Domain V is where the Global Internal Audit Standards meet the engagement file. Performing Internal Audit Services covers three principles and fourteen standards that run from the first communication with the auditee to the confirmation that management did what it said it would, and every one of them corresponds to a document a reviewer can open: the notification, the engagement risk assessment, the objectives and scope, the criteria, the resource plan, the work program, the evidence, the analyses, the findings, the recommendations and action plans, the conclusion, the documentation, the final communication and the follow-up. This guide takes the domain standard by standard, with what each requires, the workpaper that evidences it and the gap a quality assessor usually finds, then adds the conformance mapping, an engagement conformance checklist, and a worked example that traces one engagement, a distributor’s route cash audit, through all fourteen standards.
This guide was rewritten in September 2026 from a shorter version published in August 2026. Standard titles and numbering follow the Global Internal Audit Standards as published by The IIA on 9 January 2024 and effective from 9 January 2025; requirement summaries are paraphrases for orientation.
In this guide
- The domain at a glance: three principles, fourteen standards, fourteen workpapers
- Principle 13: Plan Engagements Effectively
- Standard 13.1 in depth: communication as a thread
- Standard 13.4 in depth: evaluation criteria
- Principle 14: Conduct Engagement Work
- Standards 14.2 to 14.4 in depth: from analysis to action plan
- Standard 14.5 in depth: conclusions and the rating rule
- Principle 15: Communicate Engagement Results and Monitor Action Plans
- Supervision and review inside the engagement
- Standard 15.2 in depth: confirming, not tracking
- Evidence of conformance and the common gaps
- Advisory engagements and the Topical Requirements
- The engagement conformance checklist
- Worked example: MidState Beverage’s route cash audit through fourteen standards
- Common mistakes
- Related guides
The domain at a glance: three principles, fourteen standards, fourteen workpapers
| Principle | Standard | The workpaper that evidences it |
|---|---|---|
| 13. Plan Engagements Effectively | 13.1 Engagement Communication | Notification and kickoff record; communication plan for the engagement |
| 13.2 Engagement Risk Assessment | Engagement-level risk assessment | |
| 13.3 Engagement Objectives and Scope | Planning memo: objectives, scope, exclusions | |
| 13.4 Evaluation Criteria | Criteria stated and agreed with management | |
| 13.5 Engagement Resources | Budget, staffing and skills for the engagement | |
| 13.6 Work Program | The work program with procedures linked to objectives | |
| 14. Conduct Engagement Work | 14.1 Gathering Information for Analyses and Evaluation | Evidence: relevant, reliable, sufficient; population records; samples |
| 14.2 Analyses and Potential Engagement Findings | Analyses; potential findings with condition and criteria | |
| 14.3 Evaluation of Findings | Findings evaluated for significance; ratings | |
| 14.4 Recommendations and Action Plans | Recommendations; management action plans with owners and dates | |
| 14.5 Engagement Conclusions | The conclusion or opinion and its basis | |
| 14.6 Engagement Documentation | The file: complete, reviewed, retained | |
| 15. Communicate Engagement Results and Monitor Action Plans | 15.1 Final Engagement Communication | The report: contents, distribution, conformance statement |
| 15.2 Confirming the Implementation of Recommendations or Action Plans | Follow-up process and the validation record |
Principle 13: Plan Engagements Effectively
Standard 13.1, Engagement Communication, requires internal auditors to communicate with management of the activity under review throughout the engagement, starting with a notification of the engagement’s objectives, scope, timing and the people involved, and continuing with progress, potential findings and the results; the artifact is the notification and kickoff record, and the audit notification letter and kickoff template is its form. Standard 13.2, Engagement Risk Assessment, requires an assessment of the risks relevant to the activity under review, using the function’s understanding from Standard 9.1 and information gathered during planning, to determine the objectives, scope and the procedures that matter; it is the engagement-level counterpart of the plan’s risk assessment and the standard most often missing from files that otherwise conform, because functions assume the annual risk assessment covers it. Standard 13.3, Engagement Objectives and Scope, requires objectives that state what the engagement will conclude on and a scope that states what is included, what is excluded and why, including the period and the locations, with limitations disclosed; the artifact is the planning memo, which the planning memo template lays out.
