Skip to content

01 Internal Audit Fundamentals

Internal auditing is one of the most important assurance functions inside an organization.

It helps answer questions such as:

Are Our Controls
Designed Properly?
Are They Operating
Effectively?
Are Policies
Being Followed?
Are Risks
Being Managed?
Are Compliance
Requirements Met?
Can Management
Rely on the Controls?

Internal Audit provides an independent and structured way to evaluate whether governance, risk-management, and control processes are working as intended.

A simplified internal-audit lifecycle looks like:

Audit Universe
Risk Assessment
Audit Planning
Scope
Evidence Collection
Control Testing
Findings
Management Response
Audit Report
Remediation
Follow-Up

By the end of this lesson, you will be able to:

  • Explain the purpose of Internal Audit.

  • Understand the difference between auditing and compliance.

  • Understand independence and objectivity.

  • Explain assurance and advisory activities.

  • Understand the three-lines model.

  • Understand risk-based auditing.

  • Define audit scope and objectives.

  • Understand the audit universe.

  • Understand audit criteria.

  • Identify control objectives.

  • Distinguish control design from operating effectiveness.

  • Understand audit evidence.

  • Understand control testing.

  • Understand sampling.

  • Understand audit findings.

  • Explain root-cause analysis.

  • Understand corrective and preventive actions.

  • Understand audit reporting.

  • Understand management responses.

  • Understand remediation tracking.

  • Explain follow-up auditing.

  • Understand the role of Internal Audit in GRC.

Internal Audit is an independent assurance activity that evaluates whether an organization’s:

Governance
Risk Management
Internal Controls

are designed and operating effectively.

Conceptually:

Business Operations
Controls
Risk Management
Internal Audit
Independent Assurance
Management / Board

Organizations operate thousands of controls.

Examples:

Access Reviews
Change Approvals
Vulnerability Scanning
Backup Testing
Firewall Reviews
Vendor Assessments
Security Monitoring
Incident Response
Financial Approvals

Management may believe these controls work.

Internal Audit asks:

Can we independently verify that they work?

3. Internal Audit Is an Assurance Function

Section titled “3. Internal Audit Is an Assurance Function”

Internal Audit provides:

Independent Evaluation

of whether:

Expected Control
=
Actual Control

Policy says:

Privileged Access
Must Be Reviewed
Quarterly

Management says:

Access Reviews
Are Performed

Internal Audit tests:

Were Reviews
Actually Performed?
Were All Accounts Included?
Were Reviewers Appropriate?
Were Exceptions Remediated?

These functions overlap but are different.

Compliance asks:

Are We Meeting
Required Rules?

Requirements may come from:

Law
Regulation
Contract
Framework
Policy
Standard

Internal Audit asks:

Are Controls
Designed and Operating
Effectively?

PCI DSS requirement:

Access Must
Be Appropriately
Controlled

Compliance may:

Map Requirement
to Control

Internal Audit may:

Test the Control
Inspect Evidence
Sample Accounts
Identify Exceptions

Performed by:

Internal Audit Function

or co-sourced specialists.

Focus:

Enterprise Risk
Governance
Controls
Operational Improvement

Performed by an independent external organization.

Examples:

Financial Statement Audit
SOC Examination
Certification Audit
Regulatory Audit

A security assessment may focus specifically on:

Technical Controls
Vulnerabilities
Configurations
Architecture

Internal Audit may evaluate:

Technical
+
Process
+
Governance
+
Evidence

One of the most important internal-audit principles is:

The auditor should be sufficiently independent from the activity being audited.

Avoid:

Control Owner
Audits Own Control

This can create:

Conflict of Interest

Objectivity means auditors evaluate evidence without inappropriate:

Bias
Pressure
Personal Interest
Management Influence

Independence relates to:

Organizational Position

Objectivity relates to:

Auditor Judgment

Both are essential.

Assurance means providing confidence that something is operating as expected.

Example:

Management Statement:
All Privileged Accounts
Use MFA

Audit testing:

Population:
250 Accounts
Sample:
40 Accounts
Exceptions:
0

Internal Audit may provide assurance that the control appears to operate effectively within the tested scope.

Audits usually do not provide:

Absolute Guarantee

because auditors may use:

Sampling
Defined Scope
Time-Bounded Testing

Instead they generally provide a level of reasonable assurance based on evidence.

Internal Audit may also perform advisory work.

Examples:

Control Design Review
New System Governance Review
Risk Workshop
Process Improvement
Pre-Implementation Review

However, auditors must preserve independence.

A simplified governance model:

First Line
Business / Operations
Second Line
Risk / Compliance / Security
Third Line
Internal Audit

The first line:

Owns Risk

and:

Operates Controls

Examples:

IT
Engineering
Finance
HR
Operations
Business Units

Second-line functions provide:

Oversight
Standards
Risk Guidance
Monitoring
Challenge

Examples:

GRC
Compliance
Cyber Risk
Privacy
Enterprise Risk

Internal Audit provides:

Independent Assurance

over both:

First Line
and
Second Line

Internal Audit commonly reports functionally to:

Audit Committee

or another appropriate governance body.

This helps protect:

Independence

The Audit Committee may oversee:

Internal Audit
Financial Reporting
Risk
External Audit
Major Control Issues

Create:

01 Internal Audit Charter

A charter commonly defines:

Purpose
Authority
Independence
Responsibilities
Access Rights
Reporting Structure

Internal Audit may require access to:

People
Systems
Records
Reports
Contracts
Evidence
Applications

relevant to approved audit work.

The:

is the complete set of auditable areas within an organization.

Examples:

Identity Management
Cloud Security
Network Security
Incident Response
Vendor Risk
Privacy
Business Continuity
Finance
HR
Application Security
Compliance

Create:

02 Audit Universe Register

Use:

Auditable Area Owner Criticality Risk Last Audit
Enterprise
├── Cybersecurity
│ ├── IAM
│ ├── Vulnerability Management
│ ├── SOC
│ └── Cloud Security
├── Technology
│ ├── Change Management
│ ├── Backup
│ └── Infrastructure
├── Compliance
│ ├── PCI DSS
│ ├── SOC
│ └── Privacy
└── Third Parties
├── Vendor Risk
└── Supplier Security

Internal Audit does not audit every area equally every year.

Instead:

Enterprise Risk
Risk Assessment
Audit Priority

Suppose the audit universe contains:

100 Auditable Areas

but audit resources allow:

20 Audits

Prioritization becomes necessary.

Consider:

Business Criticality
Financial Impact
Cyber Risk
Regulatory Exposure
Control Changes
Incident History
Previous Findings
Management Concern

Create:

03 Audit Risk Assessment

Example:

Area Impact Likelihood Change Audit Priority
IAM High High High Critical
Backup High Medium Medium High
Training Medium Low Low Medium

Risk assessment feeds:

Annual Audit Plan

A plan may include:

Audit Area
Objective
Quarter
Resources
Estimated Duration

An individual audit assignment is often called an:

Audit Engagement

Examples:

IAM Audit
Cloud Security Audit
PCI Compliance Audit
Vendor Risk Audit
Incident Response Audit

Every engagement should have a clear:

Audit Objective

Example:

Determine whether privileged-access controls are appropriately designed and operating effectively.

Scope defines:

What Is Included?
Which Systems?
Which Locations?
Which Period?
Which Processes?
Audit:
Privileged Access Management
Systems:
AWS
Azure
Active Directory
Period:
January–June
Locations:
Global

Also identify:

Out of Scope

Example:

Customer IAM
Not Included

Audit criteria define what the auditor evaluates against.

Examples:

Company Policy
Security Standard
ISO 27001
PCI DSS
Contract
Procedure
Regulatory Requirement

Control expectation:

Privileged Accounts
Must Use MFA

Source:

Enterprise IAM Standard
Section 8.2

That becomes:

Audit Criteria

Scope:

What Will We Audit?

Criteria:

What Standard
Will We Test Against?

A control objective describes:

What risk outcome should the control achieve?

Example:

Prevent Unauthorized
Privileged Access

A control activity describes:

How the Objective
Is Achieved

Example:

MFA Required
for Privileged Users

Create:

04 Audit Control Matrix

Use:

Risk Control Objective Control Criteria Test
Risk Control Objective Control
Unauthorized access Prevent unauthorized privileged access MFA
Excessive access Ensure minimum permissions Access review
Orphan accounts Remove access timely Offboarding

Design effectiveness asks:

If the control operates as designed, would it adequately address the risk?

Policy:

Administrator Access
Must Be Reviewed
Every 12 Months

Risk:

Highly Privileged
Production Accounts

Audit may determine:

Annual Review
Is Not Frequent Enough

Therefore:

Design Deficiency

even if the annual review happens perfectly.

Operating effectiveness asks:

Is the control actually operating as designed?

Example:

Control design:

Quarterly Access Review

Evidence:

Q1 Completed
Q2 Not Completed
Q3 Completed
Q4 Completed

Potential:

Operating Effectiveness
Exception
Control Requirement
Design Effective?
├── No → Design Finding
└── Yes
Operating Effectively?
┌────┴────┐
No Yes
↓ ↓
Operating Finding Pass

Not every control has equal importance.

A:

Key Control

is especially important in reducing material risk.

Examples:

MFA
Financial Approval
Production Change Approval
Backup Restoration
Vendor Risk Approval

Prevent events before they occur.

Examples:

MFA
Firewall
Approval Workflow
Segregation of Duties

Detect events after or while they occur.

Examples:

SIEM Alert
Access Review
Reconciliation
Log Review

Reduce impact after an event.

Examples:

Incident Response
Backup Restoration
Account Disablement
Patch Deployment

Performed by people.

Example:

Manager Reviews
Quarterly Access List

Performed by technology.

Example:

IAM Automatically
Disables Accounts
after 90 Days

A person performs the control using system-generated information.

Example:

Manager Reviews
IAM Access Report

The auditor may need to validate:

Report Completeness
Report Accuracy

Evidence supports audit conclusions.

Common evidence includes:

Policies
Procedures
Screenshots
System Reports
Logs
Tickets
Configurations
Contracts
Meeting Records
Interviews

Strong evidence should be:

Relevant
Reliable
Sufficient
Appropriate
Traceable

Evidence must relate to:

Control Being Tested

Generally stronger:

System-Generated Evidence

than:

Unverified Verbal Statement

depending on context.

The auditor must gather enough evidence to support a conclusion.

One example may not be enough to conclude:

Control Operates
for Entire Population

Conceptually:

Verbal Statement
Document
System Report
Configuration
Independent Verification

The exact strength depends on the control.

Create:

05 Audit Evidence Register

Use:

Evidence ID Control Source Period Received Validated

Use:

AE-001
AE-002
AE-003

to maintain traceability.

A strong evidence request specifies:

What?
Which Period?
Which System?
Which Population?
Which Format?
Please Send
Access Evidence
Provide the complete
population of privileged
AWS IAM users and roles
active from January 1
through March 31.

Interviews help auditors understand:

Process
Control Design
Responsibilities
Exceptions
System Behavior

But interview statements should often be corroborated.

A walkthrough follows a transaction or process from beginning to end.

Example:

Access Request
Manager Approval
IAM Provisioning
System Access
Logging

Walkthroughs help determine:

How the Process
Actually Works

rather than relying only on:

Written Procedure

Testing determines whether controls are:

Designed Correctly
Operating Effectively

Auditors may use:

Inquiry
Inspection
Observation
Reperformance
Data Analysis

Ask responsible personnel:

How Does
the Control Work?

Inquiry alone usually provides weaker evidence.

Review:

Documents
Tickets
Logs
Reports
Configurations

Watch control execution.

Example:

Observe
Backup Restore
Process

The auditor independently performs:

Control Procedure

or recalculation.

Example:

Recalculate
User Access
Exception Count

Auditors may analyze entire populations.

Examples:

All User Accounts
All Firewall Rules
All Vendor Records
All Changes

This can reduce reliance on small samples.

The:

Population

is the complete set of items relevant to the control.

Example:

All Production
Changes During 2026

When testing all items is impractical, auditors may select a:

Sample

Example:

Population:
5,000 Changes
Sample:
60 Changes

Because only part of the population is tested:

Sample Result

may not perfectly represent:

Entire Population

Methods may include:

Random
Systematic
Judgmental
Risk-Based

depending on methodology.

Create:

06 Audit Test Sheet

Use:

Sample Control Criteria Evidence Result Exception

A sample passes when:

Control Meets Criteria

An exception occurs when:

Expected Control
Observed Control

Control:

All Terminated Users
Disabled Within 24 Hours

Sample:

30 Terminations

Results:

28 Disabled Within 24 Hours
2 Disabled After 5 Days

Exceptions:

2

83. Exception Does Not Automatically Equal Finding

Section titled “83. Exception Does Not Automatically Equal Finding”

Auditors should determine:

Frequency
Cause
Impact
Population Exposure
Compensating Controls

before finalizing a finding.

If exceptions appear, the auditor may:

Increase Sample
Analyze Entire Population
Perform Additional Interviews

A strong audit finding usually includes:

Condition
Criteria
Cause
Effect / Risk
Recommendation

What was observed?

Example:

3 of 30
Terminated Accounts
Were Disabled
More Than 24 Hours
After Termination

What should have happened?

Example:

IAM Standard Requires
Termination Access
to Be Removed
Within 24 Hours

Why did the issue occur?

Example:

HR Termination Feed
Failed to Send
Notifications to IAM

What risk results?

Example:

Former Employees
May Retain
Unauthorized Access

What should management improve?

Example:

Implement Automated
Termination Integration
and Exception Monitoring

Create:

07 Audit Findings Register

Use:

ID Finding Severity Owner Due Status

Organizations may use:

Critical
High
Medium
Low

or other rating models.

Consider:

Business Impact
Likelihood
Control Importance
Regulatory Exposure
Population Size
Duration
Compensating Controls

Strong auditing looks beyond:

What Failed?

to:

Why Did It Fail?

Finding:

Access Reviews
Were Not Completed

Why?

Managers Did Not
Complete Reviews

Why?

No Escalation Process

Why?

Access Review Workflow
Does Not Track
Overdue Reviewers

Root cause:

Insufficient Governance
and Escalation

Fix the immediate issue.

Example:

Complete
Outstanding Review

Prevent recurrence.

Example:

Implement Automated
Review Escalation

Prevent similar issues elsewhere.

Example:

Deploy the Same
Automated Review Workflow
Across All Applications

Organizations may use:

Corrective and
Preventive Action

or:

CAPA

to manage systemic remediation.

Management should respond to findings with:

Agreement / Disagreement
Corrective Action
Owner
Target Date

100. Auditor vs Management Responsibilities

Section titled “100. Auditor vs Management Responsibilities”

Auditor:

Identifies Risk
and Recommends Improvement

Management:

Owns Remediation

Avoid:

Auditor
Designs
+
Implements
+
Tests
Same Control

because independence can be impaired.

The audit report communicates:

Objective
Scope
Conclusion
Findings
Risk
Management Response

Create:

08 Internal Audit Report Template

Suggested sections:

Executive Summary
Audit Objective
Scope
Methodology
Overall Conclusion
Key Findings
Detailed Findings
Management Responses
Action Plan

Executives should understand:

What Was Audited?
What Was Found?
How Serious?
What Needs Attention?

Organizations may use ratings such as:

Effective
Generally Effective
Needs Improvement
Ineffective

or another approved model.

Overall rating should be traceable to:

Testing Results
Findings
Severity
Control Coverage

Audit often produces:

Draft Report

for management review.

Management may identify:

Factual Errors
Missing Context
New Evidence

The auditor should evaluate this objectively.

109. Auditor Independence During Challenge

Section titled “109. Auditor Independence During Challenge”

Management disagreement does not automatically mean:

Remove Finding

Auditor should ask:

Does New Evidence
Change the Conclusion?

After factual validation and management responses:

Draft
Review
Final

Distribution may include:

Process Owner
Business Leadership
Risk
Security Leadership
Audit Committee

depending on severity and governance.

Audit findings should not disappear after report issuance.

Track:

Finding
Owner
Action
Due Date
Status
Evidence
Validation

Use:

Open
In Progress
Pending Validation
Closed
Risk Accepted

When:

Current Date
>
Target Date

and remediation is incomplete:

Finding
=
Overdue

Track:

0–30 Days
31–60 Days
61–90 Days
90+ Days

Example:

High Finding
Past Due
Process Owner
Executive Owner
Audit Leadership
Audit Committee

depending on governance.

Possible evidence:

Updated Policy
Configuration
Ticket
System Report
Reperformance
Independent Test

Do not close a finding because management says:

Fixed

Audit should verify:

Action Completed?
Control Effective?
Risk Addressed?

A follow-up may verify:

Findings Remediated?
Controls Sustainable?
New Issues Introduced?

Management may accept certain risks.

Audit should determine whether:

Correct Authority?
Documented?
Time-Bound?
Within Risk Appetite?

121. Internal Audit Does Not Accept Business Risk

Section titled “121. Internal Audit Does Not Accept Business Risk”

Audit may:

Challenge
Report
Escalate

but the appropriate business or risk authority:

Accepts Risk

Every audit should maintain traceability from:

Risk
Control
Test
Evidence
Result
Finding
Report

Working papers support the audit conclusion.

Examples:

Planning Documents
Risk Assessment
Control Matrix
Evidence
Test Sheets
Samples
Interview Notes
Findings
Review Notes

Create:

Internal-Audit/
├── 01 Planning/
├── 02 Scope/
├── 03 Risk Assessment/
├── 04 Control Matrix/
├── 05 Evidence/
├── 06 Testing/
├── 07 Findings/
├── 08 Management Response/
├── 09 Report/
└── 10 Follow-Up/

A reviewer should be able to determine:

What Was Tested?
How?
Using What Evidence?
What Was the Result?
Why Did Auditor
Reach Conclusion?

A useful mindset:

If the audit work is not documented, it may be difficult to demonstrate that it was performed.

Audit work may be reviewed by:

Senior Auditor
Audit Manager
Quality Assurance

Review:

Was Scope Appropriate?
Was Evidence Sufficient?
Was Testing Complete?
Are Findings Supported?
Is Severity Reasonable?
Are Conclusions Traceable?

Auditors should maintain:

Professional Skepticism

Meaning:

Trust
but
Verify

Do not assume:

Policy Exists
=
Control Works

Criteria:

100%
Privileged Accounts
Must Use MFA

Population:

250 Accounts

Testing identifies:

243 MFA Enabled
7 Without MFA

Coverage:

243
─── × 100
250
= 97.2%

Potential finding:

Seven privileged accounts were not protected by required multi-factor authentication.

Control:

Quarterly Review

Expected:

4 Reviews

Performed:

3

Operating effectiveness:

Ineffective /
Partially Effective

depending on methodology.

Control:

Monthly Restore Test

Evidence:

12 Months Required
7 Tests Completed

Potential finding:

Recovery Capability
Not Consistently Validated

Policy:

All Tier 1 Vendors
Require Annual
Risk Assessment

Population:

40 Tier 1 Vendors

Current assessment:

34

Coverage:

85%

Finding:

6 Critical Vendors
Without Current
Risk Assessment

Policy:

Personal Data
Must Be Deleted
After Retention Period

Testing identifies:

Expired Records
Still Stored

Potential:

Privacy
and Compliance Risk

Requirement:

Cloud Audit Logs
Must Be Enabled

Population:

100 Cloud Accounts

Result:

95 Enabled
5 Disabled

Finding:

Security Activity
May Not Be
Fully Traceable

Internal Audit may track:

Audit Plan Completion
Audit Cycle Time
Finding Closure
Overdue Findings
Repeat Findings
Management Acceptance
Audits Completed
──────────────── × 100
Audits Planned
Findings Closed
Within Due Date
──────────────── × 100
Findings Due
High / Critical
Audit Findings
Past Due
Audit Findings
Repeated Across
Multiple Audit Cycles

Create:

09 Internal Audit Dashboard

Example:

Metric Target
Audit plan completion 100%
High findings overdue 0
Critical findings open 0
Repeat findings 0
Remediation within SLA 100%

Mistake 1 — Auditing Without Defined Criteria

Section titled “Mistake 1 — Auditing Without Defined Criteria”

Without criteria, conclusions become subjective.

An audit trying to cover everything may test nothing deeply.

People can describe how a control should work rather than how it actually works.

A policy demonstrates design expectations, not necessarily operation.

A sample is unreliable if the underlying population is incomplete.

Mistake 6 — Finding Based on One Exception Without Analysis

Section titled “Mistake 6 — Finding Based on One Exception Without Analysis”

Understand frequency, cause, and impact.

Fixing symptoms may allow the issue to return.

This can impair independence.

Mistake 9 — Closing Findings Without Validation

Section titled “Mistake 9 — Closing Findings Without Validation”

Management completion is not the same as verified remediation.

Unsupported conclusions are difficult to defend.

Not every exception is Critical or High.

Mistake 12 — Reporting Detail Without Business Impact

Section titled “Mistake 12 — Reporting Detail Without Business Impact”

Executives need to understand why a finding matters.

