,

Sawyer’s Guide for Internal Auditors: Summary, Editions and Free Study Notes

Sawyer’s is the book every internal auditor is told to read and almost nobody reads cover to cover. It has been in print since 1973, it is on its seventh edition, it has changed title twice, and it has gone from one author to ten. The current edition, Sawyer’s Internal Auditing: Enhancing and Protecting Organizational Value (Internal Audit Foundation, 2019), is a single 400-page volume that replaced the three-volume Sawyer’s Guide for Internal Auditors of 2012, which is the title most people still search for. This guide explains what is in it, which edition you are actually looking at, how its ideas map to the 2024 Global Internal Audit Standards it predates, who should read which half, and where it is weak.

Free download: Sawyer’s Internal Auditing: Summary and Study Notes (PDF, four pages). These are our own notes: an edition guide, the twelve ideas that survive every edition, the crosswalk to the 2024 Standards, a reading plan by role and twenty self-check questions. They are not the book and do not reproduce its text; the section below explains why no free PDF of the book itself exists and where to buy it.

Two things make this book worth the effort that its length demands. First, the argument at its core, that internal auditing is a management-oriented discipline whose product is better decisions rather than checked transactions, is the argument the Global Internal Audit Standards guide finally wrote into mandatory guidance in 2024, half a century after Lawrence Sawyer first made it. Second, the seventh edition is organised the way a chief audit executive’s year is organised: the first half is about building and positioning a function, the second about delivering its work. Read in that order, with the crosswalk beside it, it is the closest thing the profession has to a textbook on running the function rather than passing the exam.

This guide was rewritten in September 2026 from a shorter review published in February 2025, and extended on September 21, 2026 with a timeline of Lawrence Sawyer’s life and legacy, the twelve ideas matched to worked engagements, a reading list by theme, the chief audit executive’s sixteen questions, a vocabulary table and five further reader questions. Edition facts (dates, formats, page counts, ISBNs, contributing authors) were checked against the Internal Audit Foundation’s listing and the book’s publication records; summaries of the book’s ideas are our own paraphrases, and the crosswalk to the 2024 Standards is our analysis, not the publisher’s.

In this guide

Is there a Sawyer’s Guide PDF? What exists, what does not, and what our notes cover

Most of the people who arrive at this page searched for the book’s title with the word PDF after it, so the honest answer comes first. There is no free, authorised PDF of any edition of Sawyer’s. The 7th edition is sold by the Internal Audit Foundation in print and as an eBook, and the eBook is delivered through VitalSource’s Bookshelf platform in a reflowable format that can be read offline, searched and annotated, but not downloaded as a plain PDF. The files that circulate on document-sharing sites under names like “Sawyer’s Internal Auditing 7th edition PDF” are unauthorised uploads of a copyrighted book; downloading them is a copyright problem for you and a revenue problem for the Foundation that funds the profession’s research, and there is no way to know which edition a file is, or how complete, until you open it.

What you can legitimately get, and what it costs, is set out below. IIA members pay member pricing at the IIA Bookstore; the VitalSource eBook is sold as time-limited access or lifetime access, and the prices move, so check the current figures before deciding. Used copies of the 5th and 6th editions are widely available and cheap, and for most of the book’s ideas they are not out of date; what is out of date in every edition, including the 7th, is the numbering of the standards it cites, which is why the crosswalk later in this guide exists.

What you wantWhere it existsWhat you get
The 7th edition in printIIA Bookstore (Internal Audit Foundation), major booksellersHardcover, about 400 pages, ISBN 978-1-63454-052-0; member pricing at the IIA store
The 7th edition as an eBookIIA Bookstore and VitalSource (ISBN 978-1-63454-053-7)Reflowable eTextbook with search, highlighting, notes and offline reading inside the Bookshelf app; time-limited or lifetime access
A free PDF of the bookDoes not exist from any authorised sourceFiles on sharing sites are unauthorised copies, often of older editions
Earlier editionsUsed-book market (5th edition 2003, 6th edition three-volume set 2012)Inexpensive; ideas largely current, standards numbering not
A summary you can keepOur study notes PDF, linked at the top of this guideFour pages: edition guide, twelve core ideas, crosswalk to the 2024 Standards, reading plan by role, twenty self-check questions; original text, no excerpts from the book

The study notes exist because the two things readers most often want from the book, its structure and its argument, fit on four pages, and because a summary is a legitimate thing to give away where the book is not. Use them to decide whether to buy, to brief a new hire before the book arrives, or to revise after reading. They will not get anyone through the CIA exam, and neither will the book; the CIA exam requirements guide explains what the exam actually tests.

