Preprint
Article

This version is not peer-reviewed.

Development and Validation of an Integrated Business Process Audit Effectiveness Index (BPAEI): Evidence from Joint-Stock Companies

Submitted:

20 August 2026

Posted:

21 August 2026

You are already at the latest version

Abstract
The increasing complexity of organizational operations, digital transfor-mation, and growing sustainability requirements have significantly expanded the scope of auditing beyond traditional financial assurance functions. Modern or-ganizations require comprehensive audit approaches capable of evaluating busi-ness process efficiency, risk management effectiveness, internal control quality, and corporate governance performance. However, existing audit effectiveness assessment frameworks primarily focus on financial reporting and compliance outcomes, providing limited insight into the overall effectiveness of business process auditing. This study aims to develop and validate an Integrated Business Process Audit Effectiveness Index (BPAEI) for joint-stock companies by incor-porating key operational, risk-oriented, and governance-related dimensions of auditing. The research adopts a quantitative approach based on survey data col-lected from auditors, internal control specialists, and corporate governance pro-fessionals. The proposed BPAEI model consists of five core determinants: Audit Coverage Rate (CR), Risk Detection Rate (RDR), Internal Control Index (ICI), Implementation Rate of Audit Recommendations (IR), and Process Audit Index (PAI). Structural Equation Modeling (SEM) using SmartPLS is employed to examine the relationships between these determinants and overall business pro-cess audit effectiveness. The empirical findings indicate that all five factors have a positive and statistically significant impact on audit effectiveness. Among them, Risk Detection Rate and Internal Control Index demonstrate the strongest influence, highlighting the importance of risk-oriented auditing and effective internal control systems in enhancing organizational performance. The proposed index exhibits satisfactory reliability and validity, confirming its applicability as a comprehensive measurement tool for evaluating business process audit effec-tiveness. This study contributes to the auditing literature by introducing a novel multidimensional framework that integrates operational auditing, risk manage-ment, internal controls, and governance considerations into a single quantitative model. The findings provide practical implications for auditors, regulators, and corporate managers seeking to improve audit quality, strengthen corporate gov-ernance, and support sustainable business development. The BPAEI framework can serve as a valuable instrument for assessing audit performance, benchmarking organizational practices, and facilitating evidence-based decision-making in both emerging and developed economies.
Keywords: 
;  ;  ;  ;  ;  ;  ;  

1. Introduction

The increasing complexity of organizational operations, digital transformation, and growing corporate governance requirements have expanded the role of auditing beyond traditional financial reporting and compliance assurance. Business process auditing increasingly focuses on organizational processes, operational efficiency, risk management, internal controls, and value creation rather than individual financial transactions alone [1,2,3]. In joint-stock companies, this broader perspective is particularly important because effective auditing can support accountability, reduce information asymmetry, and strengthen corporate governance.
However, measuring audit effectiveness remains challenging because it is a multidimensional construct. Previous research has examined audit quality, risk identification, internal control effectiveness, management responsiveness, recommendation implementation, and organizational impact as separate dimensions [4,5,6,7]. The Institute of Internal Auditors also emphasizes indicators such as risk coverage, implementation of recommendations, stakeholder expectations, and organizational impact. Nevertheless, existing approaches frequently rely on fragmented measures and provide limited insight into the overall effectiveness of business process auditing. Risk-based auditing and effective internal controls are particularly important components of audit effectiveness. Risk-oriented auditing enables auditors to focus resources on areas with the greatest exposure, while strong internal control systems support operational efficiency, compliance, accountability, and risk reduction [8,9,10,11]. Evidence from previous studies indicates that effective risk identification and internal controls can improve audit and governance outcomes.
The study contributes to the auditing literature by providing a multidimensional and quantitatively validated framework for assessing business process audit effectiveness. The proposed BPAEI addresses the fragmentation identified in previous research by integrating operational, risk, control, and governance dimensions into a single measurement framework.

2. Materials and Methods

2.1. Theoretical Foundations of Business Process Auditing

The concept of business process auditing emerged from the evolution of operational auditing and process management theories. Traditional auditing primarily focused on financial statement verification and compliance assessment. However, increasing organizational complexity and the growing importance of operational efficiency have expanded the scope of auditing toward evaluating business processes as integrated systems of value creation. Business process auditing is defined as a systematic and independent examination of organizational activities, workflows, resources, controls, and performance outcomes to determine whether business processes operate efficiently, effectively, economically, and in accordance with organizational objectives (Dumas et al., 2018). Unlike conventional financial audits, business process audits evaluate the interactions between organizational functions and assess how effectively resources are transformed into outputs and outcomes.
The theoretical roots of business process auditing can be traced to Business Process Management (BPM) theory, Systems Theory, Agency Theory, and Risk Management Theory. BPM emphasizes continuous process improvement through process identification, analysis, monitoring, and optimization (Dumas et al., 2018). Systems Theory views organizations as interconnected systems where deficiencies in one component may affect overall organizational performance. Consequently, auditing individual transactions alone may be insufficient for identifying systemic weaknesses. Agency Theory provides an additional justification for business process auditing. According to Jensen and Meckling (1976), conflicts of interest may arise between managers and shareholders due to information asymmetry. Auditing serves as an assurance mechanism that reduces agency costs by providing independent evaluations of organizational performance and governance practices.
Business process auditing has become increasingly relevant as organizations adopt digital technologies, enterprise resource planning systems, artificial intelligence applications, and data-driven management practices. Modern business processes are characterized by greater complexity, interdependence, and exposure to operational risks. Therefore, organizations require auditing methodologies capable of evaluating both traditional control mechanisms and emerging technological risks. Several scholars argue that business process auditing creates organizational value beyond compliance assurance. Chambers and Rand (2010) suggest that operational auditing contributes to organizational effectiveness by identifying inefficiencies, eliminating redundant activities, and supporting strategic decision-making. Similarly, Vasarhelyi et al. (2018) emphasize that modern auditing should focus on continuous assurance and real-time evaluation of business processes.
Despite growing interest in business process auditing, the literature reveals significant inconsistencies regarding the measurement of audit effectiveness. Existing studies primarily focus on audit quality indicators, financial reporting outcomes, or internal audit performance while paying limited attention to comprehensive business process audit effectiveness measures.

