Internal Auditing 101: Build the Practical Skills Every New Auditor Needs
- John C. Blackshire, Jr.

- 1 hour ago
- 9 min read
Internal Auditing Is More Than Checking Transactions
New internal auditors are often introduced to the profession through checklists, sample selections, policy reviews, and requests for supporting documentation.
Those activities are part of the job, but they are not the purpose of internal auditing.
A capable internal auditor must understand:
What the organization is trying to accomplish
Which risks could prevent those objectives from being achieved
Which internal controls management has established
Whether those controls are properly designed
Whether the controls operate consistently
What evidence supports the auditor’s conclusion
How audit results should be communicated to management
Corporate Compliance Seminars will present Internal Auditing 101: Basic Training for Auditors on Wednesday and Thursday, September 30–October 1, 2026.
This live, instructor-led webinar provides 8 NASBA-approved CPE credits in Auditing through two four-hour sessions. The course is designed for new auditors, aspiring auditors, finance professionals, compliance personnel, and experienced professionals who want a practical refresher on the internal audit process.
The program moves beyond definitions. It helps participants understand how an internal audit is planned, conducted, documented, concluded, and communicated.
Why Internal Auditing Matters
Internal Audit provides independent and objective assurance concerning the effectiveness of governance, risk management, and internal control.
A well-functioning Internal Audit department can help an organization:
Identify significant risks
Protect financial and operational assets
Improve inefficient business processes
Detect control weaknesses
Strengthen regulatory compliance
Reduce fraud exposure
Improve management information
Support Board and Audit Committee oversight
Internal auditing is therefore not merely a regulatory requirement or accounting activity.
It is a management and governance resource.
The CCS program introduces participants to Internal Audit’s purpose, its relationship to internal control, and the ways auditors help organizations manage risk and improve operations.
The Internal Auditor Does Not Own the Controls
One of the first principles every new auditor must understand is the distinction between management’s responsibilities and Internal Audit’s responsibilities.
Management:
Establishes organizational objectives
Identifies and manages risks
Designs and operates internal controls
Accepts residual risk
Implements corrective action
Internal Audit:
Evaluates governance, risk management, and controls
Tests whether controls operate effectively
Communicates identified weaknesses
Recommends improvements
Provides independent assurance
The auditor should not operate the process being audited or accept risk on management’s behalf.
Internal Audit evaluates management’s system. It does not replace management.
Internal Audit Begins with Objectives and Risks
Weak audits often begin by asking:
Which transactions should we test?
A stronger audit begins with:
What objective is this process intended to accomplish?
Once the objective is understood, the auditor identifies the risks that could interfere with it.
For example, an Accounts Payable process may have the objective of paying valid vendors accurately and on time.
The related risks may include:
Duplicate payments
Fictitious vendors
Unauthorized purchases
Fraudulent vendor-bank changes
Payments for goods not received
Improper approvals
Incorrect account coding
Business Email Compromise
The auditor then determines which controls address those risks.
The CCS course teaches this relationship through an Objective–Risk–Control approach and places risk assessment at the center of individual audit planning.
Understanding the Internal Audit Lifecycle
An internal audit is not a collection of disconnected procedures.
It is a structured lifecycle.
A typical engagement includes:
Understanding the audit objective
Assessing risks
Defining the scope
Planning the engagement
Conducting interviews and walkthroughs
Identifying important controls
Performing fieldwork
Gathering evidence
Testing controls and transactions
Documenting workpapers
Evaluating exceptions
Developing findings
Communicating results
Conducting the exit meeting
Following up on corrective action
Each phase affects the next.
Poor planning produces unfocused testing.
Weak testing produces inadequate evidence.
Inadequate evidence produces unsupported findings.
Unsupported findings damage Internal Audit’s credibility.
The CCS program walks participants through the audit lifecycle from risk assessment and planning through fieldwork, reporting, and the closing meeting.
Risk Assessment Determines Where Audit Resources Should Be Used
No Internal Audit department can examine every process, transaction, system, or location.
Auditors must prioritize.
A risk assessment may consider:
Financial impact
Operational disruption
Regulatory exposure
Fraud opportunity
Cybersecurity risk
Reputational damage
Likelihood
Control effectiveness
Management concerns
Recent organizational changes
The objective is to focus limited audit resources on the areas presenting the greatest risk to organizational success.
The course examines both the broader Internal Audit risk-assessment process and the planning of an individual audit engagement.
Audit Planning Must Be Specific
A vague audit objective creates vague audit work.
Consider this objective:
Review purchasing.
It does not define what the auditor is expected to conclude.
A stronger objective might be:
Determine whether purchases exceeding $10,000 were properly authorized, competitively procured, accurately recorded, and supported by evidence that the goods or services were received.
