Internal Audit: FY2025/26 focus areas and value delivered
Strategic risk management – real estate, investments, third-party relationships
ARC emphasis: cyber, real estate, litigation, third-party risk.
Cybersecurity and information technology governance
Strengthened the protection of member data and critical systems, reducing risk and enhancing stakeholder trust. Improved operational resilience and enabled secure, reliable digital services that support long-term value creation.
Employer compliance and contribution recovery
Employer compliance improved to 56% on a one-month basis (FY2024/25: 52%). The Employer Amnesty Campaign returned 11,427 businesses to compliance and recovered UGX 89 billion against a UGX 30 billion target.
Financial reporting integrity and going-concern assessment
ARC reviewed draft AFS, management letter and external audit conclusions. Going-concern status confirmed throughout the year.
Internal Audit QAIP – conformance with IIA standards
External quality assessment (FY2024/25) confirmed general conformance with IIA Global Internal Audit Standards. Next assessment: FY2027/28.
Ethics and whistleblowing monitoring
No material ethics breaches reported. Whistleblowing platform (SIGNUM Advocates) operational. Internal Audit reviewed ethics compliance quarterly.