,

Living With Internal Audit Year-Round: The Auditee’s Guide to the Off-Season

An internal audit of your area lasts a few weeks. The other ten or eleven months of the year decide how those weeks go. The managers who find audits uneventful are rarely the ones with flawless processes; they are the ones who treat internal audit as a year-round relationship. They tell the auditors about changes before the auditors find them, ask for advice before building something new rather than after it fails, check their own controls once a year with the last report in hand, and keep evidence as a habit rather than a scramble. None of that takes much time. It changes what the auditors expect to find, what they plan to test, and how the next report reads.

This guide covers the off-season: what internal audit is doing when it is not auditing you, the heads-ups that build credit, how to use the audit function’s advice without compromising its independence, a self-check ritual, evidence habits, keeping actions on track, the risk assessment interview that shapes next year’s plan, the honest version of the pre-audit tidy-up, and a month-by-month calendar. A worked example follows a treasury operations manager whose area went from two middling reports to a clean one. The weeks of the audit itself are covered in the site’s guide to what to expect during an internal audit.

In this guide

What internal audit is doing when it is not auditing you

The audit function’s year does not stop between engagements, and several of its activities touch your area whether or not you are in this year’s plan. Two rules in the Global Internal Audit Standards explain why the off-season matters. Standard 9.4 requires the audit plan to be based on a documented assessment of the organization’s strategies, objectives and risks, performed at least annually, informed by the board and senior management, and updated promptly when the business, its systems or its risks change. Standard 11.1 requires the chief audit executive to build relationships and trust with stakeholders, including operational management, and to promote formal and informal communication about risks, controls and changes. In plain terms, internal audit is supposed to be listening all year, and what it hears shapes where it looks.

ActivityWhenHow it touches you
Annual risk assessment and planUsually the last quarter before the audit year startsAn interview or survey asking about your risks, changes and concerns; the plan the audit committee approves
Plan updatesDuring the year, when risks changeAn engagement added, moved or dropped because of something that happened
Continuous monitoring and analyticsOngoing in many functionsQuestions about anomalies in your data, often small and quick if answered promptly
Follow-up and validationOn your action due datesRequests for status and for evidence that fixes work
Advisory workWhen requestedReviews of a new process, system or policy before it goes live
Relationship meetingsQuarterly or twice a year in larger functionsA standing conversation with your assigned audit contact
Audit committee reportingEvery quarterYour area’s open and overdue actions, listed by name

Heads-ups that build credit

The cheapest thing you can do for your next audit is to tell internal audit about significant changes when they happen, not when an auditor finds them. A change the auditors learned about from you is context; the same change discovered in fieldwork is a question about why nobody mentioned it. The rule is simple: tell early, tell in writing, and say what you are doing about it. The table lists the changes that matter most.

ChangeWhy internal audit wants to knowWhen to tell them
A new system or a major upgradeControls move into configuration or disappear in migrationAt project start, while design can still change
A reorganization or key people leavingControls lose their owners and performersBefore the effective date
A new product, business line or acquisitionNew risks with no controls yetWhen it is announced internally
A control failure or incident you foundIt changes the risk picture; self-identified issues are treated differently from ones the auditors findPromptly, with the fix you are making
Contact from a regulator or a finding from the external auditorCoordination, and possible changes to the audit planThe same week
A new outsourcing arrangement or change of key vendorThird-party risk and a new set of controls at the providerAt the contract stage
A process redesign or automationControls can be built in, or lost, in redesignAt design, not at go-live
A significant policy changeThe criteria the next audit will test against have changedWhen approved

Self-identified problems deserve a note of their own. In most audit functions, an issue management found and disclosed, with a credible fix under way, is rated with that context and reported as management-identified, if it is reported at all. The identical issue found by the auditors after management knew about it is rated more severely, and the fact that management knew becomes part of the cause. The incentive could not be clearer.

Asking internal audit for advice before you build

Most audit functions offer advisory services alongside assurance, and the most valuable use of them for a process owner is a review of control design before something new goes live. A gap found in a design review costs a configuration change; the same gap found in an audit a year later costs a finding, a remediation project and a validation. Advisory work has limits worth knowing. The auditors will review and advise; they will not design your controls, approve your decisions or take ownership of the process, because doing so would compromise their objectivity when they later audit it. Standard 2.2 of the Global Internal Audit Standards requires the chief audit executive, before assurance work on an area where the function earlier gave advice, to confirm that the advice did not impair objectivity and to staff the engagement accordingly. The practical upshot: advice now does not buy an easier audit later, but it does make the audit find less.