Which Sawyer’s is which: every edition from 1973 to the 7th

The title confusion is real, and it matters when you are buying, citing or searching. Lawrence B. Sawyer published the first edition in 1973 as The Practice of Modern Internal Auditing. The editions that followed under his name and then under co-authors Mortimer Dittenhofer and James Scheiner carried the title Sawyer’s Internal Auditing. The 6th edition of 2012 was reissued as a three-volume set and marketed as Sawyer’s Guide for Internal Auditors, the name that stuck in search engines and on office shelves. The 7th edition of 2019 went back to Sawyer’s Internal Auditing, added the subtitle Enhancing and Protecting Organizational Value, and returned to a single volume. If a colleague says “the Sawyer’s guide”, they may mean any of the last three.

EditionYearTitle and formWhat to know
1st1973The Practice of Modern Internal Auditing, Lawrence B. Sawyer (The IIA)The original case for management-oriented, operational auditing at a time when most internal audit work was financial checking.
5th2003Sawyer’s Internal Auditing: The Practice of Modern Internal Auditing (Sawyer, Dittenhofer, Scheiner)One very large volume; the edition many audit libraries still hold.
6th2012Sawyer’s Guide for Internal Auditors, three-volume set (The IIA), about 780 pages in totalEach volume carries its own index and glossary; the set separates the essentials of the profession, audit processes and methodologies, and governance, risk management and compliance topics. Written against the pre-2013 IPPF.
7th2019Sawyer’s Internal Auditing: Enhancing and Protecting Organizational Value (Internal Audit Foundation), single volume, about 400 pagesSixteen chapters in two parts, ten contributing authors, print and eBook. Written against the 2017 IPPF; it predates the Global Internal Audit Standards of 2024.

Which one to buy is a shorter question than it looks. For anyone whose job is running or joining a function today, the 7th edition is the one, because it is written for the modern shape of the profession (advisory alongside assurance, risk-based plans, technology, the audit committee relationship) and because it is the only one still sold new. The 6th edition’s three volumes are more encyclopaedic on techniques, and a used set is a reasonable companion for the price of a lunch, but its standards references are two frameworks out of date. The 5th edition is a historical document now; read it to see what Sawyer himself sounded like.

Who Lawrence Sawyer was and what he changed

Lawrence B. Sawyer (1911 to 2002) spent his career inside internal audit at a time when the function was, in most organisations, a unit of the controller’s department that re-checked the accounting. His contribution was to argue, in print and at length, that the job was something else: an appraisal of how well the organisation’s operations were managed, done for management and the board, judged by whether it improved anything. The profession now calls this management-oriented auditing, or operational auditing, and treats it as obvious. In 1973 it was not obvious, and the first edition of the book was the argument for it.

Three of Sawyer’s positions explain why the book still reads as current. He insisted that the auditor’s frame of reference is the manager’s objective, not the ledger: a control matters because of what it protects, and an audit that reports a control weakness without saying what objective is at risk has not finished. He described the relationship he wanted between auditor and auditee as a problem-solving partnership, in which independence is protected by evidence and objectivity rather than by keeping the auditee at arm’s length, which is why later editions spend so much time on how to interview, how to negotiate a finding and how to write for a reader who would rather not be reading. And he treated the audit report as an act of persuasion aimed at a busy executive, a stance that our audit report writing guide still has to argue for today.

What he did not anticipate, because nobody did, was the shape of the modern function: the audit committee as the function’s primary principal, the rise of risk management as a separate discipline the function relies on, advisory work as a formal service line, and technology as both subject and tool. The later editions, and especially the 7th, are the profession’s attempt to keep Sawyer’s stance while rebuilding the book around that shape, which is also why the 7th edition has ten authors: no single practitioner now covers the whole field.

Lawrence Sawyer’s life and legacy: a timeline

The section above gives Sawyer’s argument; this one gives the record, because readers citing the book in a dissertation or a training deck keep asking for dates that are surprisingly hard to find in one place. Lawrence B. Sawyer was born on April 13, 1911 and died on September 18, 2002 in Camarillo, California, at 91. He held the CIA, the CPA and a law degree, spent his working life inside corporate internal audit, taught operational auditing at UCLA, and wrote, by the IIA’s count, nineteen books and twenty-six articles and delivered 186 seminars for the Institute. The profession’s name for him, the Father of Modern Internal Auditing, was earned by the first edition of this book and by the thirty years of argument that followed it.

