- Annual Internal Audit Planning & Resource Management — Internal Audit · 7 steps
Run the chief audit executive's annual internal audit planning cycle: refresh the audit universe and the documented understanding of governance, risk, and control processes, develop the risk-based strategy and plan, secure the budget, staffing, and technology to deliver it, obtain board approval, and reassess the plan and resource sufficiency each quarter as the risk landscape changes.
- Audit Engagement Planning — Internal Audit · 8 steps
Establish the scope, engagement risk assessment, control population, and sampling plan for an already-opened audit engagement — together the engagement Risk & Control Matrix (RCM) — culminating in an approved planning memo and an enriched audit record handed to fieldwork.
- Audit Fieldwork, Findings & Reporting — Internal Audit · 3 steps
Execute approved audit procedures, evaluate and clear observations, issue a supported report, and close the engagement record with tracked actions.
- Audit Planning and Scoping — Internal Audit · 2 steps
Define engagement objectives, boundaries, independence, program, resources and approval before fieldwork.
- Audit Report Drafting — Internal Audit · 10 steps
Compile fieldwork findings into a formal audit report, from issue drafting and executive summary through management responses and final issuance.
- Continuous Monitoring & Agent Evaluation — Internal Audit · 2 steps
Run the standing continuous auditing program: define KRI thresholds and queries, build and approve the monitoring dashboard, run the recurring monitoring cycle and triage breaches, then sample and grade agent-drafted suggestions and step results from across the course against the agent-draft rubric and raise every agent-quality finding as an owned issue.
- Control Design Assessment — Internal Audit · 1 steps
Judge whether the control's precision, evidence, ownership, frequency and segregation address its stated risk.
- Control Exception Evaluation and Remediation — Internal Audit; with Risk Management · 2 steps
Evaluate exception scope, impact, severity and compensating controls, then obtain management-owned remediation and authorized escalation.
- Control Remediation Retest and Closure — Internal Audit · 2 steps
Independently retest failed attributes on post-remediation evidence, assess recurrence and authorize finding closure.
- Control Walkthrough — Internal Audit · 1 steps
Trace an actual occurrence from input through operator action and retained evidence, challenging differences between procedure and practice.
- Cybersecurity Assurance Review — Internal Audit; with IT · 8 steps
Run a CAE-owned cybersecurity assurance review on the existing IT-audit engagement item — IIA Topical Requirement coverage tested against NIST 800-53 — producing a four-Cs findings register and a Standard 14.5 posture conclusion for report drafting.
- Finding Remediation & Action-Plan Monitoring — Internal Audit · 7 steps
Track audit findings and agreed actions from registration through evidence validation, escalation, risk acceptance, and committee reporting.
- Fraud & Forensic Investigation Engagement — Internal Audit; with Compliance & Legal · 13 steps
Run a predication-gated fraud and forensic investigation from allegation intake through evidence preservation, forensic procedures, interviews, loss quantification, audit-committee reporting, and referral and remediation handoffs.
- Fraud Risk Assessment & JE Testing — Internal Audit · 2 steps
Assess fraud risks across the fraud triangle and management override, map anti-fraud controls, profile and flag the journal-entry population, draw a reproducible random sample from the unflagged remainder, test every selected entry for support, and raise unsupported anomalies as issues.
- Internal Audit Charter, Independence & Board Governance Cycle — Internal Audit; with Executive · 8 steps
Run the internal audit function's board-governance cycle: deliver the CAE's functional reporting and executive sessions to the audit committee, secure committee action on the CAE's appointment, evaluation, remuneration, and the audit plan and budget, and reaffirm the function's organizational independence in writing. Lead the periodic board review and reapproval of the audit mandate and charter with its unrestricted-access provisions, execute the stakeholder communication plan across the board, management, regulators, and external auditors, and retain the governance evidence.
- Internal Audit Engagement Lifecycle — Internal Audit · 7 steps
Run an IIA-aligned engagement on the existing Audit item — from evidence requests and fieldwork through an evaluated findings register (Issue items), conclusions per objective, a report-ready handoff package, and registered action plans.
- Internal Audit Ethics, Objectivity & Competency Program — Internal Audit · 6 steps
Run the internal audit function's annual professional-practice cycle: every auditor and assisting party attests to the ethics and professional-courage expectations with deviations documented and resolved, signs conflict-of-interest declarations backed by per-engagement conflict screening, assignment rotation, and recusal, and completes confidentiality acknowledgments while access to audit files is reviewed and restricted; the cycle closes with competency assessment against role requirements and approved, tracked continuing-professional-development plans for each auditor.
- ISO 27001 Certification Readiness — Internal Audit · 2 steps
Assess ISO/IEC 27001 certification readiness across ISMS scope, clauses, risk treatment, Annex A applicability, internal assurance, gaps, and audit-entry governance.
- ISO 27001 Stage 1 ISMS Documentation Review — Internal Audit · 1 steps
Review ISMS clauses 4–10 documentation, record findings, and conclude readiness for Stage 2 planning.
- ISO 27001 Stage 2 Annex A Controls Audit — Internal Audit · 5 steps
Audit the organizational, people, physical and technological Annex A controls in the approved Statement of Applicability, with specialist assessments and an independent conclusion.
- ISO/IEC 42001 AI Management System Internal Audit — Internal Audit; with AI Governance · 2 steps
Plan and perform an independent internal audit of an AI management system against ISO/IEC 42001, using AIUC-1 crosswalk evidence where it helps test AI-specific safeguards; document findings, management actions, and an independent conclusion without presenting the work as certification.
- ITGC Change & Provisioning Testing — Internal Audit · 2 steps
Test the design and operating effectiveness of change-management and access-provisioning controls for one in-scope system: validate the populations, draw the samples, test each ticket against the control's attributes, conclude, and raise exceptions.
- Process Narrative & Walkthrough — Internal Audit · 1 steps
Document an end-to-end process, corroborate the narrative through a representative walkthrough, and approve a traceable current-state record.
- Quality Assurance & Improvement Program Cycle — Internal Audit · 10 steps
Operate the QAIP cycle on a per-cycle Audit item — ongoing-monitoring evidence, periodic self-assessment, external quality assessment support, improvement planning, and board reporting — producing the per-standard conformance ratings matrix, below-GC finding Issues, and the QAIP results report handed to board reporting.
- SOC 2 Availability Assessment — Internal Audit · 1 steps
Assess design readiness for Availability with documented evidence, findings and reviewer conclusions.
- SOC 2 Confidentiality Assessment — Internal Audit · 1 steps
Assess design readiness for Confidentiality with documented evidence, findings and reviewer conclusions.
- SOC 2 Privacy Criteria Assessment — Internal Audit · 1 steps
Assess design readiness for Privacy with documented evidence, findings and reviewer conclusions.
- SOC 2 Processing Integrity Assessment — Internal Audit · 1 steps
Assess design readiness for Processing Integrity with documented evidence, findings and reviewer conclusions.
- SOC 2 Trust Services Readiness — Internal Audit · 3 steps
Assess SOC 2 CC1–CC9 design readiness, reconcile scoped category assessments, and approve a criterion-level readiness disposition with evidence, findings and owned actions.
- SOC 2 Type II Interim Testing — Internal Audit · 2 steps
Perform SOC 2 Type II interim walkthroughs and control testing, then triage exceptions for remediation and retest.
- Substantive Testing & Data Analytics — Internal Audit · 2 steps
Validates a test population, draws a reproducible sample sized to risk, runs whole-population analytics (duplicates, gaps, three-way match) alongside it, evaluates and projects exceptions, and concludes on the tested FSLI assertion(s).
- Third-Party Vendor Assurance Engagement — Internal Audit; with Procurement · 8 steps
Run an IA-led third-party assurance engagement covering governance, risk tiering, control environment, monitoring, exclusions, and reporting.