This chapter reviews the organisation, mechanisms, and practices of government internal control and external oversight in the Dominican Republic. The chapter explores how to strengthen internal control and risk management, emphasising the need to incorporate integrity into internal control and adopt a shared vision of integrity risks and their treatment. It also offers recommendations for strengthening the internal audit function and its role in promoting integrity and internal control. The chapter also examines the work of the Chamber of Accounts of the Dominican Republic and explores ways to strengthen the entity by taking advantage of its new law, taking measures to ensure that its external audits achieve greater quality, reliability and use, and enhancing public outreach.
OECD Integrity Review of the Dominican Republic
6. Strengthening risk management and auditing
Copy link to 6. Strengthening risk management and auditingAbstract
6.1. Introduction
Copy link to 6.1. IntroductionAt a time when governments around the world are operating under considerable financial constraints and must do more with less, public sector organisations are forced to optimise their resources in an effective and financially responsible manner. Consequently, the OECD Recommendation on Public Integrity urges its adherents to “implement an internal control and risk management framework to protect integrity in public sector organisations” (OECD, 2017[1]). A public internal control system and risk management framework requires institutions to develop internal control policies and practices to support sound management, ensure compliance with applicable rules, safeguard public assets, and achieve organisational objectives. In doing so, it helps prevent waste, inefficiency and the misuse of public resources, while strengthening the value delivered to citizens.
Having an internal control system and risk management framework in public sector organisations is essential to any public integrity strategy (OECD, 2020[2]). Effective internal control and risk management policies and processes reduce the vulnerability of public sector organisations to fraud and corruption, while ensuring that governments operate optimally to deliver programmes that benefit citizens (OECD, 2020[2]). Internal control systems and risk management frameworks serve government and organisational objectives, enabling the proper delivery of goods and services to the population. These policies and processes also help ensure cost-effectiveness and facilitate decision-making. When firmly established, they help governments implement effective risk-based preventive approaches.
The following are critical components of an internal control system and risk management framework designed to safeguard integrity (OECD, 2020[2]):
An effective control environment and integrity risk management framework.
An approach tailored to risk management and integrity risk assessments.
Monitoring and evaluation of the integrity risk management framework.
Consistent and responsive procedures within the internal control and integrity risk management framework.
An internal audit function that is clearly separated from operations and provides independent and objective assurance and advice to strengthen internal control and the integrity risk management framework.
Regarding the latter, the internal audit function examines the adequacy and effectiveness of public sector organisations’ internal control systems, procedures, governance arrangements, risk management processes, and performance of operations (Institute of Internal Auditors, 2024[3]). Internal audit’s role is therefore expected to extend beyond compliance-oriented, rules-based approaches to assessing controls. This contemporary view of internal auditing captures the broader value that the function can add to an organisation (OECD, 2020[2]). Internal audit can contribute not only to the achievement of financial objectives and control of resources, but also to improved decision-making and risk management in support of the organisation's overall strategic and operational objectives (OECD, 2020[2]).
In addition, internal auditors should assess the effectiveness of the organisation's integrity-related objectives and activities, and the processes for promoting integrity and values (OECD, 2020[2]). This may include, for example, broad assessments of the effectiveness of the governance structure in fostering a culture of integrity, audits of integrity processes and mechanisms such as whistleblowing mechanisms, or staff training and awareness programmes for integrity. Conversely, internal auditors are not expected to be investigators. While internal auditors should have sufficient knowledge to assess fraud risk factors and fraud risk management in the organisation, they are not required to have the knowledge or expertise necessary to take on an investigative role. Nor are internal auditors expected to be internal controllers. Their role is to provide advice at the highest level, based on objective techniques and methodologies and independent judgement. Internal auditing strengthens the organisation's ability to create, protect and maintain value by providing the organisation's management with independent, risk-based and objective assurance, advice, insight and foresight (Table 6.1).
Table 6.1. The role of the internal auditor in integrity risk management
Copy link to Table 6.1. The role of the internal auditor in integrity risk management|
Core internal audit roles |
Providing independent assurance of the effectiveness and efficiency of risk management processes |
|
Evaluating risk management processes |
|
|
Evaluating the reporting of key risks |
|
|
Reviewing the management of key risks |
|
|
Making recommendations to improve risk management |
|
|
Legitimate internal audit roles with safeguards |
Facilitating identification and evaluation of risks |
|
Coaching management in responding to risks |
|
|
Consolidating risk reports |
|
|
Developing and updating the risk management framework |
|
|
Championing risk management practices |
|
|
Roles internal audit should not undertake |
Setting risk criteria |
|
Imposing risk management processes |
|
|
Carrying out risk assessments for managers |
|
|
Deciding how to mitigate or respond to risks |
|
|
Implementing risk mitigation measures for management |
Source: Adapted from (Institute of Internal Auditors, 2009[4])
The role of the internal audit function can be guided by the Three Lines Model (Figure 6.1) promoted by the Institute of Internal Auditors (IIA) (Institute of Internal Auditors, 2020[5]). The model helps organisations identify the roles, responsibilities and processes that best facilitate the achievement of objectives and promote sound governance and risk management. The advantages of the model highlight the contribution of risk management to the achievement of objectives, as well as to the creation and protection of value. It also helps to clearly understand organisational roles and responsibilities in control and their relationships.
Figure 6.1. Three Lines Model
Copy link to Figure 6.1. Three Lines ModelIn addition to an internal control system, a Supreme Audit Institution (SAI) has the mandate to perform independent external oversight, overseeing the use of public resources and holding governments to account (OECD/IDI, 2026[6]). SAIs can also contribute to the effectiveness of internal control and risk management. SAIs provide opinions on the regularity of financial statements and assesses whether government performance meets the criteria of efficiency, economy and effectiveness. As SAIs determine whether public entities are fulfilling their governance responsibilities, they are well positioned to provide the external oversight to inform the effectiveness of internal controls and integrity risk management practices.
The Dominican Republic has a structure of internal audit, internal control and external oversight, comprising the following entities and units:
Comptroller General of the Republic (Contraloría General de la República, CGR) as the governing body for internal control of the Executive Branch. Within the CGR, different directorates and areas deal with issues related to risk management, internal control and internal audit:
CGR’s Internal Audit Directorate (Dirección de Auditoría Interna, DAI) carries out the internal audit function, as established in Article 27 of Law No. 10-2007. The DAI is responsible for assessing and examining compliance with policies, guidelines, internal controls, procedures, and the identification and management of risks in institutions within the scope of Law No. 10-2007.
CGR’s Directorate of Government Internal Audit Units (Dirección de Unidades de Auditoría Interna Gubernamentales, DUAIG). Within the DUAIG, Internal Audit Units (unidades de auditoria interna, UAIs) are primarily responsible for ex ante controls, including the verification of payment orders and other responsibilities established in Law No. 10-2007. Although these units are established and embedded within public entities, they belong administratively, functionally and technically to the CGR.
CGR's Anti-Fraud Unit (Unidad Antifraude) conducts special administrative investigations to provide recommendations to mitigate fraud and corruption risks. The unit collaborates consistently with the Specialised Prosecutor's Office for the Prosecution of Administrative Corruption (Procuraduría Especializada de Persecución de la Corrupción Administrativa, PEPCA) of the Prosecutor General's Office (Procuraduría General de la República) through executive reports that may lead to criminal investigations.
CGR’s Directorate for Regulatory Development (Dirección de Desarrollo Normativo, DDN) responsible for drafting, updating and issuing the basic standards and guidelines of internal control, as well as the standards and guidelines governing government internal audit, in accordance with the legal framework and international standards.
Chamber of Accounts of the Dominican Republic (Cámara de Cuentas de la República Dominicana, CCRD) is the SAI of the Dominican Republic. As an autonomous constitutional body, the CCRD exercises external oversight over public resources, administrative processes and public assets.
This chapter highlights the progress made as well as the main challenges facing the country's control system to make recommendations on risk management and internal control, as well as on internal and external auditing. The recommendations emphasise the importance of the Dominican Republic adopting public integrity as a government objective that extends to all public entities, supported by the governing body for internal control (i.e. the CGR), promoting institutional ownership and accountability for the performance of policies, mechanisms, and processes for the prevention, detection and sanction of breaches of integrity. Along with this, it proposes that the external control body (i.e. the CCRD) strengthen the quality and transparency of its independent oversight activities in relation to the public.
6.2. Strengthening integrity risk management and internal control
Copy link to 6.2. Strengthening integrity risk management and internal controlThe OECD Recommendation on Public Integrity calls for public entities to have internal control systems in place, manage integrity risks and adopt consistent control measures to promote and protect public integrity. To this end, countries should implement an internal control system and a risk management framework that safeguard integrity in public sector entities, specifically (OECD, 2017[1]):
Ensuring a control environment with clear objectives that demonstrate managers’ commitment to public integrity and public-service values, and that provides a reasonable level of assurance of an organisation’s efficiency, performance and compliance with laws and practices.
