,

What to Expect During an Internal Audit: The Auditee’s Guide

The notification email arrives on a Tuesday: your depot, or your department, or the process you have run for six years, has been selected for an internal audit starting in three weeks. Most people read that email the way they would read a letter from a tax authority, and then make the same three mistakes: they tidy up, they say as little as possible, and they treat every question as an accusation. None of that helps. An internal audit is a fixed sequence of steps with known rules, the auditors’ questions are more predictable than they look, and the outcome depends far less on how well your area performs on the day than on how you handle the request list, the fieldwork questions, the closing meeting, and the written response. The people who come out of an audit well are not the ones with the cleanest operation; they are the ones who understood the process and did not fight it in the wrong places.

This guide is written for the auditee, by an auditor, and it is candid about how audits actually run. It walks through every phase from notification to final report and follow-up, with a phase table showing what you will be asked for and how long each stage takes, a 20-item document request list explaining why each item is requested, a rating explainer that says what each rating means for you, a management response template you can adapt, a six-week worked example from the auditee’s side, a time-commitment estimate by role, a do-and-don’t table, and the mistakes auditees make most often. It was rewritten in September 2026 to reflect the Global Internal Audit Standards and how audit functions work today. If you are new to the idea of being audited, the site’s older pieces on the fears people have about internal audits and why an audit is worth welcoming cover the mindset; this one covers the mechanics.

In this guide

Why your area was selected, and what that does and does not mean

Internal audit functions build an annual plan from a risk assessment, and the plan is approved by the audit committee of the board months before you hear about it. Your area was selected because something about it scores high on that assessment: it handles cash or inventory, it changed recently (a new system, a reorganization, an acquisition), it has not been audited for several years, it had findings last time that are due for follow-up, a regulator or the external auditor cares about it, or a senior executive asked for it. Selection is not an accusation. It is also not random, and it helps to know which of those reasons applies to you, because the reason shapes the scope. Ask the audit lead at the first conversation why the engagement is in the plan; a good auditor will tell you, and the answer tells you where the fieldwork will concentrate.

There is one exception. If the audit is unannounced, if the scope is narrow and specific to a person or a set of transactions, if the auditors ask you not to discuss it with your team, or if someone from legal or human resources is in the room, you are not in a routine audit; you are in an investigation, and different rules apply. Everything in this guide is about the routine kind, which is the overwhelming majority: a scheduled engagement with a written scope, a request list, a closing meeting, and a report that goes to your executive and, in summarized form, to the audit committee. Under the Global Internal Audit Standards the function is required to be independent of the areas it audits, which cuts both ways: the auditors do not report to your executive, so your executive cannot make the audit go away, and equally the auditors cannot be pressured by anyone in your chain to reach a conclusion the evidence does not support.

The phases of an internal audit, from notification to follow-up

Every internal audit, whatever the subject, runs through the same nine phases. The durations below are typical for a mid-sized engagement of 300 to 500 audit hours; a narrow compliance review compresses them and a multi-site operational audit stretches them, but the sequence does not change. The column that matters most to you is the fourth: what to prepare before each phase, because most of the auditee’s leverage is in preparation rather than in the meetings themselves.

