Implementation Guide for Internal Audits in Small Enterprises: The Practical Solution of 'Cross-Auditing' Chosen by a TPM-Listed Company with Under 30 Employees
It has been a while, this is Sannomiya. In my previous note, I talked about the overall schedule and practical processes for preparing for a TPM listing. This time, I will focus on and delve deeper into 'internal audits' specifically.
“Are internal audits really necessary for a company like ours?”
This was the question I heard most often within the company during the early stages of preparing for the listing. For a venture company with fewer than 30 employees, the word 'audit' can feel like something that has nothing to do with us. When I first faced this topic as CFO, I honestly thought, 'We don't have the capacity for that right now.'
However, as we proceeded with the listing preparations, the one point that was repeatedly questioned was, 'How do we incorporate internal audits into our systems and ensure their continuity?' In other words, what is required is not just 'doing it,' but 'being able to keep doing it.'
That said, we didn't have enough staff to appoint a dedicated auditor. That is why we chose the 'cross-audit' method. As a result, this mechanism also became a catalyst for fostering internal check-and-balance functions.
I am writing this note to provide information that will be at least somewhat useful to executives, CFOs, and administrative department managers of companies similar in size to NowVillage (under 30 employees) who are aiming for a TPM listing.
What is an Internal Audit (Difference from External Audit)
First, it is important to understand that 'internal audit' and 'external audit' are completely different things.
An external audit is conducted by an audit firm from a third-party perspective to confirm the fairness of financial statements. In contrast, an internal audit is a process where an independent internal organization directly under the Representative Director inspects business operations and leads to improvements.
I believe there are three main pillars of internal auditing.
One is “preventing risks before they occur.” This means nipping risks in the bud within business processes before fraud or losses occur. The second is “optimizing operations.” This involves improving systems so that business runs more efficiently and rationally. And the third is “confirming legal compliance.”.
I feel this third point is particularly important for small businesses. When a company conducts business, there are a wide variety of laws to follow, such as the Labor Standards Act, the Act on the Protection of Personal Information, the Subcontract Act, and the Act against Unjustifiable Premiums and Misleading Representations. However, in companies without a dedicated legal department, the reality is often that 'we think we are complying, but we have no opportunity to confirm it objectively.' Internal auditing is a mechanism to regularly check the status of compliance with laws and internal regulations, and to correct course before risks become apparent.
In NowVillage's internal audit regulations, the significance of internal auditing is defined as 'examining whether business operations and the management and preservation of assets are being efficiently implemented in appropriate compliance with predetermined standards such as laws, articles of incorporation, and various regulations' and aiming for the rationalization of management and the improvement of business efficiency.' It is a stiff expression, but in short, it means 'checking whether things are running properly in light of all rules, including laws and internal regulations, and trying to make them better.'
In NowVillage's actual audits, we confirm not only business processes but also whether internal regulations are being updated appropriately in line with legal amendments, and whether legal compliance corresponding to business characteristics is incorporated into daily operations.
I explained these to the company as “the company's health checkup.” It is not about looking for illness (fraud), but about reviewing lifestyle habits (systems). Compliance is also not about 'finding violations and punishing them,' but a process to 'check if we have drifted away from the rules without realizing it and return to the right direction.' This analogy seemed easy for the members to understand, and I feel it lowered the psychological hurdle toward internal audits a little.
TPM is a principle-based market. It is constantly asked whether things are 'actually functioning' and 'leading to improvements.' That is why the key is how to achieve effectiveness rather than just formality.
By the way, in TPM, the submission of an internal control report is optional. Compared to general markets (Prime, Standard, and Growth), the formal requirements are looser. However, that does not mean you don't have to do internal audits. J-Adviser has a mechanism to continue monitoring even after listing, and the effectiveness of corporate governance and internal management systems is continuously confirmed. My feeling is that 'it is optional in the system, but almost a must in practice.'
The Practical Solution of Cross-Auditing
Appointing a dedicated internal auditor was not realistic for our size. But we needed to have a check-and-balance function. That is why we adopted “cross-auditing.”
As I touched upon in my previous note, specifically, it is a mechanism where the directors in charge of the Consulting Division and the Administrative Division audit each other's departments. I (Administrative Division Director/CFO) audit the Consulting Division, and the Director/COO audits the Administrative Division. By swapping the 'auditor' and 'auditee' roles, we make mutual checks function as a system.
The advantage of this method is that because you understand your own department well, your eyes become sharper when looking at other departments. Conversely, having your own department viewed through the eyes of others allows you to notice improvements in operations that you previously took for granted.
The first year was a process of trial and error. The audit checklist wasn't perfect, and we operated with the spirit of 'let's just do it.' We didn't aim for 100 points from the start; we operated at 70 points and improved from there. This is a stance we have valued throughout our entire IPO preparation process, and it was exactly the same for internal audits.
