Internal Audit

Four business professionals collaborating
A businesswoman explaining her point of view at a meeting table, male colleagues in the background
Modern internal audit that supports management and creates assurance

Internal audit helps management and the supervisiory board to assess whether the organisation’s governance, risk management and controls support the achievement of its objectives. Internal audit is not limited to reviewing controls — it helps identify key risks, assess the reliability of processes and support better decision-making in a rapidly changing environment.

PwC helps organisations design, develop and implement an internal audit approach that is aligned with their objectives, risk profile and level of maturity. We support clients in setting up and transforming the internal audit function, delivering the audit plan, implementing technology, developing the team and assessing internal audit quality.

Why it matters 

Modern internal audit helps organisations understand where the most significant risks, control weaknesses and development opportunities lie. In a fast-changing environment, the board and audit committee need an independent view on whether key processes are functioning as intended and whether the organisation is ready to respond to emerging risks.

Key questions include:

  • Do controls work in practice, not just on paper?
  • Is internal audit focused on the right risks and priorities?
  • Does the organisation have sufficient resources and capabilities for internal audit?
  • How can internal audit become more impactful and data-driven?

Kuidas saame aidata?

Setting up or transforming the internal audit function

We help design, develop and structure the internal audit function so that it fits the organisation’s objectives, structure and risk environment and is ready for future needs. A well-functioning internal audit function is not just a control function — it is a partner to management and the audit committee that brings clarity, assurance and value across the organisation.

We support organisations in areas including:

  • Setting up and launching the internal audit function;
  • Developing the internal audit charter, strategy and vision;
  • Designing policies, methodologies and audit plans;
  • Restructuring internal audit, for example due to a merger or other significant change;
  • Clarifying the role and responsibilities of internal audit within the governance model;
  • Organisation-wide alignment and integrated assurance across the second and third lines of defence.

Delivering internal audits

We help organisations deliver their internal audit plan by combining modern audit methods, technology, sector knowledge and practical experience. We provide internal audit support flexibly — from individual audits to fully managed internal audit services.

We support clients in areas including:

  • Internal audit co-sourcing and outsourcing solutions;
  • Risk assessments;
  • Audit planning, scoping and work-programme design;
  • Audit execution using data-led and technology-enabled approaches;
  • Management, coordination and communication of international audit projects;
  • Specialist audits such as cyber, ESG, M&A, HR, culture or strategy audits;
  • Third-party audits, including vendor compliance and due diligence reviews.

 

Financial services internal audits

In financial services, internal audit must provide independent and meaningful assurance in areas where regulatory expectations, technological complexity and the impact of risks are particularly high. PwC has extensive experience supporting financial services organisations in Estonia and internationally, and we understand the key risks and supervisory expectations facing banks, insurance companies, payment institutions, investment firms and fund managers.

We support financial services internal audit in areas including:

  • Audits of credit, payments, investment and insurance processes;
  • AML/CTF, sanctions and transaction monitoring audits;
  • DORA, IT, cyber and third-party risk audits;
  • audits of risk management, compliance and the effectiveness of the three lines of defence..

We help financial institutions strengthen their internal audit function, demonstrate the effectiveness of controls and increase assurance for the board and audit committee in the areas that matter most from a supervisory perspective.

Developing the internal audit team

Strong internal audit depends on people — their skills, confidence and ability to adapt to new expectations. We help internal audit teams build capabilities, evolve ways of working and strengthen leadership so that they can support the organisation effectively and with a forward-looking mindset.

We support clients in areas including:

  • Training for internal audit and other assurance functions;
  • Training for leaders and key persons responsible for internal control functions;
  • Raising awareness among executives and senior management on governance, controls and the role of internal audit;
  • Coaching and mentoring for internal audit leaders, audit committee members and management.

Assessing internal audit maturity and quality

We help organisations assess whether the internal audit function meets stakeholder expectations, international standards and the organisation’s strategic needs. Maturity and quality assessments help identify strengths, gaps and improvement opportunities, and support the development of next-generation internal audit.

We support clients in areas including:

  • External quality assessments (EQA);
  • Internal audit maturity and performance assessments;
  • Development and evaluation of internal audit quality management frameworks and processes;
  • Siseauditi KPI-de kujundamine ja hindamine, sidudes need organisatsiooni strateegiaga;
  • Optimisation of reporting to internal audit, the audit committee, the board and other stakeholders.

A collaborative approach creates more value

Our experience shows that solving complex problems requires a combination of capabilities from different disciplines. Modern internal audit needs a broader set of skills to assess multidimensional risks and support the organisation in a meaningful way.

PwC combines core internal audit capabilities with other important areas such as cybersecurity, ESG, compliance, organisational culture, financial crime prevention and tax. Where needed, we bring in subject matter specialists and use digital tools to make internal audit more targeted, efficient and aligned to business needs.

This creates a multiplier effect: broader risk coverage, greater efficiency and more meaningful insights that support management and the audit committee in decision-making.

Four colleagues collaborating and discussing

A pictogram depicting a team of people

Experienced Estonian internal audit professionals


A pictogram depicting the side view of a human head with gears symbolising connectivity

The ability to combine financial, risk management, control, and regulatory knowledge



A pictogram depicting the globe

Global tools and sector expertise


A pictogram depicting a check mark

A practical, independent and management-supportive approach


Contact us

Karin Grents

Karin Grents

Leader of Governance, Risk, Compliance (GRC), and Internal Audit services, PwC Estonia

Tel: +372 614 1800

Follow us

Required fields are marked with an asterisk(*)

By clicking the "Submit" button, you consent to the processing of your personal data. You have the right to withdraw your consent at any time by sending an email to ee_info@pwc.com or ee_legal@pwc.com. The withdrawal of consent shall not affect the lawfulness of any processing carried out on the basis of your consent prior to its withdrawal. Please refer to our Privacy Statement for further information on how your personal data is processed.

Hide