, ,

Inside the Internal Audit Department: Roles and Structure

An internal audit department looks simple from outside: a group of people who check things and write reports. From inside it is a small organization with its own governance, its own production line, and a division of labor that decides whether the reports are worth reading. This guide walks through that organization role by role, from the associate on their first walkthrough to the chief audit executive in front of the audit committee, and explains what each person actually does, how the work moves between them, who signs what, and how the department is held to account for the value it produces. It is written for three readers: people considering the profession, new hires trying to understand the machine they have joined, and managers in the business who want to know who they are dealing with and why.

This guide was rewritten in September 2026 against the Global Internal Audit Standards, which since January 2025 define what a function must have in place: a charter approved by the board, a chief audit executive with direct access to it, a risk-based plan, supervision and review of every engagement, and a quality program that is assessed externally at least every five years. Two example functions run through it: MidState Beverage’s six-person team at a three-state distributor, and Lakeshore Bancorp’s twenty-two-person department at a nine-billion-dollar public bank, so that the same roles can be seen at two very different scales. For the profession’s definition and the Standards themselves, start with the Standards overview; for how the department relates to the compliance function next door, the internal audit vs. compliance guide.

In this guide

What the department is for, and where it sits

The department exists to give the board, through its audit committee, an independent and objective view of whether the organization’s governance, risk management, and control processes work, and to help management improve them. That sentence comes from the IIA’s definition of the profession and it settles the department’s position in the organization: it reports functionally to the board and administratively to an executive, usually the chief executive or chief financial officer, and the two lines mean different things. The functional line is where independence lives: the committee approves the charter, the plan, the budget, and the chief audit executive’s appointment, evaluation, and pay, and receives the results. The administrative line handles the things a function needs from the company it sits inside: payroll, facilities, HR policy, and a senior executive who can open doors. When the two lines are confused, the department starts answering to the people it audits, which is the failure the GIAS Domain III guide describes in detail.

The department’s mandate is written down in one document, the internal audit charter, which the Standards require the board to approve and which defines the function’s purpose, authority, responsibilities, position in the organization, scope of work, and the nature of the services it may provide. Everything else about the department flows from the charter: the right to unrestricted access to records, people, and property; the obligation to follow the Standards; the split between assurance and advisory work; and the reporting lines just described. A department without a current charter is a department whose authority depends on who is asking, and a good first question for any new hire is when the charter was last approved. The charter guide shows what a complete one contains.

Three things the department is not. It is not management’s control function; it does not own risks, design controls, or run remediation, which is the difference between the third line and the second that the Three Lines guide works through. It is not the external auditor; it reports to the board rather than to shareholders, covers operations and compliance as well as financial reporting, and issues no opinion on the financial statements, though the external auditor may rely on parts of its work. And it is not a police force; it can investigate, and often does, but the authority to discipline, prosecute, or terminate belongs to management and the board.

How departments are structured, by size

Size determines structure more than industry does. The same roles exist in a three-person function and a hundred-person one, but in the small function they are worn as hats by the same people, and in the large one they become teams. The table describes the common configurations, with the two example companies placed where they fall; the audit cost guide covers what each configuration costs to run.

Department sizeTypical organizationRoles presentHow coverage is achievedCharacteristic strengths and weaknesses
One to three peoplePrivate companies and nonprofits with revenue from tens of millions to a few hundred million; a first function set up as the small-company guide describesA head of internal audit who is also the senior auditor, plus one or two auditors; IT audit and specialist work co-sourcedA short plan of six to ten engagements a year; heavy reliance on co-source for technical areas; the head does fieldworkClose to the business and fast; thin review, single points of failure, and a head who cannot be away for a month
Four to ten people (MidState Beverage: six)Mid-sized companies, regional banks, hospital systems, universitiesChief audit executive, one or two managers, seniors and staff; one person carries IT audit or analytics; co-source for the restEight to fifteen engagements plus analytics and validation; a formal risk assessment and universe; the CAE still reviews every reportEnough depth for real supervision; still exposed when two people leave at once; analytics depends on one person
Ten to thirty people (Lakeshore Bancorp: twenty-two)Public companies, larger banks and insurers, large health systemsCAE, directors or senior managers by area (financial, operational, IT, compliance or regulatory), managers, seniors, staff; a dedicated IT audit team; an analytics lead; often an audit operations or quality roleTwenty-five to sixty engagements; continuous monitoring in some areas; regulatory-driven coverage where applicable; co-source for specialist topics such as model riskReal specialization and review layers; risk of silos between the financial and IT teams; the CAE becomes a manager of managers
Thirty to a hundred or moreLarge multinationals, global banks, federal agenciesEverything above plus regional teams, a methodology and quality assurance group, a data and technology group, a professional practices lead, and sometimes a dedicated investigations unitHundreds of engagements; global plan with regional plans beneath it; audit management systems; continuous auditing programsDepth in every area; bureaucracy, slow reporting, and a real risk that the audit committee sees only summaries of summaries

