-
Procurement Fraud Schemes: Bid Rigging, Kickbacks and Phantom Vendors, and How to Find Them
The corruption branch of the fraud tree with a purchase order attached: bid rigging in its four forms and the indicators, kickbacks and price creep inside the tolerance…
Updated
·
19–29 minutes -
How to Audit Cash Management and Bank Reconciliations: Controls, Not Rituals
The internal auditor’s guide to cash management and bank reconciliations: the cash structure and where it fails, the seven properties of a reconciliation that is a control rather…
Updated
·
19–28 minutes -
How to Audit Payment Operations and Wire Transfers: Stopping the Nine-Figure Mistake
The internal auditor’s guide to payment operations and wire transfers, for banks and corporates: the eight-stage payment life cycle and the rails, who bears the loss under UCC…
Updated
·
19–28 minutes -
How to Audit Treasury: Cash, Debt, Investments and Hedging, With a 14-Test Program
The internal auditor’s guide to corporate treasury: the five activities and where each goes wrong, a ten-control starter matrix, a fourteen-test program built on confirmation and reperformance, the…
Updated
·
19–29 minutes -
How to Audit Inventory: Counts, Costing and Shrink, With a 14-Test Program
The internal auditor’s guide to inventory: the six handoffs where the record and the stock part company, a ten-control starter matrix, a fourteen-test program, how to observe a…
Updated
·
20–30 minutes -
How to Audit Accounts Receivable and Collections: Risks, Controls and a 14-Test Program
The internal auditor’s guide to accounts receivable and collections: where the risk concentrates from invoice to cash, a ten-control starter matrix, a fourteen-test program with sample sizes, the…
Updated
·
20–29 minutes -
Vendor Due Diligence: What to Actually Check, by Risk Tier
A due-diligence workbench organised by what you need to know before you sign and calibrated by risk tier: the fourteen interagency factors with the evidence that counts, depth…
Updated
·
19–29 minutes -
Walkthrough vs Test of Controls: Different Questions, Different Evidence
A walkthrough answers whether the process is understood and the control is designed and implemented; a test of controls answers whether it operated across the period. This guide…
Updated
·
19–29 minutes -
Manual, Automated, and IT-Dependent Manual Controls: Testing Implications of Each
The three control natures defined by what can fail, their testing implications side by side (design test, operating test, sample sizes, ITGC reliance, evidence, roll-forward), a five-question classification…
Updated
·
20–30 minutes -
How to Audit the SDLC and DevOps Pipeline
How to audit a modern software delivery pipeline: the five change control objectives mapped from traditional ITGCs to pipeline mechanisms, the standards (NIST SSDF, SLSA, ISO/IEC 27001:2022 A.8.25…
Updated
·
21–31 minutes -
Building the IT Audit Plan: From Risk Assessment to Coverage Map
The technology layer of the audit plan, built in six steps: an IT universe reconciled from sources that already exist, a ten-factor risk assessment with evidence behind every…
Updated
·
20–30 minutes -
Testing Automated Controls and System Configurations: A Non-IT Auditor’s Method
How to test the controls a system performs without anyone watching: the seven types of automated control and where their logic lives, why one well-designed test can cover…
Updated
·
21–31 minutes -
The Sampling Memo: A Template for Documenting Every Sampling Decision
A nine-section sampling memo written before testing: objective, population and completeness, method, size rationale, selection mechanics with the seed, exception definition, evaluation rules, conclusion boundary, and changes. Annotated…
Updated
·
18–27 minutes -
Judgmental Sampling That Survives Scrutiny: Documenting Non-Statistical Selections
Risk-directed judgmental selection is legitimate when documented. The three kinds of selection and what each supports, when judgment beats a random sample, the seven workpaper elements, deliberate versus…
Updated
·
18–27 minutes -
The QAIP Documentation Kit: Self-Assessment Workbook and Quality Metrics Sheet
The four documents a quality program runs on, in full: the standard-by-standard self-assessment workbook with rating definitions and completed rows, a one-page engagement QC checklist at three checkpoints,…