Standard 13.5, Engagement Resources, requires the engagement to be staffed with people who collectively have the competencies it needs, in the time it needs, with external expertise obtained where the function lacks it; the artifact is the resource allocation in the planning memo and the co-source arrangement where there is one. Standard 13.6, Work Program, requires a work program that specifies the procedures for gathering evidence sufficient to achieve the objectives, approved before fieldwork begins and amended with approval when the engagement changes; the audit work program guide covers the structure and the walkthrough versus test of controls guide the procedure choice that most work programs get wrong.
Standard 13.1 in depth: communication as a thread, not an event
The engagement communication standard is written as a thread that runs the length of the engagement, and files that conform show four moments on it. The notification, which states the objectives, scope, timing, the auditors and what is requested of management, and which is sent early enough that management can prepare and object; the kickoff, at which the objectives and criteria are discussed, the process owner’s concerns heard and the logistics agreed, with a record kept; the progress communications, at a cadence agreed at kickoff, at which potential findings are discussed as they arise so that the facts are confirmed under Standard 14.2 and nothing in the draft report is a surprise; and the closing meeting, at which the findings, ratings and proposed actions are walked through with management before the draft is issued, with disagreements recorded. The Standards add a consideration that is easy to miss: communication runs to the board where the engagement’s results warrant it, and the CAE decides, during the engagement rather than after, whether a finding is one the audit committee should hear about before the report is final. The notification and kickoff template covers the first two moments, the auditee’s guide is what the auditee should have been told about all four, and the verbal communication guides cover the meetings themselves.
Two practices make the thread hold. The engagement keeps a communication log, a dozen lines in the planning memo, with the date, the parties and the substance of each significant exchange, so that the assessment can see the thread without reconstructing it from email. And the closing meeting’s record states what management agreed with, what it disputed and on what basis, so that the report’s management responses are the second statement of a position the file already holds rather than the first.
Standard 13.4 in depth: evaluation criteria
Standard 13.4 requires internal auditors to identify the criteria against which the activity will be evaluated: the policies, procedures, laws, regulations, contracts, standards and expectations that define what “should be”, agreed with management where possible, and, where management has not established criteria, the criteria the auditor selects and the basis for them, communicated to management. The standard exists because a finding is a difference between a condition and a criterion, and a finding with no stated criterion is an opinion. The artifact is a criteria statement in the planning memo listing, for each objective, the source of the criteria (the organization’s own policy, an external standard, a regulatory requirement, a benchmark, or the auditor’s professional judgment with its rationale) and the record of management’s agreement or disagreement. Three practices make the standard work. Where the organization’s own policy is the criterion and the policy is weak, the auditor evaluates the policy against an external standard as well and says so, so that conformance with a bad policy is not reported as good practice. Where the criteria are the auditor’s, they are stated before fieldwork, not constructed to fit the findings. And where management disagrees with the criteria, the disagreement is recorded and the report presents both positions, which is the honest form of a finding management does not accept. The CSF 2.0 assessment method is an extended example of turning an external framework into agreed criteria, and the Topical Requirement workbook shows the criteria a Topical Requirement imposes.
Principle 14: Conduct Engagement Work
Standard 14.1, Gathering Information for Analyses and Evaluation, requires internal auditors to gather information that is relevant, reliable and sufficient to achieve the engagement objectives: relevant in that it supports the objectives and the potential findings, reliable in that it comes from a source and by a method the auditor can trust, and sufficient in that a prudent, informed person would reach the same conclusion from it. The artifacts are the evidence itself, the population records that show where samples came from, and the notes that show how reliability was assessed, which the audit evidence guide, the IPE testing guide and the sampling memo template cover. Standard 14.5, Engagement Conclusions, requires a conclusion at the engagement level, on the objectives, that considers the findings’ significance in aggregate and is supported by them; where the function issues an opinion or rating, the rating methodology is applied and stated. Standard 14.6, Engagement Documentation, requires documentation that is sufficient to support the conclusions and the findings, allows an experienced reviewer to understand the work, is reviewed and retained under the function’s policy, with access controlled; the workpaper best practices guide and the workpaper example set the standard, and the walkthrough documentation template is the most-used single workpaper. The assessment of Principle 14 reads sampled files for the chain from objective to procedure to evidence to finding to conclusion, and breaks in the chain, a finding with no procedure behind it or a conclusion the findings do not support, are the observations it makes.
