Institutional Analysis of Internal Audit in Maltese Local Government
Abstract:
Across the international audit and public governance literature, the OECD and the Institute of Internal Auditors (IIA) increasingly framed internal audit as a risk-based and continuous assurance function rather than a retrospective and compliance-checking exercise. In small-state local government systems such as Malta’s, however, this shift has not yet been matched by a comparable institutional transformation. This study examined the institutional position of the internal audit function in Maltese local governments within the framework of public financial management, internal control, risk management, and accountability, and then developed an internal audit model applicable to Malta’s administrative scale. A directed qualitative content analysis was adopted to examine official institutional documents, informed theoretically by agency theory and institutional theory, and combined with comparative institutional analysis. Documents were coded against eight core criteria, including institutional independence, risk-based audit capacity, and follow up of the findings, when applied uniformly to Malta and five comparator countries (the United Kingdom, the Netherlands, Sweden, Estonia, and Ireland), plus four supplementary criteria used only for the Malta case. The findings demonstrated that Malta’s core institutional weakness was not the absence of audit mechanisms, but insufficient integration of external audit, compliance review, internal control, and corrective action into a continuous internal audit cycle. The comparative analysis indicated that a centrally coordinated, locally connected, and risk-based hybrid model was more applicable to Malta than separate per-council internal audit units. The original contribution of the study lies in systematically linking National Audit Office Malta (NAO)’s recurring local-government findings to a structured and criterion-based comparison across five European models, thus translating this into an institutional design calibrated to Malta’s scale, and extending agency and institutional-isomorphism theory to small-state local government audit.
1. Introduction
Local governments are institutional structures in which public services are delivered at the level closest to citizens and where expectations of accountability regarding the use of public resources become most visible. In the European public financial management approach, public internal control is not viewed solely as compliance checking; rather, it is regarded as a governance instrument that supports the effective, efficient, and results-oriented management of resources while also reducing the risks of irregularity and corruption (European Commission, n.d.). In Malta, the local government system operates through local councils organized under the Local Government Act (Legislation Malta, 1993), while the Local Government Division (LGD) is responsible for the control, coordination, monitoring, and oversight of the functions of local and regional councils, including the supervision of financial and procurement compliance. However, the 2024 local government report of the National Audit Office Malta pointed to recurring problems in the timely submission of financial statements, internal control weaknesses, documentation gaps, and the sustainability of financial management (National Audit Office Malta, 2024). Therefore, internal audit in Malta’s municipalities should be addressed not merely as a technical control activity but as a strategic governance mechanism that strengthens risk management, institutional capacity, and democratic accountability.
In Malta, local governments are not entirely unaudited; however, existing external audit, monitoring, and compliance mechanisms have not been sufficiently transformed at the municipal level into continuously operating, risk-based internal control capacity with systematic follow-up. The LGD is responsible for controlling, coordinating, supervising, and monitoring local government functions, as well as the financial and procurement compliance of local and regional councils. Within this institutional structure, the Finance and Procurement Compliance Directorate reportedly conducts compliance reviews of local councils’ financial and procurement activities and internal audits focused on primary financial cycles (Local Government Division, 2023). Nevertheless, the 2024 report of the National Audit Office Malta identified recurring internal control weaknesses in local councils, including continued reliance on year-end audits, temporary measures that failed to address root causes, and insufficient corrective action. It also reported that 11 local councils had failed to submit their audited financial statements for the 2023 financial year by the prescribed deadline and that 48% of the opinions issued by that deadline were qualified (National Audit Office Malta, 2024). These findings indicate that the main problem in Malta’s municipalities is not isolated non-compliance, but the absence of an effective internal audit architecture capable of ensuring institutional continuity in internal control, risk management, financial reporting, and accountability.
The aim of this study is to analyze the current institutional position of the internal audit function in Malta’s local governments through the lenses of public financial management, internal control, risk management, and accountability. The study evaluated the institutional constraints within which audit and oversight processes operated in local councils and discussed the extent to which the existing structure met the need for risk-based internal audit. Accordingly, the study did not merely identify existing problems; it also proposed an internal audit model that was feasible, centrally coordinated, and operational at the local level, considering Malta’s administrative scale and local government capacity.
This study focused on explaining the internal audit capacity within the institutional functioning of Malta’s local governments and the extent to which the existing audit architecture met the need for risk-based management. Within this study, the main questions guiding the research are as follows:
(1) What institutional, managerial, and implementation-related factors lead to the limited internal audit function in Malta’s local governments?
(2) To what extent do existing audit, oversight, and compliance mechanisms meet the internal control and risk management needs of local councils?
(3) Which of the central, local, or hybrid internal audit models appears more feasible for Malta’s local governments?
(4) What contribution might the proposed internal audit model make in terms of financial management, accountability, and institutional capacity?
This study examines internal audit in Malta’s local governments not merely as a mechanism for identifying financial errors or ensuring regulatory compliance, but as an integral component of public resource management, institutional risk oversight, and accountability. It brings together two bodies of evidence that are typically considered separately: recurring findings from local government audits in Malta and comparative evidence on the institutional organization of internal audit at the local level. To the authors’ knowledge, previous peer-reviewed research has not systematically assessed the findings of the National Audit Office Malta (NAO) against institutional arrangements in five European countries to develop an internal audit model tailored to Malta’s administrative scale.
2. Conceptual Framework
In the public sector, internal audit could not be treated as a narrow audit activity that merely seeks errors or checks compliance with legislation in the classical sense. According to the Institute of Internal Auditors (2024) (IIA), internal audit is an independent and objective assurance and advisory service carried out to add value to the organization, improve its operations, and support the achievement of its objectives. This function requires the effectiveness of governance, risk management, and control processes to be assessed through a systematic and disciplined approach. Figure 1 illustrates how proactive public-sector internal auditing operates as a continuous risk-based cycle linking risk identification, planning, execution, corrective action, digital monitoring, and verified closure of findings.

In the context of public administration, this definition acquires a broader meaning. In public institutions, internal audit is concerned not only with financial transactions but also with how public resources are managed, whether decision-making processes are reliable, whether internal control mechanisms operate effectively, and how institutional risks are monitored. Public-sector internal audit should therefore assess the adequacy and effectiveness of internal control systems, governance arrangements, risk management processes, and operational performance, extending beyond rule-based compliance checks. It should function as an independent and objective assurance mechanism rather than make decisions on behalf of management, and its organizational positioning should preserve its independence from risk management and managerial responsibilities (OECD, 2020). Accordingly, internal audit should be considered in direct relation to internal control, risk management, and accountability.
