-
Financial Statement Fraud: How the Numbers Get Cooked, and Who Should Catch It
The financial reporting branch of the fraud tree: the five mechanisms and their mirror images, who commits it and the pressures that produce it, the cases from Enron…
Updated
·
19–29 minutes -
How to Audit Cash Management and Bank Reconciliations: Controls, Not Rituals
The internal auditor’s guide to cash management and bank reconciliations: the cash structure and where it fails, the seven properties of a reconciliation that is a control rather…
Updated
·
19–28 minutes -
How to Audit Inventory: Counts, Costing and Shrink, With a 14-Test Program
The internal auditor’s guide to inventory: the six handoffs where the record and the stock part company, a ten-control starter matrix, a fourteen-test program, how to observe a…
Updated
·
20–30 minutes -
How to Audit Accounts Receivable and Collections: Risks, Controls and a 14-Test Program
The internal auditor’s guide to accounts receivable and collections: where the risk concentrates from invoice to cash, a ten-control starter matrix, a fourteen-test program with sample sizes, the…
Updated
·
20–29 minutes -
Manual, Automated, and IT-Dependent Manual Controls: Testing Implications of Each
The three control natures defined by what can fail, their testing implications side by side (design test, operating test, sample sizes, ITGC reliance, evidence, roll-forward), a five-question classification…
Updated
·
20–30 minutes -
How to Audit Active Directory and Entra ID: The Identity Backbone
The directory is the control plane of every other control. The method for auditing Active Directory and Entra ID: why it is in scope of everything, the privileged…
Updated
·
20–30 minutes -
Testing Automated Controls and System Configurations: A Non-IT Auditor’s Method
How to test the controls a system performs without anyone watching: the seven types of automated control and where their logic lives, why one well-designed test can cover…
Updated
·
21–31 minutes -
How to Audit IT Change Management: From Ticket to Production
The working method for auditing IT change management: the ten controls and their COBIT, ITIL, NIST and COSO references, why the population must come from the production system…
Updated
·
26–38 minutes -
How to Write a Control Description: Well-Written vs Poor Examples
Who, what, when, how, and evidence, plus precision and exception handling: the formula for a control description a stranger can test, ten poor descriptions rewritten, the five-question testability…
Updated
·
19–28 minutes -
Preventive, Detective, and Corrective Controls: The Complete Taxonomy With 50 Examples
The classic taxonomy done properly: crisp definitions, the cost-and-assurance trade-offs, the layering doctrine — prevent first, detect always, correct completely — and a categorized library of 50 real…
Updated
·
8–12 minutes -
COSO’s 17 Principles: The Complete List, What Each Requires, and How to Evaluate Them
All seventeen COSO 2013 principles across the five components: the question each asks, the evidence that answers it, what each looks like when it fails, the present-functioning-operating-together evaluation,…
Updated
·
18–27 minutes -
How to Run an ERP Segregation of Duties Analysis (Any Platform)
Vendor rulesets flag thousands of conflicts; a few dozen matter. The platform-agnostic method for an ERP segregation of duties analysis: a conflict matrix built from your own risks…
Updated
·
21–31 minutes -
How to Perform a User Access Review That Actually Works
Most user access reviews are signatures, not reviews. How to build one that removes access: scoping by tier with the right reviewers, population completeness reconciled to the system…
Updated
·
19–29 minutes -
Management Review Controls: Documenting and Testing the Hardest Controls in SOX
How to design a management review control that can be tested and test one that exists: the six-element anatomy, the precision factors from PCAOB Staff Audit Practice Alert…
Updated
·
19–29 minutes -
SOX 404 Explained: The Complete Guide to ICFR Compliance
Section 404 in full for the internal auditor: what 404(a), 404(b), 302 and 906 require, the filer categories and exemptions as amended in April 2020 that decide whether…
Updated
·
19–28 minutes -
How to Audit Privileged Access: Admin Rights, Break-Glass, and Vaulting
Privileged access decides how bad everything else can get. The method for auditing it: privilege defined by capability across every layer from the directory to the database and…
Updated
·
19–28 minutes -
ITGC vs Application Controls: The Dependency Everyone Gets Backwards
An application control is only as reliable as the general controls over the system it runs in. The two layers defined precisely, the mechanism by which each ITGC…
Updated
·
21–31 minutes -
Segregation of Duties Beyond the ERP: A Universal SoD Framework
Segregation of duties is taught as an ERP problem and most of the losses it prevents happen nowhere near one. The universal framework: the four incompatible functions and…
Updated
·
19–28 minutes -
How to Audit Identity and Access Management: The Full IAM Program
Identity is the control plane of everything else. The program audit of identity and access management: the seven domains and their frameworks, the joiner-mover-leaver chain with the leaver…
Updated
·
20–29 minutes -
Risk and Control Matrix (RCM) Template: Every Column, Six Worked Rows, One Real Rebuild
The full risk and control matrix template with every column explained, six fully worked rows, a real rebuild of an accounts payable matrix showing how the walkthrough and…
Updated
·
25–37 minutes -
How to Audit Accounts Payable: Risks, Controls, a 14-Test Program and a Worked Engagement
The internal auditor’s guide to accounts payable: where the risk concentrates in procure-to-pay, a ten-control starter matrix, a fourteen-test program with attributes, the analytics that find real dollars,…
Updated
·
23–34 minutes -
IT General Controls (ITGC) Audit: The Complete Primer for Non-IT Auditors
How to scope and test ITGCs without an IT background: a 24-row test matrix with populations, samples and evidence, a PBC list, a 20-question IT interview script, and…
Updated
·
30–46 minutes -
Risks of Not Having Internal Controls in Hospital Revenue Cycle Management
Hospital revenue cycle management (RCM) is at the very heart of any healthcare organization’s financial stability. In simple terms, RCM encompasses all administrative and clinical functions that contribute…
Updated
·
14–21 minutes -
Internal Controls: What They Are, Who Tests Them, and How
A precise definition of internal control, the classifications that decide how each control is tested, who tests controls and why five parties test the same one, the four…
Updated
·
21–31 minutes -
Stewardship, Risk and Trust: Why Internal Audit Exists
Imagine an organization—maybe a big company producing electronics, a bank handling your savings, or a hospital caring for patients. Beneath the surface, countless decisions and transactions occur every…
-
What Is an Internal Control? Definition, Types, 40 Examples
A control is an action, not a policy, a system, a report, or a person. The COSO and IIA definitions taken apart, the seven attributes every control description…
Updated
·
24–36 minutes