Updated
·
18–27 minutes -
Building a QAIP From Scratch: The Complete Playbook
How to build a quality assurance and improvement program that actually runs: what the Global Internal Audit Standards require and where the evidence lives, the four layers on…
Updated
·
19–28 minutes -
Root Cause Analysis for Audit Findings: 5 Whys Worked Examples
Stop restating the condition as the cause. The five whys and the fishbone worked on three real findings (access not removed, a reconciliation backlog, vendors onboarded without assessment),…
Updated
·
19–28 minutes -
The Finding and Issue Log Template: Fields That Make Follow-Up Work
A complete internal audit issue log template: every field defined, a status taxonomy that survives audit-committee scrutiny, ageing and escalation rules, the committee-reporting cuts, an Excel-tier build, and…
Updated
·
21–32 minutes -
The Internal Audit Report Template Set: Full, Short-Form and Memo Shells, Annotated
Three annotated audit report shells — full report, short-form, and advisory memo — with model language for every section, house style rules, and a fully worked example: MidState…
Updated
·
27–41 minutes -
The Walkthrough Documentation Template: Capturing a Process End-to-End
The walkthrough artifact done properly: an eight-part narrative-plus-flowchart structure with control-point call-outs, system handoffs, evidence inventory, the documented-vs-actual gap log, and a conclusion that drives testing — with…
Updated
·
24–36 minutes -
The Engagement Planning Memo Template (Annotated): Eight Sections Mapped to GIAS 13.1–13.6
An annotated engagement planning memo template: all eight sections, each mapped to Global Internal Audit Standards 13.1 to 13.6, a worked example from a route cash-handling audit, variants…
Updated
·
19–28 minutes -
The Annotated Internal Audit Plan Template
The complete annual audit plan document — eight sections with model language, drafting guidance on every one, and a fully worked example for a real-shaped company. Risk summary,…
Updated
·
11–17 minutes -
The Journal Entry Analytics Catalog: Risk-Scoring the General Ledger
Twenty-five journal entry analytics tests in four families, each with logic, data, threshold, what a hit means and its false positives, anchored to the entry characteristics in PCAOB…
Updated
·
19–29 minutes -
Finding Severity Ratings: Building a Calibrated High/Medium/Low Matrix
An actual severity matrix, published: impact and likelihood anchors you can calibrate to your materiality, the 4×4 grid, worked examples at every level, aggregation rules for when five…
Updated
·
7–10 minutes -
A Fraud Red Flags Library, Organized by Business Cycle
Forty-eight fraud red flags across seven categories — procurement, payroll, sales, inventory, treasury, financial reporting, and behavior — each paired with the confirming test that turns suspicion into…
Updated
·
8–12 minutes -
GIAS Domain V: Performing Engagements From Planning to Closure
Domain V of the Global Internal Audit Standards, standard by standard: the fourteen workpapers the domain produces, engagement communication as a thread from notification to closing meeting, the…
Updated
·
19–29 minutes -
GIAS Domain IV: Managing the Function — Strategy, Plan, Resources, Communication
Domain IV of the Global Internal Audit Standards, standard by standard: the sixteen artifacts the domain produces, understanding the organization, the new internal audit strategy requirement with an…
Updated
·
19–29 minutes -
The Payroll Analytics Catalog: 30 Tests for Ghost Employees and Beyond
Thirty payroll analytics tests in five families, each with its logic, data, threshold, what a hit usually means and what produces false positives; the five datasets and the…
Updated
·
19–29 minutes -
The Accounts Payable Analytics Catalog: 40 Tests With Logic
Forty accounts payable analytics tests in six families, each with its logic, the data and threshold it needs, what a hit usually means and what produces false positives;…
Updated
·
20–29 minutes -
Evaluating Control Deficiencies: From Exception to Material Weakness
How to evaluate a control deficiency under AS 2201 and the SEC guidance: the three definitions, the exception-to-deficiency gate, likelihood and magnitude factors, the compensating control precision bar,…
Updated
·
27–40 minutes