YearEventWhy it matters to a reader of the book
1911Born, April 13He belonged to the generation that built corporate internal audit inside the controller’s function, which is the world the first edition argues against
1941The Institute of Internal Auditors founded in New YorkThe professional body Sawyer would spend his later career writing for; the IIA published every edition of the book
1973The Practice of Modern Internal Auditing published by the IIAThe first edition: the case that internal auditing is an appraisal of how well operations are managed, not a re-check of the accounting
1970s to 1990sSecond through fourth editions; teaching at UCLA; four Thurston Awards for articles in the IIA’s magazine; the Bradford Cadmus Memorial AwardThe Thurston Award recognizes the year’s outstanding article in Internal Auditor; four of them is a measure of how much of the profession’s early literature he wrote himself
2000The Larry B. Sawyer Student Scholarship established through the IIA, funded by his familyStill awarded, at the time of writing, to students in internal audit programs, with an award to the student and a matching contribution to the school; the IIA’s academic relations pages carry the current amounts and the spring deadline
2002Died, September 18, Camarillo, CaliforniaThe IIA named him the first recipient of its Lifetime Achievement Award, and the library at its global headquarters carries his name
2003Fifth edition, with Mortimer Dittenhofer and James ScheinerThe last edition to carry his voice throughout; the co-authors kept the structure and updated the standards
2012Sixth edition, the three-volume Sawyer’s Guide for Internal AuditorsThe title that dominates search results, and the edition most audit libraries still hold
2019Seventh edition, Sawyer’s Internal Auditing: Enhancing and Protecting Organizational Value, ten contributing authorsThe current edition, rebuilt around the modern function; the subject of the rest of this guide
2024The Global Internal Audit Standards published, effective January 2025The framework that finally wrote Sawyer’s management-oriented stance into mandatory guidance, and that the seventh edition predates

Two things in the timeline are worth pausing on. The awards are for writing, not for office: the profession honored Sawyer as its author, and the book is the reason the honors exist rather than a by-product of them. And the gap between the first edition and the Standards that adopted its stance is fifty-one years, which is the most useful fact on this page for anyone who wonders whether arguing for a better way of doing the job is worth the time. The history of the IIA’s standards covers the frameworks that came and went in between, and the analysis of the 2024 update covers what finally changed.

What is inside the 7th edition: two parts, sixteen chapters, ten authors

The 7th edition is organised as a business book about a business unit. Its first eight chapters are about establishing an internal audit function and positioning it: what the function is for, whom it serves, how it is authorised and governed, what it should cover, what people, budget and tools it needs, how it plans, and how it measures and improves its own quality. Its second eight chapters are about delivering the function’s services and products: building the risk-based plan, scoping and planning engagements, gathering and evaluating evidence, developing findings and conclusions, communicating results, following up, and providing advisory as well as assurance work. The publisher’s own framing is that the book helps a chief audit executive ask the right questions about the value, services and products to offer in their particular environment, and that is an accurate description of its tone: it is a book of questions and frameworks more than a book of procedures.

The ten contributing authors are practitioners and educators drawn from across the profession: Dan Clayton, Cris Riddle, Bruce Turner, Farah George Araj, Han Beumer, Angelina Chin, Andrew Cox, Jenitha John, Michael H. Levy and Jason Mefford. The edited-volume structure is a strength for coverage and a weakness for voice, which the critique section below returns to. The table summarises what each half is for and who should read it.

PartChaptersThe questions it answersWho should read it first
Part one: establishing and positioning the function1 to 8What is the function for and what value does it deliver? Who does it answer to and how is it authorised? What should it cover? What people, budget and technology does it need? How does it plan strategically, and how does it know it is any good?Chief audit executives, audit managers moving into leadership, audit committee members, and anyone building a function from nothing (see the guide to setting up an internal audit function in a small company)
Part two: delivering services and products9 to 16How is a risk-based plan built? How is an engagement scoped and planned? What counts as evidence, and how is it evaluated? How are findings developed, rated and communicated? How is action confirmed? How does advisory work differ from assurance?New and mid-career auditors, seniors and managers supervising engagements, and anyone whose function is rewriting its methodology

Two things the book does well that summaries miss. It keeps returning to the idea that the function has customers and products, and it makes the reader say what those are; a function that cannot name its products in a sentence usually cannot name its value either, and the 2024 Standards now require a strategy and performance measures that make the same demand. And it treats the advisory side of the work as a service with its own rules rather than as assurance with the report softened, which is where many functions still go wrong.

The twelve ideas that survive every edition

Strip the editions down to what they agree on and twelve ideas remain. They are paraphrased here in our words; each is followed by where it lives in current practice.

1. Auditing is management-oriented. The auditor evaluates whether operations achieve management’s objectives at acceptable cost and risk. A control is good if it does that; it is not good because it exists, is documented, or was there last year. In practice this is the difference between a finding that says a reconciliation was late and one that says what the late reconciliation left exposed.

2. The problem-solving partnership. The auditor and the auditee are on the same side of the problem. Independence is protected by objectivity, evidence and reporting lines, not by hostility or distance. The 2024 Standards make the same point from the other direction: Standard 2.2 lists the safeguards that protect objectivity, and none of them is unfriendliness.

3. Look beyond financial correctness. Efficiency, effectiveness and economy of operations are audit subjects. Sawyer’s original argument, and still the reason operational audits exist.

