Internal Audit in Cyprus

Internal audit provides independent, objective assurance to the board of directors and senior management on the effectiveness of a Cyprus company's risk management, internal controls, and governance processes. Unlike statutory audit, it is typically discretionary for private companies but mandatory for public-interest entities, CySEC-regulated firms, and larger organisations pursuing best practice governance.

56 firms offering this
18 featured or network members
7 areas covered

What is internal audit?

Internal audit is an independent, objective assurance and consulting activity designed to add value to an organisation. It helps evaluate and improve the effectiveness of governance, risk management, and internal control processes. In Cyprus, internal audit engagements are typically performed against the International Standards for the Professional Practice of Internal Auditing (IPPF) issued by the Institute of Internal Auditors (IIA).

Engagements can be operational, financial, compliance-focused, or IT-focused. Reports are typically issued to the audit committee or board, not to external parties.

When is internal audit mandatory?

Under Cyprus corporate governance requirements, certain entities are required to have an internal audit function: banks and credit institutions supervised by the Central Bank of Cyprus, insurance companies under Insurance Companies Law, Cyprus Investment Firms (CIFs) supervised by CySEC, publicly listed companies on the Cyprus Stock Exchange, and Alternative Investment Fund Managers (AIFMs) exceeding certain size thresholds.

Beyond regulated entities, many mid-market Cyprus companies engage internal audit selectively for specific risk areas — cybersecurity, procurement, supplier relationships, or compliance programmes.

Cyprus regulatory framework

CySEC-regulated CIFs must maintain an internal audit function proportionate to the nature, scale, and complexity of their business, as detailed in CySEC Circular C136 and related directives. Banks must comply with the Central Bank's Governance and Management Arrangements Directive. Public interest entities follow the corporate governance code recommendations.

The internal audit function must be independent of operational management, with direct reporting to the audit committee or board. It cannot report to a function it audits.

In-house vs outsourced internal audit

Cyprus regulators generally permit outsourcing of the internal audit function to a qualified external firm, provided the arrangement preserves independence and the board retains ultimate responsibility. For smaller regulated entities and mid-market companies, outsourced internal audit is often more cost-effective than building an in-house team.

Typical annual fees for outsourced internal audit range from €10,000 for smaller CIFs to €50,000+ for larger regulated firms with multiple risk domains to cover annually.

Global network members

18 firms

Where these firms are located

7 areas

Firms offering Internal Audit have offices in these areas. Click through to see all accountants in that area.

Frequently asked questions

Do all Cyprus companies need internal audit?

No. Internal audit is mandatory for regulated entities such as CIFs, banks, and insurance firms, and for listed companies. Private unregulated companies have no legal obligation, though many mid-market firms voluntarily commission internal audit reviews for governance or risk management purposes.

Can internal audit and statutory audit be provided by the same firm?

For most Cyprus private companies, yes. However, for public interest entities and CySEC-regulated firms, EU Audit Regulation restricts non-audit services by the statutory auditor, including internal audit in some cases. Firms should check the current rules with their auditor before engaging.

What qualifications should an internal auditor have?

The Certified Internal Auditor (CIA) qualification from the IIA is the international benchmark. Many Cyprus practitioners also hold ACCA, ACA, or ICPAC qualifications with specialisation in internal audit or risk. For IT audits, CISA (Certified Information Systems Auditor) is standard.

How often should internal audits be performed?

The Internal Audit Plan is typically approved annually by the audit committee based on a risk assessment. Higher-risk areas may be audited annually or more frequently; lower-risk areas on a 2-3 year cycle. Regulated entities must follow a documented plan proportionate to their risk profile.

What does an internal audit report look like?

A typical report describes the scope and objectives, methodology, findings ranked by risk severity, recommendations for improvement, and management responses. Reports are issued to the audit committee or board, with executive summaries for senior management. Follow-up on remediation is part of the ongoing audit cycle.

Related services