-
How to Audit Payment Operations and Wire Transfers: Stopping the Nine-Figure Mistake
The internal auditor’s guide to payment operations and wire transfers, for banks and corporates: the eight-stage payment life cycle and the rails, who bears the loss under UCC…
Updated
·
19–28 minutes -
Vendor and Third-Party Models: Validating What You Cannot See Inside
Vendor does not mean exempt: the types of vendor model and what is visible in each, six due-diligence substitutes for transparency, the customisation boundary where your configuration becomes…
Updated
·
18–28 minutes -
Third-Party Resilience: Continuity When the Failure Is Not Yours
Continuity planning for the failures that belong to someone else: criticality-tiered continuity requirements for suppliers, the evidence that proves resilience rather than asserting it, the arithmetic linking a…
Updated
·
19–28 minutes -
Fourth Parties and Vendor Concentration: The Risk Behind the Risk
Your vendors’ vendors: three failures that arrived through the back door (CrowdStrike, Change Healthcare, MOVEit), the terms defined precisely, what DORA, the interagency guidance, the EBA and PRA,…
Updated
·
18–28 minutes -
Vendor Due Diligence: What to Actually Check, by Risk Tier
A due-diligence workbench organised by what you need to know before you sign and calibrated by risk tier: the fourteen interagency factors with the evidence that counts, depth…
Updated
·
19–29 minutes -
Third-Party Risk Management End-to-End: The Full Lifecycle Program
The third-party risk management lifecycle end to end: the regimes the program must satisfy (interagency guidance, the IIA Third-Party Topical Requirement, DORA, EBA, PRA, UK Critical Third Parties),…
Updated
·
21–31 minutes -
How to Audit Cloud Security: A Control-by-Control Program
A provider-agnostic cloud security audit program: the shared-responsibility test map by service model, criteria (CSA CCM v4, ISO/IEC 27017 and 27018, NIST SP 800-210, CIS Foundations Benchmarks, DORA),…
Updated
·
19–28 minutes -
How to Audit Patch and Vulnerability Management
You cannot patch what you cannot see. The method for auditing vulnerability and patch management as a program: the frameworks from NIST SP 800-40 Rev. 4 to the…
Updated
·
19–29 minutes -
How to Review a SOC 2 Report: Trust Services Criteria for User Entities
The user entity’s method for a SOC 2 report under the AICPA Trust Services Criteria: what the report is and is not, which of the five categories your…
Updated
·
20–29 minutes -
How to Review a SOC 1 Report: A User Entity’s Working Method
The user entity’s method for a SOC 1 report under SSAE 18: what the report is and is not, the five sections and what to read in each,…
Updated
·
21–31 minutes -
How to Run a Risk and Control Self-Assessment (RCSA) That Is Not Theater
RCSA end to end: scoping, workshop vs survey design, scoring discipline, the challenge function, facilitator scripts, and the classic failure modes.
Updated
·
10–15 minutes -
Third-Party Topical Requirement: The 17 Requirements, Mapped for 15 September 2026
The IIA’s Third-Party Topical Requirement, effective 15 September 2026, as a working guide: what counts as a third party, when the requirement binds, all seventeen requirements in three…
Updated
·
19–28 minutes -
Operational Risk Guide for Internal Auditors (2026)
Operational risk from the third line’s seat: the Basel event types with examples, the framework’s components with the audit test for each, twelve leading KRIs with thresholds, loss…
Updated
·
21–31 minutes -
OCC Risk Categories: The 8 Risk Stripes Explained
For decades the OCC supervised US national banks through eight risk categories, often called risk stripes: credit, interest rate, liquidity, price, operational, compliance, strategic, and reputation. Since 2025…
-
Top Questions for an Internal Audit Technical Interview
Internal audit technical interviews can be challenging. Employers look for auditors who not only grasp the fundamentals—like control testing, compliance standards, and risk assessment—but can also apply their…
-
Top Non-Financial Risk Indicators Internal Auditors Need to Understand
In today’s complex business landscape, non-financial risks are increasingly capturing the attention of boards, executives, and, crucially, internal auditors. Historically, auditing practices have focused heavily on financial metrics—such as revenue…
Updated
·
11–17 minutes