Michael Power’s The Audit Society: Rituals of Verification (Oxford University Press, 1997) is the most quoted book ever written about auditing by someone who is not selling it. Its argument is uncomfortable for anyone who audits for a living: that the explosion of audit since the 1980s has less to do with the value of what auditors find than with the comfort that the act of checking produces; that organisations reshape themselves to be auditable rather than to be good; and that audit has become a ritual whose failures generate demands for more audit rather than for something better. Nearly thirty years on, with the profession operating under a new set of Global Internal Audit Standards, the book reads less like a critique from outside and more like a set of tests the function ought to run on itself.
This guide summarises the book chapter by chapter, explains the six ideas that made it famous (the audit explosion, rituals of verification, auditability, decoupling and colonisation, the dialectic of regulatory failure, and trust), sets out what each one means for an internal audit function in 2026, and answers the practical questions readers arrive with: is there a free version (yes, of the shorter pamphlet that preceded it), which edition to buy, how long it takes to read, and what the serious criticisms of Power’s thesis are. It ends with a worked example of a function using Power’s tests on its own reporting. Companion reading is our guide to Sawyer’s Guide for Internal Auditors, the profession’s own account of what internal auditing is for; the two books are best read against each other.
This guide was rewritten in September 2026 from a shorter review published in February 2025. Bibliographic facts were checked against Oxford University Press’s listings; the summaries of Power’s arguments are our own paraphrases, and the application to the 2024 Standards is our analysis. No passages from the book are reproduced.
In this guide
- The book in one page
- Who Michael Power is, and what the book grew out of
- The six chapters, summarised
- The six ideas that made the book famous
- Power’s vocabulary: eight terms defined for practitioners
- What it means for internal audit in 2026: Power’s tests against the Global Internal Audit Standards
- The criticisms of Power, and what he conceded
- Editions, the free pamphlet, and how long it takes to read
- How to use the book with a team: a one-hour discussion guide
- Worked example: running Power’s tests on a function’s own reporting
- Related guides
The book in one page
Power’s starting observation is empirical: from the early 1980s, in Britain and North America, the word audit escaped from financial statements and attached itself to everything. Medical audit, environmental audit, quality audit, teaching audit, value-for-money audit, technology audit, data audit. He calls this the audit explosion, and he asks a question that practitioners rarely ask: what does all this checking actually do? His answer is not that audit is useless. It is that audit’s value is largely assumed rather than demonstrated; that audit works by producing comfort for people at a distance from the activity (regulators, boards, funders, the public) rather than by producing knowledge about the activity; and that to be audited, an activity has to be made auditable first, which changes the activity, often for the worse.
From that he builds the book’s three most durable claims. Audit is a ritual of verification: its procedures reassure independently of what they find, which is why an audit that finds nothing is treated as a success rather than as a question about the audit. Audit constructs its own auditees: organisations respond to being audited by building the documents, measures and control structures the auditor will look for, so that over time the auditable representation of the work displaces the work. And audit is caught in a dialectic of failure: when something goes wrong in an audited organisation, the political response is more audit, not a re-examination of whether audit was ever able to prevent it, so the system ratchets. The book closes by asking what a world less dependent on audit and more dependent on trust would look like, and by conceding that nobody, including the author, knows how to get there.
Who Michael Power is, and what the book grew out of
Michael Power is Professor of Accounting at the London School of Economics, where he has taught since 1987, and a chartered accountant (a member of the Institute of Chartered Accountants in England and Wales). That combination matters to how the book reads: it is written by someone who trained in the practice he is describing and then stepped back to ask what it is for. The Audit Society grew out of a short pamphlet, The Audit Explosion, published by the think tank Demos in 1994, which made the core argument in about forty pages and is still freely available from Demos as a PDF (the editions section below has the details). The book expanded the pamphlet into a study of audit as a principle of social organisation, drawing on accounting research, sociology and political theory, and it was followed by two related works, The Risk Management of Everything (Demos, 2004) and Organized Uncertainty: Designing a World of Risk Management (Oxford, 2007), which extend the same method to risk management.
The context the book came out of is worth holding in mind while reading it: Britain in the 1990s, after a decade of public-sector reform that had imported audit and performance measurement into hospitals, schools and universities, and after a run of corporate collapses that had produced new corporate governance codes and new demands on auditors. Power is writing about a particular moment. Readers in 2026, in the United States or elsewhere, have to do some translation, and the criticism section below is partly about how much.
