top of page
Search

How to Build an Internal Audit Department: A Practical Guide from Charter to First Audit Plan

23 minutes ago
10 min read

Building an internal audit department is not simply a matter of hiring an internal auditor and developing a list of audits.


A successful internal audit function must be designed around the organization's risks, governance structure, business objectives, regulatory environment, information systems, and expectations of the board and senior management.


When properly established, internal audit becomes an important component of organizational governance. It provides independent assurance concerning whether risk management, governance, and internal controls are designed appropriately and operating effectively.


When poorly established, internal audit can become little more than a compliance checklist or a collection of disconnected audits.


Organizations creating or rebuilding an internal audit function should therefore approach the project systematically.


1. Start With the Purpose of Internal Audit

Before deciding whom to hire or what to audit, management and the board should determine why the organization needs internal audit.


Questions should include:

  • What does the board expect from internal audit?

  • What are the organization's most significant risks?

  • Are there regulatory or contractual requirements affecting internal audit?

  • What assurance does the audit committee currently receive?

  • Where are there gaps in the organization's assurance activities?

  • What does management expect internal audit to accomplish?

  • Will internal audit focus primarily on financial, operational, compliance, technology, cybersecurity, fraud, or enterprise risks?

  • How mature are the organization's existing risk management and internal control processes?


The answers establish the foundation for the department.


Internal audit should ultimately be aligned with the organization's objectives and risks—not merely with a predetermined list of audit topics.


2. Establish Organizational Independence

One of the first governance decisions is determining where internal audit will report.


Internal audit cannot provide credible independent assurance if the people responsible for the activities being audited control the audit function.


The chief audit executive should have sufficient organizational authority and direct access to the board or audit committee.


A common governance structure provides for:


Functional reporting to the audit committee or board, including oversight of matters such as:

  • Approval of the internal audit charter

  • Approval of the risk-based internal audit plan

  • Appointment and removal of the chief audit executive

  • Evaluation of the chief audit executive

  • Internal audit resources and budget

  • Significant audit findings

  • Internal audit independence


Administrative reporting to senior management for routine matters such as facilities, payroll administration, and organizational logistics.


The specific structure will vary, but the objective is the same: internal audit must be positioned so that auditors can perform their work objectively and communicate significant matters without inappropriate interference.


3. Develop the Internal Audit Charter

The internal audit charter is one of the foundational documents of the department.


It should formally establish internal audit's:

  • Purpose

  • Authority

  • Organizational position

  • Reporting relationships

  • Scope

  • Responsibilities

  • Access rights

  • Accountability


The charter should explicitly authorize internal audit to obtain access to the organization's records, systems, personnel, property, and other information necessary to perform its responsibilities.


The charter should also address internal audit's relationship with the board, management, external auditors, compliance, risk management, information security, legal counsel, and other assurance providers.


The board or audit committee should approve the charter.


A charter should not simply be downloaded from the Internet and adopted without modification. It needs to reflect how internal audit will actually operate within the organization.


4. Understand the Three Lines Model

A new internal audit department needs to understand where it fits within the organization's overall governance and risk structure.


The Three Lines Model provides a useful framework.


Management owns and manages organizational risks and controls. Specialized functions such as risk management, compliance, information security, quality, and other oversight functions may provide additional expertise, monitoring, and challenge.


Internal audit provides independent assurance.


This distinction is critical.


Internal audit should evaluate management's risk management and control processes, but it should not assume management's responsibility for operating them.


For example, internal audit can evaluate the organization's vendor risk management program. Internal audit should not become the department responsible for approving vendors.


Likewise, internal audit can assess the enterprise risk management process without becoming the owner of the organization's risks.


5. Build the Audit Universe

Before developing the audit plan, internal audit needs to understand what could potentially be audited.


This is commonly called the audit universe.


The audit universe may include:

  • Business units

  • Legal entities

  • Geographic locations

  • Financial processes

  • Operational processes

  • Information systems

  • Cybersecurity

  • Regulatory compliance

  • Third-party relationships

  • Major projects

  • Capital expenditures

  • Human resources

  • Payroll

  • Procurement

  • Revenue

  • Treasury

  • Financial reporting

  • Fraud risk

  • Business continuity

  • Data governance

  • Artificial intelligence

  • Environmental or sustainability processes

  • Strategic initiatives


The audit universe should reflect the actual organization rather than a generic list of audit areas.


For a large organization, the audit universe may contain hundreds of auditable entities.


6. Perform an Enterprise-Level Risk Assessment

The audit universe tells internal audit what can be audited.


Risk assessment helps determine what should be audited.


Internal audit should evaluate risks across the organization using factors such as:

  • Financial exposure

  • Regulatory exposure

  • Strategic importance

  • Cybersecurity exposure

  • Fraud risk

  • Complexity

  • Transaction volume

  • Management changes

  • System changes

  • Prior audit findings

  • Time since the last audit

  • Control maturity

  • Third-party dependence

  • Reputation risk

  • Emerging risks


Internal audit should also interview key executives and members of the board or audit committee.


These discussions often identify risks that will not appear in financial reports or process documentation.


The risk assessment should not become a mathematical exercise where an audit is automatically selected because it received a particular numerical score. Professional judgment remains essential.


7. Develop the Risk-Based Internal Audit Plan

The risk assessment should drive the audit plan.


The audit plan identifies the assurance and advisory work internal audit expects to perform during a defined period.


A mature plan may include:

  • Operational audits

  • Financial audits

  • Compliance audits

  • IT audits

  • Cybersecurity reviews

  • Fraud-related reviews

  • Third-party audits

  • Governance reviews

  • Follow-up audits

  • Special projects

  • Investigations

  • Advisory engagements


The plan should also reserve capacity for emerging risks and unexpected requests.


An internal audit department that commits 100 percent of its available hours before the year begins may have little ability to respond when an unexpected acquisition, cyber incident, fraud allegation, regulatory issue, or major system implementation occurs.


8. Determine the Resources Needed

Once the organization understands what needs to be audited, it can determine what resources are required.


The organization should consider:

  • Number of auditors

  • Experience levels

  • Industry knowledge

  • Accounting expertise

  • IT audit expertise

  • Cybersecurity knowledge

  • Data analytics capabilities

  • Fraud examination skills

  • Regulatory expertise

  • Geographic coverage

  • Specialized technical knowledge


Few internal audit departments can economically maintain every specialized skill internally.


Consequently, organizations should consider an appropriate combination of:

  • In-house staffing — employees who understand the organization's operations and culture.

  • Co-sourcing — internal staff supplemented by external specialists.

  • Outsourcing — an external provider performs substantial portions of the internal audit activity.


Co-sourcing can be particularly useful for areas such as cybersecurity, cloud computing, penetration testing, complex regulatory requirements, specialized tax matters, construction auditing, and sophisticated data analytics.


9. Hire the Right Internal Audit Leadership

The person leading the department will significantly influence its effectiveness.


Technical audit knowledge is important, but it is not sufficient.


An effective chief audit executive needs the ability to:

  • Communicate with executives and directors

  • Understand business strategy

  • Evaluate enterprise risks

  • Challenge management professionally

  • Manage difficult conversations

  • Develop audit talent

  • Understand technology

  • Exercise professional judgment

  • Communicate complex issues clearly

  • Maintain independence under pressure


A technically excellent auditor who cannot communicate with senior management and the board may struggle as a chief audit executive.


10. Develop an Internal Audit Methodology

Auditors need a consistent methodology for planning, performing, documenting, reviewing, and reporting engagements.


The methodology should address the complete audit lifecycle:


Planning → Risk Assessment → Audit Objectives → Scope → Audit Program → Fieldwork → Evidence → Findings → Reporting → Corrective Action → Follow-Up


Policies and procedures should address areas such as:

  • Engagement planning

  • Preliminary risk assessment

  • Audit objectives

  • Scope development

  • Sampling

  • Evidence

  • Workpaper documentation

  • Supervisory review

  • Issue development

  • Report writing

  • Management responses

  • Corrective action

  • Follow-up procedures


Consistency becomes increasingly important as the department grows.


11. Connect Risks, Controls, Testing, and Conclusions

One of the most important disciplines for a new internal audit department is maintaining a logical connection between:


Business Objective → Risk → Control → Audit Procedure → Evidence → Conclusion


Weak audit functions sometimes begin with an old audit program and simply repeat last year's procedures.


A risk-based audit asks a different question:


What could prevent this process from accomplishing its objectives?


Once the significant risks are identified, auditors determine what controls management has established to address those risks and whether those controls are appropriately designed and operating effectively.


This produces a much stronger audit than simply completing a checklist.


12. Establish Workpaper Standards

Audit documentation should allow an experienced reviewer to understand:

  • What was tested

  • Why it was tested

  • Who performed the work

  • When the work was performed

  • What evidence was examined

  • What results were obtained

  • What exceptions were identified

  • How conclusions were reached

  • Who reviewed the work


A common internal audit problem is performing good work but failing to document it adequately.


From an assurance perspective, undocumented work is difficult to demonstrate, supervise, review, or defend.


13. Develop a Strong Audit Finding Process

Internal audit findings should do more than describe errors.


A useful finding generally explains:

  • Condition — What did internal audit find?

  • Criteria — What should have happened?

  • Cause — Why did the condition occur?

  • Effect or Risk — Why does it matter?

  • Management Action Plan, Recommendation or Agreed Action — What should change?


The most valuable component may be root-cause analysis.


If an auditor merely identifies the visible problem without understanding why it occurred, management may correct the symptom while leaving the underlying control weakness intact.


14. Create an Effective Reporting Process

Audit reports should communicate significant information quickly and clearly.


Senior executives and audit committee members generally need to understand:

  • What was audited?

  • Why was it important?

  • What did internal audit conclude?

  • What significant problems were identified?

  • What risks do those problems create?

  • What is management doing about them?

  • Who is responsible?

  • When will corrective action be completed?


Long reports are not necessarily better reports.


Internal audit should focus attention on the information decision-makers need.


15. Establish a Corrective-Action Follow-Up Process

Issuing the audit report does not complete the assurance process.


Internal audit needs a system for tracking agreed corrective actions.


At minimum, the system should identify:

  • Audit finding

  • Risk level

  • Agreed corrective action

  • Responsible executive

  • Original due date

  • Revised due date

  • Current status

  • Evidence of remediation

  • Internal audit validation


Overdue high-risk findings should receive particular attention.


The audit committee should periodically receive information concerning significant unresolved findings and aging corrective actions.


16. Use Technology and Data Analytics

A new internal audit department has an opportunity to build technology into its methodology from the beginning.


Potential applications include:

  • Full-population transaction testing

  • Duplicate-payment identification

  • Journal-entry analysis

  • Vendor analytics

  • Payroll analytics

  • Accounts payable testing

  • User-access analysis

  • Segregation-of-duties analysis

  • Continuous auditing

  • Exception monitoring

  • Trend analysis

  • Artificial intelligence-assisted research and analysis


Technology should not replace professional judgment.


It should expand the population an auditor can examine and improve the auditor's ability to identify unusual transactions, relationships, trends, and control failures.


17. Coordinate With Other Assurance Providers

Organizations frequently have numerous groups evaluating risk and controls.


These may include:

  • External audit

  • Compliance

  • Enterprise risk management

  • Information security

  • Quality assurance

  • Legal

  • Regulatory examination teams

  • Safety

  • Fraud investigation

  • Internal control groups


Internal audit should understand what assurance these functions provide.


An assurance map can identify both unnecessary duplication and areas where significant risks receive little independent review.


18. Establish a Quality Assurance and Improvement Program

Internal audit should evaluate its own performance just as it evaluates other functions.


A quality assurance and improvement program can include:

  • Ongoing supervision

  • Engagement reviews

  • Workpaper quality reviews

  • Stakeholder feedback

  • Internal assessments

  • Performance measures

  • External quality assessments

  • Continuous improvement activities


Quality should be designed into the department rather than added after problems arise.


19. Measure What Matters

The number of audits completed is useful information, but it does not by itself demonstrate internal audit effectiveness.


A balanced performance dashboard might include:

  • Percentage of the risk-based plan completed

  • Coverage of high-risk areas

  • Cycle time for audit reports

  • Aging of corrective actions

  • Percentage of high-risk findings overdue

  • Stakeholder feedback

  • Staff utilization

  • Training and professional development

  • Quality-review results

  • Implementation of agreed corrective actions


Internal audit should be evaluated based on the quality and relevance of its assurance—not simply the volume of reports produced.


20. Build Relationships Without Losing Independence

Internal auditors need productive relationships throughout the organization.


Auditors should understand the business, listen to management, communicate professionally, and recognize legitimate operational constraints.


But internal audit is not management.


There will be times when the auditor and management disagree.


The internal audit function must have the organizational standing and professional discipline necessary to communicate significant unresolved risks to the appropriate level of governance.


A department that never disagrees with management may need to ask whether it is providing truly independent assurance.


A Practical Internal Audit Department Startup Roadmap

Organizations do not need to build every element simultaneously. A practical sequence might be:


Phase 1 — Governance

Establish reporting relationships, audit committee expectations, internal audit authority, and the internal audit charter.


Phase 2 — Risk

Understand organizational objectives, develop the audit universe, perform the enterprise-level risk assessment, and identify assurance gaps.


Phase 3 — Resources

Determine the department's staffing model, recruit leadership and staff, and identify areas requiring co-sourced specialists.


Phase 4 — Methodology

Develop audit policies, workpaper standards, engagement procedures, reporting protocols, and corrective-action tracking.


Phase 5 — Audit Plan

Translate the risk assessment into a risk-based audit plan and obtain appropriate board or audit committee approval.


Phase 6 — Execution

Perform audits using a consistent methodology that connects objectives, risks, controls, testing, evidence, findings, and conclusions.


Phase 7 — Quality and Improvement

Measure performance, evaluate stakeholder expectations, perform quality assessments, develop staff capabilities, and continuously improve the function.


The Bottom Line

A strong internal audit department is not created by writing an audit charter, buying audit software, or hiring several auditors.


It is created by establishing the right governance structure and then systematically connecting organizational objectives and risks to independent assurance.


The essential chain is:


Organizational Objectives → Risks → Controls → Audit Universe → Risk Assessment → Audit Plan → Audit Engagements → Findings → Corrective Action → Board Assurance


Every link matters.

Organizations establishing a new internal audit function have an unusual opportunity: they can design the department correctly from the beginning rather than inheriting decades of procedures, checklists, and audit programs whose original purposes may have been forgotten.


The goal should not simply be to create an internal audit department.


The goal should be to create an internal audit function capable of telling the board and senior management—independently, objectively, and based on evidence—whether the organization's most important risks are being appropriately governed and controlled.


Corporate Compliance Seminars (CCS) provides continuing professional education for internal auditors, external auditors, compliance professionals, accounting professionals, and information technology professionals. CCS training addresses internal auditing, internal controls, risk management, governance, fraud, cybersecurity, information technology auditing, and other areas important to today's assurance professionals.

 
 
 

Recent Posts

See All
How to Develop a Risk-Based Internal Audit Plan

An internal audit plan should not begin with a list of audits. It should begin with risk. A risk-based internal audit plan identifies the areas where independent assurance can provide the greatest val

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

​

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

​

National Registry of CPE Sponsors ID #108983

​

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366; davem@cseminars.com) and/ or John Blackshire (479-200-4373; johnb@cseminars.com)

 

​

bottom of page