01 Internal Audit Fundamentals
Internal auditing is one of the most important assurance functions inside an organization.
It helps answer questions such as:
Are Our ControlsDesigned Properly?
Are They OperatingEffectively?
Are PoliciesBeing Followed?
Are RisksBeing Managed?
Are ComplianceRequirements Met?
Can ManagementRely on the Controls?Internal Audit provides an independent and structured way to evaluate whether governance, risk-management, and control processes are working as intended.
A simplified internal-audit lifecycle looks like:
Audit Universe ↓Risk Assessment ↓Audit Planning ↓Scope ↓Evidence Collection ↓Control Testing ↓Findings ↓Management Response ↓Audit Report ↓Remediation ↓Follow-UpLearning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain the purpose of Internal Audit.
-
Understand the difference between auditing and compliance.
-
Understand independence and objectivity.
-
Explain assurance and advisory activities.
-
Understand the three-lines model.
-
Understand risk-based auditing.
-
Define audit scope and objectives.
-
Understand the audit universe.
-
Understand audit criteria.
-
Identify control objectives.
-
Distinguish control design from operating effectiveness.
-
Understand audit evidence.
-
Understand control testing.
-
Understand sampling.
-
Understand audit findings.
-
Explain root-cause analysis.
-
Understand corrective and preventive actions.
-
Understand audit reporting.
-
Understand management responses.
-
Understand remediation tracking.
-
Explain follow-up auditing.
-
Understand the role of Internal Audit in GRC.
1. What Is Internal Audit?
Section titled “1. What Is Internal Audit?”Internal Audit is an independent assurance activity that evaluates whether an organization’s:
Governance
Risk Management
Internal Controlsare designed and operating effectively.
Conceptually:
Business Operations ↓Controls ↓Risk Management ↓Internal Audit ↓Independent Assurance ↓Management / Board2. Why Internal Audit Exists
Section titled “2. Why Internal Audit Exists”Organizations operate thousands of controls.
Examples:
Access Reviews
Change Approvals
Vulnerability Scanning
Backup Testing
Firewall Reviews
Vendor Assessments
Security Monitoring
Incident Response
Financial ApprovalsManagement may believe these controls work.
Internal Audit asks:
Can we independently verify that they work?
3. Internal Audit Is an Assurance Function
Section titled “3. Internal Audit Is an Assurance Function”Internal Audit provides:
Independent Evaluationof whether:
Expected Control=Actual Control4. Example
Section titled “4. Example”Policy says:
Privileged AccessMust Be ReviewedQuarterlyManagement says:
Access ReviewsAre PerformedInternal Audit tests:
Were ReviewsActually Performed?
Were All Accounts Included?
Were Reviewers Appropriate?
Were Exceptions Remediated?5. Internal Audit vs Compliance
Section titled “5. Internal Audit vs Compliance”These functions overlap but are different.
Compliance
Section titled “Compliance”Compliance asks:
Are We MeetingRequired Rules?Requirements may come from:
Law
Regulation
Contract
Framework
Policy
StandardInternal Audit
Section titled “Internal Audit”Internal Audit asks:
Are ControlsDesigned and OperatingEffectively?6. Example
Section titled “6. Example”PCI DSS requirement:
Access MustBe AppropriatelyControlledCompliance may:
Map Requirementto ControlInternal Audit may:
Test the Control
Inspect Evidence
Sample Accounts
Identify Exceptions7. Internal Audit vs External Audit
Section titled “7. Internal Audit vs External Audit”Internal Audit
Section titled “Internal Audit”Performed by:
Internal Audit Functionor co-sourced specialists.
Focus:
Enterprise Risk
Governance
Controls
Operational ImprovementExternal Audit
Section titled “External Audit”Performed by an independent external organization.
Examples:
Financial Statement Audit
SOC Examination
Certification Audit
Regulatory Audit8. Internal Audit vs Security Assessment
Section titled “8. Internal Audit vs Security Assessment”A security assessment may focus specifically on:
Technical Controls
Vulnerabilities
Configurations
ArchitectureInternal Audit may evaluate:
Technical+Process+Governance+Evidence9. Independence
Section titled “9. Independence”One of the most important internal-audit principles is:
Independence
Section titled “Independence”The auditor should be sufficiently independent from the activity being audited.
Avoid:
Control Owner ↓Audits Own ControlThis can create:
Conflict of Interest10. Objectivity
Section titled “10. Objectivity”Objectivity means auditors evaluate evidence without inappropriate:
Bias
Pressure
Personal Interest
Management Influence11. Independence vs Objectivity
Section titled “11. Independence vs Objectivity”Independence relates to:
Organizational PositionObjectivity relates to:
Auditor JudgmentBoth are essential.