Two structural choices cut across size. The first is in-house versus co-sourced capacity: nearly every department buys some specialist hours from outside, and the co-sourcing comparison covers how much is healthy and when it tips into outsourcing the function’s judgment. The second is organization by audit type versus by business area: a bank of Lakeshore’s size usually organizes by type, with financial, operational, IT, and regulatory teams, while a manufacturer often organizes by division or geography and lets each team cover every type. Neither is right; the failure is organizing by type and never rotating people across the boundary, which produces IT auditors who cannot read a reconciliation and financial auditors who cannot read an access report.

The roles: what each person actually does

Job titles vary by company; the work does not. The table describes each role by what fills its days, what experience it usually carries, what good looks like, and how it typically fails. Read the last column carefully if you are joining a department, because the failures are the things nobody puts in the job description.

RoleWhat fills the daysTypical experience and credentialsWhat good looks likeHow it fails
Staff auditor or associateWalkthroughs, document requests, control testing, sampling, workpapers, drafting observations; the majority of the fieldwork hours on every engagementZero to three years; accounting, finance, business, or IT degree; working toward the CIA or CPAClean, re-performable workpapers; asks why a control exists before testing whether it operates; flags problems the day they appearTicks and ties without understanding; hides uncertainty until the review; treats the auditee as an adversary
Senior auditorLeads fieldwork on an engagement: scopes the test plan, allocates work to staff, performs the hardest tests, reviews staff workpapers, drafts the findings and the reportThree to six years; CIA, CPA, or CISA in hand or imminentRuns the engagement to budget; findings are accurate and evidenced before the manager sees them; auditees hear about issues from the senior first, not from the draft reportDoes all the work personally and never develops staff; lets scope drift; finds out in week four that the population was incomplete
Audit manager or supervisorOwns two to four concurrent engagements: planning memos, risk assessment of the area, review of all workpapers and findings, the closing meeting, the report, and the relationship with the process owner; contributes to the annual planSix to ten years; CIA plus a second credential is common; the audit manager interview guide shows what is expectedReports that leave the manager’s desk are ready for the CAE; findings are rated consistently; engagements finish within the hours the timeline guide describes as normalBecomes a bottleneck; re-performs seniors’ work instead of reviewing it; softens findings to keep the relationship
Senior manager or directorOwns a portfolio, typically an audit type or a business division: the risk assessment for that portfolio, the plan input, resourcing, the quality of every report in the portfolio, and the executive relationshipsTen to fifteen years; often the CAE’s successor; manages managers rather than engagementsThe portfolio’s coverage is defensible to the committee; managers are developed, not supervised; the director sees problems across engagements that no single manager canLoses touch with the fieldwork and cannot judge report quality; builds a silo
Chief audit executiveThe charter, the risk assessment and plan, the budget, the audit committee relationship, the executive relationships, the quality program, hiring and development, the final review of every report, and the judgment calls: which findings go to the committee, how they are rated, when to escalateFifteen years or more; CIA expected, CPA common, both frequent; the CAE interview guide describes the selectionThe committee trusts the function’s opinion because it has been right before; management sees the function as demanding and fair; the plan tracks the risks that matter this year rather than last year’sCaptured by management; over-promises coverage; hides behind the committee or hides from it
IT audit specialist or IT audit managerITGC engagements, application control testing, access reviews, cyber and cloud audits, IT support on every engagement that touches a system, and increasingly the audit of technology projects and AIThree to fifteen years; CISA expected, often CISSP, CISM, or CRISC; described in the CIA vs. CISA guideFinancial auditors can rely on the ITGC conclusions; IT findings are written so a CFO can understand why they matterReports in jargon; audits configuration rather than risk; becomes a separate department inside the department
Data analytics leadBuilds the population extracts and analytics for engagements, continuous monitoring routines, and the tools the rest of the team uses; increasingly owns the department’s automationThree to ten years; a mix of audit and data skills; SQL and a visualization tool at minimumEvery engagement starts from a full population rather than a sample; the journal entry analytics and accounts payable analytics routines run without a requestBuilds dashboards nobody uses; the department’s analytics live in one person’s head
Audit operations, methodology, or quality leadThe audit manual, workpaper standards, the audit management system, the quality assurance and improvement program, self-assessments, external quality assessment readiness, metrics, and committee reporting logisticsFive to fifteen years; often a former manager who prefers the machinery to the engagementsWorkpapers look the same across teams; the QAIP produces findings about the department that get fixed; the EQA holds no surprisesMethodology grows into bureaucracy; templates replace thinking
Co-source staff and guest auditorsSpecialist hours from an outside firm on topics the department lacks, and rotational staff from the business seconded for an engagement or a yearVaries; co-source staff bring the firm’s methodology, guests bring the business’s knowledgeCo-source work is supervised and reviewed to the department’s standard and stays in the department’s files; guests learn the method and go back as alliesCo-source runs unsupervised and the department cannot defend the work; guests audit their own former area
Administrative and coordination supportScheduling, document request tracking, issue log administration, committee pack assembly, travel, budget trackingVaries; in small functions the CAE’s assistant, in large ones a teamThe committee pack goes out on time and complete; the issue log is currentUnderestimated until it is missing

