A company usually gets its first internal auditor for one of four reasons: a lender or a new board member asks whether it has one, a fraud is discovered and the answer to “how did nobody see this” is that nobody was looking, an IPO or a SOX readiness project needs someone to test controls, or the company has grown past the point where the CFO can personally know what happens in every location. Whichever reason, the first year decides whether the function becomes a source of assurance the board trusts or a compliance cost the CFO resents. The difference is not the size of the budget. It is whether the function is set up with a charter that gives it independence, a plan that starts with the risks the board actually worries about, and a sourcing model that buys skills the company does not have instead of hiring a generalist and hoping.
This guide is the setup sequence for a small or mid-size company, from the decision to the end of the first year: when a company needs the function and what it is for, the charter clauses and reporting line that make it independent, a sourcing decision matrix with cost ranges, a staffing and budget model for a one-person and a three-person function, the first ninety days, a first-year plan with six engagements and hours, the templates and tools to adopt rather than build, board reporting cadence, the measures that show whether it is working, and the mistakes that sink first-year functions. It was rewritten in September 2026 to reflect the Global Internal Audit Standards, which apply to a one-person function exactly as they apply to a hundred-person one, and it points throughout to the site’s templates for the annual plan, the planning memo, the report, and the issue log, so that the first year is spent auditing rather than designing forms.
In this guide
- When a small company needs internal audit, and what it is for
- The charter and the reporting line
- Sourcing: in-house, co-source, or outsource
- Staffing and budget: two models with numbers
- The first ninety days
- The first-year plan
- Templates and tools: adopt, do not build
- Reporting to the board
- Measuring whether it is working
- Common first-year mistakes
- Adapting: family-owned, PE-backed, pre-IPO, and nonprofit
When a small company needs internal audit, and what it is for
There is no revenue threshold, but there are signals. Multiple locations where cash, inventory, or customer payments are handled by people the CFO does not see weekly. A finance team small enough that the same person approves, records, and reconciles. Lenders or investors with covenants and reporting requirements the company has never independently checked. Growth by acquisition, where the acquired entity’s controls are unknown. A board or audit committee that has started asking questions the management team cannot answer from data. And any fraud, however small, because the loss is rarely the point; the point is that nobody had the job of noticing. A company with two or more of those signals and a few hundred employees has an internal audit need whether or not it has an internal auditor.
What the function is for, in a small company, is narrower and more useful than the textbook definition. It gives the board an independent view of whether the controls over money, assets, and compliance obligations actually operate, which the board cannot get from management and cannot afford to get from the external auditor, whose scope is the financial statements. It gives the CFO a second pair of eyes on the locations and processes the finance team cannot cover. And it gives the company a mechanism for fixing what is found, through an issue log the board sees. It is not a second accounting department, not a compliance function, and not the person who fills in the SOX spreadsheets; a first auditor who is pulled into those jobs will be doing them in year three. The Global Internal Audit Standards describe the purpose in one sentence that survives translation to any size: to strengthen the organization’s ability to create, protect, and sustain value by providing independent, risk-based, and objective assurance, advice, insight, and foresight.
The charter and the reporting line
The charter is the document that makes the function independent, and in a small company it is the only thing that does, because the auditor will sit near the CFO, share the CFO’s budget line, and be asked by the CFO for help. The Standards require a charter approved by the board that establishes the function’s purpose, authority, and position, and the clauses below are the ones a small company’s charter must contain to mean anything. The charter guide has the full step-by-step; the Domain III guide explains the board’s obligations that the charter implements.