4. Risk decides the plan. Coverage follows risk to objectives. A rotation that audits every unit on a cycle regardless of risk is a habit, not a plan, and the audit plan guide shows what the alternative looks like in a real function.

5. Evidence has standards. Sufficient, reliable, relevant and useful, gathered by procedures chosen for the question being asked. The book’s treatment is the ancestor of Standard 14.1, and it is still the clearest explanation of why an interview note is not evidence of a control operating.

6. Findings have anatomy. Criteria, condition, cause, effect, recommendation. The five-element finding in most methodologies today, and in the 5 Cs of audit findings guide, is Sawyer’s structure.

7. Cause is the auditor’s real product. A condition without a cause is an observation; the recommendation that fixes the cause is what management is paying for. Functions that skip root cause produce findings that recur, which is the subject of the root cause analysis guide.

8. Reports persuade or fail. Lead with what matters, write for the executive, prove the finding, make the action plain. The book’s reporting chapters are still the best argument against the twelve-page report with the conclusion on page nine.

9. Follow-up closes the loop. An unimplemented recommendation is a failure of the audit, not only of management. Standard 15.2 now requires the function to confirm implementation rather than record management’s word for it.

10. The function is a business. It has customers, products, a cost, a quality programme and a strategy. The 7th edition’s subtitle, enhancing and protecting organizational value, is this idea stated as the mission, and Standards 9.2 and 12.2 are it stated as requirements.

11. Standards are the floor, not the ceiling. Conformance is the minimum condition for credibility. Value comes from what the function does above the floor, and a function that reports only its conformance has confused the licence with the work.

12. Judgment cannot be outsourced to a checklist. Checklists structure the work; they do not replace the obligation to understand the business and think. Sawyer wrote this when audit software was in its infancy, and it is truer now than it was then.

The twelve ideas at work: where each shows up in the engagements on this site

Sawyer’s ideas are easy to nod at and hard to see, so here each of the twelve is matched to a moment in the worked engagements written up across this site, where an auditor at MidState Beverage, Brightwater Foods, Pennine Foods or Lakeshore Bank did the thing the idea describes, or paid for not doing it. The engagements are fictional and structurally faithful, like the book’s own cases; the links go to the guides that carry them in full.

#Sawyer’s ideaWhere it shows upRead it in
1Auditing is management-orientedThe Brightwater fixed asset audit’s largest finding was an idle bottling line carried at $1.4 million with no impairment review: not a register error, but a number the board was relying on that no longer described anything; the objective, not the ledger, set the findingFixed assets
2The problem-solving partnershipThe Lakeshore reconciliation audit found a reviewer approving 210 reconciliations in forty minutes and wrote the finding about the program, because the program had no standard for what a review was; the criteria were agreed with the Controller at planning and the rating survived the exit meeting without an argumentAccount reconciliations as a program
3Look beyond financial correctnessThe Pennine close audit rated days-to-close, a metric with no ledger effect, because the board was using it to run the function; economy and effectiveness are audit subjectsThe financial close
4Risk decides the planMidState’s FY28 plan put the purchasing card audit after the travel and expense audit because the earlier engagement had shown the acquired entities claiming in cash; coverage followed the risk the last audit foundPurchasing cards and the audit risk assessment
5Evidence has standardsThe MidState payroll audit refused the provider’s own register as evidence of existence and joined the master to HR status, badge activity and bank data instead; sufficiency was decided at planningAudit evidence and payroll
6Findings have anatomyFive findings dissected element by element, including the Lakeshore review and the MidState split transactions, each rebuilt from a version nobody would have acted onThe 5 C’s of audit findings
7Cause is the auditor’s real productThe split-transaction finding’s cause was a vendor absent from the purchasing system, so the fix was a blanket purchase order rather than training; the same finding with “cardholder error” as its cause would have recurredWriting cause statements and root cause analysis
8Reports persuade or failThe purchasing card report derived its rating in the open, in one sentence, so the committee member who read only the conclusion paragraph knew why it was Needs Improvement and not UnsatisfactoryModel report examples and report anatomy
9Follow-up closes the loopThe follow-up on the accounts payable report closed one finding on four kinds of evidence and left the other open with 94 bank changes still unverified, at its original ratingThe life of a finding and issue validation
10The function is a businessMidState’s six-person function wrote a strategy and performance measures during its ninety-day quality build, and rated itself partially conformant on 12.2 in the first self-assessmentThe QAIP playbook and the self-assessment template
11Standards are the floor, not the ceilingA function that reports its conformance to the audit committee once a year and its value, recoveries, decisions changed and risks surfaced, every quarter has understood the distinction; the second report is the one the committee reads, and the presentation template is built for itThe audit committee presentation
12Judgment cannot be outsourced to a checklistThe fraud red flags library pairs every flag with a confirming test and a scoring method precisely because a flag is a probability shift, not a finding; the checklist tells you where to look, the auditor decides what was foundFraud red flags and the severity matrix

Read the table as a test of your own function rather than of the book: for each idea, name the last engagement where it showed up in your work, in a sentence with a number in it. Ideas 7 and 9 are the ones most functions cannot answer, and they are the two whose absence shows up in the audit committee’s least favorite report, the aging of open issues.

