INTERNAL CONTROLS AND ASSURANCE
Scope of assurance across the Fund
Internal Audit's mandate spans the entire audit universe, demonstrating a broad enterprise-wide assurance footprint rather than a narrow compliance function.
Commercial
Enterprise Risk Management
Procurement & Disposal
People & Culture
Finance
Legal & Board Affairs
Investments
Technology & Enterprise Solutions
Marketing & Corporate Affairs
Enterprise & Growth
We believe in US
The strength of Internal Audit begins with its people. During FY2026, the function invested in specialised artificial intelligence training, benchmarking visits, auditor project rotation programmes, and continuous professional development. These initiatives are expanding technical expertise, strengthening future readiness, and ensuring Internal Audit remains capable of providing assurance over emerging risks and rapidly evolving technologies.
“We want assurance to be as close as possible to real time, enabling us to respond to risk as it emerges rather than looking only at past transactions.”
Strategic Outcome
A strategically aligned, technology-enabled and trusted Internal Audit function that strengthens governance, enhances resilience, and supports sustainable value creation.
GOVERNANCE ALIGNMENT · V, PRINCIPLE 12
Aligning assurance with governance: Our evolving King V in practice
Alignment with King V
| Governance outcome | Internal Audit contribution |
|---|---|
| Ethical culture | Promotes integrity, accountability, and transparency |
| Performance and value creation | Provides assurance over strategic execution, transformation, and strategic investments |
| Conformance and prudent control | Assesses governance, risk management, and controls |
| Legitimacy and stakeholder confidence | Supports credible reporting, combined assurance, and stakeholder trust |
Principle 12 in practice
King V, released 31 October 2025, sharpens the expectations placed on governing bodies to ensure that assurance functions and the combined assurance model deliver an effective control environment, and that they support the integrity of information used for internal decision-making and external reporting – the essence of Principle 12.
| Principle 12 expectation | NSSF Internal Audit response |
|---|---|
| Independent and objective assurance | Internal Audit reports functionally to the Board (through the Audit and Risk Assurance Committee) and administratively to the Managing Director. Internal Auditors have unrestricted access to information and annual confirmation of independence. Internal Audit works closely with the External auditors who are appointed by Auditor General. |
| Effective combined assurance | Coordination with Enterprise Risk Management, Legal and other assurance providers, supported by development of a formal combined assurance framework. |
| Assurance aligned to emerging risks | Increased focus on technology, cybersecurity, AI, ESG and strategic transformation programmes. |
| Continuous improvement | Ongoing three-tier quality assurance programme – engagement-level and activity-level self-assessment plus independent external assessment (EY, FY2024/25; next assessment planned for FY2027/28). |
| Integrity of reporting | ESG assurance and contribution to the Fund's integrated reporting process. |