Two of these roles deserve more than a row. The senior auditor is the position on which engagement quality actually turns: the manager reviews and the CAE approves, but the senior decides what to test, how many items, from which population, and what the exception means, and a department with weak seniors produces reports that the reviewers can polish but cannot rescue. The workpaper best practices guide is written mostly for this role. The chief audit executive, at the other end, is the only person in the department whose job is mostly judgment rather than production: what the committee hears, how a finding is rated when the evidence is mixed, when a management response is accepted and when it is challenged, whether to escalate a matter now or wait for the report. Everyone else in the department produces evidence and conclusions; the CAE decides what they mean and to whom they are said.

One engagement through every role

The cleanest way to see how the roles fit is to follow one engagement. MidState Beverage’s FY27-01 route cash handling audit was the first engagement of the year, planned at 520 hours and delivered in 548, and it ended with an Unsatisfactory rating, five findings, and eleven management actions after the FY26 discovery that a Dayton depot driver had diverted $18,400 over five months before a customer complaint exposed it. The department is six people: the CAE, one manager, two seniors, one staff auditor, and one auditor who carries analytics and IT. The table shows who did what in each phase; the planning memo template and work program guide show the documents behind the first two rows.

PhaseStaff auditorSenior auditor (engagement lead)ManagerChief audit executiveAnalytics and IT auditor
Planning (weeks 1 to 2)Collects the prior-year report, the FY26 investigation file, depot policies, and the settlement process documents; drafts the process narrativeWrites the planning memo: objectives, scope of twelve depots, risk assessment by process step, test approach, hours by phase; schedules the kickoffReviews and challenges the memo, adds the acquisition depots to scope, approves the sampling designApproves the memo; briefs the CFO and COO that the engagement will be direct about the Dayton patternPulls the full population of 37,400 route settlements for the year and the variance override log; builds the stratification
Fieldwork (weeks 3 to 7)Performs walkthroughs at four depots, tests deposit listings, tests the 20 targeted customer confirmations, documents everything in re-performable workpapersRuns the 60 stratified settlement reconciliations across all twelve depots, of which 14 failed; reviews staff work daily; tells depot managers about exceptions as they ariseReviews workpapers weekly; decides with the senior that the 1,412 self-approved overrides are a finding rather than a note; manages the extra 28 hoursBriefed weekly; approves extending confirmations after the first failuresRuns the 70-item monetary unit sample on cash deposits, the override analysis, and the statement-coverage analysis that found 1,130 of 4,200 customers receive no monthly statement
Reporting (weeks 8 to 9)Drafts observations in the five Cs format from the findings guideTurns observations into findings with root causes, drafts the report, holds the closing meeting with the managerRates each finding and the overall engagement; negotiates management responses; edits the report to executive lengthFinal review; decides the Unsatisfactory rating stands despite the COO’s objection; presents to the audit committeeProduces the exhibits: depot-by-depot exception rates and the override chart
Follow-up (months 3 to 12)Collects remediation evidence as actions come dueValidates each of the eleven actions on evidence before closureReviews validations; reports status quarterlyReports open and closed actions to the committee; escalates anything past due twiceBuilds a monthly override and reconciliation dashboard so the depots’ own monitoring continues after the audit

