The Internal Audit department is the internal audit department of the University of Twente (hereinafter: UT) and forms part of the General Affairs department. Based on expert and objective investigations (audits and advice), the Internal Audit department provides the Executive Board and management with additional assurance regarding the effectiveness and control of the university’s operations, enabling it to operate decisively. Through both solicited and unsolicited advice, the Internal Audit department contributes to the control and quality of operational management, the provision of governance information and risk management.
Internal Audit adopts an integrated and risk-based approach, with areas of expertise covering processes (operations), systems (IT) and culture and behaviour. These areas of expertise are not separate from one another but are interconnected. Internal Audit adopts a multidisciplinary approach, whereby investigations may cover more than one area of expertise.
Together with its stakeholders and the Executive Board, Internal Audit identifies the key risk areas for the UT each year and thereby determines which audit topics will be included in the annual plan. For example, audits and advice are provided in the following areas:
· The effectiveness and efficiency of (operational) processes;
· The maturity of internal controls relating to IT systems;
· Cultural and behavioural aspects within the organisation (and its sub-units);
· (Financial) information from faculties and support services.
The remit of the Internal Audit department has been established by the UT Executive Board and set out in an Audit Charter. In addition, Internal Audit operates a quality management system to ensure that the audit work carried out and the resulting reports meet the specified quality requirements (based on relevant legislation and regulations).
Team members
Services
Operational audit and consultancy
The UT is a complex organisation in which a wide range of processes in the fields of education, research and operational management converge. These processes contribute to the achievement of the UT’s strategic objectives and require sound design and control. It is important that processes are not only carried out lawfully and reliably, but are also designed to be effective, efficient and appropriate.
Changing legislation and regulations, ambitions in the fields of education and research, and developments within the organisation constantly place new demands on the design and implementation of processes. Effective risk management helps to safeguard the continuity and quality of operational management and to achieve the organisation’s objectives.
Operational audit and advisory work focuses primarily on the quality and control of business processes, the risks involved, and the extent to which processes contribute to achieving the UT’s objectives. Examples of such work include:
· Assessing the effectiveness and efficiency of primary and support processes;
· Evaluating the design, existence and functioning of internal control measures within
processes;
· Identifying and analysing process risks (e.g. bottlenecks);
· Advising on opportunities to improve governance, processes and procedures (e.g. by
means of a baseline assessment
· Conducting thematic or organisation-wide investigations into specific aspects of
processes.
IT audit and consultancy
Developments in the field of IT and digitalisation have been advancing at breakneck speed in recent years. First and foremost, this presents opportunities for the UT – opportunities to explore technological possibilities and utilise them to drive innovation and improve existing processes.
Developments in IT and digitalisation have a major impact on the realisation of the UT’s future ambitions. Increasing digitalisation has meant that the majority of processes within the UT now depend on IT systems. This means it is important to guarantee the reliability, predictability and continuity of data processing.
Furthermore, within the open university environment that we are, knowledge and data are shared between students and staff. This leads to cross-fertilisation and new insights, and ensures that we can take steps together towards innovation and improvement. However, being an open environment also entails increasing risks in the areas of information security and the protection of personal data (privacy). Control measures relating to security and privacy are therefore essential for a safe (working) environment.
IT audit and consultancy activities focus primarily on processes supported by IT systems and the associated risks and control measures. Examples include:
· Assessing general IT controls relating to relevant applications;
· Fulfilling a quality assurance role in change management processes (for example, within
the application landscape);
· Carrying out or coordinating security or privacy assessments;
· Assessing university processes (particularly with regard to automated control measures).
Behavioural audit and consultancy
Behavioural auditing is a discipline within the field of auditing that examines behaviour within organisations, with a focus on gaining insight into this behaviour and reporting on it, with the aim of influencing it (the climate and culture within organisations).
As it is widely recognised that aspects such as leadership, culture and integrity must increasingly be taken into account in standard audits (which focus on the quality of internal control measures), this discipline (as part of a multidisciplinary approach) forms an integral part of Internal Audit’s remit.
The following activities may fall under a behavioural audit or consultancy engagement:
· Entity-level audit: a UT-wide assessment of culture or behaviour;
· Process-level audit: investigating the drivers of behaviour within an existing process;
· Thematic audit: investigating the drivers of behaviour related to a relevant theme;
· Instrument analysis: an assessment of the design and existence of instruments used to
steer behaviour (including codes of conduct).
Last edit: 12 August 2026