
Walkthrough Process Mapping Tool
Document how a process really works during walkthroughs — steps, roles, systems, approvals, evidence, exceptions and manual workarounds.
PDF • 6 Pages • Free
Internal controls are how organizations make sure that transactions are authorized, recorded correctly and protected from error and fraud. For internal auditors, evaluating controls is everyday work — and also where weak methodology is most visible to management and external auditors.
In a controls review, auditors typically walk through the process to see how it really works, map risks to controls, assess whether each control is designed well enough to address its risk, and then test whether it operates consistently over time. They also look at segregation of duties, ownership and the evidence each control leaves behind.
Common risks include controls that exist on paper only, controls with no named owner, reviews performed without real challenge, tests that rely on inquiry instead of evidence, samples that do not represent the population, and exceptions that are dismissed without understanding why they happened.
The resources below cover the full control evaluation cycle. Tools help you assess design, choose test methods, plan samples and evaluate exceptions; guides explain walkthroughs and control testing step by step; checklists keep fieldwork consistent; and templates such as the risk and control matrix and walkthrough notes give you working papers you can use on your next engagement.
35 free resources · No registration

Document how a process really works during walkthroughs — steps, roles, systems, approvals, evidence, exceptions and manual workarounds.
PDF • 6 Pages • Free

Check whether a control is designed well enough to address its risk — owner, frequency, evidence, precision and exception response — before you test it.
PDF • 6 Pages • Free

Test the quantity, relevance, reliability and corroboration of your evidence before finalizing a finding or conclusion.
PDF • 6 Pages • Free

Choose the strongest practical test method — inquiry, inspection, observation, reperformance or data analytics — for each control and assertion.
PDF • 6 Pages • Free

Plan a defensible sampling approach — population, objective, risk strata and selection method — before you pull a sample. A planning aid, not a sample-size calculator.
PDF • 6 Pages • Free

Decide whether a test exception is isolated, recurring, systemic or evidence of control failure — and whether to expand testing or raise a finding.
PDF • 6 Pages • Free

Plan focused interviews and walkthrough meetings that separate what people say from the evidence that still needs corroboration.
PDF • 6 Pages • Free

Map key activities to Responsible, Accountable, Consulted and Informed roles to expose ownership gaps, conflicting accountability and concentration of duties.
PDF • 6 Pages • Free

How to follow a real transaction from start to finish, see the process rather than hear the policy, and close with a confirmed process map and evidence list.
PDF • 6 Pages • Free

A practical six-step approach to testing both control design and operating effectiveness — choosing the strongest test method and evaluating exceptions before concluding.
PDF • 6 Pages • Free

Plan and run interviews that produce evidence, not just answers — open questions, “show me” demonstrations, probing exceptions, and notes that separate facts from opinions.
PDF • 6 Pages • Free

Convert audit objectives into focused, evidence-producing procedures — linking each objective to its risk, evidence source, coverage and sampling logic, owner and expected workpaper output.
PDF • 6 Pages • Free

Identify combinations that let one person initiate and complete a risky transaction, test them against actual user access, and judge whether compensating controls really work.
PDF • 6 Pages • Free

Audit access to critical systems — joiner, mover and leaver workflows, timely removal, privileged and dormant accounts, access recertification, and the change and logging controls behind them.
PDF • 6 Pages • Free

Confirm how a process actually works before testing: trace a real transaction, watch each system step and hand-off, capture workarounds and overrides, then compare practice with policy.
PDF • 6 Pages • Free

Verify both control design and operating effectiveness — clear risk and owner, complete populations, tests beyond inquiry, meaningful review evidence, validated exceptions and a conclusion another auditor could reperform.
PDF • 6 Pages • Free

Test whether your evidence is relevant, reliable and sufficient — right period and population, credible sources, corroborated high-risk evidence, resolved conflicts and conclusions that do not exceed the evidence.
PDF • 6 Pages • Free

Check supplier creation, changes and maintenance: sponsored and validated vendors, maker-checker approval, independently verified bank changes, complete change logs, blocked dormant vendors and employee/vendor overlaps.
PDF • 6 Pages • Free

Check that fraud risk is assessed properly: schemes identified by process and asset, override and collusion considered, controls mapped to each scenario, and red-flag analytics, whistleblowing and investigation protocols in place.
PDF • 6 Pages • Free

Review segregation of duties end to end — risk-based conflict definitions, privileged and emergency access, users matched to current roles, tested compensating controls and remediation prioritized by business impact.
PDF • 6 Pages • Free

Verify access and core IT general controls: approved least-privilege access, prompt leaver removal, controlled privileged and service accounts, evidence-based access reviews, approved changes and tested backups.
PDF • 6 Pages • Free

Check inventory controls from receipt to write-off: matched receipts, physical security, authorized transfers, independent cycle counts, approved adjustments and destruction, and analytics on unusual movements.
PDF • 6 Pages • Free

Review sales and revenue controls — approved price and discount authority, controlled overrides and promotions, order-to-invoice matching, period-end cut-off, and analytics on discounts, credit notes and revenue trends.
PDF • 6 Pages • Free

Check customer credit and collections: verified customers, documented credit limits, enforced credit holds, timely cash application, risk-based collections, supported bad-debt provisions and reported concentration risk.
PDF • 6 Pages • Free

Audit store operations on site: cash counts and deposits, POS access, refunds, voids and discounts, inventory and shrink controls, price accuracy, staffing records, security and incident handling.
PDF • 6 Pages • Free

Build a practical risk and control matrix that links each business objective and risk to its control, owner, frequency and evidence, then records the planned test and conclusion.
PDF • 6 Pages • Free

Convert audit objectives and risks into clear, reviewable procedures, recording the expected control, procedure steps, population or sample, evidence expected, results and reviewer clearance.
PDF • 6 Pages • Free

Capture how a process actually works during a walkthrough, documenting triggers, hand-offs, systems, key controls, override rights, urgent exceptions, evidence captured and open questions.
PDF • 6 Pages • Free

Document a defensible sample: population source and completeness, risk strata, sample size and selection method, high-risk items added, exceptions found and the conclusion on the population.
PDF • 6 Pages • Free

Record audit interviews in a structured way, separating key facts from stated judgments, flagging potential contradictions, and tracking the evidence promised, owners and any further interviews.
PDF • 6 Pages • Free

Develop a well-supported audit finding from criteria, condition and cause through risk, evidence and frequency, to the recommended outcome, management action, owner and due date.
PDF • 6 Pages • Free

Document whether a management action was truly implemented and is working, from evidence received and retesting to a clear close, partially close or keep-open decision with rationale.
PDF • 6 Pages • Free

Design and document a repeatable monitoring test: risk statement, data fields and rule logic, alert threshold and tolerance, false-positive handling, alert reviewers, evidence retained and escalation.
PDF • 6 Pages • Free

Assess fraud scenarios process by process, recording who could commit them, incentive, pressure and opportunity, preventive and detective controls, gaps and override risk, and the audit response.
PDF • 6 Pages • Free

Summarize a store visit with a scorecard for cash and POS, inventory and operations, critical observations with evidence and photo references, immediate actions, owners and the follow-up visit.
PDF • 6 Pages • Free