Notice where the hours went. The staff auditor and the senior carried the fieldwork, the analytics auditor turned a sample-based engagement into a population-based one for the parts that could be, the manager’s contribution was mostly judgment about what the exceptions meant, and the CAE’s was mostly the conversations outside the department. Notice also the one moment of real tension, the rating. The COO argued for Needs Improvement on the grounds that the Dayton loss was already known and fixed; the CAE held Unsatisfactory because the same design weaknesses existed at nine of twelve depots and the company had discovered the first loss by luck. That call is the CAE’s alone, and the committee, told both sides, agreed with it. The severity ratings guide explains how the rating scale is meant to work and the report template shows what the finished document looked like.

Who prepares, reviews, and approves what

A department runs on sign-offs, and the pattern is the same at every size: the person who does the work prepares, someone senior reviews, and someone accountable approves. The Standards require supervision of every engagement and evidence of it, which in practice means every workpaper carries a preparer and a reviewer, every report carries the CAE’s approval, and the department can show an external assessor who did what. The table sets out the standard allocation; small functions collapse the columns, and the risk when they do is that the same person prepares and approves, which is exactly what the department tells auditees not to do.

DeliverablePrepared byReviewed byApproved byReceived by
Internal audit charterCAEGeneral counsel, executive sponsorAudit committeeBoard, executive team
Risk assessment and annual planManagers and directors for their portfolios; CAE consolidatesExecutive team for input, not approvalAudit committee; see the audit plan guideExecutive team, external auditor
Planning memo and work programSenior or engagement leadManagerManager, or CAE for high-risk engagementsProcess owner, for the scope and timing
Workpapers and test resultsStaff and seniorSenior for staff work; manager for the engagement fileManager closes the file; CAE spot-checksNobody outside the department, except the external auditor or a regulator on request
Findings and ratingsSeniorManager, with a consistency check against the rating scaleCAEProcess owner first, then management
Audit reportSenior drafts; manager rewritesCAECAEManagement, then the audit committee; the external auditor for financial-reporting matters
Management responses and action plansProcess owner and responsible executiveManager for adequacy; CAE where a response is inadequateResponsible executiveAudit committee, as part of the report
Issue validation and closureSenior or staffManagerCAE, for high-rated issuesCommittee, through quarterly status; see the issue validation guide
Quarterly committee packAudit operations or the CAE’s officeCAECAE; committee chair sets the agendaAudit committee
Quality assessmentsQuality lead or a manager not involved in the engagementCAECAE for internal assessments; the committee commissions the external oneAudit committee, executive team

How the department is governed and measured

The department audits everyone else, so the question of who audits the department has a specific answer in the Standards: the audit committee, through the charter and the plan; a quality assurance and improvement program that the CAE runs; and an external quality assessment at least once every five years by a qualified, independent assessor, whose report goes to the committee. The QAIP guide covers the mechanics. Between assessments the department is measured by a small set of metrics that the committee sees each quarter, and the ones worth tracking are the ones that would embarrass the department if they were bad.

MeasureWhat it tells the committeeHealthy range in practiceThe number MidState reported for FY26
Plan completionWhether the coverage promised was delivered85 to 95 percent of planned engagements reported by year end, with every deferral explainedTen of eleven; the eleventh deferred when the Dayton investigation absorbed 300 hours
Hours against budgetWhether the department estimates its own work honestlyWithin 10 percent on most engagements; a pattern of overruns means the plan is overloadedWithin 8 percent across the year; FY27-01 ran 5 percent over
Report cycle timeWhether findings reach management while they still matterDraft within two to three weeks of fieldwork ending; final within two weeks of the draftMedian 18 days to draft, 12 to final
Open issues past dueWhether management acts on findings and whether audit follows upUnder 10 percent of open actions past their agreed date; none past due twice without escalationFourteen open FY26 findings at year end; three past due, all escalated
Issue validation rateWhether closed means fixedEvery high-rated action validated on evidence; a sample of the restAll fourteen scheduled for validation in FY27 engagement seven
Auditee surveyWhether the department is respected as well as fearedConsistently positive on professionalism and understanding of the business; a low score on “findings were fair” is the one to act onPositive overall; the depots scored the FY26 route audit lowest on timing
Staff retention and developmentWhether the department can keep the people it trainedTurnover in line with the company; every auditor with a development plan and CPE on trackOne departure in FY26; five of six with a credential or sitting for one
Quality assessment resultsWhether the work conforms to the StandardsInternal assessment annually with actions closed; external assessment “generally conforms” with a short improvement listInternal assessment done; first external assessment scheduled for FY28

