An internal audit of your area lasts a few weeks. The other ten or eleven months of the year decide how those weeks go. The managers who find audits uneventful are rarely the ones with flawless processes; they are the ones who treat internal audit as a year-round relationship. They tell the auditors about changes before the auditors find them, ask for advice before building something new rather than after it fails, check their own controls once a year with the last report in hand, and keep evidence as a habit rather than a scramble. None of that takes much time. It changes what the auditors expect to find, what they plan to test, and how the next report reads.
This guide covers the off-season: what internal audit is doing when it is not auditing you, the heads-ups that build credit, how to use the audit function’s advice without compromising its independence, a self-check ritual, evidence habits, keeping actions on track, the risk assessment interview that shapes next year’s plan, the honest version of the pre-audit tidy-up, and a month-by-month calendar. A worked example follows a treasury operations manager whose area went from two middling reports to a clean one. The weeks of the audit itself are covered in the site’s guide to what to expect during an internal audit.
In this guide
- What internal audit is doing when it is not auditing you
- Heads-ups that build credit
- Asking internal audit for advice before you build
- Your own annual check
- Audit-ready by default: evidence habits
- Keeping your actions on track between audits
- Your audit contact, and how to use them
- When the organization changes around you
- Metrics worth watching between audits
- The risk assessment interview: your chance to shape the plan
- The pre-audit tidy-up, the honest version
- A process owner’s year, month by month
- Worked example: from two middling reports to a clean one
- Questions auditees ask about the off-season
- Related guides
What internal audit is doing when it is not auditing you
The audit function’s year does not stop between engagements, and several of its activities touch your area whether or not you are in this year’s plan. Two rules in the Global Internal Audit Standards explain why the off-season matters. Standard 9.4 requires the audit plan to be based on a documented assessment of the organization’s strategies, objectives and risks, performed at least annually, informed by the board and senior management, and updated promptly when the business, its systems or its risks change. Standard 11.1 requires the chief audit executive to build relationships and trust with stakeholders, including operational management, and to promote formal and informal communication about risks, controls and changes. In plain terms, internal audit is supposed to be listening all year, and what it hears shapes where it looks.
| Activity | When | How it touches you |
|---|---|---|
| Annual risk assessment and plan | Usually the last quarter before the audit year starts | An interview or survey asking about your risks, changes and concerns; the plan the audit committee approves |
| Plan updates | During the year, when risks change | An engagement added, moved or dropped because of something that happened |
| Continuous monitoring and analytics | Ongoing in many functions | Questions about anomalies in your data, often small and quick if answered promptly |
| Follow-up and validation | On your action due dates | Requests for status and for evidence that fixes work |
| Advisory work | When requested | Reviews of a new process, system or policy before it goes live |
| Relationship meetings | Quarterly or twice a year in larger functions | A standing conversation with your assigned audit contact |
| Audit committee reporting | Every quarter | Your area’s open and overdue actions, listed by name |
Heads-ups that build credit
The cheapest thing you can do for your next audit is to tell internal audit about significant changes when they happen, not when an auditor finds them. A change the auditors learned about from you is context; the same change discovered in fieldwork is a question about why nobody mentioned it. The rule is simple: tell early, tell in writing, and say what you are doing about it. The table lists the changes that matter most.
| Change | Why internal audit wants to know | When to tell them |
|---|---|---|
| A new system or a major upgrade | Controls move into configuration or disappear in migration | At project start, while design can still change |
| A reorganization or key people leaving | Controls lose their owners and performers | Before the effective date |
| A new product, business line or acquisition | New risks with no controls yet | When it is announced internally |
| A control failure or incident you found | It changes the risk picture; self-identified issues are treated differently from ones the auditors find | Promptly, with the fix you are making |
| Contact from a regulator or a finding from the external auditor | Coordination, and possible changes to the audit plan | The same week |
| A new outsourcing arrangement or change of key vendor | Third-party risk and a new set of controls at the provider | At the contract stage |
| A process redesign or automation | Controls can be built in, or lost, in redesign | At design, not at go-live |
| A significant policy change | The criteria the next audit will test against have changed | When approved |
Self-identified problems deserve a note of their own. In most audit functions, an issue management found and disclosed, with a credible fix under way, is rated with that context and reported as management-identified, if it is reported at all. The identical issue found by the auditors after management knew about it is rated more severely, and the fact that management knew becomes part of the cause. The incentive could not be clearer.