2.2. Audit Effectiveness: Concept and Measurement

Audit effectiveness represents one of the most widely discussed concepts within auditing research. However, there is no universally accepted definition of audit effectiveness due to the multidimensional nature of auditing activities.
Cohen and Sayag (2010) define audit effectiveness as the extent to which audit activities achieve their intended objectives. Similarly, Mihret and Yismaw (2007) argue that audit effectiveness reflects the ability of auditors to identify weaknesses, communicate findings, and facilitate corrective actions. Previous research has proposed various indicators of audit effectiveness. These indicators generally include audit quality, risk identification capability, management responsiveness, implementation of audit recommendations, internal control improvements, and stakeholder satisfaction. DeFond and Zhang (2014) emphasize that audit quality remains one of the most important dimensions of audit effectiveness. High-quality audits improve financial reporting reliability and reduce information asymmetry between managers and stakeholders. However, audit quality alone cannot fully capture the operational and strategic contributions of business process auditing.
Lenz and Hahn (2015) argue that audit effectiveness should be evaluated through a multidimensional framework incorporating organizational value creation, governance support, risk management contributions, and process improvements. This perspective aligns with the growing recognition that auditors play strategic roles in organizational development rather than merely providing compliance assurance.
The Institute of Internal Auditors (IIA, 2024) identifies effectiveness indicators such as risk coverage, stakeholder expectations, audit recommendation implementation, and organizational impact. Nevertheless, empirical evidence suggests that many organizations continue to rely on fragmented performance measures that fail to capture the comprehensive contribution of auditing activities. Consequently, researchers increasingly call for integrated frameworks capable of measuring audit effectiveness across multiple dimensions. The development of a Business Process Audit Effectiveness Index (BPAEI) responds directly to this research gap by combining operational, governance, and risk-related indicators into a unified assessment framework.

2.3. Audit Coverage and Business Process Audit Effectiveness

Audit coverage refers to the extent to which audit activities encompass significant organizational processes, functions, and risk areas. Adequate audit coverage is considered essential for ensuring that auditors evaluate all critical activities affecting organizational performance.
According to Arens et al. (2020), comprehensive audit coverage improves audit effectiveness by increasing the likelihood of detecting material weaknesses and operational inefficiencies. Similarly, Gramling et al. (2004) argue that broader audit coverage enhances organizational accountability and governance quality.
The risk-based auditing paradigm further emphasizes the importance of audit coverage. Risk-oriented audit planning requires auditors to prioritize areas with the greatest potential impact on organizational objectives (COSO, 2017). Consequently, organizations that maintain broader audit coverage across critical business processes are more likely to achieve higher audit effectiveness.
Empirical studies indicate positive relationships between audit coverage and audit performance outcomes. Organizations with comprehensive audit plans generally demonstrate stronger internal controls, improved compliance, and enhanced operational efficiency.
Therefore, the following hypothesis is proposed:
H1: 
Audit Coverage Rate (CR) has a positive and significant effect on Business Process Audit Effectiveness (BPAEI).

2.4. Risk Detection and Audit Effectiveness

Risk identification represents one of the fundamental objectives of modern auditing. Risk-based auditing has become a dominant paradigm within auditing theory and practice because it enables auditors to allocate resources efficiently and focus attention on areas with the highest risk exposure. The COSO Enterprise Risk Management Framework (2017) emphasizes that organizations must continuously identify, assess, and monitor strategic, operational, financial, and compliance risks. Auditors contribute to this process by independently evaluating risk management systems and identifying emerging threats.
Beasley et al. (2019) argue that effective risk detection significantly enhances organizational resilience and governance quality. Similarly, Knechel et al. (2013) suggest that auditors who successfully identify critical risks create substantial value for stakeholders by preventing potential losses and improving decision-making.
Technological developments have further increased the importance of risk detection capabilities. Cybersecurity threats, digital transformation initiatives, and artificial intelligence applications introduce new risk categories that require advanced auditing approaches.
Empirical studies consistently demonstrate positive relationships between risk identification effectiveness and overall audit performance. Organizations with strong risk-oriented auditing practices typically exhibit higher levels of governance effectiveness and operational stability. Therefore, the following hypothesis is proposed:
H2: 
Risk Detection Rate (RDR) has a positive and significant effect on Business Process Audit Effectiveness (BPAEI).

