Reviewed, Not Audited

Introduction

A board audit committee asks a fair question: is our product still Shariah compliant? In response, it receives the Shariah certificate issued at launch, perhaps together with a few subsequent opinions on specific issues. Each document is signed by a respected Shariah adviser. The committee notes them and moves on.
 
The documents are genuine, and the work behind them is genuine. But they answer different questions. The certificate confirms that the product was designed correctly when it was approved. The later opinions confirm that specific issues were addressed correctly. None of them confirms that the product as a whole has been operated correctly from launch until today. That question can only be answered by a Shariah audit. Many institutions have these reviews and believe that they have an audit.
 
Shariah assurance rests on two separate tasks. Shariah review assesses a product in full before launch, and after launch it addresses specific issues and changes as they arise. Shariah audit is a periodic, comprehensive assessment, based on evidence, of everything done from launch up to the audit date. Alongside both, sits the institution’s own Shariah compliance function, which maintains day-to-day operations in order.
This article explains where the line between review and audit falls, how the two become confused, what that confusion costs, and what is required to close the gap.
 

Two Tasks, Two Different Questions

Shariah review asks: is this product, or this specific matter, acceptable under Shariah?
Before launch, the review is comprehensive. It is carried out when a product is first brought to the Shariah adviser or Shariah board, and it covers everything from the drafting stage onwards: licensing and regulatory position; product structure and the sequence of contracts; the structuring of cash flows, profit, fees, security and guarantees; every product document, including term sheets, offering documents, policies and marketing materials; and the agreements with each party, such as customers, investors, agents, trustees, custodians and service providers. If everything is in order, a Shariah certificate or pronouncement is issued. That certificate is what the market calls Shariah compliance.
 
After launch, review continues, but its scope is narrow. When a specific issue arises, a document is amended, a new counterparty is added, or the product is changed, the matter is brought back to the Shariah adviser for review. This remains the Shariah review. It addresses one matter at a time and does not assess how the product has operated as a whole.
 
Regulators treat pre-launch approval as a formal gate. In Malaysia, the Securities Commission requires Islamic capital market products to be assessed by a registered Shariah adviser, whose Shariah pronouncement certifies the product before it is offered, and its 2026 revision strengthened the adviser’s continuing obligations (Securities Commission Malaysia, 2022, revised 2026). IFSB 10 builds Shariah governance around the issuance of Shariah pronouncements and the subsequent verification of compliance (IFSB, 2009). Grais and Pellegrini (2006) identify the Shariah board’s authority to approve new instruments as the starting point of the compliance chain.
 
Shariah audit asks a different question: has everything done since launch been carried out in accordance with the approved basis and the Shariah guidelines? It is periodic, rather than issue-driven. It covers the whole period from launch, or from the last audit, up to the audit date, and relies on evidence: signed transaction documents, the dates and sequence of asset purchases and sales, profit recognition, charity and late payment accounts, financial statements, board and Shariah committee minutes, and the governance and control arrangements surrounding the product. Bank Negara Malaysia describes Shariah audit as a periodic, independent and objective assessment whose main purpose is to confirm that the internal control system for Shariah compliance is sound and effective (Bank Negara Malaysia, 2019).
The difference, therefore, is one of scope and period. A review, however many times it is repeated, answers questions one at a time. An audit answers the full question for the full period.
 

Where Shariah Compliance Fits

Once the certificate is issued, the internal Shariah compliance function keeps daily operations in line with the approved structure: guiding staff, ensuring that approved documents are used, and bringing issues to the Shariah adviser for review. It is part of how the business operates, not an independent stage of assurance, and its effectiveness is one of the matters that a Shariah audit must test.
Some frameworks, including Bank Negara Malaysia (2019) and IFSB 10, also use the word review for ongoing checks after launch.
 

The Standards Point the Same Way

AAOIFI’s own history shows the direction. Governance Standard No. 3, Internal Shariah Review, issued in 1999, relied on internal review of operations (AAOIFI, 1999). In 2019, AAOIFI issued Governance Standard No. 11, Internal Shariah Audit, to replace it (AAOIFI, 2019). The message is that ongoing review, useful as it is, cannot substitute for a structured audit. Governance Standard No. 1, revised in 2024 as the Shariah Governance Framework, sets out the Shariah board’s role in approving products and the separate assurance arrangements that follow (AAOIFI, 2024).
 
The Central Bank of the UAE requires the head of internal Shariah audit to hold a recognised professional certificate in Shariah audit, to have at least ten years of Shariah audit experience, and to report to the Board. It also prohibits the internal Shariah control division from issuing fatwas (CBUAE, 2020). In simple terms, the function that rules should not be the function that audits.
 
Research supports this. Kasim, Ibrahim and Sulaiman (2009) found a clear gap between the Shariah audit that stakeholders expect and the practice institutions actually carry out. Hasan (2011) found that review and audit arrangements differ widely across Malaysia, the GCC and the UK, with limited consistency in how the functions are defined.
 

How the Two Get Confused in Practice

The certificate is treated as permanent. A product certified in 2021 is still presented to the board in 2026 as proof of compliance. But products drift: templates are updated, processes change and systems are replaced. The certificate confirms the design at one point in time only.
 
A file of reviews is treated as an audit. Over several years, the adviser reviews many specific issues and changes. Each review may be sound. But together they show only the matters that someone chose to raise. Problems that nobody raises are never examined.
 
The reporting line weakens. The function was established to report to the Board Audit Committee, but over time it reports through the Chief Compliance Officer or the CEO, and findings are filtered by the management being assessed.
 
There is no charter, no plan and no follow-up. The function examines whatever is escalated, and issues raised one year appear again the next.
 

What This Actually Costs

Non-compliance is found late, and often by outsiders. Without a periodic audit, a product that has drifted from its approved structure can operate for several reporting periods before anyone notices.
Purification obligations build up quietly. Income from non-compliant transactions must be identified, separated and given to charity. Without full-period testing, the amount is not measured reliably, and it grows over time.
The board cannot discharge its duty. Directors who rely on a certificate and a set of issue reviews as though they were an independent audit are governing on a misunderstanding.
Regulatory exposure increases. As frameworks in the UAE, Malaysia, Bahrain, Pakistan and elsewhere become more detailed about Shariah audit, institutions whose arrangements do not match become visible on inspection.
 

Closing the Gap: What Good Practice Requires

Keep a complete review file. For every certified product, record the approved structure, the final documents, the certificate conditions and every subsequent issue review. This file becomes the benchmark for audit.
Bring every change for review. Any material change to the structure, documents or counterparties after launch must be reviewed and approved before it is used.
 
Audit periodically and in full. Set a fixed cycle, and make each audit cover everything done since launch or since the last audit, supported by evidence.
 
Separate the reviewer from the auditor. This is about mandates and reporting, not headcount. An adviser who reviews and an independent party who audits is a proper structure, even in a small institution.
 
Correct the reporting line. The head of Shariah audit should report functionally to the Board Audit Committee.
Use data to test whole populations. Data queries can identify every financing where profit was recognised before the asset was owned, every Murabaha where the sequence of ownership transfers does not match the approved structure, and every account where late payment charges were retained instead of sent to charity.
Formalise the non-compliance lifecycle: identification, escalation to the Shariah board, income measurement, purification, root cause analysis, control correction and closure confirmed by audit.
 

The Underlying Issue

Shariah assurance in many institutions grew out of the advisory function. Advisers are trained to design, solve and certify, which are the right qualities for review. Audit needs different qualities: distance, scepticism and a willingness to record what management would prefer to leave unrecorded. When certificates and issue reviews become the final word, the institution quietly stops asking whether its products, taken as a whole, still deserve them.
 

Conclusion

Review and audit depend on each other. Review sets the approved basis before launch and keeps it current as issues and changes arise. Audit tests, periodically and with evidence, whether everything done since launch has followed that basis. An audit without proper review has no benchmark, and review without audit leaves the full picture unchecked.
 
The remedy is not complicated. Keep a complete review file, bring every change for review, audit the full period on a fixed cycle, correct the reporting line, and make sure the person who approved the product is not the person who audits it.
 
Islamic finance rests on substance over form. A set of reviews presented as an audit is the same problem, appearing in the one place the industry can least afford: the mechanism by which it verifies itself.
 

References

Accounting and Auditing Organization for Islamic Financial Institutions. (1999). Governance Standard No. 3: Internal Shariah review. AAOIFI. https://aaoifi.com
Accounting and Auditing Organization for Islamic Financial Institutions. (2019). Governance Standard No. 11: Internal Shariah audit for Islamic financial institutions. AAOIFI. https://aaoifi.com
Accounting and Auditing Organization for Islamic Financial Institutions. (2024). Governance Standard No. 1 (Revised 2024): Shariah governance framework. AAOIFI. https://aaoifi.com
Accounting and Auditing Organization for Islamic Financial Institutions. (2025). AGEB Statement 1/2025 on Governance Standard No. 1 (Revised 2024): External Shariah audit exemption. AAOIFI. https://aaoifi.com
Bank Negara Malaysia. (2019). Shariah governance policy document. Bank Negara Malaysia. https://www.bnm.gov.my
Central Bank of the United Arab Emirates. (2020). Standard re. Shariah governance for Islamic financial institutions. CBUAE Rulebook. https://rulebook.centralbank.ae/en/rulebook/standard-re-shariah-governance-islamic-financial-institutions
Grais, W., and Pellegrini, M. (2006). Corporate governance and Shariah compliance in institutions offering Islamic financial services (Policy Research Working Paper No. 4054). World Bank. https://hdl.handle.net/10986/8901
Hasan, Z. (2011). A survey on Shariah governance practices in Malaysia, GCC countries and the UK: Critical appraisal. International Journal of Islamic and Middle Eastern Finance and Management, 4(1), 30 to 51.
Islamic Financial Services Board. (2009). IFSB 10: Guiding principles on Shariah governance systems for institutions offering Islamic financial services. IFSB. https://www.ifsb.org
Kasim, N., Ibrahim, S. H. M., and Sulaiman, M. (2009). Shariah auditing in Islamic financial institutions: Exploring the gap between the desired and the actual. Global Economy and Finance Journal, 2(2), 127 to 137.
Kasim, N., NuHtay, S. N., and Salman, S. A. (2013). Comparative analysis on AAOIFI, IFSB and BNM Shariah governance guidelines. International Journal of Business and Social Science, 4(15), 220 to 227.
Securities Commission Malaysia. (2022, revised 2026). Guidelines on Islamic capital market products and services. Securities Commission Malaysia. https://www.sc.com.my
Yaacob, H. (2012). Issues and challenges of Shariah audit in Islamic financial institutions: A contemporary view. Proceedings of the 3rd International Conference on Business and Economics Research. https://ssrn.com/abstract=2175700