Internal controls and assurance: closing the loop
Every section of this chapter has described what the Board, its committees and its executives do. This section describes how the Fund knows it is working – the assurance architecture that tests governance against its own claims.
Internal Audit, established in 1985, continues its evolution into a risk-based, technology-enabled strategic adviser under the Internal Audit Strategy 2025–2030. The combined assurance model – Enterprise Risk Management, Legal and Internal Audit operating as three lines of defence – remains in force for FY2025/26.
Three lines of defence
First line
Second line
Third line
Management controls: Business units; EXCO; Operational management. Day-to-day risk ownership and control implementation.
Oversight functions: Enterprise Risk Management; Legal and Board Affairs; Compliance. Risk frameworks, policies, monitoring, and reporting.
Independent assurance: Internal Audit (reports to ARC); External Audit (KPMG / OAG); independent legal advisers (selected engagements).