| Clause | What it must say | Why it matters in a small company |
|---|---|---|
| Purpose and mandate | Independent assurance and advice over risk management, control, and governance, across the whole company including subsidiaries and locations | Closes the argument about whether the acquired entity or the founder’s side business is in scope |
| Functional reporting line | The head of internal audit reports functionally to the audit committee, or where none exists to the board through an independent director, who approves the charter, the plan, the budget, and the head’s appointment, evaluation, compensation, and removal | Without this, the auditor works for the CFO in every way that counts |
| Administrative reporting line | Day-to-day administration through the CEO or CFO, explicitly limited to logistics and excluding scope, findings, and reporting | Names the arrangement so it cannot expand |
| Authority and access | Unrestricted access to all records, systems, property, and personnel, and the authority to communicate directly with the board | The first time a location manager refuses access, this clause is what the auditor cites |
| Independence and objectivity | No operational responsibilities; a cooling-off period before auditing an area the auditor worked in; disclosure of impairments to the board | Prevents the auditor becoming the SOX coordinator, the policy writer, or the acting controller |
| Advisory services | Permitted when management retains responsibility for decisions and the work is disclosed as advisory; not assured by the auditor for a stated period | The CFO will ask for help; this says how |
| Standards and quality | Conformance with the Global Internal Audit Standards; a quality program proportionate to size; an external assessment at least every five years | Signals to lenders, investors, and the external auditor that the function is real |
| Reporting and follow-up | Findings reported to management and the board; an issue log with status reported to the board at each meeting; management’s responses recorded | The follow-up mechanism is written into the governance, not left to the auditor’s persistence |
| Sourcing | Authority to engage external providers under the head’s direction, with the company retaining responsibility | Makes co-sourcing a normal instrument, not an exception |
| Review | Charter reviewed annually with the board | The clauses erode unless they are re-read |
Where the company has no audit committee, create one or designate an independent director to hold the functional line; a private company with a five-person board can do this in one resolution. Where the board has no independent director, the charter’s functional line runs to the full board, the auditor’s appointment and removal require a board vote, and the auditor reports to the board in a session without management present at least twice a year. A function that reports only to the CFO, in a company with no independent oversight, is an internal control review team, which is useful and is not internal audit; call it what it is and do not tell the lenders otherwise.
Sourcing: in-house, co-source, or outsource
The sourcing decision is the one most small companies get wrong in the same direction: they hire one generalist and expect that person to audit IT security, the ERP’s access model, revenue recognition, and the warehouse in the same year. The honest choice is between three models, and the right answer for most companies under a few thousand employees is the middle one, an in-house head who owns the plan and the relationships and buys the specialist hours. Cost ranges below are for the US in 2026 and vary by market; the point is the shape of the comparison rather than the exact figures.
| Model | What it looks like | Annual cost range | Fits when | Risks |
|---|---|---|---|---|
| In-house only | One to three employees doing all the work | One senior auditor: $130,000 to $190,000 loaded; three-person team: $400,000 to $600,000 loaded, plus tools and travel | The universe is mostly financial and operational processes the team knows; IT and specialist areas are small or bought separately | Skills gaps in IT, cyber, and specialist areas; key-person dependency; no surge capacity for an acquisition or an investigation |
| Co-source (recommended default) | An in-house head (or head plus one) who owns the charter, risk assessment, plan, relationships, reporting, and issue log, and buys specialist and surge hours from a firm under the head’s direction | Head $150,000 to $220,000 loaded, plus $80,000 to $250,000 of purchased hours at $150 to $350 per hour depending on specialty | Most companies from a few hundred to a few thousand employees; any company with meaningful IT, cyber, or regulatory exposure | The firm’s methodology overriding the company’s; the head becoming a contract manager; purchased hours spent on low-value work because they were budgeted |
| Fully outsourced | A firm performs the function under an engagement letter; a company executive is the designated liaison and the board oversees the firm directly | $120,000 to $400,000 depending on scope; typically 600 to 1,500 hours | Companies too small for a full-time head; a bridge before hiring; regulated companies that need a function before they can staff one | No institutional memory; the firm audits to its template; the company retains responsibility under every regulator’s guidance whether it knows it or not; independence questions if the firm also provides other services |
Whatever the model, two rules hold. The company owns the risk assessment, the plan, the findings, and the issue log, and they live in the company’s files under the company’s templates, not the firm’s. And the external auditor is not the internal auditor; the independence rules on both sides prevent it, and a board that is offered “internal audit services” by its financial statement auditor should ask its counsel before saying yes. The co-sourcing guide covers how to scope, contract, and manage purchased hours so that they integrate with the function rather than run beside it.
