Internal audit procedures involve a structured, multi-phase process: Planning (defining scope, objectives, risks), Fieldwork/Conducting (gathering evidence, testing controls via interviews, observation, documentation review), Reporting (documenting findings, issues, and recommendations), and Follow-up (monitoring corrective actions) to provide assurance, improve processes, and manage risks for an organization. These steps ensure objective evaluation of financial records, operations, and compliance, bringing value by identifying inefficiencies and potential fraud.
The five stages of the audit process are: planning and scoping, risk assessment and understanding internal controls, audit testing (including tests of controls and substantive tests), evaluation and reporting, and follow-up and remediation.
What happens during an audit? Internal audit conducts assurance audits through a five-phase process which includes selection, planning, conducting fieldwork, reporting results, and following up on corrective action plans.
The seven types of audit procedures
These methods are used when designing audit procedures.
A successful internal audit function relies on four fundamental pillars, often referred to as the “4 C's”: Competence, Confidentiality, Communication, and Collaboration. These principles guide auditors in delivering meaningful and impactful results. Let's explore each of these elements in detail.
Audit Procedure Methods
The COSO internal control framework identified five interrelated components:
The 7 E's in operational auditing are Effectiveness, Efficiency, Economy, Excellence, Ethics, Equity, and Ecology, forming a comprehensive framework for internal auditors to assess an organization's success beyond mere compliance, focusing on goal achievement, resource optimization, quality, moral conduct, fair treatment, and environmental impact to add significant value.
The 5 Cs of audit (Criteria, Condition, Cause, Consequence, Corrective Action) are a framework for structuring clear, actionable audit findings, explaining what should be (Criteria), what is found (Condition), why it happened (Cause), what the impact is (Consequence/Effect), and how to fix it (Corrective Action/Recommendation) to drive organizational improvement and compliance.
ISO 9001 provides an audit checklist that organizations are required to use when conducting internal audits. The checklist includes questions for assessing an organization's context, leadership, planning and quality management systems, support structures, operations, performance evaluation and areas for improvement.
The checklist for Internal Audit
What Are the Steps in the Internal Audit Process?
What is an Internal Audit SOP? An internal audit standard operating procedure (SOP) is a formal document that outlines the systematic process for planning, conducting, reporting, and following up on internal audits within an organization.
Types of Internal audits include compliance audits, operational audits, financial audits, and an information technology audits.
The “5 P's of Internal Audit” includes 5 video-clips presenting testimonials from audit managers on the topics of Plan, Perform, People, Profile and Product.
An Internal Finance Control (IFC) audit checklist is an invaluable tool for comparing a business's practices and processes to the requirements set out by ISO standards.
7 Audit Procedures
Balancing the 3 C's in Auditing Practice
Balancing competence, confidentiality, and communication is essential for the effectiveness of the auditing process.
SOX aims to prevent corporate fraud by setting strict regulatory mandates to protect financial records from tampering and ensure greater independence between auditors and their clients.
The principles of independence, objectivity, competence, confidentiality, professionalism, due professional care, and continuous improvement are essential for the internal audit function to fulfill its role as a trusted advisor to the organization.
The Audit Bureau of Circulations (ABC) of India is a non-profit circulation-audit organisation. It certifies and audits the circulations of major publications, including newspapers and magazines in India.
ACL Analytics (Galvanize, now part of Diligent) is one of the most popular tools. It is specifically designed for audit professionals and enables users to analyse 100% of the data, identify patterns, anomalies, and issues in financial and operational data.