The six chapters, summarised
The book is short, about two hundred pages including notes and bibliography, and its six chapters form a single argument rather than a collection of essays. The table gives each chapter’s question, its answer in our words, and the idea it contributes to the rest of the book.
| Chapter | The question it asks | The answer, in our words | What it contributes |
|---|---|---|---|
| 1. The Audit Society: General Themes | Why treat audit as a social phenomenon rather than a technique? | Because audit has become a way of organising accountability across society, and its spread cannot be explained by its technical merits alone. | The framing: audit as an idea with a life of its own. |
| 2. The Rise of Audit | Where did audit come from and how did it acquire authority? | Financial audit’s history is one of claims to expertise, professional self-regulation and negotiated expectations about what audit can and cannot do. | The idea that audit’s authority is constructed and maintained, not given. |
| 3. The Audit Explosion | Why did audit spread so far, so fast, after 1980? | Political demand for accountability and control, especially over public services and professions, met a supply of audit techniques and a language of assurance that travelled easily. | The explosion as a political rather than technical event. |
| 4. Audit and the Dialectic of Regulatory Failure | Why does audit survive its own failures? | Because each failure is interpreted as a shortage of audit rather than a limit of audit, and the response is more checking, more standards and more independence. | The ratchet: failure feeds demand. |
| 5. Audit Knowledge and the Construction of Auditees | What does audit know, and what does it do to the audited? | Audit’s knowledge is thin and procedural; to work at all it needs the audited activity to be made auditable, and the audited organisation obliges by producing auditable surfaces. | Auditability; decoupling and colonisation as the two ways organisations respond. |
| 6. Beyond Audit, Towards Trust | Is there an alternative? | Audit is institutionalised distrust; trust-based alternatives exist but are fragile, and the honest conclusion is a plea for less audit done better rather than a programme. | The normative close, and its admitted incompleteness. |
The six ideas that made the book famous
The audit explosion. Power’s term for the spread of audit from financial statements to almost every activity that receives public money or public attention. His point is not that the spread was wrong but that it was unexamined: audit was adopted as the answer to accountability problems without anyone establishing that it answered them. For internal auditors the term has a specific echo: the function’s own growth in scope (from finance to operations, then to IT, then to culture, third parties, resilience, models, artificial intelligence) is an audit explosion in miniature, and the same question applies to each extension. What does auditing this actually change?
Rituals of verification. The subtitle and the sharpest idea. A ritual is an action whose meaning comes from its performance rather than its effect. Power’s claim is that much audit work functions this way: procedures are performed, sign-offs accumulate, an opinion is issued, and the people who commissioned the audit are reassured, largely regardless of what the procedures were capable of detecting. The comfort is real; the knowledge behind it is often thin. Any internal auditor who has watched a reviewer initial a workpaper without reading it, or a committee accept a green rating without asking what was tested, has seen the ritual in operation.
Auditability, and the construction of auditees. Audit cannot examine an activity directly; it examines representations of the activity: records, measures, documented controls. So before something can be audited it has to be made auditable, and the organisation does that work by building the representations the auditor will ask for. Over time the representations become the thing managed. A school teaches to the inspection framework; a hospital manages its waiting-list statistics; a control owner maintains the evidence of review rather than the review. Power’s phrase for the result is that audit constructs its auditees. Internal auditors see this whenever a control exists mainly because a past audit asked for it.
Decoupling and colonisation. The two ways an organisation can respond to being audited, borrowed from organisational sociology and critical theory. Decoupling is when the audit process runs in parallel to the real work and touches it as little as possible: the compliance file is immaculate and irrelevant. Colonisation is when audit values take over the work itself: the activity is redesigned around what can be measured and checked, and the parts that cannot be measured wither. Power treats both as pathologies, and the interesting observation for practitioners is that a function can produce either, depending on how it behaves. A function that accepts the immaculate file produces decoupling; a function that demands metrics for everything produces colonisation.
The dialectic of regulatory failure. When an audited organisation fails, the failure is rarely read as evidence that audit could not have prevented it. It is read as evidence that there was too little audit, or that the auditors were insufficiently independent, or that the standards were too loose, and the response is more of each. The system ratchets in one direction. Power wrote this before the corporate failures of 2001 and 2002 produced the Sarbanes-Oxley Act, and before the 2008 crisis produced another wave of assurance requirements, and his readers have been pointing out ever since that both episodes followed the script.
Audit as institutionalised distrust, and the case for trust. The closing argument. Audit is what a society does when it does not trust professionals, managers or institutions to account for themselves, and it carries a cost: it can crowd out the trust-based, judgment-based ways of working that made the activity worth doing. Power does not offer a programme for replacing audit with trust, and says so. What he offers is a demand that audit justify itself by its effects, not by its rituals, and that is the demand the rest of this guide turns on the internal audit function.
Power’s vocabulary: eight terms defined for practitioners
Part of the book’s influence is its vocabulary, which has escaped into audit committee papers, regulatory speeches and conference keynotes, often without the meaning Power gave it. The table fixes the meanings and gives the practitioner’s equivalent for each.
| Term | What Power means by it | What it looks like in an internal audit function |
|---|---|---|
| Audit explosion | The post-1980 spread of audit into activities far from financial statements, driven by political demands for accountability rather than by proven effectiveness. | A universe that grows with every new risk topic while capacity and evidence standards stay flat. |
| Ritual of verification | Audit procedures whose reassuring effect is independent of what they are capable of finding. | Reviews initialled without notes; ratings issued without a coverage statement; “no exceptions” from a sample that could not detect the exception. |
| Comfort | The reassurance audit produces for people at a distance from the activity; the real product of much audit work, as distinct from knowledge. | The quarterly pack the committee likes because it is green. |
| Auditability | The property an activity must acquire before it can be audited: records, measures, documented controls; produced by the audited organisation in response to audit. | Controls that exist because a prior audit asked for them; evidence of review maintained in place of review. |
| Construction of auditees | The process by which audit reshapes organisations into auditable form, so that the auditable representation displaces the work. | A process rated on the completeness of its documentation rather than on whether it achieves its objective. |
| Decoupling | An organisation’s response in which the audit process runs beside the real work and touches it as little as possible. | The immaculate compliance file; findings closed on management’s confirmation; a QAIP that checks files and never judgment. |
| Colonisation | The opposite response, in which audit’s values take over the work and reshape it around what can be measured and checked. | Recommendations that add controls with no reference to cost or objective; a function measured on hours that produces hours. |
| Dialectic of regulatory failure | The pattern in which each failure of an audited system is read as a shortage of audit, producing more audit, more standards and more independence, but never a re-examination of what audit can do. | Every incident answered with a new engagement; the universe expanded after each failure without added capacity or an honest statement of limits. |
What it means for internal audit in 2026: Power’s tests against the Global Internal Audit Standards
Power wrote about audit in general, and financial and public-sector audit in particular; internal audit gets less attention in the book than it deserves, and the Global Internal Audit Standards of 2024 did not exist. Read together, though, the book and the Standards have a striking relationship: several of the 2024 requirements are, in effect, defences against the pathologies Power described, and several others could produce them. The table takes each of Power’s ideas and asks two questions: which Standard answers it, and which Standard, badly applied, would prove him right.
| Power’s idea | The Standard that answers it | How a function proves him right instead |
|---|---|---|
| Rituals of verification: procedures reassure regardless of what they can detect | 14.1 to 14.5: evidence must be sufficient and reliable, findings evaluated for significance, conclusions supported; 15.1: the report states what was and was not covered | Reports that lead with a rating and never say what was tested; review sign-offs without notes; “no exceptions noted” from a sample that could not have found any |
| Auditability: organisations build the surfaces the auditor asks for | 13.2 and 13.4: engagement risk assessment and evaluation criteria set from the objective, not from what is documented; 9.1: understanding the business, not its control inventory | Testing only what is in the control matrix; accepting a screenshot of a checklist as evidence the control operates; rating a process by the completeness of its documentation |
| Decoupling: the compliance file runs beside the real work | 14.2 and 14.3: analysis against criteria and evaluation of cause and effect; 15.2: confirming that action was implemented rather than reported | Closing findings on management’s word; reporting control existence rather than control effect; a QAIP that checks the file and never the judgment |
| Colonisation: the work is redesigned around what can be measured | 12.2 Performance Measurement, if the measures are about outcomes; 11.1: stakeholder relationships that keep the function close to the work | 12.2 badly applied: a function measured on plan completion and hours produces plans and hours; recommendations that add controls with no reference to cost or objective |
| The dialectic of failure: every failure produces more audit | 9.4: the plan must state its limitations and what it does not cover; 11.5: escalation when management accepts risk beyond tolerance | Responding to every incident with a new audit rather than with an honest statement of what audit could not have caught; expanding the universe after each failure without adding capacity |
| Institutionalised distrust; the case for trust | Principle 2 and Standard 2.2: objectivity safeguarded without hostility; 6.1 and the Domain III introduction: the mandate discussed with the board and management as a shared responsibility | A function that treats every auditee as a suspect and every control owner as an adversary, and reports it as independence |
The practical reading is that the Standards give a function the tools to be the kind of audit Power was not writing about, and no obligation to use them that way. A function conforming with every Standard can still be a ritual of verification if its evidence is thin, its findings are about documentation, and its committee reporting is designed to reassure. Conformance is the floor. Power’s book is a description of what a function looks like when it stops at the floor and calls it the ceiling, which is why it belongs on the same shelf as the Global Internal Audit Standards guide and the Domain IV guide rather than on the shelf for critics.
The criticisms of Power, and what he conceded
Four criticisms recur in the academic response to the book, and a reader should know them before quoting it in an audit committee paper. First, the evidence is thin in exactly the way Power accuses audit of being thin: the book is an essay built on examples and reading rather than on systematic study of what audits find and change, and later scholars, most pointedly in a 2008 article titled There Is No Such Thing as Audit Society, argued that the audit society is a rhetorical construct rather than an empirical one. Second, it is a book about Britain in the early 1990s, and about public services and professions under a particular political programme; how far it travels to a 2026 American bank or a European manufacturer is a question the reader has to answer, not one Power answers. Third, the treatment of internal audit is slight: Power’s audit is mostly external, financial and regulatory, and the management-oriented, advisory, risk-based internal audit that the internal audit department roles and structure guide describes is not really his subject. Fourth, the alternative is missing: having described audit as institutionalised distrust, the book has no account of how trust is rebuilt at scale, and admits it.
Power’s own later work concedes some of this and extends the rest. The Risk Management of Everything (2004) argued that the audit explosion had migrated into risk management, with the same pathologies: reputational risk management as a ritual, risk registers as auditable surfaces, and a defensive style of decision-making he called the risk management of everything. Organized Uncertainty (2007) is the fuller academic version. For an internal auditor the sequence is instructive, because the function moved in exactly the direction Power predicted, from checking controls to assuring risk management, and inherited the same question at each step: what does this change?
Editions, the free pamphlet, and how long it takes to read
Readers who arrive here searching for a PDF of the book should know two things. The book itself is in copyright and is sold by Oxford University Press in paperback and as an eBook, with chapter-level access through Oxford Academic for institutional subscribers; there is no authorised free PDF. The argument, however, exists in a shorter, earlier and entirely free form: The Audit Explosion, the 1994 Demos pamphlet, is published by Demos as a free PDF on its own website and covers the core thesis in about forty pages. For a practitioner who wants the idea rather than the scholarship, the pamphlet is the place to start, and for a reading group it is the better assignment.
| What | Details | Best for |
|---|---|---|
| The Audit Explosion (Demos, 1994) | Pamphlet, about forty pages, free PDF from Demos | First contact with the argument; audit committee reading; team discussion in an hour |
| The Audit Society: Rituals of Verification, hardback | Oxford University Press, 2 October 1997, about 200 pages, ISBN 978-0-19-828947-0 | Libraries; collectors |
| The Audit Society: Rituals of Verification, paperback | Oxford University Press, 28 October 1999, ISBN 978-0-19-829603-4; also sold as an eBook | The edition to buy; text identical to the hardback |
| The Risk Management of Everything (Demos, 2004) | Pamphlet; free PDF from Demos | The sequel argument, applied to risk management |
| Organized Uncertainty (Oxford, 2007) | Full-length academic follow-up | Readers who want the developed theory |
The book takes a working auditor about six hours to read properly, which for two hundred pages says something about the density of the prose; the pamphlet takes one. Chapters three, five and six carry most of the argument and can be read on their own by a reader short of time. Chapter two, on the history of financial audit, is the one practitioners skip and the one that explains why audit’s authority is fragile, so skip it last.
How to use the book with a team: a one-hour discussion guide
The book is more useful discussed than read alone, because its tests are uncomfortable in exactly the way that a team will rationalise away in private and confront in a room. The guide below fits an hour, assigns the free pamphlet rather than the book, and ends with a decision rather than a conversation. It works for an internal audit team of any size and, in a shorter form, for an audit committee.
Pre-read (one hour, individually): The Audit Explosion (Demos, 1994), free PDF. Optional: chapter 5 of The Audit Society.
Discussion (45 minutes, in three rounds of 15): Round one, ritual: take the last report each person worked on and answer, in one sentence, what the rating could not have detected. Round two, auditability: name one control in the organisation that exists because audit asked for it, and say whether it protects an objective or a file. Round three, measures: list the function’s own performance measures and mark each as rewarding volume, effect, or neither.
Decision (15 minutes): One change to the report template, one change to the evidence standard, one change to the function’s measures, each with an owner and a date. Record them in the quality programme’s improvement log so the internal assessment under Standard 12.1 can test whether they happened.
Questions for an audit committee (20 minutes): How much of the pack we receive is comfort and how much is knowledge? What did the last three audits test, in one line each? What would the function have to stop doing to do the rest better? Which risks does the plan not cover, and did we agree to that?
Two cautions from experience. The exercise fails if the CAE uses it to defend the function; the point is to find the rituals, and every function has them. And it fails if it produces a list of new controls, because that is the colonisation Power warned about wearing the costume of self-criticism. The right output is usually less: fewer findings about documentation, shorter reports with coverage statements, and one or two measures that reward effect.
Worked example: running Power’s tests on a function’s own reporting
MidState Beverage’s internal audit function, the six-person team used as the running example across this site, had the book put to it in an unexpected way. After the function’s first quarterly report under its new quality programme, the audit committee chair, who had read the Demos pamphlet on a flight, asked the chief audit executive a question in the chair’s own words: how much of what you send us is comfort, and how much is knowledge? The CAE took the question seriously and ran the six ideas above against the function’s last four quarterly packs and its two most recent reports, the route cash audit and the ERP user access audit. The findings are in the table, with what changed as a result.
| Power’s test | What the CAE found | What changed |
|---|---|---|
| Ritual: do the ratings say what was tested? | The quarterly pack reported engagement ratings and open-action counts with no statement of coverage; a reader could not tell that the route cash rating rested on 60 reconciliations and 90 customer confirmations, or that the user access audit had tested a sample of the 74 roles rather than all of them. | Each rating now carries a one-line coverage statement (population, sample, what was not tested) in the pack, per Standards 15.1 and 11.3. |
| Auditability: were findings about documentation or about effect? | All five findings in the route cash report described an effect (money at risk, unmonitored failures, customers without statements); of the eleven actions, two required only documentation of controls that, on inspection, already operated. | The two documentation-only actions were re-scoped; the methodology now requires a stated effect for any finding above Low. |
| Decoupling: were closed actions confirmed or reported? | Of fourteen open actions, three were past due with no escalation, and four earlier closures had been accepted on management’s confirmation without evidence. | The Standard 15.2 confirmation process described in the Domain V guide: evidence for every closure, testing for High findings, past-due escalation to the committee. |
| Colonisation: what did the function’s own measures reward? | The function’s measures were plan completion, hours against budget, report turnaround and past-due actions; three of the four reward volume or speed, none rewards effect. | Performance measures adopted from the strategy under Standard 12.2, including actions implemented and confirmed, and stakeholder assessment of usefulness. |
| Dialectic of failure: what happened after the last incident? | After the Dayton driver theft, the function had proposed adding two engagements to the plan and nothing else. | The plan’s limitations section now states which risks the plan does not cover and why; the response to an incident starts with whether audit could have detected it. |
| Trust: how did the function treat auditees? | Auditee survey results, introduced with the quality programme, had been filed after each engagement but not yet discussed with the team or acted on. | Survey results reviewed quarterly with the manager; two process changes made in response to depot feedback. |
The CAE’s answer to the chair, a quarter later, was that the pack had been roughly half comfort and half knowledge, and that the half that was comfort had been the half the committee liked. The chair’s reply, minuted, was that the committee would rather have the other half. Power would have recognised both halves of that exchange, and would probably have noted that the committee’s preference is the rarer one.
Related guides
- Sawyer’s Guide for Internal Auditors: summary, editions and free study notes
- The Global Internal Audit Standards: the complete guide
- GIAS Domain IV: Managing the Internal Audit Function
- GIAS Domain V: Performing Engagements, Standard by Standard
- GIAS Domain II: Ethics and Professionalism
- Inside the internal audit department: roles and structure
- Issue validation in internal audit: evidence and closure
- How to audit corporate culture
- How to write an internal audit report people actually read
- Audit committee presentation template
- More book reviews for internal auditors
Leave a Reply