Staffing and budget: two models with numbers
The models below are for Brightwater Foods, a $180 million specialty food manufacturer with 600 employees, three plants, a distribution center, a lender covenant package, and a board with two independent directors, setting up its first function in FY27. Available hours assume 1,800 productive hours per full-time auditor after leave, training, and administration; the head’s hours are split between engagements and running the function.
| Line | Model A: one-person function plus co-source | Model B: three-person function |
|---|---|---|
| Head of internal audit | 1 FTE, $185,000 loaded; 1,000 engagement hours, 800 function hours | 1 FTE, $195,000 loaded; 800 engagement hours, 1,000 function hours |
| Senior auditor | — | 1 FTE, $135,000 loaded; 1,700 engagement hours |
| Staff auditor or IT auditor | — | 1 FTE IT auditor, $145,000 loaded; 1,700 engagement hours |
| Co-sourced hours | 600 hours at an average $220: $132,000 (IT general controls 200, cybersecurity 150, revenue and inventory specialist 150, surge 100) | 150 hours at $280: $42,000 (penetration testing review and a fraud specialist on call) |
| Tools | Workpaper and issue tracking on the company’s document platform and the site’s templates: $0 to $6,000; data analytics with spreadsheet and query tools: $0 to $3,000 | Audit management platform, entry tier: $15,000 to $35,000; analytics tooling: $5,000 |
| Travel and training | $18,000 (three plants, two conferences, certification maintenance) | $40,000 |
| Total annual cost | About $345,000 | About $600,000 |
| Engagement hours available | 1,600 (1,000 in-house plus 600 purchased) | 4,350 |
| Engagements per year | 5 to 6 at 250 to 300 hours each, plus validation and the risk assessment | 12 to 14, plus validation, advisory, and analytics |
| Cost per engagement hour | About $215 | About $138 |
Brightwater chose Model A for FY27 with a commitment to review at the end of the year, on the reasoning that a first year with five well-chosen engagements would show the board what the function was worth better than a first year spent hiring. The budget conversation with the board used two comparisons: the FY26 inventory shrink write-off at the distribution center ($410,000, discovered by the external auditor at year-end) and the lender’s covenant reporting fee for a third-party review the bank had required ($45,000), which the function would replace.
The first ninety days
| Days | Do | Output | Do not |
|---|---|---|---|
| 1–15 | Get the charter approved by the board with the reporting line settled; meet every board member and every executive; read the last two years of external audit management letters, lender correspondence, insurance claims, and any investigation files | Approved charter; a list of every concern each person raised, verbatim | Start an audit; agree to “just help with” the close, the SOX project, or the ERP go-live |
| 16–35 | Build the audit universe: every entity, location, process, and system, with the money and people in each; visit every plant and the distribution center; walk the cash, inventory, and payroll processes at each | Audit universe with values; site visit notes; a first list of what could go wrong per location | Rely on the org chart; assume the plants run the same way |
| 36–55 | Perform the risk assessment against the universe using the site’s risk assessment method; score, rank, and choose the first-year engagements; identify the skills the plan needs that the function lacks | Scored risk assessment; draft plan with hours; co-source scope | Plan by what is easy to audit; plan by what management asked for |
| 56–70 | Adopt the templates (plan, memo, work program, workpapers, report, issue log); set the rating scale and the issue log rules; set up the workpaper repository with access controls; contract the co-source provider under the function’s methodology | Template set; rating definitions; repository; signed engagement letter | Build templates from scratch; adopt the co-source firm’s templates |
| 71–90 | Present the plan and budget to the board for approval; agree the reporting calendar; begin the first engagement, chosen to be visible, bounded, and likely to find something the board cares about (cash and inventory at the highest-risk location is the usual choice) | Approved plan; reporting calendar; first planning memo issued | Choose a first engagement that will take five months; choose one that will find nothing |
The first-year plan
Brightwater’s FY27 plan, approved on day 84, is below. It follows the annual plan template and its coverage logic: the highest-scored risks first, one engagement that tests the external auditor’s reliance area (ICFR readiness for the lender’s covenant reporting), one that covers the biggest unknown (the newest plant, acquired in FY25), and a reserve. Hours foot to the 1,600 available.
