Internal Audit in Cyprus
Internal audit provides independent, objective assurance to the board of directors and senior management on the effectiveness of a Cyprus company's risk management, internal controls, and governance processes. Unlike statutory audit, it is typically discretionary for private companies but mandatory for public-interest entities, CySEC-regulated firms, and larger organisations pursuing best practice governance.
What is internal audit?
Internal audit is an independent, objective assurance and consulting activity designed to add value to an organisation. It helps evaluate and improve the effectiveness of governance, risk management, and internal control processes. In Cyprus, internal audit engagements are typically performed against the International Standards for the Professional Practice of Internal Auditing (IPPF) issued by the Institute of Internal Auditors (IIA).
Engagements can be operational, financial, compliance-focused, or IT-focused. Reports are typically issued to the audit committee or board, not to external parties.
When is internal audit mandatory?
Under Cyprus corporate governance requirements, certain entities are required to have an internal audit function: banks and credit institutions supervised by the Central Bank of Cyprus, insurance companies under Insurance Companies Law, Cyprus Investment Firms (CIFs) supervised by CySEC, publicly listed companies on the Cyprus Stock Exchange, and Alternative Investment Fund Managers (AIFMs) exceeding certain size thresholds.
Beyond regulated entities, many mid-market Cyprus companies engage internal audit selectively for specific risk areas — cybersecurity, procurement, supplier relationships, or compliance programmes.
Cyprus regulatory framework
CySEC-regulated CIFs must maintain an internal audit function proportionate to the nature, scale, and complexity of their business, as detailed in CySEC Circular C136 and related directives. Banks must comply with the Central Bank's Governance and Management Arrangements Directive. Public interest entities follow the corporate governance code recommendations.
The internal audit function must be independent of operational management, with direct reporting to the audit committee or board. It cannot report to a function it audits.
In-house vs outsourced internal audit
Cyprus regulators generally permit outsourcing of the internal audit function to a qualified external firm, provided the arrangement preserves independence and the board retains ultimate responsibility. For smaller regulated entities and mid-market companies, outsourced internal audit is often more cost-effective than building an in-house team.
Typical annual fees for outsourced internal audit range from €10,000 for smaller CIFs to €50,000+ for larger regulated firms with multiple risk domains to cover annually.
Global network members
18 firmsAdonis Theocharides
Certified Public Accountant
📍 Nicosia
Reanda InternationalAntranic Keremidjian
Certified Public Accountant
📍 Nicosia
Reanda InternationalAraik Markarian
Certified Public Accountant
📍 Nicosia
Reanda InternationalChristina Charalambous
Certified Public Accountant
📍 Nicosia
Kreston International LimitedKyriaki Theocharous
Certified Public Accountant
📍 Nicosia
BKR InternationalKyriakos Tramountanellis
Certified Public Accountant
📍 Nicosia
BKR InternationalLoucas H' Vasiliou
Certified Public Accountant
📍 Nicosia
BKR InternationalNareg Tavitian
Certified Public Accountant
📍 Nicosia
Reanda InternationalNicholas Michael
Certified Public Accountant
📍 Nicosia
Kreston International LimitedPhivos Theocharides
Certified Public Accountant
📍 Nicosia
Reanda InternationalProdromos Anastasiou
Certified Public Accountant
📍 Nicosia
Kreston International LimitedRaffi Boyadjian
Certified Public Accountant
📍 Nicosia
Nexia InternationalWhere these firms are located
7 areasFirms offering Internal Audit have offices in these areas. Click through to see all accountants in that area.
Frequently asked questions
Do all Cyprus companies need internal audit?
No. Internal audit is mandatory for regulated entities such as CIFs, banks, and insurance firms, and for listed companies. Private unregulated companies have no legal obligation, though many mid-market firms voluntarily commission internal audit reviews for governance or risk management purposes.
Can internal audit and statutory audit be provided by the same firm?
For most Cyprus private companies, yes. However, for public interest entities and CySEC-regulated firms, EU Audit Regulation restricts non-audit services by the statutory auditor, including internal audit in some cases. Firms should check the current rules with their auditor before engaging.
What qualifications should an internal auditor have?
The Certified Internal Auditor (CIA) qualification from the IIA is the international benchmark. Many Cyprus practitioners also hold ACCA, ACA, or ICPAC qualifications with specialisation in internal audit or risk. For IT audits, CISA (Certified Information Systems Auditor) is standard.
How often should internal audits be performed?
The Internal Audit Plan is typically approved annually by the audit committee based on a risk assessment. Higher-risk areas may be audited annually or more frequently; lower-risk areas on a 2-3 year cycle. Regulated entities must follow a documented plan proportionate to their risk profile.
What does an internal audit report look like?
A typical report describes the scope and objectives, methodology, findings ranked by risk severity, recommendations for improvement, and management responses. Reports are issued to the audit committee or board, with executive summaries for senior management. Follow-up on remediation is part of the ongoing audit cycle.