Within the company, there were voices asking, 'What exactly should I be checking here?' By sharing the purpose of 'why we are checking this item' so that it wouldn't become a mere formality, the audit gradually became something that everyone took ownership of.
Annual Cycle of Internal Audits

It is important that internal audits are not a 'one-time event' but a mechanism that runs on an annual basis. At NowVillage, we run our one-year cycle based on our internal audit regulations using the following flow.
First is the Planning Phase. At the beginning of the fiscal year, we create an 'Internal Audit Plan' that includes the audit policy, target departments, objectives, items, methods, schedule, and auditors, and obtain approval from the Representative Director and President. We created separate plans for the Administration Department and the Consulting Division. The key is to determine the priority items to check based on the results of the previous audit, changes in the business environment, and the status of legal amendments.
Next is the Notification and Preparation Phase. We send an 'Internal Audit Implementation Notice' to the auditee department, which includes the audit scope, schedule, and auditors. By notifying them in advance, they can prepare the necessary documents and materials.
Then comes the Audit Implementation Phase. We proceed mainly through on-site verification, document review, and interviews. At NowVillage, we started with interviews of department heads regarding their operational status, and then comprehensively reviewed relevant documents and checked operational status in areas such as HR/labor, accounting/payments, contract management, and information security.
After the audit is the Reporting Phase. We create an 'Internal Audit Report,' summarizing the audit results, overall findings, points of concern, and recurrence prevention measures, and report them to the Representative Director and President. If improvements are needed, we send an 'Improvement Instruction' to the head of the auditee department.
Following that is the Improvement Phase. The auditee department creates an 'Improvement Plan and Report,' indicating a concrete improvement schedule and countermeasures.
Finally, there is the Confirmation and Follow-up Phase. We verify whether the improvements are actually being implemented and report to the Representative Director and President as a 'Confirmation Report on Improvement Status.' Furthermore, at NowVillage, we also conduct a 'Follow-up Audit' every time. This involves re-verifying the continuity of business operations after a certain period has passed since the departmental audit, and it is formally incorporated into our annual schedule.
Plan -> Notice -> Audit Implementation -> Report -> Improvement Instruction -> Improvement Plan -> Confirmation of Improvement Status -> Follow-up Audit. This series of processes completes the one-year cycle.
Honestly, when I first saw this flow, I thought, 'Do we really have to create this many documents?' But once we actually ran it, I understood well that each one has meaning. In particular, the mechanism of tracking everything from improvement instructions to improvement plans, improvement confirmation, and follow-up audits in a single, integrated flow is essential to ensure we don't just 'point out issues and stop there.'
The first year was honestly hectic, but from the second year onwards, we were able to run it much more smoothly. If you organize document formats as standard templates, you only need to reflect improvements based on the previous year. It's unglamorous, but this preparation is the key to continuity.
What We Learned from the Administration Department Audit
In the audit of the Administration Department, the Director and COO served as the auditor and comprehensively checked all business operations. Specifically, we conducted reviews mainly through document inspection and interviews regarding the operational status of HR and labor management (attendance management, confirmation of payroll-related vouchers, confirmation of HR-related regulations), the operational status of accounting operations and payment flows, and information security (confirmation of PC security systems).
As a result, no major issues were identified in the areas of Board of Directors operations, minutes management, accounting processes, HR and labor management, contract management, or security management.
On the other hand, we also found 'points that could be improved further.'
One was the improvement of how regulations are communicated. Although the revisions themselves were carried out appropriately, an improvement theme emerged regarding whether we could further strengthen the mechanism to ensure that revision details reach employees. In response to this, we newly constructed a notification flow for when regulations are changed and organized the folders where regulations are stored.
Another was the systematization of information security training. While the operation of access management and password management itself was appropriate, we decided to incorporate regular training as a mechanism to further raise the overall security awareness of employees.
In none of these cases were there "major problems"; rather, these were preventive improvements made with the mindset of "let's get our systems in order while we can." I believe this is a perfect example of how an audit can function as a "catalyst for improvement."
What We Learned from the Consulting Division Audit
I (the CFO) was in charge of the audit for the Consulting Division. I conducted a comprehensive review of the entire business process, from contract execution to service delivery and invoicing, as well as the management status of related supporting documents.
As a result, we found that proper processes were maintained for contract management, and the practice of exchanging memoranda when changing terms was functioning effectively. In billing management, the supervisor approval flow was working reliably, with no missed or duplicate invoices. Regarding delivery management, consistency between delivery notes and order details was also ensured.
The improvement theme that emerged was the visualization of project progress. As the number of projects increased, the direction was to establish a system that would allow the entire department to grasp progress in real-time.
We formulated an improvement plan and proceeded in stages. This included selecting and introducing a project management tool, establishing operational rules, training staff on its use, building a system for sharing and reporting project progress, and ensuring adoption through follow-up training. Ultimately, a practice where the division manager checks progress weekly took root, and we have confirmed the effectiveness of these improvements.