PhaseWhat happensWhat you will be asked forWhat to prepareTypical duration
1. NotificationA memo or email from the chief audit executive to your executive and you, naming the engagement, the lead auditor, the planned dates, and the high-level objectiveA single point of contact in your area; confirmation of dates; names of key peopleRead the objective twice; name a coordinator who knows where documents live; block calendar time for the people the auditors will need2 to 4 weeks before fieldwork
2. Planning and scopingThe auditors read policies, prior reports, and system data, interview you and your executive, and write a planning memo that fixes objective, scope, risks, and approachA 60- to 90-minute interview about how the process works, what has changed, what worries you, and where the data livesA one-page description of the process as it actually runs today; a list of changes in the last 18 months; the status of any prior findings1 to 2 weeks
3. Kickoff meetingThe lead auditor presents the scope, the timeline, the request list, and the ground rules to you and your teamAttendance by the people who will be involved; agreement on the contact protocolQuestions about anything in the scope you consider out of date or wrong; the scope is easiest to correct here1 hour
4. Document requestA written list of documents, reports, and data extracts with due dates, usually through a portal or a tracked spreadsheetPolicies, procedures, organization charts, system reports, transaction listings, reconciliations, prior reviews (the next section lists 20 typical items)Send what exists, as it exists; log what does not exist rather than creating it; ask for clarification on anything ambiguous within a dayDue 1 week before fieldwork, additions throughout
5. FieldworkWalkthroughs with the people who perform the work, sample selection from your transaction data, testing of the samples against policy and control, interviews, observation, and analytics on full populationsTime with performers at their desks; retrieval of specific transactions and their support; answers to follow-up questions, usually in writingBrief your team on what a walkthrough is; set a daily 15-minute check-in with the lead auditor; keep a log of every request and every answer2 to 5 weeks
6. Preliminary findings and closing meetingThe auditors share each potential finding as it firms up, then hold a closing meeting to confirm the facts, discuss causes, and preview ratingsConfirmation or correction of facts; additional evidence where you believe a finding is wrong; initial views on cause and fixCheck every fact against your records before the meeting; bring the evidence, not the argument; separate “the fact is wrong” from “the rating is unfair”Findings shared during fieldwork; closing meeting 1 to 2 hours in the final week
7. Draft report and management responseA draft report with findings, ratings, and recommendations goes to you and your executive; you write a management response with an action, an owner, and a date for each findingA written response within a fixed window, typically 5 to 10 business daysThe response template in this guide; realistic dates; an owner who actually controls the fix1 to 2 weeks
8. Final reportThe final report, with your responses printed under each finding, goes to your executive, the CFO or CEO, the external auditor if relevant, and in summary to the audit committeeNothing further unless the committee asks a question through your executiveTell your team what was found and what will change before they hear it elsewhereWithin 2 weeks of the response
9. Follow-up and validationActions are tracked in the audit function’s issue log; when you report an action complete, the auditors test that it works before closing itStatus updates at each due date; evidence that the action is in place and operating, usually a sample of items after the changeKeep evidence as you implement; do not declare an action closed until it has run for at least one cycleFrom the action due dates until every action is validated; 3 to 18 months

Two things in the table surprise most first-time auditees. The first is that findings are shared during fieldwork rather than sprung at the end; any competent function follows a no-surprises rule, so if you reach the closing meeting and hear a finding for the first time, say so, because that is a failure on the audit side. The second is that the audit does not end with the report. Phase 9 is where the auditee’s real workload sits, and where the auditee’s reputation with the audit committee is made, because the committee sees a list of overdue actions by name every quarter. The audit function’s side of the same process is described in the site’s guide to how audit departments prepare for an engagement, which is worth reading if you want to see the planning memo and request list from the other side of the table.

The document request: 20 typical items and why each is asked for

The request list is where audits are won or lost from the auditee’s side, and the rule is simple: send what exists, exactly as it exists, and say plainly what does not exist. Auditors are trained to notice documents that were created for the audit, because a procedure written last week has no version history, no sign-off, and no staff who have seen it, and a reconciliation prepared retrospectively has no review evidence from the period. A missing document is an observation about documentation. A fabricated one is a finding about integrity, and it changes how everything else you provide is read. The list below is representative for a process audit; the third column is the part auditors rarely explain, and it tells you what each item will be used to test.

