top of page
Search

Internal Auditing 101: Build the Practical Skills Every New Auditor Needs

Internal Auditing Is More Than Checking Transactions

New internal auditors are often introduced to the profession through checklists, sample selections, policy reviews, and requests for supporting documentation.


Those activities are part of the job, but they are not the purpose of internal auditing.


A capable internal auditor must understand:

  • What the organization is trying to accomplish

  • Which risks could prevent those objectives from being achieved

  • Which internal controls management has established

  • Whether those controls are properly designed

  • Whether the controls operate consistently

  • What evidence supports the auditor’s conclusion

  • How audit results should be communicated to management



This live, instructor-led webinar provides 8 NASBA-approved CPE credits in Auditing through two four-hour sessions. The course is designed for new auditors, aspiring auditors, finance professionals, compliance personnel, and experienced professionals who want a practical refresher on the internal audit process.


The program moves beyond definitions. It helps participants understand how an internal audit is planned, conducted, documented, concluded, and communicated.


Why Internal Auditing Matters

Internal Audit provides independent and objective assurance concerning the effectiveness of governance, risk management, and internal control.


A well-functioning Internal Audit department can help an organization:

  • Identify significant risks

  • Protect financial and operational assets

  • Improve inefficient business processes

  • Detect control weaknesses

  • Strengthen regulatory compliance

  • Reduce fraud exposure

  • Improve management information

  • Support Board and Audit Committee oversight


Internal auditing is therefore not merely a regulatory requirement or accounting activity.


It is a management and governance resource.


The CCS program introduces participants to Internal Audit’s purpose, its relationship to internal control, and the ways auditors help organizations manage risk and improve operations.


The Internal Auditor Does Not Own the Controls

One of the first principles every new auditor must understand is the distinction between management’s responsibilities and Internal Audit’s responsibilities.


Management:

  • Establishes organizational objectives

  • Identifies and manages risks

  • Designs and operates internal controls

  • Accepts residual risk

  • Implements corrective action


Internal Audit:

  • Evaluates governance, risk management, and controls

  • Tests whether controls operate effectively

  • Communicates identified weaknesses

  • Recommends improvements

  • Provides independent assurance


The auditor should not operate the process being audited or accept risk on management’s behalf.


Internal Audit evaluates management’s system. It does not replace management.


Internal Audit Begins with Objectives and Risks

Weak audits often begin by asking:

Which transactions should we test?

A stronger audit begins with:

What objective is this process intended to accomplish?

Once the objective is understood, the auditor identifies the risks that could interfere with it.


For example, an Accounts Payable process may have the objective of paying valid vendors accurately and on time.


The related risks may include:

  • Duplicate payments

  • Fictitious vendors

  • Unauthorized purchases

  • Fraudulent vendor-bank changes

  • Payments for goods not received

  • Improper approvals

  • Incorrect account coding

  • Business Email Compromise


The auditor then determines which controls address those risks.


The CCS course teaches this relationship through an Objective–Risk–Control approach and places risk assessment at the center of individual audit planning.


Understanding the Internal Audit Lifecycle

An internal audit is not a collection of disconnected procedures.


It is a structured lifecycle.


A typical engagement includes:

  1. Understanding the audit objective

  2. Assessing risks

  3. Defining the scope

  4. Planning the engagement

  5. Conducting interviews and walkthroughs

  6. Identifying important controls

  7. Performing fieldwork

  8. Gathering evidence

  9. Testing controls and transactions

  10. Documenting workpapers

  11. Evaluating exceptions

  12. Developing findings

  13. Communicating results

  14. Conducting the exit meeting

  15. Following up on corrective action


Each phase affects the next.


Poor planning produces unfocused testing.


Weak testing produces inadequate evidence.


Inadequate evidence produces unsupported findings.


Unsupported findings damage Internal Audit’s credibility.


The CCS program walks participants through the audit lifecycle from risk assessment and planning through fieldwork, reporting, and the closing meeting.


Risk Assessment Determines Where Audit Resources Should Be Used

No Internal Audit department can examine every process, transaction, system, or location.


Auditors must prioritize.


A risk assessment may consider:

  • Financial impact

  • Operational disruption

  • Regulatory exposure

  • Fraud opportunity

  • Cybersecurity risk

  • Reputational damage

  • Likelihood

  • Control effectiveness

  • Management concerns

  • Recent organizational changes


The objective is to focus limited audit resources on the areas presenting the greatest risk to organizational success.


The course examines both the broader Internal Audit risk-assessment process and the planning of an individual audit engagement.


Audit Planning Must Be Specific

A vague audit objective creates vague audit work.


Consider this objective:

Review purchasing.

It does not define what the auditor is expected to conclude.

A stronger objective might be:

Determine whether purchases exceeding $10,000 were properly authorized, competitively procured, accurately recorded, and supported by evidence that the goods or services were received.

That objective identifies:

  • The process

  • The transaction threshold

  • The expected controls

  • The intended conclusion

  • The evidence likely to be required


A detailed audit plan should identify:

  • Engagement objectives

  • Scope

  • Applicable criteria

  • Significant risks

  • Key controls

  • Audit procedures

  • Required evidence

  • Staffing

  • Timing

  • Expected deliverables


The CCS program provides practical guidance for developing individual audit plans and selecting procedures aligned with the identified risks.


Walkthroughs Help Auditors Understand How the Process Really Works

Policies explain how a process is supposed to operate.


Walkthroughs help the auditor understand how it actually operates.


During a walkthrough, the auditor follows a transaction or activity through the process and determines:

  • Who performs each step

  • Which systems are used

  • Which approvals are required

  • Where information enters the process

  • Where information is reviewed

  • What evidence is retained

  • How exceptions are handled

  • Where the actual process differs from the written procedure


Walkthroughs are especially valuable when processes involve multiple departments, systems, or manual workarounds.


The CCS course includes audit walkthroughs as a key fieldwork technique.


Audit Interviews Require More Than a Questionnaire

Good auditors do not simply ask questions.


They ask the right questions in the right sequence.


The course introduces the S.P.I.N. questioning methodology:

  • Situation

  • Problem

  • Implication

  • Need


This approach helps auditors move from basic facts to meaningful risk discussions.


Situation Questions

These establish how the process operates.


Examples:

  • Who performs the reconciliation?

  • Which system is used?

  • How often is the report reviewed?

  • Who can approve an exception?


Problem Questions

These identify weaknesses or difficulties.


Examples:

  • Where do delays occur?

  • Which control is hardest to perform consistently?

  • What types of errors occur most often?

  • Where does practice differ from policy?


Implication Questions

These explore consequences.


Examples:

  • What happens if the reconciliation is not completed?

  • Could unauthorized transactions remain undetected?

  • How could this issue affect regulatory reporting?

  • What is the financial exposure?


Need Questions

These focus on improvement.


Examples:

  • How would automated monitoring improve the process?

  • What additional information would help management?

  • Which corrective action would reduce the risk most effectively?


This questioning structure helps auditors conduct more productive interviews and develop stronger findings.


Active Listening Is an Audit Skill

An auditor who prepares excellent questions but fails to listen carefully may still miss important information.


Active listening includes:

  • Allowing the client to finish the explanation

  • Asking appropriate follow-up questions

  • Restating important points

  • Identifying contradictions

  • Distinguishing fact from opinion

  • Recognizing hesitation or uncertainty

  • Requesting corroborating evidence


The CCS program includes active listening and rapport-building as practical fieldwork and communication skills.


These are not optional personality traits.


They directly affect evidence quality and client cooperation.


Internal Controls Must Be Evaluated, Not Merely Identified

A new auditor may initially focus on whether a control exists.


The stronger question is whether the control is capable of addressing the identified risk and whether it operates consistently.


For each control, the auditor should determine:

  • Who performs it?

  • How frequently?

  • What risk does it address?

  • What evidence demonstrates performance?

  • Who reviews the results?

  • What happens when an exception occurs?

  • Can the control be overridden?

  • Does it operate with sufficient precision?


A policy stating that reconciliations must be completed does not prove that reconciliations are actually performed or reviewed.


The CCS course teaches participants how to evaluate, document, and test internal controls during fieldwork.


Audit Evidence Must Be Sufficient and Appropriate

Audit conclusions require evidence.


Evidence may include:

  • Documents

  • System records

  • Reconciliations

  • Approvals

  • Observations

  • Interviews

  • Data analysis

  • Confirmations

  • Reperformance

  • Physical inspection


Auditors evaluate two important characteristics.


Sufficiency

Is there enough evidence?


Appropriateness

Is the evidence relevant and reliable?


A large amount of weak evidence does not automatically support a conclusion.


For example, inquiry may explain how a control is intended to work. Inquiry alone may not prove that the control operated throughout the audit period.


The auditor may also need to inspect documentation, review system logs, observe the process, or reperform the control.


The program specifically addresses techniques for gathering audit evidence and documenting the auditor’s work.


Sampling Requires Professional Judgment

Auditors frequently test less than 100 percent of a population.


That does not mean they should select an arbitrary number of transactions.


Sample selection should consider:

  • Audit objective

  • Population

  • Risk level

  • Control frequency

  • Expected exceptions

  • Nature of the evidence

  • Desired assurance


Common approaches include:

  • Random selection

  • Haphazard selection

  • Systematic selection

  • Judgmental selection

  • Targeted high-risk testing


The CCS course introduces sample-size considerations as part of internal-control testing and fieldwork.


The important principle is that the auditor must be able to explain why the testing performed supports the conclusion.


Workpapers Must Demonstrate the Work

Audit workpapers provide the record of the engagement.


They should allow an experienced reviewer to understand:

  • What objective was tested

  • What procedure was performed

  • Which population was used

  • Which items were selected

  • What evidence was examined

  • Which exceptions were identified

  • How the exceptions were evaluated

  • What conclusion was reached

  • Who performed and reviewed the work


The course covers workpaper characteristics and workpaper review as important parts of audit quality.


A workpaper stating only “tested with no exceptions” is incomplete.


It should demonstrate what was tested and how the auditor reached the conclusion.


Audit Software Can Improve Audit Efficiency

Modern auditors use technology to support:

  • Data analysis

  • Risk assessment

  • Audit management

  • Process flowcharting

  • Workpaper organization

  • Reporting

  • Content management

  • Exception identification


The CCS program includes a separate section on audit software and its application to data analysis, audit management, flowcharting, risk management, and reporting.


Technology helps auditors examine larger populations and identify unusual activity.


It does not replace professional judgment.


Exceptions Must Be Converted into Meaningful Findings

An exception is not automatically an audit finding.


The auditor must understand:

  • What happened

  • What should have happened

  • Why the condition occurred

  • What consequence or risk exists

  • What corrective action is appropriate


A strong audit finding generally contains:

Condition

What did the auditor identify?

Criteria

What standard, policy, control, or expectation applies?

Cause

Why did the condition occur?

Consequence

What actual or potential effect exists?

Corrective Action

What should management do?


The CCS course teaches participants how to document exceptions and findings and connect fieldwork results to the audit-reporting process.


The Exit Meeting Should Not Be the First Discussion of a Finding

Significant issues should ordinarily be discussed with management during fieldwork.


Waiting until the exit meeting creates unnecessary surprises and conflict.


Early discussion allows the auditor to:

  • Verify the facts

  • Obtain missing evidence

  • Correct misunderstandings

  • Understand root cause

  • Evaluate compensating controls

  • Discuss practical corrective actions


The CCS program addresses exit meetings and the importance of building professional rapport with audit clients.


The objective is not to negotiate away valid findings.


It is to ensure that the final report is accurate, fair, and actionable.


Reporting Determines Whether the Audit Creates Change

A technically correct audit may still fail if the results are poorly communicated.


Management needs to understand:

  • What happened

  • Why it matters

  • How serious the risk is

  • What action is required

  • Who should be responsible

  • When the issue should be corrected


The CCS program covers the key sections of internal audit reports, documenting findings, communicating results, and conducting impactful exit meetings.


A strong report should be:

  • Accurate

  • Objective

  • Clear

  • Concise

  • Constructive

  • Complete

  • Timely


Audit communication is not an administrative step added after fieldwork.


It is part of the audit.


Who Should Attend Internal Auditing 101?

The course is designed for:

  • Aspiring internal auditors

  • Newly hired audit staff

  • Finance and accounting professionals

  • Compliance personnel

  • Risk-management professionals

  • Government auditors

  • Bank auditors

  • Insurance auditors

  • Nonprofit auditors

  • Professionals seeking a practical refresher


No prerequisites or advance preparation are required. The course is presented at a basic level and is appropriate across industries.


What Participants Will Learn

Participants will learn how to:

  • Explain the purpose of Internal Audit

  • Understand important auditing standards and guidance

  • Distinguish Internal Audit from External Audit

  • Assess audit risk

  • Plan an individual audit

  • Conduct walkthroughs

  • Identify and test internal controls

  • Use S.P.I.N. questioning during interviews

  • Apply active listening techniques

  • Gather audit evidence

  • Consider sample size

  • Prepare and review workpapers

  • Use audit software

  • Document exceptions and findings

  • Conduct exit meetings

  • Communicate audit results effectively


Start Building Your Internal Audit Career

New auditors are expected to learn quickly.


They must understand unfamiliar processes, identify risks, evaluate controls, gather evidence, document conclusions, and communicate professionally with management.


Those skills require more than a checklist.


They require a practical understanding of the entire audit process.


Corporate Compliance Seminars’ Internal Auditing 101: Basic Training for Auditors gives participants a structured introduction to the knowledge and techniques required to contribute effectively to an internal audit engagement.


The course connects:

  • Risk to planning

  • Controls to objectives

  • Testing to evidence

  • Exceptions to findings

  • Findings to management action


Internal auditing is not about identifying every mistake.


It is about helping the organization understand and manage the risks that matter.


Register for the September 30–October 1, 2026 Event

The two-day program provides a practical foundation for professionals beginning or strengthening their careers in Internal Audit.


Participants earn 8 NASBA-approved CPE credits while learning how to plan an audit, conduct fieldwork, evaluate internal controls, gather evidence, prepare workpapers, use audit tools, document findings, and communicate results.


A strong audit begins with a clear objective.


A strong audit career begins with the right foundation.


Frequently Asked Questions

What is Internal Auditing 101?

Internal Auditing 101 is an introductory training program covering internal audit fundamentals, risk assessment, planning, fieldwork, internal-control testing, evidence, workpapers, audit tools, findings, and reporting.


Is the course appropriate for someone with no audit experience?

Yes. The program is presented at a basic level and has no prerequisites or advance-preparation requirements.


Does the course cover audit interviews?

Yes. It covers audit interviewing, active listening, rapport building, and the S.P.I.N. questioning methodology.


Does the course cover internal-control testing?

Yes. Participants learn how to identify, evaluate, document, and test important internal controls.


How many CPE credits are available?

The live two-day webinar provides 8 NASBA-approved CPE credits in Auditing, based on a 50-minute instructional hour.


Is private training available?

Yes. CCS can schedule private presentations for organizations registering two or more participants.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page