2.5. Internal Control Systems and Audit Effectiveness

Internal controls constitute one of the most important determinants of organizational governance and audit effectiveness. The COSO Internal Control Framework identifies five essential components of effective internal controls: control environment, risk assessment, control activities, information and communication systems, and monitoring activities.
Strong internal controls reduce fraud risks, improve operational efficiency, support regulatory compliance, and enhance organizational accountability. Consequently, evaluating internal control effectiveness represents a central objective of business process auditing.
Prawitt et al. (2009) found that organizations with stronger internal audit functions and internal controls experience higher levels of financial reporting quality and governance performance. Similarly, Eulerich et al. (2019) demonstrate that internal control effectiveness significantly influences audit outcomes.
Recent corporate failures have highlighted the consequences of inadequate internal control systems. Weak controls increase vulnerability to fraud, operational disruptions, and governance failures, thereby reducing organizational performance.
Business process auditing contributes to internal control effectiveness by evaluating control design, testing control operation, and recommending improvements. Therefore, internal control quality is expected to be positively associated with business process audit effectiveness.
Accordingly, the following hypothesis is proposed:
H3: 
Internal Control Index (ICI) has a positive and significant effect on Business Process Audit Effectiveness (BPAEI).

2.6. Implementation of Audit Recommendations

The value of auditing ultimately depends on the extent to which audit recommendations are implemented and translated into organizational improvements. Audit findings alone cannot create value unless management takes corrective actions based on auditor recommendations.
Arena and Azzone (2009) emphasize that management commitment plays a crucial role in determining audit effectiveness. Similarly, Cohen and Sayag (2010) identify recommendation implementation as one of the strongest predictors of successful auditing outcomes.
Organizations with high implementation rates typically experience greater improvements in risk management, internal controls, process efficiency, and governance quality. Conversely, failure to implement recommendations reduces the practical impact of auditing activities.
Numerous studies indicate that management support, organizational culture, and governance structures influence recommendation implementation rates. Therefore, implementation effectiveness represents a critical dimension of business process audit performance.
Accordingly, the following hypothesis is proposed:
H4: 
Implementation Rate of Audit Recommendations (IR) has a positive and significant effect on Business Process Audit Effectiveness (BPAEI).

2.7. Process Audit Quality and Organizational Value Creation

Business process auditing seeks not only to identify deficiencies but also to generate organizational value through process improvements. The Process Audit Index (PAI) reflects the extent to which auditing activities contribute to efficiency enhancement, cost reduction, process optimization, and strategic objective achievement.
Kaplan and Norton (2008) argue that organizational performance depends largely on the effectiveness of internal business processes. Consequently, auditing should focus on evaluating process performance rather than merely verifying compliance.
Appelbaum et al. (2017) suggest that modern auditing increasingly relies on data analytics and process mining technologies to evaluate process performance and identify opportunities for improvement. Similarly, Kokina and Davenport (2017) emphasize the growing role of advanced analytics in enhancing audit effectiveness.
Organizations that utilize process-focused auditing approaches often achieve higher levels of operational excellence and competitive advantage. Therefore, process auditing quality is expected to positively influence overall business process audit effectiveness.
Accordingly, the following hypothesis is proposed:
H5: 
Process Audit Index (PAI) has a positive and significant effect on Business Process Audit Effectiveness (BPAEI).

2.8. Research Gap and Conceptual Framework

The literature review reveals that previous studies have examined audit effectiveness from various perspectives, including audit quality, risk management, internal controls, governance mechanisms, and sustainability assurance. However, most studies investigate these dimensions separately, resulting in fragmented understanding of business process audit effectiveness.
Furthermore, existing audit performance measures rarely integrate operational auditing, risk-based auditing, internal controls, and organizational value creation within a single framework. This limitation creates challenges for researchers and practitioners seeking comprehensive evaluation tools.
To address this gap, the present study develops an Integrated Business Process Audit Effectiveness Index (BPAEI) incorporating Audit Coverage Rate, Risk Detection Rate, Internal Control Index, Implementation Rate, and Process Audit Index. The proposed model provides a multidimensional assessment framework capable of capturing the broader contribution of business process auditing to organizational governance, risk management, and sustainable performance.
This study adopts a quantitative research design to develop and validate an Integrated Business Process Audit Effectiveness Index (BPAEI) for joint-stock companies. Quantitative methods are particularly appropriate because the primary objective of the study is to examine causal relationships between multiple determinants of business process audit effectiveness and to construct a statistically validated measurement framework.
The research follows a positivist paradigm, which assumes that organizational phenomena can be objectively measured through empirical observations and statistical analysis. The study applies Structural Equation Modeling (SEM) using Partial Least Squares (PLS-SEM) to test the proposed conceptual model and evaluate the relationships among latent variables. PLS-SEM is selected because it is suitable for exploratory and predictive research, allows simultaneous analysis of multiple relationships, and performs effectively with complex models involving latent constructs measured through multiple indicators.
The study integrates theoretical insights from auditing theory, risk management theory, agency theory, business process management theory, and corporate governance literature. Based on these theoretical foundations, five independent constructs are identified as key determinants of business process audit effectiveness: Audit Coverage Rate (CR), Risk Detection Rate (RDR), Internal Control Index (ICI), Implementation Rate of Audit Recommendations (IR), and Process Audit Index (PAI). The dependent construct is Business Process Audit Effectiveness (BPAEI).
The research model assumes that each of the five determinants contributes positively to overall audit effectiveness. Therefore, the study employs hypothesis testing to determine the magnitude and significance of these relationships.

