
How to Plan a Risk-Based Internal Audit
A six-step approach for moving from business objectives and risks to a focused, defensible audit plan — with clear objectives, scope, evidence and agreed boundaries.
PDF • 6 Pages • Free
Concise practical guides explaining how to perform key internal audit activities and audit specific business processes.
20 resources

A six-step approach for moving from business objectives and risks to a focused, defensible audit plan — with clear objectives, scope, evidence and agreed boundaries.
PDF • 6 Pages • Free

How to follow a real transaction from start to finish, see the process rather than hear the policy, and close with a confirmed process map and evidence list.
PDF • 6 Pages • Free

A practical six-step approach to testing both control design and operating effectiveness — choosing the strongest test method and evaluating exceptions before concluding.
PDF • 6 Pages • Free

How to build findings management acts on: condition, criteria, business risk, root cause, quantified exposure and an action that fixes the cause — in neutral, evidence-based language.
PDF • 6 Pages • Free

Go beyond the immediate error: separate symptoms from recurring conditions, verify each “why” with evidence, and link the real cause to an action that prevents recurrence.
PDF • 6 Pages • Free

A six-step approach to auditing purchase-to-pay — supplier onboarding and bank changes, approvals, three-way matching, and analytics for duplicates, split purchases and overrides.
PDF • 6 Pages • Free

How to audit travel and expenses beyond receipts — policy design, approval quality, spend analytics and behavior patterns such as split claims and unusual taxi or hotel usage.
PDF • 6 Pages • Free

Start with the audit question, not the software: define and validate the data, design risk-based tests, investigate exceptions in context and save logic for reuse or monitoring.
PDF • 6 Pages • Free

Plan and run interviews that produce evidence, not just answers — open questions, “show me” demonstrations, probing exceptions, and notes that separate facts from opinions.
PDF • 6 Pages • Free

Close engagements that withstand challenge: evidence-based conclusions for every objective, validated facts, clear actions and owners, an executive message, and archived follow-up requirements.
PDF • 6 Pages • Free

Convert audit objectives into focused, evidence-producing procedures — linking each objective to its risk, evidence source, coverage and sampling logic, owner and expected workpaper output.
PDF • 6 Pages • Free

Identify where opportunity, pressure and weak oversight create fraud exposure — mapping who can initiate, approve and conceal transactions, then testing the most plausible fraud scenarios.
PDF • 6 Pages • Free

Audit supplier creation and change controls — onboarding evidence, bank-account change verification, duplicate and dormant vendors, change logs and segregation of duties around master-data access.
PDF • 6 Pages • Free

Identify combinations that let one person initiate and complete a risky transaction, test them against actual user access, and judge whether compensating controls really work.
PDF • 6 Pages • Free

Audit payroll from employee changes and time data to calculation and payment — testing joiners, leavers and one-off payments, reconciling to the ledger and analyzing ghost-employee indicators.
PDF • 6 Pages • Free

Judge whether proposed actions will fix the confirmed root cause — with a named owner, realistic date, measurable completion evidence, interim controls and an agreed way to validate closure.
PDF • 6 Pages • Free

Verify that agreed actions are really implemented and working — prioritizing by residual risk, obtaining evidence rather than status updates, reperforming key controls and escalating overdue high-risk items.
PDF • 6 Pages • Free

Design repeatable tests that flag exceptions reliably — choosing suitable risks, defining exact logic and thresholds, assigning investigation owners, piloting with real data and tracking trends.
PDF • 6 Pages • Free

Audit access to critical systems — joiner, mover and leaver workflows, timely removal, privileged and dormant accounts, access recertification, and the change and logging controls behind them.
PDF • 6 Pages • Free

Communicate results executives act on: lead with the conclusion and the two or three risks that matter, explain cause and consequence, and show actions, owners and decisions needed.
PDF • 6 Pages • Free