
Audit Scope Builder Tool
Turn a broad request such as “audit procurement” into a clear, risk-based scope linking objectives, risks, processes, locations, systems and exclusions.
PDF • 6 Pages • Free
Practical tools, guides, checklists and templates for internal auditors — free to download and use.
Built for auditors who want practical resources they can apply immediately. Explore professionally designed tools, step-by-step guides, audit checklists and ready-to-use templates covering the full internal audit lifecycle.
80+
Free Resources
20
Tools
20
Guides
20
Checklists
20
Templates

Turn a broad request such as “audit procurement” into a clear, risk-based scope linking objectives, risks, processes, locations, systems and exclusions.
PDF • 6 Pages • Free

Check whether a control is designed well enough to address its risk — owner, frequency, evidence, precision and exception response — before you test it.
PDF • 6 Pages • Free

A six-step approach for moving from business objectives and risks to a focused, defensible audit plan — with clear objectives, scope, evidence and agreed boundaries.
PDF • 6 Pages • Free

How to build findings management acts on: condition, criteria, business risk, root cause, quantified exposure and an action that fixes the cause — in neutral, evidence-based language.
PDF • 6 Pages • Free

Cover the key procurement controls: supplier due diligence and competitive sourcing, approved requisitions and POs, evidenced receipt, invoice matching, and monitoring for split spend, duplicates and bank changes.
PDF • 6 Pages • Free

Turn an audit request into a focused, risk-based engagement plan, documenting purpose, objectives, in- and out-of-scope areas, walkthroughs, data needs and milestones in one reviewable record.
PDF • 6 Pages • Free
80 resources

Turn a broad request such as “audit procurement” into a clear, risk-based scope linking objectives, risks, processes, locations, systems and exclusions.
PDF • 6 Pages • Free

Reduce a long risk list to the few risks that deserve audit attention, scoring impact, likelihood, velocity, control weakness and sensitivity.
PDF • 6 Pages • Free

Document how a process really works during walkthroughs — steps, roles, systems, approvals, evidence, exceptions and manual workarounds.
PDF • 6 Pages • Free

Check whether a control is designed well enough to address its risk — owner, frequency, evidence, precision and exception response — before you test it.
PDF • 6 Pages • Free

Test the quantity, relevance, reliability and corroboration of your evidence before finalizing a finding or conclusion.
PDF • 6 Pages • Free

Move beyond “remind employees” and “provide training” — use repeated why-questions and cause categories to reach the condition that created the issue.
PDF • 6 Pages • Free

Rate findings consistently by combining consequence, exposure, control failure, recurrence and urgency, mapped to your own rating methodology.
PDF • 6 Pages • Free

Check that proposed corrective actions are specific, owned, measurable and actually address the root cause — before the report is issued.
PDF • 6 Pages • Free

Identify who can block, support, inform or approve an audit and plan how to engage them — preventing late surprises on sensitive or cross-border engagements.
PDF • 6 Pages • Free

Decide which audit tests should become monthly, weekly or near-real-time monitoring routines — based on risk, repeatable logic, reliable data and clear ownership.
PDF • 6 Pages • Free

Turn a vague request such as “review procurement” into clear, testable, outcome-focused audit objectives linked to a specific risk and clear criteria.
PDF • 6 Pages • Free

Choose the strongest practical test method — inquiry, inspection, observation, reperformance or data analytics — for each control and assertion.
PDF • 6 Pages • Free

Plan a defensible sampling approach — population, objective, risk strata and selection method — before you pull a sample. A planning aid, not a sample-size calculator.
PDF • 6 Pages • Free

Decide whether a test exception is isolated, recurring, systemic or evidence of control failure — and whether to expand testing or raise a finding.
PDF • 6 Pages • Free

Plan focused interviews and walkthrough meetings that separate what people say from the evidence that still needs corroboration.
PDF • 6 Pages • Free

Match each risk to a practical data test, the fields it needs and whether it suits one-off audit work or continuous monitoring.
PDF • 6 Pages • Free

Turn an engagement scope into a realistic time budget, allocating hours by risk, complexity, data effort and review needs rather than equally.
PDF • 6 Pages • Free

Map key activities to Responsible, Accountable, Consulted and Informed roles to expose ownership gaps, conflicting accountability and concentration of duties.
PDF • 6 Pages • Free

