An internal audit department looks simple from outside: a group of people who check things and write reports. From inside it is a small organization with its own governance, its own production line, and a division of labor that decides whether the reports are worth reading. This guide walks through that organization role by role, from the associate on their first walkthrough to the chief audit executive in front of the audit committee, and explains what each person actually does, how the work moves between them, who signs what, and how the department is held to account for the value it produces. It is written for three readers: people considering the profession, new hires trying to understand the machine they have joined, and managers in the business who want to know who they are dealing with and why.
This guide was rewritten in September 2026 against the Global Internal Audit Standards, which since January 2025 define what a function must have in place: a charter approved by the board, a chief audit executive with direct access to it, a risk-based plan, supervision and review of every engagement, and a quality program that is assessed externally at least every five years. Two example functions run through it: MidState Beverage’s six-person team at a three-state distributor, and Lakeshore Bancorp’s twenty-two-person department at a nine-billion-dollar public bank, so that the same roles can be seen at two very different scales. For the profession’s definition and the Standards themselves, start with the Standards overview; for how the department relates to the compliance function next door, the internal audit vs. compliance guide.
In this guide
- What the department is for, and where it sits
- How departments are structured, by size
- The roles: what each person actually does
- One engagement through every role
- Who prepares, reviews, and approves what
- How the department is governed and measured
- What the department produces, and how to tell whether it is working
- Career paths through and out of the department
- Common structural mistakes
What the department is for, and where it sits
The department exists to give the board, through its audit committee, an independent and objective view of whether the organization’s governance, risk management, and control processes work, and to help management improve them. That sentence comes from the IIA’s definition of the profession and it settles the department’s position in the organization: it reports functionally to the board and administratively to an executive, usually the chief executive or chief financial officer, and the two lines mean different things. The functional line is where independence lives: the committee approves the charter, the plan, the budget, and the chief audit executive’s appointment, evaluation, and pay, and receives the results. The administrative line handles the things a function needs from the company it sits inside: payroll, facilities, HR policy, and a senior executive who can open doors. When the two lines are confused, the department starts answering to the people it audits, which is the failure the GIAS Domain III guide describes in detail.
The department’s mandate is written down in one document, the internal audit charter, which the Standards require the board to approve and which defines the function’s purpose, authority, responsibilities, position in the organization, scope of work, and the nature of the services it may provide. Everything else about the department flows from the charter: the right to unrestricted access to records, people, and property; the obligation to follow the Standards; the split between assurance and advisory work; and the reporting lines just described. A department without a current charter is a department whose authority depends on who is asking, and a good first question for any new hire is when the charter was last approved. The charter guide shows what a complete one contains.
Three things the department is not. It is not management’s control function; it does not own risks, design controls, or run remediation, which is the difference between the third line and the second that the Three Lines guide works through. It is not the external auditor; it reports to the board rather than to shareholders, covers operations and compliance as well as financial reporting, and issues no opinion on the financial statements, though the external auditor may rely on parts of its work. And it is not a police force; it can investigate, and often does, but the authority to discipline, prosecute, or terminate belongs to management and the board.
How departments are structured, by size
Size determines structure more than industry does. The same roles exist in a three-person function and a hundred-person one, but in the small function they are worn as hats by the same people, and in the large one they become teams. The table describes the common configurations, with the two example companies placed where they fall; the audit cost guide covers what each configuration costs to run.
