Internal Audit Practices: Standards and Methodology — TheAudit.org

Internal Audit Practices: Standards, Methodology and Quality

Internal audit practices are the methods a function uses to plan, execute, evidence and report its work — and the discipline that makes the output defensible when someone challenges it. Two audit functions can follow the same standards and produce very different assurance, because practice is where standards meet reality: how the plan is built, how evidence is captured, how findings actually close.

This guide sets out the practice areas that matter, what good looks like in each, and the failure patterns that show up most often in quality assessments.

The standards that define the baseline

  • IIA Global Internal Audit Standards — the profession’s baseline, restructured around domains covering purpose, ethics, governance, managing the function and performing engagements. If your methodology has not been revisited against the current version, that is the first gap to close.
  • COSO Internal Control – Integrated Framework — the control model most engagements are implicitly testing against, whether or not the working papers say so.
  • ISO 19011 — guidance on auditing management systems; useful for audit programme design, auditor competence and evidence sufficiency.

Standards tell you what must be true. Practice is how you make it true repeatedly, across a team, under time pressure.

Practice area 1 — Risk-based planning

The audit universe should be an inventory of auditable entities scored on risk, not a list of departments. Weighted risk factors, inherent and residual scoring, and a refresh cadence faster than annual are the difference between a plan that reflects the business and one that reflects last year’s org chart.

The practice failure here is rarely the scoring model. It is capacity. A plan approved without a capacity check is a forecast of disappointment: coverage slips, engagements get compressed, and quality is the thing that gives. Good practice models auditor availability in days, matches skills to engagements, and shows planned-versus-actual utilisation while there is still time to act.

Practice area 2 — Engagement execution and evidence

Execution practice starts before testing: document the end-to-end process walkthrough and the controls that should be operating, so testing begins from a clear understanding of control design rather than an assumption about it.

Then the evidence discipline. The recurring failure across engagements is that proof lives in an inbox rather than in the working paper it supports. When evidence is forwarded rather than captured, three things follow: the file is incomplete at review, the sufficiency of evidence cannot be assessed, and the trail has to be reconstructed at report time. Our guide to testing and documenting IT controls covers what the working paper needs to demonstrate.

Practice area 3 — Review and supervision

Review that happens only at the end of an engagement is review that arrives too late to improve anything. By the time notes come back, the preparer has moved on and cannot clear them from memory — so the correction becomes rework rather than coaching.

Good practice is a defined preparer → reviewer → approver chain with interim review during fieldwork, coaching notes distinguished from correction notes, and sign-off captured as the work happens rather than assembled afterwards. Independence and objectivity evidence should be a by-product of the workflow, not a document created at report time.

Practice area 4 — Findings and follow-up

This is where most functions lose credibility. Repeat findings recur not because management is negligent but because the practice around closure is weak in three specific ways:

  • Ambiguous ownership. A finding assigned to a department is assigned to nobody.
  • Unchased ageing. If follow-up depends on an auditor remembering to email, overdue actions quietly persist.
  • Self-verification. When the assignee confirms their own remediation, you have a status update, not assurance. Verification needs segregation of duties.

Good practice stages observations through defined states, keeps a management-response thread attached to the finding, and maintains an issue repository that carries across engagements and years so repeats are visible as repeats. See the most common IT audit missteps for how these compound.

Practice area 5 — Reporting

A report that lands two weeks after fieldwork closes is reporting on a risk picture that has already moved. Reporting practice should compress the gap: a consistent finding structure, ratings applied against a documented rubric rather than by feel, and a committee view that distinguishes the few things requiring a decision from the many things requiring awareness. Our post on quality assurance in IT audit reporting goes deeper on consistency.

Practice area 6 — Quality assurance

The Standards require a quality assurance and improvement programme: ongoing internal monitoring, periodic internal assessment, and an external quality assessment at least every five years. In practice, the internal half is what gets skipped, and then the external assessment becomes an event to survive rather than a confirmation of what you already knew.

Sustainable practice: sample completed engagements against a defined checklist each quarter, track conformance findings the same way you track audit findings, and report QAIP results to the committee alongside audit results.

A practice self-assessment

  • Is the audit universe risk-scored and refreshed more often than annually?
  • Was this year’s plan capacity-tested before approval?
  • Can you show planned-versus-actual hours mid-year, not just at the post-mortem?
  • Does evidence live in the working paper, or in an inbox?
  • Is review interim, or end-loaded?
  • Is remediation verified by someone other than the assignee?
  • Can you list your repeat findings across three years without manual analysis?
  • Are finding ratings applied against a written rubric?
  • Does the QAIP run continuously, or only before an external assessment?

For the fieldwork end, our free IT audit checklist template covers ITGC, application controls and NCA ECC requirements.

Where tooling helps

Disclosure: ControlVista is our own audit management software. The practice guidance above stands independently of it.

Most of the failures above are practice problems before they are tooling problems — but several of them are structurally hard to fix in spreadsheets, because a spreadsheet cannot enforce a workflow. Interim review, ageing and escalation, and verification with segregation of duties all depend on the system refusing to let a step be skipped.

ControlVista maps to the practice areas above: VistaPlan for risk-scored planning and capacity, VistaField for walkthroughs, testing and three-stage sign-off, VistaResolve for staged findings and verified closure, and VistaReport for committee-ready reporting. It aligns to IIA Standards, COSO and ISO 19011, and deploys on infrastructure you control rather than multi-tenant SaaS — which matters when the files in question are draft findings and unremediated control weaknesses. See our fuller guide to audit management software for evaluation criteria.

Related reading

Leave a Reply

Your email address will not be published. Required fields are marked *