Ensuring a strategic approach to risk management that includes assessing risks to public integrity, addressing control weaknesses (including building warning signs into critical processes) as well as building effective monitoring and quality assurance mechanisms for the risk management system.
6.2.1. The Dominican Republic could set internal control objectives for integrity across policies and programmes and ensuring full coverage of the CGR’s Internal Control Index
The Political Constitution of the Dominican Republic (Articles 246 and 247) establishes that the Comptroller General of the Republic (CGR) is the Executive Branch body responsible for internal control. Its functions include defining, issuing and developing the guiding principles of the national internal control system and issuing basic regulations on the matter, including risk management. In addition, it must assess whether the provisions, systems and procedures established by each public entity or agency are consistent with the basic rules, advising entities and agencies on how to strengthen internal controls and risk management.
Dominican public entities are subject to a series of internal control principles and precepts, established in Law No. 10-2007 and Regulation No. 491-2007. They are also subject to the Basic Internal Control Standards (Normas Básicas de Control Interno, NOBACI), which set the regulatory framework for internal control and risk management for public entities, developed in accordance with COSO 2013 (CGR, 2019[7]). These standards apply to the central government, decentralised and autonomous institutions, public social security institutions, public companies with majority state ownership, and municipal and national district councils.
In line with Law No. 10-2007 and the NOBACI, public entities and civil servants at all levels have powers and duties to ensure the effectiveness of institutional internal control. These duties include establishing and maintaining internal controls, developing secondary rules for the system within the entity, operating and maintaining its own internal control process, complying in a timely manner with the recommendations made by the CGR and the Internal Audit Units (UAIs), and providing internal auditors with the means and information required to perform their duties. Public entities must establish an adequate control environment, which is made up of the entity's standards, processes and structure, including the integrity standards and mechanisms established in the organisations. The CGR issues guidelines and technical standards to support public entities to ensure the effectiveness of their internal control system.
Annually, public entities must submit to the CGR a self-assessment of internal control carried out in the previous year, the action plan for improvement, and their corresponding follow-up actions (IN-CGR-RCNCI-2021-04). The highest authorities of each entity are responsible for overseeing the quality and compliance of the self-assessment and action plans, and the CGR may carry out verification reviews on the accuracy or reasonableness of the statements made in the reports. Since 2023, the CGR has been using this self-assessment information to feed into an Internal Control Index (Índice de Control Interno, ICI) that provides a consolidated analysis of the degree of development of the internal control system of public entities and reports to the Presidency of the Republic. While the ICI should cover all institutions under the scope of the law, there is partial coverage with approximately 61% of institutions currently completing and providing their self-assessment.
Beyond this specific leadership of the CGR, there is no clear evidence of institutional leadership across the different public entities to ensure the proper functioning of the internal control system, nor the development and implementation of effective control mechanisms at the institutional level (including those specifically related to integrity). Furthermore, although the NOBACI require public entities to continuously and independently assess their internal control systems to verify its functioning and effectiveness and their authorities must be accountable for the actions they are taking to strengthen them, this does not happen across all institutions (as mentioned in the previous paragraph).
Moreover, according to the CGR's guidelines, the head, directors and managers of each entity have the obligation and duty to demonstrate, through their instructions, actions and behaviour, the importance of integrity and ethical values as fundamental elements for the proper functioning of the internal control system. They must comply with standards of conduct, implement processes to evaluate the performance of their staff with regard to compliance with those standards, and address deviations in a timely manner. The NOBACI also indicates that the authorities of each public entity can reinforce their message on internal control by issuing clear guidance on integrity and ethics, conflict of interest, illegal activities, the existence and use of communication channels for ethical issues, and the response of the authorities to deviations from standards of conduct.
However, in general, public integrity is not sufficiently incorporated as a priority area for strengthening internal controls and risk management. This limits the possibilities for contributing to government decision-making. For instance, integrity risk management is not systematically integrated into internal control processes and remains limited to specific initiatives or sectors rather than being applied consistently across government (see Section 6.2.2). The absence of a focus on integrity in the identification, assessment and treatment of risks may be creating unnoticed but relevant gaps in public diagnoses, decisions and actions, affecting government objectives at various levels. As such, the limited focus of internal control on integrity and the limited high-level commitment across public institutions to monitor and improve the implementation of control activities may impact government effectiveness.
Therefore, the government could further support the proper functioning of the internal control system and ensure that the internal control system contributes to the consolidation of the country’s framework for public integrity by implementing the following complementary measures: i) establishing internal control objectives for integrity; ii) mainstreaming public integrity in entities through the internal control function applied to policies and programmes; and iii) ensuring full coverage of the CGR’s Internal Control Index for effective accountability on the mainstreaming of internal control. Such measures can improve the government's capacity to lead and update a nationwide integrity strategy, while ensuring compliance with the government's programmatic objectives.
The proposed measures listed above are detailed below:
Establish government internal control objectives to strengthen integrity: corruption affects the ability of governments to meet their policy objectives and be accountable to the public. The Presidency of the Dominican Republic could define clear internal control objectives for public integrity to ensure that integrity risks are systematically addressed across public entities and aligned with government policy priorities. These objectives could be translated into measurable targets and reporting requirements applicable to all relevant entities. The CGR is the competent body within the government structure for disseminating the control objectives defined by the Presidency of the Republic and providing technical guidelines to public entities. This type of measure encourages public entities to mainstream integrity into their policies, plans and programmes, thereby responding to the control objectives (including those specifically related to integrity) that are priorities for the Government. If these objectives are implemented, the President of the Dominican Republic and each public entity could periodically receive information on their capacity to control and manage risks to public integrity that could affect the government's policy objectives, thereby improving decision-making. The aim is to align internal control and risk management as a priority for senior management to promote the achievement of the government's own policy objectives.
Mainstreaming integrity within institutional internal control: mainstreaming consists of incorporating integrity standards and mechanisms into the day-to-day operations of entities. Public entities could systematically integrate integrity into their internal control frameworks, including through the identification, assessment and management of integrity risks within their core processes and operations. This could include the use of standardised methodologies and tools to ensure consistency across entities and sectors. Additionally, mainstreaming means that entities should: develop and implement institutional integrity policies; adopt ethical standards tailored to their mission and environment; identify and assess integrity risks tailored to their mission, processes, and operations; facilitate reporting and appropriate investigative processes; and monitor the performance of their own mechanisms for preventing, detecting, and sanctioning corruption, in accordance with indicators that reconcile government objectives with institutional resources. The CGR has the capacity and authority to guide the mainstreaming process, following the integrity policies promoted by the Directorate General of Ethics and Government Integrity (Dirección General de Ética e Integridad Gubernamental, DIGEIG), the governing body for public integrity policies. The CGR could provide additional technical support to public entities by issuing technical standards, co-ordinate actions, test the quality of the methodologies applied and prepare comprehensive reports for government decision-making. Thanks to evidence-based information and analysis from the CGR, the government could identify those public entities or sectors with the greatest need for support. The CGR could be an ally of entities in mainstreaming integrity, while sharing information on mainstreaming with the DIGEIG, to jointly identify synergies and opportunities for improving government ethics mechanisms and processes.
Ensuring full coverage of the CGR’s Internal Control Index for effective accountability on the mainstreaming of internal control: The CGR should continue its efforts and enhance methodological guidance and capacity-building to ensure all public institutions complete the self-assessment of internal controls, achieving full coverage in the Internal Control Index (ICI). Complete participation would provide a comprehensive view of the development of internal control systems, including integrity-related subsystems, across all entities. This would enable the Presidency of the Republic to monitor implementation over time, identify institutions with weaker controls, and demand evidence-based accountability. An ICI which takes into consideration the assessment of all institutions would facilitate targeted support measures, such as increasing resources for institutional control units, providing technical assistance, and communicating government guidelines. Additionally, considering the new role of the UAIs in issuing annual reports on internal control evaluation, the use of the ICI could be further strengthened. In their new role, the UAIs issue annual reports containing an independent and qualitative assessment of the effectiveness of the internal control system. In this way, the UAIs can validate and compare the results of the ICI against evidence, while their assessments can feed into key ICI sub-indicators. This combined assurance would facilitate continuous improvement.
Finally, the DIGEIG would also benefit from having access to this information for the purposes of planning, supporting and monitoring policies, mechanisms and processes for the prevention and detection of corruption and integrity violations. Periodic measurement and monitoring mechanisms would benefit of key performance indicators, in accordance with government priorities. The risk management approach applied by the CGR would also facilitate monitoring the causes and consequences of internal control risks, enabling the DIGEIG to evaluate and propose updated government policy measures.