#Item requestedWhy it is asked for
1Current policies and procedures for the process, with version datesThe criteria the auditors will test against; a procedure dated 2019 for a system installed in 2023 is itself an observation
2Organization chart with names, titles, and start datesWho performs and approves what; new joiners and vacancies explain many exceptions
3Process flowchart or narrative, if one existsThe process as designed, to be compared with the process as performed in the walkthrough
4System access listing for the applications in scope, with rolesSegregation of duties: whether the same person can initiate, approve, and record
5Delegation of authority or approval matrixWhether approvals in the sample were given by people entitled to give them
6Full transaction listing for the period, exported directly from the systemThe population the sample is drawn from and the basis for analytics; auditors will ask to watch the export or run it themselves
7Month-end reconciliations for the period, with preparer and reviewer evidenceWhether the detective control operated, on time, by someone independent of the preparer
8Exception, override, and manual adjustment logsWhere the process is bypassed; overrides self-approved by the person who created the exception are a standard finding
9Key performance and volume reports used by managementWhat management actually monitors, and whether the reports come from the system or from spreadsheets
10The last internal audit report on the area and the status of its actionsRepeat findings are rated more severely; closed actions will be retested
11External auditor management letter points and regulator correspondence relevant to the areaKnown issues that the audit must address; nothing embarrasses an audit function more than missing what the external auditor already found
12Contracts and service level agreements with third parties involved in the processWhether the control relies on a vendor, and whether anyone monitors the vendor
13Training records and policy attestations for staff in scopeWhether people were told the rules they are being tested against
14Change records for the system or process in the periodWhether changes were authorized and tested; changes often explain when exceptions began
15Budget versus actual and headcount for the areaContext for cause: an area at 70 percent of planned staffing gets a different cause analysis than one fully staffed
16Customer or supplier complaint logs, credit memos, and refund listingsSymptoms of process failure that show up outside the process
17Spreadsheets used in the process, with a description of who maintains themEnd-user computing risk: a spreadsheet between two systems is an unlogged manual step
18Physical access, custody, or count records where assets are involvedWhether custody controls exist and whether counts are reconciled to the books
19Meeting minutes or management review evidence for the processWhether management review is a control (documented, questions asked, follow-up) or a briefing
20Any self-assessments, quality checks, or compliance monitoring done by your own teamEvidence that the area manages its own risk, which is weighed in the rating and the cause

Three practical rules for the list. Use the auditors’ numbering in every file name and email, because a request list with 40 items and 200 attachments becomes unmanageable in a week without it. Answer every item, including with “does not exist” or “not applicable because”, so the auditors never have to chase; the request log itself is evidence of how the area is run, and a log with twelve items open for three weeks appears in the cause analysis as “management was unable to provide”. And where an item is expensive to produce, say a custom system extract that takes IT two days, ask what the auditors need it for; a narrower extract that answers the question is usually acceptable, and the audit lead would rather have it in two days than the full version in two weeks.

Fieldwork: what auditors are actually looking for

Walkthroughs

Fieldwork usually opens with a walkthrough: an auditor picks one real transaction, sits next to the person who processed it, and follows it from start to finish on the live screen, asking at each step what could go wrong and what stops it. Two things about walkthroughs unsettle auditees. The auditor will choose the transaction, not you, and will decline the clean example you offer; that is standard and not a comment on you. And the auditor will want the person who does the work, not the manager who describes it, because the point is to find the steps that are not in the procedure, and managers do not know those steps. Tell your team that the questions “what do you do if the system rejects it” and “who else could do this if you were out” are not trick questions; they are the questions that find undocumented workarounds, and an undocumented workaround found in a walkthrough is a design observation, whereas one found in the sample is a failure. The auditor’s side of this exercise is set out in the site’s guide to process walkthroughs.

Sampling and testing

Auditors do not check everything, and they do not pick items at random from a pile. They take the population listing you provided in item 6, select a sample by a documented method, usually random or systematic with a fixed size tied to how often the control operates (25 items for a daily control is common, 40 or 60 for higher-risk areas), and test each item against the policy and the control. The number matters to you for one reason: a single exception in 25 is not dismissed as one mistake. Under standard practice, one deviation in a sample of 25 means the control cannot be relied on for the period, because the sample was sized on the assumption of zero deviations. So the response “that was a one-off” does not work, and the productive response is to help the auditor establish whether the exception was isolated (a specific, documented cause that no longer applies) or systemic (a gap that would recur). The 25/40/60 sampling guide explains the arithmetic if you want it.