| # | Engagement | Why (risk assessment) | Quarter | Hours | Sourcing |
|---|---|---|---|---|---|
| 1 | Distribution center inventory and shipping controls | FY26 $410,000 shrink write-off; counts unreconciled for two quarters; the location the board asked about | Q1 | 280 | In-house 200; specialist 80 |
| 2 | Procure-to-pay and vendor master, all entities | One AP clerk approves, enters, and pays for the two smaller plants; 1,900 vendors with no master-data controls; see the AP audit guide | Q1–Q2 | 260 | In-house 260 |
| 3 | ERP access and segregation of duties | Roles built at go-live in 2021 by the implementer; 38 users with administrator access; see the ERP SoD guide | Q2 | 220 | In-house 70; IT co-source 150 |
| 4 | Cybersecurity program review | No prior independent review; cyber insurer’s questionnaire answered by IT alone; IIA Cybersecurity Topical Requirement now applies | Q3 | 200 | In-house 50; cyber co-source 150 |
| 5 | Acquired plant: financial and operational controls | Acquired FY25; runs its own payroll and purchasing; never reviewed | Q3 | 240 | In-house 200; specialist 40 |
| 6 | Lender covenant reporting and ICFR readiness | Covenant calculations prepared by one person; lender previously required a third-party review; board wants an ICFR baseline | Q4 | 200 | In-house 120; specialist 80 |
| — | Issue validation (Q3 and Q4 windows) | Findings from engagements 1 to 3 | Q3–Q4 | 80 | In-house |
| — | Reserve | Investigations, board requests, acquisition due diligence support | — | 120 | In-house and surge |
| Total | 1,600 |
The plan leaves out payroll, revenue, treasury, and the two older plants’ operations, and says so in a coverage statement with the year each will be reached. A first-year plan that covers everything covers nothing; a plan that covers six things well and names what it did not cover gives the board a map. Each engagement runs on the planning memo and the work program conventions, which is how a one-person function produces files an external assessor or a lender’s reviewer can read.
Templates and tools: the minimum viable toolkit
A one-person function does not need a GRC platform in year one, and buying one before there is a process to put in it is the most common way a new function burns its first discretionary dollars. What it needs is a fixed set of documents that look the same every time, stored in a folder structure a reviewer can follow without a guide. The table below is the toolkit Brightwater ran on for its first year: eleven artifacts, all of them spreadsheets, documents, or free site tools, with the trigger that tells you when each one has outgrown its format. The rule for the upgrade column is that the tool follows the process, never the other way round.
| Need | Minimum viable version | When to upgrade | Start from |
|---|---|---|---|
| Audit universe and risk assessment | One workbook: entities and processes on rows, impact and likelihood factors on columns, a score, and a column for the last time the area was audited | When the universe passes roughly 60 auditable entities or three people are scoring it independently | Internal audit risk assessment |
| Annual plan | A plan document with the engagement list, hours, sourcing, and the link from each engagement back to a risk score, approved and dated by the committee | Never; the format scales, only the number of rows changes | Internal audit plan template |
| Engagement planning memo | Two pages: objective, scope, risks, approach, budget, timing, and who was interviewed to set them | Never | Audit planning memo template |
| Risk and control matrix | One tab per process: risk, control, owner, frequency, key or non-key, test procedure, result | When you have more than about 15 processes with RCMs to maintain across years | RCM Workbench (free) |
| Work program | The RCM’s test procedure column expanded into steps, with a workpaper reference per step | Never | Audit work program |
| Workpapers | Shared drive, one folder per engagement, an index sheet, a naming convention (engagement code, section, sequence), preparer and reviewer sign-off on the index | When two or more people prepare and review concurrently and version conflicts appear, usually at three auditors | Audit workpaper example |
| Sampling | A documented sample-size rule and a random selection you can reproduce | Never; the rule is the control | mySampler (free) and the 25/40/60 guide |
| Audit report | One fixed format: opinion or rating, summary, findings in the five-Cs structure, management action with owner and date | Never | Internal audit report template |
| Issue log | One spreadsheet: finding, rating, owner, due date, status, evidence of closure, validation date | When open issues pass about 40 or the committee asks for trend reporting you cannot build by hand | Audit issue log template |
| Audit committee pack | A six-page quarterly document with the same sections every quarter (next section) | Never | Internal audit report examples |
| Quality program | A one-page self-assessment against the Standards completed at year end, plus a reviewer checklist on every engagement index | Year five, when the external assessment is due | QAIP guide |
Two rules make the toolkit work. First, every document has a code, and the code appears on the workpaper, in the issue log, and in the committee pack, so a director who asks “where did this finding come from” can be walked from the pack to the evidence in under a minute. Brightwater used engagement codes of the form FY27-03 and workpaper references of the form FY27-03-C-04, which is section C, paper four. Second, the reviewer checklist on the index is completed before the report is issued, not after, and in a one-person function the reviewer is the co-source partner for the first two engagements and the head thereafter, with the committee chair told which arrangement applies. A GRC tool bought in year three inherits a clean structure; one bought in year one inherits nothing and shapes the process around its own defaults.
