Published 2026-08-17 · EuroQuest International
Quick summary
Two audit reports land on the same desk. The first lists eleven observations, none ranked, most of them procedural, and the process owner disputes four of them in the meeting. The second lists three, each with the control that failed, the exposure it creates, an owner, and a date. Only one of those reports changes anything, and it is not the longer one.
The difference is almost never the auditor's technical knowledge. It is method: how the subject was chosen, how the scope was fixed, how evidence was gathered, and how the findings were written. This guide walks through an internal audit end to end, in the order the work actually happens, for auditors and for the managers who are audited and want to know what a competent one should look like.
On this page
An internal audit is an independent examination of whether a process is controlled: whether the risks that matter have been identified, whether the controls over them exist, and whether those controls operate as intended. It reports to a governing body rather than to the manager of the process being examined, which is what makes the opinion worth anything.
It is not an inspection looking for individual mistakes, and it is not a consulting project that redesigns the process. Auditors who drift into either lose the independence that gives the work its authority.
The profession's reference point is the Global Internal Audit Standards, 2024 Edition, which are organized into five domains, from the purpose of internal auditing through to performing internal audit services, and contain 15 principles. They are a mandatory component of the International Professional Practices Framework, and all internal audit functions are expected to be in conformance with them. Public sector work carries a second layer: auditors of government entities, and of entities that receive government awards, work to Government Auditing Standards, whose 2024 edition required a compliant quality management system to be designed and implemented by December 15, 2025.
Key terms
Not by rotation, and not by whoever asked loudest. The annual plan should follow risk: where would a failure hurt most, where has the process changed recently, where are controls newest or least tested, and where has the organization already had incidents.
Three inputs make the choice defensible. The enterprise risk register tells you what leadership already agrees is significant. Incident, complaint, and loss data tells you where control has failed in practice. Process change tells you where controls have not yet been proven. Building that into a documented, ranked plan rather than a calendar is the point of developing and managing an effective audit plan.
An audit that needs six weeks and is given two produces a report with caveats nobody reads. Estimate the testing population, the availability of the process owners, and the systems access required, and either scope down or reschedule. Scoping down is a decision; running short is an accident.
Planning is where an audit is won or lost, and it is the phase most often compressed. Four things have to be fixed in writing before fieldwork opens.
Which process, which entities, which period, and which systems. "Procurement" is not a scope. "Purchase orders raised in the two operating companies between January and June, excluding capital projects" is a scope, and it is what stops the engagement expanding every time something interesting appears.
Write down what the process is supposed to do and where that requirement comes from. If the policy is silent, say so and audit against the stated business objective instead, but never invent a standard after the test. Agreeing criteria up front is the single biggest reason findings survive challenge, and it is central to internal audit planning and execution.
List the risks in scope, the control that addresses each one, and how you will test it. This document drives fieldwork and later becomes the evidence that the audit covered what it claimed to cover. Where risks are financial or fraud-related, mapping controls this way is what internal controls and fraud risk mitigation teaches.
Held with the process owner, not around them. Confirm scope, timing, contacts, and how findings will be raised during the work rather than at the end. An auditee who first learns of a problem in the draft report will spend the closing meeting defending, not fixing.
| Phase | Main output | Typical failure |
|---|---|---|
| Selection | A ranked, risk-based annual plan | Auditing by rotation, or by whoever requested it |
| Planning | Scope, criteria, risk and control matrix | Compressed to a day, so scope drifts later |
| Fieldwork | Working papers and tested samples | Evidence that cannot be reproduced by anyone else |
| Reporting | Ranked findings with owners and dates | Long lists, no ranking, no named owner |
| Follow-up | A log of what was actually fixed | Closed on the owner's word, with no retest |
Fieldwork is evidence gathering against the matrix, and it uses four methods in roughly ascending order of strength: asking, observing, inspecting records, and re-performing the control yourself. An answer in a meeting is the weakest evidence there is, and it is the most commonly relied on.
If the control as designed could not prevent the risk, testing forty samples of it proves nothing. Walk one transaction end to end first, confirm the control would work, and only then test whether it was performed consistently.
State the population, the method, and the sample size before selecting, and record why the size is adequate. A sample chosen after the results are known is not a sample. Method choice for risk-weighted populations is the practical content of auditing techniques for effective risk management.
The test is simple: could another auditor, with no context, re-perform your work and reach your conclusion from your file alone? Purpose, source of data, procedure performed, result, and conclusion. Anything less is a note, not a working paper.