Beyond these professional definitions, the institutional position of internal audit in local government could be explained through two complementary theoretical lenses. Agency theory frames the relationship between elected councils, executive management, and citizens as a principal-agent relationship in which information asymmetry creates the risk of opportunistic behavior. Independent audit and monitoring mechanisms are the classic response to this risk (Eisenhardt, 1989). This lens explains why an internal audit function organizationally separates from the units it reviews, and why bodies such as audit committees are considered necessary safeguards for the accountability in the local government (West & Berman, 2003). Institutional theory complements this view by showing that public organizations often adopt audit structures not purely for efficiency reasons but to conform with regulatory requirements and professional norms and to secure legitimacy with oversight bodies and citizens, a process described as institutional isomorphism (DiMaggio & Powell, 1983). Taken together, these two perspectives suggest that the internal audit gaps identified later in this study should be read not only as technical or resource shortcomings, but as a sign that formal audit structures in Malta’s local councils have not yet been substantively internalized as a continuous assurance practice, even where compliance with the underlying legal and reporting requirements is nominally observed.
The relationship among internal control, risk management, and accountability enables public-sector audit to move beyond a technical control function and become an institutional mechanism that shapes the quality of governance. In public institutions, an integrated internal control and risk management framework is essential for protecting public integrity, reducing exposure to fraud and corruption, supporting value for money, and strengthening decision-making. Internal control should therefore be understood not as a set of procedures detached from an institution’s daily operations, but as an integrated management arrangement through which risks are identified, managed, and made traceable through policies, processes, and actions (OECD, 2020). Evidence from outside the strict public-sector context reinforces this view: stronger corporate governance and higher internal audit quality have been associated with better financial reporting quality, which supports treating internal audit as a governance-quality variable rather than merely a technical compliance function (Kaawaase et al., 2021).
Risk management constitutes the preventive dimension of this arrangement. When public institutions assess in advance the financial, operational, and ethical risks that may hinder the achievement of their objectives, internal controls cease to be tools that detect past errors only; they become a management capacity that helps safeguard resources, ensure compliance with legislation, and monitor performance. Internal audit is the independent assurance component of this structure. The IIA’s 2024 standards stated that internal audit strengthened governance, risk management, and control processes and supports decision making, oversight, reliability, and the capacity to serve the public interest (Institute of Internal Auditors, 2024). The European Commission Internal Audit Service also positions internal audit as a risk-based assurance activity that assesses and improves the effectiveness of risk management, control, and governance processes (European Commission Internal Audit Service, 2020). In this context, accountability is the visible outcome of internal control and risk management. The 2024 local government report of the Malta National Audit Office emphasized that strong internal controls were critical for reducing risk, limiting errors, ensuring the prudent use of public funds, and supporting accountability and transparency (National Audit Office Malta, 2024). Therefore, if these three elements are not considered together, the institutional value of internal audit in local governments could not be fully demonstrated.
The importance of internal audit in local governments stems from the direct connection between financial resources and procurement processes and the everyday delivery of services. The OECD regards internal audit at the subnational level as an important element in achieving financial objectives, controlling resources, improving decision-making and risk management, and supporting strategic and operational objectives (OECD, 2025). Therefore, internal audit is not merely an audit tool that examines the compliance of past transactions in municipalities; it is an institutional assurance mechanism that enables errors, risks of irregularity, and weak control areas to be identified before they affect service quality.
The demand for internal audit becomes more concrete in Malta. The Finance and Procurement Compliance Directorate within the LGD was established in 2021 to conduct compliance reviews of the financial and procurement activities of local councils, carry out internal audits focused on the primary financial cycles of local councils, and support the improvement of internal controls (Local Government Division, 2023). This arrangement shows that internal audit in local governments performs not only a controlling function but also a guiding function that strengthens local institutional capacity. On the other hand, the 2025 report of the Malta National Audit Office reported that certain weaknesses had recurred over the years and those problems persisted in areas such as accounting errors, fixed asset management, debt management, and non-compliance with procurement legislation (National Audit Office Malta, 2025). This picture demonstrated that internal audit in local governments was not a complementary mechanism but a necessary management capacity in terms of accountability and sustainable financial management.
The internal audit model in local governments should not be evaluated as a uniform organizational chart, but as a governance choice that should be designed by considering the municipality’s scale, volume of financial transactions, institutional capacity, and audit needs. The OECD/Support for Improvement in Governance and Management (OECD/SIGMA) 2023 Principles of Public Administration stated clearly that internal audit should be applied consistently across public administration, while the structure and organization of the internal audit function might be adapted according to the type, size, and complexity of the institution. The same principles identified shared internal audit services as a possible option, indicating that establishing an individual internal audit unit is not necessarily the most appropriate solution in all cases, especially in small-scale local governments (OECD/SIGMA, 2023).
Within this framework, three main internal audit models could be identified in local governments. The first is the in-house model, in which internal audit is carried out by a team established within the municipality and operating directly within the local government. The Local Government Association (LGA) guide defines the in-house model as the provision of internal audit services by a team composed of the organization’s employees; it also notes that outsourced, shared service, consortium, partnership, and co-sourced models could also be used in local governments (Local Government Association, 2024). The strength of this model lies in its proximity to local processes and institutional culture; however, in small municipalities, it may create limitations in finding specialist staff, maintaining independence, and sustaining diversity of expertise.
The second model is one in which internal audit is provided through outsourcing, shared services, or a central structure. In this approach, audit capacity is not established separately in each municipality; instead, it is delivered through a professional structure that serves multiple local governments. The LGA guide states that an outsourced model could be established through a shared service, commercial contract, or partnership arrangement, while in the co-sourced model, the in-house audit unit supplements particular expertise or capacity needs through external sources (Local Government Association, 2024). This model offers a practical option, especially in systems where specialist expertise is costly or the municipal scale is small; however, it requires the boundaries of responsibility between the service provider and the local government to be clearly defined.
The third model is the hybrid model, which combines central coordination with knowledge of local implementation. In this model, standards, methodology, quality assurance, and risk-based planning are coordinated centrally, while local data, process knowledge, and the follow-up of corrective actions are retained at the local level. The Chartered Institute of Public Finance and Accountancy (CIPFA) code of governance for local government internal audit addresses the roles of the authorized body, audit committee, and senior management in establishing, overseeing, and supporting internal audit arrangements, and states that the code applies regardless of how internal audit is delivered (CIPFA, 2025). This is consistent with the wider empirical literature on local government audit committees, which links their presence and active functioning to stronger financial accountability and oversight, while also revealing that committees are frequently under-resourced or only sporadically used in practice (Agyemang & Modisane, 2024; West & Berman, 2003). Therefore, the central issue in the hybrid model is not where the service is provided from, but the independence of internal audit, its relationship with the audit committee, quality assessment, and the systematic follow-up of recommendations.