Documentation under 14.6 has one more requirement that files built on shared drives fail without noticing: access control. The standard expects the CAE to control access to engagement documentation, to have a retention policy consistent with the organization’s requirements and the law, and to obtain approval from the CAE, and where required legal counsel, before releasing documentation to parties outside the organization. The evidence is the audit management system’s access model or, for a function without one, a restricted evidence store with an access list and a log, together with the retention schedule and the record of any external release; the workpaper best practices guide covers the practical arrangements, and the confidentiality standards in the Domain II guide are the reason the requirement exists.
Standards 14.2 to 14.4 in depth: from analysis to action plan
The three middle standards of Principle 14 describe the arc of a finding. Standard 14.2, Analyses and Potential Engagement Findings, requires the auditor to analyze the information gathered to identify potential findings, described as a difference between the condition and the criteria, with the cause and effect where determinable, and to discuss potential findings with management to confirm the facts. Standard 14.3, Evaluation of Findings, requires each finding’s significance to be evaluated, considering its impact, likelihood and the organization’s risk appetite, and rated on the function’s scale, with root cause identified where the finding’s remediation depends on it; the 5 Cs of audit findings guide gives the finding its structure (condition, criteria, cause, consequence, corrective action), the root cause analysis guide the cause, and the finding severity ratings guide the scale. Standard 14.4, Recommendations and Action Plans, requires the auditor to develop recommendations, or to obtain management’s action plans, that address the root cause, with management’s response, the owner and the target date recorded, and, where management declines to act, the acceptance of risk documented and handled under Domain IV’s Standard 11.5.
The arc has two discipline points a reviewer checks. The first is that the potential finding was confirmed with management before it became a finding: the standard requires the facts to be discussed, and a file that shows the finding appearing in the draft report with no record of the conversation has skipped a step that later becomes an argument. The second is that the action plan addresses the cause the finding names, not the symptom: a finding whose cause is an undesigned delegation rule and whose action plan is “retrain the approvers” will recur, and the follow-up under 15.2 will record it as implemented and ineffective, which is the worst outcome for everyone.
Standard 14.5 in depth: conclusions, opinions and the rating rule
The conclusion is the sentence the engagement exists to produce, and Standard 14.5 requires it to be stated at the engagement level, on the objectives, and to be supported by the findings taken together. Where the function issues an engagement rating or opinion (Satisfactory, Needs Improvement, Unsatisfactory, or whatever scale the function uses), the standard’s consideration is that the methodology for reaching it be documented and applied consistently, which in practice means a rule that connects the findings’ ratings to the engagement rating and that the audit committee has seen. The rule matters because it takes the engagement rating out of negotiation: MidState’s rule, agreed with its committee, is that an engagement is Unsatisfactory when a High finding shows a key control not operating across a material part of the scope, and Needs Improvement when High findings exist but the control layer as a whole still functions, which is what turned five findings into the Unsatisfactory opinion in the worked example and what allowed the cybersecurity program audit, with six High findings, to be rated Needs Improvement, as the cybersecurity program audit guide explains. The conclusion also has to answer the objectives as written: an engagement whose objective was to conclude on the design and operation of controls over route cash concludes on exactly that, and a report that concludes on something broader, or narrower, has changed the scope without saying so. The finding severity ratings guide covers the finding scale and the aggregation rule, and the report writing guide the placement of the conclusion at the top of the report where the reader will see it.
Principle 15: Communicate Engagement Results and Monitor Action Plans
Standard 15.1, Final Engagement Communication, requires a final communication that includes the objectives, scope and conclusions, the findings with their significance, the recommendations or action plans, and management’s responses; that is accurate, objective, clear, concise, constructive, complete and timely under Standard 11.2; that is distributed to the parties who can ensure the results receive due consideration; and that states whether the engagement was conducted in conformance with the Standards, with any nonconformance disclosed. Where an engagement covered a Topical Requirement, the conformance statement includes it. The internal audit report template and the report writing guide carry the form, and the report examples show finished ones. Standard 15.2, Confirming the Implementation of Recommendations or Action Plans, requires the CAE to establish a process to monitor and confirm implementation, with confirmation proportionate to the significance of the finding (inquiry for low, validation testing for high), results reported to senior management and the board, and unimplemented actions escalated, with the acceptance of risk handled under 11.5 where management decides not to act; the issue validation guide covers the confirmation and the issue log template the tracking. The assessment of 15.2 is the one that most often finds partial conformance, because functions track actions and rarely confirm them, and because the escalation of overdue actions to the board happens in a footnote or not at all.
Supervision and review inside the engagement
Domain V does not have a supervision standard of its own; supervision lives in Domain IV’s Standard 12.3 and in the documentation standard’s requirement that the file be reviewed, and the assessment tests it in the engagement file. The pattern that conforms has three levels: the in-charge auditor reviews every workpaper prepared by others before it supports a finding; the engagement manager reviews the planning memo before fieldwork, the findings before the closing meeting and the file before the report; and the CAE reviews the report and, on a risk basis, the file. Each review leaves evidence, which is not a signature but review notes: the questions asked, the answers, the changes made and the date cleared. A file with sign-offs and no notes has evidence that someone was present, not that anyone reviewed. Timing is the second test: review that happens after the report is issued has not supervised the engagement, and the assessment compares review dates to the report date. The third test is that review notes were cleared rather than deleted, because a cleared note shows what the reviewer challenged and how it was resolved, which is the evidence of professional skepticism the Domain II guide describes. Small functions where the CAE is also the in-charge auditor conform by having the manager or a peer review the CAE’s own workpapers, and by saying so in the manual.
Standard 15.2 in depth: confirming, not tracking
The follow-up standard is the one most functions partially conform with, and the reason is a single word: confirm. Tracking an action means recording that management said it was done. Confirming it means the function established that it was done and that it addressed the finding, with the method proportionate to the finding’s significance: inquiry and a document for a Low, inspection of the changed control for a Medium, and re-testing for a High, on a sample sized to the control’s frequency as the sample sizes guide sets out. The process the standard requires has five parts: a register of every action with owner, date and significance; a validation approach set when the action is agreed, not when it falls due; the validation performed at or after the due date, with its evidence in a workpaper; reporting to senior management and the board of the status of actions, including those past due; and escalation of overdue or ineffective actions, with management’s decision not to act treated as an acceptance of risk under Standard 11.5. Three failure patterns recur. Actions closed on management’s confirmation alone, which the assessment finds by asking for the validation workpaper. Due dates extended repeatedly without the extensions reaching the board, so that an action three years old shows as “in progress”. And actions validated as implemented that did not fix the finding, because the action addressed the symptom, which the issue validation guide treats as the central test: was the control now operating, and would it have prevented the condition the finding described? The issue log template carries the fields that make the five parts visible, and a function that reports the past-due list to its audit committee every meeting, by name, rarely has one.
Evidence of conformance and the common gaps
| Standard | Evidence in a conforming file | Where files usually fall short |
|---|---|---|
| 13.1 Communication | Notification with objectives, scope, timing, people; kickoff record; progress communications; closing meeting record | Notification sent; nothing recorded between kickoff and draft report |
| 13.2 Engagement risk assessment | Documented assessment of the activity’s risks driving objectives and procedures | Absent; the annual risk assessment assumed to cover it |
| 13.3 Objectives and scope | Planning memo with objectives, scope, exclusions with reasons, period, locations, limitations | Scope stated as a process name; exclusions unstated |
| 13.4 Criteria | Criteria per objective with sources; management’s agreement or disagreement recorded | Criteria implied by the findings rather than stated before fieldwork |
| 13.5 Resources | Budget, staffing and skills; external expertise arranged | Staffing by availability; skills gaps unaddressed |
| 13.6 Work program | Procedures linked to objectives and risks; approved before fieldwork; amendments approved | Last year’s program reused; amendments unrecorded |
| 14.1 Gathering information | Population records with completeness checks; sampling design; reliability assessed; evidence retained | Samples from unreconciled populations; management assertions as evidence |
| 14.2 Analyses and potential findings | Analyses; condition and criteria for each potential finding; management discussion recorded | Findings appearing first in the draft report |
| 14.3 Evaluation of findings | Significance evaluated; rating on the scale with rationale; root cause | Ratings without rationale; cause stated as the condition restated |
| 14.4 Recommendations and action plans | Recommendations addressing cause; management responses with owners and dates; accepted risks recorded | Action plans that treat symptoms; no owner or date |
| 14.5 Conclusions | Engagement conclusion on the objectives; rating methodology applied | Report with findings and no conclusion, or a conclusion the findings do not support |
| 14.6 Documentation | Complete file; review evidence; retention; access control | Evidence in mailboxes; reviews unsigned; files never closed |
| 15.1 Final communication | Report with all required elements; distribution record; conformance statement | No conformance statement; distribution decided by management |
| 15.2 Confirming implementation | Follow-up process; validation proportionate to significance; reporting to board; escalation of overdue actions | Tracking without validation; overdue actions not escalated |
Advisory engagements and the Topical Requirements
Domain V applies to advisory engagements with the adjustments the Standards describe: the objectives and scope are agreed with the party requesting the service, the criteria may be the requester’s own goals, the communication is to the requester, and the conclusion may be advice rather than an opinion, but the risk assessment, the work program, the evidence standard and the documentation requirements apply. A function that treats advisory work as exempt from the domain produces files that cannot show what was done, and an advisory engagement in an area the function later audits raises the objectivity questions the Domain II guide covers. The Topical Requirements add a layer to assurance engagements on their subjects: mandatory for assurance and recommended for advisory, each requirement assessed or documented as not applicable, with conformance documented under 14.6 and stated under 15.1; the Topical Requirements guide covers the family, and the cybersecurity requirement is the one most functions meet first.
The engagement conformance checklist
One checklist per engagement, completed by the reviewer at file close and used by the QAIP’s ongoing monitoring under Standard 12.1. It is deliberately short; the detail sits in the workpapers it references.
Engagement conformance checklist (Domain V)
Planning. 13.1 Notification issued with objectives, scope, timing and people; kickoff and closing meetings recorded. 13.2 Engagement risk assessment documented and used. 13.3 Objectives, scope, exclusions, period, locations and limitations in the planning memo. 13.4 Criteria stated per objective with sources; management agreement recorded. 13.5 Resources and skills assigned; external expertise arranged where needed. 13.6 Work program approved before fieldwork; amendments approved.
Fieldwork. 14.1 Populations reconciled; sampling designed and documented; evidence relevant, reliable and sufficient; IPE tested. 14.2 Analyses documented; potential findings with condition and criteria; facts confirmed with management. 14.3 Findings rated with rationale; root cause identified. 14.4 Recommendations address cause; action plans with owner and date; accepted risks recorded. 14.5 Engagement conclusion stated and supported; rating methodology applied. 14.6 File complete, reviewed with evidence of review, retained, access controlled.
Reporting and follow-up. 15.1 Final communication with objectives, scope, conclusion, findings, action plans, responses; quality criteria met; distribution recorded; conformance statement included (Standards and any Topical Requirement). 15.2 Actions entered in the follow-up process with validation approach set by significance.
Topical Requirement (if applicable). Requirements assessed or documented as not applicable; conformance record filed.
Sign-off. Reviewer; date; observations for the QAIP.
Worked example: MidState Beverage’s route cash audit through fourteen standards
MidState Beverage, the illustrative three-state drinks distributor used across this site, runs 300 routes from 12 depots and collects about $31 million a year in cash and checks. Its FY27 route cash audit, reported as FY27-01 and shown in full in the report examples guide, was the first engagement the function’s new quality program assessed against Domain V, and the assessment traced the file through all fourteen standards. The table is the trace.
| Standard | What the file showed | Assessment |
|---|---|---|
| 13.1 | Notification to the operations director and depot managers with objectives, scope, timing and the team; kickoff at three depots; weekly progress notes; closing meeting with the COO recorded | Conforms |
| 13.2 | Engagement risk assessment identifying driver-collected cash, depot reconciliation independence, override approvals and customer statements as the risks; used to set objectives | Conforms |
| 13.3 | Planning memo with four objectives, scope of all 12 depots and 300 routes for the fiscal year, exclusion of the two acquired distributors’ routes with the reason (separate systems, covered in the integration engagement) | Conforms |
| 13.4 | Criteria stated: the cash handling policy, the depot procedure, the delegation of authority for overrides, and, for statement practice, the auditor’s criterion with rationale; management agreed except on the statement criterion, recorded | Conforms; the disagreement recorded is cited as good practice |
| 13.5 | 520 hours budgeted, 548 used; one senior reassigned for objectivity (see the Domain II guide); analytics auditor assigned for the override population work | Conforms |
| 13.6 | Work program approved before fieldwork; amended once to add the override routing test after the walkthrough, with approval | Conforms |
| 14.1 | Populations reconciled (37,400 overrides; 4,200 customers; ~3,000 reconciliations); 60 reconciliations stratified five per depot; 70 monetary-unit selections at a $134,600 interval on $9,421,880 plus 20 targeted confirmations; IPE tested | Conforms |
| 14.2 | Analyses documented; five potential findings with condition and criteria; facts confirmed with depot managers and the operations director before the draft | Conforms |
| 14.3 | Findings rated (two High, three Medium) with rationale; root causes stated (a workflow routing rule; a depot administrator role designed for one person) | Conforms |
| 14.4 | Eleven actions with owners and dates addressing causes; the COO’s acceptance of residual risk on part of F5 recorded and escalated under 11.5 | Conforms |
| 14.5 | Unsatisfactory opinion under the rating methodology agreed with the audit committee; basis stated | Conforms |
| 14.6 | File complete in the audit management system; review notes cleared; two walkthrough workpapers missing the reviewer’s sign-off at close | Conforms with an observation |
| 15.1 | Report with all elements; distributed to the COO, CFO, CEO and the committee; conformance statement included | Conforms |
| 15.2 | Actions in the issue log; validation approach set (testing for the two High findings); at the assessment date, 3 of the function’s 14 open actions across engagements were past due without escalation to the committee | Partially conforms (function-level); escalation rule added, past-due actions reported at the next meeting |
The engagement conformed on thirteen standards, with an observation on documentation and a partial conformance on follow-up that was a function-level gap rather than this engagement’s: the tracking existed, the validation approach existed, and the escalation of overdue actions to the audit committee did not. That result, one of the three partial conformances the QAIP playbook records for MidState’s first assessment, is typical, and the fix, an escalation rule in the manual and a standing agenda line for past-due actions, took an afternoon. The file’s strength was the chain: every finding traced back through a procedure in the approved work program to an objective in the planning memo and forward to a rated finding, an action plan with an owner, and a conclusion the findings supported, which is what Domain V asks for in fourteen different ways.
Common mistakes
Skipping the engagement risk assessment because the annual one exists. Stating scope as a process name with no exclusions. Discovering the criteria after the findings. Reusing last year’s work program without approval of the changes. Sampling from populations nobody reconciled. Putting findings in the draft report before discussing the facts. Rating without rationale and naming the condition as the cause. Writing action plans that treat symptoms. Issuing reports with findings and no conclusion. Leaving the conformance statement out, or including it when the file cannot support it. Tracking actions without validating them. Never escalating overdue actions. And treating advisory engagements as outside the domain. The Domain IV guide covers the methodologies these standards are implemented through, the IPPF-to-GIAS mapping the old 2200 to 2600 series standards this domain descends from, and the QAIP self-assessment template the annual review in which the engagement checklists are aggregated.
Related guides
- The Global Internal Audit Standards: the complete guide
- GIAS Domain II: Ethics and Professionalism
- GIAS Domain III: Governing the Internal Audit Function
- GIAS Domain IV: Managing the Internal Audit Function
- Old IPPF to new GIAS: the complete mapping
- Audit notification letter and kickoff template
- Audit planning memo template
- The audit work program
- Walkthrough versus test of controls
- Audit evidence
- The 5 Cs of audit findings
- Root cause analysis for audit findings
- Finding severity ratings
- Internal audit report template
- Issue validation
- Audit issue log template
Leave a Reply