دليل الرقابة الداخلية والتدقيق الداخليA Guide to Internal Controls & Internal Audit
دليل يشرح الرقابة الداخلية كممارسة إدارية لا كإجراء شكلي — من فهم بيئة الرقابة إلى تصميم الضوابط واختبار فعاليتها وبناء وظيفة تدقيق داخلي فعّالة.A guide explaining internal control as a management practice rather than a formality — from understanding the control environment to designing controls, testing their effectiveness and building an effective internal audit function.
آخر مراجعة: 2026-09-18Last reviewed: 2026-09-18
كيف تبني منظومة رقابة داخلية؟How do you build an internal control system?
ابدأ بالدورات الحرجة الأربع: الإيرادات، المشتريات، الرواتب، المخزون. وثّق ما هو قائم فعلياً، ثم ابنِ مصفوفة تربط كل خطر بالضابط الذي يعالجه مع مالك ودليل متوقع. ثم اختبر الفعالية على عينة وحدد الفجوات. الضابط بلا دليل لا يمكن إثباته أمام مدقق، والضابط الذي لا يُنفَّذ أسوأ من عدمه.Start with the four critical cycles: revenue, procurement, payroll and inventory. Document what actually exists, then build a matrix linking each risk to the control addressing it with an owner and expected evidence. Then test effectiveness on a sample and identify gaps. A control without evidence cannot be demonstrated to an auditor, and a control not executed is worse than none.
محتويات الدليلContents
ما هي الرقابة الداخلية فعلاًWhat Internal Control Actually Is
- ضوابط وقائية — تمنع الخطأ قبل وقوعه (فصل المهام، الاعتماد المسبق)Preventive controls — stop the error before it occurs (separation of duties, prior approval)
- ضوابط كاشفة — تكتشف الخطأ بعد وقوعه (التسويات، المراجعة الدورية)Detective controls — detect the error after it occurs (reconciliations, periodic review)
- ضوابط تصحيحية — تعالج الخطأ بعد اكتشافه (خطة المعالجة، التصحيح)Corrective controls — address the error once detected (remediation plan, correction)
بيئة الرقابة: المكونات الخمسةThe Control Environment: Five Components
- بيئة الرقابة — النزاهة والقيم والهيكل والمساءلة من القمةControl environment — integrity, values, structure and accountability from the top
- تقييم المخاطر — تحديد المخاطر التي تهدد الأهداف وتحليلهاRisk assessment — identifying and analysing risks to objectives
- أنشطة الرقابة — السياسات والإجراءات التي تعالج المخاطرControl activities — policies and procedures that address the risks
- المعلومات والتواصل — تدفق المعلومات الصحيحة للأشخاص المناسبينInformation and communication — the right information reaching the right people
- المتابعة — تقييم مستمر أو دوري لفعالية الضوابطMonitoring — ongoing or periodic evaluation of control effectiveness
مصفوفة المخاطر والضوابطThe Risk and Control Matrix
| العمود | الوصف |
|---|---|
| معرّف الخطر | رقم مرجعي ثابت |
| وصف الخطر | الحدث المحتمل وسببه الجذري |
| التقييم | الأثر × الاحتمالية |
| الضابط | الإجراء الذي يمنع أو يكشف الخطر |
| نوع الضابط | وقائي / كاشف / تصحيحي |
| التكرار | يدوي / آلي · يومي / شهري / سنوي |
| المالك | من المسؤول عن تنفيذ الضابط |
| الدليل | ما يُثبت أن الضابط نُفّذ |
تصميم الضوابط: القواعد العمليةDesigning Controls: Practical Rules
- اجعل الضابط جزءاً من العمل لا إجراءً إضافياً منفصلاًMake the control part of the work, not a separate add-on procedure
- فضّل الضوابط الآلية داخل النظام على الضوابط اليدويةPrefer automated controls inside the system over manual ones
- حدد مالكاً واحداً لكل ضابط — لا مسؤولية جماعيةAssign a single owner per control — no collective responsibility
- وثّق الدليل المتوقع من الضابط منذ التصميمDocument the expected evidence from the outset
- راجع التكلفة مقابل الفائدة — ليس كل خطر يحتاج ضابطاً معقداًReview cost versus benefit — not every risk needs a complex control