Risk-based planning is the ordinary distinguishing criterion of these models. A 2024 study of 77 municipalities in Spain reported a positive relationship between the quality of risk analysis and the scope of operational audits, on the one hand, and the financial sustainability of municipalities, on the other (de Vicente-Lama et al., 2024). This finding indicated that the internal audit model in local governments should be evaluated not only by its organizational form but also by how it prioritized risks and translated them into an audit plan. Similarly, a study of internal audit functioned in South African metropolitan municipalities discovered that risk management was treated as a shared responsibility of internal audit, the audit committee, management, and external audit within a combined assurance arrangement, rather than as the task of a single unit acting alone (Ackermann & Marx, 2016), hence reinforcing the case for the multi-component hybrid model discussed below.
From Malta’s perspective, the Finance and Procurement Compliance Directorate within the LGD conducted compliance reviews of the financial and procurement activities of local councils, carried out internal audits focused on primary financial cycles, supported the improvement of internal controls, and coordinated action plans for implementing NAO recommendations (Local Government Division, 2023). This structure indicated that, in Malta, a hybrid internal audit model that strengthened the link between central oversight and local implementation could be discussed more realistically than a fully local or unit-based model.
3. Audit Architecture in Maltese Local Government
Malta’s local government structure operates through local councils within the country’s small-scale and centralized state system. The country is divided into 68 settlements classified as cities, towns, and villages, each governed by a local council elected by residents, with the overall structure supported by six regional councils. Under the Local Government Act (Chapter 363), local councils have defined duties and legal powers covering service areas such as infrastructure, the environment, culture, education and sports, and citizens’ rights (National Audit Office Malta, 2024).
In terms of institutional functioning, elected mayors and council members in local councils determine the policy direction, while the office of the Executive Secretary is responsible for execution, administrative affairs, and financial duties (National Audit Office Malta, 2025). This dual structure creates a division of duties between local representation and administrative execution; however, the 2024 assessment by the Council of Europe stated that the scope of local autonomy in Malta was limited and that central administrative supervision remained strong, especially through the executive secretary mechanism (Council of Europe, 2024). Therefore, although the institutional structure of Malta’s local governments contains elements of local representation, it is closely linked to the central system in terms of financial and administrative capacity.
The financial management structure of local governments in Malta is built on the close connection between the financing of local services and the central administration’s budget allocations, oversight, and financial reporting framework. The 2025 report of the NAO stated that local councils were financed mainly by central government and that, for the 2024 financial year, EUR 48 million was allocated directly to local councils, EUR 4 million to regional councils, and EUR 490,000 to the Association of Local Councils (National Audit Office Malta, 2025). This structure indicated that municipal finance was largely dependent on the flow of central resources.
In the financial reporting process, executive responsibility is concentrated on the Executive Secretary. According to the NAO report, the preparation of year-end financial statements is the responsibility of the Executive Secretary; these statements are expected to be prepared in accordance with International Financial Reporting Standards (IFRS) requirements and to include the statement of comprehensive income, statement of financial position, statement of cash flows, and notes (National Audit Office Malta, 2025). In addition, the LGD is responsible for managing financial subsidies to local authorities and supervising financial and procurement compliance, while the Finance and Procurement Compliance Directorate conducts compliance reviews of the financial and procurement activities of local councils (Local Government Division, 2023). Therefore, local financial management in Malta displays a structure in which local implementation responsibility and central monitoring and compliance oversight operate together.
The audit and oversight structure for local governments in Malta is based on a multilayered arrangement incorporating external audit, administrative monitoring, and financial and procurement compliance reviews. Within this structure, the NAO is the main external assurance actor in local government financial audit. According to the NAO 2025 report, from the 2021 financial year onward, the annual statutory audits conducted on behalf of the NAO have emphasized the financial transactions of local governments, while the supervision of compliance with the relevant laws and regulations has been carried out by the Finance and Procurement Compliance Directorate within the LGD. Nevertheless, the NAO has retained the authority to execute compliance audits on a sample basis, with three compliance audits for 2024 carried out in the Mellieħa, Nadur, and Xgħajra local councils (National Audit Office Malta, 2025).
In the dimension of administrative oversight, the LGD is responsible for the control, coordination, supervision, and monitoring of local government functions. Within the same institutional structure, the Monitoring and Support Department monitors the activities of local authorities and performs the management of financial subsidies (Local Government Division, 2023). The Finance and Procurement Compliance Directorate was established in June 2021 to strengthen the oversight role of the LGD; it assumed responsibilities such as compliance reviews of the financial and procurement activities of local councils, internal audits focused on primary financial cycles, on-site visits, and the coordination of action plans for implementing NAO recommendations (Local Government Division, 2023).
This picture depicted that the audit mechanism in Malta has not disappeared entirely; however, it is strongly organized around central oversight and external audit. Indeed, in its 2024 assessment, the Congress of the Council of Europe drew attention to the limited scope of local autonomy in Malta, the excessive supervision exercised by central authorities especially through the executive secretary mechanism, and the financial constraints of local authorities (Council of Europe, 2024).
In Malta, the internal audit function is positioned within a central oversight structure focused on the financial and procurement processes of local councils. Established in June 2021 to strengthen the oversight role of the LGD, the Finance and Procurement Compliance Directorate conducts compliance reviews of local councils’ financial and procurement activities, performs internal audits focused on primary financial cycles, and seeks to improve internal controls through on-site visits. It also facilitates the implementation of NAO recommendations, coordinates action plans, and conducts follow-up reviews (Local Government Division, 2023). In contrast, the NAO maintains its external assurance role through annual financial audits and sample-based compliance audits (National Audit Office Malta, 2025). The Council of Europe’s 2024 assessment, which identified strong central administrative supervision, indicates that the internal audit function has developed in connection with central audit capacity rather than local autonomy (Council of Europe, 2024).
4. Methodology
This study was a comparative institutional analysis based on structured document analysis within a qualitative research approach. It examined the current position of the internal audit function in Malta’s local governments through legal regulations, institutional reports, audit findings, and international public financial management standards. The central focus of the study was not merely to describe the audit structure in local councils by referring to existing practices, but to assess the extent to which this structure was adequate in terms of internal control, risk management, and accountability capacity. Therefore, the research design considered the Malta case within its own institutional context and then sought to develop a feasible model proposal by comparing it with selected internal audit models in Europe.
