-
Risk Acceptance by Management: The Right Process for Letting an Audit Issue Go
Management may accept the risk an audit finding describes, but only by a decision made at the right level, on a stated risk, recorded and revisited. This guide…
Updated
·
20–29 minutes -
How to Run a Fraud Risk Assessment: Method, Workshop Plan and Register Template
A practitioner’s method for the fraud risk assessment: what it is and is not, who owns it, the seven-step method with hours, the scheme library that seeds the…
Updated
·
19–28 minutes -
Building the IT Audit Plan: From Risk Assessment to Coverage Map
The technology layer of the audit plan, built in six steps: an IT universe reconciled from sources that already exist, a ten-factor risk assessment with evidence behind every…
Updated
·
20–30 minutes -
Finding Severity Ratings: The Calibrated Matrix, Twelve Cases and the Report Rating Rule
The calibrated High/Medium/Low matrix: impact and likelihood anchors, the 4×4 grid, twelve rated cases from worked engagements, the rule that derives the report rating, a rating memo template,…
Updated
·
24–36 minutes -
The Risk Register: Anatomy, a Worked Example, and How to Keep It From Becoming a Graveyard
The risk register end to end: every field and why it exists, a worked enterprise register, scoring and appetite wiring, governance that keeps it alive, and the classic…
Updated
·
11–16 minutes -
How to Run a Risk and Control Self-Assessment (RCSA) That Is Not Theater
RCSA end to end: scoping, workshop vs survey design, scoring discipline, the challenge function, facilitator scripts, and the classic failure modes.
Updated
·
10–15 minutes -
Risk Appetite Statements That Actually Guide Decisions: Eight Examples and the Cascade
The capacity-appetite-tolerance-limit ladder, the five-part anatomy, the cascade worked from the board to the desk for two statements, eight realistic example statements including a manufacturer and a public…
Updated
·
23–34 minutes -
The Annual Internal Audit Risk Assessment: A Step-by-Step Playbook
The annual internal audit risk assessment, step by step: inputs, a worked scoring model, management calibration, and turning scores into the audit plan.
Updated
·
11–17 minutes -
Operational Risk Guide for Internal Auditors (2026)
Operational risk from the third line’s seat: the Basel event types with examples, the framework’s components with the audit test for each, twelve leading KRIs with thresholds, loss…
Updated
·
21–31 minutes -
Interest Rate Risk (IRR) vs. Asset-Liability Management (ALM)
1. Introduction 1.1 What Is Interest Rate Risk (IRR)? Interest Rate Risk (IRR) is the possibility that changes in market interest rates will adversely impact an institution’s earnings, cash…
Updated
·
15–22 minutes -
How to Audit Business Continuity and Resilience (2026 Guide)
Auditing resilience as a capability, not a binder: the 2026 setting (the IIA Topical Requirement effective 30 April 2027, DORA, the UK regime, ISO 22301), precise vocabulary, all…
Updated
·
22–33 minutes -
Model Risk Audit: How Internal Audit Validates the Models Management Relies On
How internal audit audits model risk management rather than re-validating models: SR 11-7 and the April 2026 revised guidance, a tiering table, a 20-test work program, a validation-report…
Updated
·
30–44 minutes -
Internal Audit in Financial Services: AML, Compliance, MRAs
What is different about the third line in a regulated institution: the audit universe by risk stripe, a regulator-expectation matrix (OCC, Fed, FDIC, FINRA, NAIC, NCUA), a 16-component…
Updated
·
20–30 minutes -
Fraud Risk Management and Internal Audit: Prevention, Detection, and Response
A working guide to internal audit’s role in fraud risk management: a 26-scheme catalog with the detective analytic for each, a scored fraud risk assessment, an investigation protocol,…
Updated
·
37–55 minutes -
Risk-Based Auditing 101: Prioritizing Audits Using Risk Assessments
Effective internal auditing hinges on one simple but powerful principle: focus your resources on what matters most. Risk-based auditing provides a systematic way to do exactly that. By…
Updated
·
12–19 minutes -
Risk Control Matrix (RCM): Names, Variants and Approaches
Within the realm of risk management and internal audit, practitioners encounter various names and approaches for what is essentially a risk control matrix (RCM). These variations, while similar…
Updated
·
3–4 minutes -
5 Common Misconceptions About Enterprise Risk Management (ERM)
Enterprise Risk Management (ERM) represents one of the most significant advances in organizational risk management, yet it remains frequently misunderstood. These misunderstandings can lead organizations to implement ERM…
Updated
·
5–8 minutes -
ERM vs. Traditional Risk Management: What’s Different
Enterprise Risk Management (ERM) represents a revolutionary departure from traditional risk management approaches, fundamentally transforming how organizations understand and respond to uncertainty. While conventional risk management methods often…
Updated
·
5–8 minutes -
From Simplicity to Complexity: The Evolution of Internal Audit as a Modern Profession
In a world where technology, globalization, and regulatory scrutiny have transformed the way businesses operate, internal audit (IA) has emerged as a cornerstone of corporate governance and risk…
Updated
·
12–18 minutes -
OCC Risk Categories: The 8 Risk Stripes Explained
For decades the OCC supervised US national banks through eight risk categories, often called risk stripes: credit, interest rate, liquidity, price, operational, compliance, strategic, and reputation. Since 2025…
-
Enterprise Risk Management History: A Timeline
Enterprise risk management (ERM) stands today as a cornerstone of organizational resilience, guiding companies through turbulent markets, regulatory shifts, and ever-changing global landscapes. Yet the roots of risk…
Updated
·
18–27 minutes -
Internal Audit’s Role in ERM: Assurance, Advice, and Limits
The roles table with a safeguard for every advisory role, charter and engagement-letter language, a five-level ERM maturity rubric across six dimensions, a 15-row ERM audit program, an…
Updated
·
20–30 minutes -
Top Questions for an Internal Audit Technical Interview
Internal audit technical interviews can be challenging. Employers look for auditors who not only grasp the fundamentals—like control testing, compliance standards, and risk assessment—but can also apply their…
-
Risk Management Frameworks Compared: COSO, ISO 31000, NIST
Nine frameworks and models in one comparison with what each is for and is not, a decision table for which fits which situation, the eight elements every framework…
Updated
·
19–29 minutes -
Top Non-Financial Risk Indicators Internal Auditors Need to Understand
In today’s complex business landscape, non-financial risks are increasingly capturing the attention of boards, executives, and, crucially, internal auditors. Historically, auditing practices have focused heavily on financial metrics—such as revenue…
Updated
·
11–17 minutes -
Stewardship, Risk and Trust: Why Internal Audit Exists
Imagine an organization—maybe a big company producing electronics, a bank handling your savings, or a hospital caring for patients. Beneath the surface, countless decisions and transactions occur every…
-
Auditing Credit Risk: Scope, Tests, and Red Flags
Auditing credit risk comes down to four tests: independently re-grading a judgmental sample of loans, testing underwriting and policy exceptions, validating watchlist and rating-migration governance, and assessing the…
Updated
·
18–28 minutes