We conducted 31 interviews with audit committee (AC) members, chief executive officers (CEOs), and chief audit executives (CAEs) to investigate the role of the internal audit function (IAF) in environmental, social, and governance (ESG) processes and related risks. We find that multiple possible combinations of the maturity of companies' ESG practices and CAE's perception of the IAF stakeholders' salience drive the type of IAF's involvement in ESG. In ESG-mature companies with more salient ACs, the IAF provides assurance over ESG practices, ESG reporting, and reputation risks related to ESG, and it focuses on the governance dimension of ESG. When the CEO is perceived as more salient, the type of IAF's involvement includes both assurance over ESG controls in the supply chain and consulting on ESG activities. In contrast, in low ESG maturity companies with more salient AC, the IAF's role is limited to providing assurance over internal controls established to comply with environmental, health, and safety legal requirements, and prevent managers' unethical behavior. Finally, we discuss the implications for the IAF's ability to add value to the organization. We contribute to the underexplored research area of IAF's involvement in ESG practices and related risk.

The involvement of internal audit in environmental, social, and governance practices and risks: Stakeholders' salience and insights from audit committees and chief executive officers

Romina Rakipi;Giuseppe D'Onza
2024-01-01

Abstract

We conducted 31 interviews with audit committee (AC) members, chief executive officers (CEOs), and chief audit executives (CAEs) to investigate the role of the internal audit function (IAF) in environmental, social, and governance (ESG) processes and related risks. We find that multiple possible combinations of the maturity of companies' ESG practices and CAE's perception of the IAF stakeholders' salience drive the type of IAF's involvement in ESG. In ESG-mature companies with more salient ACs, the IAF provides assurance over ESG practices, ESG reporting, and reputation risks related to ESG, and it focuses on the governance dimension of ESG. When the CEO is perceived as more salient, the type of IAF's involvement includes both assurance over ESG controls in the supply chain and consulting on ESG activities. In contrast, in low ESG maturity companies with more salient AC, the IAF's role is limited to providing assurance over internal controls established to comply with environmental, health, and safety legal requirements, and prevent managers' unethical behavior. Finally, we discuss the implications for the IAF's ability to add value to the organization. We contribute to the underexplored research area of IAF's involvement in ESG practices and related risk.
2024
Rakipi, Romina; D'Onza, Giuseppe
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11568/1290169
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 8
  • ???jsp.display-item.citation.isi??? 6
social impact