12. Assurance
Section titled “12. Assurance”Assurance means providing confidence that something is operating as expected.
Example:
Management Statement:All Privileged AccountsUse MFAAudit testing:
Population:250 Accounts
Sample:40 Accounts
Exceptions:0Internal Audit may provide assurance that the control appears to operate effectively within the tested scope.
13. Reasonable Assurance
Section titled “13. Reasonable Assurance”Audits usually do not provide:
Absolute Guaranteebecause auditors may use:
Sampling
Defined Scope
Time-Bounded TestingInstead they generally provide a level of reasonable assurance based on evidence.
14. Advisory Activities
Section titled “14. Advisory Activities”Internal Audit may also perform advisory work.
Examples:
Control Design Review
New System Governance Review
Risk Workshop
Process Improvement
Pre-Implementation ReviewHowever, auditors must preserve independence.
15. The Three Lines Model
Section titled “15. The Three Lines Model”A simplified governance model:
First LineBusiness / Operations
Second LineRisk / Compliance / Security
Third LineInternal Audit16. First Line
Section titled “16. First Line”The first line:
Owns Riskand:
Operates ControlsExamples:
IT
Engineering
Finance
HR
Operations
Business Units17. Second Line
Section titled “17. Second Line”Second-line functions provide:
Oversight
Standards
Risk Guidance
Monitoring
ChallengeExamples:
GRC
Compliance
Cyber Risk
Privacy
Enterprise Risk18. Third Line
Section titled “18. Third Line”Internal Audit provides:
Independent Assuranceover both:
First Line
and
Second Line19. Internal Audit Reporting
Section titled “19. Internal Audit Reporting”Internal Audit commonly reports functionally to:
Audit Committeeor another appropriate governance body.
This helps protect:
Independence20. Audit Committee
Section titled “20. Audit Committee”The Audit Committee may oversee:
Internal Audit
Financial Reporting
Risk
External Audit
Major Control Issues21. Internal Audit Charter
Section titled “21. Internal Audit Charter”Create:
01 Internal Audit CharterA charter commonly defines:
Purpose
Authority
Independence
Responsibilities
Access Rights
Reporting Structure22. Audit Authority
Section titled “22. Audit Authority”Internal Audit may require access to:
People
Systems
Records
Reports
Contracts
Evidence
Applicationsrelevant to approved audit work.
23. Audit Universe
Section titled “23. Audit Universe”The:
Audit Universe
Section titled “Audit Universe”is the complete set of auditable areas within an organization.
Examples:
Identity Management
Cloud Security
Network Security
Incident Response
Vendor Risk
Privacy
Business Continuity
Finance
HR
Application Security
Compliance24. Build an Audit Universe
Section titled “24. Build an Audit Universe”Create:
02 Audit Universe RegisterUse:
| Auditable Area | Owner | Criticality | Risk | Last Audit |
|---|
25. Audit Universe Example
Section titled “25. Audit Universe Example”Enterprise├── Cybersecurity│ ├── IAM│ ├── Vulnerability Management│ ├── SOC│ └── Cloud Security├── Technology│ ├── Change Management│ ├── Backup│ └── Infrastructure├── Compliance│ ├── PCI DSS│ ├── SOC│ └── Privacy└── Third Parties ├── Vendor Risk └── Supplier Security26. Risk-Based Auditing
Section titled “26. Risk-Based Auditing”Internal Audit does not audit every area equally every year.
Instead:
Enterprise Risk ↓Risk Assessment ↓Audit Priority27. Why Risk-Based Auditing Matters
Section titled “27. Why Risk-Based Auditing Matters”Suppose the audit universe contains:
100 Auditable Areasbut audit resources allow:
20 AuditsPrioritization becomes necessary.
28. Audit Risk Factors
Section titled “28. Audit Risk Factors”Consider:
Business Criticality
Financial Impact
Cyber Risk
Regulatory Exposure
Control Changes
Incident History
Previous Findings
Management Concern29. Audit Risk Assessment
Section titled “29. Audit Risk Assessment”Create:
03 Audit Risk AssessmentExample:
| Area | Impact | Likelihood | Change | Audit Priority |
|---|---|---|---|---|
| IAM | High | High | High | Critical |
| Backup | High | Medium | Medium | High |
| Training | Medium | Low | Low | Medium |
30. Annual Audit Plan
Section titled “30. Annual Audit Plan”Risk assessment feeds:
Annual Audit PlanA plan may include:
Audit Area
Objective
Quarter
Resources
Estimated Duration31. Audit Engagement
Section titled “31. Audit Engagement”An individual audit assignment is often called an:
Audit EngagementExamples:
IAM Audit
Cloud Security Audit
PCI Compliance Audit
Vendor Risk Audit
Incident Response Audit32. Audit Objective
Section titled “32. Audit Objective”Every engagement should have a clear:
Audit ObjectiveExample:
Determine whether privileged-access controls are appropriately designed and operating effectively.