How Sawyer’s maps to the 2024 Global Internal Audit Standards

The 7th edition cites the 2017 International Standards for the Professional Practice of Internal Auditing. The Global Internal Audit Standards were published in January 2024 and took effect in January 2025, so every standard number in the book now points somewhere else, and a few of the book’s assumptions (that the board’s responsibilities are implied rather than stated, that a strategy is good practice rather than a requirement) have been overtaken. The ideas transfer cleanly; the numbering does not. The crosswalk below is our analysis of where each of the book’s themes now lives; the IPPF to GIAS mapping table does the same job for the old standard numbers themselves.

Book themeWhere it lives in the 2024 StandardsWhat changed since the book
Purpose of the function; the value it deliversDomain I (Purpose of Internal Auditing); 9.2 Internal Audit Strategy; 12.2 Performance MeasurementA written strategy and reported performance measures are now requirements, not good practice.
Mandate, charter, reporting lines, independenceDomain III: 6.1 Mandate, 6.2 Charter, 7.1 Organizational Independence, 8.1 Board InteractionThe board’s and senior management’s obligations are written as essential conditions; the CAE must discuss them with both (see the Domain III guide).
Staffing, competence, budget, toolsPrinciple 10 (10.1 to 10.3); 3.1 Competency; 7.2 CAE QualificationsTechnological resources have their own standard; the CAE’s own qualifications are a board matter.
Risk-based planning; understanding the business9.1 Understanding Governance, Risk Management, and Control Processes; 9.4 Internal Audit Plan; 9.5 Coordination and RelianceThe plan must state its limitations and be revisited when risks change; reliance on other providers has explicit criteria (see the Domain IV guide).
Engagement planning and work programsPrinciple 13 (13.1 to 13.6)A documented engagement risk assessment and evaluation criteria are explicit requirements.
Evidence, analysis, findings, conclusionsPrinciple 14 (14.1 to 14.6)The finding’s elements and the evaluation of significance are standardised; disagreement with management has a required methodology (see the Domain V guide).
Reporting and persuasion11.2 Effective Communication; 11.3 Communicating Results; 15.1 Final Engagement CommunicationThe final communication must name owners and dates and be approved by the CAE.
Follow-up and unresolved risk15.2 Confirming the Implementation of Recommendations or Action Plans; 11.5 Communicating the Acceptance of RisksConfirmation, not monitoring; escalation to the board when senior management accepts a risk beyond tolerance.
Quality of the function8.3 Quality; 8.4 External Quality Assessment; Principle 12 (12.1 to 12.3)The board’s role in the external assessment is an essential condition; supervision is quality evidence.
Ethics, objectivity, due careDomain II: Principles 1 to 5 (Standards 1.1 to 5.2)The Code of Ethics became standards with evidence of conformance; professional courage and scepticism are explicit (see the Domain II guide).

Read with the crosswalk, the book becomes more useful rather than less: it explains why the 2024 requirements exist, which the Standards themselves, being requirements, do not. A reader who wants to know why Standard 9.2 demands a strategy will find the reasoning in the book’s first part; a reader who wants to know what the strategy must contain will find it in the Standard and in the strategy outline in our Domain IV guide.

A reading list by theme: the book, the Standards and the guides on this site

The crosswalk above maps the book to the Standards. This table adds the third column readers ask for: for each of the book’s themes, the guide on this site that turns the theme into something you can do on Monday, with the template or worked example it carries. The book supplies the why, the Standard supplies the must, and the guide supplies the how; read them in that order and the book stops being a shelf reference.

Theme in the bookPart and chaptersThe StandardsRead next on this site
What the function is for; its customers and productsPart one, opening chaptersDomain I; 9.2Inside the internal audit department; setting up a function in a small company
Mandate, charter, reporting lines, the boardPart one, governance chapters6.1, 6.2, 7.1, 8.1GIAS Domain III; the audit committee presentation template
People, budget, technologyPart one, resourcing chapters10.1 to 10.3; 3.1GIAS Domain IV; the RCM Workbench as an example of a technological resource
Strategy, planning and coveragePart one, planning chapters; part two, the risk-based plan9.1, 9.4, 9.5The internal audit risk assessment; building the audit plan; risk appetite statements
Quality and performance of the functionPart one, closing chapters8.3, 8.4, 12.1 to 12.3The QAIP playbook; the self-assessment template
Engagement planning and programsPart two, scoping and planning13.1 to 13.6The planning memo; the RCM template; the work program; walkthrough documentation
Evidence and analysisPart two, fieldwork chapters14.1, 14.2Audit evidence; the model workpaper; sample sizes; test of design vs operating effectiveness
Findings, ratings and recommendationsPart two, findings chapters14.3, 14.4The 5 C’s; conditions, causes, consequences, recommendations; the severity matrix
Communicating resultsPart two, reporting chapters11.2, 11.3, 14.5, 15.1Model report examples; report anatomy; the template set; negotiating findings; report writing
Follow-up and unresolved riskPart two, follow-up chapter15.2, 11.5Issue validation; the life of a finding; evaluating management responses; risk acceptance; the issue log
Advisory servicesPart two, advisory chapterAdvisory considerations across Domain VGIAS Domain V, which marks the advisory considerations standard by standard
Ethics, objectivity and professional courageThroughout; the problem-solving partnershipDomain II, 1.1 to 5.2GIAS Domain II; The Audit Society, for the outside view of what verification does to organizations