Asking internal audit for advice before you build
Most audit functions offer advisory services alongside assurance, and the most valuable use of them for a process owner is a review of control design before something new goes live. A gap found in a design review costs a configuration change; the same gap found in an audit a year later costs a finding, a remediation project and a validation. Advisory work has limits worth knowing. The auditors will review and advise; they will not design your controls, approve your decisions or take ownership of the process, because doing so would compromise their objectivity when they later audit it. Standard 2.2 of the Global Internal Audit Standards requires the chief audit executive, before assurance work on an area where the function earlier gave advice, to confirm that the advice did not impair objectivity and to staff the engagement accordingly. The practical upshot: advice now does not buy an easier audit later, but it does make the audit find less.
| A good advisory request | A poor one |
|---|---|
| “We go live with a new payments platform in four months. Can you review the approval and access design against the risks you would test?” | “Can you design the controls for our new platform?” |
| “The new regulation applies from next year. Can you do a readiness review of our process against it?” | “Can you confirm we are compliant, so we can tell the regulator?” |
| “We are redesigning the month-end close. Could you facilitate a risk workshop with the team?” | “Can you sign off the new close procedure?” |
| “We found a weakness in our reconciliation process. Would you look at our proposed fix before we build it?” | “Please don’t mention this weakness in the next audit.” |
A pre-implementation review usually looks at four things: whether the approval and access design separates the people who set up, change and release transactions; whether the controls the old process relied on have been rebuilt or deliberately retired; whether the reports the new process depends on will be complete and accurate; and whether data migrating from the old system will be reconciled. Ask for the review early enough that its answers can still change the design, which in most projects means before build starts rather than during testing. A review requested two weeks before go-live can only tell you what will go wrong.
Your own annual check
The single habit that most reliably turns a middling rating into a clean one is an annual self-check: once a year, and again a couple of months before any scheduled audit, walk your own process with the last audit report beside you and test your key controls the way an auditor would, on a small scale. It takes a day or two. It finds the drift that creeps in as staff change and systems update, and it gives you the chance to fix problems and disclose them before anyone else finds them. If your organization runs a formal risk and control self-assessment, this is the same idea done with the auditor’s lens.
| Step | What you do | Time |
|---|---|---|
| 1. Reread the last report | List every finding, its action and its status; note any that closed and could have drifted back | 30 minutes |
| 2. Walk the process | Follow one real transaction end to end with the person who does it, asking at each step what could go wrong and what stops it | Two hours |
| 3. Test the key controls | Pick five recent operations of each key control and check the evidence is there, dated and complete | Half a day |
| 4. Check what changed | New systems, people, volumes, vendors, policies since the last audit | An hour |
| 5. Fix and record | Fix what you can, note what you cannot, and write a one-page summary | Varies |
| 6. Tell internal audit | Send the summary to your audit contact; most functions welcome it, and it feeds their risk assessment | Ten minutes |
Five operations is not a statistical sample, and it is not meant to be. The point is to catch the obvious: the review nobody has signed since the reviewer left, the report whose parameters were changed in the upgrade, the access list that still includes last year’s contractor. The auditors will test properly; your job is to make sure they are not the first to notice.