| Department size | Typical organization | Roles present | How coverage is achieved | Characteristic strengths and weaknesses |
|---|---|---|---|---|
| One to three people | Private companies and nonprofits with revenue from tens of millions to a few hundred million; a first function set up as the small-company guide describes | A head of internal audit who is also the senior auditor, plus one or two auditors; IT audit and specialist work co-sourced | A short plan of six to ten engagements a year; heavy reliance on co-source for technical areas; the head does fieldwork | Close to the business and fast; thin review, single points of failure, and a head who cannot be away for a month |
| Four to ten people (MidState Beverage: six) | Mid-sized companies, regional banks, hospital systems, universities | Chief audit executive, one or two managers, seniors and staff; one person carries IT audit or analytics; co-source for the rest | Eight to fifteen engagements plus analytics and validation; a formal risk assessment and universe; the CAE still reviews every report | Enough depth for real supervision; still exposed when two people leave at once; analytics depends on one person |
| Ten to thirty people (Lakeshore Bancorp: twenty-two) | Public companies, larger banks and insurers, large health systems | CAE, directors or senior managers by area (financial, operational, IT, compliance or regulatory), managers, seniors, staff; a dedicated IT audit team; an analytics lead; often an audit operations or quality role | Twenty-five to sixty engagements; continuous monitoring in some areas; regulatory-driven coverage where applicable; co-source for specialist topics such as model risk | Real specialization and review layers; risk of silos between the financial and IT teams; the CAE becomes a manager of managers |
| Thirty to a hundred or more | Large multinationals, global banks, federal agencies | Everything above plus regional teams, a methodology and quality assurance group, a data and technology group, a professional practices lead, and sometimes a dedicated investigations unit | Hundreds of engagements; global plan with regional plans beneath it; audit management systems; continuous auditing programs | Depth in every area; bureaucracy, slow reporting, and a real risk that the audit committee sees only summaries of summaries |
Two structural choices cut across size. The first is in-house versus co-sourced capacity: nearly every department buys some specialist hours from outside, and the co-sourcing comparison covers how much is healthy and when it tips into outsourcing the function’s judgment. The second is organization by audit type versus by business area: a bank of Lakeshore’s size usually organizes by type, with financial, operational, IT, and regulatory teams, while a manufacturer often organizes by division or geography and lets each team cover every type. Neither is right; the failure is organizing by type and never rotating people across the boundary, which produces IT auditors who cannot read a reconciliation and financial auditors who cannot read an access report.
The roles: what each person actually does
Job titles vary by company; the work does not. The table describes each role by what fills its days, what experience it usually carries, what good looks like, and how it typically fails. Read the last column carefully if you are joining a department, because the failures are the things nobody puts in the job description.
| Role | What fills the days | Typical experience and credentials | What good looks like | How it fails |
|---|---|---|---|---|
| Staff auditor or associate | Walkthroughs, document requests, control testing, sampling, workpapers, drafting observations; the majority of the fieldwork hours on every engagement | Zero to three years; accounting, finance, business, or IT degree; working toward the CIA or CPA | Clean, re-performable workpapers; asks why a control exists before testing whether it operates; flags problems the day they appear | Ticks and ties without understanding; hides uncertainty until the review; treats the auditee as an adversary |
| Senior auditor | Leads fieldwork on an engagement: scopes the test plan, allocates work to staff, performs the hardest tests, reviews staff workpapers, drafts the findings and the report | Three to six years; CIA, CPA, or CISA in hand or imminent | Runs the engagement to budget; findings are accurate and evidenced before the manager sees them; auditees hear about issues from the senior first, not from the draft report | Does all the work personally and never develops staff; lets scope drift; finds out in week four that the population was incomplete |
| Audit manager or supervisor | Owns two to four concurrent engagements: planning memos, risk assessment of the area, review of all workpapers and findings, the closing meeting, the report, and the relationship with the process owner; contributes to the annual plan | Six to ten years; CIA plus a second credential is common; the audit manager interview guide shows what is expected | Reports that leave the manager’s desk are ready for the CAE; findings are rated consistently; engagements finish within the hours the timeline guide describes as normal | Becomes a bottleneck; re-performs seniors’ work instead of reviewing it; softens findings to keep the relationship |
| Senior manager or director | Owns a portfolio, typically an audit type or a business division: the risk assessment for that portfolio, the plan input, resourcing, the quality of every report in the portfolio, and the executive relationships | Ten to fifteen years; often the CAE’s successor; manages managers rather than engagements | The portfolio’s coverage is defensible to the committee; managers are developed, not supervised; the director sees problems across engagements that no single manager can | Loses touch with the fieldwork and cannot judge report quality; builds a silo |
| Chief audit executive | The charter, the risk assessment and plan, the budget, the audit committee relationship, the executive relationships, the quality program, hiring and development, the final review of every report, and the judgment calls: which findings go to the committee, how they are rated, when to escalate | Fifteen years or more; CIA expected, CPA common, both frequent; the CAE interview guide describes the selection | The committee trusts the function’s opinion because it has been right before; management sees the function as demanding and fair; the plan tracks the risks that matter this year rather than last year’s | Captured by management; over-promises coverage; hides behind the committee or hides from it |
| IT audit specialist or IT audit manager | ITGC engagements, application control testing, access reviews, cyber and cloud audits, IT support on every engagement that touches a system, and increasingly the audit of technology projects and AI | Three to fifteen years; CISA expected, often CISSP, CISM, or CRISC; described in the CIA vs. CISA guide | Financial auditors can rely on the ITGC conclusions; IT findings are written so a CFO can understand why they matter | Reports in jargon; audits configuration rather than risk; becomes a separate department inside the department |
| Data analytics lead | Builds the population extracts and analytics for engagements, continuous monitoring routines, and the tools the rest of the team uses; increasingly owns the department’s automation | Three to ten years; a mix of audit and data skills; SQL and a visualization tool at minimum | Every engagement starts from a full population rather than a sample; the journal entry analytics and accounts payable analytics routines run without a request | Builds dashboards nobody uses; the department’s analytics live in one person’s head |
| Audit operations, methodology, or quality lead | The audit manual, workpaper standards, the audit management system, the quality assurance and improvement program, self-assessments, external quality assessment readiness, metrics, and committee reporting logistics | Five to fifteen years; often a former manager who prefers the machinery to the engagements | Workpapers look the same across teams; the QAIP produces findings about the department that get fixed; the EQA holds no surprises | Methodology grows into bureaucracy; templates replace thinking |
| Co-source staff and guest auditors | Specialist hours from an outside firm on topics the department lacks, and rotational staff from the business seconded for an engagement or a year | Varies; co-source staff bring the firm’s methodology, guests bring the business’s knowledge | Co-source work is supervised and reviewed to the department’s standard and stays in the department’s files; guests learn the method and go back as allies | Co-source runs unsupervised and the department cannot defend the work; guests audit their own former area |
| Administrative and coordination support | Scheduling, document request tracking, issue log administration, committee pack assembly, travel, budget tracking | Varies; in small functions the CAE’s assistant, in large ones a team | The committee pack goes out on time and complete; the issue log is current | Underestimated until it is missing |
Two of these roles deserve more than a row. The senior auditor is the position on which engagement quality actually turns: the manager reviews and the CAE approves, but the senior decides what to test, how many items, from which population, and what the exception means, and a department with weak seniors produces reports that the reviewers can polish but cannot rescue. The workpaper best practices guide is written mostly for this role. The chief audit executive, at the other end, is the only person in the department whose job is mostly judgment rather than production: what the committee hears, how a finding is rated when the evidence is mixed, when a management response is accepted and when it is challenged, whether to escalate a matter now or wait for the report. Everyone else in the department produces evidence and conclusions; the CAE decides what they mean and to whom they are said.
One engagement through every role
The cleanest way to see how the roles fit is to follow one engagement. MidState Beverage’s FY27-01 route cash handling audit was the first engagement of the year, planned at 520 hours and delivered in 548, and it ended with an Unsatisfactory rating, five findings, and eleven management actions after the FY26 discovery that a Dayton depot driver had diverted $18,400 over five months before a customer complaint exposed it. The department is six people: the CAE, one manager, two seniors, one staff auditor, and one auditor who carries analytics and IT. The table shows who did what in each phase; the planning memo template and work program guide show the documents behind the first two rows.