The engagement rows are where the book is thinnest and the site is thickest, which is not a criticism of either: the seventh edition is explicit that it is a book of questions for a chief audit executive, and the fieldwork guides exist to answer the questions it raises about how. A function that owns the book and the Standards and works through the third column has, in effect, a methodology.

How to read it, by role

Nobody should read this book front to back on a first pass, and the two-part structure is an invitation not to. The table gives a reading order and a time budget by role; the worked example at the end turns the first row into a week-by-week plan.

ReaderRead firstThenTime budgetPair it with
New internal auditor (first two years)Part two, chapters 9 to 16, alongside the function’s methodology manualPart one, to understand why the function is set up as it isFour to six weeks at one or two chapters a weekThe internal audit department roles and structure guide and the Domain V guide
Senior or audit managerPart two as a review standard for the engagements you supervisePart one, chapters on planning and qualityThree weeksStandards 13.1 to 15.2; the workpaper example
Chief audit executivePart one as a self-assessment of your charter, strategy, resourcing and quality programmePart two, reporting and follow-up chaptersTwo to three weeks, with the Standards openDomains III and IV; the QAIP playbook
CIA candidateThe reporting, evidence and planning chapters as backgroundNothing else until after the examA weekend per partThe IIA’s CIA Learning System and the CIA exam cost guide; the book is not the syllabus
Audit committee memberPart one onlyThe follow-up chapter, to know what to ask about open actionsA weekThe audit committee guides on this site

The chief audit executive’s sixteen questions from part one

The publisher describes the seventh edition as a book that helps a chief audit executive ask the right questions, and the most useful thing to take from part one is the questions themselves, in your own words, answered for your own function. The sixteen below are ours, one or two per chapter of the first part, written so that each has a document, a number or a name as its answer rather than a feeling. A CAE who can answer all sixteen in writing has a strategy, whether or not the document is called one; a CAE who cannot answer four of them has found next quarter’s work.

Purpose and value. 1. In one sentence, what does this function exist to do for this organization, and does the audit committee chair say the same sentence? 2. What are the function’s products, named, and which of them did the board use to make a decision this year?

Mandate and governance. 3. When did the board last approve the charter, and what in the charter has the function never actually done? 4. Which of the board’s essential conditions in Domain III has the CAE discussed with the chair in the last year, with a record? 5. Who could stop the function from auditing something, and what happened the last time someone tried?

Coverage. 6. What share of the audit universe was covered in the last three years, weighted by risk rather than by count, and what has never been covered? 7. Which risks does the function rely on other assurance providers for, and by what criteria did it decide to rely?

Resources. 8. What competence does the plan require that the team does not have, and how is the gap being closed this year: hiring, co-sourcing, training or scope? 9. What did the function pay for technology, and which engagements ran differently because of it? 10. If the budget were cut by a fifth, which risks would leave the plan, and does the board know?

Planning. 11. How does the plan change when the risk assessment changes mid-year, and when did it last change? 12. What are the plan’s stated limitations, in the words the board approved?

Quality and performance. 13. What are the function’s performance measures, who sees them, and which one moved this year? 14. When was the last external assessment, what did it find, and which finding is still open? 15. What did the last internal self-assessment rate as partially conformant, and what is the date for closing it? 16. What would the function’s harshest reasonable critic say it does badly, and is that critic on the audit committee?

Question 16 is the one the book’s problem-solving stance implies and never quite asks. The QAIP playbook turns questions 13 to 15 into a program with evidence, and the Domain III guide gives the essential conditions behind questions 3 to 5.

Sawyer’s vocabulary, then and now

The book’s language has aged less than its standard numbers, but a reader coming from the 2024 Standards will meet terms that have shifted. The table gives the term as the book’s tradition uses it, what current practice calls the same thing, and where the difference matters.