Alongside samples, most functions now run analytics on the full population: every transaction in the period tested for duplicates, approvals outside the delegation matrix, activity on weekends, round amounts, entries by users who should not have access, and similar patterns. Analytics produce lists of anomalies that the auditors then ask you to explain, and a list of 300 anomalies does not mean 300 findings; most will have benign explanations, and the auditors expect that. What you owe them is an explanation per item or per category, with evidence, within the time agreed. What they owe you is a clear statement of what each analytic tested and what the threshold was, and you should ask for it.

Evidence

Auditors rank what they are shown. A system record they retrieved themselves outranks a report you exported; a document from a third party outranks one your team created; something they observed outranks something they were told. Your statement that a review happens every month is inquiry evidence, the weakest kind, and it will not support a conclusion on its own; the reviewed reconciliation with the reviewer’s initials and date, and a note of the question the reviewer raised, is inspection evidence and it will. This is why “we do check it, we just don’t write it down” produces a finding: from the auditor’s chair, a control with no evidence of operation cannot be distinguished from a control that did not operate. The site’s guide to audit evidence sets out the full hierarchy, and reading it before fieldwork is the single most useful preparation an auditee can do, because it tells you which of your documents will carry weight and which will not.

When a document the auditors ask for does not exist, say so in writing the same day. When you find during fieldwork that something is wrong in your area that the auditors have not yet found, tell them. Self-identified issues are rated with the cause taken into account, are usually reported as management-identified, and change the tone of the whole report; issues the auditors find after you knew about them do the opposite. When the auditors ask a question you do not know the answer to, say you do not know and find out; a guess that turns out to be wrong is remembered longer than an honest gap.

How findings and reports are rated, and what each rating means for you

Every finding carries a rating, and most functions also rate the report as a whole. The scales vary by organization (High/Medium/Low, Critical through Low, or numbered), but the logic underneath is the same everywhere: a rating is a judgment about the likelihood and impact of what could go wrong given the gap found, not about whether anything did go wrong, and not about you. A High finding in an area with a good manager is still High. Ask for the function’s rating definitions at the kickoff meeting; they are written down, they are usually approved by the audit committee, and knowing them lets you have a rating discussion about criteria rather than about feelings. The site’s guide to finding severity ratings explains how auditors build the scale; the table below explains what each level means from where you sit.

RatingWhat the auditors mean by itWho sees itWhat it means for you
High (or Critical)A control is missing or not working in a way that could cause a material loss, misstatement, regulatory breach, or safety event, and the exposure is currentThe full audit committee, by name of the finding; often the CEO and CFO before the report is final; the external auditor if financialAn action plan with an owner at executive level and a date measured in weeks, not quarters; interim measures expected immediately; status reported to the committee every quarter until validated
MediumA control weakness that could cause a meaningful but not material loss, or a High-type gap that is partly mitigated by other controlsThe audit committee in summary; your executive in fullAn action plan with a date within one to two quarters; overdue Medium actions are named to the committee
LowA process or documentation improvement with limited exposure, or an isolated exception with an identified causeYour executive; the committee sees only the countAn action with a date, tracked in the issue log, but rarely escalated; the volume of Lows across audits is what the committee notices
Observation or advisory pointSomething worth knowing that is not a control gap: an efficiency point, a risk the business has accepted, good practice worth spreadingUsually in a separate section or a management letter; not tracked as an actionNothing required; the useful ones are worth acting on because the next audit will ask
Report rating: Satisfactory (or Effective)Controls are designed and operating; findings, if any, are Low or isolatedCommittee sees the rating in the plan status tableThe next audit of the area will be lighter and later
Report rating: Needs Improvement (or Partially Effective)Controls generally in place but with one or more Medium findings, or several Lows in a patternCommittee sees the rating and the Medium findingsFollow-up within two quarters; your executive will be asked about progress
Report rating: Unsatisfactory (or Ineffective)One or more High findings, or a pattern of Mediums showing the control environment does not workCommittee discusses the report itself; the CEO is briefed; the area may be re-audited within a yearExecutive-level action plan, monthly status reporting, a validation audit, and in most organizations a conversation about the area’s leadership, which is why the facts in the report have to be right

Ratings also compound. A finding that was raised in the last audit and is found again is rated at least one level higher than it would be on its own, because the cause has moved from a control gap to management not acting on a known gap. This is the strongest practical argument for taking the follow-up phase seriously: the cheapest High finding to avoid is the repeat.