| Phase | Staff auditor | Senior auditor (engagement lead) | Manager | Chief audit executive | Analytics and IT auditor |
|---|---|---|---|---|---|
| Planning (weeks 1 to 2) | Collects the prior-year report, the FY26 investigation file, depot policies, and the settlement process documents; drafts the process narrative | Writes the planning memo: objectives, scope of twelve depots, risk assessment by process step, test approach, hours by phase; schedules the kickoff | Reviews and challenges the memo, adds the acquisition depots to scope, approves the sampling design | Approves the memo; briefs the CFO and COO that the engagement will be direct about the Dayton pattern | Pulls the full population of 37,400 route settlements for the year and the variance override log; builds the stratification |
| Fieldwork (weeks 3 to 7) | Performs walkthroughs at four depots, tests deposit listings, tests the 20 targeted customer confirmations, documents everything in re-performable workpapers | Runs the 60 stratified settlement reconciliations across all twelve depots, of which 14 failed; reviews staff work daily; tells depot managers about exceptions as they arise | Reviews workpapers weekly; decides with the senior that the 1,412 self-approved overrides are a finding rather than a note; manages the extra 28 hours | Briefed weekly; approves extending confirmations after the first failures | Runs the 70-item monetary unit sample on cash deposits, the override analysis, and the statement-coverage analysis that found 1,130 of 4,200 customers receive no monthly statement |
| Reporting (weeks 8 to 9) | Drafts observations in the five Cs format from the findings guide | Turns observations into findings with root causes, drafts the report, holds the closing meeting with the manager | Rates each finding and the overall engagement; negotiates management responses; edits the report to executive length | Final review; decides the Unsatisfactory rating stands despite the COO’s objection; presents to the audit committee | Produces the exhibits: depot-by-depot exception rates and the override chart |
| Follow-up (months 3 to 12) | Collects remediation evidence as actions come due | Validates each of the eleven actions on evidence before closure | Reviews validations; reports status quarterly | Reports open and closed actions to the committee; escalates anything past due twice | Builds a monthly override and reconciliation dashboard so the depots’ own monitoring continues after the audit |
Notice where the hours went. The staff auditor and the senior carried the fieldwork, the analytics auditor turned a sample-based engagement into a population-based one for the parts that could be, the manager’s contribution was mostly judgment about what the exceptions meant, and the CAE’s was mostly the conversations outside the department. Notice also the one moment of real tension, the rating. The COO argued for Needs Improvement on the grounds that the Dayton loss was already known and fixed; the CAE held Unsatisfactory because the same design weaknesses existed at nine of twelve depots and the company had discovered the first loss by luck. That call is the CAE’s alone, and the committee, told both sides, agreed with it. The severity ratings guide explains how the rating scale is meant to work and the report template shows what the finished document looked like.
Who prepares, reviews, and approves what
A department runs on sign-offs, and the pattern is the same at every size: the person who does the work prepares, someone senior reviews, and someone accountable approves. The Standards require supervision of every engagement and evidence of it, which in practice means every workpaper carries a preparer and a reviewer, every report carries the CAE’s approval, and the department can show an external assessor who did what. The table sets out the standard allocation; small functions collapse the columns, and the risk when they do is that the same person prepares and approves, which is exactly what the department tells auditees not to do.
| Deliverable | Prepared by | Reviewed by | Approved by | Received by |
|---|---|---|---|---|
| Internal audit charter | CAE | General counsel, executive sponsor | Audit committee | Board, executive team |
| Risk assessment and annual plan | Managers and directors for their portfolios; CAE consolidates | Executive team for input, not approval | Audit committee; see the audit plan guide | Executive team, external auditor |
| Planning memo and work program | Senior or engagement lead | Manager | Manager, or CAE for high-risk engagements | Process owner, for the scope and timing |
| Workpapers and test results | Staff and senior | Senior for staff work; manager for the engagement file | Manager closes the file; CAE spot-checks | Nobody outside the department, except the external auditor or a regulator on request |
| Findings and ratings | Senior | Manager, with a consistency check against the rating scale | CAE | Process owner first, then management |
| Audit report | Senior drafts; manager rewrites | CAE | CAE | Management, then the audit committee; the external auditor for financial-reporting matters |
| Management responses and action plans | Process owner and responsible executive | Manager for adequacy; CAE where a response is inadequate | Responsible executive | Audit committee, as part of the report |
| Issue validation and closure | Senior or staff | Manager | CAE, for high-rated issues | Committee, through quarterly status; see the issue validation guide |
| Quarterly committee pack | Audit operations or the CAE’s office | CAE | CAE; committee chair sets the agenda | Audit committee |
| Quality assessments | Quality lead or a manager not involved in the engagement | CAE | CAE for internal assessments; the committee commissions the external one | Audit committee, executive team |
How the department is governed and measured
The department audits everyone else, so the question of who audits the department has a specific answer in the Standards: the audit committee, through the charter and the plan; a quality assurance and improvement program that the CAE runs; and an external quality assessment at least once every five years by a qualified, independent assessor, whose report goes to the committee. The QAIP guide covers the mechanics. Between assessments the department is measured by a small set of metrics that the committee sees each quarter, and the ones worth tracking are the ones that would embarrass the department if they were bad.
| Measure | What it tells the committee | Healthy range in practice | The number MidState reported for FY26 |
|---|---|---|---|
| Plan completion | Whether the coverage promised was delivered | 85 to 95 percent of planned engagements reported by year end, with every deferral explained | Ten of eleven; the eleventh deferred when the Dayton investigation absorbed 300 hours |
| Hours against budget | Whether the department estimates its own work honestly | Within 10 percent on most engagements; a pattern of overruns means the plan is overloaded | Within 8 percent across the year; FY27-01 ran 5 percent over |
| Report cycle time | Whether findings reach management while they still matter | Draft within two to three weeks of fieldwork ending; final within two weeks of the draft | Median 18 days to draft, 12 to final |
| Open issues past due | Whether management acts on findings and whether audit follows up | Under 10 percent of open actions past their agreed date; none past due twice without escalation | Fourteen open FY26 findings at year end; three past due, all escalated |
| Issue validation rate | Whether closed means fixed | Every high-rated action validated on evidence; a sample of the rest | All fourteen scheduled for validation in FY27 engagement seven |
| Auditee survey | Whether the department is respected as well as feared | Consistently positive on professionalism and understanding of the business; a low score on “findings were fair” is the one to act on | Positive overall; the depots scored the FY26 route audit lowest on timing |
| Staff retention and development | Whether the department can keep the people it trained | Turnover in line with the company; every auditor with a development plan and CPE on track | One departure in FY26; five of six with a credential or sitting for one |
| Quality assessment results | Whether the work conforms to the Standards | Internal assessment annually with actions closed; external assessment “generally conforms” with a short improvement list | Internal assessment done; first external assessment scheduled for FY28 |
Beyond the metrics, the committee governs by asking. The questions a good committee chair puts to the CAE in private session each quarter are whether anything was kept out of the report, whether management pressured a rating, whether the department has the people and budget for the plan, and what the CAE is worried about that is not on the plan. A CAE who cannot answer those in private session with the executives out of the room is a CAE whose independence exists only on paper, and the private session is the single most important governance mechanism the department has.
What the department produces, and how to tell whether it is working
The department’s output is not reports; reports are the packaging. The outputs are assurance, which is a supported opinion the board can rely on; advice, which is the department’s knowledge applied before a decision rather than after it; and insight, which is the pattern across engagements that no single business unit can see. A function producing only the first is a compliance-checking function that happens to report to the board. A function producing only the second has drifted into consulting. The balance shifts with the organization’s maturity, and the table sets out the products in each category with the evidence that they are landing.
| Output | What it is | Who consumes it | Evidence it is working | Example from the two companies |
|---|---|---|---|---|
| Engagement assurance | An opinion on the design and operation of controls in a defined area, supported by testing | Process owners, executives, the committee, the external auditor | Findings are acted on; the external auditor relies on the work; the committee’s questions get sharper rather than repetitive | MidState’s FY27-01 route cash report: five findings, eleven actions, and a redesign of settlement reconciliation at nine depots |
| Annual or periodic overall opinion | The CAE’s view of the control environment as a whole, drawn from the year’s engagements | The board | The board can point to the opinion when a regulator or investor asks how it oversees control | Lakeshore’s CAE issues an annual overall opinion by risk category, a practice examiners noted favorably |
| Advisory work | Review of a project, a control design, or a policy before it goes live, without an assurance opinion | Executives and project sponsors | The department is invited before decisions, not after; the advisory hours are capped and disclosed | MidState’s FY27 fleet and DOT advisory, 300 hours, which produced a compliance inventory with named owners |
| Investigations | Fact-finding into suspected fraud or misconduct, usually with legal and HR | General counsel, executives, the committee | Facts established and evidenced; no conclusions about guilt; controls improved afterward | MidState’s FY26 Dayton investigation, which established the $18,400 loss and the design weakness behind it |
| Continuous monitoring and analytics | Recurring tests over full populations, with results to management | Process owners, the department’s own planning | Exceptions fall over time; the routines are owned by the business eventually, not by audit | Lakeshore’s monthly access and journal-entry analytics; MidState’s override dashboard after FY27-01 |
| Issue tracking and validation | The register of open findings, their owners and dates, and the evidence of closure | Executives and the committee | Past-due actions are rare and escalated; closed means validated | MidState’s fourteen open FY26 findings, validated in FY27; see the issue log template |
| Insight across engagements | Patterns that only the department can see: the same root cause in three areas, a control that fails whenever a system is replaced | The executive team and the board | Themes appear in the committee pack and lead to enterprise-level change | Lakeshore’s finding that four unrelated engagements traced to the same unmonitored privileged access, which became a program |
| People | Auditors who leave the department for the business, carrying its way of thinking | The whole organization | Alumni in management roles who ask for audits rather than avoiding them | Lakeshore’s rotation program has placed former auditors in finance, operations, and compliance |
The test of whether the department is working is not activity but behavior elsewhere: whether management asks for its view before decisions, whether the external auditor relies on its work, whether findings stay fixed, and whether the committee’s understanding of the company’s risks is better than it was a year ago. A department can be busy, conformant with the Standards, and still fail that test if its reports describe last year’s risks in language nobody outside the department reads. The report-writing guide covers the last of those failures, because it is the most common.
Career paths through and out of the department
Internal audit is one of the few functions where the career ladder is visible from the bottom rung and where leaving is considered a success. The department hires from public accounting, from the business, and from universities; it promotes on a roughly three-year cadence in healthy functions; and it exports people into finance, risk, operations, and compliance roles at a rate that some CAEs track as a metric. The table sets out the ladder with what each step requires and where people step off, and the By Role hub expands every row.
| Step | Typical years in role | What earns the promotion | Credential expected by the next step | Common exits at this step |
|---|---|---|---|---|
| Staff auditor | Two to three | Workpapers that need no rework; running a small engagement end to end under supervision; one credential passed or in progress | CIA, CPA, or CISA in progress; the interview guide covers how the role is hired | Financial analyst, accounting, a public accounting firm |
| Senior auditor | Two to four | Engagements delivered to budget with findings that hold up; staff developed; auditees who trust the senior | CIA or CPA in hand; CISA for the IT track | Controller’s team, risk management, compliance, SOX team, consulting |
| Manager | Three to five | A portfolio run without the CAE’s intervention; consistent ratings; contribution to the plan; a reputation with executives | Two credentials common | Finance director, head of risk or compliance, head of a small internal audit function elsewhere |
| Senior manager or director | Three to six | Managers developed; portfolio coverage defensible to the committee; executive relationships; the ability to stand in for the CAE | CIA expected; the credential mix should cover the portfolio | CAE at a smaller organization, chief risk officer, operations leadership |
| Chief audit executive | Five to ten or more | Appointed by the committee; reappointed by results and trust | CIA, often with CPA or CISA | CFO, chief risk officer, board roles, a larger CAE role, consulting practice leadership |
| Specialist tracks | Parallel to the ladder | IT audit, analytics, methodology, and investigations have their own ladders to director level without managing generalists | CISA, CRISC, CFE, or data credentials | Information security, IT risk, data functions, forensic practices |
Rotation deserves a specific mention because it changes the department’s relationship with the company. A guest auditor program, where people from finance or operations spend six to twelve months in the department, and an alumni policy, where departing auditors are placed deliberately into control-sensitive roles, together produce a company in which management understands what audit does and why, which makes every subsequent engagement faster. The objectivity rule that goes with it is simple and non-negotiable: nobody audits an area they worked in during the previous year, and the staffing memo for every engagement says so. The GIAS Domain II guide covers the rule and its cousins.
Common structural mistakes
| Mistake | What it looks like | Why it matters | Fix |
|---|---|---|---|
| Reporting line to the CFO only | The committee sees the CAE twice a year; the CFO sets the plan and the pay | Independence exists on paper; financial-reporting risks get covered and the CFO’s own areas do not | Functional reporting to the committee in the charter, with the committee approving plan, budget, and the CAE’s appointment and pay |
| No supervision layer | Seniors’ work goes straight to the CAE, or nobody reviews the seniors at all | Quality depends on individuals; the external assessor will find it | Preparer and reviewer on every workpaper; a manager between the senior and the CAE, or co-sourced review in a tiny function |
| Everyone is a generalist, or everyone is a specialist | No one can audit the ERP, or the IT team never sees a reconciliation | Coverage gaps the plan does not show | One specialist per critical domain and deliberate rotation across the boundary |
| Co-source without ownership | The outside firm runs engagements the department does not review and could not defend | The committee is relying on work the CAE has not supervised | Department-owned planning, review, and files; the co-sourcing guide covers the contract terms |
| The plan is the calendar | The same engagements every year in the same order because that is what the team knows | The risks that matter this year go unaudited | A risk assessment that can change the plan, and a committee that asks what fell off and why; see the risk assessment guide |
| No time for follow-up | Validation is squeezed out by new engagements; issues close on management’s word | Findings do not stay fixed and the committee does not know | Validation hours in the plan as an engagement of its own, as MidState’s engagement seven is |
| The CAE does the fieldwork | In a small function, the head spends most hours testing | Nobody is doing the CAE’s actual job: the plan, the committee, the judgment calls | Buy fieldwork hours before buying management hours; the head’s time goes to planning, review, and the committee |
| Metrics that measure activity | Reports issued, hours charged, findings raised | The department optimizes for volume and the committee cannot tell whether anything improved | Measure closure, validation, cycle time, reliance by the external auditor, and what management does with the advice |
| No development plan | Staff learn by osmosis; credentials are personal projects | The best people leave for firms that will invest in them | A credential expectation per level with paid study time and fees, and a CPE budget that is actually spent |
Seen whole, an internal audit department is an argument the organization makes to itself: that someone independent will look, that what they find will be said plainly to the people who can act, and that the looking will be done well enough to be believed. The roles exist to make that argument credible at each step, from the staff auditor whose workpaper can be re-performed to the CAE whose rating survives an executive’s objection. When the roles are filled and the lines between them respected, the department is worth many times what it costs. When they are not, it is a group of people who check things and write reports.
Related guides
- Global Internal Audit Standards overview
- GIAS Domain III: governing the function
- GIAS Domain IV: managing the function
- How to write an internal audit charter
- How to build an internal audit plan
- QAIP and the external quality assessment
- How to establish an internal audit function in a small company
- The true total cost of an internal audit
- Co-sourcing vs. outsourcing
- Internal audit vs. compliance
- Internal controls and the Three Lines Model
- How to prepare for an internal audit
- Internal audit interview questions
- Internal audit careers by role
- Start here
Leave a Reply