
A finance director hears “audit” and often pictures one thing: an external firm arriving in January to sign off the year-end statements. That is only half the picture. Many Saudi businesses run an internal audit function too, and the two are not interchangeable, even though vendors sometimes market them as if they were.
Confusing the two leads to real problems. A company that treats its internal audit as a substitute for a statutory external audit can find itself non-compliant with the Companies Law. One that skips internal audit entirely can miss control weaknesses that surface, expensively, during the external audit instead.
This guide sets out exactly what separates external audit from internal audit in Saudi Arabia, when each is legally required, and how the two work together in practice.
External Audit vs Internal Audit
External audit is an independent, SOCPA-licensed examination of financial statements, required by the Companies Law for most companies. Internal audit is an ongoing review of controls, risk, and operations, generally voluntary for private companies but mandatory for listed companies under CMA governance rules since January 2024.
What Is an External Audit?
An external audit is an independent examination of a company’s financial statements, carried out by an auditor who has no employment relationship with the company. In Saudi Arabia, only auditors licensed by the Saudi Organization for Chartered and Professional Accountants (SOCPA) can perform this work and sign the resulting opinion.
The auditor tests the balance sheet, income statement, cash flow statement, and the transactions behind them, against the accounting standards SOCPA has endorsed, which are based on International Financial Reporting Standards (IFRS). The output is a formal audit opinion addressed to shareholders, stating whether the financial statements give a true and fair view of the company’s position.
External audit is generally an annual exercise tied to the company’s financial year end, and for most joint stock companies and limited liability companies it is a legal obligation under the Companies Law, not a discretionary service.
What Is an Internal Audit?
An internal audit is an ongoing evaluation of a company’s internal controls, risk management, and governance processes, carried out by staff inside the organisation or by an outsourced team working on the company’s behalf. Unlike an external audit, it is not aimed at producing a public opinion on the financial statements.
Internal auditors look at whether policies are actually being followed, where controls are weak, and where the business is exposed to operational, financial, IT, or compliance risk. Findings go to management and, where one exists, the audit committee, so leadership can act on them before they become bigger problems.
Because internal audit answers to management and the board rather than to shareholders and regulators, its scope is set by the company itself. A retail business might focus internal audit on inventory and cash controls, while a construction company might prioritise project cost tracking and subcontractor payments.
Key Differences Between External Audit Vs Internal Audit

The table below sets out how the two functions differ in practice, not just in definition.
| Aspect | External Audit | Internal Audit |
|---|---|---|
| Purpose | Independent opinion on the financial statements | Evaluate and improve controls, risk, and operations |
| Performed by | A SOCPA-licensed external auditor | Employees or an outsourced provider |
| Independence | Fully independent of the company | Independent of day-to-day operations, but part of the organisation |
| Reports to | Shareholders, via the audit opinion | Management and the board or audit committee |
| Legal basis | Required by the Companies Law for most companies | Voluntary for most private companies; mandatory for listed companies |
| Frequency | Typically annual | Ongoing, per an approved audit plan |
| Scope | Financial statements and supporting records | Controls, operations, IT, compliance, and risk |
| Output | A formal, publishable audit opinion | Internal reports and recommendations, not for public release |
Is Internal Audit Legally Required in Saudi Arabia?
This is where most confusion starts, because the answer depends entirely on the type of company.
Private companies. The Companies Law does not require most limited liability companies or unlisted joint stock companies to maintain an internal audit function. Many still choose to, because lenders and investors increasingly expect it, and because a functioning internal audit process makes the annual external audit faster and cheaper.
Listed companies. The position changed in January 2024, when Articles 73 to 75 of the Capital Market Authority’s Corporate Governance Regulations became mandatory. Listed companies on the Saudi Exchange must now establish an internal audit unit, adopt a formal internal audit plan, and produce an internal audit report. This sits alongside the long-standing requirement for listed companies to maintain an audit committee of three to five members, with a majority of non-executive directors and at least one independent member.
Regulated financial institutions. Banks, insurance companies, and other entities supervised by the Saudi Central Bank are expected to run a full internal audit function covering financial, operational, and IT risk as part of their licensing conditions, generally to a higher standard than the CMA rules require of other listed companies.
If your company falls outside these categories, internal audit remains a management choice rather than a legal duty, but it is worth weighing against the cost of the control failures it is designed to catch.
What Are the Main Types of Internal Audit?
Internal audit is not a single activity. Most functions run a mix of the following, prioritised by risk.
Financial audit. Checks the accuracy of accounting records, transaction processing, and account reconciliations, catching errors and misclassifications before the external auditor ever sees them.
Operational audit. Reviews how efficiently a process runs, looking for bottlenecks, duplicated work, or wasted spend across departments such as procurement, supply chain, and HR.
Compliance audit. Confirms that the business is operating within tax law, labour regulations, licensing conditions, and its own internal policies, reducing the risk of penalties from ZATCA or other regulators.
IT and systems audit. Examines access controls, cybersecurity practices, data protection, and whether software systems support the business reliably and securely.
Risk management audit. Assesses how well the company identifies, measures, and responds to the risks it faces, whether financial, operational, regulatory, or reputational.
A company does not need to run every type every year. A well-designed internal audit plan targets the areas of highest risk first and works through the rest on a rotating cycle.
How External and Internal Audit Work Together
Treated as separate exercises, external and internal audit still share common ground. Both rely on documented evidence rather than assumptions, both aim to give stakeholders confidence in the business, and both work toward the same goal: a company that is well controlled and accurately reported.
Where a strong internal audit function exists, the external audit usually goes faster. Reconciliations are already done, documentation is already organised, and known control weaknesses have already been flagged and, ideally, fixed. External auditors will often review the internal audit function’s work as part of their own risk assessment, though they cannot rely on it entirely for their own opinion.
The reverse is also true. External audit findings frequently shape the following year’s internal audit plan, since a weakness the external auditor raises is a strong candidate for closer internal review before it recurs.
Independence: The Difference That Matters Most
Independence is the single biggest structural difference between the two functions, and it explains most of the other differences on the table above.
An external auditor cannot be an employee of the company, cannot have a financial interest in it, and is restricted by SOCPA rules in the non-audit services it can provide to the same client. This distance is what makes the audit opinion credible to shareholders, lenders, and regulators who were not in the room when the numbers were produced.
Internal auditors do not have that same distance from the business, and are not meant to. Their value comes from proximity: understanding how the company actually operates, sitting close enough to management to flag a problem quickly, and having the access needed to test controls in real time. What internal audit is expected to maintain is independence from the operations it reviews, typically by reporting to the audit committee rather than to the department it is examining.
Which One Does Your Business Need?
For most Saudi companies, this is not really an either-or decision, because the Companies Law already answers the external audit question. If your company is a joint stock company, or an LLC that does not qualify for the small and micro exemption, external audit is a legal requirement regardless of whether you also run internal audit.
Internal audit is the genuine choice. It becomes worth the investment when a business has grown past the point where the owner or a small finance team can personally verify that controls are working, when a lender or investor is asking for stronger governance, when the company is preparing for an IPO or a sale, or when a previous external audit turned up findings that suggest control gaps.
Smaller, closely held businesses with straightforward operations often find that a well-run finance function, combined with the annual external audit, gives them adequate assurance without a dedicated internal audit unit. As the business adds locations, product lines, or outside investors, that calculation usually shifts.
In-House vs Outsourced Internal Audit
Companies that decide to build an internal audit function generally choose between an in-house team and an outsourced provider, and the right answer depends on size and complexity rather than one option being universally better.
An in-house team builds deep knowledge of the business over time and is available for ad hoc reviews at short notice, but carries a fixed cost that only makes sense once the business is large enough to keep the team busy year-round.
An outsourced or co-sourced internal audit function gives access to specialist skills, such as IT audit or fraud investigation, without carrying that cost permanently, and scales up or down as the company’s risk profile changes across a wide range of areas. Many mid-sized Saudi businesses start with an outsourced model and build an in-house team later if the function grows.
Frequently Asked Questions
What is the main difference between external and internal audit?
External audit is an independent examination of the financial statements by a SOCPA-licensed auditor, aimed at producing a public opinion for shareholders. Internal audit is an ongoing internal review of controls, risk, and operations, aimed at helping management run the business better.
Is internal audit mandatory in Saudi Arabia?
It depends on the company. Listed companies have been required to maintain an internal audit unit under CMA Corporate Governance Regulations since January 2024. Most private companies are not legally required to have one, though many choose to for governance and lending reasons.
Can the same firm provide both external and internal audit services to one company?
Generally no, or only with significant restrictions. SOCPA independence rules limit the non-audit services an external auditor can provide to the same client, specifically to protect the independence the external audit opinion depends on.
Does a strong internal audit function reduce external audit fees?
It often helps. Clean, well-documented records and previously resolved control issues can reduce the time an external auditor needs to spend on fieldwork, though the external auditor must still perform its own independent testing regardless of internal audit’s work.
Do small businesses need an internal audit function?
Not usually, and it is rarely a legal requirement for smaller private companies. Many small businesses rely on the annual external audit plus solid day-to-day financial management until they reach a size or ownership structure where dedicated internal audit becomes worthwhile.
Who does the internal auditor report to?
Internal auditors typically report to senior management and, where one exists, the audit committee of the board. This reporting line is what preserves their independence from the departments and processes they are reviewing.
What happens if a listed company does not have an internal audit function?
Since the CMA’s Corporate Governance Regulations made Articles 73 to 75 mandatory in January 2024, a listed company without an internal audit unit, plan, and report would be out of step with its governance obligations, which can draw regulatory attention and affect investor confidence.
Summary
External audit and internal audit answer different questions. External audit tells shareholders and regulators whether the financial statements can be trusted. Internal audit tells management whether the controls behind those numbers, and the wider operations of the business, are actually working.
Most Saudi companies of any scale need external audit because the Companies Law requires it. Internal audit is a management choice for private companies, but a firm legal requirement for listed companies since the CMA’s 2024 governance changes. Understanding which applies to your business, and how the two functions reinforce each other, is the first step toward a stronger control environment.
Next Steps
If you are weighing up whether your business needs a dedicated internal audit function, or you want a second opinion on how your next external audit is likely to go, request an audit consultation with our team in Jeddah. You can also explore our Saudi external audit services and our internal audit services to see how each engagement is scoped and delivered.