| Engagement snapshot | |
|---|---|
| Client archetype | Privately held, mid-market surface-mining company in Indonesia |
| Service lines | Internal audit co-sourcing · Process review |
| Jurisdiction | Indonesia (no cross-border element; no tax treaty engaged) |
| Engagement model | Co-sourced internal audit covering one financial year |
| Duration band | 1–3 months (fieldwork of several weeks) |
| Frameworks | COSO 2013 · IIA Global Internal Audit Standards · UU 4/2009 as last amended by UU 2/2025 · PP 96/2021 as amended · Kepmen ESDM 1827 K/30/MEM/2018 · UU 5/2011 |
| Team shape | Partner-led; associate partner as project lead; audit team |
What was the challenge?
The company could not test its own controls across every function. Management wanted an independent, risk-based view of control gaps before they turned into losses, filing failures or safety events. This operator had no group internal audit function to draw on.
| Challenge | Operational reality | Business risk |
|---|---|---|
| Untested functions | No internal audit capacity covering all functions | Gaps surface only after a loss or a filing failure |
| Invoice to payment | Invoice processing, payables, contracts and capital expenditure run through finance | A payment released without an approved invoice or contract |
| Stockpile and logistics | Inventory, stockpile procedures and outbound logistics are managed at site | Recorded quantities differ from physical quantities |
| IT security | Backups, access rights and licences sit in IT | Excess access or an unrecoverable backup halts operations and records |
| Compliance and safety | Compliance register, filings and safety training are maintained by operations and administration | A missed filing or untrained worker becomes a regulatory or safety event |
What does a co-sourced internal audit cover for a mining company in Indonesia?
It covers five domains, each reviewed for process-control effectiveness, compliance with internal policies, regulatory requirements and industry practice.
| Domain | Areas reviewed |
|---|---|
| Accounting and finance | Financial controls, tax compliance, receivables and payables, contracts, capital expenditure, SOPs |
| IT security | Data backups, access rights, cybersecurity, software licences, IT policies |
| Compliance and regulatory | Compliance register, regulatory filings, reporting, safety-training process |
| Mining operations | Logistics including outbound logistics, inventory management, site visits, asset maintenance, stockpile procedures |
| Invoicing | Invoice processing and payments |
The scope excluded legal opinions and advice outside these domains.
How did JCSS Indonesia approach it?
We ranked the processes by risk first, then tested high-risk areas in detail and sampled the rest.
Rank processes by risk. We mapped the five domains to processes and ranked them using COSO 2013 as the control framework. Artefact: risk-ranked process list that sets testing depth.
Walk through each process. We traced each process with its owner and compared practice to internal policies and SOPs. Artefact: process notes and a control matrix.
Test high-risk areas in detail. Stockpile and inventory, and invoice to payment, received detailed testing of controls against records and physical evidence. Artefact: test workpapers with exceptions.
Sample the remaining areas. Lower-risk areas were tested on a sample basis, with the sample drawn from the walkthrough results. Artefact: sampling schedule.
Visit the site. We observed asset maintenance, stockpile and logistics procedures where they operate. Artefact: site-visit observations tied to the workpapers.
Report by function. We planned, conducted and communicated the work in the sequence of Domain V of the IIA Global Internal Audit Standards. Artefact: one audit report with findings and recommendations by function.
Why this approach: uniform sampling spends the same effort on a low-risk SOP as on the stockpile or the payment run. A compliance checklist confirms that a document exists, not that the control operates. We rejected both. Testers stayed independent of control owners, and the report states findings to management, not an assurance conclusion: jasa asurans (assurance services) in Indonesia is reserved to Akuntan Publik (UU 5/2011, Pasal 3(2)).
What were the results?
JCSS Indonesia delivered one report that showed management where control gaps sit, function by function.
| Result | What was delivered | Why it matters |
|---|---|---|
| Function-by-function view | Findings and recommendations for finance, IT security, compliance, operations and invoicing | Each function head sees the gaps in their own area |
| Risk-led depth | High-risk areas tested in detail; other areas sampled | Management can sequence remediation by risk |
| One consolidated report | A single document across all five domains | Directors read one report, not five |
| Defined boundary | No legal opinions, no assurance, no advice outside scope | Readers know what the report does not cover |
Which frameworks and regulations applied?
Indonesian law governs the operations and the assurance boundary. No treaty is engaged.
- COSO Internal Control – Integrated Framework (2013): control framework for process-control assessment.
- IIA Global Internal Audit Standards: effective 09 Jan 2025; Domain V on performing internal audit services.
- UU 4/2009 on Pertambangan Mineral dan Batubara (mineral and coal mining), as last amended by UU 2/2025: sector law; reference for the compliance domain.
- PP 96/2021, as amended by PP 25/2024 and PP 39/2025: implementation of mining business activities; reference for the compliance domain.
- Kepmen ESDM 1827 K/30/MEM/2018, as partly revoked by Kepmen ESDM 111.K/MB.01/MEM.B/2024: guidelines on good mining engineering practice; reference for safety and operations.
- UU 27/2022 on Pelindungan Data Pribadi: personal data in access and backup records.
- UU 5/2011 on Akuntan Publik, Pasal 3(1)–(2): audit, review and other assurance services may be provided only by public accountants.
Key takeaways for CAEs and finance heads
- Rank processes by risk before testing; depth should follow risk, not calendar convenience.
- Test the stockpile and the payment run in detail; a control that exists on paper does not prove the quantity or the payment.
- Report once, by function; one consolidated report lets a board see every gap without reconciling five reviews.
Frequently asked questions
How long does a co-sourced internal audit take for a mining company in Indonesia?
Elapsed time depends on scope, the number of functions and the site visits needed; this engagement fell within a one-to-three-month band. Risk ranking and walkthroughs come first, then detailed and sample testing. A draft report precedes the final report, and the schedule is agreed with management in advance.
Does a co-sourced internal audit give statutory assurance under Indonesian law?
No. Under UU 5/2011, Pasal 3(1) and (2), jasa asurans (audit, review and other assurance services) may be provided only by an Akuntan Publik (public accountant). JCSS Indonesia delivers an internal audit report with findings and recommendations to management. It contains no audit opinion, no assurance conclusion under UU 5/2011 and no legal opinion.
Which standards guide a co-sourced internal audit?
The IIA Global Internal Audit Standards, effective 09 Jan 2025, set the professional practice for internal audit. Domain V covers planning engagements, conducting engagement work, agreeing recommendations with management, communicating results and monitoring action plans. COSO Internal Control – Integrated Framework (2013) supplies the control framework against which process controls are assessed.
What does an IT security review cover in a mining company internal audit?
It covers data backups, access rights, cybersecurity, software licences and IT policies. Access and backup records often hold employee personal data, so UU 27/2022 on Pelindungan Data Pribadi (personal data protection) also bears on how evidence is handled. Indonesian counsel confirms the legal position; the review gives no legal opinion.
What does the compliance domain test in a co-sourced mining audit?
It tests whether the compliance register is complete and maintained, whether regulatory filings and reporting are made as the register requires, and whether the safety-training process operates. Sector instruments such as UU 4/2009 as amended and PP 96/2021 as amended frame the obligations. The audit tests operation of the process, not the legal interpretation.
