, and do not subordinate their judgment on audit matters to others, either in fact or appearance.
Internal auditors will have no direct operational responsibility or authority over any of the activities they review. Accordingly, internal auditors will not implement internal controls, develop procedures, install systems, or engage in other activities that may impair their judgment, including:
- Assessing specific operations for which they had responsibility within the previous year.
- Performing operational duties for PSAA or its affiliates.
- Initiating or approving transactions external to the internal audit function.
- Directing the activities of any PSAA employee that is not employed by the internal audit function, except to the extent that such employees have been appropriately assigned to internal audit teams or to assist internal auditors.
Internal auditors will:
- Disclose impairments of independence or objectivity, in fact or appearance, to appropriate parties and at least annually, such as the CAE, AC, Chief Finance Officer, management, or others.
- Exhibit professional objectivity in gathering, evaluating, and communicating information.
- Make balanced assessments of all available and relevant facts and circumstances.
- Take necessary precautions to avoid conflicts of interest, bias, and undue influence.
Quality Assurance and Improvement Programme
The CAE will develop, implement, and maintain a quality assurance and improvement program that covers all aspects of the internal audit function. The program will include external and internal assessments of the internal audit function’s conformance with the Global Internal Audit Standards, as well as performance measurement to assess the internal audit function’s progress toward the achievement of its objectives and promotion of continuous improvement. The program also will assess, if applicable, compliance with laws and/or regulations relevant to internal auditing. Also, if applicable, the assessment will include plans to address the internal audit function’s deficiencies and opportunities for improvement.
Annually, the CAE will communicate with the AC and senior management about the internal audit function’s quality assurance and improvement program, including the results of internal assessments (ongoing monitoring and periodic self-assessments) and external assessments. External assessments will be conducted at least once every five years by a qualified, independent assessor or assessment team from outside PSAA; qualifications must include at least one assessor holding an active Certified Internal Auditor® credential.
Managing the Internal Audit Function
The CAE has the responsibility to:
- Develop a risk‑based Internal Audit Plan (IAP) annually, that considers the input of the Board / AC and senior management informed by the corporate risk register and prior audits. Discuss the plan with the AC and senior management and submit the plan to the AC for review and approval.
- Communicate the impact of resource limitations on the internal audit plan to the AC and senior management.
- Review and adjust the internal audit plan, as necessary, in response to changes in PSAA’s business, risks, operations, programs, systems, and controls.
- Communicate with the AC and senior management if there are significant interim changes to the internal audit plan.
- Ensure internal audit engagements are performed, documented, and communicated in accordance with the Global Internal Audit Standards and laws and/or regulations, reporting clear, concise findings with risk ratings, root causes, and practical recommendations.
- Follow up on engagement findings and confirm the implementation of recommendations or action plans, tracking remediation to closure and reporting overdue actions.
- communicate the results of internal audit services to the AC and senior management (at least quarterly) on plan delivery, key findings, themes, and emerging risks and for each engagement as appropriate.
- Ensure the internal audit function collectively possesses or obtains the knowledge, skills, and other competencies and qualifications needed to meet the requirements of the Global Internal Audit Standards and fulfil the internal audit mandate.
- Identify and consider trends and emerging issues that could impact PSAA and communicate to the AC and senior management as appropriate.
- Consider emerging trends and successful practices in internal auditing.
- Establish and ensure adherence to methodologies designed to guide the internal audit function.
- Ensure adherence to PSAA’s relevant policies and procedures unless such policies and procedures conflict with the internal audit charter or the Global Internal Audit Standards. Any such conflicts will be resolved or documented and communicated to the AC and senior management.
- Coordinate activities and consider relying upon the work of other internal and external providers of assurance and advisory services. If the CAE cannot achieve an appropriate level of coordination, the issue must be communicated to senior management and if necessary escalated to the AC.
- Coordinate with External Audit to minimise duplication and share insights where appropriate.
- Escalate significant control weaknesses, suspected fraud, or legal/regulatory non‑compliance promptly to the Head of Transformation, Corporate Services in the first instance, and subsequently to the AC Chair and CE.
Communication with the AC and Senior Management
The CAE will report annually to the AC and senior management regarding:
- The internal audit function’s mandate.
- The internal audit plan and performance relative to its plan.
- Internal audit budget.
- Significant revisions to the internal audit plan and budget.
- Potential impairments to independence, including relevant disclosures as applicable.
- Results from the quality assurance and improvement program, which include the internal audit function’s conformance with The IIA’s Global Internal Audit Standards and action plans to address the internal audit function’s deficiencies and opportunities for improvement.
- Significant risk exposures and control issues, including fraud risks, governance issues, and other areas of focus for the AC that could interfere with the achievement of PSAA’s strategic objectives.
- Results of assurance and advisory services.
- Resource requirements.
- Management’s responses to risk that the internal audit function determines may be unacceptable or acceptance of a risk that is beyond PSAA’s risk appetite.
Planning and Engagement Protocols
- Annual Plan: Drafted by IA following consultations with AC and senior management and approved by the AC. Includes resource hours, audit universe, risk rationale, and contingency.
- Engagement Terms: Each audit will have a brief Terms of Reference (ToR) confirming objectives, scope, timing, and key contacts.
- Fieldwork: Evidence-based testing with proportionate samples; maintain working papers.
- Closing Meeting: Discuss findings and agree actions/owners/dates.
- Reporting: In line with the timelines set out within the contract.
- Rating Scale: Excellent, Substantial, Adequate, Limited, Poor which inform RAG rated risk ratings High/Medium/Low.
- Stakeholder feedback surveys: used after each engagement to feed continuous improvement.
Third Party/Internal Audit Service Provider Arrangements
Because IA is outsourced to KOSI Corporation Ltd (KOSI):
- Contract & SLAs: Defined KPIs/SLAs govern timeliness, quality, and stakeholder satisfaction.
- Right to Substitute/Named Team: The provider will supply suitably qualified staff (CMIIA/IIA/CCAB/CISA as appropriate) and notify material team changes.
- Independence Safeguards: The provider will disclose conflicts and not provide services that impair IA independence without AC approval.
- Security: Provider adheres to PSAA’s security requirements, including confidentiality, secure file transfer, and data minimisation.
- Right to Audit Provider: PSAA reserves the right to audit the provider’s delivery relating to this engagement.
Coordination with External Assurance
IA will coordinate with:
- External Audit to align on key risks and avoid duplication.
- Regulators/Assurance providers (e.g., cyber specialists, Payment Card Industry (PCI), ISO auditors) to leverage assurance where appropriate and use reliance judiciously.
- LGA Internal Auditors to share assurances over services provided under the SLA.
Resourcing and Budget
- The AC approves the annual IA budget and plan hours.
- Any material out-of-scope or unplanned work requires AC Chair preapproval (or between‑meeting‑approval via the Chair and reported at next AC).
- The provider will ensure competence consistent with the Standards and the complexity of the audit universe.
Performance Management
- IA performance will be monitored using periodic stakeholder feedback.
- Delivery against the plan, implementation of agreed actions, and value add‑insights will be reported to the AC.
Charter Review and Approval
This Charter will be reviewed annually by the CAE, the AC and senior management, and be presented to the AC for approval. Interim updates may be required if organisational or regulatory changes occur.
Sign off
- Audit Committee Chair: Alan Edwards, 13 April 2026
- Head of Transformation, Corporate Services: Chris Reilly, 13 April 2026
- Chief Audit Executive (KOSI Corporation Ltd): Sinead Spencer, 13 April 2026