Policy 37 — Internal Audit and Oversight

PHIG checks that its controls work in practice, not only on paper, through a yearly risk-based internal review reported to the Board. Owner: Board Audit and Risk lead, with Ethics and Compliance (Irakli Pshinashvili).

PHIG Institutional Policy Manual · Consolidated edition, September 2026

Part of the PHIG policy framework. Download the full manual (PDF). To raise a concern: admin@accreditation.ge.

PHIG checks that its controls work in practice, not only on paper, through a yearly risk-based internal review reported to the Board. Owner: Board Audit and Risk lead, with Ethics and Compliance (Irakli Pshinashvili).

  • Annual internal review plan: approved by the Board, covering the highest risks in the register (Policy 34) — for example procurement, payroll, sub-awards and safeguarding.
  • Independence: reviews are done by someone not responsible for the area reviewed; for larger grants, PHIG may engage an external reviewer.
  • Scope: sample testing of transactions, procurement files, timesheets, asset checks and partner files against this manual and donor rules.
  • Findings: rated high, medium or low, with an agreed action, owner and deadline; high findings are reported to the Board within 30 days.
  • Follow-up: the Ethics and Compliance Officer tracks every action to closure and reports progress to each Board meeting.
  • External audit: the annual statutory audit and any donor project audits follow Policy 22; auditors’ management letters are answered in writing within 60 days.