Beyond the metrics, the committee governs by asking. The questions a good committee chair puts to the CAE in private session each quarter are whether anything was kept out of the report, whether management pressured a rating, whether the department has the people and budget for the plan, and what the CAE is worried about that is not on the plan. A CAE who cannot answer those in private session with the executives out of the room is a CAE whose independence exists only on paper, and the private session is the single most important governance mechanism the department has.

What the department produces, and how to tell whether it is working

The department’s output is not reports; reports are the packaging. The outputs are assurance, which is a supported opinion the board can rely on; advice, which is the department’s knowledge applied before a decision rather than after it; and insight, which is the pattern across engagements that no single business unit can see. A function producing only the first is a compliance-checking function that happens to report to the board. A function producing only the second has drifted into consulting. The balance shifts with the organization’s maturity, and the table sets out the products in each category with the evidence that they are landing.

OutputWhat it isWho consumes itEvidence it is workingExample from the two companies
Engagement assuranceAn opinion on the design and operation of controls in a defined area, supported by testingProcess owners, executives, the committee, the external auditorFindings are acted on; the external auditor relies on the work; the committee’s questions get sharper rather than repetitiveMidState’s FY27-01 route cash report: five findings, eleven actions, and a redesign of settlement reconciliation at nine depots
Annual or periodic overall opinionThe CAE’s view of the control environment as a whole, drawn from the year’s engagementsThe boardThe board can point to the opinion when a regulator or investor asks how it oversees controlLakeshore’s CAE issues an annual overall opinion by risk category, a practice examiners noted favorably
Advisory workReview of a project, a control design, or a policy before it goes live, without an assurance opinionExecutives and project sponsorsThe department is invited before decisions, not after; the advisory hours are capped and disclosedMidState’s FY27 fleet and DOT advisory, 300 hours, which produced a compliance inventory with named owners
InvestigationsFact-finding into suspected fraud or misconduct, usually with legal and HRGeneral counsel, executives, the committeeFacts established and evidenced; no conclusions about guilt; controls improved afterwardMidState’s FY26 Dayton investigation, which established the $18,400 loss and the design weakness behind it
Continuous monitoring and analyticsRecurring tests over full populations, with results to managementProcess owners, the department’s own planningExceptions fall over time; the routines are owned by the business eventually, not by auditLakeshore’s monthly access and journal-entry analytics; MidState’s override dashboard after FY27-01
Issue tracking and validationThe register of open findings, their owners and dates, and the evidence of closureExecutives and the committeePast-due actions are rare and escalated; closed means validatedMidState’s fourteen open FY26 findings, validated in FY27; see the issue log template
Insight across engagementsPatterns that only the department can see: the same root cause in three areas, a control that fails whenever a system is replacedThe executive team and the boardThemes appear in the committee pack and lead to enterprise-level changeLakeshore’s finding that four unrelated engagements traced to the same unmonitored privileged access, which became a program
PeopleAuditors who leave the department for the business, carrying its way of thinkingThe whole organizationAlumni in management roles who ask for audits rather than avoiding themLakeshore’s rotation program has placed former auditors in finance, operations, and compliance

The test of whether the department is working is not activity but behavior elsewhere: whether management asks for its view before decisions, whether the external auditor relies on its work, whether findings stay fixed, and whether the committee’s understanding of the company’s risks is better than it was a year ago. A department can be busy, conformant with the Standards, and still fail that test if its reports describe last year’s risks in language nobody outside the department reads. The report-writing guide covers the last of those failures, because it is the most common.

Career paths through and out of the department

Internal audit is one of the few functions where the career ladder is visible from the bottom rung and where leaving is considered a success. The department hires from public accounting, from the business, and from universities; it promotes on a roughly three-year cadence in healthy functions; and it exports people into finance, risk, operations, and compliance roles at a rate that some CAEs track as a metric. The table sets out the ladder with what each step requires and where people step off, and the By Role hub expands every row.