Confirm each potential finding with the process owner while fieldwork is open. Half of them turn out to have an explanation you did not have, and the other half start getting fixed before the report is written, which is the actual objective.
Fieldwork evidence checklist
Rank the findings. An unranked list forces the reader to do the auditor's prioritization, and readers respond by treating everything as minor. Two or three significant findings with a clear exposure will move more than eleven undifferentiated observations.
Condition, what was found. Criteria, what it should have been. Cause, why the gap exists. Effect, what it exposes the organization to. The cause is the part most often missing, and without it the recommendation is a guess. A control that fails because nobody was trained needs a different fix from one that fails because the system permits an override.
"Segregation of duties is not enforced" is a control statement. "One person can create a supplier and approve a payment to it" is an exposure a chief financial officer will act on this week. The second sentence is the same finding, translated. That translation is the skill behind developing audit reports with impact.
The auditor owns the finding; the process owner owns the fix and its date. A recommendation imposed without agreement is closed on paper and ignored in practice. If no agreement is reached, that disagreement belongs in the report, stated plainly, rather than being smoothed away.
Control failures are found by regulators as well as by auditors. In fiscal year 2024 the US Securities and Exchange Commission filed 583 enforcement actions and obtained orders for $8.2 billion in financial remedies, and received 45,130 tips, complaints, and referrals in the same year. Occupational fraud is similarly ordinary rather than exotic: the 2026 Report to the Nations, the 14th edition of that study, examined 2,402 real cases across 143 countries and territories and 22 major industry categories. Internal audit is one of the few functions positioned to find these things first.
Follow-up is where most audit functions quietly lose their value. An action agreed and never verified is an action that did not happen, and a follow-up log closed on the owner's assurance is a list of opinions.
Re-perform enough of the original test to confirm the control now works. For significant findings that means evidence, not an email confirming completion.
The governing body needs to see overdue actions by age and by risk rank. Twelve open items of which two are high risk and nine months old is a different message from twelve open items.
Areas where actions are repeatedly late, or where the same finding returns, belong in next year's plan at a higher rank. That loop is what turns a series of engagements into a function, and it sits at the center of corporate compliance and internal audit best practices.
In practice
If you are building a function rather than running a single engagement, start with the follow-up log rather than the plan. It shows which past findings were never fixed, which owners never closed anything, and which areas keep reappearing. That is a risk-based plan already written, and it is grounded in your own organization rather than in a template. Comparing your approach against external practice is where best practices in internal and external auditing earns its place.
An audit is not judged by how many findings it produced. It is judged by whether, a year later, the thing it found is still broken.
EuroQuest International runs audit, governance, and compliance programs in London, Geneva, Singapore, Manama, and Dubai, for internal auditors and audit managers, compliance and risk officers, quality and governance leads, and the process owners who are on the other side of the engagement.
Five: selection of the subject from a risk-based annual plan, planning that fixes scope and criteria and builds a risk and control matrix, fieldwork that gathers evidence against that matrix, reporting that ranks findings with named owners and dates, and follow-up that retests whether the agreed actions actually worked. Functions name them differently, but the sequence is the same, and planning is the phase most often compressed.
A focused engagement on a single process commonly runs four to eight weeks from opening meeting to draft report, with fieldwork taking about half of that. The variables are the size of the testing population, how quickly process owners and systems access become available, and whether the scope was fixed properly at planning. An audit given less time than the scope requires should be scoped down rather than run short.
External auditors are appointed from outside to give an opinion on the financial statements for shareholders and regulators, over a defined reporting period. Internal audit is part of the organization, reports to a governing body such as an audit committee, and covers any process where control matters, including operations, procurement, safety, and technology. The two use similar evidence techniques for different audiences and purposes.
Four elements: the condition found, the criteria it is measured against, the cause of the gap, and the effect on the organization. Criteria must be agreed before testing begins, evidence must be reproducible from the working papers by someone with no context, and the finding must have been discussed with the process owner while fieldwork was still open. Findings that fail challenge usually fail on cause or on criteria set after the fact.
Internal auditors and audit managers; compliance, risk, and governance officers; quality managers who run internal quality audits; finance staff moving into an assurance role; and the process owners in procurement, operations, and human resources who are audited and want to understand what a competent engagement should look like. Public sector and government-funded bodies benefit from the reporting discipline in particular.
EuroQuest International delivers internal audit, governance, risk, and compliance programs for auditors, audit managers, compliance and quality leads, and the process owners on the other side of the engagement, in London, Geneva, Singapore, Manama, and Dubai.
Explore Quality, Governance and Audit Programs