Reporting to the board and management
The reporting cadence is set in the charter and then run without exception, because a small function’s credibility with its committee is built almost entirely on showing up with the same document at the same interval and saying what changed. Standard 11.3 requires the chief audit executive to communicate results to the board and senior management, and Standard 8.1 requires the board to receive the information it needs to oversee the function; Brightwater’s cadence below satisfies both with about 40 hours of preparation across the year.
| Occasion | Audience | Content | Length and timing |
|---|---|---|---|
| Quarterly audit committee meeting | Audit committee, CFO, CEO, external auditor | Plan status (engagements completed, in progress, deferred, added); reports issued since last meeting with ratings; open issues by rating and age, overdue issues by name; hours used against budget; emerging risks the plan does not cover | Six pages, same section order every quarter, circulated five business days before the meeting |
| Private session | Audit committee members only; the head of internal audit without management present | Anything constraining independence, resistance to scope, management pressure on ratings, the head’s own performance and resourcing | Fifteen minutes at every quarterly meeting, held even when there is nothing to raise, so holding it never signals a problem |
| Annual plan and budget approval | Audit committee | Risk assessment summary, proposed engagements with the risk they address, hours and cost by sourcing model, areas not covered and why | Fourth-quarter meeting; the plan is a standalone document, not a section of the quarterly pack |
| Annual charter and independence confirmation | Audit committee | Charter reaffirmed or amended; written confirmation of organizational independence and any impairments during the year; QAIP self-assessment results | Same fourth-quarter meeting, one page plus the charter |
| Monthly CFO and CEO update | Management | Engagement progress, findings emerging, help needed from management, action plans coming due | Thirty minutes, one page; findings are previewed here, never first disclosed at the committee |
| Significant finding notification | Committee chair, then the full committee | Any finding rated High, any indication of fraud, any control failure affecting the covenant package or the financial statements | Within two business days of the head concluding the finding is supportable; by call to the chair, then in writing |
| Final report distribution | Process owner, their executive, CFO; committee receives the executive summary in the pack | The report in the fixed format with management’s action plan | Within ten business days of the closing meeting |
Two independent directors who have sat on larger boards will ask the same three questions at the first meeting, and the answers should be in the pack before they ask. “What are you not covering?” is answered by the uncovered-areas section of the annual plan, which at Brightwater listed treasury, tax, and the sales commission scheme with the risk score and the year each was expected to be reached. “How do I know your findings are fixed?” is answered by the issue log summary showing closure validated by internal audit rather than declared by management, with the validation windows visible in the plan. “Are you independent?” is answered by the reporting line in the charter, the private session on the agenda, and the head’s written annual confirmation, plus a plain statement of what the head does not do: no month-end review, no sign-off on journal entries, no ownership of the covenant calculation. The GIAS Domain III guide covers the board’s side of these obligations in detail.
The wording of the first quarterly pack sets the tone for every one after it. Ratings are stated without softening, management’s response is printed as management wrote it, and disagreement is recorded rather than negotiated out. Brightwater’s first pack reported the distribution center engagement as Needs Improvement with three findings, one of them High, and the operations vice president’s response, which disputed the High rating, appeared verbatim under the finding with the head’s one-sentence reason for keeping it. The committee chair later said that page was the reason the committee trusted the function; a first pack that reports six engagements as Satisfactory teaches directors to stop reading. The 5 Cs of audit findings structure keeps each finding to the condition, criteria, cause, consequence, and corrective action a director can act on in a single reading.
Measuring the function in year one
Standard 12.2 requires the chief audit executive to develop performance objectives and measure against them, and a new function should choose its measures before the first engagement starts, because a measure adopted in month nine will be chosen to flatter the first nine months. Eight measures are enough. Two of the most common ones are missing from the table deliberately: findings issued, which rewards volume and punishes a well-controlled process for being well controlled, and cost savings identified, which turns the function into a consultancy chasing a number it does not control. Both can appear as commentary; neither should be a target.