بناء وظيفة تدقيق داخليBuilding an Internal Audit Function
- ميثاق معتمد يحدد النطاق والصلاحيات والمسؤولياتAn approved charter defining scope, authority and responsibilities
- استقلالية تنظيمية — التقارير لمجلس الإدارة أو لجنة المراجعةOrganizational independence — reporting to the board or audit committee
- خطة مبنية على المخاطر لا على الطلباتA risk-based plan, not a request-driven one
- منهجية عمل موثقة وبرامج تدقيق تفصيليةA documented methodology and detailed audit programmes
- نظام متابعة لإغلاق الملاحظاتA follow-up system to close findings
- قياس جودة الوظيفة ذاتياًInternal quality assessment of the function
الأدوار الثلاثة: من يفعل ماذاThe Three Roles: Who Does What
خلط الأدوار هو أكثر ما يُفشل منظومة الرقابة. ثلاثة أدوار يجب أن تكون منفصلة بوضوح:Confusing roles is the most common cause of control failure. Three roles must be clearly separated:
,| الدور | المسؤولية | لا يفعل |
|---|---|---|
| الإدارة التنفيذية | تصميم الضوابط وتنفيذها وامتلاك المخاطر | لا تقيّم فعالية ضوابطها بنفسها بشكل مستقل |
| إدارة المخاطر والامتثال | تحديد الإطار، تجميع المخاطر، مراقبة الالتزام | لا تنفّذ العمليات ولا تدققها |
| التدقيق الداخلي | تقييم مستقل لفعالية الضوابط | لا يصمم الضوابط ولا ينفّذها |
مبدأ «خطوط الدفاع الثلاثة» يلخص ذلك: العملية تحمي نفسها، والرقابة تراقب، والتدقيق يقيّم. إذا دمجت اثنين منهم، فقدت الاستقلالية.The “three lines of defence” principle summarises this: the business protects itself, compliance oversees, and audit assesses. Merge any two and you lose independence.
اختبار فعالية الضوابطTesting Control Effectiveness
وجود الضابط ليس كافياً. السؤال: هل يعمل فعلاً؟ الاختبار يجيب على سؤالين:The existence of a control is not enough. The question is: does it actually work? Testing answers two questions:
,- فعالية التصميم: هل الضابط مصمم بطريقة تمنع أو تكشف الخطأ؟Design effectiveness: is the control designed in a way that prevents or detects the error?
- الفعالية التشغيلية: هل نُفّذ فعلاً خلال الفترة؟ ومن قام به؟Operating effectiveness: was it actually performed during the period? By whom?
طريقة الاختبار: عينة من المعاملات خلال الفترة، مع فحص الدليل على التنفيذ — توقيع، طابع زمني، سجل نظام، أو مرفق. إذا كان الضابط آلياً، فالدليل هو إعداد النظام نفسه وليس توقيعاً.The testing method: a sample of transactions over the period, examining evidence of execution — a signature, a timestamp, a system log, or an attachment. If the control is automated, the evidence is the system configuration itself, not a signature.
كيف تعرف أن لديك ضعفاً رقابياًHow to Recognise a Control Weakness
الضعف الرقابي ليس خطأً واحداً — هو ثغرة تسمح بالخطأ أو التجاوز دون اكتشاف. المؤشرات:A control weakness is not a single error — it is a gap allowing error or override to go undetected. The indicators:
,- نفس الملاحظة تتكرر في كل مراجعةThe same finding repeats every review
- تجاوزات متكررة من الإدارة تُبرَّر بالاستعجالFrequent management overrides justified by urgency
- ملاحظات لا تُغلق أو تُغلق شكلياً بلا معالجة جذريةFindings never closed, or closed nominally without root remediation
- تركيز الصلاحيات في شخص أو اثنينAuthority concentrated in one or two people
- غياب دليل التنفيذ — الضابط موجود لكن لا يُوثَّقNo evidence of execution — the control exists but is not documented
- غياب الفصل بين من ينفّذ ومن يعتمد ومن يراجعNo separation between executing, approving and reviewing
الضعف الأكثر خطورة هو الذي تعرف به ولا تعالجه، لأنك فقدت حجة «لم نكن نعلم».The most serious weakness is the one you know about and do not address, because you have lost the defence of not knowing.
