Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

Internal audit practices are the methods a function uses to plan, execute, evidence and report its work — and the discipline that makes the output defensible when someone challenges it. Two audit functions can follow the same standards and produce very different assurance, because practice is where standards meet reality: how the plan is built, how evidence is captured, how findings actually close.
This guide sets out the practice areas that matter, what good looks like in each, and the failure patterns that show up most often in quality assessments.
Standards tell you what must be true. Practice is how you make it true repeatedly, across a team, under time pressure.
The audit universe should be an inventory of auditable entities scored on risk, not a list of departments. Weighted risk factors, inherent and residual scoring, and a refresh cadence faster than annual are the difference between a plan that reflects the business and one that reflects last year’s org chart.
The practice failure here is rarely the scoring model. It is capacity. A plan approved without a capacity check is a forecast of disappointment: coverage slips, engagements get compressed, and quality is the thing that gives. Good practice models auditor availability in days, matches skills to engagements, and shows planned-versus-actual utilisation while there is still time to act.
Execution practice starts before testing: document the end-to-end process walkthrough and the controls that should be operating, so testing begins from a clear understanding of control design rather than an assumption about it.
Then the evidence discipline. The recurring failure across engagements is that proof lives in an inbox rather than in the working paper it supports. When evidence is forwarded rather than captured, three things follow: the file is incomplete at review, the sufficiency of evidence cannot be assessed, and the trail has to be reconstructed at report time. Our guide to testing and documenting IT controls covers what the working paper needs to demonstrate.
Review that happens only at the end of an engagement is review that arrives too late to improve anything. By the time notes come back, the preparer has moved on and cannot clear them from memory — so the correction becomes rework rather than coaching.
Good practice is a defined preparer → reviewer → approver chain with interim review during fieldwork, coaching notes distinguished from correction notes, and sign-off captured as the work happens rather than assembled afterwards. Independence and objectivity evidence should be a by-product of the workflow, not a document created at report time.
This is where most functions lose credibility. Repeat findings recur not because management is negligent but because the practice around closure is weak in three specific ways:
Good practice stages observations through defined states, keeps a management-response thread attached to the finding, and maintains an issue repository that carries across engagements and years so repeats are visible as repeats. See the most common IT audit missteps for how these compound.
A report that lands two weeks after fieldwork closes is reporting on a risk picture that has already moved. Reporting practice should compress the gap: a consistent finding structure, ratings applied against a documented rubric rather than by feel, and a committee view that distinguishes the few things requiring a decision from the many things requiring awareness. Our post on quality assurance in IT audit reporting goes deeper on consistency.
The Standards require a quality assurance and improvement programme: ongoing internal monitoring, periodic internal assessment, and an external quality assessment at least every five years. In practice, the internal half is what gets skipped, and then the external assessment becomes an event to survive rather than a confirmation of what you already knew.
Sustainable practice: sample completed engagements against a defined checklist each quarter, track conformance findings the same way you track audit findings, and report QAIP results to the committee alongside audit results.
For the fieldwork end, our free IT audit checklist template covers ITGC, application controls and NCA ECC requirements.
Disclosure: ControlVista is our own audit management software. The practice guidance above stands independently of it.
Most of the failures above are practice problems before they are tooling problems — but several of them are structurally hard to fix in spreadsheets, because a spreadsheet cannot enforce a workflow. Interim review, ageing and escalation, and verification with segregation of duties all depend on the system refusing to let a step be skipped.
ControlVista maps to the practice areas above: VistaPlan for risk-scored planning and capacity, VistaField for walkthroughs, testing and three-stage sign-off, VistaResolve for staged findings and verified closure, and VistaReport for committee-ready reporting. It aligns to IIA Standards, COSO and ISO 19011, and deploys on infrastructure you control rather than multi-tenant SaaS — which matters when the files in question are draft findings and unremediated control weaknesses. See our fuller guide to audit management software for evaluation criteria.