6.2.2. The CGR and the DIGEIG should use a shared notion of “integrity risks” and adopt a common methodological framework for their identification, assessment, and treatment by public entities
The Dominican Republic has different standards, governing bodies and processes for risk management:
First, the CGR, as the governing body of the internal control system, is responsible for establishing and supervising a risk management model, standards, and controls applicable to strengthening internal control. Through the NOBACI, the CGR has instructed public entities to implement the identification, assessment, and treatment of institutional risks. However, under this approach, the CGR does not verify that specific integrity risk management exercises are applied in public entities. The CGR approaches risk management in a general manner, focused on control and good management of public resources, without considering an approach dedicated to corruption risk (CGR, 2019[7]). Indeed, the NOBACI address the relevance of integrity in the proper functioning of internal controls and risk management in a limited way. Except for the activities of the UA, which pursues cases of corruption based on its own integrity risk management methodology, the internal control assessments and audits carried out by the CGR do not demonstrate a focus on public integrity.
Second, the DIGEIG is addressing the challenge of identifying and assessing behavioural integrity risks. The DIGEIG is implementing, across a wide range of public entities, a series of initiatives aimed at strengthening public integrity within government. These include the implementation of the “Guide to Managing Behavioural Risks of Corruption in Public Administration” (“Guía de Gestión de Riesgos Conductuales de Corrupción en la Administración Pública”) and the development of institutional action plans (DIGEIG, 2024[8]). This initiative seeks to promote the treatment of integrity risks in public entities using a methodology led by the Government Integrity and Regulatory Compliance Commissions (Comisiones de integridad Gubernamental y Cumplimiento Normativo, CIGCNs) with the participation of senior management from the various areas of each entity (see Chapter 1). However, this initiative is not integrated into the broader risk assessment activities of the CGR and public entities, nor into systemic initiatives to strengthen internal control.
Third, the General Directorate of Public Procurement (Dirección General de Compras Públicas, DGCP) has been applying integrity risk management in the specific area of public procurement. To this end, it has integrity-focused instruments, such as the Comprehensive Integrity Risk Management Guide (“Guía de Gestión Integral de Riesgos de Integridad”), the Preventive and Reactive Alert System (Sistema de Alertas Preventivas y Reactivas, SAPR), and a risk matrix for each stage of the procurement process. Through these tools, the DGCP has contributed to the implementation of practices for identifying and addressing risks associated with collusion and conflict of interest within the procurement cycle.
In short, the CGR promotes the strengthening of internal control systems in entities without specifically taking integrity risks into account, while the DIGEIG applies a specific tool for assessing and addressing behavioural integrity risks that is not integrated into internal control systems. The result is that integrity risk management is carried out within a limited set of public entities, constrained by the separation of institutional functions and competences between the DIGEIG and the CGR, and lacking a common vision and tools.
To overcome this situation, the CGR and the DIGEIG could develop a shared notion of “integrity risks” and a common framework for their identification, assessment and treatment. This joint work between the DIGEIG and the CGR should aim at refining their tools and make them complementary or integrate them through shared concepts, assessment criteria, responsibilities, etc, while allowing the required flexibility so that public institutions can identify and manage their own integrity risks. This review could benefit from the experience in public procurement promoted by the DGCP and from the identification and assessment of fraud and corruption risks carried out by the CGR's UA. These perspectives go beyond behavioural risk and can feed into a coherent and unified approach to integrity risks within the wider universe of risks. A shared notion should consider that integrity risks can also be strategic, systemic, process-related, and may include aspects of organisational culture. Common criteria and specific guidelines for internal control and integrity risk management would strengthen the impact of both the CGR and the DIGEIG.
The need for a shared vision on control and integrity risks must also include the CCRD. The CCRD is the highest body of the National Control and Oversight System (Sistema Nacional de Control y Fiscalización) of the Dominican Republic (Law No. 18-2024 of the Chamber of Accounts of the Dominican Republic), which integrates external oversight (by the CCRD), internal control (led by the CGR) and the activities of the UAIs. As the governing body of this system, the CCRD has legal powers to issue technical standards and guidelines for internal and external government auditing, as well as regulations to assess the quality of institutional internal controls and their degree of implementation. From this perspective, the CCRD could update standards related to internal controls, risk management and auditing, participating in a dialogue with the CGR, taking advantage of the standards and guidelines issued by this body on internal controls and risk management, as well as the policies and guidelines on integrity promoted by the DIGEIG.
The CGR and the CCRD already have committees that could support efforts to ensuring the consistency of objectives and standards for risk management. Considering that one of the CCRD's constitutional functions is to issue binding standards for inter-institutional co-ordination among bodies and agencies responsible for the control and auditing of public resources, spaces for formal dialogue between the CCRD, the CGR and the DIGEIG could be institutionalised. This would help to facilitate joint approaches for co-ordinating the issuance of regulations, technical guidelines and internal control assessments, while ensuring that integrity remains a central element in the co-ordination between internal control systems and external oversight functions. Such mechanisms encourage open debate and promote co-ordination among actors with different mandates but covering compatible objectives such as strengthening internal control systems at the institutional level and improving the identification and assessment of integrity risks in entities. Criteria for support and monitoring could also be developed that are relevant to the various governing bodies and, ultimately, to the State as a whole.
When working together for a shared notion of integrity risks and aligning integrity risk management methodologies, lessons learned from recent OECD work on integrity risk management offers relevant lessons. This work emphasises key elements for increasing the likelihood that managers will effectively implement integrity risk management, such as demystifying risk management, favouring simplicity, providing support and guidance to avoid misunderstandings and biases, and involving leaders to set a good example (OECD, 2022[9]; OECD, 2023[10]; OECD, 2024[11]).
6.2.3. The CGR could further strengthen the Anti-Fraud Unit and thus contribute significantly to the analysis and investigation of integrity risks
Since 2021, the CGR has had an Anti-Fraud Unit (Unidad Antifraude, UA), an administrative investigation body responsible for conducting administrative investigations into allegations of irregularities in the use of public resources, according to Article 14, numeral 7 of Law No. 10-2007. The UA is structured into four areas: (i) Detection and intelligence, (ii) Investigation, (iii) Forensic financial analysis, and (iv) Prevention and monitoring. Each area has distinct functions, while also working in close co-ordination with the others. As of December 2025, the UA had around 30 professionals, who produced more than 120 reports on anti-fraud investigations. As elaborated below, beyond its investigative function, the UA also plays a critical role in identifying systemic integrity risks and informing preventive control measures across public entities.
The UA works closely with a range of institutions both within and beyond the Dominican State to strengthen co-ordination and co-operation on integrity and anti-corruption matters. For example, the UA participates in the Technical Working Group of the Regulatory Compliance Programme under Resolution PNP-05-2021 of the General Directorate of Public Procurement (DGCP), as well as in meetings of the Operational Working Group of CONCLAFIT, with the aim of agreeing on information-sharing and collaboration mechanisms among institutions. The UA also collaborates with other relevant Dominican bodies, such as the Public Prosecutor's Office, the DIGEIG and the DGCP, by sharing relevant executive reports that may lead to criminal investigations, administrative disciplinary investigations, or investigations within the field of public procurement, respectively. For instance, between 2021 and 2022, the UA contributed 428 reports that helped strengthen the investigations of the Specialised Prosecutor's Office for the Prosecution of Administrative Corruption (PEPCA).
The UA's administrative investigations are initiated through various channels, including complaints filed with the CGR via the CGR Secure Alert (Alerta SeguraI, CGR), requests from the DIGEIG and the DGCP, public rumours, informal complaints and information provided by other areas within the CGR (particularly the DAI). The UA applies a range of investigative techniques, including document collection, field verification and interviews, when appropriate, draws on historical databases of suppliers and contracts. During its investigations, the UA may identify gaps and specific risks, which it communicates directly to the relevant public entity with the aim of triggering mitigation actions. In such cases, the UA may require the entity to develop an action plan to effectively address and mitigate the identified risks and follows up its implementation. In short, the UA conducts investigations while also carrying out corruption risk analyses, providing valuable, technically validated information to public entities, the CGR and other institutional actors for integrity.
Despite its growing role and analytical capacity, the contribution of the UA to the broader internal control and integrity risk management system could be further improved. At the moment, the DAI supports the UA by referring reports that show indications of fraud so that the UA can conduct a more in-depth investigation. However, more could be done to make proactive and comprehensive use of the information collected and analysed by the UA through the investigations it conducts. Increasing the resources of the UA to expand both its investigative and preventive analytical functions would bring more impact. In particular, the UA should play a more systematic role in identifying and analysing integrity and fraud risks, and in systematically feeding these insights into internal control processes and risk management frameworks across public entities to support preventive action. These insights could support the activities of the DAI, DUAIG and the methodologies used as part of the ICI.
6.2.4. The CGR could clarify the role of UAIs by changing their names, further strengthening their new responsibility and aligning their structure with the Three Lines Model
As mentioned, the Internal Audit Units (unidades de auditoria interna, UAIs) currently perform line control activities, including the verification of payment orders and other responsibilities established under Law No. 10-2007. These responsibilities include supervising financial and administrative operations, reviewing lease and rental contracts, supervising the receipt of goods, conducting cash counts (including general cash, petty cash, and fixed funds), evaluating bank reconciliations, advising administrative staff on operational matters and evaluating direct payment transactions by entities each year (CGR, 2024[12]). Although these units are established and embedded within public entities, UAIs report administratively, functionally, and technically to the CGR. As of April 2026, the UAIs comprised 988 public officials distributed across various public entities.
More recently, the UAIs have taken on a new function consisting of issuing annual reports that provide an independent and qualitative assessment of the effectiveness of the internal control system, in line with the 2025-2028 Institutional Strategy Plan (Plan Estratégico Institucional). This enables them to validate the results of the ICI reports, which are based on institutions’ self-assessments, against their own evidence and findings. As these evaluations also provide key information for the ICI sub-indicators, the CGE could further strengthen the new UAIs’ function by developing additional methods to support and verify the self-assessment ICI reports in a consistent way across the public administration. As such, this expanded role could support, but not replace, the responsibility of management for internal control and risk management.
However, the current organisational arrangement of the UAIs does not fully align with the Three Lines model (see Figure 6.1). Despite their name, the UAIs do not carry out internal audits. While these units perform second-line control activities, their reporting lines to the CGR blur the distinction between first-line management responsibilities, second-line control activities and third-line assurance. As a result, the current structure can create overlaps, confusion regarding accountability, and challenges in maintaining a clear segregation of duties.
To address these issues, the CGR could consider implementing the following recommendations:
Clarify the role through renaming the units. The CGR could change the name of the UAIs to better reflect the work they perform. This would help dissociate the units from the term “internal audit,” reduce confusion and help both internal and external stakeholders understand their precise responsibilities. A clear name would also support accountability and strengthen the credibility of their work.
Strengthen the second-line oversight function. Further efforts should be made to consolidate the UAIs’ role in verifying the effectiveness of internal control systems. This could include the development of standardised methodologies, enhanced training for staff and the implementation of consistent reporting frameworks (see also Section 6.2.1). By doing so, the units will be able to provide high-quality assessments, which enhance institutional accountability, reinforce transparency and promote the integrity of financial and administrative operations.
In the future, consider separating the units from the CGR. Considering that UAIs perform second-line control activities, the CGR should consider transferring the (rebranded) UAIs to the respective organisations of which they are performing control activities. The tasks carried out by the UAIs ideally should be managerial responsibilities within a public entity and not the responsibility of an internal audit body such as the CGR. This would also contribute to preventing confusion between the UAIs and CGR’s Internal Audit Directorate and safeguard the independence of the CGR to audit the work of the UAIs.
Such a transition would clarify roles, eliminate overlaps and ensure that second-line oversight is positioned within the organisational structure and the responsibility of public entities. This alignment with international good practices would improve the effectiveness of internal controls, strengthen risk management and reinforce the independence of third-line assurance provided by the CGR, that should not be involved in such second-line oversight. Indeed, the International Organisation of Supreme Audit Institutions (INTOSAI) emphasises that although internal auditors can be a valuable source of advice on internal control, they should not act as substitutes for a robust internal control system and should not perform operational or management tasks (INTOSAI, 2019[13]).
6.3. Strengthening the internal audit function
Copy link to 6.3. Strengthening the internal audit functionThe internal audit function in public sector organisations play an important role in providing independent, objective assessments of whether public resources are being managed effectively to achieve intended results (OECD, 2020[2]). Their objective, value-based insights and evidence can help public sector organisations better manage and assess integrity risks (OECD, 2020[2]). At the same time, the results of internal audit activity can support managers in aligning integrity risk management processes and controls with organisational objectives, so that these processes are helping to advance strategic goals and inform decision making (OECD, 2020[2]).
The CGR serves both as the central harmonisation body for internal control the Executive Branch and as the central internal audit authority:
Through its Regulatory Development Directorate (Dirección de Desarrollo Normativo), the CGR develops, updates and issues the basic rules, guidelines and standards governing the professional practice of government internal auditing, in line with the legal framework and international standards.
Through the Internal Audit Directorate (Dirección de Auditoría Interna), the CGR evaluates the use of State resources and oversees public funds through ex post auditing, in accordance with Law No. 10-2007.
6.3.1. The Dominican Republic could strengthen the relationship between the DAI and senior institutional management by further strengthening the communication of audit findings and reports to improve their uptake
In the Dominican Republic, the internal audit function has a distinctive feature: it is carried out by centrally based auditors within the CGR’s Internal Audit Directorate. This Directorate has substantial capacity, with 170 auditors as of May 2026, and conducts integrated audits combining financial, compliance and performance reviews across public institutions. Audit planning is risk-based and relies on defined criteria (including budget execution, budget size, number of employees, and the nature of the entity), as well as input from key institutions to prioritise audit coverage. Audit plans are prepared one year in advance, covering the period from early September to the end of October of the following year. For 2026, a total of 63 audits are planned.
A central internal audit function exists in other OECD countries (for instance, Brazil, Canada and the Netherlands (see Box 6.1)). The main challenge of this model is that the effectiveness of the internal audit function could be limited by an inadequate relationship of trust and engagement between the Internal Audit Directorate and the management of public entities. In some cases, management of public entities may perceive the Internal Audit Directorate as an external entity pursuing objectives not fully aligned with those of the public entity. As a result, audit findings and recommendations are not fully integrated into managerial decision-making, thereby limiting their impact and reducing opportunities for improvement.
This situation may be exacerbated by two distinctive characteristics in the Dominican Republic. First, the current naming and positioning of internal audit units that perform line control activities may generate confusion among public officials regarding their distinct but complementary roles with the Internal Audit Directorate (see previous section). This lack of clarity can further weaken understanding and acceptance of internal audit functions across the administration. Second, the internal audit function is relatively recent, which may mean that awareness of its role and value remains limited. Discussions with key stakeholders for this Integrity Review highlighted that one of the main operational constraints faced by the CGR Internal Audit Directorate is the limited availability and timely submission of information from public institutions required to conduct audits. While this situation may be driven by multiple factors, insufficient awareness of the internal audit function and a lack of trust in its role are likely contributing causes.
Box 6.1. Internal Audit Framework in the Netherlands
Copy link to Box 6.1. Internal Audit Framework in the NetherlandsIn the Netherlands, the internal audit system is governed by the Central Government Audit Service (CGAS), which conducts annual audits for both financial and non-financial accountability information, as well as the government's budget and financial management. This centralised system ensures that internal audits comply with national laws and regulations, maintaining independence and quality through regular evaluations. CGAS is responsible for both financial/compliance audits and consultative operational audits across ministries. These audits cover strategic, operational, and transaction levels, ensuring comprehensive oversight. Since 2014, all internal audit departments have merged into CGAS for efficiency, operating under the Ministry of Finance but reporting to individual ministers. CGAS tasks are regulated by the Government Accounts Act 2001, with auditors required to undergo continuous professional education. Audit findings are discussed with management, and actions are taken on recommendations. Irregularities or fraud are reported to appropriate authorities, and disciplinary actions are taken as needed.
The Minister of Finance oversees the quality control system, ensuring independent performance and adherence to ethical standards. Annual activity reports and quality assessments every five years are mandated, promoting transparency and accountability in public sector auditing. Additionally, audit results are reported to relevant ministers and the House of Representatives, enhancing oversight and governance. This structured approach ensures a high standard of internal control and risk management across central government institutions.
Considering this, the Dominican government would benefit from reviewing the current approach of the UAIs and the DUAIG, as recommended in Section 6.2.4, as well as from further strengthening the socialisation of audit findings and reports issued by the Internal Audit Directorate. Currently, findings are communicated and presented to public entities using tools such as TeamMate+, which contains a module through which entities maintain real-time communication regarding audit findings and recommendations, thereby providing a formal mechanism for feedback and dialogue. The socialisation of reports should also ensure the findings are understood by the institutions. To this end, the CGR could ensure its recommendations are feasible and risk mitigation-oriented, as well as define specific deadlines for their implementation. This would enhance ownership of audit outcomes and support more effective follow-up and implementation of corrective actions.
Ultimately, this relationship should be strengthened through enhanced communication not only of the audit findings and reports, but also about the role, mandate, and activities of the Internal Audit Directorate. Greater institutional understanding of its functions can help clarify its value as an assurance and improvement mechanism rather than a supervisory body. As awareness of these functions increases across public institutions, trust is likely to improve, facilitating greater co-operation, more timely information sharing, and stronger uptake of audit recommendations.
6.3.2. Through its Prioritised Training Plan, the CGR should continue supporting the professional development of internal auditors and promote a change in organisational culture to support recent reforms
The knowledge and objective, value-based evidence assessments provided by internal auditors can help senior management in public entities better manage integrity risks, thereby making a substantial contribution to the prevention of corruption. Thus, strengthening the professional capacity of internal auditors is essential to enable the transition towards a more risk-based, advisory, and integrity-focused internal audit function. As part of CGR’s Institutional Strategic Plan 2025-2028, axis III describes that there will be capacity building for internal audit units. The interventions will focus on strengthening internal institutional and management capacities that allow the standardisation and efficiency of processes.
Since 2024 the CGR has been implementing a Prioritised Training Plan (Plan Priorizado de Capacitación), with the support of the Inter-American Development Bank and the Institute of Internal Auditors of the Dominican Republic (Instituto de Auditores Internos de la República Dominicana, IAIRD). This Plan is aimed at strengthening the technical and leadership capacities of personnel in internal control and auditing.
Considering these advances and building on this initiative, the CGR could further strengthen its Prioritised Training Plan to support the enhancement of internal auditors’ suitability, technical knowledge and professional capacity, including on integrity policies. To this end, the CGR could carry out a training needs assessment, linked to its strategic plan or at least to its long-term strategic objectives, to establish priority areas for training. This assessment can help define the training and specialisation gap of audit staff, in accordance with the entity's most important interests, as well as facilitate the determination of the resources necessary to achieve the objectives and goals, and their scheduling over time.
The professional development plan could include induction, training, certification (e.g. Certified Internal Auditor by the Institute of Internal Auditors of the Dominican Republic) and specialisation programmes:
Induction programmes help to communicate expectations regarding the behaviour of new staff joining the CGR. It is an ideal opportunity to inform new employees about the institution's values, integrity standards, the handling of conflict of interest and how to manage reports or complaints. Induction programmes can be an opportunity to conduct early assessments of the professional and technical skills of those joining the institution and inform follow-up trainings.
Training and certification programmes should meet the specific needs of organisational areas and their objectives. The content of the courses should cover internationally recognised technical standards in the field of control and auditing (e.g. COSO, internal auditing, regulatory control, evaluation of internal control systems, techniques and methods, etc.). Programmes could focus on strengthening impartiality and judgment and could include training on public integrity, which would help auditors better understand and audit the implementation and functioning of integrity policies, including national frameworks and international standards. Programmes could also include practical courses in areas such as integrity risk management, conflict of interest management, fraud detection and treatment, the use of big data for fraud and corruption detection, and advanced cybersecurity, among other topics. Trainings aimed at strengthening soft skills such as leadership, communication, teamwork, collaboration and internal client relationship management, among others, are equally relevant.
Given limited budgetary resources, it is important to consider complementary approaches. Considering that the CGR has a National School of Internal Control (Escuela Nacional de Control Interno) that is developing a virtual training initiative, efforts could be co-ordinated to ensure collaboration with relevant national and foreign entities for the training of auditors. Thanks to the use of information technology, videoconferencing and training applications, the CGR could leverage the wide range of digital education offered by training centres and universities around the world.
Likewise, the CGR could incorporate its most skilled and experienced staff into its professional development plan. This is a valuable internal resource that can be used to expand audit knowledge and practices through mentoring. More experienced staff could take on training and technical support tasks for new or inexperienced staff through a series of meetings, workshops and monitoring of practical learning objectives. The example in Box 6.2 provides an example from the Treasury Board Secretariat of Canada on how they centrally recruit and develop the skills of their auditors in the public service.
Box 6.2. Internal Audit Development Programme and Internal Audit Competency Profiles and Dictionary in Canada
Copy link to Box 6.2. Internal Audit Development Programme and Internal Audit Competency Profiles and Dictionary in CanadaAmong its initiatives to upgrade the development of internal audit recruitment and strengthen the system, the Office of the Comptroller General of Canada developed the Internal Audit Competency Framework, which aims to support and empower a quality and self-sufficient internal audit community in the federal public sector. It provides excellent infrastructure, along with tools and support services, to position the internal audit community as professionals who perform a job in the government of Canada that adds value to organisations.
In addition to coaching, mentoring, and professional development courses, the Internal Audit Recruitment and Development (IARD) Programme offers:
Up to 36 months of training and job experience,
A development plan designed to help to succeed,
Access to mentoring and networking opportunities,
Support towards obtaining Certified Internal Auditor certification (including paid study leave and reimbursement of tuition fees),
The place to learn about an organisation's business and to be exposed to senior management,
Opportunity for promotion within the programme.
The IA Competency Profiles and Dictionary are the main pillars of competency-based management (CBM). They allow organisations to focus on how a person undertakes their job based on the skills, abilities, and knowledge necessary to perform the tasks. CBM is the application of a set of competences to the administration of human resources (staff, training, performance management and resource planning) to achieve excellence in performance and results that are relevant to organisations.
Source: Treasury Board Secretariat of Canada; (Government of Canada, 2024[19]; Government of Canada, 2025[20])
Finally, training is necessary but not sufficient to support the ongoing reforms of the CGR, including the UAIs. To achieve the objectives of the reforms, it is key to ensure that the organisational culture is aligned with the institution's mission and objectives. Organisational culture can have a significant positive impact on staff commitment, motivation and performance. Conversely, a misaligned organisational culture may become a major obstacle, hindering the execution of CGR’s strategy and the institution’s ability to achieve its goals. Behavioural barriers to change could be impeding employees of the CGR to adopt new roles and methodologies, digital tools or follow new processes, embrace a new mindset or engage in required capacity building and learning activities that are meant to promote the ongoing reforms. At the same time, such reforms often generate internal resistance to change. It is therefore key to understand the concerns, established interests and fears of employees of the CGR.
Therefore, the CGR could carry out an assessment of its organisational culture, identifying current barriers, enablers and informal dynamics amongst staff that could support, undermine or slow down the ongoing reforms. The assessment could provide a road map for targeted activities aimed at supporting a stronger organisational culture. For instance, the assessment could follow the COM-B model (West and Michie, 2020[21]; Michie, Atkins and West, 2014[22]):
Capability: Explore whether the employees have the knowledge, skills and abilities to engage in behaviours desired by the CGR’s leadership in the context of the reforms. This includes, for example, looking at whether auditors have the skillset required to constructively liaise with auditees, communicating about the value added of audits or are capable of using new tools or technologies.
Opportunities: Analyse external factors of the physical and social environment that make an action harder or easier to perform. Physical opportunities refer, for example, to time and monetary resources, infrastructure or any tangible element that influences the feasibility of a behaviour. Social opportunities refer to how acceptable or reprehensible an action is in the view of other persons that are relevant for the auditor (e.g. other auditors, supervisors etc.).
Motivation: Explore the internal drivers that encourage or create the desire to act. These drivers can be via conscious or unconscious cognitive processes. An example of a reflective motivation is a cognitive process that weights pros and cons of an action. Automatic motivations, in turn, are impulses that lead to an action through emotional responses or habits that do not require people’s full attention. Motivation of staff is key to underpin the desired changes of the current reforms.
6.4. Promoting trust and strengthening the impact of the Chamber of Accounts of the Dominican Republic
Copy link to 6.4. Promoting trust and strengthening the impact of the Chamber of Accounts of the Dominican RepublicThe independent external oversight function over government is of paramount importance for integrity and public accountability in the eyes of the public (OECD/IDI, 2026[6]). The audit of governments and public entities by Supreme Audit Institutions (SAIs) can have a positive impact on public confidence, as it forces those responsible for public resources to reflect on their use of those resources. The extent to which a SAI can make a difference in the lives of citizens will depend on whether the SAI strengthens the accountability, transparency and integrity of government and public entities, demonstrates its continued relevance to citizens, Parliament and other stakeholders and is a model organisation through example (INTOSAI, 2019[23]). This awareness promotes desired values and reinforces accountability mechanisms, which in turn leads to better decision-making (INTOSAI, 2019[23]; OECD, 2017[24]).
The Chamber of Accounts of the Dominican Republic (Cámara de Cuentas de la República Dominicana, CCRD), as the country's SAI, is the oversight body for the protection of public resources. Interviews conducted as part of this Integrity Review revealed that the CCRD has struggled with low levels public trust in the past, related to historical malpractice and a perceived lack of technical capacity and independence.
Law No. 18-2024, establishing a National Control and Oversight System, represents a significant step forward in strengthening the CCRD and the systems of internal and external control. The law recognises the CCRD as the highest body within this system, granting it powers to issue binding regulations, to promote and achieve inter-institutional co-ordination among agencies and units responsible for the control and oversight of public funds and to formulate a national plan for these purposes.
The law as well as the current reforms triggered by the law and aimed at modernising and digitalising the CCRD are an opportunity to further strengthen the external audit function in the country. The following recommendations therefore seek to consolidate the role and the relevance of the CCRD and to help it build trust so that it can perform more effectively and efficiently its key role in the governance of the Dominican Republic.
6.4.1. The National Congress could improve the selection and appointment process for CCRD plenary members based on clear, objective and transparent criteria
The effectiveness of SAIs depends on their ability to operate independently, free from undue influence, and to deliver credible, evidence-based insights. Independence depends on several dimensions and goes beyond formally recognising it in legal documents (OECD/IDI, 2026[6]). The independence of the SAI begins with ensuring the independence of the heads and members of the SAIs (of collegiate institutions), including security of tenure and legal immunity in the normal performance of their duties (INTOSAI, 2007[25]). For this reason, it must be ensured that the head of the SAIs and the members of collegiate institutions are appointed, re-elected and dismissed through processes that guarantee their independence and promotes adequate accountability. The selection of SAIs heads and members has an impact on the trust that the entity generates among citizens and institutional actors: where appointment procedures are perceived as opaque or politically driven, even strong legal safeguards may be insufficient to ensure trust in the institution’s independence (OECD/IDI, 2026[6]).
The Constitution and laws of the Dominican Republic establish minimum rules for the selection process of the five members of the CCRD plenary, including requirements for candidates and the election process. Specifically, Article 249 of the Constitution provides that “To be a member of the Chamber of Accounts, one must be a Dominican citizen in full exercise of civil and political rights, be of recognised ethical and moral standing, be at least thirty years of age, hold a university degree and be qualified to practise professionally, preferably in the areas of accounting, finance, economics, law or related fields, and meet any other conditions determined by law”. According to the Constitution, members of the CCRD plenary must be elected by the Senate of the Republic from a shortlist of three candidates presented by the Chamber of Deputies.
The process followed by the National Congress is as follows: i) The Permanent Commission of the Chamber of Accounts in the Chamber of Deputies evaluates the candidates based on a thorough review of their records; ii) such Permanent Commission prepares a report with a selection of five shortlists; this report must be approved by the plenary session of the Chamber of Deputies and then sent to the Senate of the Republic; iii) the Senate of the Republic forms a Special Commission to evaluate the report submitted by the Chamber of Deputies and to select the members of the Chamber of Accounts; iv) the Senate’s Special Commission conducts candidate evaluations, submits a favourable report to the Senate plenary regarding the analysis of the shortlists, and then presents the five selected candidates for membership; and v) the Senate approves the report of the Special Commission and confirms the selection of the members of the plenary of the Chamber of Accounts.
However, since the chambers of the National Congress have not issued public specific criteria or parameters for evaluating candidates, the pool of potential candidates is very broad, and the selection criteria are opaque. This lack of transparency allows the participation of individuals who may not possess the necessary qualifications for such a high office and responsibility, contributing to uncertainty in the selection process.
Considering this, the Chamber of Deputies could establish objective and clearly defined parameters for pre-selection, as well as specific grounds for ineligibility of candidates. This would allow experience and qualification requirements for candidates for CCRD membership to be assessed in an orderly and impartial manner, thereby increasing the transparency and accountability of the procedures and basis used to create the shortlist of candidates submitted to the Senate.
The Senate, in turn, could consider issuing guidelines that explain the procedure and rationale for selecting CCRD members, including clear procedures and criteria for appointing the chairperson for each term and in the event of a vacancy. These measures could help ensure that the CCRD is led by individuals with high professional suitability and relevant experience, compatible with the complex and multiple responsibilities of leading the governing body of external oversight. Additionally, both chambers of Congress could establish public criteria and mechanisms to favour the selection of candidates with a proven track record of ethical leadership and impartiality, and without political affiliation, thereby strengthening the independence and the impartiality of the members of the CCRD plenary.
6.4.2. The Chamber of Accounts could continue strengthening the quality of its audits, ensuring that the Audit Quality Directorate has the resources and capacities to oversee standards for audit quality
Ensuring the quality of audits is key for safeguarding the relevance, impact and reputation of a SAI. Quality control and quality assurance aims to ensure that audits are relevant and that they are accurate. Audit quality is obtained by identifying and administering the activities needed to achieve the quality objectives, ensuring alignment with INTOSAI Auditing Standards and other relevant standards and criteria. Improving audit quality requires a systematic and continuous SAI-wide approach (OECD, 2004[26]).
Until the creation of the Audit Quality Directorate (Dirección de Gestión de Calidad) in 2024, through Law No. 18-2024, there was no clear responsibility for ensuring the quality of audit processes in the CCRD. With this new Directorate, the CCRD has the opportunity to establish internal policies and standards that provide greater clarity regarding its mission and responsibilities, as well as technical guidelines to ensure more technically reliable and high-quality audits. These guidelines, as well as manuals and procedures, should be aligned with internationally recognised standards and good practices, and staff responsible for their implementation should receive specialised training in the application of audit techniques and procedures.
Therefore, it is vital that the Audit Quality Directorate established under the new law be fully operational and equipped with the necessary capabilities to effectively guide and supervise the quality of the audits carried out by CCRD units and staff. The Directorate should have sufficient well-trained staff to develop methodologies aimed at strengthening professional and institutional quality of CCRD audits and to develop internal capacities. Audits should be risk-based, grounded in sound methodologies, and carried out using appropriate audit criteria, techniques and standards, with findings documented through evidence-based reports. An example of a dedicated quality control role is described in Box 6.3.
In addition, the CCRD could strengthen hierarchical oversight to ensure auditors perform their respective functions in accordance with professional and ethical standards. Violations of the CCRD audit quality standards by auditors can cause significant damage to the public treasury. Supervisors therefore have the duty to prevent such violations and, if they occur, to report them, allowing an objective and impartial investigation to determine their effectiveness and seriousness.
Finally, transparency also plays an important role in quality management. Standards and mechanisms governing audit work, including supervision and guidance, must be communicated to the CGR, CCRD staff, and other public bodies. This communication should also extend to third parties with vested interests in the work and results of the external oversight body, such as professional associations, training institutes and academic institutions. Public trust in the performance of the CCRD can be strengthened through transparency regarding the methodologies and quality managements standards applied in its audits.
Box 6.3. Poland – Najwyższa Izba Kontroli (NIK): Structure audit quality assurance system
Copy link to Box 6.3. Poland – Najwyższa Izba Kontroli (NIK): Structure audit quality assurance systemPoland’s Supreme Audit Institution, Najwyższa Izba Kontroli (NIK), introduced a comprehensive audit quality assurance system in 2015, designed in line with the ISSAIs as well as Poland’s national state auditing standards. The system established clear responsibilities for quality at both organisational and engagement levels and introduced structured processes for planning, supervision, review, and documentation of audit work. It also strengthened internal monitoring arrangements through regular quality reviews and feedback mechanisms, enabling NIK to identify systemic issues and continuously improve audit methodologies and practices.
By embedding quality assurance into its core audit processes and governance structures, NIK provides a practical example of how SAIs can institutionalise quality management to support consistency, credibility, and compliance with international standards.
Source: (Supreme Audit Office, 2022[27])
6.4.3. The Chamber of Accounts could continue its efforts to professionalise and promote public integrity among the institution's staff
SAIs are expected to lead by example, demonstrating a clear commitment to integrity and the public interest. Ensuring integrity within SAI operations was identified by the OECD and the INTOSAI Development Initiative (IDI) as an area requiring further attention to safeguard a SAI’s independence (OECD/IDI, 2026[6]). To mitigate integrity risks, SAIs’ should promote organisational cultures, with clear guidance and support to staff as well as strong risk management practices and internal controls. Leadership and a merit and values-based workforce are also central to achieving resilience against integrity risks. Leaders shape organisational culture, establish ethical practices and ensure that institutional decisions follow the laws, shared values and are taken in the public interest (see Chapter 3).
Law No. 18-2024 requires that the CCRD employ highly qualified personnel with recognised professional prestige and integrity. It also requires that the CCRD implement human resource management systems that consider competences, performance, professional progress as well as personal and professional conduct when assessing employees. It also stipulates that staff shall be governed by a Special Administrative Career Regime of the Chamber of Accounts, which is to be based on merit and professionalisation of the civil service. The Human Resources and Special Administrative Career Regulations were approved in 2025 through Resolution ADM2025046, representing a significant step forward in the professionalisation of the CCRD’s technical staff. These regulations establish recruitment and selection processes designed to ensure the knowledge, professional experience, academic qualifications and merit of CCRD personnel.
Therefore, along the ongoing efforts to professionalise its staff, the CCRD could consider implementing more explicitly initiatives to promote integrity. To this end, the CCRD could commission an external assessment of its current internal integrity policies and, as a minimum, consider implementing the following measures:
Establish rules and mechanisms for managing conflict of interest and recusals among CCRD staff. In developing these rules, the country’s general framework for managing conflicts of interest and the recommendations provided in Chapter 2 could be considered. The CCRD could work in co-ordination with the CGR to explore the possibility of extending these rules and mechanisms to internal auditors and staff of the CGR, ensuring consistent treatment of personnel performing internal and external control functions. In defining these rules and mechanisms, both the CCRD and the CGR could draw on standards and guidelines established by the INTOSAI and the IIA.
Strengthen reporting channels for irregularities and breaches of integrity. While the CCRD has recently developed a digital public complaints channel (Ojo Cuidadano), efforts should be made to enhance its internal reporting mechanisms. This should consider the recommendations for whistleblowing and whistleblower protection in Chapter 7. The CCRD should develop and implement initiatives to enhance a culture of openness within the institution, as well as a robust internal channel that enables staff to report irregularities or breaches of integrity while ensuring the protection of whistleblowers.
Ensure the consistent application of appropriate disciplinary procedures for the investigation and application of sanctions within the institution. The CCRD could formalise disciplinary procedures for addressing first-, second-, and third-degree offences committed by employees and officials of the institution. These procedures should guarantee due process and ensure that any sanctions applied are based on reasoned, objective and documented grounds. This could consider the recommendations provided in Chapter 7 for the disciplinary system of the Executive Branch.
6.4.4. The Chamber of Accounts could increase the impact of its work by widely disseminating the results of its audits to the National Congress and the public
The INTOSAI recognises the need to include external stakeholders such as citizens and parliaments in their efforts to increase the impact of their audit work (INTOSAI, 2013[28]). Legislators and civil society can rely on SAIs audit reports as a key tool for holding the executive accountable. Through debates, committee hearings, particularly within public accounts or budget committees, and formal inquiries, legislators can use SAIs findings to scrutinise government spending, assess compliance with laws and policies and evaluate performance (OECD/IDI, 2026[6]). In turn, citizens, media, academia, professional associations and civil society organisations are natural allies of the SAIs in generating impact as they can demand for change and follow-up on audit reports. Therefore, SAIs should communicate audit results clearly and accessibly, disclose information about their mandate and responsibilities, publish reports in a timely manner, facilitate stakeholder access to information, apply transparent auditing standards and methods, and engage effectively with the media and other stakeholders (INTOSAI, 2013[28]).
Interviews held with the presidents of the Senate and the Chamber of Deputies, as well as with CCRD officials for this Integrity Review indicated that legislators in the Dominican Republic are not fully using the potential of CCRD reports to inform their oversight role and when approving budget allocations for public entities. For example, serious findings concerning violations of public integrity identified through special investigations or CCRD audits could strengthen the work and decisions of special committees in the Chamber of Deputies or the Senate. In addition, these reports could support evidence-based political oversight by helping to assess the performance of public authorities or scrutinise them in cases of political scandals related to public integrity.
To ensure that external oversight effectively contributes to decision-making at the political level, the CCRD could adopt measures to ensure appropriate and regular channels of communication and dissemination of information on the results of its oversight activities and relevant findings. This could include, for example, incorporating relevant findings into its regular or annual reports to the National Congress. In addition, consideration could be given to automatically sending audit reports or summaries of annual audits to the National Congress. The CCRD could also provide information on a special and timely basis on contingent matters that require the attention of the Government and the National Congress. For its part, Congress could make greater use of the CCRD reports and audits to support legislative initiatives, inform voting decisions, and hold officials and institutions accountable based on evidence from the external oversight body.
In addition, the CCRD should engage more actively with citizens, civil society organisations, media and academia to disseminate the findings of its work, to leverage these stakeholders as allies in promoting change and to build public trust. Through a community-oriented communication strategy, the CCRD could periodically inform citizens about audit findings and challenges identified in areas of high public interest, thereby demonstrating the benefits of external oversight for the well-being of society. Examples from other countries could serve as inspiration for the CCRD (see Box 6.4).
Box 6.4. Examples of communication
Copy link to Box 6.4. Examples of communicationComptroller General of the Republic of Chile
In Chile, the Comptroller General of the Republic (Contraloría General de la República) communicates information on its external control activities through a range of channels, using clear and accessible language. For example:
It publishes annual reports on its website, accompanied by a short video summarising the year’s results, as well as a recording of the high-level event at which the report was presented.
It prepares and publishes compilations of public information (consolidados de información circularizada, CIC) on its website and social media. These explain, in plain language, key irregularities identified across the country. In 2025, 18 CICs were published.
In addition, the Comptroller General of the Republic has developed a dedicated section on its website with frequently asked questions (FAQs) to promote public understanding of its work. These FAQs are organised by topic, covering areas such as its mandate, relevant legislation, public administration, the roles and responsibilities of public officials, public finances, municipal governance, public works, and the environment. For more information, see: https://www.contraloria.cl/web/cgr/preguntas-frecuentes.
National Audit Office of Norway
The National Audit Office of Norway has a strategy to communicate the results of its work to relevant professional environments where the findings can have practical impact. Conferences, presentations, and dialogue meetings are key channels for this dissemination. This contributes to increasing the presence and improving the reputation of the SAI among different groups.
In line with the communication policy, the Auditor General and audit department representatives present findings, share methodological approaches, and engage in discussions with relevant audiences across the country.
These activities support the National Audit Office’s objective of promoting transparency, facilitating knowledge transfer, and contributing to long-term improvements in public-sector governance. Regular dissemination helps ensure that audit results reach those who can act on them.
6.4.5. The Chamber of Accounts could elaborate a digital transformation strategy to leverage data and technology for more timely, efficient and transparent audits
A more timely, efficient and less intrusive way of exercising oversight can be achieved using data analytics and artificial intelligence tools, taking advantage of the increasing availability of high-quality data. This allows for preventive and real-time oversight of the execution of public resources, while offering opportunities to improve administrative efficiency (OECD, 2024[30]; OECD, 2021[31]; OECD, 2025[32]). In turn, a digital document management system significantly contributes to the efficiency of audit management but also to the transparency and accountability of a SAI. Such systems provide secure, reliable and accessible storage of documents and information, supporting daily operational needs across departments. As such, they are useful for organising archives, consolidating documents from different areas and maintaining comprehensive document databases so that they are available to officials.
Currently, information gathered in the context of this Integrity Review indicates that the CCRD relies mainly on a paper-based documentation system. However, it has started some first digitalisation initiatives, including the use of digital signatures, the development of a digital audit system, and the implementation of an early warning mechanism.
Therefore, the CCRD could build on these first initiatives and consider developing an internal digital transformation strategy, guided by an assessment of the current state of digital maturity. Such an assessment should look into, among others, the availability and quality of databases across the public administration relevant for auditing, available internal skills and capabilities, IT infrastructure, and the institutional preparedness for the adoption of artificial intelligence. Based on this assessment, the CCRD could develop a road map to gradually strengthening its digital capacities, implementing a digital document management system and leveraging available data and technology. Moreover, a digital document management system would help better organise, preserve, and access audit files over time, thereby strengthening day-to-day operations and facilitating more effective audit management. The implementation of such a system could also consider the recommendations outlined in Chapter 4. The co-operation between the OECD and the Supreme Audit Institution of Mexico provides an example for an assessment focusing on the use of data and analytics for integrity risk detection to strengthen the institution’s first digital transformation work programme (Box 6.5).
Box 6.5. Strengthening Analytics in Mexico's Supreme Audit Institution
Copy link to Box 6.5. Strengthening Analytics in Mexico's Supreme Audit InstitutionThe Supreme Audit Institution (SAI) of Mexico, the Superior Audit of the Federation (Auditoría Superior de la Federación, ASF) has early recognised the critical role that data and analytics can play in the fulfilment of its mandate and achievement of strategic goals.
In 2020, the ASF published its first digital transformation work programme, which emphasised ASF-wide goals and objectives for equipping auditors with the infrastructure, architecture, skills and tools needed to effectively audit in a digital environment. The COVID-19 pandemic reinforced the need for this programme so that auditors have the necessary infrastructure and tools to audit remotely.
Together with the ASF, the OECD identified strategic opportunities and operational priorities for the ASF to build its analytics capacity, particularly with regards to the integrity context, through improved co-ordination, digital skills development and nurturing a data-centric culture. The review of the OECD did not provide an exhaustive discussion of all of the ASF’s applications of and capacity for leveraging analytics, or of the numerous ways auditors use data to support their work. Rather, the primary objective of the collaboration was to focus on data and analytics for integrity risk detection and the activities of the key teams working in this area, as identified by the ASF itself.
Source: (OECD, 2022[33])
6.5. Proposals for action
Copy link to 6.5. Proposals for actionStrengthening integrity risk management and internal control
The Dominican Republic could set internal control objectives for integrity across policies and programmes and ensuring full coverage of the CGR’s Internal Control Index.
The CGR and the DIGEIG should use a shared notion of “integrity risks” and adopt a common methodological framework for their identification, assessment, and treatment by public entities.
The CGR could further strengthen the Anti-Fraud Unit and thus contribute significantly to the analysis and investigation of integrity risks.
The CGR could clarify the role of UAIs by changing their names, further strengthening their new responsibility and aligning their structure with the Three Lines Model.
Strengthening the internal audit function
The Dominican Republic could strengthen the relationship between the DAI and senior institutional management by further strengthening the communication of audit findings and reports to improve their uptake.
Through its Prioritised Training Plan, the CGR should continue supporting the professional development of internal auditors and promote a change in organisational culture to support recent reforms.
Promoting trust and strengthening the impact of the Chamber of Accounts of the Dominican Republic
The National Congress could improve the selection and appointment process for CCRD plenary members based on clear, objective and transparent criteria.
The Chamber of Accounts could continue strengthening the quality of its audits, ensuring that the Audit Quality Directorate has the resources and capacities to oversee standards for audit quality.
The Chamber of Accounts could continue its efforts to professionalise and promote public integrity among the institution's staff.
The Chamber of Accounts could increase the impact of its work by widely disseminating the results of its audits to the National Congress and the public.
The Chamber of Accounts could elaborate a digital transformation strategy to leverage data and technology for more timely, efficient and transparent audits.
References
[12] CGR (2024), Memoria Institucional Anual 2024, Contraloría General de la República Dominicana, Santo Domingo, https://www.contraloria.gob.do/transparencia/phocadownload/PlanEstrategico/Memoria%20Institucional%20Anual%202024.pdf (accessed on 24 July 2025).
[7] CGR (2019), Normas Básicas de Control Interno (NOBACI) para el diseño y la implementación del Sistema Nacional de Control Interno (SINACI), Contraloría General de la República Domincana, Santo Domingo, https://www.contraloria.gob.do/phocadownload/Nobaci/Normas/4-NOBACICoso2013-1.pdf (accessed on 24 July 2025).
[29] Comptroller General of the Republic of Chile (2025), Public Account, https://www.contraloria.cl/web/cgr/cuentas-publicas.
[8] DIGEIG (2024), Manual Didáctico para Comisiones de Integridad Gubernamental y Cumplimiento Normativo, Dirección General de Ética e Integridad Gubernamental, https://gobernacionlavega.gob.do/transparencia/wp-content/uploads/2025/06/Manual-Didactico-para-CIGCN-GUIA-COMPLETA-DEFINITIVA.pdf (accessed on 25 July 2025).
[18] European Union (2014), Compendium of the public internal control systems in the EU Member States 2014, https://op.europa.eu/en/publication-detail/-/publication/f5d1aca3-f349-11e6-8a35-01aa75ed71a1/language-en (accessed on 7 January 2026).
[20] Government of Canada (2025), Understanding the application process: Job opportunities, https://www.canada.ca/en/treasury-board-secretariat/corporate/understanding-application-process.html (accessed on 7 January 2026).
[19] Government of Canada (2024), Financial Officer and Internal Auditor Recruitment and Development Program, https://www.canada.ca/en/public-service-commission/services/staffing-assessment-tools-resources/human-resources-specialists-hiring-managers/recruitment-options-managers/graduate-general-recruitment/financial-officer-internal-auditor-recruitment-developmen (accessed on 7 January 2026).
[16] Government of the Netherlands (2026), Accounting Profession Act, https://wetten.overheid.nl/BWBR0032573/2021-07-01/ (accessed on 7 January 2026).
[14] Government of the Netherlands (2026), Auditdienst Rijk, Ministry of Finance, https://www.auditdienstrijk.nl/ (accessed on 7 January 2026).
[15] Government of the Netherlands (2025), Further regulations for quality systems, https://wetten.overheid.nl/BWBR0038869/2022-01-01/ (accessed on 7 January 2026).
[3] Institute of Internal Auditors (2024), Global Internal Audit Standards, IIA, https://www.theiia.org/globalassets/site/standards/globalinternalauditstandards_2024january9_printable.pdf.
[5] Institute of Internal Auditors (2020), The IIA’s Three Lines Model – An update of the Three Lines of Defense.
[4] Institute of Internal Auditors (2009), The Role of Internal Auditing in Enterprise-Wide Risk Management, https://www.theiia.org/globalassets/documents/resources/the-role-of-internal-auditing-in-enterprise-wide-risk-management-january-2009/pp-the-role-of-internal-auditing-in-enterprise-risk-management.pdf.
[13] INTOSAI (2019), Independencia de la auditoría interna en el sector público.
[23] INTOSAI (2019), INTOSAI-P 12 The Value and Benefits of Supreme Audit Institutions – making a difference to the lives of citizens, https://www.intosai.org/fileadmin/downloads/documents/open_access/INT_P_11_to_P_99/INTOSAI_P_12/INTOSAI_P_12_en_2019.pdf.
[28] INTOSAI (2013), “INTOSAI P-12. The Value and Benefits of Supreme Audit Institutions – making a difference to the lives of citizens”, https://www.issai.org/pronouncements/intosai-p-12-the-value-and-benefits-of-supreme-audit-institutions-making-a-difference-to-the-lives-of-citizens/ (accessed on 13 May 2026).
[25] INTOSAI (2007), INTOSAI P-10 Mexico Declaration on SAI Independence, International Organisation of Supreme Audit Institutions (INTOSAI), https://www.intosai.org/fileadmin/downloads/documents/open_access/INT_P_1_u_P_10/INTOSAI_P_10_en_2019.pdf (accessed on 15 September 2025).
[22] Michie, S., L. Atkins and R. West (2014), The Behaviour Change Wheel A Guide to Designing Interventions, Silverback Publishing.
[17] NBA (2026), Bundle of all relevant laws and regulations for accountants, Koninklijke Nederlandse Beroepsorganisatie van Accountants (NBA), https://www.nba.nl/wet--en-regelgeving/hra/ (accessed on 7 January 2026).
[32] OECD (2025), Governing with Artificial Intelligence: The State of Play and Way Forward in Core Government Functions, OECD Publishing, Paris, https://doi.org/10.1787/795de142-en.
[11] OECD (2024), Improving Corruption Risk Management in the Slovak Republic: Results from a 2023 Experiment in Applying Behavioural Insights to Public Integrity, OECD Public Governance Reviews, OECD Publishing, Paris, https://doi.org/10.1787/45f8d2e0-en.
[30] OECD (2024), Strengthening Oversight of the Court of Auditors for Effective Public Procurement in Portugal: Digital Transformation and Data-driven Risk Assessments, OECD Public Governance Reviews, OECD Publishing, Paris, https://doi.org/10.1787/35aeab1e-en.
[10] OECD (2023), Promoting Corruption Risk Management Methodology in Romania: Applying Behavioural Insights to Public Integrity, OECD Public Governance Reviews, OECD Publishing, Paris, https://doi.org/10.1787/ceb6faec-en.
[9] OECD (2022), Modernising Integrity Risk Assessments in Brazil: Towards a Behavioural-sensitive and Data-driven Approach, OECD Public Governance Reviews, OECD Publishing, Paris, https://doi.org/10.1787/ad3804f0-en.
[33] OECD (2022), Strengthening Analytics in Mexico’s Supreme Audit Institution: Considerations and Priorities for Assessing Integrity Risks, OECD Public Governance Reviews, OECD Publishing, Paris, https://doi.org/10.1787/d4f685b7-en.
[31] OECD (2021), Preventive and Concomitant Control at Colombia’s Supreme Audit Institution: New Strategies for Modern Challenges, OECD Public Governance Reviews, OECD Publishing, Paris, https://doi.org/10.1787/a2bdadf3-en.
[2] OECD (2020), OECD Public Integrity Handbook, OECD Publishing, Paris, https://doi.org/10.1787/ac8ed8e8-en.
[1] OECD (2017), “Recommendation of the Council on Public Integrity”, OECD Legal Instruments, OECD/LEGAL/0435, OECD, Paris, https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0435 (accessed on 7 April 2025).
[24] OECD (2017), Supreme Audit Institutions and Good Governance: Oversight, Insight and Foresight, OECD Public Governance Reviews, OECD Publishing, Paris, https://doi.org/10.1787/9789264263871-en.
[26] OECD (2004), “Achieving High Quality in the Work of Supreme Audit Institutions”, SIGMA Papers, No. 34, OECD Publishing, Paris, https://doi.org/10.1787/5kml60v9gsd6-en.
[6] OECD/IDI (2026), “Strengthening the Independence of Supreme Audit Institutions: Looking at Informal Factors Beyond Legal Safeguards”, OECD Public Governance Reviews, OECD Publishing, Paris, https://doi.org/10.1787/d4ee3498-en.
[27] Supreme Audit Office (2022), “Quality Control and Assurance System”, INTOSAI Framework of Professional Pronouncements, https://www.nik.gov.pl/plik/id,25914.pdf.
[21] West, R. and S. Michie (2020), A Brief Introduction to the COM-B Model of Behaviour and the PRIME Theory of Motivation, Qeios Ltd, https://doi.org/10.32388/ww04e6.2.