Audit-ready by default: evidence habits
Evidence produced at the time a control operates is worth far more than evidence assembled when the auditors ask, and it costs almost nothing to keep if the habit is built into the process. From an auditor’s chair a control that operated but left no trace cannot be told apart from one that did not operate. The table lists the evidence that most often goes missing.
| Control | Evidence to keep at the time | Where |
|---|---|---|
| Reconciliations | The reconciliation with preparer and reviewer names and dates, and notes on reconciling items | A folder by period, or the reconciliation tool |
| Management reviews | What was reviewed, the thresholds used, the questions asked and how they were resolved | With the reviewed report, not in someone’s inbox |
| Approvals | The approval in the system workflow, or a dated signature on the document | The system of record |
| Access reviews | The user list reviewed, the reviewer’s decisions and evidence that removals were made | The ticketing system or a review folder |
| Changes to systems or configurations | The change request, approval, testing and go-live date | The change management tool |
| Exceptions and overrides | Who approved each and why | The system log, with a reason field completed |
Keep the evidence for at least as long as the audit cycle for your area, and longer where regulation or your records policy requires it. Auditors test a period, usually the twelve months before fieldwork, and validation of an old action can reach back further. A folder structure by control and period, set up once, removes most of the pain: the evidence goes in as the control operates, and the request list becomes a matter of pointing to the right folder.
Keeping your actions on track between audits
Open actions from the last audit are the part of the off-season the audit committee sees, because overdue items are reported by name every quarter. Send your audit contact a one-line status on each action every month whether or not they ask, keep the evidence as you implement, and ask for any extension before the due date with a reason and a new date. When an action is done, report it only after the new control has run long enough to be tested, and send the evidence with the notice. The guide to writing management action plans that close covers the whole cycle, and the life of an audit finding shows where each step sits.
Your audit contact, and how to use them
Many audit functions assign each business area a named contact, often an audit manager, who owns the relationship between engagements. If yours does, use that person deliberately. A short quarterly conversation with a standing agenda keeps the auditors’ picture of your area current and gives you early warning of what they are thinking about. If your function does not assign contacts, ask who the audit manager responsible for your area is and treat them the same way. What the contact will not do is pre-clear findings or tell you what the next audit will conclude; the relationship is about information flowing both ways, not about negotiating outcomes in advance.
| Agenda item | What you bring | What you can ask for |
|---|---|---|
| Changes since last time | Systems, people, volumes, vendors, policies | Whether any change affects the plan or needs an advisory look |
| Open actions | Status, evidence gathered, any date at risk | Agreement on the evidence the validation will need |
| Upcoming projects | Anything you are designing or implementing in the next six months | A design review before go-live |
| Concerns | What worries you about your own area | Their view, and whether other areas have solved the same problem |
| The audit function’s plans | Nothing | When your area is next in the plan, and any themes the function is looking at across the organization |
When the organization changes around you
Reorganizations, acquisitions, new leaders and outsourcing decisions are where the off-season goes wrong most often, because they move controls and open actions without anyone deciding what should happen to them. An action owned by someone who has left the company does not close itself; it goes overdue under a name nobody recognizes, and the auditors come looking for whoever inherited the process. When a change is coming, decide what happens to each control and each open action before the change takes effect, record it, and tell internal audit.
| Change | What tends to happen to controls and actions | What to do |
|---|---|---|
| A control owner or action owner leaves | The control keeps running from habit, then stops; the action goes overdue under the departed name | Name a new owner before the departure, hand over the evidence, and tell your audit contact |
| A reorganization moves the process | Controls split between teams, or fall between them | Map every key control to its new owner and performer on the day the new structure starts |
| The process is outsourced | Controls move to the provider and the organization keeps only the monitoring, often without realizing it | Decide which controls the provider performs, how you will monitor them, and what evidence you will receive |
| An acquisition brings a second version of your process | Two sets of controls, one of them unaudited | Ask internal audit how it plans to cover the acquired process, and share what you know about it |
| A system replacement changes how the process works | An open action written for the old system becomes impossible | Propose a replacement action for the new system before the old date passes |
The site’s guide to control ownership sets out a register and a handover checklist that make these transitions routine rather than accidental.
Metrics worth watching between audits
A handful of simple numbers, looked at monthly, will tell you when a process is drifting long before an auditor does. None of them needs a new system; most come from reports you already have. Pick the ones that fit your process, set a threshold that would make you look closer, and note what you did when a threshold was crossed. That note is also useful evidence of management monitoring when the auditors arrive.
| Metric | What a rise usually means |
|---|---|
| Overrides and manual exceptions as a share of transactions | A control is being bypassed because it gets in the way, or a system rule is wrong |
| Reviews or reconciliations completed late | Capacity problems, often after someone leaves |
| Reconciling items older than 60 or 90 days | Problems being carried rather than resolved |
| Access changes outside the normal request process | Emergency access that is not being cleaned up |
| Errors found downstream (by customers, suppliers or another team) | A preventive control that is not working |
| Open audit actions past or near their due date | The fixes are losing priority |
The risk assessment interview: your chance to shape the plan
Once a year, usually a few months before the audit year begins, someone from internal audit will ask for an hour to discuss your area’s risks. This is the input to the risk assessment the plan is built on, and it is the one conversation in which you can legitimately influence what gets audited and when. Be candid about what worries you; a risk you name is one the plan can address, often through an advisory review rather than an audit. Mention the changes coming in the next year, because the plan is supposed to reflect them. Flag timing constraints, such as a system go-live or a peak season, since audit functions would rather schedule around them than collide with them. And if there is an area you would like audited, ask; a manager who requests assurance over a process they are worried about is doing exactly what the Standards expect management to do.
What not to do is lobby to be left out. Auditors hear that often, it does not work, and it raises exactly the question you were hoping to avoid. The site’s guide to how audit plans choose what gets audited explains the scoring behind the plan, and the risk assessment playbook shows the auditors’ side of the interview.
The pre-audit tidy-up, the honest version
Every manager tidies up before an audit. Some of it helps and some of it does real damage, and the line between them is whether you are organizing what exists or creating what should have existed. Auditors test the period before the tidy-up anyway, and file dates, version histories and metadata make retrospective work easy to spot.
| Fine, and useful | Not fine, and noticed |
|---|---|
| Gathering existing evidence into one place, organized by control and period | Completing reconciliations or reviews now for months when they were not done |
| Fixing a problem you found in your self-check, and telling the auditors you fixed it and when | Fixing it quietly and hoping the earlier period is not tested |
| Updating a procedure that is genuinely out of date, with the real approval date | Rewriting a procedure the week before fieldwork and presenting it as long-standing |
| Briefing the team on what a walkthrough is and that honest answers are expected | Coaching the team on what to say |
| Checking that the reports and extracts you will be asked for can be produced | Editing or filtering those reports before they are sent |
The right column is not a gray area. A document created for the audit and presented as if it existed earlier turns a control finding into an integrity finding, and it changes how everything else you provide is read. If something was not done, say so, show what you have done since, and let the auditors weigh it. The site’s guide to preparing for an internal audit sets out a month of legitimate preparation in detail.
A process owner’s year, month by month
The calendar below assumes an audit of your area happened at the start of the year and the next one is due in twelve to eighteen months. The rhythm is light: a few hours a month for most of the year, more around the self-check and the risk interview.
| When | What to do | Roughly how long |
|---|---|---|
| Month 1 | Final report issued; brief your team; confirm action owners, dates and the evidence each will keep | Half a day |
| Months 2 to 6 | Implement actions; monthly status to your audit contact; keep evidence as you go; heads-ups as changes happen | Two to four hours a month |
| Month 3 | Quarterly check-in with your audit contact, if the function runs them | An hour |
| Month 6 | Mid-year self-check, focused on controls touched by the actions | A day |
| Months 6 to 9 | Report actions complete once they have operated; support validation | A few hours per action |
| Month 9 | Risk assessment interview for next year’s plan | An hour, plus preparation |
| Months 10 to 12 | Full self-check; fix and disclose; update procedures that have drifted; send your one-page summary | One to two days |
| Next audit | Request list triage in 48 hours; one coordinator; the evidence is already where it should be | See the request list guide |
Worked example: from two middling reports to a clean one
This example is a composite, drawn from common situations. The treasury operations manager at a mid-sized company had two consecutive audits of payments rated Needs Improvement, each with three or four Medium findings and a couple of repeats. Nothing was badly wrong; things drifted between audits, and each audit found the drift. After the second report she changed how her team worked with internal audit between engagements.
| What she did | What it produced |
|---|---|
| Sent a monthly one-line status on each open action, and reported actions complete only after a month of operation, with evidence attached | All six actions validated closed on the first attempt; none ever appeared on the overdue list |
| Told internal audit, at project start, that the company was moving to a new payments platform | A pre-implementation advisory review, about 60 hours of the audit function’s time, found that payment templates could be edited by the same users who released payments; the permission was split before go-live |
| Gave four heads-ups over the year: the platform, a senior analyst leaving, a bank changing its file format, and a reconciliation backlog during the analyst’s vacancy | The backlog, disclosed with its fix, was noted in the next report as management-identified and closed |
| Ran two self-checks: one at mid-year, one two months before the next audit | Found that the new platform’s daily exception report had not been reviewed for three weeks after go-live; fixed and disclosed |
| Used the risk interview to ask for the next audit to wait until the platform had run for a full quarter | The audit was scheduled accordingly, and tested a stable process |
The next audit was rated Satisfactory with one Low finding. The team estimated its off-season effort at two to three hours a month for the manager and less for everyone else, a fraction of what the two previous remediation cycles had cost. The difference was not better controls in the abstract. It was that the auditors arrived to a process they already understood, with its problems already disclosed and fixed, and very little left to find.
Just as telling is what the team stopped doing. It stopped the two-week scramble before each audit, because the evidence was already filed. It stopped arguing ratings in closing meetings, because there was little left to argue about. And it stopped treating the audit function as something that happened to it once every eighteen months. The manager’s own summary to her director was two sentences long: the auditors now learn about our problems from us, and they find fewer of them because we have usually fixed them first.
Questions auditees ask about the off-season
If I tell internal audit about a problem, will it end up in a report?
It may, but it will read very differently. Most functions report a disclosed issue with a credible fix as management-identified, rate it with that context, and sometimes simply track it. The same issue found by the auditors later, after you knew about it, is rated higher and the delay becomes part of the cause.
Can I ask internal audit to audit my area?
Yes. Requested engagements are a normal part of an audit plan, and the plan is expected to respond to management’s concerns. If a full audit is not warranted, an advisory review may be offered instead.
Does asking for advice make the next audit easier?
It makes the next audit find less, which is not the same thing. The audit will be as rigorous as ever, and the function has to confirm its objectivity before auditing something it advised on. What changes is that the design problems were fixed before they could become findings.
How often should I talk to internal audit when I am not being audited?
Whenever something significant changes, plus the risk assessment interview once a year. Larger functions assign a relationship contact to each business area and meet quarterly; if yours does not, a short note to the audit manager responsible for your area when things change is enough.
What should I keep from the last audit?
The final report, your management responses, the evidence for every action you closed, the request list with everything you sent, and your own notes on what surprised you. The next audit starts from the last report, the auditors will retest what closed, and a repeat finding is rated higher; the old file is the fastest way to make sure nothing drifted back.
Should I share my self-check with internal audit?
In most organizations, yes. A one-page summary of what you checked, what you found and what you fixed feeds the audit function’s risk assessment and shows management monitoring its own controls. It will not replace the auditors’ testing, and it should not claim to, but it changes the conversation at the start of the next audit.
Related guides
- Being audited? — every guide for auditees and management, by stage of the audit.
- What to expect during an internal audit — the weeks of the audit itself.
- How to prepare for an internal audit — the month before fieldwork.
- When will internal audit come? — how audit plans choose what gets audited.
- Writing management action plans that close — the cycle from response to validation.
- The PBC survival guide — handling the request list when the audit arrives.
- Why welcome an internal audit — what your area can get out of one.
- Control ownership — keeping controls owned through reorganizations.
- The RCSA process — formal self-assessment of risks and controls.
- The annual internal audit risk assessment — the auditors’ side of the risk interview.
- Issue validation — what the auditors test when you close an action.
Leave a Reply