For the people being audited · Auditees & Management

Being audited? Here is what actually happens, and what to do at each step.

Internal audit is a fixed sequence with known rules, and the people who come out of it well are not always the ones with the cleanest operation; more often they are the ones who understood the process. Every guide on this page is written for process owners, managers and the people who do the work, by practitioners who run audits: what to expect, how to handle the requests and the interviews, how to answer a finding, and how to make the next audit uneventful.

  • Written by auditors, for auditees
  • Every stage, from notification to follow-up
  • Free to read, no sign-up

Content on this site is educational and general in nature; it is not legal or employment advice.

Find your place in the audit

Where are you right now?

An internal audit runs through the same stages whatever the subject. Pick the one you are in; each card lists the guides that help most at that point.

1 Before the audit

An audit is coming

Why your area was chosen, what internal audit is allowed to do, and a month of legitimate preparation.

2 Notification and kickoff

The audit has been announced

The nine phases, how long each takes, what you will be asked for and what the kickoff meeting is for.

3 Requests and fieldwork

The requests and interviews have started

Triage the request list, produce extracts that are accepted first time, and handle walkthroughs and interviews well.

4 Findings and the closing meeting

The findings are on the table

Check the facts, agree the cause, argue the rating from the definitions, and disagree the right way when you need to.

5 The report and your response

You have to write the response

Actions that fix the cause, owners who control the fix, dates that hold, and the evidence the validators will test.

6 After the audit, and between audits

The audit is over

Keep actions on track, own your controls through change, and make the next audit uneventful.

If you read nothing else

Eight guides, in the order you will need them

  1. 01What to expect during an internal audit — the nine phases, twenty typical requests, what each rating means for you, and a six-week worked example from a depot manager’s side.
  2. 02How to prepare for an internal audit — a month of preparation that helps, and the kind of tidying up that does damage.
  3. 03The PBC survival guide — triage the request list in 48 hours, one coordinator, extracts that are accepted first time.
  4. 04When internal audit interviews you — sixteen common questions, what each is really testing, and how to answer.
  5. 05When you disagree with a finding — facts, cause and rating are argued differently; how to win on the facts and disagree properly on the rest.
  6. 06Writing management action plans that close — the response that decides your next twelve months, with twelve weak plans rewritten.
  7. 07Failed an internal audit? — what an Unsatisfactory rating means, who sees it, and the first 72 hours and 90 days.
  8. 08Living with internal audit year-round — heads-ups, early advice, a yearly self-check, and why the next audit then finds less.

The rules both sides work to

What the auditors owe you, and what you owe them

Internal auditors work to the IIA’s Global Internal Audit Standards, and several of them protect the people being audited. Knowing them changes how you handle the audit.

  • You hear about findings before the report. When auditors evaluate potential findings, they must work with management to identify root causes where possible, determine the potential effects and evaluate how significant each one is (Standard 14.3).
  • You can disagree, on the record. The audit function must have a method that lets both sides state their positions on the final report, and auditors must try to reach a mutual understanding; they need a valid reason to change the results (Standard 13.1).
  • Fixes you make early count. The final report must acknowledge actions management has already started or completed (Standard 15.1).
  • Your information is protected. Auditors must respect the confidentiality and privacy of what they gather and not disclose it to unauthorized parties (Standard 5.2).
  • Access is unrestricted, by design. The board and senior management are expected to support internal audit’s unrestricted access to the data, records, people and property it needs (Standard 6.3). A refusal becomes a scope limitation the auditors report.
  • Accepting a risk is allowed, openly. Management may decide to live with a risk; if it exceeds the organization’s appetite, the chief audit executive must raise it with senior management and, if unresolved, the board (Standard 11.5).

For managers and executives

If the controls are yours

Most findings are about controls a manager owns. These guides are about owning them well, answering for them when something goes wrong, and using the audit function to your advantage.

Ownership

Control ownership: making someone actually accountable

Owner, performer, reviewer and monitor; how controls become orphans after a reorganization; an ownership register, a RACI and a handover checklist.

Read the guide →
Using the audit

Why welcome an internal audit

What your area can get out of an audit: independent evidence for a budget case, fixes you have been asking for, and advice before you build.

Read the guide →
Authority

What internal audit can and cannot do

Where the mandate comes from, what access auditors have, what they are not allowed to do, and where management’s decisions stay management’s.

Read the guide →
The Field Desk Series · paid PDF

The Auditee’s Playbook

For managers who want it all in one working document: eleven scripts, four templates and a phrasebook for every stage of being audited. Everything on this page stays free.

See sample pages →

Quick answers

The questions people ask first

Why was my area chosen?

Audit plans are built from a risk assessment and approved by the audit committee. Cash, change, time since the last audit, regulatory interest and management requests all raise an area’s score. Selection is not an accusation. How audit plans choose.

Am I in trouble?

In a routine audit, almost certainly not. Findings describe how a process is designed and run. An unannounced interview about specific transactions with legal present is different, and different rules apply. Interviews and investigations.

Can I refuse a request?

You can question it and propose a cheaper route to the same evidence. Refusing outright becomes a scope limitation the auditors report, because their access comes from a charter the board approves. Handling requests.

How long will it take?

A typical engagement runs six to ten weeks from notification to report, and the follow-up of actions runs for months after that. Timelines and what drives them.

Can I disagree with a finding?

Yes, and the Standards require the audit function to let you. Correct wrong facts with evidence, argue ratings from the written definitions, and record any remaining disagreement in your response. Disagreeing properly.

Who will see the report?

Your executive in full, the chief executive and audit committee in summary or in full depending on the rating, and in some cases the external auditor or a regulator. Who sees a bad rating.

What happens after the report?

Every action goes into a tracking log with your name and date, and the auditors check the evidence that each fix is in place before closing it. Writing actions that close.

Should I tell them about a problem they have not found?

Yes. Many audit functions report an issue management disclosed as self-identified, the final report must acknowledge fixes already under way (Standard 15.1), and the disclosure changes the tone of the whole report. Heads-ups that build credit.