That objective identifies:
The process
The transaction threshold
The expected controls
The intended conclusion
The evidence likely to be required
A detailed audit plan should identify:
Engagement objectives
Scope
Applicable criteria
Significant risks
Key controls
Audit procedures
Required evidence
Staffing
Timing
Expected deliverables
The CCS program provides practical guidance for developing individual audit plans and selecting procedures aligned with the identified risks.
Walkthroughs Help Auditors Understand How the Process Really Works
Policies explain how a process is supposed to operate.
Walkthroughs help the auditor understand how it actually operates.
During a walkthrough, the auditor follows a transaction or activity through the process and determines:
Who performs each step
Which systems are used
Which approvals are required
Where information enters the process
Where information is reviewed
What evidence is retained
How exceptions are handled
Where the actual process differs from the written procedure
Walkthroughs are especially valuable when processes involve multiple departments, systems, or manual workarounds.
The CCS course includes audit walkthroughs as a key fieldwork technique.
Audit Interviews Require More Than a Questionnaire
Good auditors do not simply ask questions.
They ask the right questions in the right sequence.
The course introduces the S.P.I.N. questioning methodology:
Situation
Problem
Implication
Need
This approach helps auditors move from basic facts to meaningful risk discussions.
Situation Questions
These establish how the process operates.
Examples:
Who performs the reconciliation?
Which system is used?
How often is the report reviewed?
Who can approve an exception?
Problem Questions
These identify weaknesses or difficulties.
Examples:
Where do delays occur?
Which control is hardest to perform consistently?
What types of errors occur most often?
Where does practice differ from policy?
Implication Questions
These explore consequences.
Examples:
What happens if the reconciliation is not completed?
Could unauthorized transactions remain undetected?
How could this issue affect regulatory reporting?
What is the financial exposure?
Need Questions
These focus on improvement.
Examples:
How would automated monitoring improve the process?
What additional information would help management?
Which corrective action would reduce the risk most effectively?
This questioning structure helps auditors conduct more productive interviews and develop stronger findings.
Active Listening Is an Audit Skill
An auditor who prepares excellent questions but fails to listen carefully may still miss important information.
Active listening includes:
Allowing the client to finish the explanation
Asking appropriate follow-up questions
Restating important points
Identifying contradictions
Distinguishing fact from opinion
Recognizing hesitation or uncertainty
Requesting corroborating evidence
The CCS program includes active listening and rapport-building as practical fieldwork and communication skills.
These are not optional personality traits.
They directly affect evidence quality and client cooperation.
Internal Controls Must Be Evaluated, Not Merely Identified
A new auditor may initially focus on whether a control exists.
The stronger question is whether the control is capable of addressing the identified risk and whether it operates consistently.
For each control, the auditor should determine:
Who performs it?
How frequently?
What risk does it address?
What evidence demonstrates performance?
Who reviews the results?
What happens when an exception occurs?
Can the control be overridden?
Does it operate with sufficient precision?
A policy stating that reconciliations must be completed does not prove that reconciliations are actually performed or reviewed.
The CCS course teaches participants how to evaluate, document, and test internal controls during fieldwork.
Audit Evidence Must Be Sufficient and Appropriate
Audit conclusions require evidence.
Evidence may include:
Documents
System records
Reconciliations
Approvals
Observations
Interviews
Data analysis
Confirmations
Reperformance
Physical inspection
Auditors evaluate two important characteristics.
Sufficiency
Is there enough evidence?
Appropriateness
Is the evidence relevant and reliable?
A large amount of weak evidence does not automatically support a conclusion.
For example, inquiry may explain how a control is intended to work. Inquiry alone may not prove that the control operated throughout the audit period.
The auditor may also need to inspect documentation, review system logs, observe the process, or reperform the control.
The program specifically addresses techniques for gathering audit evidence and documenting the auditor’s work.
Sampling Requires Professional Judgment
Auditors frequently test less than 100 percent of a population.
That does not mean they should select an arbitrary number of transactions.
Sample selection should consider:
Audit objective
Population
Risk level
Control frequency
Expected exceptions
Nature of the evidence
Desired assurance
Common approaches include:
Random selection
Haphazard selection
Systematic selection
Judgmental selection
Targeted high-risk testing
The CCS course introduces sample-size considerations as part of internal-control testing and fieldwork.
The important principle is that the auditor must be able to explain why the testing performed supports the conclusion.
Workpapers Must Demonstrate the Work
Audit workpapers provide the record of the engagement.
They should allow an experienced reviewer to understand:
What objective was tested
What procedure was performed
Which population was used
Which items were selected
What evidence was examined
Which exceptions were identified
How the exceptions were evaluated
What conclusion was reached
Who performed and reviewed the work
The course covers workpaper characteristics and workpaper review as important parts of audit quality.
A workpaper stating only “tested with no exceptions” is incomplete.
It should demonstrate what was tested and how the auditor reached the conclusion.
Audit Software Can Improve Audit Efficiency
Modern auditors use technology to support:
Data analysis
Risk assessment
Audit management
Process flowcharting
Workpaper organization
Reporting
Content management
Exception identification
The CCS program includes a separate section on audit software and its application to data analysis, audit management, flowcharting, risk management, and reporting.
Technology helps auditors examine larger populations and identify unusual activity.
It does not replace professional judgment.
Exceptions Must Be Converted into Meaningful Findings
An exception is not automatically an audit finding.
The auditor must understand:
What happened
What should have happened
Why the condition occurred
What consequence or risk exists
What corrective action is appropriate
A strong audit finding generally contains:
Condition
What did the auditor identify?
Criteria
What standard, policy, control, or expectation applies?
Cause
Why did the condition occur?
Consequence
What actual or potential effect exists?
Corrective Action
What should management do?
The CCS course teaches participants how to document exceptions and findings and connect fieldwork results to the audit-reporting process.
The Exit Meeting Should Not Be the First Discussion of a Finding
Significant issues should ordinarily be discussed with management during fieldwork.
Waiting until the exit meeting creates unnecessary surprises and conflict.
Early discussion allows the auditor to:
Verify the facts
Obtain missing evidence
Correct misunderstandings
Understand root cause
Evaluate compensating controls
Discuss practical corrective actions
The CCS program addresses exit meetings and the importance of building professional rapport with audit clients.
The objective is not to negotiate away valid findings.
It is to ensure that the final report is accurate, fair, and actionable.
Reporting Determines Whether the Audit Creates Change
A technically correct audit may still fail if the results are poorly communicated.
Management needs to understand:
What happened
Why it matters
How serious the risk is
What action is required
Who should be responsible
When the issue should be corrected
The CCS program covers the key sections of internal audit reports, documenting findings, communicating results, and conducting impactful exit meetings.
A strong report should be:
Accurate
Objective
Clear
Concise
Constructive
Complete
Timely
Audit communication is not an administrative step added after fieldwork.
It is part of the audit.
Who Should Attend Internal Auditing 101?
The course is designed for:
Aspiring internal auditors
Newly hired audit staff
Finance and accounting professionals
Compliance personnel
Risk-management professionals
Government auditors
Bank auditors
Insurance auditors
Nonprofit auditors
Professionals seeking a practical refresher
No prerequisites or advance preparation are required. The course is presented at a basic level and is appropriate across industries.
What Participants Will Learn
Participants will learn how to:
Explain the purpose of Internal Audit
Understand important auditing standards and guidance
Distinguish Internal Audit from External Audit
Assess audit risk
Plan an individual audit
Conduct walkthroughs
Identify and test internal controls
Use S.P.I.N. questioning during interviews
Apply active listening techniques
Gather audit evidence
Consider sample size
Prepare and review workpapers
Use audit software
Document exceptions and findings
Conduct exit meetings
Communicate audit results effectively
Start Building Your Internal Audit Career
New auditors are expected to learn quickly.
They must understand unfamiliar processes, identify risks, evaluate controls, gather evidence, document conclusions, and communicate professionally with management.
Those skills require more than a checklist.
They require a practical understanding of the entire audit process.
Corporate Compliance Seminars’ Internal Auditing 101: Basic Training for Auditors gives participants a structured introduction to the knowledge and techniques required to contribute effectively to an internal audit engagement.
The course connects:
Risk to planning
Controls to objectives
Testing to evidence
Exceptions to findings
Findings to management action
Internal auditing is not about identifying every mistake.
It is about helping the organization understand and manage the risks that matter.
Register for the September 30–October 1, 2026 Event
The two-day program provides a practical foundation for professionals beginning or strengthening their careers in Internal Audit.
Participants earn 8 NASBA-approved CPE credits while learning how to plan an audit, conduct fieldwork, evaluate internal controls, gather evidence, prepare workpapers, use audit tools, document findings, and communicate results.
A strong audit begins with a clear objective.
A strong audit career begins with the right foundation.
Frequently Asked Questions
What is Internal Auditing 101?
Internal Auditing 101 is an introductory training program covering internal audit fundamentals, risk assessment, planning, fieldwork, internal-control testing, evidence, workpapers, audit tools, findings, and reporting.
Is the course appropriate for someone with no audit experience?
Yes. The program is presented at a basic level and has no prerequisites or advance-preparation requirements.
Does the course cover audit interviews?
Yes. It covers audit interviewing, active listening, rapport building, and the S.P.I.N. questioning methodology.
Does the course cover internal-control testing?
Yes. Participants learn how to identify, evaluate, document, and test important internal controls.
How many CPE credits are available?
The live two-day webinar provides 8 NASBA-approved CPE credits in Auditing, based on a 50-minute instructional hour.
Is private training available?
Yes. CCS can schedule private presentations for organizations registering two or more participants.
Comments