33. Audit Scope
Section titled “33. Audit Scope”Scope defines:
What Is Included?
Which Systems?
Which Locations?
Which Period?
Which Processes?34. Scope Example
Section titled “34. Scope Example”Audit:Privileged Access Management
Systems:AWSAzureActive Directory
Period:January–June
Locations:Global35. Scope Boundaries
Section titled “35. Scope Boundaries”Also identify:
Out of ScopeExample:
Customer IAMNot Included36. Audit Criteria
Section titled “36. Audit Criteria”Audit criteria define what the auditor evaluates against.
Examples:
Company Policy
Security Standard
ISO 27001
PCI DSS
Contract
Procedure
Regulatory Requirement37. Criteria Example
Section titled “37. Criteria Example”Control expectation:
Privileged AccountsMust Use MFASource:
Enterprise IAM StandardSection 8.2That becomes:
Audit Criteria38. Audit Scope vs Criteria
Section titled “38. Audit Scope vs Criteria”Scope:
What Will We Audit?Criteria:
What StandardWill We Test Against?39. Control Objective
Section titled “39. Control Objective”A control objective describes:
What risk outcome should the control achieve?
Example:
Prevent UnauthorizedPrivileged Access40. Control Activity
Section titled “40. Control Activity”A control activity describes:
How the ObjectiveIs AchievedExample:
MFA Requiredfor Privileged Users41. Audit Control Matrix
Section titled “41. Audit Control Matrix”Create:
04 Audit Control MatrixUse:
| Risk | Control Objective | Control | Criteria | Test |
|---|
42. Example
Section titled “42. Example”| Risk | Control Objective | Control |
|---|---|---|
| Unauthorized access | Prevent unauthorized privileged access | MFA |
| Excessive access | Ensure minimum permissions | Access review |
| Orphan accounts | Remove access timely | Offboarding |
43. Control Design
Section titled “43. Control Design”Design effectiveness asks:
If the control operates as designed, would it adequately address the risk?
44. Design Example
Section titled “44. Design Example”Policy:
Administrator AccessMust Be ReviewedEvery 12 MonthsRisk:
Highly PrivilegedProduction AccountsAudit may determine:
Annual ReviewIs Not Frequent EnoughTherefore:
Design Deficiencyeven if the annual review happens perfectly.
45. Operating Effectiveness
Section titled “45. Operating Effectiveness”Operating effectiveness asks:
Is the control actually operating as designed?
Example:
Control design:
Quarterly Access ReviewEvidence:
Q1 CompletedQ2 Not CompletedQ3 CompletedQ4 CompletedPotential:
Operating EffectivenessException46. Design vs Operating Effectiveness
Section titled “46. Design vs Operating Effectiveness”Control Requirement ↓Design Effective? │ ├── No → Design Finding │ └── Yes ↓ Operating Effectively? │ ┌────┴────┐ No Yes ↓ ↓Operating Finding Pass47. Key Controls
Section titled “47. Key Controls”Not every control has equal importance.
A:
Key Controlis especially important in reducing material risk.
Examples:
MFA
Financial Approval
Production Change Approval
Backup Restoration
Vendor Risk Approval48. Preventive Controls
Section titled “48. Preventive Controls”Prevent events before they occur.
Examples:
MFA
Firewall
Approval Workflow
Segregation of Duties49. Detective Controls
Section titled “49. Detective Controls”Detect events after or while they occur.
Examples:
SIEM Alert
Access Review
Reconciliation
Log Review50. Corrective Controls
Section titled “50. Corrective Controls”Reduce impact after an event.
Examples:
Incident Response
Backup Restoration
Account Disablement
Patch Deployment51. Manual Controls
Section titled “51. Manual Controls”Performed by people.
Example:
Manager ReviewsQuarterly Access List52. Automated Controls
Section titled “52. Automated Controls”Performed by technology.
Example:
IAM AutomaticallyDisables Accountsafter 90 Days53. IT-Dependent Manual Controls
Section titled “53. IT-Dependent Manual Controls”A person performs the control using system-generated information.
