
Internal Audit and the COSO Framework: Who Must Have One in Egypt
Does every company need internal audit or an audit committee? Not under general Egyptian law; sector rules require them, mainly for banks, finance firms, insurers and listed firms.
Executive summary
- COSO's Internal Control – Integrated Framework (2013 edition, still current) rests on five components and 17 principles.
- The Global Internal Audit Standards, issued by the Institute of Internal Auditors (IIA) on 9 January 2024, became effective on 9 January 2025, organised into five Domains and 15 guiding principles.
- Egyptian company law has no general rule requiring every company to have an internal audit function or an audit committee. The requirement comes from sector rules, chiefly four instruments, for banks, specified non-bank financial companies, insurers and listed companies; all four require an audit committee, and three also require an internal audit function reporting to it.
- Small and medium listed companies with issued and paid-in capital below EGP 100 million are exempt from having an audit committee.
- The insurance governance rules (FRA Decision 200/2025) have applied since 22 October 2025; the compliance period under them has been extended and now ends in January 2027.
The COSO framework: five components, 17 principles
COSO's Internal Control – Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission — 2013 edition, not since replaced — defines internal control as:
"A process, effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance."
The framework rests on five components containing 17 principles in total. An effective system of internal control requires each of the five components and the relevant principles to be present and functioning, and the five components to operate together in an integrated manner:
| Component | Principles | Examples |
|---|---|---|
| Control Environment | 5 | Commitment to integrity and ethical values; board independence from management and oversight of internal control |
| Risk Assessment | 4 | Clear objectives; risk analysed; potential for fraud considered |
| Control Activities | 3 | Activities that mitigate risk, deployed through policies and procedures |
| Information and Communication | 3 | Quality information; internal and external communication |
| Monitoring Activities | 2 | Ongoing or separate evaluations; deficiencies communicated to those who can act on them |
The Global Internal Audit Standards: scope and effective date
The IIA, in the glossary to its Global Internal Audit Standards, defines internal auditing as:
"An independent, objective assurance and advisory service designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of governance, risk management, and control processes."
The Standards were issued on 9 January 2024 and took effect on 9 January 2025. They are organised into five Domains — Purpose of Internal Auditing, Ethics and Professionalism, Governing the Internal Audit Function, Managing the Internal Audit Function, and Performing Internal Audit Services — and rest on 15 guiding principles supported by standards, each containing mandatory Requirements ("must") and Considerations for Implementation ("should" and "may").
They are international professional standards that, on their own terms, apply to any individual or function providing internal audit services; they are not Egyptian law. The Central Bank's instructions make the head of a bank's internal audit sector responsible for ensuring its work conforms with "prevailing internal audit standards" (clause 6-1-4).
When Egyptian law requires an internal audit function or an audit committee
Companies Law 159 of 1981 contains no general rule requiring a joint-stock company to have an internal audit function or an audit committee. The requirement comes from sector rules, chiefly these four instruments:
| Entity | Instrument | Audit committee | Internal audit function |
|---|---|---|---|
| Banks | Central Bank Law 194/2020 (Articles 117, 119) and the Central Bank's "Governance and Internal Control for Banks" instructions (19 September 2024) | Three non-executive board members; an outside expert may be added with the Governor's approval; meets at least every three months with both external auditors present (Article 119; clauses 3-2-1, 3-2-2, 3-2-4) | Independent sector reporting to the committee and submitting its reports directly to it; its head needs the Central Bank's approval (clauses 6-1-2, 6-1-6) |
| Securities, mortgage finance and refinance, microfinance, financial leasing, factoring and consumer finance companies | FRA Decision 100/2020 (Article 1), last amended by Decision 185/2024 (28 August 2024) | Odd-numbered, no fewer than 3 non-executive members, majority and chair independent (clause 2-2-1) | Internal audit department assessing internal control and reporting to the chairman and the committee (clause 5-3) |
| Insurance and reinsurance companies | FRA Decision 200/2025 (Al-Waqa'i' al-Misriyya, 21 October 2025) | Odd-numbered, no fewer than 3 non-executive and independent members, chaired by an independent member (Articles 23, 25) | Independent department with a full-time head reporting functionally to the committee (Article 38) |
| Companies with shares or Egyptian depositary receipts listed on EGX | Listing and Delisting Rules (FRA Decision 11/2014, August 2026 edition), Article 37 | Odd-numbered, no fewer than 3 non-executive members, majority and chair independent; small and medium companies with issued and paid-in capital below EGP 100 million exempt | Not required by the article; the committee reviews the internal audit function's mechanisms, plans and results |
The Central Bank's instructions state (in translation):
"The internal audit function must be fully independent of the activities it reviews (...) the Internal Audit Sector reports to the Audit Committee and submits its reports directly to it" (clause 6-1-2).
Insurers are in a transition. Decision 200/2025, issued under the Unified Insurance Law 155/2024 (Article 172), applies from the day after its publication, and its board and committee composition requirements apply from the company's next board election. For its other provisions, including the internal audit department, companies have one year from its effective date to comply (Article 2, and FRA Circular 3/2026); FRA Decision 173/2026 extended that period by three months, so it now ends in January 2027.
The audit committee requirement in these instruments is broader than the internal-audit-function one: it also covers listed companies. Other sector rules may impose similar requirements on particular entities, so the rules governing the entity's own activity decide. Outside these regimes, the Egyptian Corporate Governance Guide, whose issue the FRA Board approved by Decision 84/2016, deals with the internal audit department and its functional reporting to the audit committee, and by its own terms works on "comply or explain": a company applies its rules and explains, in its annual report, any it does not. As with the statutory external auditor, the first step is identifying the company's category, then its applicable instrument.
What this requires
- Identify which sector rules, if any, apply to the entity before designing any control structure.
- Where one of the four instruments applies: issue a written internal audit charter, approved by the board, setting out its independence and its reporting line to the audit committee.
- Benchmark the internal control system against COSO's components and principles before the audit committee or the external auditor asks for it.
- For banks: obtain the Central Bank's approval before appointing the head of internal audit, and notify it when that person leaves.
- For insurers: set up the internal audit department before the extended period ends in January 2027, and form the audit committee as the Decision requires at the next board election.
- Approve a risk-based annual internal audit plan and track its recommendations, as the Central Bank's instructions require of banks (clause 6-1-3), even where the entity is not bound to.
The firm's Audit & Assurance Department assesses an entity's internal control against COSO's components and principles, and designs the internal audit charter and reporting line to the audit committee that its sector's instrument requires.
Mahmoud Nassef — Chartered Accountant (Egyptian Register), Founder Partner
Member, Egyptian Society of Accountants & Auditors
Member, Egyptian Tax Society
Member, Egyptian Society for Public Finance and Taxation
Partner profile · Book a consultation
Disclaimer: This bulletin is prepared for general information on the legislation in force at the date of its publication. It does not constitute a professional opinion or tax or legal advice on any particular matter, and it should not be relied upon in place of advice based on an examination of the circumstances of each case. Nassef & Partners International accepts no responsibility for any action taken, or refrained from, in reliance on its contents. The positions stated remain subject to subsequent legislation and decisions.