In the book’s traditionIn current practiceWhere the difference matters
Management-oriented auditing; operational auditingRisk-based internal auditing; assurance over governance, risk management and control processesSame stance, wider object: the modern function audits governance and risk management processes as well as operations
AuditeeManagement, the process owner, or the client of an advisory engagementThe Standards avoid the word; the partnership the book describes is easier to see when the person is a process owner rather than an auditee
Audit programWork program; engagement work program (Standard 13.6)Now a documented requirement with approval before implementation and approved adjustments; see the work program guide
Working papersEngagement documentation (Standard 14.6)Retention, access and supervision requirements are now explicit; see the model workpaper
RecommendationRecommendation or management action plan (Standard 14.4)The Standards permit either; the book’s later editions describe the collaborative version as the practical one
Criteria, condition, cause, effectThe same four, in Standard 14.3, plus the recommendation or action plan as the fifth CSawyer’s structure, adopted whole; the five C’s guide is the current treatment
Deficiency; audit findingEngagement finding, evaluated for significance and rated (Standard 14.3)The rating is now expected to follow a published methodology; see the severity matrix
Follow-up; monitoringConfirming the implementation of recommendations or action plans (Standard 15.2)Confirmation on evidence, not monitoring of management’s word; see issue validation
Consulting servicesAdvisory servicesThe word changed with the 2024 Standards; the book uses both
Quality assurance; peer reviewQuality assurance and improvement program; internal and external assessments (Standards 8.3, 8.4, 12.1)The external assessment is now a board matter with a five-year requirement; see the QAIP playbook
The audit universeStill the audit universe, inside the internal audit risk assessment (Standard 9.4)The term survived; what changed is that the plan must state what the universe leaves out

Where the book is weakest

Five criticisms, in the order a working auditor is likely to meet them. First, the standards problem already described: the 7th edition is written against a framework that has been replaced, and a reader without the crosswalk will cite numbers that no longer exist. Second, the edited-volume problem: ten authors produce ten voices and some repetition, and the chapters vary in depth, so the book reads as a handbook by committee rather than as the single sustained argument the early editions were. Third, the procedures problem: the 7th edition is stronger on questions than on how-to, and a function looking for test steps, sample sizes or workpaper formats will not find them here; the 6th edition’s three volumes were more encyclopaedic, and this site’s fieldwork guides exist partly to fill the gap. Fourth, the perspective problem: the book is written from within the IIA’s world and largely from a North American vantage point, and it says little about regulated-industry expectations, about small functions of one or two people, or about outsourced and co-sourced models, all of which are common. Fifth, the price problem: a 400-page reference at a professional-book price, with an eBook sold on time-limited access, is a real barrier for the junior auditors who would benefit most, which is part of why searches for a free PDF are so common and why this guide’s notes exist.

None of these is a reason not to read it. They are reasons to read it as what it is: the profession’s statement of what internal auditing is for, written by practitioners, and not a methodology manual or an exam guide.

Sawyer’s against the alternatives

Sawyer’s is rarely the only book on the shelf, and it is not always the right first one. The comparison below is deliberately narrow: what each does that the others do not, and who it is for.

Book or sourceWhat it does that Sawyer’s does notBest for
The Global Internal Audit Standards themselves (The IIA, 2024; free)State the requirements, considerations and evidence for every standard; the authoritative textEveryone; read the domain you are working in before the corresponding part of Sawyer’s
Internal Auditing: Assurance and Advisory Services (Internal Audit Foundation textbook)A structured textbook with chapter objectives, cases and review questions, aligned to the IIA’s body of knowledgeStudents, new hires and CIA candidates who want a course, not a reference
Brink’s Modern Internal Auditing (Wiley)Broad single-author coverage with more on IT, SOX and specific audit areasPractitioners who want one reference with more how-to
Operational Auditing: Principles and Techniques for a Changing World (Hernan Murdock)Depth on operational audit techniques, process analysis and the consulting postureAuditors moving from financial to operational work
The Audit Society: Rituals of Verification (Michael Power)The outside view: what auditing does to organisations and why it can become ritualAnyone who wants to understand the profession’s critics; see the Audit Society summary
Sawyer’s Internal Auditing, 7th editionThe profession’s own account of what the function is for and how to position and run itLeaders and future leaders of a function; the reader who wants the why

Worked example: a six-week reading plan for a new auditor

MidState Beverage’s internal audit function, the six-person team used as the running example across this site, rewrote its methodology manual to the 2024 Standards during its ninety-day quality programme build. Its staff auditor had come from the depot finance team with no audit background, and the manager’s onboarding plan paired the 7th edition with the manual and the Standards, six weeks at two chapters a week, in the order below. The point of the pairing is that each week ends with something done at work, not only something read.

WeekReadStandards to read alongsideDo at work
1Part two: the risk-based plan and engagement planning chapters9.4; 13.1 to 13.3Read the FY27 plan and the planning memo for the depot rotation you will join; write one paragraph on what the engagement is for.
2Part two: evidence and analysis chapters14.1 to 14.3Take one completed workpaper from the route cash file and mark each piece of evidence as sufficient, reliable, relevant and useful, or not.
3Part two: findings, conclusions and reporting chapters14.4, 14.5, 11.2, 15.1Rewrite one finding from the last report in the five-element structure; compare with the issued version with the manager.
4Part two: follow-up and advisory chapters15.2, 11.5; 13.4 and 14.2 advisory notesTest two closed actions in the issue log for evidence of implementation; note which would have failed the new escalation rule.
5Part one: purpose, mandate, charter, independence and board chaptersDomain I; 6.1, 6.2, 7.1, 8.1Read the June 2026 charter against the book’s list of what a charter should do; list anything the charter says that the book does not, and the reverse.
6Part one: resources, planning, quality and performance chapters9.1, 9.2, 10.1 to 10.3, 12.1 to 12.3Read the function’s strategy and the first self-assessment; explain to the manager, in two minutes, why 12.2 was rated partially conformant.

Six weeks later the staff auditor had read the whole book, had touched every stage of the function’s work, and could say in her own words what the function was for, which is the test the book itself sets. The manager’s note in the training record was that weeks two and three had done more for her fieldwork than the two-day external course the function had budgeted for, and that the charter comparison in week five had turned up two items the charter promised that the function had never done.

Five questions readers ask before buying

Is Sawyer’s on the CIA exam? No. The exam is written to the IIA’s CIA Learning System and the 2025 syllabus, and the syllabus tests the Standards and the practice of the profession, not a book. Sawyer’s explains the reasoning behind much of what the exam tests, which makes it useful background and useless as a question bank.

How long does it take to read? Read in role order, four to six weeks at one or two chapters a week for a new auditor; two to three weeks for a CAE reading part one closely and part two selectively. Reading it front to back in a week is possible and pointless; nothing sticks without the work beside it.

Is it worth the price for someone outside the IIA? For anyone leading or planning to lead a function, yes, because the first eight chapters are the only sustained treatment of positioning and running a function that is written by practitioners rather than by a standard-setter or a regulator. For a junior auditor on their own money, borrow it, buy a used 6th edition, or start with the notes and the Standards.

Does it cover IT audit, SOX or data analytics? Lightly. It treats technology as a resource and a risk area at the level a CAE needs, not at the level an IT auditor needs. For those subjects use specialist references and the guides on this site; for the argument about why the function exists at all, use Sawyer’s.

Will there be an 8th edition? Nothing has been announced at the time of writing. Given that the 2024 Standards changed the numbering and several assumptions the 7th edition rests on, a revision would be a natural next step, and this guide will be updated if one is published.

Five more questions, from readers who already own it

Is Sawyer’s Guide for Internal Auditors the same book as Sawyer’s Internal Auditing? Same lineage, different editions. Sawyer’s Guide for Internal Auditors is the title of the three-volume sixth edition of 2012; Sawyer’s Internal Auditing is the title of the fifth edition of 2003 and of the single-volume seventh edition of 2019, which added the subtitle Enhancing and Protecting Organizational Value. A citation should give the edition and year, because the chapter numbering and the standards references differ between them; the edition table above has the details.

Is there a Kindle or audiobook edition? The seventh edition is listed in Kindle format at the major booksellers alongside the hardcover, and it is the Kindle listing that names the ten contributing authors. We are not aware of an audiobook, and a book built around tables and frameworks would not survive one well. The Foundation’s own eBook, through VitalSource, is the version with the search and annotation tools a working auditor wants.

Can I cite Sawyer’s in an audit report or a methodology? As reasoning, yes; as criteria, no. The criteria for a finding are policy, regulation, contract or an adopted framework, and the criteria for a methodology are the Standards. Sawyer’s is the place to explain why a methodology requires root cause analysis or a management action plan, in the methodology’s introduction or in training, and it is the wrong thing to put in a finding’s criteria line, where a process owner will reasonably ask why they are bound by a book they have never read.

Which chapters matter most for a function moving from compliance checking to risk-based auditing? Part one’s chapters on purpose, coverage and planning, read with Standards 9.1 and 9.4, and then part two’s chapter on the risk-based plan. The move fails in most functions not for lack of technique but because the charter, the plan and the committee’s expectations were never rewritten together; the book is unusually good on that, and the audit risk assessment guide shows what the rewritten plan looks like.

What should I read after Sawyer’s? The Standards themselves, in full, once. Then, depending on the job: for the function, the QAIP playbook and the Domain IV guide; for engagements, the fieldwork guides in the theme table above, starting with audit evidence and the five C’s; and for perspective, Michael Power’s The Audit Society, which asks whether all this verification does what it claims, and which every auditor should read once with the answer not assumed. The rest of the book reviews on this site are chosen on the same principle.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading