Internal Audit

A principled model that contributes to value creation and protection

This is the internal and independent unit that oversees the proper functioning of the Group's internal control, risk management systems and governance processes. In its role, we incorporate international best practices to ensure its proper functioning, work that demonstrates our commitment to quality and professional practice.

The Internal Audit Department, reporting to the Internal Audit and Risk Department, has as its main function the independent and objective provision of assurance and advisory services to add value and improve the Company's operations, providing a systematic and disciplined approach to assess and improve the effectiveness of the Group's risk management, internal control and governance processes. 

Its activities are governed by the provisions of the Basic Internal Audit Regulations of Iberdrola, SA [PDF], which form part of the Company's Governance and Sustainability System. This standard regulates, among other aspects, the nature, organisation, competencies, resources, activities, powers, and duties of the members of the Internal Audit function, as well as the framework of their relationships within the Group. 

Internal Audit Independence

The independence of the Internal Audit role from executive management responsibilities is fundamental to its objectivity, authority and credibility.

As a guarantee of independence, the director of the Internal Audit and Risk Area reports hierarchically to the chairman of the Board of Directors and functionally to Iberdrola's Audit and Risk Supervision Committee (ARSC).

With this same positioning, there are Audit and Compliance Committees (ACC) and Internal Audit departments in the various country-based subholdings, with which there are internal coordination mechanisms, working under the same methodological and quality framework defined in accordance with the International Framework for Professional Practice approved by the Institute of Internal Auditors.

In addition, the independence of the internal audit function at Iberdrola is established through:

The functional reporting structure of the Audit Committee within Iberdrola’s Audit and Risk Oversight Committee (CASR)

Unrestricted access to the people, resources and data needed to complete its work

The absence of conflicts of interests with the provision of audit services

Internal Audit Activities

The annual activity plans of Iberdrola's Internal Audit Division and of the Internal Audit divisions of the Group are prepared considering the Company’s most significant risks, from a perspective coordinated with other assurance functions, providing an independent view of the operation and effectiveness of the risk management, internal control systems and governance processes established in the Group.  

All of this responds to the requirements set by the ARSC and the respective ACCs of the country subholdings, including the following lines of work:

Supervision of the comprehensive system and risk control established at the Group level, and its adequacy to ensure compliance with risk guidelines and limits. 

Supervision of the effective functioning of the internal control over financial reporting (ICFR) and internal control over sustainability information (ICSI) systems to prepare and present the Group's financial and sustainability information, as well as other information that, as a listed company, it must periodically disclose. 

Audits of the internal control systems of the Company's Compliance System, which aims to prevent, manage and mitigate the risk of regulatory and ethical breaches. 

Oversight of the mechanisms for implementing the governance and sustainability system, amongst other things.

In addition, the Internal Audit Department assists the Committee in the development of its competencies, in particular about the supervision of the effectiveness of the internal control, risk management systems and governance processes, relations with the statutory auditor and the supervision of the process of preparing the related financial and non-financial information. 

Basic Internal Audit Regulations

This standard regulates the nature, organisation, competencies, powers and duties of the internal audit function corresponding to IBERDROLA, S.A.'s Internal Audit and Risk Department.

See PDF

Commitment to professional and quality standards

The Internal Audit function operates in accordance with the International Framework for the Professional Practice of Internal Auditing, as adopted by the Institute of Internal Auditors (IIA) which contains the global standards for internal auditing. This International Framework guides the professional practice of the internal audit profession throughout the Group, as a guarantee of our commitment to quality and professional practice.  

The commitment to compliance with these Standards is embodied in the maintenance of the most relevant international certification issued by the Institute of Internal Auditors, the Quality Assurance certification, which guarantees that Internal Audit applies the highest quality standards and works in accordance with the global internal auditing standards. 

The members of Internal Audit have the most relevant professional certifications, which accredit the knowledge and experience of the teams and their continuous training, including Certified Internal Auditor (CIA), Certified Information System Auditor (CISA), Certified Fraud Examiner (CFE), Certified in Risk Management Assurance (CRMA). 

As part of its commitment to continuous improvement and operational efficiency, the Internal Audit function has established a strategic plan designed to evolve its activities so that they contribute to achieving the Group’s objectives. This plan is built around three strategic lines: 

Innovation and technology

Promoting innovation to adopt and utilise new technologies and digital tools that streamline processes, improve operational efficiency and add greater value to the organisation.

Forward-thinking and a driving force

The ability to anticipate trends, risks and opportunities, providing relevant insights at the right time and driving the organisation’s continuous development.

Commitment to inclusion

A collaborative approach, based on integration with the business and other assurance functions, promoting coordination, alignment of objectives and the creation of synergies that enhance overall effectiveness.

Iberdrola, S.A. Board of Directors

As provided in the Regulations of the Board of Directors, the Board of Directors of Iberdrola, S.A. has the broadest powers and authority to manage and represent the company.

Learn more about the Board of Directors

Regulations of the Audit and Risk Supervision Committee

The purpose of these regulations is to ensure the independence of the Audit and Risk Supervision Committee and to determine the principles of action and the rules governing its internal functioning.

View PDF