A good advisory requestA poor one
“We go live with a new payments platform in four months. Can you review the approval and access design against the risks you would test?”“Can you design the controls for our new platform?”
“The new regulation applies from next year. Can you do a readiness review of our process against it?”“Can you confirm we are compliant, so we can tell the regulator?”
“We are redesigning the month-end close. Could you facilitate a risk workshop with the team?”“Can you sign off the new close procedure?”
“We found a weakness in our reconciliation process. Would you look at our proposed fix before we build it?”“Please don’t mention this weakness in the next audit.”

A pre-implementation review usually looks at four things: whether the approval and access design separates the people who set up, change and release transactions; whether the controls the old process relied on have been rebuilt or deliberately retired; whether the reports the new process depends on will be complete and accurate; and whether data migrating from the old system will be reconciled. Ask for the review early enough that its answers can still change the design, which in most projects means before build starts rather than during testing. A review requested two weeks before go-live can only tell you what will go wrong.

Your own annual check

The single habit that most reliably turns a middling rating into a clean one is an annual self-check: once a year, and again a couple of months before any scheduled audit, walk your own process with the last audit report beside you and test your key controls the way an auditor would, on a small scale. It takes a day or two. It finds the drift that creeps in as staff change and systems update, and it gives you the chance to fix problems and disclose them before anyone else finds them. If your organization runs a formal risk and control self-assessment, this is the same idea done with the auditor’s lens.

StepWhat you doTime
1. Reread the last reportList every finding, its action and its status; note any that closed and could have drifted back30 minutes
2. Walk the processFollow one real transaction end to end with the person who does it, asking at each step what could go wrong and what stops itTwo hours
3. Test the key controlsPick five recent operations of each key control and check the evidence is there, dated and completeHalf a day
4. Check what changedNew systems, people, volumes, vendors, policies since the last auditAn hour
5. Fix and recordFix what you can, note what you cannot, and write a one-page summaryVaries
6. Tell internal auditSend the summary to your audit contact; most functions welcome it, and it feeds their risk assessmentTen minutes

Five operations is not a statistical sample, and it is not meant to be. The point is to catch the obvious: the review nobody has signed since the reviewer left, the report whose parameters were changed in the upgrade, the access list that still includes last year’s contractor. The auditors will test properly; your job is to make sure they are not the first to notice.

Audit-ready by default: evidence habits

Evidence produced at the time a control operates is worth far more than evidence assembled when the auditors ask, and it costs almost nothing to keep if the habit is built into the process. From an auditor’s chair a control that operated but left no trace cannot be told apart from one that did not operate. The table lists the evidence that most often goes missing.

ControlEvidence to keep at the timeWhere
ReconciliationsThe reconciliation with preparer and reviewer names and dates, and notes on reconciling itemsA folder by period, or the reconciliation tool
Management reviewsWhat was reviewed, the thresholds used, the questions asked and how they were resolvedWith the reviewed report, not in someone’s inbox
ApprovalsThe approval in the system workflow, or a dated signature on the documentThe system of record
Access reviewsThe user list reviewed, the reviewer’s decisions and evidence that removals were madeThe ticketing system or a review folder
Changes to systems or configurationsThe change request, approval, testing and go-live dateThe change management tool
Exceptions and overridesWho approved each and whyThe system log, with a reason field completed

Keep the evidence for at least as long as the audit cycle for your area, and longer where regulation or your records policy requires it. Auditors test a period, usually the twelve months before fieldwork, and validation of an old action can reach back further. A folder structure by control and period, set up once, removes most of the pain: the evidence goes in as the control operates, and the request list becomes a matter of pointing to the right folder.

Keeping your actions on track between audits

Open actions from the last audit are the part of the off-season the audit committee sees, because overdue items are reported by name every quarter. Send your audit contact a one-line status on each action every month whether or not they ask, keep the evidence as you implement, and ask for any extension before the due date with a reason and a new date. When an action is done, report it only after the new control has run long enough to be tested, and send the evidence with the notice. The guide to writing management action plans that close covers the whole cycle, and the life of an audit finding shows where each step sits.

Your audit contact, and how to use them

Many audit functions assign each business area a named contact, often an audit manager, who owns the relationship between engagements. If yours does, use that person deliberately. A short quarterly conversation with a standing agenda keeps the auditors’ picture of your area current and gives you early warning of what they are thinking about. If your function does not assign contacts, ask who the audit manager responsible for your area is and treat them the same way. What the contact will not do is pre-clear findings or tell you what the next audit will conclude; the relationship is about information flowing both ways, not about negotiating outcomes in advance.