Documents were analyzed using directed qualitative content analysis, in which an a priori set of categories derived from the analytical criteria below was used to code the material, while allowing additional categories to emerge inductively from the documents themselves (Hsieh & Shannon, 2005). A source was included if it was issued either by a public or professional body with responsibility for audit, governance, or local administration, or a formally published academic study used to document a comparator for which equivalent official material was not available in the reviewed corpus. The corpus therefore included Maltese legislation and institutional reports, professional standards, documents related to international public administration, and the comparator studies listed in the reference list. Each source was coded against the relevant analytical criteria; statements not supported by the reviewed materials were recorded as “Not addressed” rather than “Inferred”.
The sources of this study consisted of official and institutional documents that directly explained the functioning of audit, financial management, and internal control in Malta’s local governments. In this scope, preliminary examination was conducted on the Local Government Act, which constituted the legal basis of Malta’s local government system as well as the duty and organizational documents published by the LGD, alongside the audit reports of the Malta National Audit Office on local governments. In addition, publicly available financial documents were evaluated to understand the financial reporting and budgetary structure of local councils. For the comparative analysis, data were collected from the OECD/SIGMA principles of public administration, documents about European public internal control, CIPFA local government internal audit guides, and existing institutional sources from selected cases of European countries. Thus, the dataset was structured to assess Malta-specific primary sources, together with international internal audit standards.
The United Kingdom, the Netherlands, Sweden, Estonia, and Ireland were selected purposively rather than at random, on three explicit criteria. Each is an EU or former EU member state with a codified and publicly documented framework governing internal or local audit oversight, respectively. It was feasible for a like-for-like comparison of institutional arrangements to be done on CIPFA’s code of governance, the Dutch system of independent local/regional audit offices, the Swedish system of elected auditors supported by certified experts, Estonia’s digital governance and open-data infrastructure, and Ireland’s statutory audit committee and findings from the follow-up mechanism. When taken together, the five cases spanned the main model archetypes identified in the Internal Audit Models in Local Governments section, namely standards-based in-house/audit-committee governance, independent local audit capacity, elected/lay oversight combined with professional support, digitally enabled monitoring, and committee-based follow up of the findings, so that the comparison was not biased toward a single institutional tradition. Ultimately, each case had sufficiently contemporary (2023–2025) English-language institutional documentation publicly available to support a comparable depth of analysis. Within this set, Estonia and Ireland additionally serve as small-state comparators closer to Malta in population and administrative scale, while the United Kingdom, the Netherlands, and Sweden represent larger and more institutionally mature systems from which specific transferable components, rather than a directly transplantable template, are drawn.
The analytical criteria were designed to assess internal audit in Maltese local government in terms of institutional functionality rather than simple presence or absence. Eight core criteria were applied to Malta and the five comparators: institutional independence; clarity of duties and responsibilities; risk-based audit capacity; traceability of internal control; reliability of financial reporting; procurement compliance; findings follow-up; and corrective-action capacity. Four supplementary criteria such as timely submission of financial statements, recurrent audit findings, qualified audit opinions, and the substance of management responses were used to structure the Malta-specific narrative analysis in Section 5.1. The eight core criteria are reported in the comparative matrices in Section 5.2. For the cross-country matrices, “Present” denotes explicit evidence of an established mechanism; “Partial” denotes a mechanism of limited scope or incomplete implementation; “Limited” denotes a documented constraint on capacity or continuity; “Gap” denotes a documented deficiency; and “Not addressed” denotes insufficient evidence in the reviewed material. These labels describe documentary evidence and are not direct measurements of implementation quality.
To guarantee consistency across cases, the coding procedure was applied separately and sequentially to Malta and each comparator country using the same eight core criteria. For each criterion, the reviewed documentary sources were examined for explicit evidence concerning the existence, scope, and operation of the relevant institutional mechanism. A criterion was coded as “Present” where the reviewed documents explicitly evidenced an established mechanism; as “Partial” where such a mechanism existed but was limited in scope or implementation; as “Limited” where the documents identified constraints affecting its capacity or continuity; and as “Gap” where a documented deficiency was identified. When the reviewed sources did not provide sufficient evidence to support a classification, the criterion was recorded as “Not addressed” rather than inferring either the presence or absence of the relevant practice. The same rules were applied across all six cases although the amount and specificity of documentary evidence available differed between countries.
The main limitation of this study is that it relied on publicly available official documents rather than field interviews or survey data. Therefore, the findings were limited to accessible legal regulations, institutional reports, and audit documents. Municipal-level implementation practices could not be observed directly; the model proposal was developed through document-based institutional analysis. This situation requires additional contextual caution in interpreting the results. A related limitation concerns the cross-case coding reported in Section 5.2: because the national documents available for Malta and the five comparator countries differ in structure and level of detail, several core criteria could not be evidenced from the reviewed sources of some countries and were coded as “not addressed in reviewed documents” rather than scored as absent; this asymmetry should be read as a boundary of the document-based design rather than as a substantive finding about practices of those countries. Future work drawing on a wider or more uniform set of national sources could extend the coding accordingly.
5. Findings
The six thematic gaps below are organized narratively, but each is anchored in the coding protocol. Lack of risk-based audit corresponds to risk-based audit capacity and recurrent findings; limited measurability of internal control systems corresponds to traceability of internal control; and failure to feed external-audit findings into internal audit corresponds to findings follow-up, corrective-action capacity, and the substance of management responses. Human-resource and institutional-capacity constraints emerged inductively as contextual conditions affecting implementation. Weaknesses in the accountability chain draw on timely financial reporting, qualified audit opinions, management responses, reliability of financial reporting, and procurement compliance. Institutional independence and clarity of duties are addressed in Section 3. The eight core criteria for all six cases are summarized in the comparative matrices in Section 5.2.
Audit activities in Malta’s local governments are not entirely detached from risk considerations. Nevertheless, the existing structure appears limited in its capacity to prioritize risks systematically and translate risk assessments into a continuous internal audit cycle. According to the 2025 report of the National Audit Office Malta, nine local councils had not submitted their audited financial statements for 2024 by the time the report was finalized. The report also identified recurring deficiencies and instances of non-compliance with procurement legislation during compliance audits of the Mellieħa, Nadur, and Xgħajra local councils (National Audit Office Malta, 2025).
These findings suggest that risks may not always be identified and addressed proactively but may instead become apparent only after transactions have occurred, particularly during year-end audits or limited-scope compliance reviews. Although the Finance and Procurement Compliance Directorate within the LGD reportedly conducts financial analyses to assess risks and support compliance monitoring and internal audit planning, seven of the 18 compliance reviews initiated in 2024 were discontinued because of outdated data and changing priorities. Furthermore, no new full-scope internal audits had been planned by the end of October 2024 (National Audit Office Malta, 2025). Taken together, these findings indicate that Malta’s risk-based internal audit gap arises primarily from difficulties in translating the existing institutional mandate into a consistent and sustainable audit cycle, rather than from the absence of a formal mandate.
The internal control problem in Malta’s local governments is less about the absence of defined controls than about the regular and results-oriented monitoring of how effectively these controls operate in practice. The Finance and Procurement Compliance Directorate within the LGD is tasked with conducting compliance reviews of the financial and procurement activities of local councils, carrying out internal audits focused on primary financial cycles, and contributing to the improvement of internal controls through on-site visits (Local Government Division, 2023). This mandate shows that internal control is institutionally recognized in Malta’s local government system. Nevertheless, the NAO 2025 report stated that weaknesses of internal control exposed local authorities to various risks and errors and classified control problems in core financial areas such as accounting records, fixed asset management, liabilities, bank reconciliations, deductions, and revenue (National Audit Office Malta, 2025). These findings revealed the need for more systematic monitoring that focused not only on the existence of internal control mechanisms but also on measuring their effectiveness and closing weaknesses. Therefore, the institutional gap in the field of internal control in Malta lies not in a lack of procedures, but in the limited capacity to transform control findings into measurable performance indicators, corrective actions, and trackable outcomes.
External audit findings concerning Malta’s local governments are produced regularly and communicated to the relevant councils. Nevertheless, clear limitations remain in translating these findings into a continuous cycle of internal audit, corrective action, and institutional learning. As the independent external auditor of local and regional councils, the NAO examines financial statements, identifies weaknesses in management letters, reviews local authorities’ responses, and recommends measures to strengthen internal controls and mitigate related risks (National Audit Office Malta, 2025).
The principal difficulty lies in translating these recommendations into institutional practice. The Finance and Procurement Compliance Directorate within the LGD is responsible for facilitating the implementation of NAO recommendations, coordinating action and improvement plans, and conducting post-audit follow-up reviews (Local Government Division, 2023). However, some council responses consisted only of brief statements of acceptance, without clear information on the actions taken or plans for implementing the recommended measures; in some cases, particular issues were not addressed at all. Such responses undermine the effectiveness of the audit process and increase the risk of recurring weaknesses and non-compliance. Continued instances of non-compliance identified during the follow-up of previous recommendations also point to constraints in the LGD’s oversight capacity (National Audit Office Malta, 2025). Therefore, the principal institutional gap in Malta is not the failure of the NAO to produce findings, but the insufficient integration of external audit findings into a systematic internal audit cycle at the local level—one that assigns responsibility, establishes implementation timelines and monitoring indicators, and includes a mechanism for verifying corrective action.
Internal audit capacity in Malta’s local governments should be evaluated not only in terms of the number of auditors, but also in terms of local councils’ ability to produce financial management, reporting, control, and corrective action. The NAO 2025 report commented that staff competencies directly affected the quality of financial reporting and governance; that regular training and professional development were necessary for the effective management of public funds; and that building institutional capacity was important particularly in small councils with limited resources (National Audit Office Malta, 2025).
This observation is consistent with the broader empirical literature on internal audit effectiveness, which identifies auditor competence, organizational independence, management support, and adequate resourcing as the recurring determinants of whether an internal audit function can operate effectively in practice (Alqudah et al., 2023). Evidence from local governments in Ghana further proved that, even where an internal audit unit formally existed, unfavorable working conditions such as inadequate staffing, weak administrative backing, and interference from the audited units themselves could prevent internal auditors from exercising their function effectively, regardless of the formal audit mandate on paper (Aikins et al., 2022). A comparative study of Malta together with Samoa and Suriname similarly cautioned that small population size did not automatically translate into administrative advantages such as more responsive service delivery and could instead produce capacity constraints of its own. This reinforced the case for a centrally supported internal audit capacity rather than separate audit capacity within each council in Malta (Jugl et al., 2026).
This issue of capacity affects the organizational form of the internal audit function. The Finance and Procurement Compliance Directorate within the LGD undertakes compliance reviews, internal audits focused on financial cycles, on-site visits, risk assessments, and coordination relating to the implementation of NAO recommendations. These responsibilities indicate that Malta’s audit capacity is supported to a significant extent through a central structure (Local Government Division, 2023). The Council of Europe’s 2024 assessment emphasized the limited scope of local autonomy in Malta, strong oversight by central authorities, and the financial constraints of local authorities (Council of Europe, 2024). This picture suggested that establishing a separate and full-scale internal audit unit for each local council was not a robust option in the current institutional context; a shared or hybrid internal audit model supported by central coordination appeared more feasible.
The accountability mechanism in Malta’s local governments operates formally; however, limitations remain in transforming audit findings into corrective actions that produce results. The NAO 2025 report recorded that all local authorities that submitted audited financial statements responded to management letters; 51 local councils, 6 regional councils, and the Association of Local Councils submitted these responses within the deadline, while eight councils exceeded the deadline (National Audit Office Malta, 2025). This indicated a certain institutional functioning at the level of reporting and response. Nevertheless, the same report stated that some responses consisted only of brief statements of acceptance, excluding specific information on corrective actions on the implementation of the recommended measures, and overlooking some issues entirely. The NAO noted that this situation limited the effectiveness of the audit process, increased the risk of recurring weaknesses and non-compliance, and might therefore weaken governance and accountability (National Audit Office Malta, 2025). Thus, the core problem in Malta is not that audit findings go unanswered, but that responses do not always become part of a robust accountability chain that includes a responsible unit, timeline, measurable target, and follow-up mechanism. Research on local government authorities in Ghana offered a relevant parallel here: it discovered that the effect of internal control systems on financial management outcomes was not automatic but was mediated by the degree of political interest and interference at the local level, so that a nominally adequate control system could still fail to produce timely corrective action when it was not insulated from local political pressure (Umar et al., 2025). This suggested that any follow-up mechanism proposed for Malta’s local councils needed to address not only reporting procedures but also the political and administrative incentives that determined whether a management response was acted upon.
Taken together, the findings illustrated that the main institutional gap in Malta’s local governments stemmed not from the complete absence of audit mechanisms, but from the inability of existing external audit, compliance review, internal control, and corrective action processes to become a continuously operating integrated internal audit cycle. Recurring findings in NAO reports, the fact that management responses are not always linked to concrete action plans, and the inability of some local councils to complete financial reporting processes on time indicated that the problem was more closely related to continuity of implementation and follow-up capacity (National Audit Office Malta, 2025). Although the financial and procurement compliance structure within the LGD provides a significant central capacity for reducing this gap, measurable risk monitoring, internal control assessment, and a results-oriented accountability mechanism need to be strengthened at the local level (Local Government Division, 2023). Within this framework, the most rational direction for Malta is a hybrid internal audit model that combines central coordination with local implementation responsibility.
A review of recent NAO reports indicated that the principal institutional weaknesses were relatively stable over successive reporting years. Delays in submitting audited financial statements, recurring procurement deficiencies, weaknesses in internal control, and limited implementation of management recommendations continue to appear across successive reports. While some councils demonstrate incremental improvements, the overall pattern suggests that institutional learning remains limited and that recurring weaknesses have not yet been translated into sustainable governance improvements (National Audit Office Malta, 2024; National Audit Office Malta, 2025).
Taken together, the five cases span the range of institutional model types identified earlier in the Internal Audit Models in Local Governments section so that the comparison is not biased toward any single model type: standards-based in-house governance with audit-committee oversight (United Kingdom), independent municipal/regional audit offices (Netherlands), elected lay auditors supported by certified professionals (Sweden), digitally enabled monitoring infrastructure (Estonia), and a statutory audit-committee and findings-follow-up mechanism (Ireland). Third, Estonia and Ireland provide small and unitary-state comparators closer to Malta’s own administrative and population scale, while the United Kingdom, the Netherlands, and Sweden represent larger and more institutionally mature systems from which specific transferable components, rather than a directly transplantable template, could be drawn; this is consistent with the broader comparative literature on small states, which cautions against assuming that population size alone determines which institutional arrangements are appropriate or effective (Jugl et al., 2026).
Comparative country models should not be treated as ready-made institutional templates to be transferred directly to Malta, but as analytical references that show which instruments may be used to address the audit gaps identified in Malta’s local governments. Therefore, the assessment is carried out through the independence of internal audit, risk-based planning, the audit committee, findings follow-up, local capacity, and digital monitoring opportunities.
The five comparator countries were selected purposively rather than at random, on three explicit criteria. First, each is a European state with a codified and publicly documented framework for local or subnational audit oversight that permits like-for-like analysis under the criteria set out in the Methodology section (a CIPFA-based code in the United Kingdom, OECD-monitored subnational arrangements in Sweden, National Oversight and Audit Commission (NOAC) oversight in Ireland, an independent local/regional audit-office tradition in the Netherlands, and an EU-supported digital-monitoring agenda in Estonia).
The United Kingdom case is important because it focuses not only on the organizational existence of internal audit in local governments but also on its position within governance. CIPFA’s 2025 code of governance for local government internal audit was developed to help local authorities establish, oversee, and support their internal audit arrangements. Applying regardless of how internal audit is provided, the code envisages internal audit as offering risk-based and objective assurance by evaluating the adequacy of governance, risk management, and internal controls (CIPFA, 2025). For Malta, the transferable aspect of this model is not the establishment of a separate internal audit unit in every municipality, but the creation of a common internal audit standard, audit requirement, quality assessment, and audit committee oversight for all local councils.
The Dutch model is noteworthy for institutionalizing local audit capacity at the municipal level. Its independent audit offices at the municipal and provincial levels can examine local financial structures and policy performance, while cooperation networks among these offices enable smaller municipalities to benefit from more advanced audit methodologies and translate audit findings into concrete improvements (Mukhamedyarova et al., 2025). The main lesson for Malta is not to establish a full-scale audit office in every local council, but to develop methodologically standardized local audit capacity through a regional or shared-service model.
The Swedish case shows that strong local autonomy and professional audit support can operate together. Sweden’s 290 municipalities and 21 regions have broad public service responsibilities and a significant degree of autonomy. At the subnational level, elected auditors cooperate with professional experts and determine the expert support they require, while preventive internal control and risk management processes should be strengthened and internal audit supported by certified auditors (OECD, 2025). The lesson for Malta is to incorporate professional and certified audit support into the system without weakening local democratic oversight.
Estonia offers an instructive example in terms of digital data infrastructure and monitoring capacity rather than a direct model for local government internal audit. A recent study examining the development of open public data in Estonia has shown that the country has made progress in the national open data ecosystem; however, open data provision at the local government level has not reached the same level of maturity, and local governments lag behind (Soosaar & Nikiforova, 2024). Another study mentioned that local administrative data in Estonian municipalities were still not used sufficiently and that problems related to data provision and data quality persisted (Soosaar & Nikiforova, 2025). For Malta, this example indicated that the proposed digital audit follow-up system was not merely a technical software issue; it should be designed together with data quality, local capacity, and standardized reporting processes.
The Irish model is particularly relevant to Malta because it illustrates the relationship among internal audit, external audit, and audit committees. Ireland has 31 local authorities, within which internal audit is recognized as a core function supporting effective governance, risk management, and internal control. Internal audit forms part of each local authority’s corporate governance and internal control framework, while the Local Government Audit Service (LGAS) is responsible for external audit and audit committees provide a link between internal and external audit findings. However, some local authorities did not use monitoring tools to track internal audit or LGAS findings, highlighting the need for follow-up systems that provide a clear audit trail (National Oversight & Audit Commission, 2024). For Malta, the principal lesson is that NAO findings should not remain merely as reports that receive formal responses; instead, their implementation should be traceable through an audit committee, a designated responsible unit, and a digital follow-up system.
Overall, the insights drawn from these country models are summarized in the comparative model matrix presented in Table 1.
Country | Prominent Model Elements | Transferable Aspect for Malta |
United Kingdom | Standards-based internal audit governance and audit committee oversight | Common internal audit standard and quality assurance framework for local councils |
Netherlands | Independent local/regional audit capacity | Shared-service or regional audit structure for small-scale councils |
Sweden | Local democratic oversight and professional auditor support | Audit model based on certified expert support while preserving local ownership |
Estonia | Digital data infrastructure and open data debates | Digital follow-up system for audit findings with strong data quality |
Ireland | Audit committees, internal audit requirement, and findings follow-up system | Linking NAO findings to action plans and a monitoring mechanism |
Table 1 summarizes the transferable institutional features identified in the comparator cases. To make the underlying criterion-based coding visible without sacrificing readability, two parallel matrices presented later in this section contain the eight core criteria. A “Not addressed in reviewed documents” rating indicates only that the reviewed country documents did not provide evidence on the criterion, not that the underlying practice is absent; this evidentiary asymmetry is discussed in Section 4.6.
Although the comparator countries provide useful institutional lessons, not all practices are equally transferable to Malta. Given Malta’s limited administrative scale, relatively small number of local councils, and centralized financial oversight, certain institutional arrangements are more realistic than others (Table 2).
Country | Directly Transferable | Adaptation Required |
United Kingdom | Audit standards | Separate audit unit in every council |
Netherlands | Shared audit services | Regional audit offices |
Sweden | Professional audit support | High municipal autonomy |
Estonia | Digital monitoring | Extensive digital infrastructure |
Ireland | Audit committee follow-up | Larger committee structures |
The core criteria for Malta, the United Kingdom, and the Netherlands are compared in Table 3, while the remaining comparator cases—Sweden, Estonia, and Ireland—are presented in Table 4.
Core Criterion | Malta | United Kingdom | Netherlands |
Institutional independence | Partial—Audit function embedded within LGD, not a separate statutory unit | Present—CIPFA code positions internal audit as independent, overseen by audit committee | Present—Independent local/regional audit offices |
Clarity of duties and responsibilities | Present—FPCD mandate documented | Present—CIPFA code defines roles of authorized body, committee, management | Partial—Described only in general terms |
Risk-based audit capacity | Limited—Full-scope audits/compliance reviews discontinued or not planned | Present—Code explicitly frames internal audit as risk-based assurance | Not addressed in reviewed documents |
Traceability of internal control | Limited—Control weaknesses recur across years without measurable closure | Present—Code requires evaluation of internal control adequacy | Partial—Reports “can lead to concrete improvements”, not detailed |
Reliability of financial reporting | Gap —Late submissions and qualified opinions recorded by NAO | Not addressed in reviewed documents | Not addressed in reviewed documents |
Procurement compliance | Gap—Non-compliance identified in Mellieħa, Nadur, and Xgħajra | Not addressed in reviewed documents | Not addressed in reviewed documents |
Findings follow-up | Gap—Brief, uninformative management-letter responses | Partial—Audit-committee oversight implies a follow-up role, not detailed | Partial—Reports “can lead to concrete improvements” |
Corrective-action capacity | Gap—Action plans are not consistently concrete or verifiable | Not addressed in reviewed documents | Not addressed in reviewed documents |
Core Criterion | Sweden | Estonia | Ireland |
Institutional independence | Partial—Elected lay auditors combined with professional experts | Not addressed in reviewed documents | Partial—Internal audit distinct from external LGAS audit, part of corporate governance |
Clarity of duties and responsibilities | Partial—General description of elected-auditor/expert split | Not addressed in reviewed documents | Present—Internal audit role defined within corporate governance |
Risk-based audit capacity | Present—The OECD recommends strengthening preventive risk-based control | Not addressed in reviewed documents | Partial—Risk management named among core functions |
Traceability of internal control | Partial—Recommended but described as needing strengthening | Not addressed in reviewed documents | Present—Control processes explicit in governance framework |
Reliability of financial reporting | Not addressed in reviewed documents | Not addressed in reviewed documents | Not addressed in reviewed documents |
Procurement compliance | Not addressed in reviewed documents | Not addressed in reviewed documents | Not addressed in reviewed documents |
Findings follow-up | Not addressed in reviewed documents | Not addressed in reviewed documents | Gap—NOAC found some authorities did not use monitoring tools to track findings |
Corrective-action capacity | Not addressed in reviewed documents | Not addressed in reviewed documents | Partial—NOAC’s emphasis on audit-trail systems implies a comparable gap |
Table 1, Table 2, Table 3, and Table 4 show that Malta’s documented gaps are concentrated in operational and follow-through criteria, including risk-based capacity, internal-control traceability, financial reporting, procurement compliance, and findings follow-up. The comparator evidence is uneven across criteria and should be read as a source of transferable institutional components rather than as a direct performance ranking.
This comparison shows that the most feasible option identified in this document-based comparison is not to establish separate municipal internal audit units. A more feasible model is a centrally coordinated hybrid internal audit approach that combines the standard and audit committee logic of the United Kingdom, the shared/regional capacity idea of the Netherlands, the professional auditor support of Sweden, the digital monitoring perspective of Estonia, and the findings follow-up mechanism of Ireland.
The model developed for Malta is based not on the assumption that the existing audit structure is entirely absent, but on the need to transform external audit, compliance review, and internal control activities into an integrated internal audit cycle. The NAO 2025 report noted that nine local councils had not submitted their audited financial statements for 2024 by the time the report was completed, that some deficiencies persisted over the years, and that procurement-related problems were identified in the compliance audits conducted in the Mellieħa, Nadur, and Xgħajra local councils (National Audit Office Malta, 2025). The Finance and Procurement Compliance Directorate within the LGD conducts compliance reviews, internal audits, and internal control improvement activities concerning the financial and procurement activities of local councils (Local Government Division, 2023). This institutional picture brings to the forefront a hybrid internal audit model for Malta that combines central coordination with the local implementation link.
The proposed model is based on a hybrid structure in which internal audit capacity is standardized at the central level and supported by local data, rather than being replicated as a separate unit in every local council. The OECD/SIGMA stated that the internal audit function could be adapted according to the type, size, and complexity of the institution and that shared internal audit services constituted a feasible option (OECD/SIGMA, 2023). In the Maltese context, this approach corresponds with the existing duties of the Finance and Procurement Compliance Directorate in compliance review, internal audit, on-site visits, and the follow-up of NAO recommendations (Local Government Division, 2023). The model combines this existing central capacity with internal control responsibility, risk data generation, and corrective action follow-up in local councils. Thus, internal audit functions not merely as a central oversight activity, but as a continuous assurance mechanism linked to local government processes.
The hybrid model is built on four institutional components. The first component is the central coordination role of the Finance and Procurement Compliance Directorate. Because this unit conducts compliance reviews, internal audits, on-site visits, and the coordination of action plan for the implementation of NAO recommendations concerning the financial and procurement activities of local councils, it forms the technical backbone of the model (Local Government Division, 2023). The second component is an internal control and compliance liaison point operating at the local council level; this liaison point supports document flow, data provision, and corrective action follow-up at the local level. The third component is the audit committee, which monitors audit plans, resource adequacy, and quality assessments. CIPFA states that the audit committee plays a central role in the oversight of internal audit arrangements (CIPFA, 2025). The fourth component is the NAO’s external assurance and financial audit function.
In the model, the internal audit process begins with the classification of risks in local councils’ financial reporting, procurement, asset management, debt management, and internal control areas. This classification constitutes the main input for the annual audit plan. IIA standards state that the internal audit plan has a risk-based and dynamic structure and is updated according to changes in the institution’s risk profile (Institute of Internal Auditors, 2024). The OECD/SIGMA also emphasizes that internal audit plans should be based on the assessment of risk management, governance, internal control, and reporting processes (OECD/SIGMA, 2023). Within this framework, the model operates through the stages of risk identification, audit planning, audit execution, findings reporting, corrective action development, implementation monitoring, and findings closure. The IIA follow-up standard is based on verifying the implementation of recommendations and action plans through a monitoring system (Institute of Internal Auditors, 2024).
Implementation of the proposed hybrid model should proceed incrementally to distinguish measures that could be introduced through existing administrative arrangements from reforms requiring more substantial institutional development. In the short term, priority should be given to administrative actions that build on the existing responsibilities of the Finance and Procurement Compliance Directorate. These include consolidating compliance reviews, internal audit findings, on-site review results, and NAO recommendations within a common finding register; introducing standardized corrective-action templates identifying the responsible unit and completion date; developing common risk classifications for local councils; and establishing a basic digital mechanism for monitoring the implementation and closure of recommendations. These measures largely strengthen existing processes and therefore do not depend on the creation of separate audit structures within each local council.
In the medium term, the model should move towards a more formalized risk-based assurance framework. Annual internal audit plans should be developed according to the risk profiles of local councils, while designated internal control and compliance liaison points should support data provision and corrective-action follow-up at the local level. Audit committee oversight should also be strengthened to review audit plans, adequacy of resources, implementation progress, and the closure of significant findings. At this stage, common performance indicators could be introduced to measure matters such as overdue recommendations, recurrence of findings, implementation time, and the completion of planned risk-based audits.
In the longer term, institutional reform should focus on embedding the hybrid model as a sustainable component of Malta’s local-government governance framework. This may include formalizing shared internal audit arrangements, strengthening the institutional position and independence of internal audit, establishing common quality-assurance requirements, and integrating risk, audit, corrective-action, and follow-up information within a continuous assurance framework. Any legislative or regulatory changes required to support these arrangements should be assessed at this stage in the light of implementation experience. The objective is therefore not immediate institutional restructuring, but a gradual progression from strengthened administrative coordination towards a mature, centrally coordinated, and locally connected internal audit system. (Institute of Internal Auditors, 2024).
6. Discussion
The results indicated that Malta’s central challenge was not the absence of audit mechanisms, but the limited connection among external audit, compliance review, internal control, and corrective action. Recurrent delays in financial reporting, procurement non-compliance, unresolved control weaknesses, and incomplete management responses showed that formal oversight did not consistently develop into a continuous assurance cycle (National Audit Office Malta, 2025). Meanwhile, the Finance and Procurement Compliance Directorate already performed compliance reviews, internal audits, on-site visits, and coordination relating to NAO recommendations (Local Government Division, 2023). The proposed hybrid model therefore built on existing central capacity while adding local responsibility for risk information, corrective action, and findings closure (See Figure 2).

Agency theory helps explain why clearer monitoring and follow-up are required when elected councils, executive management, central oversight bodies, and citizens hold different information and responsibilities (Eisenhardt, 1989; West & Berman, 2003). Institutional theory complements this interpretation: the coexistence of formal audit arrangements and recurrent operational weaknesses suggests that compliance structures have not yet been fully embedded as an ongoing assurance practice (DiMaggio & Powell, 1983). The comparison does not establish causal superiority among national models. Instead, it supports a context-specific design in which common standards and quality assurance are coordinated centrally while local councils remain responsible for risk data, internal controls, and timely corrective action.
7. Conclusions
This study examined the institutional position of the internal audit function in Malta’s local governments through the lenses of public financial management, internal control, risk management, and accountability. The research was done through qualitative document analysis and a comparative institutional analysis approach; institutional documents, audit reports, and selected country models related to Malta were evaluated together.
The findings revealed that the main problem in Malta was not the complete absence of audit mechanisms. The real issue is that external audit, compliance review, internal control, and corrective action processes are not sufficiently connected to a continuously operating integrated internal audit cycle. The delayed submission of financial statements, compliance problems in procurement processes, internal control weaknesses, and the fact that management responses do not always translate into concrete action plans emerged as the main indicators of this institutional gap.
The main contribution of the study is that it proposed a potentially applicable internal audit model for Malta. The proposed centrally coordinated hybrid model combined existing central technical capacity with data generation, internal control responsibility, risk-based planning, and findings follow-up in local councils. This structure appeared more realistic than establishing a separate internal audit unit in each local council, because Malta’s local government scale, financial capacity, and existing central oversight structure rendered a shared and coordinated model more feasible.
The main limitation of the study is that it relied on publicly available official documents rather than field interviews or survey data. Therefore, municipal-level implementation practices could not be observed directly. Future research involving interviews with local council managers, public officials responsible for audit, and representatives of the central administration could test the feasibility of the model more robustly.
From an implementation perspective, the proposed model should be developed progressively. Short-term administrative measures should prioritize standardized risk assessment, corrective-action planning, and digital findings follow-up within the existing institutional structure. Medium-term development should strengthen risk-based audit planning, local liaison arrangements, performance monitoring, and audit committee oversight. Longer-term reform should focus on institutionalizing shared internal audit capacity, quality assurance, and a continuous assurance framework appropriate to Malta’s administrative scale. This phased approach allowed the proposed model to be built on existing capacity while avoiding the costs and fragmentation associated with establishing separate internal audit units in each local council.
Conceptualization, Ö.Ş., E.Ö., and S.G.; methodology, Ö.Ş., E.Ö., and S.G.; validation, Ö.Ş., E.Ö., and S.G.; formal analysis, Ö.Ş., E.Ö., and S.G.; investigation, Ö.Ş., E.Ö., and S.G.; resources, Ö.Ş., E.Ö., and S.G.; data curation, Ö.Ş., E.Ö., and S.G.; writing—original draft preparation, Ö.Ş., E.Ö., and S.G.; writing—review and editing, Ö.Ş., E.Ö., and S.G.; visualization, Ö.Ş., E.Ö., and S.G.; supervision, Ö.Ş., E.Ö., and S.G.; project administration, Ö.Ş., E.Ö., and S.G. All authors have read and agreed to the published version of the manuscript.
The institutional documents analyzed in this study are publicly available through the sources cited in the reference list.
The authors declare no conflicts of interest.
AI was used for English-language editing and consistency checks.