| Measure | Year-one target | How it is measured | What it tells the committee |
|---|---|---|---|
| Plan completion | 85 percent of planned engagements reported by year end; deferrals approved by the committee, not decided by the head | Engagements with a final report issued, divided by engagements in the approved plan; additions and deferrals shown separately | Whether the plan was realistic and whether the function can be relied on to deliver what it commits to |
| Report cycle time | Draft within 15 business days of fieldwork end; final within 10 business days of the closing meeting | Calendar days from the last fieldwork day to draft, and from closing meeting to final, per engagement | Whether findings reach the people who can act on them while the evidence is current |
| Action plan closure on time | 75 percent of actions closed by the original due date; no High action more than 90 days overdue without committee notification | From the issue log, by original due date, with extensions counted as late | Whether management takes the function seriously, which is the single best predictor of its second year |
| Validation coverage | Every closed High and Medium action validated by internal audit within 60 days of management’s closure claim | Actions validated divided by actions closed by management, by rating | Whether “closed” means fixed |
| Hours against budget | Within 15 percent per engagement; within 10 percent for the year | Timesheet hours by engagement code against the planned hours in the approved plan | Whether budgets were honest and whether scope crept |
| Time allocation | At least 65 percent of total hours on assurance and validation; no more than 20 percent on advisory and requests; the rest on running the function | Timesheet categories, reported quarterly | Whether the function is being pulled into management’s work |
| Stakeholder feedback | Post-engagement survey returned by the process owner’s executive for every engagement; committee self-assessment of the function at year end | Five questions on a five-point scale: scope relevance, disruption, accuracy of facts, fairness of rating, usefulness of recommendations | Whether findings are landing as accurate and fair, which is different from whether they are welcome |
| Conformance readiness | Year-end self-assessment against the Standards completed, with every “partially conforms” carrying a dated action | Self-assessment against the domains and standards, reviewed with the committee chair | Whether the function will pass its external assessment in year five without a rescue project in year four |
Brightwater reported all eight on one page of the quarterly pack from the first quarter, with year-one actuals of 100 percent plan completion (the cybersecurity review was deferred to Q1 of FY28 by committee decision and counted as such), a 19-day average to draft, 71 percent on-time closure, and 62 percent of hours on assurance, the last two of which became the first two objectives for year two. Reporting a miss in the first year, with the reason, is worth more to the function’s standing than a clean scorecard nobody believes. The GIAS Domain IV guide covers the full set of managerial requirements these measures sit under.
Common mistakes in the first year
| Failure | What it looks like | Why it matters | Fix |
|---|---|---|---|
| Reporting to the CFO only | The charter names the CFO as the reporting line; the committee sees the head twice a year | Finance is the most-audited area in any small company, and the auditor’s appraiser owns it | Functional reporting to the committee in the charter, administrative to the CEO or CFO, private session every quarter |
| Hiring the controller | The former controller becomes the head of internal audit and reviews the close they used to run | Standard 7.1 impairment on every finance engagement for at least a year; the committee’s independence confirmation is untrue | Hire from outside or from operations; if the controller is the only candidate, co-source finance engagements for year one and disclose it |
| Starting with a controls inventory | Six months documenting every control in the company before auditing anything | No findings, no reports, no credibility, and the inventory is out of date before it is finished | Risk assessment in 30 days, first engagement in fieldwork by day 60, RCMs built one process at a time as each is audited |
| Importing a large-company plan | Twenty-two engagements copied from a former employer’s plan for a function with 1,600 hours | Plan completion of 40 percent in year one and a committee that stops believing the plan | Six to eight engagements sized from the hours table, with a reserve and a named list of what is not covered |
| Doing management’s work | The head prepares the covenant calculation, reviews journal entries, or writes the policies the function will later audit | Self-review and management responsibility impairments; the lender and external auditor stop relying on the function | Advisory work is allowed and recorded; performing controls is not; the charter says which is which |
| No validation step | Actions are closed when management emails “done” | The same finding reappears in year three, and the committee learns the issue log was fiction | Validation windows in the plan; closure by internal audit only, with evidence filed |
| Buying a GRC platform first | A tool selected in month two, configured for months three to six, populated with nothing | Year-one discretionary budget gone; the tool’s defaults become the process | Spreadsheets and a folder structure until the triggers in the toolkit table are hit |
| Softening the first report | The first engagement is rated Satisfactory with “opportunities for improvement” to avoid a fight | Every later rating is calibrated against the first; the function has taught management that ratings are negotiable | Rate what the evidence supports, print management’s disagreement, let the committee see both |
| Ignoring the acquired entity | The plan covers the parent’s processes; the plant acquired last year runs its own payroll and purchasing unaudited | Acquired entities carry the highest concentration of unreviewed control gaps in any small company | One engagement in the first-year plan for every entity on a separate system or ledger |
| No quality program until year four | Nothing written about quality until the external assessment is 12 months away | Standard 8.3 and 12.1 nonconformance, and a rescue project that consumes the year-four plan | Reviewer checklist on every index from engagement one; annual self-assessment from year one |
The pattern across the ten is that a new function fails on structure, not on audit technique. The head almost always knows how to run an engagement; what goes wrong is the reporting line, the plan size, the boundary between assurance and management’s work, and the follow-up discipline, all of which are settled in the charter and the first plan if they are settled at all. The GIAS Domain II guide covers the independence and objectivity requirements behind the first, second, and fifth rows.
