- Annual Internal Audit Planning & Resource Management — Internal Audit · 7 steps
Run the chief audit executive's annual internal audit planning cycle: refresh the audit universe and the documented understanding of governance, risk, and control processes, develop the risk-based strategy and plan, secure the budget, staffing, and technology to deliver it, obtain board approval, and reassess the plan and resource sufficiency each quarter as the risk landscape changes.
- Audit Engagement Planning — Internal Audit · 8 steps
Establish the scope, engagement risk assessment, control population, and sampling plan for an already-opened audit engagement — together the engagement Risk & Control Matrix (RCM) — culminating in an approved planning memo and an enriched audit record handed to fieldwork.
- Audit Fieldwork, Findings & Reporting — Internal Audit · 3 steps
Execute approved audit procedures, evaluate and clear observations, issue a supported report, and close the engagement record with tracked actions.
- Audit Planning and Scoping — Internal Audit · 2 steps
Define engagement objectives, boundaries, independence, program, resources and approval before fieldwork.
- Audit Report Drafting — Internal Audit · 10 steps
Compile fieldwork findings into a formal audit report, from issue drafting and executive summary through management responses and final issuance.
- Combined Assurance Mapping — Internal Audit; with Risk Management · 7 steps
Map effective assurance across the Three Lines, resolve self-review safeguards, assess independent reliance and agree coverage commitments; govern remaining gaps and deliver the map and evidence to audit-committee reporting.
- Continuous Monitoring & Agent Evaluation — Internal Audit · 2 steps
Run the standing continuous auditing program: define KRI thresholds and queries, build and approve the monitoring dashboard, run the recurring monitoring cycle and triage breaches, then sample and grade agent-drafted suggestions and step results from across the course against the agent-draft rubric and raise every agent-quality finding as an owned issue.
- Control Design Assessment — Internal Audit · 1 steps
Judge whether the control's precision, evidence, ownership, frequency and segregation address its stated risk.
- Control Exception Evaluation and Remediation — Internal Audit; with Risk Management · 2 steps
Evaluate exception scope, impact, severity and compensating controls, then obtain management-owned remediation and authorized escalation.
- Control Interim Testing Record — Internal Audit · 2 steps
Test a defined interim-period population using a documented sampling and attribute plan, then record exceptions and a bounded conclusion.
- Control Remediation Retest and Closure — Internal Audit · 2 steps
Independently retest failed attributes on post-remediation evidence, assess recurrence and authorize finding closure.
- Control Walkthrough — Internal Audit · 1 steps
Trace an actual occurrence from input through operator action and retained evidence, challenging differences between procedure and practice.
- Cybersecurity Assurance Review — Internal Audit; with IT · 8 steps
Run a CAE-owned cybersecurity assurance review on the existing IT-audit engagement item — IIA Topical Requirement coverage tested against NIST 800-53 — producing a four-Cs findings register and a Standard 14.5 posture conclusion for report drafting.
- Finding Remediation & Action-Plan Monitoring — Internal Audit · 7 steps
Track audit findings and agreed actions from registration through evidence validation, escalation, risk acceptance, and committee reporting.
- Fraud & Forensic Investigation Engagement — Internal Audit; with Compliance & Legal · 13 steps
Run a predication-gated fraud and forensic investigation from allegation intake through evidence preservation, forensic procedures, interviews, loss quantification, audit-committee reporting, and referral and remediation handoffs.
- Fraud Risk Assessment & JE Testing — Internal Audit · 2 steps
Assess fraud risks across the fraud triangle and management override, map anti-fraud controls, profile and flag the journal-entry population, draw a reproducible random sample from the unflagged remainder, test every selected entry for support, and raise unsupported anomalies as issues.
- Interim Operating Effectiveness Testing — Internal Audit; with Finance · 2 steps
Review program coverage and aggregate interim exceptions from approved Control tests, then agree auditor reliance and management actions.
- Internal Audit Charter, Independence & Board Governance Cycle — Internal Audit; with Executive · 8 steps
Run the internal audit function's board-governance cycle: deliver the CAE's functional reporting and executive sessions to the audit committee, secure committee action on the CAE's appointment, evaluation, remuneration, and the audit plan and budget, and reaffirm the function's organizational independence in writing. Lead the periodic board review and reapproval of the audit mandate and charter with its unrestricted-access provisions, execute the stakeholder communication plan across the board, management, regulators, and external auditors, and retain the governance evidence.
- Internal Audit Engagement Lifecycle — Internal Audit · 7 steps
Run an IIA-aligned engagement on the existing Audit item — from evidence requests and fieldwork through an evaluated findings register (Issue items), conclusions per objective, a report-ready handoff package, and registered action plans.
- Internal Audit Ethics, Objectivity & Competency Program — Internal Audit · 6 steps
Run the internal audit function's annual professional-practice cycle: every auditor and assisting party attests to the ethics and professional-courage expectations with deviations documented and resolved, signs conflict-of-interest declarations backed by per-engagement conflict screening, assignment rotation, and recusal, and completes confidentiality acknowledgments while access to audit files is reviewed and restricted; the cycle closes with competency assessment against role requirements and approved, tracked continuing-professional-development plans for each auditor.
- ISMS Internal Audit & Management Review — Internal Audit; with IT, Executive · 6 steps
Run the ISMS clause 9.2 internal audit and clause 9.3 management review: findings, corrective actions, review inputs, decisions, and follow-up.
- ISO 27001 Certification Readiness — Internal Audit · 2 steps
Assess ISO/IEC 27001 certification readiness across ISMS scope, clauses, risk treatment, Annex A applicability, internal assurance, gaps, and audit-entry governance.
- ISO 27001 Stage 1 ISMS Documentation Review — Internal Audit · 1 steps
Review ISMS clauses 4–10 documentation, record findings, and conclude readiness for Stage 2 planning.
- ISO 27001 Stage 2 Annex A Controls Audit — Internal Audit · 5 steps
Audit the organizational, people, physical and technological Annex A controls in the approved Statement of Applicability, with specialist assessments and an independent conclusion.
- ISO/IEC 42001 AI Management System Internal Audit — Internal Audit; with AI Governance · 2 steps
Plan and perform an independent internal audit of an AI management system against ISO/IEC 42001, using AIUC-1 crosswalk evidence where it helps test AI-specific safeguards; document findings, management actions, and an independent conclusion without presenting the work as certification.
- ITGC Change & Provisioning Testing — Internal Audit · 2 steps
Test the design and operating effectiveness of change-management and access-provisioning controls for one in-scope system: validate the populations, draw the samples, test each ticket against the control's attributes, conclude, and raise exceptions.
- Period-End Roll-Forward / Rollover Testing — Internal Audit · 2 steps
Bridge an approved interim control test through period end by assessing change, remaining occurrences, incremental evidence, and unresolved exceptions.
- Period-End Roll-Forward Testing — Internal Audit; with Finance · 3 steps
Bridge interim testing to period end using the remaining population, control changes, additional evidence and a bounded combined conclusion.
- Process Narrative & Walkthrough — Internal Audit · 1 steps
Document an end-to-end process, corroborate the narrative through a representative walkthrough, and approve a traceable current-state record.
- Process Walkthrough & Design Assessment — Internal Audit · 2 steps
Perform a SOX process walkthrough, update the ICFR narrative and control mapping, and document design observations for management follow-up.
- Quality Assurance & Improvement Program Cycle — Internal Audit · 10 steps
Operate the QAIP cycle on a per-cycle Audit item — ongoing-monitoring evidence, periodic self-assessment, external quality assessment support, improvement planning, and board reporting — producing the per-standard conformance ratings matrix, below-GC finding Issues, and the QAIP results report handed to board reporting.
- Quarterly Board & Audit-Committee GRC Reporting — Risk Management; with Internal Audit, Executive · 6 steps
Compile the quarterly GRC board pack across risk profile, audit, SOX, regulatory deadlines, control health, incidents, issues, and decisions.
- SOC 2 Availability Assessment — Internal Audit · 1 steps
Assess design readiness for Availability with documented evidence, findings and reviewer conclusions.
- SOC 2 Confidentiality Assessment — Internal Audit · 1 steps
Assess design readiness for Confidentiality with documented evidence, findings and reviewer conclusions.
- SOC 2 Privacy Criteria Assessment — Internal Audit · 1 steps
Assess design readiness for Privacy with documented evidence, findings and reviewer conclusions.
- SOC 2 Processing Integrity Assessment — Internal Audit · 1 steps
Assess design readiness for Processing Integrity with documented evidence, findings and reviewer conclusions.
- SOC 2 Trust Services Readiness — Internal Audit · 3 steps
Assess SOC 2 CC1–CC9 design readiness, reconcile scoped category assessments, and approve a criterion-level readiness disposition with evidence, findings and owned actions.
- SOC 2 Type II Interim Testing — Internal Audit · 2 steps
Perform SOC 2 Type II interim walkthroughs and control testing, then triage exceptions for remediation and retest.
- SOX Control Testing — Internal Audit · 2 steps
Native SAMPLE approves history, attributes and reproducible selection; TEST independently approves evidence, exceptions and the published SOX result for the fiscal year.
- SOX IPE Validation — Internal Audit; with Finance · 7 steps
Validate an Information Produced by the Entity (IPE) report for completeness and accuracy, then decide whether it is reliable control evidence or a deficiency.
- SOX ITGC Testing — Internal Audit; with IT, Finance · 8 steps
Scope and test SOX-relevant ITGCs by referencing the controls-owned 800-53 catalog and test scripts rather than rebuilding procedures.
- SOX Key Control TOD/TOE Test — Internal Audit; with Finance · 10 steps
Test key controls for design and operating effectiveness, including walkthrough, sampling, IPE linkage, exception handling, and reviewer sign-off.
- SOX Process Walkthrough — Finance; with Internal Audit · 7 steps
Capture an end-to-end process walkthrough and identify the key controls inside it, producing a walkthrough memo and draft control records.
- Substantive Testing & Data Analytics — Internal Audit · 2 steps
Validates a test population, draws a reproducible sample sized to risk, runs whole-population analytics (duplicates, gaps, three-way match) alongside it, evaluates and projects exceptions, and concludes on the tested FSLI assertion(s).
- Third-Party Vendor Assurance Engagement — Internal Audit; with Procurement · 8 steps
Run an IA-led third-party assurance engagement covering governance, risk tiering, control environment, monitoring, exclusions, and reporting.