خارطة طريق لبناء الرقابة الداخليةA Roadmap for Building Internal Control
بناء منظومة رقابة كاملة يستغرق وقتاً. التسلسل العملي:Building a complete control system takes time. The practical sequence:
,| المرحلة | المخرجات | المدة النموذجية |
|---|---|---|
| الأولى — التقييم | فهم العمليات الحرجة، تحديد المخاطر، تقييم البيئة الرقابية | 3–6 أسابيع |
| الثانية — التصميم | مصفوفة المخاطر والضوابط، توثيق الضوابط، تحديد المالكين | 4–8 أسابيع |
| الثالثة — التنفيذ | تطبيق الضوابط، تدريب الفرق، تعديل إعدادات الأنظمة | 6–12 أسبوعاً |
| الرابعة — الاختبار | اختبار الفعالية على عينة، تحديد الفجوات المتبقية | 3–6 أسابيع |
| الخامسة — المتابعة | تقرير دوري، مراجعة مستقلة، تحسين مستمر | مستمر |
ابدأ بالعمليات الحرجة فقط — الإيرادات، المشتريات، الرواتب، المخزون. تغطية هذه الأربع تغطي معظم المخاطر الجوهرية في أي منشأة.Start with critical processes only — revenue, procurement, payroll, inventory. Covering these four addresses most significant risks in any organization.
تنبيه مهم حول نطاق الخدمةImportant Note on Scope
الدورات الأربع الحرجةThe Four Critical Cycles
إذا كانت الموارد محدودة، فابدأ بهذه الدورات الأربع — تغطي معظم المخاطر الجوهرية في أي منشأة:If resources are limited, start with these four cycles — they cover most significant risks in any organization:
,| الدورة | الخطر الرئيسي | الضوابط الأساسية |
|---|---|---|
| الإيرادات | إيراد مسجّل دون استحقاق أو غير مسجّل | فصل الاعتماد · مطابقة الفواتير · مراجعة الإيرادات المؤجلة |
| المشتريات | شراء غير مصرّح أو بسعر غير متفق عليه | طلب شراء معتمد · ثلاثة عروض · مطابقة أمر الشراء بالفاتورة |
| الرواتب | موظف وهمي أو صرف غير مستحق | مطابقة كشف الرواتب بالموارد البشرية · فصل الإعداد عن الصرف |
| المخزون | فقد أو تحريف قيمة المخزون | جرد دوري مفاجئ · مطابقة النظام بالواقع · فصل الاستلام عن التسجيل |
كل دورة من هذه الأربع تحتوي على تعارضات فصل مهام يجب حلها — وهذا ما يُختبر عادة في أي مراجعة.Each of these four contains segregation-of-duties conflicts that must be resolved — and this is what is typically tested in any review.
التوثيق الذي يفيد فعلاًDocumentation That Actually Helps
التوثيق ليس لجمع الملفات. التوثيق الجيد يجيب على ثلاثة أسئلة بسرعة:Documentation is not about collecting files. Good documentation answers three questions quickly:
,- من يفعل ماذا؟ — مصفوفة الأدوار والمسؤوليات لكل عمليةWho does what? — a roles and responsibilities matrix per process
- ما الخطوات؟ — إجراء مكتوب يمكن لموظف جديد تنفيذهWhat are the steps? — a written procedure a new employee can follow
- ما الدليل؟ — ما يُثبت أن الخطوة نُفّذت ومن قام بها ومتىWhat is the evidence? — what proves the step was performed, by whom and when
معيار عملي: إذا احتاج موظف جديد أكثر من يوم ليفهم إجراءً، فالتوثيق غير كافٍ. وإذا لم يستطع المدقق إيجاد الدليل خلال دقائق، فالأرشيف غير منظّم.A practical test: if a new employee needs more than a day to understand a procedure, the documentation is insufficient. If an auditor cannot find the evidence within minutes, the archive is not organised.
الثقافة: العامل الذي لا يُوثَّقCulture: The Factor That Is Not Documented
يمكنك كتابة أفضل الضوابط وشراء أفضل الأنظمة، لكن إذا كانت الثقافة تتجاوز القواعد فكل شيء ينكسر عند أول اختبار.You can write the best controls and buy the best systems, but if the culture overrides the rules everything breaks at the first test.
,- هل يُسأل عن تجاوز الإجراء، أم يُبارك لمن «أنجز بسرعة»؟Is an override questioned, or is someone praised for “getting it done fast”?
- هل تُغلق الملاحظات بمعالجة حقيقية أم بتبرير مكتوب؟Are findings closed with real remediation or with a written justification?
- هل يمكن للموظف الإبلاغ عن مخالفة دون خوف من الأثر؟Can an employee report a violation without fear of consequence?
- هل الإدارة العليا تخضع لنفس الضوابط أم تستثني نفسها؟Does senior management follow the same controls or exempt itself?
- هل يُقاس الأداء بالنتيجة فقط أم بالنتيجة والالتزام؟Is performance measured by result alone, or by result and compliance together?
المؤشر الأقوى على ثقافة رقابة صحية: أن يستخدم المدير التنفيذي نفسه قناة الاعتماد الرسمية بدل تجاوزها.The strongest indicator of a healthy control culture: the executive uses the official approval channel rather than bypassing it.
خدمات مرتبطةRelated Services
أدوات وقوالب مجانيةFree Tools & Templates
الأسئلة الشائعةFAQ
هل الرقابة الداخلية إلزامية؟Is internal control mandatory?
قد تكون إلزامية بحسب الشكل النظامي والقطاع والجهة الرقابية. لكن حتى حيث لا تكون إلزامية، فهي ممارسة إدارية سليمة تحمي الأصول ودقة التقارير.It may be mandatory depending on legal form, sector and regulator. Even where not mandatory, it is sound management practice protecting assets and reporting accuracy.
ما الفرق بين التدقيق الداخلي والخارجي؟What is the difference between internal and external audit?
التدقيق الداخلي وظيفة مستقلة داخل المنشأة تراجع الضوابط والمخاطر لصالح الإدارة ومجلس الإدارة. التدقيق الخارجي يصدر رأياً نظامياً على القوائم المالية من مكتب مرخص.Internal audit is an independent function inside the entity reviewing controls and risk for management and the board. External audit issues a statutory opinion on the financial statements from a licensed firm.
هل نحتاج وظيفة تدقيق داخلي كاملة؟Do we need a full internal audit function?
ليس بالضرورة. في المنشآت الصغيرة قد يكفي نموذج مخفّف — مراجعة دورية مستقلة للضوابط الحرجة. نحدد الأنسب بحسب الحجم والمخاطر.Not necessarily. In smaller organizations a lighter model may suffice — periodic independent review of critical controls. We define what fits your size and risk.
كيف نبدأ إذا لم يكن لدينا أي ضوابط موثقة؟How do we start with no documented controls?
نبدأ بتوثيق ما هو قائم فعلياً — حتى لو لم يكن مكتوباً — ثم نحدد الفجوات ونبني خطة معالجة مرتبة بحسب الأثر لا بحسب السهولة.We start by documenting what actually exists — even if unwritten — then identify gaps and build a remediation plan ordered by impact, not ease.
ما المؤشر على أن بيئة الرقابة ضعيفة؟What indicates a weak control environment?
تكرار نفس الملاحظات في كل مراجعة، تجاوزات متكررة من الإدارة، غياب إغلاق للملاحظات، وتركيز الصلاحيات في أشخاص محددين.The same findings repeating every review, frequent management overrides, findings never closed, and authority concentrated in specific individuals.
المصادر الرسميةOfficial Sources
نوصي بالرجوع إلى المصدر الرسمي والأحدث دائماً، فالأطر والأنظمة تُحدَّث دورياً.We recommend always referring to the current official source, as frameworks and regulations are updated periodically.
تحتاج مساعدة في تطبيق هذا على مؤسستك؟Need Help Applying This to Your Organization?
نراجع وضعك الراهن ونساعدك على ترتيب الأولويات وبناء خطة عمليةWe review your current position, help prioritise, and build a practical plan