The closing meeting and the draft report: how to disagree productively

The closing meeting is where the auditors present each finding with its condition (what they found), criteria (what should have been the case), cause, consequence, and proposed action, and ask you to confirm the facts. Everything you say in that meeting is more effective if it is sorted into three categories before you walk in. The first is facts: the sample item was approved, and here is the approval; the reconciliation was performed, and here is the file. Factual corrections with evidence are accepted immediately by any competent auditor, and a finding built on a wrong fact is withdrawn, so this is where your preparation goes. The second is cause: the finding is accurate, but the reason given is wrong, and the reason matters because the action plan follows from it. The third is rating: the facts and cause are accepted, but you believe the exposure is lower than the rating implies because of a mitigating control the auditors have not weighed. Each category is argued differently, and mixing them, which is what happens when an auditee argues that a finding is “unfair”, produces a meeting in which nothing is resolved.

Type of disagreementWhat worksWhat does not workLikely outcome
The fact is wrongProduce the document that shows it; identify the specific sample item and what the auditors missed“That’s not how it works” without evidence; asking the performer to remember it differentlyFinding corrected or withdrawn; auditors will also check whether the same error affects other items
The fact is right but not representativeShow the population data: the exception rate across the period, with the extract the auditors can verify“That was a one-off”; offering a hand-picked set of clean examplesRating may drop if the data supports isolation; the auditors may extend the sample instead
The cause is wrongExplain the actual cause with evidence: staffing at the time, a system change, a policy that was itself unclearNaming an individual; blaming another department without involving themCause revised; the action plan changes to match, which is usually to your advantage
A mitigating control was not consideredDescribe the control, show evidence it operated in the period, and show what it would have caughtDescribing a control that exists in the policy but has no operating evidenceRating reduced if the control is real and evidenced; a new finding if it is not
The rating is too highArgue from the function’s own rating definitions: which criterion the finding meets and which it does notComparing to what another department got; appealing to your executive to lean on the audit leadThe audit lead reconsiders against the definitions; the chief audit executive decides if it stays disputed
The recommendation is impracticalPropose an alternative action that addresses the same risk, with the reason the original does not work hereRejecting the recommendation without an alternative; accepting it with no intention of doing itRecommendations are the auditors’ suggestion; the action is yours, and an alternative that closes the risk is normally accepted
Still disagree after all of thatSay so in the management response, in one paragraph, with the reason; it is printed in the report next to the findingRefusing to respond; escalating to the CEO to have the finding removedThe finding stands with your disagreement visible; the committee decides whose view it accepts, and in a well-run company that is a fair hearing

Two conventions protect you in this phase. Draft reports are drafts: the facts are open to correction until the report is final, and a good audit lead would rather correct a finding at the closing meeting than issue a wrong one. And disagreement is legitimate: the Global Internal Audit Standards require the final report to include management’s response, including a response that management has accepted the risk or disagrees with the finding, and the chief audit executive is required to tell the board when management has accepted a risk the auditors consider too high. Disagreement recorded through that route is professional. Disagreement pursued by asking your executive to have the finding removed is remembered by every auditor in the function for years, and it does not work, because the reporting line does not run through your executive.

Writing the management response

The management response is printed under each finding in the final report, unedited, and it is the only part of the document you write. It is read by the audit committee as a statement about the area’s management, so it should be short, specific, and honest about timing. A response has five parts: whether you agree with the finding (or which part you disagree with), the action you will take, the person accountable for it by name and title, the date it will be complete, and any interim measure in place until then. The template below is the one most functions accept without edits; adapt the wording, not the structure.

Management response to Finding 2 (Settlement reconciliations not independent). Management agrees with the finding. Depot settlement reconciliations have been prepared and approved by the depot manager since the route accounting module was implemented, and no independent review has been in place.

Action. Regional finance will assume review of daily settlement reconciliations for all depots in the region, with the reviewer’s approval recorded in the ERP workflow. The depot manager will continue to prepare the reconciliation and will no longer hold approval rights in the module.

Owner. Regional Finance Manager, Central Region.

Target date. 31 January 2027 for the workflow change; 28 February 2027 for one full month of independent review completed.

Interim measure. From 1 December 2026 the regional finance manager will review a weekly sample of ten settlement reconciliations per depot and record the review by email until the workflow change is live.

The two most common ways a response goes wrong are the date and the owner. A date chosen to satisfy the meeting rather than the work becomes an overdue action reported to the committee by name, and one extension is tolerated where two are not; ask for the time the fix will actually take, and if that is nine months, say nine months and explain why. An owner who does not control the fix (the depot manager for a change that IT has to make) means the action stalls and the auditors come back to the depot manager. Name the person who can make it happen, even if that is someone senior to you, and get their agreement before the response is submitted. Where you disagree with a finding, the response says so in one paragraph with the reason and, ideally, the risk you are accepting and who is accepting it; a disagreement that reads as reasoned is treated as a legitimate management position, and one that reads as annoyed is treated as evidence for the finding. The site’s internal audit report template shows where the response sits in the finished report.

Worked example: six weeks at a MidState Beverage depot

MidState Beverage is a three-state beverage distributor with twelve depots and 300 delivery routes, where about 4,200 smaller customers pay drivers in cash and checks, roughly $31 million a year. Its FY27 audit plan opened with a route cash handling audit across all twelve depots, prompted by a Dayton driver who had diverted $18,400 over five months in FY26 before a customer complaint exposed it. Renee Okafor manages the Fort Wayne depot, 26 routes, and had never been audited. The timeline below is her six weeks, and it is typical of what a site manager experiences inside a larger engagement: the audit team of six spent the equivalent of about 40 hours on her depot, spread across a three-day visit and remote follow-up.

WeekWhat happenedWhat the depot was asked forDepot hoursWhat Okafor did right, and wrong
Week 0 (three weeks before fieldwork)Notification memo from the chief audit executive to the operations VP and all twelve depot managers; kickoff call for all depotsA depot contact; the depot’s settlement procedure; names of settlement clerks and route supervisors3Right: named her senior settlement clerk as contact and read the FY26 Dayton report. Wrong: rewrote the depot’s settlement procedure the week before, which the auditors spotted from the file date and asked about
Week 1Planning interviews by phone; request list issued with 22 items, due in five business daysTwelve months of settlement records, variance override log, deposit slips and bank confirmations, handheld sync error reports, customer statement mailing list, access listing for the route module14Right: answered all 22 items, including “no report exists” for the sync errors, which became a finding about monitoring rather than about her depot. Wrong: sent the deposit listings from her spreadsheet rather than from the ERP, which prompted the question of why a spreadsheet existed at all
Week 2Analytics run centrally on all 37,400 settlements company-wide; Fort Wayne flagged for 118 self-approved variance overridesExplanations for a list of 30 override examples; the delegation of authority for overrides9Right: explained the overrides by category (short-pays by four large customers accounted for 71) with the customer correspondence attached. Wrong: initially replied that “everyone does it that way”, which is true and is also the finding
Week 3Three-day site visit: walkthrough of two routes’ settlement from handheld to deposit, observation of the afternoon cash count, sample testing of 25 settlements, interviews with three drivers and both clerksTime with clerks at their screens; retrieval of 25 settlement packages; access to the cash room during count22Right: briefed the clerks that the auditors would ask what they do when the handheld fails to sync, and let them answer honestly. Wrong: sat in on the driver interviews, which the audit lead asked her to leave
Week 4Preliminary findings shared: settlement reconciliations reviewed by Okafor herself (not independent); deposit listing re-keyed in a spreadsheet; 94 customers on Fort Wayne routes receiving no monthly statementConfirmation of facts; the reason the statement list was incomplete6Right: checked all three against her records and corrected one fact (the statement count was 88, not 94, with six accounts closed); the correction was accepted. Wrong: argued the independence finding was unfair because “there is no one else here to review it”, which is a cause, and a good one, but not a reason the finding is wrong
Week 5Closing meeting for the Central Region depots, two hours; ratings previewed; draft report issued three days later with five findings across the company, three of which named Fort Wayne among the affected depotsManagement responses within ten business days, coordinated by the operations VP8Right: proposed regional finance review as the fix for independence, with the workflow change and interim sample review shown in the template above; the proposal was adopted for all nine affected depots. Wrong: nothing; this was her best week
Week 6Final report FY27-01 issued, rated Unsatisfactory, five findings and eleven actions, summary to the audit committeeNothing further; a briefing of depot staff by Okafor before the report circulated2Right: told her team the depot’s findings and the fixes the same day, before the regional rumor mill did it for her
Weeks 7 to 30Actions implemented; validation testing by internal audit in the Q3 window: 25 settlement reconciliations sampled after the workflow change, spreadsheet retirement confirmed, statement mailing list retestedMonthly status updates; evidence of each change; access for the validation sample15Right: kept the evidence as she went, so validation took the auditors half a day. The three Fort Wayne actions were validated closed in the first window, which was noted by name in the committee pack

The report was unsatisfactory, three of five findings touched Fort Wayne, and the depot manager came out of it with a stronger position than she went in, because the committee pack showed her depot’s actions validated closed while others were still open. That is the pattern to aim for: the rating is about the control environment, most of which is designed above the depot; the response and the follow-up are about you.

What it will cost you in time

The honest estimate for a department that is the sole subject of a 400-hour engagement is 80 to 120 hours of the auditee’s time across the phases, concentrated in the request list and fieldwork weeks, with the manager carrying about a third of it. The table below is for that case; a site inside a multi-site audit, like the depot above, carries roughly half. Auditees consistently underestimate the follow-up phase and overestimate fieldwork, and the manager’s largest single time cost is usually the management response, which is written in a hurry and rewritten twice.

RolePlanning and request listFieldworkClosing, response, reportFollow-up and validationTotal hours
Department manager81212840
Audit coordinator (the named contact)16164642
Process performers (combined)4162426
Your executive21429
IT or finance support for extracts640212
Total36492222129

Do and don’t: the auditee’s rules

DoDon’tWhy
Ask why the area is in the plan and what the auditors are most concerned aboutAssume the audit is about you personallyThe reason for selection tells you where fieldwork will concentrate
Send documents as they exist, with their real datesCreate, backdate, or polish documents for the auditFabrication is the one thing that turns a control finding into an integrity finding
Say in writing what does not existLeave requests open and hope they are forgottenOpen requests become “management was unable to provide” in the cause analysis
Let performers answer walkthrough questions themselvesAnswer for your staff or sit in to manage what they sayAuditors read intervention as concealment, and they will ask the same questions again without you
Tell the auditors about problems you already know ofWait to see if they find themSelf-identified issues are rated and reported differently from issues found by audit
Correct facts with evidence, at onceArgue that a finding is unfairFacts get changed; fairness does not
Give real dates and real owners in the responsePromise what the meeting wants to hearOverdue actions are reported to the audit committee by name
Keep evidence as you implement actionsDeclare an action closed and look for evidence laterValidation tests operation over a period, not a declaration
Brief your team before and afterLet them learn about the audit from the auditors, or about the findings from the rumor millUnbriefed staff are anxious in walkthroughs and defensive about findings
Ask what an analytic tested and what its threshold wasTry to explain 300 anomalies one by one without knowing what produced themMost anomaly lists resolve by category once the test is understood

Common auditee mistakes

FailureWhat it looks likeWhy it mattersFix
The pre-audit clean-upProcedures rewritten, reconciliations completed, and files reorganized in the two weeks before fieldworkFile dates give it away; the auditors test the period before the clean-up anyway, and the clean-up itself shows the controls were not operatingPrepare by understanding your process and gathering what exists; fix what you find and tell the auditors you fixed it
Minimal answers“Yes”, “no”, and “that’s not my area” in interviews; documents sent without contextAuditors fill silence with testing; an unexplained exception becomes a finding that an explained one would notAnswer the question asked, then add the context that explains it; volunteer the cause
Over-explainingA history of the department in response to a question about one transactionWastes the hours you are paying for in disruption, and buries the answerAnswer, offer the detail, let the auditor ask for it
The manager as gatekeeperEvery request routed through the manager; performers told not to speak to auditors directlySlows everything and reads as control of the narrative; walkthroughs with the manager only produce a finding that the walk could not be completedA coordinator for logistics; direct access to performers for content
Treating the closing meeting as a negotiationTrading acceptance of one finding for the removal of another; bargaining on ratingsRatings are set against written definitions, not traded; the attempt goes in the auditors’ notesArgue facts, cause, and criteria; record disagreement in the response
The optimistic responseEvery action due in 30 days with the manager as ownerHalf will be overdue, and overdue actions are the committee’s main view of your areaDates from the people doing the work; owners who control the fix
Silence between report and due dateNo status updates until the auditors askThe issue log shows no progress; the committee assumes noneMonthly one-line updates to the audit function whether or not they ask
Closing on paperAction marked complete when the memo is issued, before the new process has runValidation fails, the action reopens, and the repeat finding is rated higherClose after at least one cycle, with evidence filed
Escalating to remove a findingThe executive calls the chief audit executive or the CEO to have a finding droppedThe reporting line does not run through your executive; the call is reported to the committee under the independence confirmationDisagree in the response with reasons; let the committee decide
Forgetting the next auditActions closed, lessons not kept, the same gaps rebuilt as staff turn overThe next audit starts from the last report, and repeats rate higherKeep the report, build the fixes into the procedure and the training, and run your own annual check against the last findings

After the audit: follow-up, validation, and the next one

Once the report is final, every action goes into the audit function’s issue log with its owner, due date, and rating, and the log is reported to the audit committee each quarter with overdue items by name. The site’s audit issue log template shows the fields that will be tracked, and it is worth keeping your own copy of your actions in the same format. When you report an action complete, the auditors do not take your word for it; they validate, which for a control change usually means sampling items processed after the change to confirm the control operated, and for a documentation change means confirming the document exists, was approved, and was communicated. The auditors’ side of that process is set out in the guide to issue validation, and the practical implication for you is that an action is not ready to close until it has run for at least one full cycle with evidence.

Extensions are possible and should be requested before the due date, in writing, with the reason and the new date; one extension on an action is routine, a second is reported, and a third usually brings the chief audit executive to your executive. Where circumstances have changed so that the original action no longer makes sense, propose a different action that addresses the same risk rather than letting the original go quietly overdue. And where the business decides that it will accept the risk rather than fix it, say so through your executive; risk acceptance is a legitimate management decision that the Standards require to be documented and, above a threshold, reported to the board, and it closes the action honestly.

The next audit of your area will begin with the last report. The auditors will retest every closed action, rate repeats higher, and read your area’s history in the issue log before they meet you. The managers who find audits easy are the ones who treat the last report as the specification for their own annual check: they walk their own process once a year with the last findings in hand, fix what has drifted, and tell the audit function what they found. That habit, more than anything on the day, is what turns a rating from Needs Improvement to Satisfactory over two cycles. The site’s Start Here page collects the guides written for auditees and for people new to the audit process.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading