• Mining
  • Internal Audit (Co-sourcing)
  • Indonesia
  • COSO / IIA Standards

Co-Sourced Internal Audit for an Indonesian Surface-Mining Company

A privately held, mid-market surface-mining company in Indonesia had no internal audit capacity covering all its functions. JCSS Indonesia co-sourced a risk-based process review across finance, IT security, compliance, mining operations and invoicing, using COSO 2013 and the IIA Global Internal Audit Standards. Management received one report with findings and recommendations for each function.

Engagement snapshot
Client archetypePrivately held, mid-market surface-mining company in Indonesia
Service linesInternal audit co-sourcing · Process review
JurisdictionIndonesia (no cross-border element; no tax treaty engaged)
Engagement modelCo-sourced internal audit covering one financial year
Duration band1–3 months (fieldwork of several weeks)
FrameworksCOSO 2013 · IIA Global Internal Audit Standards · UU 4/2009 as last amended by UU 2/2025 · PP 96/2021 as amended · Kepmen ESDM 1827 K/30/MEM/2018 · UU 5/2011
Team shapePartner-led; associate partner as project lead; audit team

What was the challenge?

The company could not test its own controls across every function. Management wanted an independent, risk-based view of control gaps before they turned into losses, filing failures or safety events. This operator had no group internal audit function to draw on.

ChallengeOperational realityBusiness risk
Untested functionsNo internal audit capacity covering all functionsGaps surface only after a loss or a filing failure
Invoice to paymentInvoice processing, payables, contracts and capital expenditure run through financeA payment released without an approved invoice or contract
Stockpile and logisticsInventory, stockpile procedures and outbound logistics are managed at siteRecorded quantities differ from physical quantities
IT securityBackups, access rights and licences sit in ITExcess access or an unrecoverable backup halts operations and records
Compliance and safetyCompliance register, filings and safety training are maintained by operations and administrationA missed filing or untrained worker becomes a regulatory or safety event

What does a co-sourced internal audit cover for a mining company in Indonesia?

It covers five domains, each reviewed for process-control effectiveness, compliance with internal policies, regulatory requirements and industry practice.

DomainAreas reviewed
Accounting and financeFinancial controls, tax compliance, receivables and payables, contracts, capital expenditure, SOPs
IT securityData backups, access rights, cybersecurity, software licences, IT policies
Compliance and regulatoryCompliance register, regulatory filings, reporting, safety-training process
Mining operationsLogistics including outbound logistics, inventory management, site visits, asset maintenance, stockpile procedures
InvoicingInvoice processing and payments

The scope excluded legal opinions and advice outside these domains.

How did JCSS Indonesia approach it?

We ranked the processes by risk first, then tested high-risk areas in detail and sampled the rest.

  1. Rank processes by risk. We mapped the five domains to processes and ranked them using COSO 2013 as the control framework. Artefact: risk-ranked process list that sets testing depth.

  2. Walk through each process. We traced each process with its owner and compared practice to internal policies and SOPs. Artefact: process notes and a control matrix.

  3. Test high-risk areas in detail. Stockpile and inventory, and invoice to payment, received detailed testing of controls against records and physical evidence. Artefact: test workpapers with exceptions.

  4. Sample the remaining areas. Lower-risk areas were tested on a sample basis, with the sample drawn from the walkthrough results. Artefact: sampling schedule.

  5. Visit the site. We observed asset maintenance, stockpile and logistics procedures where they operate. Artefact: site-visit observations tied to the workpapers.

  6. Report by function. We planned, conducted and communicated the work in the sequence of Domain V of the IIA Global Internal Audit Standards. Artefact: one audit report with findings and recommendations by function.

Why this approach: uniform sampling spends the same effort on a low-risk SOP as on the stockpile or the payment run. A compliance checklist confirms that a document exists, not that the control operates. We rejected both. Testers stayed independent of control owners, and the report states findings to management, not an assurance conclusion: jasa asurans (assurance services) in Indonesia is reserved to Akuntan Publik (UU 5/2011, Pasal 3(2)).

What were the results?

JCSS Indonesia delivered one report that showed management where control gaps sit, function by function.

ResultWhat was deliveredWhy it matters
Function-by-function viewFindings and recommendations for finance, IT security, compliance, operations and invoicingEach function head sees the gaps in their own area
Risk-led depthHigh-risk areas tested in detail; other areas sampledManagement can sequence remediation by risk
One consolidated reportA single document across all five domainsDirectors read one report, not five
Defined boundaryNo legal opinions, no assurance, no advice outside scopeReaders know what the report does not cover

Which frameworks and regulations applied?

Indonesian law governs the operations and the assurance boundary. No treaty is engaged.

Key takeaways for CAEs and finance heads

  • Rank processes by risk before testing; depth should follow risk, not calendar convenience.
  • Test the stockpile and the payment run in detail; a control that exists on paper does not prove the quantity or the payment.
  • Report once, by function; one consolidated report lets a board see every gap without reconciling five reviews.

Frequently asked questions

How long does a co-sourced internal audit take for a mining company in Indonesia?

Elapsed time depends on scope, the number of functions and the site visits needed; this engagement fell within a one-to-three-month band. Risk ranking and walkthroughs come first, then detailed and sample testing. A draft report precedes the final report, and the schedule is agreed with management in advance.

Does a co-sourced internal audit give statutory assurance under Indonesian law?

No. Under UU 5/2011, Pasal 3(1) and (2), jasa asurans (audit, review and other assurance services) may be provided only by an Akuntan Publik (public accountant). JCSS Indonesia delivers an internal audit report with findings and recommendations to management. It contains no audit opinion, no assurance conclusion under UU 5/2011 and no legal opinion.

Which standards guide a co-sourced internal audit?

The IIA Global Internal Audit Standards, effective 09 Jan 2025, set the professional practice for internal audit. Domain V covers planning engagements, conducting engagement work, agreeing recommendations with management, communicating results and monitoring action plans. COSO Internal Control – Integrated Framework (2013) supplies the control framework against which process controls are assessed.

What does an IT security review cover in a mining company internal audit?

It covers data backups, access rights, cybersecurity, software licences and IT policies. Access and backup records often hold employee personal data, so UU 27/2022 on Pelindungan Data Pribadi (personal data protection) also bears on how evidence is handled. Indonesian counsel confirms the legal position; the review gives no legal opinion.

What does the compliance domain test in a co-sourced mining audit?

It tests whether the compliance register is complete and maintained, whether regulatory filings and reporting are made as the register requires, and whether the safety-training process operates. Sector instruments such as UU 4/2009 as amended and PP 96/2021 as amended frame the obligations. The audit tests operation of the process, not the legal interpretation.

How this case study was prepared: anonymised and based on the engagement record; regulations as in force at 03 Oct 2026; not legal or tax advice.

Client details are anonymised and the engagement is described with client confidentiality preserved. Last reviewed: 03 Oct 2026. Reviewed by: Managing Partner.