Challenge whether a recommendation fixes the root cause, reduces risk, has a named owner and can be verified later — before it goes into the report.
PDF • 6 Pages • Free

Decide which open audit actions need immediate follow-up by combining residual risk, aging, recurrence, dependencies and evidence of progress.
PDF • 6 Pages • Free

A six-step approach for moving from business objectives and risks to a focused, defensible audit plan — with clear objectives, scope, evidence and agreed boundaries.
PDF • 6 Pages • Free

How to follow a real transaction from start to finish, see the process rather than hear the policy, and close with a confirmed process map and evidence list.
PDF • 6 Pages • Free

A practical six-step approach to testing both control design and operating effectiveness — choosing the strongest test method and evaluating exceptions before concluding.
PDF • 6 Pages • Free

How to build findings management acts on: condition, criteria, business risk, root cause, quantified exposure and an action that fixes the cause — in neutral, evidence-based language.
PDF • 6 Pages • Free

Go beyond the immediate error: separate symptoms from recurring conditions, verify each “why” with evidence, and link the real cause to an action that prevents recurrence.
PDF • 6 Pages • Free

A six-step approach to auditing purchase-to-pay — supplier onboarding and bank changes, approvals, three-way matching, and analytics for duplicates, split purchases and overrides.
PDF • 6 Pages • Free

How to audit travel and expenses beyond receipts — policy design, approval quality, spend analytics and behavior patterns such as split claims and unusual taxi or hotel usage.
PDF • 6 Pages • Free

Start with the audit question, not the software: define and validate the data, design risk-based tests, investigate exceptions in context and save logic for reuse or monitoring.
PDF • 6 Pages • Free

Plan and run interviews that produce evidence, not just answers — open questions, “show me” demonstrations, probing exceptions, and notes that separate facts from opinions.
PDF • 6 Pages • Free

Close engagements that withstand challenge: evidence-based conclusions for every objective, validated facts, clear actions and owners, an executive message, and archived follow-up requirements.
PDF • 6 Pages • Free

Convert audit objectives into focused, evidence-producing procedures — linking each objective to its risk, evidence source, coverage and sampling logic, owner and expected workpaper output.
PDF • 6 Pages • Free

Identify where opportunity, pressure and weak oversight create fraud exposure — mapping who can initiate, approve and conceal transactions, then testing the most plausible fraud scenarios.
PDF • 6 Pages • Free

Audit supplier creation and change controls — onboarding evidence, bank-account change verification, duplicate and dormant vendors, change logs and segregation of duties around master-data access.
PDF • 6 Pages • Free

Identify combinations that let one person initiate and complete a risky transaction, test them against actual user access, and judge whether compensating controls really work.
PDF • 6 Pages • Free

Audit payroll from employee changes and time data to calculation and payment — testing joiners, leavers and one-off payments, reconciling to the ledger and analyzing ghost-employee indicators.
PDF • 6 Pages • Free

Judge whether proposed actions will fix the confirmed root cause — with a named owner, realistic date, measurable completion evidence, interim controls and an agreed way to validate closure.
PDF • 6 Pages • Free

Verify that agreed actions are really implemented and working — prioritizing by residual risk, obtaining evidence rather than status updates, reperforming key controls and escalating overdue high-risk items.
PDF • 6 Pages • Free

Design repeatable tests that flag exceptions reliably — choosing suitable risks, defining exact logic and thresholds, assigning investigation owners, piloting with real data and tracking trends.
PDF • 6 Pages • Free

Audit access to critical systems — joiner, mover and leaver workflows, timely removal, privileged and dormant accounts, access recertification, and the change and logging controls behind them.
PDF • 6 Pages • Free

Communicate results executives act on: lead with the conclusion and the two or three risks that matter, explain cause and consequence, and show actions, owners and decisions needed.
PDF • 6 Pages • Free

Check that an engagement is ready for fieldwork: purpose linked to business risk, prior issues reviewed, risks and scope explicit, out-of-scope areas justified, and resources and timing realistic.
PDF • 6 Pages • Free

Start an audit with clear expectations: prepare scope and information requests, confirm roles and escalation points in the meeting, and document agreed dates, owners and scope changes afterwards.
PDF • 6 Pages • Free

Confirm how a process actually works before testing: trace a real transaction, watch each system step and hand-off, capture workarounds and overrides, then compare practice with policy.
PDF • 6 Pages • Free

Verify both control design and operating effectiveness — clear risk and owner, complete populations, tests beyond inquiry, meaningful review evidence, validated exceptions and a conclusion another auditor could reperform.
PDF • 6 Pages • Free

Test whether your evidence is relevant, reliable and sufficient — right period and population, credible sources, corroborated high-risk evidence, resolved conflicts and conclusions that do not exceed the evidence.
PDF • 6 Pages • Free

Cover the key procurement controls: supplier due diligence and competitive sourcing, approved requisitions and POs, evidenced receipt, invoice matching, and monitoring for split spend, duplicates and bank changes.
PDF • 6 Pages • Free

Check supplier creation, changes and maintenance: sponsored and validated vendors, maker-checker approval, independently verified bank changes, complete change logs, blocked dormant vendors and employee/vendor overlaps.
PDF • 6 Pages • Free

Review travel and expense controls end to end — realistic policy limits, pre-trip approval, complete receipts, substantive approver review, and analytics for duplicates, personal extensions and repeated overrides.
PDF • 6 Pages • Free

Check payroll from employee master data to payment: approved hires and changes, timely leaver removal, validated overtime and adjustments, reconciliations, independently approved payment files and reviewed system access.
PDF • 6 Pages • Free

Verify invoice processing and payment controls — controlled receipt, PO/receipt matching, justified non-PO invoices, independently reviewed payment runs, and analytics for duplicates, threshold payments and recent bank changes.
PDF • 6 Pages • Free

Check that fraud risk is assessed properly: schemes identified by process and asset, override and collusion considered, controls mapped to each scenario, and red-flag analytics, whistleblowing and investigation protocols in place.
PDF • 6 Pages • Free

Review segregation of duties end to end — risk-based conflict definitions, privileged and emergency access, users matched to current roles, tested compensating controls and remediation prioritized by business impact.
PDF • 6 Pages • Free

Verify access and core IT general controls: approved least-privilege access, prompt leaver removal, controlled privileged and service accounts, evidence-based access reviews, approved changes and tested backups.
PDF • 6 Pages • Free

Check inventory controls from receipt to write-off: matched receipts, physical security, authorized transfers, independent cycle counts, approved adjustments and destruction, and analytics on unusual movements.
PDF • 6 Pages • Free

Review sales and revenue controls — approved price and discount authority, controlled overrides and promotions, order-to-invoice matching, period-end cut-off, and analytics on discounts, credit notes and revenue trends.
PDF • 6 Pages • Free

Check customer credit and collections: verified customers, documented credit limits, enforced credit holds, timely cash application, risk-based collections, supported bad-debt provisions and reported concentration risk.
PDF • 6 Pages • Free

Audit third-party arrangements: risk-based due diligence, contracts with data protection and audit rights, measurable and validated SLAs, applied penalties, continuity and exit plans, and dependency oversight.
PDF • 6 Pages • Free

Review a report before issue: an executive summary that answers the objective, consistent conclusions, well-built and evidenced findings, actions that fix root causes, and checked names, figures and sensitive information.
PDF • 6 Pages • Free

Validate that agreed actions really work before closure — defined closure evidence, controls operating in practice, residual risk reassessed, partial completion not closed, and overdue high-risk actions escalated.
PDF • 6 Pages • Free

Audit store operations on site: cash counts and deposits, POS access, refunds, voids and discounts, inventory and shrink controls, price accuracy, staffing records, security and incident handling.
PDF • 6 Pages • Free

Turn an audit request into a focused, risk-based engagement plan, documenting purpose, objectives, in- and out-of-scope areas, walkthroughs, data needs and milestones in one reviewable record.
PDF • 6 Pages • Free

Define exactly what the audit will cover and what it will not, recording included processes, locations and systems, documented exclusions with reasons, and how scope changes are approved.
PDF • 6 Pages • Free

Build a practical risk and control matrix that links each business objective and risk to its control, owner, frequency and evidence, then records the planned test and conclusion.
PDF • 6 Pages • Free

Convert audit objectives and risks into clear, reviewable procedures, recording the expected control, procedure steps, population or sample, evidence expected, results and reviewer clearance.
PDF • 6 Pages • Free

Issue clear PBC and information requests that state the item, period, population, required fields and format, track owner and status, and check completeness against the source system.
PDF • 6 Pages • Free

Capture how a process actually works during a walkthrough, documenting triggers, hand-offs, systems, key controls, override rights, urgent exceptions, evidence captured and open questions.
PDF • 6 Pages • Free

Document a defensible sample: population source and completeness, risk strata, sample size and selection method, high-risk items added, exceptions found and the conclusion on the population.
PDF • 6 Pages • Free

Record audit interviews in a structured way, separating key facts from stated judgments, flagging potential contradictions, and tracking the evidence promised, owners and any further interviews.
PDF • 6 Pages • Free

Develop a well-supported audit finding from criteria, condition and cause through risk, evidence and frequency, to the recommended outcome, management action, owner and due date.
PDF • 6 Pages • Free

Document management actions that address the root cause, with milestones, dependencies, budget, evidence of completion, a success measure and Internal Audit validation of residual risk.
PDF • 6 Pages • Free

Condense audit results into a sharp executive summary: the headline message, overall risk implication, top three findings and common root cause, positive controls, critical actions and follow-up timing.
PDF • 6 Pages • Free
Track open audit issues across a portfolio, recording finding ID, risk rating, owner and due date, latest status and evidence, days overdue, residual risk and escalation decisions.
PDF • 6 Pages • Free

Document whether a management action was truly implemented and is working, from evidence received and retesting to a clear close, partially close or keep-open decision with rationale.
PDF • 6 Pages • Free

Design and document a repeatable monitoring test: risk statement, data fields and rule logic, alert threshold and tolerance, false-positive handling, alert reviewers, evidence retained and escalation.
PDF • 6 Pages • Free

Assess fraud scenarios process by process, recording who could commit them, incentive, pressure and opportunity, preventive and detective controls, gaps and override risk, and the audit response.
PDF • 6 Pages • Free

Document vendor due diligence before onboarding: registration and beneficial ownership, conflicts, sanctions and adverse information, PEP and high-risk countries, bank verification, payment terms and risk classification.
PDF • 6 Pages • Free

Review a trip end to end: business purpose, pre-approval and policy limits, hotel, flight, taxi and meal testing, receipts, duplicates and personal spend, exception value and recovery action.
PDF • 6 Pages • Free

Summarize a store visit with a scorecard for cash and POS, inventory and operations, critical observations with evidence and photo references, immediate actions, owners and the follow-up visit.
PDF • 6 Pages • Free

Prepare a concise Audit Committee dashboard covering plan completion and changes, coverage gaps, emerging risks, high-rated findings, recurring root causes, overdue high-risk actions and decisions needed.
PDF • 6 Pages • Free

Build a risk-based annual audit plan from the risk universe: risk scores and trends, last assurance coverage, proposed engagements with rationale, quarters and days, resource allocation and contingency.
PDF • 6 Pages • Free

Build a risk-based annual audit plan from the risk universe: risk scores and trends, last assurance coverage, proposed engagements with rationale, quarters and days, resource allocation and contingency.
PDF • 6 Pages • Free

Prepare a concise Audit Committee dashboard covering plan completion and changes, coverage gaps, emerging risks, high-rated findings, recurring root causes, overdue high-risk actions and decisions needed.
PDF • 6 Pages • Free

Summarize a store visit with a scorecard for cash and POS, inventory and operations, critical observations with evidence and photo references, immediate actions, owners and the follow-up visit.
PDF • 6 Pages • Free

Review a trip end to end: business purpose, pre-approval and policy limits, hotel, flight, taxi and meal testing, receipts, duplicates and personal spend, exception value and recovery action.
PDF • 6 Pages • Free

Document vendor due diligence before onboarding: registration and beneficial ownership, conflicts, sanctions and adverse information, PEP and high-risk countries, bank verification, payment terms and risk classification.
PDF • 6 Pages • Free

Assess fraud scenarios process by process, recording who could commit them, incentive, pressure and opportunity, preventive and detective controls, gaps and override risk, and the audit response.
PDF • 6 Pages • Free