Agenda itemWhat you bringWhat you can ask for
Changes since last timeSystems, people, volumes, vendors, policiesWhether any change affects the plan or needs an advisory look
Open actionsStatus, evidence gathered, any date at riskAgreement on the evidence the validation will need
Upcoming projectsAnything you are designing or implementing in the next six monthsA design review before go-live
ConcernsWhat worries you about your own areaTheir view, and whether other areas have solved the same problem
The audit function’s plansNothingWhen your area is next in the plan, and any themes the function is looking at across the organization

When the organization changes around you

Reorganizations, acquisitions, new leaders and outsourcing decisions are where the off-season goes wrong most often, because they move controls and open actions without anyone deciding what should happen to them. An action owned by someone who has left the company does not close itself; it goes overdue under a name nobody recognizes, and the auditors come looking for whoever inherited the process. When a change is coming, decide what happens to each control and each open action before the change takes effect, record it, and tell internal audit.

ChangeWhat tends to happen to controls and actionsWhat to do
A control owner or action owner leavesThe control keeps running from habit, then stops; the action goes overdue under the departed nameName a new owner before the departure, hand over the evidence, and tell your audit contact
A reorganization moves the processControls split between teams, or fall between themMap every key control to its new owner and performer on the day the new structure starts
The process is outsourcedControls move to the provider and the organization keeps only the monitoring, often without realizing itDecide which controls the provider performs, how you will monitor them, and what evidence you will receive
An acquisition brings a second version of your processTwo sets of controls, one of them unauditedAsk internal audit how it plans to cover the acquired process, and share what you know about it
A system replacement changes how the process worksAn open action written for the old system becomes impossiblePropose a replacement action for the new system before the old date passes

The site’s guide to control ownership sets out a register and a handover checklist that make these transitions routine rather than accidental.

Metrics worth watching between audits

A handful of simple numbers, looked at monthly, will tell you when a process is drifting long before an auditor does. None of them needs a new system; most come from reports you already have. Pick the ones that fit your process, set a threshold that would make you look closer, and note what you did when a threshold was crossed. That note is also useful evidence of management monitoring when the auditors arrive.

MetricWhat a rise usually means
Overrides and manual exceptions as a share of transactionsA control is being bypassed because it gets in the way, or a system rule is wrong
Reviews or reconciliations completed lateCapacity problems, often after someone leaves
Reconciling items older than 60 or 90 daysProblems being carried rather than resolved
Access changes outside the normal request processEmergency access that is not being cleaned up
Errors found downstream (by customers, suppliers or another team)A preventive control that is not working
Open audit actions past or near their due dateThe fixes are losing priority

The risk assessment interview: your chance to shape the plan

Once a year, usually a few months before the audit year begins, someone from internal audit will ask for an hour to discuss your area’s risks. This is the input to the risk assessment the plan is built on, and it is the one conversation in which you can legitimately influence what gets audited and when. Be candid about what worries you; a risk you name is one the plan can address, often through an advisory review rather than an audit. Mention the changes coming in the next year, because the plan is supposed to reflect them. Flag timing constraints, such as a system go-live or a peak season, since audit functions would rather schedule around them than collide with them. And if there is an area you would like audited, ask; a manager who requests assurance over a process they are worried about is doing exactly what the Standards expect management to do.

What not to do is lobby to be left out. Auditors hear that often, it does not work, and it raises exactly the question you were hoping to avoid. The site’s guide to how audit plans choose what gets audited explains the scoring behind the plan, and the risk assessment playbook shows the auditors’ side of the interview.

The pre-audit tidy-up, the honest version

Every manager tidies up before an audit. Some of it helps and some of it does real damage, and the line between them is whether you are organizing what exists or creating what should have existed. Auditors test the period before the tidy-up anyway, and file dates, version histories and metadata make retrospective work easy to spot.

Fine, and usefulNot fine, and noticed
Gathering existing evidence into one place, organized by control and periodCompleting reconciliations or reviews now for months when they were not done
Fixing a problem you found in your self-check, and telling the auditors you fixed it and whenFixing it quietly and hoping the earlier period is not tested
Updating a procedure that is genuinely out of date, with the real approval dateRewriting a procedure the week before fieldwork and presenting it as long-standing
Briefing the team on what a walkthrough is and that honest answers are expectedCoaching the team on what to say
Checking that the reports and extracts you will be asked for can be producedEditing or filtering those reports before they are sent

The right column is not a gray area. A document created for the audit and presented as if it existed earlier turns a control finding into an integrity finding, and it changes how everything else you provide is read. If something was not done, say so, show what you have done since, and let the auditors weigh it. The site’s guide to preparing for an internal audit sets out a month of legitimate preparation in detail.

A process owner’s year, month by month

The calendar below assumes an audit of your area happened at the start of the year and the next one is due in twelve to eighteen months. The rhythm is light: a few hours a month for most of the year, more around the self-check and the risk interview.

WhenWhat to doRoughly how long
Month 1Final report issued; brief your team; confirm action owners, dates and the evidence each will keepHalf a day
Months 2 to 6Implement actions; monthly status to your audit contact; keep evidence as you go; heads-ups as changes happenTwo to four hours a month
Month 3Quarterly check-in with your audit contact, if the function runs themAn hour
Month 6Mid-year self-check, focused on controls touched by the actionsA day
Months 6 to 9Report actions complete once they have operated; support validationA few hours per action
Month 9Risk assessment interview for next year’s planAn hour, plus preparation
Months 10 to 12Full self-check; fix and disclose; update procedures that have drifted; send your one-page summaryOne to two days
Next auditRequest list triage in 48 hours; one coordinator; the evidence is already where it should beSee the request list guide

Worked example: from two middling reports to a clean one

This example is a composite, drawn from common situations. The treasury operations manager at a mid-sized company had two consecutive audits of payments rated Needs Improvement, each with three or four Medium findings and a couple of repeats. Nothing was badly wrong; things drifted between audits, and each audit found the drift. After the second report she changed how her team worked with internal audit between engagements.

What she didWhat it produced
Sent a monthly one-line status on each open action, and reported actions complete only after a month of operation, with evidence attachedAll six actions validated closed on the first attempt; none ever appeared on the overdue list
Told internal audit, at project start, that the company was moving to a new payments platformA pre-implementation advisory review, about 60 hours of the audit function’s time, found that payment templates could be edited by the same users who released payments; the permission was split before go-live
Gave four heads-ups over the year: the platform, a senior analyst leaving, a bank changing its file format, and a reconciliation backlog during the analyst’s vacancyThe backlog, disclosed with its fix, was noted in the next report as management-identified and closed
Ran two self-checks: one at mid-year, one two months before the next auditFound that the new platform’s daily exception report had not been reviewed for three weeks after go-live; fixed and disclosed
Used the risk interview to ask for the next audit to wait until the platform had run for a full quarterThe audit was scheduled accordingly, and tested a stable process

The next audit was rated Satisfactory with one Low finding. The team estimated its off-season effort at two to three hours a month for the manager and less for everyone else, a fraction of what the two previous remediation cycles had cost. The difference was not better controls in the abstract. It was that the auditors arrived to a process they already understood, with its problems already disclosed and fixed, and very little left to find.

Just as telling is what the team stopped doing. It stopped the two-week scramble before each audit, because the evidence was already filed. It stopped arguing ratings in closing meetings, because there was little left to argue about. And it stopped treating the audit function as something that happened to it once every eighteen months. The manager’s own summary to her director was two sentences long: the auditors now learn about our problems from us, and they find fewer of them because we have usually fixed them first.

Questions auditees ask about the off-season

If I tell internal audit about a problem, will it end up in a report?

It may, but it will read very differently. Most functions report a disclosed issue with a credible fix as management-identified, rate it with that context, and sometimes simply track it. The same issue found by the auditors later, after you knew about it, is rated higher and the delay becomes part of the cause.

Can I ask internal audit to audit my area?

Yes. Requested engagements are a normal part of an audit plan, and the plan is expected to respond to management’s concerns. If a full audit is not warranted, an advisory review may be offered instead.

Does asking for advice make the next audit easier?

It makes the next audit find less, which is not the same thing. The audit will be as rigorous as ever, and the function has to confirm its objectivity before auditing something it advised on. What changes is that the design problems were fixed before they could become findings.

How often should I talk to internal audit when I am not being audited?

Whenever something significant changes, plus the risk assessment interview once a year. Larger functions assign a relationship contact to each business area and meet quarterly; if yours does not, a short note to the audit manager responsible for your area when things change is enough.

What should I keep from the last audit?

The final report, your management responses, the evidence for every action you closed, the request list with everything you sent, and your own notes on what surprised you. The next audit starts from the last report, the auditors will retest what closed, and a repeat finding is rated higher; the old file is the fastest way to make sure nothing drifted back.

Should I share my self-check with internal audit?

In most organizations, yes. A one-page summary of what you checked, what you found and what you fixed feeds the audit function’s risk assessment and shows management monitoring its own controls. It will not replace the auditors’ testing, and it should not claim to, but it changes the conversation at the start of the next audit.

New guides & tools by email

Useful so far?

There are 400+ more guides where this came from. Get new guides, templates and free audit tools by email when they ship. No schedule, no filler.

Free. One confirmation email from WordPress.com, then you’re in. Unsubscribe anytime.

New guides & tools by email

Don’t lose this library.

400+ practitioner-written guides and free tools. Hear when new ones land.

One confirmation email from WordPress.com, then you’re in. Unsubscribe anytime.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading