How to Conduct an Internal Audit: How to Plan the Engagement, Run Fieldwork That Holds Up, and Write Findings Management Will Act On

The Audit Nobody Argues With

Published 2026-08-17 · EuroQuest International

Quick summary

  • What it is: a structured engagement that tests whether controls over a defined process actually work, against criteria agreed before anyone looks at anything.
  • The five phases: selection, planning, fieldwork, reporting, follow-up. Skipping planning is what produces reports that get argued with instead of acted on.
  • The hard part: not finding problems. Writing them so that the cause is clear, the owner is named, and the fix has a date.
  • What kills credibility: a scope that drifts, evidence that cannot be reproduced, and findings the auditee first hears about in the final report.
  • What good looks like: a risk-based plan, working papers a stranger could follow, and a follow-up log that shows which fixes actually landed.

Two audit reports land on the same desk. The first lists eleven observations, none ranked, most of them procedural, and the process owner disputes four of them in the meeting. The second lists three, each with the control that failed, the exposure it creates, an owner, and a date. Only one of those reports changes anything, and it is not the longer one.

The difference is almost never the auditor's technical knowledge. It is method: how the subject was chosen, how the scope was fixed, how evidence was gathered, and how the findings were written. This guide walks through an internal audit end to end, in the order the work actually happens, for auditors and for the managers who are audited and want to know what a competent one should look like.

On this page

  1. What an internal audit is, and what it is not
  2. How do you decide what to audit?
  3. What happens during planning?
  4. What does fieldwork actually look like?
  5. How do you write a report management acts on?
  6. What happens after the report?
  7. Frequently asked questions
15 principles
In the Global Internal Audit Standards, 2024 Edition, organized across five domains
2,402 cases
Of occupational fraud studied across 143 countries and territories in the 2026 ACFE report
Dec 15, 2025
The date by which a Yellow Book quality management system had to be designed and implemented

What an Internal Audit Is, and What It Is Not

An internal audit is an independent examination of whether a process is controlled: whether the risks that matter have been identified, whether the controls over them exist, and whether those controls operate as intended. It reports to a governing body rather than to the manager of the process being examined, which is what makes the opinion worth anything.

It is not an inspection looking for individual mistakes, and it is not a consulting project that redesigns the process. Auditors who drift into either lose the independence that gives the work its authority.

The profession's reference point is the Global Internal Audit Standards, 2024 Edition, which are organized into five domains, from the purpose of internal auditing through to performing internal audit services, and contain 15 principles. They are a mandatory component of the International Professional Practices Framework, and all internal audit functions are expected to be in conformance with them. Public sector work carries a second layer: auditors of government entities, and of entities that receive government awards, work to Government Auditing Standards, whose 2024 edition required a compliant quality management system to be designed and implemented by December 15, 2025.

Key terms

  • Criteria: the standard the process is measured against, whether a policy, a regulation, a contract, or a documented procedure. No criteria, no finding.
  • Control: the specific step that prevents or detects a failure. An approval, a reconciliation, a segregation of duties, a system restriction.
  • Design vs operating effectiveness: whether the control would work if performed, versus whether it was actually performed, every time, across the period.
  • Finding: condition, criteria, cause, and effect. A finding missing its cause is an observation, and it will be argued with.
  • Assurance vs advisory: testing against criteria and giving an opinion, versus helping improve a process without opining on it. Say which one you are doing before you start.

How Do You Decide What to Audit?

Not by rotation, and not by whoever asked loudest. The annual plan should follow risk: where would a failure hurt most, where has the process changed recently, where are controls newest or least tested, and where has the organization already had incidents.

Three inputs make the choice defensible. The enterprise risk register tells you what leadership already agrees is significant. Incident, complaint, and loss data tells you where control has failed in practice. Process change tells you where controls have not yet been proven. Building that into a documented, ranked plan rather than a calendar is the point of developing and managing an effective audit plan.

Size the engagement before you commit

An audit that needs six weeks and is given two produces a report with caveats nobody reads. Estimate the testing population, the availability of the process owners, and the systems access required, and either scope down or reschedule. Scoping down is a decision; running short is an accident.

What Happens During Planning?

Planning is where an audit is won or lost, and it is the phase most often compressed. Four things have to be fixed in writing before fieldwork opens.

Scope, in a sentence anyone can repeat

Which process, which entities, which period, and which systems. "Procurement" is not a scope. "Purchase orders raised in the two operating companies between January and June, excluding capital projects" is a scope, and it is what stops the engagement expanding every time something interesting appears.

Criteria, agreed in advance

Write down what the process is supposed to do and where that requirement comes from. If the policy is silent, say so and audit against the stated business objective instead, but never invent a standard after the test. Agreeing criteria up front is the single biggest reason findings survive challenge, and it is central to internal audit planning and execution.

The risk and control matrix

List the risks in scope, the control that addresses each one, and how you will test it. This document drives fieldwork and later becomes the evidence that the audit covered what it claimed to cover. Where risks are financial or fraud-related, mapping controls this way is what internal controls and fraud risk mitigation teaches.

The opening meeting

Held with the process owner, not around them. Confirm scope, timing, contacts, and how findings will be raised during the work rather than at the end. An auditee who first learns of a problem in the draft report will spend the closing meeting defending, not fixing.

PhaseMain outputTypical failure
SelectionA ranked, risk-based annual planAuditing by rotation, or by whoever requested it
PlanningScope, criteria, risk and control matrixCompressed to a day, so scope drifts later
FieldworkWorking papers and tested samplesEvidence that cannot be reproduced by anyone else
ReportingRanked findings with owners and datesLong lists, no ranking, no named owner
Follow-upA log of what was actually fixedClosed on the owner's word, with no retest

What Does Fieldwork Actually Look Like?

Fieldwork is evidence gathering against the matrix, and it uses four methods in roughly ascending order of strength: asking, observing, inspecting records, and re-performing the control yourself. An answer in a meeting is the weakest evidence there is, and it is the most commonly relied on.

Test design before you test operation

If the control as designed could not prevent the risk, testing forty samples of it proves nothing. Walk one transaction end to end first, confirm the control would work, and only then test whether it was performed consistently.

Sampling that can be defended

State the population, the method, and the sample size before selecting, and record why the size is adequate. A sample chosen after the results are known is not a sample. Method choice for risk-weighted populations is the practical content of auditing techniques for effective risk management.

Working papers a stranger could follow

The test is simple: could another auditor, with no context, re-perform your work and reach your conclusion from your file alone? Purpose, source of data, procedure performed, result, and conclusion. Anything less is a note, not a working paper.

Raise issues as you find them

Confirm each potential finding with the process owner while fieldwork is open. Half of them turn out to have an explanation you did not have, and the other half start getting fixed before the report is written, which is the actual objective.

Fieldwork evidence checklist

  • Population defined and reconciled to a system total, not to a spreadsheet someone sent you
  • Sample method and size documented before selection
  • Design tested through one full walkthrough before operating tests begin
  • Every exception traced to a cause, not just counted
  • Source documents referenced so the test can be re-performed
  • Each potential finding discussed with the owner while fieldwork is still open
  • Conclusion written against the criteria agreed in planning, not against what was found

How Do You Write a Report Management Acts On?

Rank the findings. An unranked list forces the reader to do the auditor's prioritization, and readers respond by treating everything as minor. Two or three significant findings with a clear exposure will move more than eleven undifferentiated observations.

Four parts to every finding

Condition, what was found. Criteria, what it should have been. Cause, why the gap exists. Effect, what it exposes the organization to. The cause is the part most often missing, and without it the recommendation is a guess. A control that fails because nobody was trained needs a different fix from one that fails because the system permits an override.

Write the effect in business terms

"Segregation of duties is not enforced" is a control statement. "One person can create a supplier and approve a payment to it" is an exposure a chief financial officer will act on this week. The second sentence is the same finding, translated. That translation is the skill behind developing audit reports with impact.