Example:
Manager ReviewsIAM Access ReportThe auditor may need to validate:
Report Completeness
Report Accuracy54. Audit Evidence
Section titled “54. Audit Evidence”Evidence supports audit conclusions.
Common evidence includes:
Policies
Procedures
Screenshots
System Reports
Logs
Tickets
Configurations
Contracts
Meeting Records
Interviews55. Evidence Characteristics
Section titled “55. Evidence Characteristics”Strong evidence should be:
Relevant
Reliable
Sufficient
Appropriate
Traceable56. Relevant Evidence
Section titled “56. Relevant Evidence”Evidence must relate to:
Control Being Tested57. Reliable Evidence
Section titled “57. Reliable Evidence”Generally stronger:
System-Generated Evidencethan:
Unverified Verbal Statementdepending on context.
58. Sufficient Evidence
Section titled “58. Sufficient Evidence”The auditor must gather enough evidence to support a conclusion.
One example may not be enough to conclude:
Control Operatesfor Entire Population59. Evidence Hierarchy
Section titled “59. Evidence Hierarchy”Conceptually:
Verbal Statement ↓Document ↓System Report ↓Configuration ↓Independent VerificationThe exact strength depends on the control.
60. Audit Evidence Register
Section titled “60. Audit Evidence Register”Create:
05 Audit Evidence RegisterUse:
| Evidence ID | Control | Source | Period | Received | Validated |
|---|
61. Evidence Identification
Section titled “61. Evidence Identification”Use:
AE-001
AE-002
AE-003to maintain traceability.
62. Evidence Request
Section titled “62. Evidence Request”A strong evidence request specifies:
What?
Which Period?
Which System?
Which Population?
Which Format?63. Weak Evidence Request
Section titled “63. Weak Evidence Request”Please SendAccess Evidence64. Strong Evidence Request
Section titled “64. Strong Evidence Request”Provide the completepopulation of privilegedAWS IAM users and rolesactive from January 1through March 31.65. Audit Interviews
Section titled “65. Audit Interviews”Interviews help auditors understand:
Process
Control Design
Responsibilities
Exceptions
System BehaviorBut interview statements should often be corroborated.
66. Walkthrough
Section titled “66. Walkthrough”A walkthrough follows a transaction or process from beginning to end.
Example:
Access Request ↓Manager Approval ↓IAM Provisioning ↓System Access ↓Logging67. Why Walkthroughs Matter
Section titled “67. Why Walkthroughs Matter”Walkthroughs help determine:
How the ProcessActually Worksrather than relying only on:
Written Procedure68. Control Testing
Section titled “68. Control Testing”Testing determines whether controls are:
Designed Correctly
Operating Effectively69. Common Testing Methods
Section titled “69. Common Testing Methods”Auditors may use:
Inquiry
Inspection
Observation
Reperformance
Data Analysis70. Inquiry
Section titled “70. Inquiry”Ask responsible personnel:
How Doesthe Control Work?Inquiry alone usually provides weaker evidence.
71. Inspection
Section titled “71. Inspection”Review:
Documents
Tickets
Logs
Reports
Configurations72. Observation
Section titled “72. Observation”Watch control execution.
Example:
ObserveBackup RestoreProcess73. Reperformance
Section titled “73. Reperformance”The auditor independently performs:
Control Procedureor recalculation.
Example:
RecalculateUser AccessException Count74. Data Analytics
Section titled “74. Data Analytics”Auditors may analyze entire populations.
Examples:
All User Accounts
All Firewall Rules
All Vendor Records
All ChangesThis can reduce reliance on small samples.
75. Population
Section titled “75. Population”The:
Populationis the complete set of items relevant to the control.
Example:
All ProductionChanges During 202676. Sampling
Section titled “76. Sampling”When testing all items is impractical, auditors may select a:
SampleExample:
Population:5,000 Changes
Sample:60 Changes77. Sampling Risk
Section titled “77. Sampling Risk”Because only part of the population is tested:
Sample Resultmay not perfectly represent:
Entire Population78. Sample Selection
Section titled “78. Sample Selection”Methods may include:
Random
Systematic
Judgmental
Risk-Baseddepending on methodology.
79. Audit Test Sheet
Section titled “79. Audit Test Sheet”Create:
06 Audit Test SheetUse:
| Sample | Control | Criteria | Evidence | Result | Exception |
|---|
80. Pass
Section titled “80. Pass”A sample passes when:
Control Meets Criteria81. Exception
Section titled “81. Exception”An exception occurs when:
Expected Control≠Observed Control82. Example
Section titled “82. Example”Control:
All Terminated UsersDisabled Within 24 HoursSample:
30 TerminationsResults:
28 Disabled Within 24 Hours
2 Disabled After 5 DaysExceptions:
283. Exception Does Not Automatically Equal Finding
Section titled “83. Exception Does Not Automatically Equal Finding”Auditors should determine:
Frequency
Cause
Impact
Population Exposure
Compensating Controlsbefore finalizing a finding.
84. Expand Testing
Section titled “84. Expand Testing”If exceptions appear, the auditor may:
Increase Sample
Analyze Entire Population
Perform Additional Interviews85. Audit Finding
Section titled “85. Audit Finding”A strong audit finding usually includes:
Condition
Criteria
Cause
Effect / Risk
Recommendation86. Condition
Section titled “86. Condition”What was observed?
Example:
3 of 30Terminated AccountsWere DisabledMore Than 24 HoursAfter Termination87. Criteria
Section titled “87. Criteria”What should have happened?
Example:
IAM Standard RequiresTermination Accessto Be RemovedWithin 24 Hours88. Cause
Section titled “88. Cause”Why did the issue occur?
Example:
HR Termination FeedFailed to SendNotifications to IAM89. Effect
Section titled “89. Effect”What risk results?
Example:
Former EmployeesMay RetainUnauthorized Access90. Recommendation
Section titled “90. Recommendation”What should management improve?
Example:
Implement AutomatedTermination Integrationand Exception Monitoring91. Findings Register
Section titled “91. Findings Register”Create:
07 Audit Findings RegisterUse:
| ID | Finding | Severity | Owner | Due | Status |
|---|
92. Finding Severity
Section titled “92. Finding Severity”Organizations may use:
Critical
High
Medium
Lowor other rating models.
93. Severity Factors
Section titled “93. Severity Factors”Consider:
Business Impact
Likelihood
Control Importance
Regulatory Exposure
Population Size
Duration
Compensating Controls94. Root Cause
Section titled “94. Root Cause”Strong auditing looks beyond:
What Failed?to:
Why Did It Fail?95. Root Cause Example
Section titled “95. Root Cause Example”Finding:
Access ReviewsWere Not CompletedWhy?
Managers Did NotComplete ReviewsWhy?
No Escalation ProcessWhy?
Access Review WorkflowDoes Not TrackOverdue ReviewersRoot cause:
Insufficient Governanceand Escalation96. Correction vs Corrective Action
Section titled “96. Correction vs Corrective Action”Correction
Section titled “Correction”Fix the immediate issue.
Example:
CompleteOutstanding ReviewCorrective Action
Section titled “Corrective Action”Prevent recurrence.
Example:
Implement AutomatedReview Escalation97. Preventive Action
Section titled “97. Preventive Action”Prevent similar issues elsewhere.
Example:
Deploy the SameAutomated Review WorkflowAcross All Applications98. CAPA
Section titled “98. CAPA”Organizations may use:
Corrective andPreventive Actionor:
CAPAto manage systemic remediation.
99. Management Response
Section titled “99. Management Response”Management should respond to findings with:
Agreement / Disagreement
Corrective Action
Owner
Target Date100. Auditor vs Management Responsibilities
Section titled “100. Auditor vs Management Responsibilities”Auditor:
Identifies Riskand Recommends ImprovementManagement:
Owns Remediation101. Auditor Should Not Own Remediation
Section titled “101. Auditor Should Not Own Remediation”Avoid:
AuditorDesigns+Implements+TestsSame Controlbecause independence can be impaired.
102. Audit Report
Section titled “102. Audit Report”The audit report communicates:
Objective
Scope
Conclusion
Findings
Risk
Management Response103. Audit Report Structure
Section titled “103. Audit Report Structure”Create:
08 Internal Audit Report TemplateSuggested sections:
Executive Summary
Audit Objective
Scope
Methodology
Overall Conclusion
Key Findings
Detailed Findings
Management Responses
Action Plan104. Executive Summary
Section titled “104. Executive Summary”Executives should understand:
What Was Audited?
What Was Found?
How Serious?
What Needs Attention?105. Overall Audit Rating
Section titled “105. Overall Audit Rating”Organizations may use ratings such as:
Effective
Generally Effective
Needs Improvement
Ineffectiveor another approved model.
106. Avoid Unsupported Ratings
Section titled “106. Avoid Unsupported Ratings”Overall rating should be traceable to:
Testing Results
Findings
Severity
Control Coverage107. Draft Report
Section titled “107. Draft Report”Audit often produces:
Draft Reportfor management review.
108. Management Validation
Section titled “108. Management Validation”Management may identify:
Factual Errors
Missing Context
New EvidenceThe auditor should evaluate this objectively.
109. Auditor Independence During Challenge
Section titled “109. Auditor Independence During Challenge”Management disagreement does not automatically mean:
Remove FindingAuditor should ask:
Does New EvidenceChange the Conclusion?110. Final Audit Report
Section titled “110. Final Audit Report”After factual validation and management responses:
Draft ↓Review ↓Final111. Report Distribution
Section titled “111. Report Distribution”Distribution may include:
Process Owner
Business Leadership
Risk
Security Leadership
Audit Committeedepending on severity and governance.
112. Remediation Tracking
Section titled “112. Remediation Tracking”Audit findings should not disappear after report issuance.
Track:
Finding
Owner
Action
Due Date
Status
Evidence
Validation113. Finding Status
Section titled “113. Finding Status”Use:
Open
In Progress
Pending Validation
Closed
Risk Accepted114. Overdue Finding
Section titled “114. Overdue Finding”When:
Current Date>Target Dateand remediation is incomplete:
Finding=Overdue115. Finding Aging
Section titled “115. Finding Aging”Track:
0–30 Days
31–60 Days
61–90 Days
90+ Days116. Escalation
Section titled “116. Escalation”Example:
High FindingPast Due ↓Process Owner ↓Executive Owner ↓Audit Leadership ↓Audit Committeedepending on governance.
117. Remediation Evidence
Section titled “117. Remediation Evidence”Possible evidence:
Updated Policy
Configuration
Ticket
System Report
Reperformance
Independent Test118. Closure Validation
Section titled “118. Closure Validation”Do not close a finding because management says:
FixedAudit should verify:
Action Completed?
Control Effective?
Risk Addressed?119. Follow-Up Audit
Section titled “119. Follow-Up Audit”A follow-up may verify:
Findings Remediated?
Controls Sustainable?
New Issues Introduced?120. Risk Acceptance
Section titled “120. Risk Acceptance”Management may accept certain risks.
Audit should determine whether:
Correct Authority?
Documented?
Time-Bound?
Within Risk Appetite?121. Internal Audit Does Not Accept Business Risk
Section titled “121. Internal Audit Does Not Accept Business Risk”Audit may:
Challenge
Report
Escalatebut the appropriate business or risk authority:
Accepts Risk122. Audit Trail
Section titled “122. Audit Trail”Every audit should maintain traceability from:
Risk ↓Control ↓Test ↓Evidence ↓Result ↓Finding ↓Report123. Audit Working Papers
Section titled “123. Audit Working Papers”Working papers support the audit conclusion.
Examples:
Planning Documents
Risk Assessment
Control Matrix
Evidence
Test Sheets
Samples
Interview Notes
Findings
Review Notes124. Working Paper Structure
Section titled “124. Working Paper Structure”Create:
Internal-Audit/│├── 01 Planning/├── 02 Scope/├── 03 Risk Assessment/├── 04 Control Matrix/├── 05 Evidence/├── 06 Testing/├── 07 Findings/├── 08 Management Response/├── 09 Report/└── 10 Follow-Up/125. Working Paper Quality
Section titled “125. Working Paper Quality”A reviewer should be able to determine:
What Was Tested?
How?
Using What Evidence?
What Was the Result?
Why Did AuditorReach Conclusion?126. Audit Documentation Principle
Section titled “126. Audit Documentation Principle”A useful mindset:
If the audit work is not documented, it may be difficult to demonstrate that it was performed.
127. Audit Quality Assurance
Section titled “127. Audit Quality Assurance”Audit work may be reviewed by:
Senior Auditor
Audit Manager
Quality Assurance128. Reviewer Questions
Section titled “128. Reviewer Questions”Review:
Was Scope Appropriate?
Was Evidence Sufficient?
Was Testing Complete?
Are Findings Supported?
Is Severity Reasonable?
Are Conclusions Traceable?129. Professional Skepticism
Section titled “129. Professional Skepticism”Auditors should maintain:
Professional SkepticismMeaning:
TrustbutVerifyDo not assume:
Policy Exists=Control Works130. Example — MFA Audit
Section titled “130. Example — MFA Audit”Criteria:
100%Privileged AccountsMust Use MFAPopulation:
250 AccountsTesting identifies:
243 MFA Enabled
7 Without MFACoverage:
243─── × 100250
= 97.2%Potential finding:
Seven privileged accounts were not protected by required multi-factor authentication.
131. Example — Access Review Audit
Section titled “131. Example — Access Review Audit”Control:
Quarterly ReviewExpected:
4 ReviewsPerformed:
3Operating effectiveness:
Ineffective /Partially Effectivedepending on methodology.
132. Example — Backup Audit
Section titled “132. Example — Backup Audit”Control:
Monthly Restore TestEvidence:
12 Months Required
7 Tests CompletedPotential finding:
Recovery CapabilityNot Consistently Validated133. Example — Vendor Risk Audit
Section titled “133. Example — Vendor Risk Audit”Policy:
All Tier 1 VendorsRequire AnnualRisk AssessmentPopulation:
40 Tier 1 VendorsCurrent assessment:
34Coverage:
85%Finding:
6 Critical VendorsWithout CurrentRisk Assessment134. Example — Privacy Audit
Section titled “134. Example — Privacy Audit”Policy:
Personal DataMust Be DeletedAfter Retention PeriodTesting identifies:
Expired RecordsStill StoredPotential:
Privacyand Compliance Risk135. Example — Cloud Audit
Section titled “135. Example — Cloud Audit”Requirement:
Cloud Audit LogsMust Be EnabledPopulation:
100 Cloud AccountsResult:
95 Enabled
5 DisabledFinding:
Security ActivityMay Not BeFully Traceable136. Internal Audit Metrics
Section titled “136. Internal Audit Metrics”Internal Audit may track:
Audit Plan Completion
Audit Cycle Time
Finding Closure
Overdue Findings
Repeat Findings
Management Acceptance137. KPI — Audit Plan Completion
Section titled “137. KPI — Audit Plan Completion”Audits Completed──────────────── × 100Audits Planned138. KPI — Finding Closure
Section titled “138. KPI — Finding Closure”Findings ClosedWithin Due Date──────────────── × 100Findings Due139. KRI — Overdue High Findings
Section titled “139. KRI — Overdue High Findings”High / CriticalAudit FindingsPast Due140. KRI — Repeat Findings
Section titled “140. KRI — Repeat Findings”Audit FindingsRepeated AcrossMultiple Audit Cycles141. Audit Dashboard
Section titled “141. Audit Dashboard”Create:
09 Internal Audit DashboardExample:
| Metric | Target |
|---|---|
| Audit plan completion | 100% |
| High findings overdue | 0 |
| Critical findings open | 0 |
| Repeat findings | 0 |
| Remediation within SLA | 100% |
142. Common Internal Audit Mistakes
Section titled “142. Common Internal Audit Mistakes”Mistake 1 — Auditing Without Defined Criteria
Section titled “Mistake 1 — Auditing Without Defined Criteria”Without criteria, conclusions become subjective.
Mistake 2 — Scope Too Broad
Section titled “Mistake 2 — Scope Too Broad”An audit trying to cover everything may test nothing deeply.
Mistake 3 — Relying Only on Interviews
Section titled “Mistake 3 — Relying Only on Interviews”People can describe how a control should work rather than how it actually works.
Mistake 4 — Policies Equal Evidence
Section titled “Mistake 4 — Policies Equal Evidence”A policy demonstrates design expectations, not necessarily operation.
Mistake 5 — No Population Validation
Section titled “Mistake 5 — No Population Validation”A sample is unreliable if the underlying population is incomplete.
Mistake 6 — Finding Based on One Exception Without Analysis
Section titled “Mistake 6 — Finding Based on One Exception Without Analysis”Understand frequency, cause, and impact.
Mistake 7 — No Root Cause
Section titled “Mistake 7 — No Root Cause”Fixing symptoms may allow the issue to return.
Mistake 8 — Auditor Owns Remediation
Section titled “Mistake 8 — Auditor Owns Remediation”This can impair independence.
Mistake 9 — Closing Findings Without Validation
Section titled “Mistake 9 — Closing Findings Without Validation”Management completion is not the same as verified remediation.
Mistake 10 — Weak Working Papers
Section titled “Mistake 10 — Weak Working Papers”Unsupported conclusions are difficult to defend.
Mistake 11 — Severity Inflation
Section titled “Mistake 11 — Severity Inflation”Not every exception is Critical or High.
Mistake 12 — Reporting Detail Without Business Impact
Section titled “Mistake 12 — Reporting Detail Without Business Impact”Executives need to understand why a finding matters.
143. Weak Internal Audit
Section titled “143. Weak Internal Audit”Ask Questions ↓Collect Documents ↓Find Problems ↓Write Report144. Strong Internal Audit
Section titled “144. Strong Internal Audit”Audit Universe ↓Risk Assessment ↓Audit Plan ↓Objective ↓Scope ↓Criteria ↓Control Matrix ↓Evidence ↓Testing ↓Exceptions ↓Root Cause ↓Findings ↓Management Response ↓Report ↓Remediation ↓Validation ↓Follow-Up145. GRC Analyst and Internal Audit
Section titled “145. GRC Analyst and Internal Audit”GRC and Internal Audit frequently work together.
GRC may:
Define Controls
Maintain Risk Registers
Coordinate Compliance
Collect Evidence
Track FindingsInternal Audit may:
Independently Test
Challenge
Validate
Report146. Internal Audit and Compliance Relationship
Section titled “146. Internal Audit and Compliance Relationship”Compliance ↓Requirements ↓Controls ↓Evidence ↓Internal Audit ↓Independent Testing147. Internal Audit Mindset
Section titled “147. Internal Audit Mindset”For every control ask:
What RiskDoes This ControlAddress?
What Shouldthe Control Do?
What CriteriaRequires It?
Who Owns It?
How OftenShould It Operate?
What Is thePopulation?
What EvidenceProves It Operated?
Is the ControlDesigned Properly?
Did It ActuallyOperate?
How ManyExceptions Exist?
Are ExceptionsIsolated or Systemic?
Why DidThey Occur?
What RiskDo They Create?
Is the FindingSupported by Evidence?
Who OwnsRemediation?
When Is It Due?
How Will WeValidate Closure?
Can Another AuditorReperform Our WorkUsing the Documentation?That is the practical mindset behind Internal Audit.
Key Takeaways
Section titled “Key Takeaways”-
Internal Audit provides independent assurance over governance, risk management, and controls.
-
Independence and objectivity are fundamental audit principles.
-
Compliance determines whether requirements are met; Internal Audit independently tests whether controls actually work.
-
Internal Audit commonly operates as the third line within enterprise governance.
-
Risk-based auditing prioritizes audit resources according to enterprise risk.
-
The audit universe identifies the organization’s auditable areas.
-
Every audit should define objectives, scope, and criteria.
-
Control objectives describe desired risk outcomes.
-
Control design and operating effectiveness must be evaluated separately.
-
Audit evidence should be relevant, reliable, sufficient, and traceable.
-
Walkthroughs help auditors understand how processes really operate.
-
Testing may use inquiry, inspection, observation, reperformance, and data analytics.
-
Sampling should be based on a defined and complete population.
-
Exceptions should be analyzed before becoming findings.
-
Strong findings describe condition, criteria, cause, effect, and recommendation.
-
Root-cause analysis helps prevent repeated issues.
-
Management owns remediation; auditors independently validate it.
-
Findings should remain tracked until closure is verified.
-
Follow-up auditing confirms whether corrective actions are sustainable.
-
Working papers provide evidence supporting audit conclusions.
-
Audit reports should communicate material risk and required action clearly.
-
GRC and Internal Audit work closely but must maintain appropriate independence.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What is Internal Audit?
-
Why does Internal Audit exist?
-
What is the difference between auditing and compliance?
-
What is the difference between Internal Audit and External Audit?
-
Why is auditor independence important?
-
What is auditor objectivity?
-
What is assurance?
-
What is the three-lines model?
-
What does the first line do?
-
What does the second line do?
-
What does the third line do?
-
What is an Internal Audit Charter?
-
What is an audit universe?
-
What is risk-based auditing?
-
What is an audit objective?
-
What is audit scope?
-
What are audit criteria?
-
What is a control objective?
-
What is design effectiveness?
-
What is operating effectiveness?
-
What is audit evidence?
-
What makes evidence reliable and sufficient?
-
What is a walkthrough?
-
What are the common control-testing methods?
-
What is an audit population?
-
Why is sampling used?
-
What is an audit exception?
-
What makes a strong audit finding?
-
What is root-cause analysis?
-
Why must remediation be independently validated?
What’s Next?
Section titled “What’s Next?”➡️ Next: 02 — Audit Planning
In the next lesson, you will move from Internal Audit fundamentals into designing and preparing a complete audit engagement.
You will work through:
Audit Universe ↓Risk Assessment ↓Audit Selection ↓Background Research ↓Audit Objective ↓Scope ↓Criteria ↓Risk & Control Analysis ↓Audit Program ↓Resource Planning ↓Stakeholder Communication ↓Fieldwork ReadinessYou will learn how to build an Annual Audit Plan, Audit Engagement Planning Memo, Risk Assessment, Audit Scope Statement, Audit Control Matrix, Audit Program, Evidence Request List, Stakeholder Communication Plan, Audit Timeline, and Planning Checklist.
This will prepare you to move from understanding what Internal Audit is to actually planning and executing a professional audit engagement.