How to Do an Internal Audit: Planning, Fieldwork, and Follow-Up

To do an internal audit, you set up an independent audit function, build a risk-based annual plan, scope each engagement to specific objectives, gather evidence through structured fieldwork, report findings with clear causes and recommendations, and then follow up until the corrective actions are verified. The steps below walk through that sequence in the order you will actually perform them.

Set Up Independence Before You Start

An internal audit is only as credible as the person conducting it. If the auditor reports to the manager whose process they are reviewing, or moonlights in compliance duties over the same area, the conclusions will not carry weight no matter how careful the fieldwork is.

The Institute of Internal Auditors expects a dual reporting relationship for the chief audit executive: a functional line directly to the board or audit committee for strategic direction and accountability, and an administrative line to a senior executive, ideally the CEO, for day-to-day support.1The Institute of Internal Auditors. Implementation Guidance – Standard 1110 Organizational Independence The functional line is what lets the CAE raise sensitive issues (fraud concerns, executive misconduct, systemic control failures) without needing permission from the people involved. Slotting the CAE under a controller defeats the purpose.

Individual auditors are bound by four ethical principles: integrity, objectivity, confidentiality, and competency. Objectivity means avoiding any relationship that could bias your assessment. Confidentiality means protecting the information you encounter and never using it for personal gain. Competency means only taking on work you are qualified to perform.2The Institute of Internal Auditors. IIA Global Code of Ethics

Build a Risk-Based Annual Plan

Before scoping any single engagement, you need a plan that decides which parts of the organization get audited and when. That plan flows from a documented risk assessment, updated at least annually by the CAE with input from the board, senior management, and the audit team.3The Institute of Internal Auditors. Developing a Risk-Based Internal Audit Plan

Start by building the audit universe: a catalog of every auditable unit in the organization. Each business process, department, system, or location that could warrant a dedicated engagement goes on the list. Then score each item against risk factors to set priority. Common factors include:

  • Financial exposure: dollar value at risk, transaction volume, and reliance on IT systems.
  • Strategic risk: reputational sensitivity, regulatory scrutiny, recent legislative changes, and significance to strategy.
  • Control environment: management turnover, degree of process formalization, tone at the top, and whether the area recently underwent system changes.
  • Complexity: level of automation, degree of specialization needed, and frequency of change.
  • Existing coverage: whether external auditors, regulators, or second-line functions already provide assurance over the area.

The board approves the final plan. If priorities or resource needs shift significantly during the year, the CAE discusses the changes with senior management and gets board approval for the revision.

Scope the Engagement

Once the annual plan pulls an area up for review, refine the risk assessment for that specific process, system, or department. You are identifying not just what could go wrong, but what matters most: the risks that, if unmanaged, could cause material financial loss, regulatory violations, or operational failures.

Clear objectives come out of that analysis. “Review the procurement process” tells your team almost nothing. Something like “assess whether purchase order approvals consistently follow the delegation-of-authority policy and whether segregation of duties prevents unauthorized payments” pins down what you are testing and what a good outcome looks like.4The Institute of Internal Auditors. Implementation Guide for Standard 2200 Engagement Planning

Resource planning follows. A cybersecurity audit needs different skills than a procurement review. Time budgets vary with the area’s complexity, transaction volume, and travel. A straightforward compliance review might take a few weeks; a cross-functional process audit touching multiple systems could stretch much longer.

The planning phase ends with a detailed audit program: a step-by-step list of procedures the team will perform during fieldwork. Every procedure should trace to a specific objective and a specific risk. If it does not, it probably does not belong. The last preparatory step is a formal engagement communication to the auditee, confirming scope, objectives, timeline, and what you will need from their team. This heads off surprises on both sides.

Do the Fieldwork

Fieldwork is where you actually gather evidence, working through the audit program procedure by procedure to determine whether controls are designed properly and operating as intended. Evidence takes several forms: inspecting documents, recalculating figures independently, observing processes as they happen, and interviewing the people who perform them.

Interviews are often the most revealing part of the work, but they require discipline. Start with open-ended questions and progressively narrow the focus as you learn how the process actually runs. Paraphrase what the interviewee said and confirm your understanding on the spot. Document the conversation in a summary and, where practical, confirm key facts back with the person you spoke with.

Control Testing vs. Substantive Testing

Procedures fall into two broad categories. Control testing evaluates whether a specific internal control is properly designed and working consistently: for example, whether purchase orders over a threshold actually carry the required approval signature. Substantive testing goes further and verifies the accuracy of the underlying data: whether reported account balances, transaction totals, or financial disclosures are correct.

Most engagements use both. If control testing shows a key control is working reliably, you can scale back substantive testing in that area because you have reasonable confidence the data flowing through the control is accurate. If a control is weak or missing, heavier substantive testing follows to understand the extent of the problem.

Sampling

Testing every transaction is rarely practical, so auditors sample. Statistical sampling uses mathematical methods to select items and quantify the risk that the sample is not representative. Judgmental sampling relies on the auditor’s professional judgment about where errors are most likely to hide. Statistical sampling measures sampling risk precisely but carries higher design costs. Judgmental sampling is more flexible but depends on the auditor’s skill. Either works when applied properly; the sample size has to account for population size, expected error rate, and tolerable misstatement.

Data Analytics

Sampling has an inherent limitation: you are drawing conclusions about a whole population from a subset. Data analytics can remove that constraint. When transaction data runs through automated procedures, you can test the full population instead of a sample, flagging outliers and exceptions for manual investigation.