Adapting the model: family-owned, PE-backed, pre-IPO, and nonprofit
Brightwater has an audit committee with independent directors and a lender who wants assurance, which is the easiest setting for a first function. The four variants below change who the function reports to, what the first year emphasizes, and what the head has to watch for. The reporting-line column is the one that matters most: where there is no audit committee, the Standards still require functional reporting to whoever performs the board’s governance role, and the charter names that person or group explicitly.
| Setting | Functional reporting line | First-year emphasis | Watch for |
|---|---|---|---|
| Family-owned, no audit committee | The owner or family council, ideally with one outside advisor added to an advisory board for the private session | Cash, payroll, vendor master, and expense controls, where a trusted long-serving employee is usually the only control; succession-related process documentation | Findings that implicate family members or a founder’s long-time deputy; the charter must state that the head reports these to the owner in writing without editing, and what happens if the owner is the subject |
| Private-equity-backed | The board’s audit committee if one exists, otherwise the board with the sponsor’s operating partner as the designated contact | The sponsor’s 100-day and value-creation plan items that touch controls: ERP consolidation, add-on integration, working capital reporting, covenant compliance; exit readiness from year two | Being redirected into value-creation projects until no assurance is done; keep the 65 percent assurance floor in the charter and report time allocation quarterly to the board, not only to the sponsor |
| Pre-IPO | An audit committee formed ahead of listing, with at least one independent member before the function starts | ICFR readiness: entity-level controls, the financial close, revenue, ITGCs, and a documented control set that management can assess under SOX 404(a) once the transition period for newly public companies ends; the internal audit function itself is a listing-readiness item | Treating the readiness project as the audit plan; the function should assess readiness work done by management or a consultant, not perform it, or it cannot audit ICFR afterward. Emerging growth companies are exempt from the 404(b) auditor attestation for up to five years, which makes internal audit’s own ICFR work the only independent view the committee gets |
| Nonprofit | The board’s audit or finance committee; where the finance committee also approves the budget, a separate audit committee of at least two independent members is worth forming before the function starts | Restricted-fund accounting, grant compliance and allowable costs, conflicts of interest and related-party transactions, executive compensation process, cybersecurity around donor data; for federal award recipients, Uniform Guidance compliance and single audit readiness | Confusing the external single audit with internal audit; a nonprofit spending more than the federal single audit threshold, which rose to one million dollars for fiscal years beginning on or after 1 October 2024, has an external compliance audit that does not test operational controls, and the board frequently believes it does |
In every variant the sourcing decision from the earlier section still holds: a single competent head with a co-source partner for specialist and surge work covers a $50 million to $300 million organization in year one, and the three-person model is justified by regulation, listing, or geography rather than by revenue alone. What changes is the first-year plan, which should be rebuilt from the setting’s own risk assessment rather than adapted from Brightwater’s, and the charter, which should name the reporting line in the terms above. The risk appetite guide is useful where the board has never articulated what level of control failure it will tolerate, which in a family-owned or PE-backed company is usually the first conversation the new head has to start.
Related guides
- How to create an internal audit charter — the full drafting guide behind the ten-clause table
- Internal audit plan template — the format Brightwater’s first-year plan uses
- Internal audit risk assessment — building the universe and scoring it in 30 days
- Internal audit co-sourcing 101 — selecting and managing the co-source partner in Model A
- GIAS Domain III: governing — the board’s obligations to the function
- GIAS Domain IV: managing — the head’s obligations, including performance measurement
- QAIP and the external quality assessment — the year-five deadline the year-one self-assessment prepares for
- Audit issue log template — the follow-up discipline that makes year two possible
- Internal audit report template — the fixed report format
- SOX 404 — for the pre-IPO variant
- Guides by role — the CAE and audit manager tracks
- All Guides — the full index
Leave a Reply