Agree actions, do not dictate them

The auditor owns the finding; the process owner owns the fix and its date. A recommendation imposed without agreement is closed on paper and ignored in practice. If no agreement is reached, that disagreement belongs in the report, stated plainly, rather than being smoothed away.

Why the stakes are not abstract

Control failures are found by regulators as well as by auditors. In fiscal year 2024 the US Securities and Exchange Commission filed 583 enforcement actions and obtained orders for $8.2 billion in financial remedies, and received 45,130 tips, complaints, and referrals in the same year. Occupational fraud is similarly ordinary rather than exotic: the 2026 Report to the Nations, the 14th edition of that study, examined 2,402 real cases across 143 countries and territories and 22 major industry categories. Internal audit is one of the few functions positioned to find these things first.

What Happens After the Report?

Follow-up is where most audit functions quietly lose their value. An action agreed and never verified is an action that did not happen, and a follow-up log closed on the owner's assurance is a list of opinions.

Retest, do not survey

Re-perform enough of the original test to confirm the control now works. For significant findings that means evidence, not an email confirming completion.

Report the ageing, not just the count

The governing body needs to see overdue actions by age and by risk rank. Twelve open items of which two are high risk and nine months old is a different message from twelve open items.

Feed the result back into the plan

Areas where actions are repeatedly late, or where the same finding returns, belong in next year's plan at a higher rank. That loop is what turns a series of engagements into a function, and it sits at the center of corporate compliance and internal audit best practices.

In practice

If you are building a function rather than running a single engagement, start with the follow-up log rather than the plan. It shows which past findings were never fixed, which owners never closed anything, and which areas keep reappearing. That is a risk-based plan already written, and it is grounded in your own organization rather than in a template. Comparing your approach against external practice is where best practices in internal and external auditing earns its place.

An audit is not judged by how many findings it produced. It is judged by whether, a year later, the thing it found is still broken.

EuroQuest International runs audit, governance, and compliance programs in London, Geneva, Singapore, Manama, and Dubai, for internal auditors and audit managers, compliance and risk officers, quality and governance leads, and the process owners who are on the other side of the engagement.

Frequently Asked Questions

What are the phases of an internal audit?

Five: selection of the subject from a risk-based annual plan, planning that fixes scope and criteria and builds a risk and control matrix, fieldwork that gathers evidence against that matrix, reporting that ranks findings with named owners and dates, and follow-up that retests whether the agreed actions actually worked. Functions name them differently, but the sequence is the same, and planning is the phase most often compressed.

How long does an internal audit take?

A focused engagement on a single process commonly runs four to eight weeks from opening meeting to draft report, with fieldwork taking about half of that. The variables are the size of the testing population, how quickly process owners and systems access become available, and whether the scope was fixed properly at planning. An audit given less time than the scope requires should be scoped down rather than run short.

What is the difference between internal and external audit?

External auditors are appointed from outside to give an opinion on the financial statements for shareholders and regulators, over a defined reporting period. Internal audit is part of the organization, reports to a governing body such as an audit committee, and covers any process where control matters, including operations, procurement, safety, and technology. The two use similar evidence techniques for different audiences and purposes.

What makes an audit finding hold up?

Four elements: the condition found, the criteria it is measured against, the cause of the gap, and the effect on the organization. Criteria must be agreed before testing begins, evidence must be reproducible from the working papers by someone with no context, and the finding must have been discussed with the process owner while fieldwork was still open. Findings that fail challenge usually fail on cause or on criteria set after the fact.

Who should attend internal audit training?

Internal auditors and audit managers; compliance, risk, and governance officers; quality managers who run internal quality audits; finance staff moving into an assurance role; and the process owners in procurement, operations, and human resources who are audited and want to understand what a competent engagement should look like. Public sector and government-funded bodies benefit from the reporting discipline in particular.

Run Audits People Act On

EuroQuest International delivers internal audit, governance, risk, and compliance programs for auditors, audit managers, compliance and quality leads, and the process owners on the other side of the engagement, in London, Geneva, Singapore, Manama, and Dubai.

Explore Quality, Governance and Audit Programs