StepTypical years in roleWhat earns the promotionCredential expected by the next stepCommon exits at this step
Staff auditorTwo to threeWorkpapers that need no rework; running a small engagement end to end under supervision; one credential passed or in progressCIA, CPA, or CISA in progress; the interview guide covers how the role is hiredFinancial analyst, accounting, a public accounting firm
Senior auditorTwo to fourEngagements delivered to budget with findings that hold up; staff developed; auditees who trust the seniorCIA or CPA in hand; CISA for the IT trackController’s team, risk management, compliance, SOX team, consulting
ManagerThree to fiveA portfolio run without the CAE’s intervention; consistent ratings; contribution to the plan; a reputation with executivesTwo credentials commonFinance director, head of risk or compliance, head of a small internal audit function elsewhere
Senior manager or directorThree to sixManagers developed; portfolio coverage defensible to the committee; executive relationships; the ability to stand in for the CAECIA expected; the credential mix should cover the portfolioCAE at a smaller organization, chief risk officer, operations leadership
Chief audit executiveFive to ten or moreAppointed by the committee; reappointed by results and trustCIA, often with CPA or CISACFO, chief risk officer, board roles, a larger CAE role, consulting practice leadership
Specialist tracksParallel to the ladderIT audit, analytics, methodology, and investigations have their own ladders to director level without managing generalistsCISA, CRISC, CFE, or data credentialsInformation security, IT risk, data functions, forensic practices

Rotation deserves a specific mention because it changes the department’s relationship with the company. A guest auditor program, where people from finance or operations spend six to twelve months in the department, and an alumni policy, where departing auditors are placed deliberately into control-sensitive roles, together produce a company in which management understands what audit does and why, which makes every subsequent engagement faster. The objectivity rule that goes with it is simple and non-negotiable: nobody audits an area they worked in during the previous year, and the staffing memo for every engagement says so. The GIAS Domain II guide covers the rule and its cousins.

Common structural mistakes

MistakeWhat it looks likeWhy it mattersFix
Reporting line to the CFO onlyThe committee sees the CAE twice a year; the CFO sets the plan and the payIndependence exists on paper; financial-reporting risks get covered and the CFO’s own areas do notFunctional reporting to the committee in the charter, with the committee approving plan, budget, and the CAE’s appointment and pay
No supervision layerSeniors’ work goes straight to the CAE, or nobody reviews the seniors at allQuality depends on individuals; the external assessor will find itPreparer and reviewer on every workpaper; a manager between the senior and the CAE, or co-sourced review in a tiny function
Everyone is a generalist, or everyone is a specialistNo one can audit the ERP, or the IT team never sees a reconciliationCoverage gaps the plan does not showOne specialist per critical domain and deliberate rotation across the boundary
Co-source without ownershipThe outside firm runs engagements the department does not review and could not defendThe committee is relying on work the CAE has not supervisedDepartment-owned planning, review, and files; the co-sourcing guide covers the contract terms
The plan is the calendarThe same engagements every year in the same order because that is what the team knowsThe risks that matter this year go unauditedA risk assessment that can change the plan, and a committee that asks what fell off and why; see the risk assessment guide
No time for follow-upValidation is squeezed out by new engagements; issues close on management’s wordFindings do not stay fixed and the committee does not knowValidation hours in the plan as an engagement of its own, as MidState’s engagement seven is
The CAE does the fieldworkIn a small function, the head spends most hours testingNobody is doing the CAE’s actual job: the plan, the committee, the judgment callsBuy fieldwork hours before buying management hours; the head’s time goes to planning, review, and the committee
Metrics that measure activityReports issued, hours charged, findings raisedThe department optimizes for volume and the committee cannot tell whether anything improvedMeasure closure, validation, cycle time, reliance by the external auditor, and what management does with the advice
No development planStaff learn by osmosis; credentials are personal projectsThe best people leave for firms that will invest in themA credential expectation per level with paid study time and fees, and a CPE budget that is actually spent

Seen whole, an internal audit department is an argument the organization makes to itself: that someone independent will look, that what they find will be said plainly to the people who can act, and that the looking will be done well enough to be believed. The roles exist to make that argument credible at each step, from the staff auditor whose workpaper can be re-performed to the CAE whose rating survives an executive’s objection. When the roles are filled and the lines between them respected, the department is worth many times what it costs. When they are not, it is a group of people who check things and write reports.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading