Skip to main content
All articles

Internal Audit

Internal Audit Checklist: How to Plan a Useful Review

By RiskSensai6 min read
Editorial archive date
First published
Facts checked

The archive date places this article in the editorial collection. It is not an original publication date. Guidance reflects the fact-check date above.

Internal Audit Checklist: How to Plan a Useful Review: original RiskSensai editorial cover

Plan the review around a business question

A useful internal audit asks a clear question about a business activity. Are purchase approvals operating as intended? Are privileged accounts reviewed within the agreed scope? Does the recovery process support the stated service need?

The IIA's Global Internal Audit Standards provide the professional framework for internal auditing.1 This article is an original planning aid, not a substitute for that framework or a complete claim of conformance. Formal internal audit responsibilities should be assigned to people with appropriate competence, objectivity and authority.

A small business may begin with a management review or self-check. Label it accurately if it does not constitute a formal internal audit engagement. A familiar checklist title should not imply independence that the review does not have.

1. Establish the mandate and objective

Identify who requested the work, who will receive the results and what decision the review supports. State the objective in a way that can be answered with evidence.

“Review purchasing” is broad. “Evaluate whether purchases above the approved threshold were authorized by the appropriate person during the last quarter” is more focused. Do not add a threshold simply because it appears in a template; use the actual approved policy or obligation.

Confirm authority to access the necessary information and arrangements for escalation. A reviewer should not obtain evidence by bypassing existing access controls or copying sensitive records into an unapproved folder.

2. Define scope and limitations

Document the activity, entity, systems, locations and period. Note exclusions, outsourced responsibilities and interfaces with other processes. Explain why each exclusion is reasonable for the objective.

The IIA's condensed standards address communication, engagement risk assessment, objectives, scope and evaluation criteria.2 Those elements help prevent a narrow review being interpreted as a conclusion about the whole company.

If records cannot be obtained or an important area is excluded, preserve that limitation in the work program and eventual communication. Do not let missing access silently become a successful test result.

3. Understand the process and its risks

Walk through the activity with people who operate it. Ask how normal work, urgent exceptions and failures are handled. Compare the documented process with a small number of actual occurrences to understand where further work is needed.

Identify risks that could prevent the objective. In purchasing, those might include unauthorized commitments, duplicate payments or emergency orders avoiding normal approval. The work program should focus on relevant risks rather than repeat every possible control topic.

The IT general controls guide explains technology dependencies that may affect a process review. Record assumptions and conflicting explanations. A process owner may believe the finance system blocks unauthorized orders while a user describes a manual workaround. That is a question to investigate, not a fact to average away.

4. Agree criteria before evaluating the condition

Criteria explain what should happen. They may come from an approved policy, applicable requirement, contract, procedure or an appropriately selected standard. Record the source and version.

Condition describes what the evidence indicates actually happened. Comparing condition with a clear criterion makes a potential finding understandable. If the criterion is unclear or disputed, address that issue before asserting a failure against it.

Do not create a new expectation during the review and treat earlier activity as nonconforming without explaining the basis. A recommended improvement can be useful even where no existing requirement was breached, but it should be described accordingly.

5. Build a focused work program

Work-program fieldWhat to record
Risk and objectiveWhy the procedure is needed
CriterionSource, version and applicable expectation
PopulationRelevant occurrences and how completeness is established
ProcedureExamination, discussion, observation or test
SelectionItems or scope chosen and the reason
EvidenceSource, period, location and integrity notes
ResultWhat was found, including exceptions and limitations
ReviewWho checked the work and unresolved questions

NIST SP 800-53A supplies a useful distinction between examination, interview and testing methods for control assessment.3 It does not prescribe your internal audit scope; use methods appropriate to the actual objective and governing requirements.

Worked example: purchasing approvals

This fictional engagement reviews a manufacturer's domestic purchasing process for a quarter. The approved policy requires a designated approver for orders above a stated threshold, with a documented emergency route.

The reviewer obtains the purchase-order population and reconciles it with the finance register. It separates normal and emergency orders, then selects procedures proportionate to the identified risks. The example does not imply a universally sufficient sample size.

Review stepExample result
Read the policy and confirm approval authorityCurrent policy identifies normal and emergency routes
Check population completenessTwo manually entered orders require reconciliation
Inspect selected approval recordsOne normal order lacks retained authorization
Discuss emergency processingStaff report a workaround not reflected in the procedure
Investigate exceptionsManagement supplies context; missing evidence remains unresolved

The reviewer does not conclude that every purchase was unauthorized. It records the affected items, applicable criterion, evidence and scope. The undocumented workaround may require further investigation or a process improvement, with its own rationale.

6. Develop potential findings carefully

A potential finding should identify the criterion, observed condition, evidence, relevant consequence and cause where supportable. Separate confirmed facts from inference and management explanation.

Discuss factual accuracy with the responsible owner without surrendering the review's objectivity. If management disagrees, record the differing position and its basis. Do not remove a supported issue solely because it is inconvenient.

Avoid unsupported severity labels. Explain the potential effect and the method used for prioritization. If the evidence is insufficient, obtain more information or report the limitation rather than present a definitive conclusion.

7. Agree actions without taking over management

Management should decide and own corrective action. A reviewer can make recommendations and evaluate whether the proposed response addresses the issue, but should not become responsible for operating the control they later review.

Each action needs an owner, date and closure criterion. “Remind staff” may not address a system or authority gap. A stronger response could update the approval route, test its operation and review subsequent records, depending on the finding.

Record any accepted risk through the appropriate authority and escalation process. An overdue action is not closed merely because its deadline was moved.

8. Communicate a bounded conclusion

State the objective, scope, period, procedures at an appropriate level, important results and limitations. Explain what management must decide and which actions are agreed.

Use language that matches the work. A limited process review should not be presented as an organization-wide assurance opinion. Distinguish an observed exception from a conclusion about the entire population where the method does not support that conclusion.

9. Follow up with evidence

Track agreed actions and confirm completion against the stated criteria. An updated policy alone may not demonstrate that the new procedure operates. Review the relevant implementation and operational evidence, and preserve failed checks.

Record who reviewed closure, what evidence was considered and any residual limitation. Escalate unresolved or materially overdue work under the agreed governance process.

Final engagement checklist

Before concluding, confirm mandate, objective, scope and criteria are documented. Verify evidence coverage and provenance, record exceptions and limitations, review findings for factual support, and agree accountable actions. Then schedule follow-up and protect the retained records.

The best checklist is the one that makes the reasoning retrievable: why the review was done, what was checked, what the evidence showed and what happens next.

Sources and references

  1. The Institute of Internal Auditors. Global Internal Audit Standards, 2024 edition (2024). Primary professional framework covers governance, objectivity, engagement planning, evidence and action monitoring. ↩

  2. The Institute of Internal Auditors. Condensed Global Internal Audit Standards (2024-01-09). Primary condensed edition supports engagement scope, criteria, evidence and follow-up; the checklist below is original, not a reproduction. ↩

  3. NIST. Assessing Security and Privacy Controls, SP 800-53A Revision 5 (2022-01). Describes examination, interview and testing methods; source examples are adapted, not a claim to meet federal requirements. ↩

General educational information, not legal advice, a professional audit opinion, certification, or a guarantee. Applicability and conclusions depend on your organization and should be assessed by an appropriately qualified professional.

Prepared with AI assistance and automated editorial checks. This does not indicate independent professional review or verification of your organization.

  • Internal Audit
  • Checklists
  • Evidence
Connecting to your conversation workspace…