top of page
Search

Internal Auditor Basic Training: Building the Skills to Plan, Perform, and Communicate High-Value Audits

Every Strong Internal Auditor Starts with a Strong Foundation

Internal auditing is not simply checking transactions, reviewing documentation, or confirming that policies exist.


A capable internal auditor must understand how an organization achieves its objectives, what risks could prevent success, which controls address those risks, whether those controls operate effectively, and how audit results should be communicated to management.


That requires a combination of:

  • Technical audit knowledge

  • Risk assessment

  • Internal-control evaluation

  • Evidence gathering

  • Interviewing

  • Workpaper documentation

  • Professional judgment

  • Written and verbal communication

  • Relationship management


Corporate Compliance Seminars will present Internal Auditor Basic Training: Essential Skills for Auditors from Tuesday through Thursday, August 11–13, 2026. This comprehensive live webinar provides 18 NASBA-approved CPE credits in Auditing through three interactive sessions conducted from 9:00 a.m. to 3:00 p.m. Central Time, with a lunch break from noon to 12:30 p.m. each day.


The program is designed for new internal auditors, professionals moving into internal audit, compliance personnel, and audit managers who want a structured review of the complete internal audit lifecycle.


Internal Auditing Is More Than Testing Controls

New auditors often begin with a narrow understanding of the profession.


They may believe an auditor’s job is to:

  • Select samples

  • Review invoices

  • Verify approvals

  • Complete checklists

  • Identify policy violations

  • Write findings


Those activities are part of auditing, but they do not define the profession.


Internal Audit exists to provide independent and objective assurance concerning the effectiveness of:

  • Governance

  • Risk management

  • Internal control

  • Compliance

  • Operational processes

  • Fraud-risk management

  • Information technology

  • Organizational performance


The CCS course begins by examining why Internal Audit exists and how it functions as a major Entity-Level Control within the organization. It also reviews the roles of Internal Audit, External Audit, management, the Board, and the Audit Committee.


A new auditor must understand this distinction:

Management owns the risks and controls. Internal Audit evaluates whether management’s system is working.

Auditors should not operate processes, approve transactions, design management’s corrective actions, or accept risk on management’s behalf.


Their role is to provide assurance, insight, and advice without assuming management responsibility.


Understanding the Audit Lifecycle

A successful audit follows a disciplined lifecycle.


The major phases generally include:

  1. Risk assessment

  2. Audit selection

  3. Preliminary research

  4. Engagement planning

  5. Client interviews and walkthroughs

  6. Control evaluation

  7. Fieldwork and testing

  8. Evidence evaluation

  9. Workpaper documentation

  10. Development of findings

  11. Reporting

  12. Management action planning

  13. Follow-up


The Internal Auditor Basic Training program walks participants through the complete audit process, from risk-based planning and fieldwork to reporting and follow-up.


Each phase affects the next.


Weak planning produces unfocused fieldwork.


Poor fieldwork produces unsupported findings.


Weak documentation undermines review and quality assurance.


Unclear reporting reduces management action.


The objective is not merely to complete each step. It is to connect the steps into one defensible audit process.


Audit Planning Begins with Organizational Objectives

Auditors should not begin by asking:

What controls should we test?

They should begin with:

What is the organization trying to accomplish?

Every audit should connect:

  • Objectives

  • Risks

  • Controls

  • Evidence

  • Conclusions


For example, assume the organization’s objective is to pay only authorized vendors for valid goods and services.


Relevant risks may include:

  • Fictitious vendors

  • Duplicate payments

  • Unauthorized invoices

  • Conflicts of interest

  • Business Email Compromise

  • Payments for goods not received

  • Improper vendor-bank changes


Controls may include:

  • Vendor authentication

  • Purchase-order approvals

  • Three-way matching

  • Segregation of duties

  • Duplicate-payment analytics

  • Independent vendor-change verification

  • Payment-file review


The auditor then determines whether those controls are properly designed and operating effectively.


The course emphasizes the relationship among business objectives, risks, and controls as a foundation for audit planning and internal-control evaluation.


Risk Assessment Determines Where Auditors Spend Their Time

Internal Audit resources are always limited.


The audit plan should therefore focus on the areas that matter most.


Risk assessment helps auditors evaluate:

  • Likelihood

  • Impact

  • Velocity

  • Persistence

  • Control effectiveness

  • Residual exposure

  • Strategic significance


The CCS program teaches participants how to identify and categorize risks using an Enterprise Risk Model and how to create an internal audit plan containing both strategic and tactical objectives.


Possible risk categories include:

  • Strategic

  • Financial

  • Operational

  • Compliance

  • Fraud

  • Technology

  • Cybersecurity

  • Reputational

  • Human capital

  • Third-party


A good audit plan is not a list of departments.


It is a reasoned response to the organization’s most significant risks.


Auditors Must Understand Professional Standards

Internal auditors may work under several professional and regulatory frameworks.


Depending on the organization and engagement, relevant guidance may include:

  • The IIA Global Internal Audit Standards

  • COSO Internal Control—Integrated Framework

  • COSO Enterprise Risk Management

  • GAO Yellow Book

  • GAO Green Book

  • PCAOB standards

  • ISACA guidance

  • ISO standards

  • NIST frameworks


The CCS training reviews the different standards and frameworks that may apply to internal audit work and helps participants understand how they influence planning, fieldwork, evidence, reporting, and governance.


New auditors do not need to memorize every requirement immediately.


They do need to know:

  • Which framework applies

  • Where authoritative guidance can be found

  • How standards affect the engagement

  • When technical consultation is necessary


Internal Controls Must Be Evaluated in Context

Internal controls are not isolated procedures.

They operate within a broader organizational environment.

Auditors should evaluate:


Control Environment

Does leadership establish integrity, accountability, competence, and appropriate authority?


Risk Assessment

Does management identify and evaluate risks that could prevent achievement of objectives?


Control Activities

Are approvals, reconciliations, system controls, segregation of duties, and other procedures appropriately designed?


Information and Communication

Does reliable information reach the right people at the right time?


Monitoring

Does management determine whether controls continue operating effectively?


The course covers internal-control evaluation, business-process maturity, testing controls, and assessing consistency and reliability.


A control should not be judged solely by whether it is documented.


The auditor should determine:

  • Who performs it?

  • How often?

  • What evidence is retained?

  • What happens when an exception occurs?

  • Who reviews the results?

  • Could the control detect the identified risk?

  • Is the control sustainable?


Audit Interviews Are Evidence-Gathering Activities

An audit interview is not casual conversation.


It is a structured method of obtaining information, understanding processes, identifying risks, and developing potential evidence.


The CCS program includes the SPIN questioning methodology:

  • Situation

  • Problem

  • Implication

  • Need


The course uses SPIN to help auditors conduct interviews and document audit findings more effectively.


Situation Questions

These establish the process.

  • How is the process organized?

  • Which systems are used?

  • Who approves transactions?

  • What reports does management review?


Problem Questions

These identify weaknesses.

  • Where do delays occur?

  • Which controls are difficult to perform?

  • What exceptions occur most frequently?

  • Where does actual practice differ from policy?


Implication Questions

These explore consequences.

  • What happens when the reconciliation is late?

  • Could an unauthorized transaction remain undetected?

  • What regulatory exposure could result?

  • How would the issue affect customers?


Need Questions

These focus on improvement.

  • How would automated monitoring improve oversight?

  • What would reduce the number of exceptions?

  • Which corrective action would provide the greatest benefit?

  • What support does management need?


The best auditors do not merely ask more questions.


They ask better questions in a logical sequence.


Auditors Must Gather Sufficient and Appropriate Evidence

Audit conclusions should be supported by evidence.


Evidence may include:

  • Documents

  • System records

  • Confirmations

  • Observations

  • Interviews

  • Data analysis

  • Reperformance

  • Inspection

  • Physical examination


The CCS program addresses practical techniques for gathering audit evidence and emphasizes the importance of quality workpapers.


Auditors should evaluate both:

Sufficiency


Is there enough evidence?

Appropriateness


Is the evidence relevant and reliable?


A large volume of weak evidence does not automatically support a conclusion.


For example, management inquiry may explain how a control is supposed to work, but inquiry alone may not demonstrate operating effectiveness.

The auditor may also need to:

  • Inspect supporting documentation

  • Observe the control

  • Reperform the procedure

  • Test transactions

  • Review system logs


Sampling Must Support the Audit Objective

Auditors rarely test every transaction.


They use sampling and targeted testing to obtain evidence efficiently.


New auditors should understand the difference between:

  • Random selection

  • Haphazard selection

  • Systematic selection

  • Judgmental selection

  • Statistical sampling

  • Non-statistical sampling

  • Targeted high-risk testing


The course introduces audit sampling as part of audit fieldwork and internal-control testing.


The sample should be driven by:

  • Audit objective

  • Population

  • Risk

  • Expected exceptions

  • Tolerable error

  • Desired assurance

  • Control frequency


“Test 25 items” is not a complete methodology unless the auditor can explain why 25 items provide appropriate evidence.


Workpapers Must Tell the Audit Story

Audit workpapers should allow an experienced reviewer to understand:

  • What objective was tested

  • What procedure was performed

  • What evidence was obtained

  • Which items were selected

  • What exceptions were identified

  • How management responded

  • What conclusion was reached

  • Who performed and reviewed the work


The CCS training emphasizes the importance of preparing quality workpapers and properly documenting credibility determinations.


Weak documentation creates several risks:

  • Conclusions cannot be defended.

  • Reviewers cannot evaluate the work.

  • Important evidence may be lost.

  • Follow-up becomes difficult.

  • External quality assessments may identify deficiencies.


A useful principle is:

The workpaper should demonstrate the work.

A statement that “the control was tested and found effective” is not sufficient unless the workpaper shows how the auditor reached that conclusion.


Fieldwork Should Focus on Risk, Not Checklists

Checklists can improve consistency.


They can also create false confidence when auditors complete them mechanically.


Effective fieldwork requires professional judgment.


The auditor should remain alert to:

  • Contradictory explanations

  • Management override

  • Unusual transactions

  • Missing documentation

  • Repeated exceptions

  • Control workarounds

  • System limitations

  • Fraud indicators

  • Scope changes


The CCS course includes detailed audit planning, fieldwork, internal-control testing, audit software, fraud auditing, operational auditing, compliance reviews, performance audits, and IT auditing.


The audit program is a guide.


It should not prevent the auditor from responding to emerging evidence.


Root-Cause Analysis Improves Audit Findings

An audit finding should do more than identify what went wrong.


It should explain why the condition occurred.


Common root causes include:

  • Inadequate training

  • Unclear responsibility

  • Weak supervision

  • System limitations

  • Staffing shortages

  • Poor communication

  • Inadequate procedures

  • Management override

  • Weak monitoring

  • Competing priorities


The CCS agenda includes root-cause analysis as a separate component of audit effectiveness.


Without root-cause analysis, recommendations may address only the symptom.


For example:

Condition: Monthly reconciliations were not completed.

Weak recommendation: Complete the reconciliations.

Root cause: Responsibility was unclear after a reorganization.

Stronger recommendation: Assign ownership, establish completion deadlines, implement escalation procedures, and require management monitoring.


The stronger recommendation reduces the risk of recurrence.


Audit Findings Must Be Factual and Actionable

A well-developed audit finding generally includes:

  • Condition

  • Criteria

  • Cause

  • Consequence

  • Corrective action


Condition

What did the auditor observe?

Criteria

What should have occurred?

Cause

Why did the condition exist?

Consequence

What risk or impact results?

Corrective Action

What should management do?


The CCS program covers the hard facts of audit findings, recommendations, corrective actions, audit opinions, ratings, report formatting, and optimization.


Findings should avoid:

  • Personal criticism

  • Unsupported claims

  • Exaggerated consequences

  • Vague recommendations

  • Technical jargon

  • Conclusions not supported by evidence


The goal is not to embarrass management.


The goal is to communicate risk accurately and support improvement.


Executive Summaries Should Drive Executive Action

Senior executives and Audit Committee members may not read every page of an audit report.


They will usually focus on:

  • Overall conclusion

  • Highest risks

  • Root causes

  • Significant findings

  • Management actions

  • Unresolved disagreements


The CCS course teaches participants how to create effective executive summaries that call for management attention and action.


A strong executive summary should answer:

  • What was audited?

  • What did Internal Audit conclude?

  • What are the most significant risks?

  • Why do they matter?

  • What should management prioritize?

  • Are corrective actions credible?


An executive summary should not merely repeat the detailed findings.


It should interpret their combined significance.


Communication Skills Affect Audit Results

Technical knowledge identifies control weaknesses.


Communication determines whether management addresses them.


Auditors need skills in:

  • Active listening

  • Interviewing

  • Meeting facilitation

  • Conflict resolution

  • Relationship building

  • Report writing

  • Presentation

  • Persuasion

  • Teamwork


The CCS program includes interpersonal and team-building skills, productive interviews, clear and concise reporting, verbal communication, written communication, and methods for motivating management action.


Independence does not require hostility.


An auditor can be:

  • Objective without being dismissive

  • Skeptical without being cynical

  • Firm without being confrontational

  • Collaborative without assuming management responsibility


Strong relationships improve access to information while professional discipline protects objectivity.


Management Action Plans Must Belong to Management

Internal Audit identifies and communicates risk.


Management determines how to address it.


A Management Action Plan should normally include:

  • Corrective action

  • Responsible owner

  • Target completion date

  • Interim controls

  • Required resources

  • Expected outcome

  • Validation criteria


The CCS program addresses how auditors can motivate management to create effective action plans concerning audit findings.


Auditors should avoid owning the solution.


A recommendation can define the control objective without dictating every operational detail.


For example:

Management should implement a sustainable process ensuring all vendor bank-account changes are independently authenticated and approved before payment.

Management can then determine the technology, staffing, or workflow used to achieve that objective.


Internal Audit Should Support Positive Change

The course incorporates Dr. John Kotter’s Eight-Stage Process to help participants understand Internal Audit’s role in supporting positive organizational change.


Internal Audit cannot force sustainable change through report issuance alone.


Corrective action is more likely when:

  • The risk is clearly understood.

  • Leadership supports the change.

  • Responsibilities are assigned.

  • Resources are available.

  • Barriers are addressed.

  • Progress is monitored.

  • Improvements are reinforced.


Auditors can contribute by communicating consequences, identifying root causes, encouraging accountability, and following up on agreed actions.


They should not become the owners of implementation.


Fraud Awareness Is Part of Every Audit

Fraud auditing is not limited to specialized investigations.


Every auditor should remain alert to the possibility of:

  • Asset misappropriation

  • Corruption

  • Financial reporting fraud

  • Payroll fraud

  • Procurement fraud

  • Vendor fraud

  • Expense abuse

  • Management override

  • Cyber-enabled fraud


The CCS curriculum includes “Frauditing—Auditing for Fraud” as part of the broader internal audit foundation.


Auditors should ask:

  • What incentives or pressures exist?

  • Where are controls weakest?

  • Who can override the process?

  • What activity would be difficult to detect?

  • Which data patterns indicate unusual behavior?

  • How could documentation be fabricated?


Fraud awareness strengthens professional skepticism.


Information Technology Is Part of Almost Every Audit

Business processes depend on technology.


Auditors must understand how:

  • Access controls

  • Automated workflows

  • Interfaces

  • System changes

  • Data integrity

  • Cybersecurity

  • Reports

  • Cloud providers

affect the audit objective.


The CCS program includes IT auditing, audit software, internal controls, and information technology frameworks as part of the course agenda.


New auditors do not need to become cybersecurity engineers.


They do need to recognize when technology affects:

  • Control design

  • Evidence reliability

  • Segregation of duties

  • Data completeness

  • Business continuity

  • Fraud exposure


Artificial Intelligence Is Changing Internal Auditing

AI can assist auditors with:

  • Preliminary research

  • Risk identification

  • Audit-program development

  • Interview questions

  • Policy comparisons

  • Data analysis

  • Workpaper organization

  • Finding development

  • Executive summaries

  • Report editing


However, AI does not replace:

  • Professional skepticism

  • Evidence evaluation

  • Independence

  • Judgment

  • Accountability

  • Client communication


A new auditor should learn to treat AI as an analytical assistant—not as the engagement decision-maker.


Every AI-generated output should be:

  • Verified

  • Supported

  • Reviewed

  • Protected from confidentiality breaches

  • Consistent with professional standards


What Participants Will Learn

The Internal Auditor Basic Training program provides a broad foundation covering the full internal audit process.


Participants will learn how to:

  • Understand why Internal Audit exists

  • Recognize applicable audit standards and frameworks

  • Identify enterprise risks

  • Develop strategic and tactical audit plans

  • Understand the roles of management and auditors

  • Plan and conduct audit engagements

  • Apply SPIN interviewing techniques

  • Evaluate business-process maturity

  • Document and test internal controls

  • Gather appropriate audit evidence

  • Prepare quality workpapers

  • Apply sampling and audit software

  • Conduct operational, compliance, fraud, revenue, disbursement, and IT audits

  • Perform root-cause analysis

  • Develop findings and recommendations

  • Prepare executive summaries

  • Communicate audit results

  • Support effective Management Action Plans


Who Should Attend?

The program is particularly valuable for:

  • New internal auditors

  • Professionals transferring into Internal Audit

  • Compliance professionals

  • Risk-management professionals

  • Audit supervisors

  • Audit managers

  • Accountants moving into assurance roles

  • Government auditors

  • Operational auditors

  • IT professionals supporting audits


The course page identifies new auditors, audit managers, and compliance professionals as key participants and describes the program as suitable for those seeking a strong foundation in internal auditing.


Why This Training Matters

Internal auditors are expected to understand the organization quickly, identify meaningful risks, evaluate controls, gather persuasive evidence, communicate clearly, and help management improve.


Those responsibilities cannot be mastered through checklists alone.


They require a practical understanding of:

  • Why Internal Audit exists

  • How risk drives audit work

  • How controls support objectives

  • How evidence supports conclusions

  • How communication creates action

  • How auditors maintain independence while building effective relationships


The Internal Auditor Basic Training program gives professionals a structured foundation for performing the work correctly from the beginning.


It does not focus only on how to complete an audit.


It focuses on how to become an effective internal auditor.


Register for the August 11–13, 2026 Program

Corporate Compliance Seminars’ Internal Auditor Basic Training provides three days of practical instruction covering audit standards, risk assessment, fieldwork, interviews, internal controls, evidence, workpapers, sampling, fraud, information technology, root-cause analysis, reporting, and corrective action.


Participants earn 18 NASBA-approved CPE credits while developing the skills needed to plan, conduct, document, and communicate high-quality internal audits.


A successful internal audit begins long before the first transaction is tested.


It begins with an auditor who understands the objective, recognizes the risk, evaluates the control, gathers the evidence, and communicates the result.


Frequently Asked Questions

What is Internal Auditor Basic Training?

It is a three-day foundational program covering the complete internal audit lifecycle, including standards, risk assessment, planning, interviewing, fieldwork, control testing, evidence, workpapers, reporting, and follow-up.


Is the course appropriate for new auditors?

Yes. The program is designed for new internal auditors, professionals moving into the field, and others seeking a structured understanding of internal auditing.


Does the course cover audit interviewing?

Yes. The program includes audit interviews, soft skills, verbal communication, and the SPIN questioning methodology.


Does the course cover internal-control testing?

Yes. Participants learn how to evaluate and document controls, gather audit evidence, use sampling, and test business processes for consistency and reliability.


Does the program address audit reporting?

Yes. The agenda includes audit findings, executive summaries, recommendations, corrective actions, opinions, ratings, report formatting, and communication optimization.


How many CPE credits are available?

The program provides 18 CPE credits in Auditing, based on a 50-minute instructional hour.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page