Ask Questions
Collect Documents
Find Problems
Write Report
Audit Universe
Risk Assessment
Audit Plan
Objective
Scope
Criteria
Control Matrix
Evidence
Testing
Exceptions
Root Cause
Findings
Management Response
Report
Remediation
Validation
Follow-Up

GRC and Internal Audit frequently work together.

GRC may:

Define Controls
Maintain Risk Registers
Coordinate Compliance
Collect Evidence
Track Findings

Internal Audit may:

Independently Test
Challenge
Validate
Report

146. Internal Audit and Compliance Relationship

Section titled “146. Internal Audit and Compliance Relationship”
Compliance
Requirements
Controls
Evidence
Internal Audit
Independent Testing

For every control ask:

What Risk
Does This Control
Address?
What Should
the Control Do?
What Criteria
Requires It?
Who Owns It?
How Often
Should It Operate?
What Is the
Population?
What Evidence
Proves It Operated?
Is the Control
Designed Properly?
Did It Actually
Operate?
How Many
Exceptions Exist?
Are Exceptions
Isolated or Systemic?
Why Did
They Occur?
What Risk
Do They Create?
Is the Finding
Supported by Evidence?
Who Owns
Remediation?
When Is It Due?
How Will We
Validate Closure?
Can Another Auditor
Reperform Our Work
Using the Documentation?

That is the practical mindset behind Internal Audit.

  • Internal Audit provides independent assurance over governance, risk management, and controls.

  • Independence and objectivity are fundamental audit principles.

  • Compliance determines whether requirements are met; Internal Audit independently tests whether controls actually work.

  • Internal Audit commonly operates as the third line within enterprise governance.

  • Risk-based auditing prioritizes audit resources according to enterprise risk.

  • The audit universe identifies the organization’s auditable areas.

  • Every audit should define objectives, scope, and criteria.

  • Control objectives describe desired risk outcomes.

  • Control design and operating effectiveness must be evaluated separately.

  • Audit evidence should be relevant, reliable, sufficient, and traceable.

  • Walkthroughs help auditors understand how processes really operate.

  • Testing may use inquiry, inspection, observation, reperformance, and data analytics.

  • Sampling should be based on a defined and complete population.

  • Exceptions should be analyzed before becoming findings.

  • Strong findings describe condition, criteria, cause, effect, and recommendation.

  • Root-cause analysis helps prevent repeated issues.

  • Management owns remediation; auditors independently validate it.

  • Findings should remain tracked until closure is verified.

  • Follow-up auditing confirms whether corrective actions are sustainable.

  • Working papers provide evidence supporting audit conclusions.

  • Audit reports should communicate material risk and required action clearly.

  • GRC and Internal Audit work closely but must maintain appropriate independence.

Before continuing, make sure you can answer:

  1. What is Internal Audit?

  2. Why does Internal Audit exist?

  3. What is the difference between auditing and compliance?

  4. What is the difference between Internal Audit and External Audit?

  5. Why is auditor independence important?

  6. What is auditor objectivity?

  7. What is assurance?

  8. What is the three-lines model?

  9. What does the first line do?

  10. What does the second line do?

  11. What does the third line do?

  12. What is an Internal Audit Charter?

  13. What is an audit universe?

  14. What is risk-based auditing?

  15. What is an audit objective?

  16. What is audit scope?

  17. What are audit criteria?

  18. What is a control objective?

  19. What is design effectiveness?

  20. What is operating effectiveness?

  21. What is audit evidence?

  22. What makes evidence reliable and sufficient?

  23. What is a walkthrough?

  24. What are the common control-testing methods?

  25. What is an audit population?

  26. Why is sampling used?

  27. What is an audit exception?

  28. What makes a strong audit finding?

  29. What is root-cause analysis?

  30. Why must remediation be independently validated?

➡️ Next: 02 — Audit Planning

In the next lesson, you will move from Internal Audit fundamentals into designing and preparing a complete audit engagement.

You will work through:

Audit Universe
Risk Assessment
Audit Selection
Background Research
Audit Objective
Scope
Criteria
Risk & Control Analysis
Audit Program
Resource Planning
Stakeholder Communication
Fieldwork Readiness

You will learn how to build an Annual Audit Plan, Audit Engagement Planning Memo, Risk Assessment, Audit Scope Statement, Audit Control Matrix, Audit Program, Evidence Request List, Stakeholder Communication Plan, Audit Timeline, and Planning Checklist.

This will prepare you to move from understanding what Internal Audit is to actually planning and executing a professional audit engagement.