Overview
A compliance audit is traditionally defined as a review process designed to verify that a business unit is adhering to the appropriate organizational or regulatory policies and procedures. The internal auditing department generally performs a compliance audit as part of its routine audit program since this type of review will assist management in determining which business units are following the corporate mission. An environmental compliance audit is defined as:
A systematic process to verify that an organisation is following all applicable federal, state, and local environmental codes.
The scope of a compliance audit should include all operations that are subject to environmental regulations. Operations should be prioritized for review depending on the risk of noncompliance in a manner that is similar to non-environmental audits that are planned and presented to the audit committee.
Compliance audits can be designed to rely upon the existing financial and operational expertise of the internal auditing department. They can also be designed to include a very detailed technical review which may require the assistance of corporate engineers, scientists, or an outside consultant during the execution of the audit. More importantly, according to the Global Environment Management Initiative (GEMI), organization compliance is defined as meeting the minimum level for satisfying a set of environmental codes and regulations. In other words, GEMI defines compliance as the minimum level at which management can support specific environmental initiatives. It is essential that internal auditors determine their organization's Environmental Management System (EMS) mission and general philosophy regarding compliance. The organization's compliance philosophy should help direct the internal auditing department in determining its overall role in the EMS process and the related level of participation in the compliance environmental audit.
Objectives
The compliance audit has the following two objectives:
- Determine that the business unit (auditee) is in compliance with federal, state, and local laws that are applicable to the organization.
- Ascertain that the business unit is in compliance with the appropriate organisational policies and procedures which promote environmental protection and safety.