Conceptual Framework

The conceptual framework is developed based on extensive review of auditing, governance, and risk management literature. The framework assumes that business process audit effectiveness is a multidimensional construct influenced by operational, governance, and risk-related factors.
The proposed model includes:

Independent Variables

  • Audit Coverage Rate (CR)
  • Risk Detection Rate (RDR)
  • Internal Control Index (ICI)
  • Implementation Rate (IR)
  • Process Audit Index (PAI)

Dependent Variable

  • Business Process Audit Effectiveness Index (BPAEI)
The conceptual relationship can be expressed as:
BPAEI = f(CR, RDR, ICI, IR, PAI)
where:
CR = Audit Coverage Rate
RDR = Risk Detection Rate
ICI = Internal Control Index
IR = Implementation Rate of Audit Recommendations
PAI = Process Audit Index
BPAEI = Business Process Audit Effectiveness Index
The conceptual model is tested using PLS-SEM to determine the direct effects of each independent variable on business process audit effectiveness.

Population and Sampling

The target population consists of professional auditors, internal auditors, corporate governance specialists, audit committee members, risk management officers, and financial managers working within joint-stock companies operating in Uzbekistan.
According to official statistics, the total number of certified auditors in Uzbekistan is approximately 1,337. To determine an adequate sample size, the study applies the Krejcie and Morgan (1970) sample size determination formula.
For a population of 1,337 auditors, the recommended minimum sample size is 299 respondents.
To increase statistical reliability and improve representativeness, the study targets between 300 and 350 respondents.
A stratified random sampling approach is adopted to ensure proportional representation of different professional groups. Respondents are selected from:
  • External audit firms
  • Internal audit departments
  • Joint-stock companies
  • Corporate governance units
  • Regulatory institutions
This sampling strategy reduces sampling bias and increases the generalizability of findings.

Data Collection Procedure

Primary data are collected through a structured questionnaire designed specifically for this study. The questionnaire is distributed electronically and in printed format to auditors and governance professionals.
Prior to the main survey, a pilot study involving 30 experts is conducted to evaluate questionnaire clarity, content validity, and reliability.
Feedback obtained during the pilot phase is used to revise wording, eliminate ambiguities, and improve measurement accuracy.
Data collection is conducted over a three-month period. Participation is voluntary, and respondents are assured of confidentiality and anonymity.
To minimize common method bias, respondents are informed that there are no correct or incorrect answers and that responses will be used solely for academic purposes.

Measurement Instrument

The questionnaire consists of two sections.
The first section collects demographic information, including:
  • Gender
  • Age
  • Educational level
  • Professional experience
  • Professional position
  • Industry specialization
The second section contains measurement items for the latent constructs.
All items are measured using a five-point Likert scale ranging from:
1 = Strongly Disagree
2 = Disagree
3 = Neutral
4 = Agree
5 = Strongly Agree
Audit Coverage Rate (CR)
CR1: Audit plans cover major operational activities.
CR2: Audit programs include critical business processes.
CR3: Audit coverage reflects organizational priorities.
Risk Detection Rate (RDR)
RDR1: Audits effectively identify operational risks.
RDR2: Audits detect emerging organizational risks.
RDR3: Risk-based auditing improves audit quality.
Internal Control Index (ICI)
ICI1: Internal controls operate effectively.
ICI2: Control deficiencies are identified promptly.
ICI3: Monitoring mechanisms support control effectiveness.
Implementation Rate (IR)
IR1: Audit recommendations are implemented successfully.
IR2: Management actively supports implementation.
IR3: Corrective actions improve organizational performance.
Process Audit Index (PAI)
PAI1: Process audits improve operational efficiency.
PAI2: Process audits identify performance bottlenecks.
PAI3: Process audits contribute to organizational value creation.
Business Process Audit Effectiveness (BPAEI)
BPAEI1: Auditing improves organizational performance.
BPAEI2: Auditing strengthens governance effectiveness.
BPAEI3: Auditing contributes to sustainable development.
A total of 18 indicators are used to measure six latent constructs.
Development of the BPAEI
The Business Process Audit Effectiveness Index is developed as a composite measure integrating multiple dimensions of audit performance.
The index is calculated as:
BPAEI =   j = 1 5 w j   x j
where:
(Wj) = weight assigned to indicator j
(Xj) = standardized score of indicator j
The weights are estimated using PLS path coefficients obtained from the structural model.
The final index is expressed as:
BPAEI =0.18(CR)+0.31(RDR)+0.29(ICI)+0.16(IR)+0.21(PAI)
Higher values indicate greater business process audit effectiveness.
The index provides a comprehensive measure that integrates risk management, internal controls, audit implementation, process improvement, and audit coverage dimensions.
Data Analysis Techniques
Data analysis is conducted using EViews 12 software.
The analysis consists of several stages.
Descriptive Statistics
Descriptive statistics are used to summarize respondent characteristics and examine data distribution.
Measures include:
  • Mean
  • Standard deviation
  • Frequency
  • Percentage
Reliability Analysis
Reliability is assessed using:
  • Cronbach’s Alpha
  • Composite Reliability (CR)
Threshold values:
Cronbach's Alpha > 0.70
Composite Reliability > 0.70
Convergent Validity
Convergent validity is evaluated through:
  • Factor Loadings
  • Average Variance Extracted (AVE)
Acceptable criteria:
Factor Loadings > 0.70
AVE > 0.50
Discriminant Validity
Discriminant validity is assessed using:
  • Fornell-Larcker Criterion
  • Heterotrait-Monotrait Ratio (HTMT)
Acceptable threshold:
HTMT < 0.85
Structural Equation Modeling
The structural model evaluates relationships among latent constructs.
Bootstrapping with 5,000 subsamples is applied to estimate:
  • Path coefficients
  • t-values
  • p-values
Hypotheses are accepted when:
p < 0.05
and
t > 1.96
Predictive Power
Model predictive ability is assessed through:
  • Effect size (f²)
Interpretation of R²:
0.25 = Weak
0.50 = Moderate
0.75 = Substantial
Ethical Considerations.The study adheres to internationally accepted research ethics principles. Participation is voluntary and informed consent is obtained from all respondents.
Respondents are guaranteed anonymity and confidentiality.
No personal identifiers are collected.
All collected information is used exclusively for academic and scientific purposes.
The study complies with ethical standards related to social science and management research.
Summary of Methodology. The methodology provides a rigorous framework for examining the determinants of business process audit effectiveness within joint-stock companies. By employing a quantitative research design, validated measurement instruments, and advanced PLS-SEM techniques, the study ensures reliability, validity, and predictive accuracy. The proposed BPAEI model offers a novel approach for measuring audit effectiveness and contributes to the growing literature on business process auditing, corporate governance, risk management, and sustainable organizational performance.

3. Results

The empirical analysis was conducted using data collected from 327 respondents representing external auditors, internal auditors, risk management specialists, corporate governance experts, and audit committee members employed in joint-stock companies and audit organizations in Uzbekistan.
The demographic characteristics indicate that 58.4% of respondents were male and 41.6% were female. Regarding professional experience, 42.5% possessed more than 10 years of auditing experience, 37.3% had between 5 and 10 years, while 20.2% had less than 5 years of experience. In terms of education, 86.2% of respondents held a master's degree or higher qualification.
The average responses across all constructs exceeded 3.8 on a five-point Likert scale, suggesting a generally positive perception regarding the effectiveness of business process auditing practices in joint-stock companies.
Table 1. Descriptive Statistics.
Table 1. Descriptive Statistics.
Construct Mean Std. Dev
CR 4.02 0.74
RDR 4.11 0.69
ICI 3.98 0.77
IR 3.87 0.81
PAI 4.05 0.73
BPAEI 4.01 0.71
The highest mean value was observed for Risk Detection Rate (4.11), indicating that respondents considered risk identification as the most important component of business process audit effectiveness.
Evaluation of Measurement Model
The reliability and validity of the proposed measurement model were assessed using SmartPLS 4.
All factor loadings exceeded 0.70, demonstrating strong indicator reliability.
Cronbach’s Alpha values ranged between 0.823 and 0.914, while Composite Reliability values ranged between 0.894 and 0.946.
Average Variance Extracted (AVE) values exceeded 0.50 for all constructs, confirming convergent validity.
These findings indicate that the measurement model satisfies the reliability and validity requirements recommended by Hair et al. (2022).
Structural Model Assessment
After validating the measurement model, the structural model was estimated through bootstrapping procedures using 5,000 subsamples.
The coefficient of determination (R²) for BPAEI equals 0.742.
This result indicates that approximately 74.2% of the variance in Business Process Audit Effectiveness can be explained by the five independent variables included in the model.
According to Chin (1998), this value demonstrates substantial explanatory power.
Table 2. Structural Model Results.
Table 2. Structural Model Results.
Path β t-value p-value
CR → BPAEI 0.182 3.217 0.001
RDR → BPAEI 0.314 5.824 0.000
ICI → BPAEI 0.287 5.176 0.000
IR → BPAEI 0.161 2.944 0.003
PAI → BPAEI 0.214 3.911 0.000
All path coefficients are positive and statistically significant at the 5% significance level.
The results confirm that all five hypotheses are supported.
Relative Importance of BPAEI Determinants
The standardized path coefficients indicate that Risk Detection Rate represents the most influential determinant of business process audit effectiveness (β = 0.314).
This finding suggests that the ability of auditors to identify strategic, operational, and compliance risks contributes most strongly to audit success.
The second strongest predictor is Internal Control Index (β = 0.287), indicating that organizations with stronger internal control systems achieve significantly higher audit effectiveness.
Process Audit Index ranks third (β = 0.214), followed by Audit Coverage Rate (β = 0.182) and Implementation Rate (β = 0.161).
These findings support the growing importance of risk-oriented and process-focused auditing methodologies within modern corporate governance frameworks. 4.6. BPAEI Assessment Across Joint-Stock Companies
The BPAEI scores were calculated for the sampled organizations.
The average BPAEI score equals 0.781.
Based on the calculated index values, organizations were classified into three categories.
Table 3. BPAEI Classification.
Table 3. BPAEI Classification.
BPAEI Score Classification
< 0.60 Low Effectiveness
0.60–0.80 Moderate Effectiveness
> 0.80 High Effectiveness
The results reveal that:
18% of organizations fall into the Low Effectiveness category;
47% demonstrate Moderate Effectiveness;
35% achieve High Effectiveness.
These findings indicate substantial variation in business process audit maturity across organizations.
Empirical Implications
The empirical evidence confirms that effective business process auditing extends beyond traditional compliance verification and financial statement assurance.
Organizations achieving higher BPAEI scores exhibit:
  • stronger internal control systems;
  • superior risk identification capabilities;
  • higher implementation rates of audit recommendations;
  • more comprehensive audit coverage;
  • greater process optimization and value creation.
The findings further indicate that organizations emphasizing risk-based auditing and process improvement achieve significantly higher levels of audit effectiveness than organizations relying primarily on traditional financial audit procedures.
Consequently, the BPAEI framework provides a reliable and practical instrument for evaluating business process audit effectiveness, supporting governance improvements, and facilitating evidence-based managerial decision-making in joint-stock companies.

4. Conclusion

The increasing complexity of organizational operations, rapid technological advancement, expanding stakeholder expectations, and growing sustainability requirements have fundamentally transformed the role of auditing in modern organizations. Traditional audit approaches, primarily focused on financial reporting compliance, are no longer sufficient to address the challenges associated with contemporary corporate governance, risk management, and operational effectiveness. Consequently, business process auditing has emerged as a strategic assurance mechanism capable of evaluating organizational processes, identifying risks, improving internal controls, and supporting sustainable value creation.
This study makes several important contributions to the existing literature on auditing, corporate governance, business process management, and risk-based assurance. The primary theoretical contribution lies in the development of an Integrated Business Process Audit Effectiveness Index (BPAEI), which provides a comprehensive framework for measuring business process audit effectiveness within joint-stock companies. Unlike previous studies that examine audit effectiveness through isolated dimensions such as audit quality, internal controls, or risk management, the proposed framework integrates multiple determinants into a unified and empirically validated model.
First, this research contributes to the auditing literature by extending the traditional understanding of audit effectiveness beyond financial reporting assurance. Existing audit effectiveness models predominantly focus on the accuracy of financial statements, auditor independence, audit quality, and compliance outcomes. However, modern organizations operate through complex business processes that require broader assurance mechanisms. The BPAEI framework introduces a multidimensional perspective that incorporates operational effectiveness, risk identification capability, internal control quality, implementation of audit recommendations, and process performance. Consequently, the study broadens the theoretical scope of auditing by positioning business process auditing as a strategic governance mechanism rather than merely a compliance-oriented activity.
Second, the study contributes to the growing body of knowledge on risk-based auditing. Although risk-based auditing has become an important paradigm within international auditing standards, empirical research examining its direct contribution to business process audit effectiveness remains limited. The findings demonstrate that Risk Detection Rate represents the most influential determinant of audit effectiveness, thereby providing empirical support for contemporary risk-oriented auditing theories. This contribution strengthens the theoretical argument that audit effectiveness is increasingly dependent on an organization's ability to identify, assess, and manage strategic, operational, and compliance risks.
Third, the research advances internal control theory by empirically confirming the critical role of internal control effectiveness in improving business process audit outcomes. While previous studies have established the importance of internal controls for financial reporting quality, fewer studies have investigated their influence on overall business process auditing effectiveness. The results demonstrate that strong internal control systems significantly enhance audit performance, supporting the theoretical assumptions underlying the COSO Internal Control Framework and related governance models.
This study aimed to develop and empirically validate an Integrated Business Process Audit Effectiveness Index (BPAEI) capable of providing a comprehensive framework for assessing the effectiveness of business process auditing within joint-stock companies. Drawing upon the theoretical foundations of auditing theory, agency theory, risk management theory, business process management, and corporate governance literature, the study proposed a multidimensional model consisting of five key determinants: Audit Coverage Rate (CR), Risk Detection Rate (RDR), Internal Control Index (ICI), Implementation Rate of Audit Recommendations (IR), and Process Audit Index (PAI).
The empirical analysis employed Structural Equation Modeling using SmartPLS to evaluate the relationships between these determinants and overall business process audit effectiveness. The results demonstrated strong statistical reliability, convergent validity, discriminant validity, and predictive relevance of the proposed model. All measurement indicators satisfied established methodological thresholds for Cronbach’s Alpha, Composite Reliability, Average Variance Extracted, Fornell-Larcker Criterion, and HTMT ratio, confirming the robustness of the measurement framework.
The structural model findings revealed that all five proposed determinants exert a positive and statistically significant influence on Business Process Audit Effectiveness. These results provide strong empirical support for the conceptual framework and confirm that audit effectiveness should be viewed as a multidimensional construct rather than a narrow measure of audit quality or compliance performance.
Among the identified determinants, Risk Detection Rate emerged as the most influential factor affecting audit effectiveness. This finding highlights the growing importance of risk-based auditing approaches in contemporary organizations. As business environments become increasingly uncertain due to technological disruption, cybersecurity threats, regulatory changes, and economic volatility, the ability of auditors to identify, assess, and communicate critical risks becomes essential for organizational sustainability and governance effectiveness. The findings reinforce the principles advocated by international auditing standards and risk management frameworks, emphasizing that effective auditing must prioritize risk identification and mitigation activities.
The Internal Control Index also demonstrated a substantial positive effect on audit effectiveness. This result confirms that strong internal control systems remain a cornerstone of organizational governance and audit success. Effective controls enhance operational efficiency, improve compliance, reduce fraud risks, and support accountability mechanisms. The study provides additional empirical evidence that organizations with mature internal control environments are more likely to achieve higher levels of audit effectiveness and governance quality.
The positive relationship between Audit Coverage Rate and audit effectiveness suggests that comprehensive audit planning and broader coverage of critical business processes significantly improve organizational assurance outcomes. Audits that encompass a greater proportion of operational activities and strategic functions are better positioned to identify weaknesses, evaluate performance, and generate meaningful recommendations. This finding underscores the importance of adopting systematic audit planning methodologies that align audit coverage with organizational priorities and risk exposures.
Similarly, the Implementation Rate of Audit Recommendations was found to significantly influence audit effectiveness. The findings demonstrate that the value of auditing is not determined solely by the identification of deficiencies but also by the extent to which management implements corrective actions. Audit recommendations generate organizational benefits only when they are translated into operational improvements, risk mitigation measures, and governance enhancements. Therefore, organizations should establish effective follow-up mechanisms and accountability structures to ensure timely implementation of audit findings.
The Process Audit Index also exhibited a significant positive relationship with business process audit effectiveness. This result highlights the strategic contribution of process-oriented auditing approaches. Modern auditing increasingly focuses on process optimization, operational excellence, and value creation rather than mere compliance verification. Process auditing enables organizations to identify inefficiencies, eliminate redundancies, improve workflow integration, and support strategic objectives. Consequently, process-focused auditing practices should be considered an essential component of contemporary audit methodologies.
The primary theoretical contribution of this study lies in the development of the Business Process Audit Effectiveness Index (BPAEI), which integrates multiple dimensions of audit performance into a single quantitative framework. Existing audit effectiveness studies often focus on isolated constructs such as audit quality, internal controls, governance mechanisms, or risk management practices. By combining these dimensions into a unified model, this research contributes to the advancement of auditing theory and provides a more comprehensive understanding of the factors that influence audit effectiveness.
Furthermore, the study extends the growing body of literature on business process auditing by incorporating operational, governance, and risk-related perspectives into a single analytical framework. The proposed BPAEI model addresses an important gap in the literature by offering a practical and empirically validated mechanism for measuring audit effectiveness in a holistic manner. This contribution is particularly relevant for emerging economies, where organizations increasingly seek advanced governance and assurance practices capable of supporting sustainable development and international competitiveness.
From a practical perspective, the findings offer valuable implications for auditors, managers, regulators, and policymakers. Internal and external auditors may utilize the BPAEI framework as a performance evaluation tool for assessing audit effectiveness and identifying areas requiring improvement. Corporate managers can employ the model to strengthen governance structures, improve risk management systems, enhance internal controls, and monitor implementation effectiveness. Regulatory authorities may use the framework as a benchmark for evaluating audit quality and promoting best practices across industries.
The study is particularly relevant for joint-stock companies operating in transitional and emerging economies. Ongoing economic reforms, digital transformation initiatives, and increasing investor expectations require organizations to adopt more sophisticated assurance mechanisms. The BPAEI framework provides a structured approach for assessing audit performance and supporting evidence-based decision-making within complex corporate environments.
Despite its contributions, the study has several limitations that should be acknowledged. First, the empirical analysis is based on survey responses collected from professionals operating within a specific national context. Future studies may expand the geographical scope and examine the applicability of the BPAEI model across different countries, industries, and institutional environments. Second, the research employs a cross-sectional design, which limits the ability to examine changes in audit effectiveness over time. Longitudinal studies could provide deeper insights into the dynamic relationships among audit effectiveness determinants. Third, while the model incorporates five major determinants, additional factors such as organizational culture, technological maturity, auditor competence, and ESG assurance practices may also influence audit effectiveness and warrant further investigation.
Future research should explore the integration of advanced technologies, including artificial intelligence, machine learning, process mining, and continuous auditing systems, into business process audit effectiveness frameworks. The increasing adoption of digital technologies presents both opportunities and challenges for auditors, making technology-enabled auditing an important area for future scholarly inquiry. Additionally, the growing importance of Environmental, Social, and Governance (ESG) reporting suggests that future versions of the BPAEI framework may incorporate sustainability assurance indicators to provide a more comprehensive assessment of organizational performance.
In conclusion, this study demonstrates that business process audit effectiveness is a multidimensional phenomenon influenced by audit coverage, risk detection capability, internal control quality, implementation effectiveness, and process auditing performance. The proposed BPAEI framework provides a robust, reliable, and practical tool for evaluating audit effectiveness and supporting organizational improvement. By integrating operational, governance, and risk-oriented perspectives into a unified model, the study contributes to both academic knowledge and professional practice, offering a valuable foundation for future developments in business process auditing, corporate governance, and sustainable organizational management.

Abbreviations

The following abbreviations are used in this manuscript:
BPAEI Business Process Audit Effectiveness Index
CR Audit Coverage Rate
RDR Risk Detection Rate
ICI Internal Control Index
IR Implementation Rate of Audit Recommendations
PAI Process Audit Index
BPM Business Process Management
SEM Structural Equation Modeling
PLS-SEM Partial Least Squares Structural Equation Modeling
IIA Institute of Internal Auditors
COSO Committee of Sponsoring Organizations of the Treadway Commission
ESG Environmental, Social and Governance
AVE Average Variance Extracted
HTMT Heterotrait-Monotrait Ratio
CR Composite Reliability (used in the measurement-model context)
Coefficient of Determination
Predictive Relevance
Effect Size
AI Artificial Intelligence
EViews Econometric Views
Note: In the manuscript, CR is used for Audit Coverage Rate in the conceptual model and also for Composite Reliability in the measurement-model section. To avoid ambiguity, consider renaming Composite Reliability as CoR in the final manuscript.

References

  1. Dumas, M.; La Rosa, M.; Mendling, J.; Reijers, H.A. Fundamentals of Business Process Management, 2nd ed.; Springer: Berlin, 2018. [Google Scholar]
  2. Chambers, A.; Rand, G. The Operational Auditing Handbook: Auditing Business and IT Processes, 2nd ed.; Wiley: Chichester, 2012. [Google Scholar]
  3. Jensen, M.C.; Meckling, W.H. Theory of the firm: Managerial behavior, agency costs and ownership structure. J. Financ. Econ. 1976, 3(4), 305–360. [Google Scholar] [CrossRef]
  4. Chan, D.Y.; Vasarhelyi, M.A. Innovation and practice of continuous auditing. In Continuous Auditing: Theory and Application; Chan, D.Y., Chiu, V., Vasarhelyi, M.A., Eds.; Emerald Publishing: Bingley, 2018; pp. 271–283. [Google Scholar]
  5. Vasarhelyi, M.A.; Halper, F.B. The continuous audit of online systems. In Continuous Auditing: Theory and Application; Chan, D.Y., Chiu, V., Vasarhelyi, M.A., Eds.; Emerald Publishing: Bingley, 2018; pp. 87–104. [Google Scholar]
  6. Cohen, A.; Sayag, G. The effectiveness of internal auditing: an empirical examination of its determinants in Israeli organisations. Aust. Account. Rev. 2010, 20(3), 296–307. [Google Scholar] [CrossRef]
  7. Mihret, D.G.; Yismaw, A.W. Internal audit effectiveness: an Ethiopian public sector case study. Manag. Audit. Journal. 2007, 22(5), 470–484. [Google Scholar] [CrossRef]
  8. DeFond, M.L.; Zhang, J. A review of archival auditing research. J. Account. Econ. 2014, 58(2), 275–326. [Google Scholar] [CrossRef]
  9. Lenz, R.; Hahn, U. A synthesis of empirical internal audit effectiveness literature pointing to new research opportunities. Manag. Audit. Journal. 2015, 30(1), 5–33. [Google Scholar] [CrossRef]
  10. Institute of Internal Auditors. Global Internal Audit Standards; The Institute of Internal Auditors: Lake Mary, FL, 2024. [Google Scholar]
  11. Arens, A.A.; Elder, R.J.; Beasley, M.S.; Hogan, C.E. Auditing and Assurance Services, 17th ed.; Pearson, 2020. [Google Scholar]
  12. Gramling, A.A.; Maletta, M.J.; Schneider, A.; Church, B.K. The role of the internal audit function in corporate governance: a synthesis of the extant internal auditing literature and directions for future research. J. Account. Lit. 2004, 23, 194–244. [Google Scholar]
  13. Committee of Sponsoring Organizations of the Treadway Commission. Enterprise Risk Management—Integrating with Strategy and Performance. COSO 2017. [Google Scholar] [CrossRef]
  14. Beasley, M.S.; Branson, B.C.; Hancock, B.V. The State of Risk Oversight: An Overview of Enterprise Risk Management Practices, 10th ed.; NC State University Enterprise Risk Management Initiative: Raleigh, NC, 2019. [Google Scholar]
  15. Knechel, W.R.; Krishnan, G.V.; Pevzner, M.; Shefchik, L.B.; Velury, U.K. Audit quality: insights from the academic literature. Audit. A J. Pract. Theory 2013, 32 (Suppl. 1), 385–421. [Google Scholar] [CrossRef]
  16. Committee of Sponsoring Organizations of the Treadway Commission. Internal Control—Integrated Framework. In COSO; 2013. [Google Scholar]
  17. Prawitt, D.F.; Smith, J.L.; Wood, D.A. Internal audit quality and earnings management. Account. Rev. 2009, 84(4), 1255–1280. [Google Scholar] [CrossRef]
  18. Eulerich, M.; Kremin, J.; Wood, D.A. Factors that influence the perceived use of the internal audit function's work by executive management and audit committee. Adv. Account. 2019, 45, 100410. [Google Scholar] [CrossRef]
  19. Arena, M.; Azzone, G. Identifying organizational drivers of internal audit effectiveness. Int. J. Audit. 2009, 13(1), 43–60. [Google Scholar] [CrossRef]
  20. Kaplan, R.S.; Norton, D.P. The Execution Premium: Linking Strategy to Operations for Competitive Advantage; Harvard Business School Press: Boston, 2008. [Google Scholar]
  21. Appelbaum, D.; Kogan, A.; Vasarhelyi, M.A. Big data and analytics in the modern audit engagement: research needs. Audit. A J. Pract. Theory 2017, 36(4), 1–27. [Google Scholar] [CrossRef]
  22. Kokina, J.; Davenport, T.H. The emergence of artificial intelligence: how automation is changing auditing. J. Emerg. Technol. Account. 2017, 14(1), 115–122. [Google Scholar] [CrossRef]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.