Practical applications are wide-ranging: automated matching routines to identify duplicate payments, testing every journal entry against authorization rules, or visualization tools to spot unusual procurement patterns. Once the analytics are built, many can run continuously with minimal manual effort. Advanced audit functions are using machine learning to analyze large datasets and identify risk patterns manual review would miss. Whatever tools you use, integrate analytics into your methodology from the planning stage rather than treating them as an afterthought.

Working Papers

Every test performed, every piece of evidence gathered, and every conclusion reached goes into working papers. They are the backbone of the audit trail. Organize them according to the audit program structure and cross-reference so anyone reviewing them can trace a finding back to the program step, the supporting evidence, and the conclusion.5The Institute of Internal Auditors. Implementation Guide 2330 – Documenting Information

The standard is straightforward: documentation must contain sufficient, reliable, and relevant information to support your results and conclusions. If another qualified auditor picked up the working papers cold, they should be able to understand what you did, why you did it, and whether the conclusions follow from the evidence.6The Institute of Internal Auditors. Effective Workpapers – Global Knowledge Brief

Write the Report

The audit report is the primary deliverable of every engagement, and for many stakeholders it is the only part they will ever see. A report that buries its conclusions or reads like a compliance checklist wastes the fieldwork behind it.

A standard report opens with an executive summary covering scope, overall assessment, and the most significant findings. This is what board members and senior executives actually read, so it has to stand on its own. The body of the report then details objectives, work performed, and individual findings.7The Institute of Internal Auditors. Audit Report Writing Toolkit

Structuring Each Finding

Develop each finding using four elements: Condition, Criteria, Cause, and Effect. The condition describes what you actually found. The criteria establishes what should have been in place, referencing an internal policy, regulatory requirement, or industry standard. The cause explains why the gap exists — not “the control failed,” but the root reason, such as inadequate training, unclear policy language, or a system limitation. The effect quantifies or describes the risk to the organization in concrete terms: potential financial loss, regulatory exposure, or operational disruption.

This is where most reports fall apart. Auditors who skip the cause write findings that describe symptoms without diagnosing the disease. Auditors who cannot articulate the effect write findings that management shrugs off because the “so what?” is not clear. A finding without a quantified or clearly described effect sits at the bottom of management’s priority list.

Every finding needs a recommendation that addresses the root cause. “Improve controls” after identifying that purchase orders lack proper approval is useless. “Configure the procurement system to require electronic approval from the budget owner before any purchase order exceeding $5,000 is released to the vendor” gives management something actionable.

The Exit Conference

Before you finalize the report, hold an exit conference with the auditee and process owners. Present the preliminary findings, confirm the facts are accurate, and give management the chance to add context you may have missed. This is also where you obtain management’s formal response to each finding: agreement or disagreement, the specific corrective action plan, the responsible person, and a target completion date.

Distribute the final report to the audit committee, senior management, and process owners. Some audit committees want to see every report in full; others prefer a periodic summary of results and trends. The CAE should establish distribution guidelines with the board.

Follow Up on Corrective Actions

An audit report that sits in a drawer accomplishes nothing. The CAE is responsible for a follow-up process that monitors whether management actually implements the corrective actions they committed to, or whether senior management has consciously accepted the risk of not acting.8The Institute of Internal Auditors. Performance Standards – Standard 2500 Monitoring Progress

In practice, this means maintaining a tracking log with every open finding, the agreed action, the responsible person, and the target date. When management reports an action complete, the audit team verifies it by re-testing the control or process, not by taking management’s word. A fix that looks good on paper but does not change behavior on the ground has not been implemented.

Status of open and completed items goes to the audit committee regularly. That reporting is what creates accountability. When department heads know overdue items will appear in front of the board, completion rates improve. A finding is formally closed only after verification confirms the action is implemented and operating effectively.

If the CAE concludes that management has accepted a level of risk that could be unacceptable to the organization, the CAE raises it with senior management first. If that does not resolve it, the matter goes to the board. Internal audit does not own the risk decision, but it owns the responsibility to make sure the right people know about it.9The Institute of Internal Auditors. Performance Standards – Standard 2600 Communicating the Acceptance of Risks

Keep the Audit Function Itself Honest

Internal audit holds other functions accountable. A Quality Assurance and Improvement Program (QAIP) holds internal audit accountable. The IIA Standards require the CAE to develop and maintain a QAIP covering conformance with the Standards and Code of Ethics, the efficiency of audit operations, and continuous improvement.10The Institute of Internal Auditors. Establishing a Quality Assurance and Improvement Program

A QAIP has two components. Internal assessments include ongoing supervisory review of each engagement plus periodic self-assessments (typically annual) of the function as a whole. External assessments bring in a qualified, independent reviewer from outside the organization at least once every five years. Results of both go to senior management and the board at least annually.

If the Company Is Publicly Traded

Public companies in the United States operate under an additional layer of federal requirements. Section 404 of the Sarbanes-Oxley Act requires every annual report filed with the SEC to include an internal control report acknowledging management’s responsibility for maintaining adequate internal controls over financial reporting and containing management’s own assessment of whether those controls are effective.11GovInfo. 15 USC 7262 – Management Assessment of Internal Controls For accelerated and large accelerated filers, the external auditor must also attest to management’s assessment. Smaller reporting companies and emerging growth companies are generally exempt from the external attestation requirement but still perform and disclose management’s assessment.

Internal audit plays a central role in supporting Section 404 compliance even though the statute puts the formal obligation on management. Testing is typically organized around the COSO Internal Control – Integrated Framework, which breaks internal control into five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. All five have to be present and working together.