MAB: Compliant in principle! And in practice?


By Robert Bogtstra, Inge Garretsen, Remko Renes

Video: Robert Bogtstra and Remko Renes about their research (in Dutch)

The revised Dutch Corporate Governance Code of 2016 (hereafter “the Code”) comprises provisions regarding the existence of an internal audit function. Following the comply or explain principle of the Code, Euronext Amsterdam listed companies with a registered office in the Netherlands either have established an internal audit function or have to explain why they did not.

Our research shows that the number of listed companies with an internal audit function has since grown. In 2016 53% of Euronext Amsterdam listed companies with their registered office in the Netherlands have established an internal audit function; in 2018 this figure is 64%. More than half of these listed companies have an in-house independent internal audit function, whereas other companies have internal audit functions with different characteristics, such as a combined internal audit and risk management function or have outsourced the internal audit function.

The majority of the companies without an internal audit function provide inadequate arguments for this absence. They thereby do not meet the standards as set forth in the Code. In most cases, the argument for not having an internal audit function is: “the organization is too small”. This is not a valid argument, as the Code specifically addresses this situation stating that in case the size of a company is not suited for an internal audit function, outsourcing may be an appropriate alternative.

We conclude that management boards should give this topic better thought and give better insight in their judgement by explaining the arguments. We therefore advocate that the principle of “comply or explain” should be “comply and explain”. Such is the case in the South African corporate governance code (King IV). The effect will be that management boards mindfully have to elaborate on how they obtain independent assurance on the company’s governance, risk management and control systems.


Read the full article at MAB-online

Download as a pdf


Relevance to practice

The research explores as to what extent Euronext Amsterdam listed companies with a registered office in the Netherlands comply to the revised Dutch Corporate Governance Code (2016) provisions regarding internal audit. Boards can benefit from the research by obtaining insight into the variety of established internal audit functions and various explanations for not establishing an internal audit function.

Terug naar het nieuwsoverzicht

IIA Nederland

Burgemeester Stramanweg 105F
1101 AA Amsterdam
Contact opnemen

Audit Magazine

Audit Magazine


IIA is dé toonaangevende beroepsorganisatie voor internal auditors. Een lidmaatschap laat u delen in de collectieve kennis van alle vakgenoten in de wereld.
Meer informatie