It was an unexpected benefit that the audit served as a catalyst for organizing and strengthening the business flow itself.
The Evolution Felt in the Second Year of Internal Audits
Up to this point, I have focused on the first year, but in the second year, the internal audit itself has certainly evolved based on the experience of the first year. I would like to introduce this process of growth, as I believe it is the real thrill of internal auditing in small businesses.
First, expansion of audit items. In the management department audit, the first year focused on three areas: HR, accounting, and information security. In the second year, this expanded to four areas by adding "management status of contracts and important documents" and "status of information management and internal checks (including responses to the risk of business personalization)." Because we solidified the foundation in the first year, we were able to conduct audits with a broader perspective in the second year.
Next, deepening of audit objectives. In the first year, the focus was mainly on two points: "whether business processes comply with internal regulations" and "whether mutual checks are functioning." In the second year, a perspective was added: "to grasp whether business operations are being conducted rationally and appropriately from the viewpoint of company-wide governance and risk management." This is a higher-level perspective that evaluates management tasks within the context of the entire company, rather than just individual regulatory compliance.
And finally, formal scheduling of follow-up audits. From the second year, we clearly positioned this in our annual plan: "March-May: Departmental Audit," "July-September: Follow-up Audit," and "December: Organizing Next Year's Plan." We check the operational status of the items confirmed in the departmental audit again six months later. This has made the "audit -> improvement -> establishment" flow more reliable.
In fact, the second-year management department audit resulted in the finding that "no major deficiencies requiring immediate correction were identified." This is proof that the methods for disseminating regulations and the systematization of security training, which were improvement themes in the first year, have been firmly established.
There is no need to aim for a perfect audit from the start. However, you must ensure it evolves every year. I have realized through my two years of practical experience that this accumulation of efforts eventually builds a robust governance system.
The Relationship Between Internal Control and Internal Audit
Internal control and internal audit are closely related, but their roles are different. Internal control is a mechanism for setting "rules", while internal audit is a mechanism for checking whether those rules are being followed.
The four areas that small businesses should prioritize are: approval processes, expense reimbursement rules, contract execution and management methods, and attendance and labor management systems.
What is important here is "leaving an audit trail of operations". Simply by clearly stating "who, when, and what decision was made" in approval documents and records, the credibility from an external perspective changes significantly. If audit trails are properly maintained, audits will also proceed smoothly.
Furthermore, adding revision history and version control to regulations and forms shows that they are not just created and forgotten, but are actually being used. As I have mentioned in past notes, from my experience of creating and organizing over 50 regulations, I can say that "whether the created regulations are actually being used" is more important than anything else.
Set up rules and check their operation through audits. This two-pronged approach is an essential foundation for proceeding with IPO preparations.
Start with the form, then cultivate the substance
From a management perspective, I felt strongly about the importance of not seeking perfection, but first establishing a structure.
At NowVillage, we first prepared the forms stipulated in our internal audit regulations (audit notices, audit reports, audit records, audit result notifications, improvement status reports, etc.) and started by running the process according to those formats for one year. At first, just "filling out the formats" was difficult, but from the second year on, we were able to manage by simply reflecting improvements based on the previous year's documents. And indeed, in the second year, we expanded our audit items, deepened our audit objectives, and scheduled follow-up audits, and the quality of the audits themselves steadily improved.
Another thing I was conscious of was incorporating audit reports into monthly reviews. It is not just about submitting a report and being done with it; management must regularly check the results and follow up on improvements. This operation, where management remains involved, is the key to supporting continuity.
Before starting internal audits, I was concerned that "the burden would increase." However, in reality, business visualization progressed, and the speed of decision-making increased. The methods for disseminating regulations were improved, and systems for project management were organized. Both of these are "improvements that might have been put off if not for the audit."
Audit does not equal surveillance; audit equals a mechanism for improvement. This was a major realization for me as well.
Summary
Finally, I would like to summarize what I wanted to convey in this note.
For internal audits, a "workable mechanism" is more important than a "perfect mechanism". Even in small businesses, you can institutionalize mutual checks through "cross-audits." An audit is not a "check" but a "trigger for improvement." Complete the one-year cycle from the audit plan to the follow-up audit. And every year, improve the quality of the audit itself little by little. By having management remain involved, continuity and reliability are born.
Internal audit is not something you are "forced to do," but a "mechanism to protect the company." Even if it is imperfect, start by trying it. That first step becomes the foundation that supports governance after listing.
I hope this note provides some encouragement to companies aiming for a TPM listing. If you have any specific questions, please feel free to contact me!
※ This article is based on the personal experience of NowVillage Co., Ltd. and is not intended as professional advice regarding listing preparation or management. The details of internal audit and internal control development vary depending on the size and industry of the company. For individual judgments, please consult with experts such as a J-Adviser or an audit firm.
