Workflow
三六零: 三六零安全科技股份有限公司内部审计制度

Core Points - The internal audit system of the company aims to enhance internal management and risk control, standardize internal audit work, improve audit quality, and protect investors' legal rights [1][2] - The internal audit applies to all business activities related to financial reporting and information disclosure across various departments, subsidiaries, and holding companies [1][2] - The internal audit is defined as an evaluation activity conducted by internal personnel to assess the effectiveness of internal controls and risk management, as well as the authenticity and completeness of financial information [1][2] Group 1: Internal Audit Organization and Responsibilities - The company has established an internal audit department responsible for supervising business activities, risk management, internal controls, and financial information [2][3] - The internal audit department reports directly to the board of directors and must maintain independence from the finance department [3][4] - The internal audit department is tasked with evaluating the integrity and effectiveness of internal control systems and auditing financial and economic data for legality and compliance [2][3][4] Group 2: Internal Audit Procedures and Methods - The internal audit department must develop an audit plan and form audit teams to conduct audits based on established objectives [7][8] - Audit methods include attending important meetings, requesting documentation, interviews, and on-site inspections [7][8] - After completing an audit, the audit team must prepare a report that is objective, clear, and based on sufficient evidence [7][8] Group 3: Internal Control Evaluation - The internal audit department is responsible for organizing and implementing internal control evaluations, which must be reported to the audit committee [5][6] - The evaluation report includes the board's declaration of the report's authenticity and must be disclosed alongside the annual report [5][6] - The internal audit department must monitor the implementation of corrective measures for identified internal control deficiencies [6][7] Group 4: Record Management and Accountability - Audit work papers and reports must be archived according to national regulations, with a retention period of no less than ten years [8][9] - The company will supervise and evaluate the performance of internal audit personnel, rewarding those who perform well and penalizing those who abuse their power [9]