Internal audit, taken seriously.
Practical thinking on the problems reshaping the profession — and the fundamentals worth getting exactly right. Written by Team CapItAll, the practitioners behind AuditNexia and Audytr AI.
The new Global Internal Audit Standards are in force. Is your function actually conforming?
The IIA rewrote the rulebook and set a hard deadline. A year on, plenty of functions are still working the old way and calling it compliance.
Auditing in the age of AI: how do you assure a system you can’t fully see?
Two problems arrived at once. Auditors now have to give assurance over AI, and are being handed AI to do it with. Both need the same discipline.
From sampling to full-population testing: why continuous monitoring stopped being optional
Sampling was a workaround for a data problem that no longer exists. The exceptions you most need to catch are exactly the ones a sample is built to miss.
Most audit teams still run on spreadsheets. Here’s what it quietly costs them.
The spreadsheet is not free. Its price is paid in broken audit trails, version confusion and the one formula error nobody caught in time.
The audit talent gap is real — and data literacy is the new baseline
The shortage isn’t only headcount. It’s auditors who can interrogate data as fluently as they interrogate a control. That skill is now table stakes.
From compliance checker to strategic advisor: earning the board’s attention
Every audit function says it wants a seat at the table. Fewer have asked what they’d say once they had it. Relevance is something you communicate, not something you’re owed.
Assurance vs. advisory: the distinction that changes how you run an engagement
Many auditors treat the two as one activity with different labels. They aren’t. The choice quietly reshapes your independence, your evidence and your report.
Independence and objectivity aren’t the same thing. Here’s why it matters.
Auditors use the words interchangeably and lose something important in the swap. One is about where you sit. The other is about how you think.
Anatomy of a strong audit finding: condition, criteria, cause, effect, recommendation
A weak finding tells the reader what you saw. A strong one tells them why it matters and what to do about it. The difference is five elements, and most drafts are missing at least one.
Root cause, not symptom: writing recommendations management will actually implement
“Increase oversight” is not a recommendation. It’s an admission that you stopped asking why one question too early.
Inherent vs. residual risk, and why your risk-and-control matrix depends on getting it right
Confuse the two and every risk rating in your matrix is quietly wrong. It’s a five-minute concept that underpins the whole of risk-based auditing.
Design vs. operating effectiveness: testing controls the right way
A control can be perfectly designed and still fail every day. If you only test one of these things, you’re giving assurance over half a control.
What ‘reasonable assurance’ actually means — and why audit never promises certainty
The phrase sounds like a hedge. It isn’t. It’s an honest description of what any assurance can and cannot deliver — and getting it wrong sets a trap for everyone.
The new Global Internal Audit Standards are in force. Is your function actually conforming?
The IIA rewrote the rulebook and set a hard deadline. A year on, plenty of functions are still working the old way and calling it compliance.
On 9 January 2025 the 2013 International Professional Practices Framework stopped being the reference point for internal audit. In its place: the Global Internal Audit Standards, published a year earlier and effective from that date. If your quality assurance program, your charter, or your engagement templates still point back to the old attribute and performance standards, you are measuring yourself against a rulebook that no longer applies.
Most functions know the Standards changed. Fewer have done the unglamorous work of checking, line by line, where they now fall short. That gap is where quality assessments will find you.
What actually changed
The architecture is the most visible shift. The Standards are organised into five domains — Purpose, Ethics and Professionalism, Governing the Internal Audit Function, Managing the Function, and Performing Services — and fifteen principles beneath them. Each standard now separates mandatory Requirements (the “must” language) from Considerations for Implementation (the “should” and “may”), and closes with examples of evidence you can point to in an assessment.
That last part matters more than it looks. The old framework told you what good looked like. The new one tells you how to prove it. Conformance is now an evidence exercise, which should feel familiar to anyone who has ever asked an auditee to show their working.
Underneath the structure, the substance leans harder on governance. The board’s role in overseeing the function is spelled out in a way it never was before, and so is the chief audit executive’s responsibility for a strategy, a methodology, and a performance measurement approach that someone could audit. The relationship between the CAE and the board is treated as a control in its own right — because it is.
The old framework told you what good looked like. The new one tells you how to prove it.
On the shift to evidenceWhere functions are quietly non-conformant
Three patterns come up again and again when we run gap assessments.
The charter never got reopened. A charter that references the IPPF, or that is silent on the board’s oversight responsibilities, is a conformance gap on its face. This is a one-afternoon fix that people keep deferring.
There is no real performance measurement. Counting audits closed is not measuring performance. The Standards expect objectives, methodology, and a way to demonstrate the function is achieving what it set out to. “We finished the plan” is an activity metric, not an outcome.
Public sector application got skipped. If you audit a government body or PSU, the Standards include a dedicated public-sector section that changes how some requirements apply. Ignoring it because the old standards didn’t single you out is a mistake.
Treat conformance as a project, not an assumption. Map your charter, QAIP, methodology and templates against the fifteen principles, and log every “must” you cannot currently evidence.
You do not need to be perfect on day one. You do need to know exactly where you stand, and to be able to explain any deviation before an external assessor does it for you.
The Standards are not a burden dressed up as a benefit. They are the clearest description the profession has produced of what internal audit is for. The functions that read them as a checklist will do the minimum. The ones that read them as a mandate will use them to renegotiate their relationship with the board — and that is worth far more than a clean assessment.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
Auditing in the age of AI: how do you assure a system you can’t fully see?
Two problems arrived at once. Auditors now have to give assurance over AI, and are being handed AI to do it with. Both need the same discipline.
A model recommends which loans get approved. Another flags which transactions look like fraud. A third drafts the first version of a contract. None of them can tell you, in a sentence a board would accept, exactly why they did what they did. And all of them are now in scope.
The instinct is to treat AI as a new specialism, something for the data scientists. It is closer to the truth to treat it as an old problem wearing new clothes. You are still asking whether a process is controlled, whether the data feeding it can be trusted, and whether someone is accountable when it goes wrong. The novelty is in how you get evidence, not in what you are trying to establish.
Auditing the organisation’s AI
Start where you always start: what could go wrong, and who owns it. For a deployed model the failure modes are reasonably well understood by now. The training data was biased or stale. The model drifted after deployment and nobody noticed. There is no human in the loop for decisions that badly need one. Nobody can reconstruct why a specific decision was made, which becomes a live problem the moment a regulator or a customer asks.
The control questions follow naturally. Is there an inventory of models in use, or does the business genuinely not know how many it has? Who signed off that this model was fit for its purpose, and against what criteria? What monitors performance after go-live, and what threshold triggers a review? Can the organisation explain an individual output, and retain the evidence to prove it later?
You are still asking whether a process is controlled and who is accountable when it goes wrong. The novelty is in the evidence, not the objective.
On what AI audit really isUsing AI to audit
The other half of the shift is more seductive and more dangerous. AI can read every transaction instead of a sample, cluster anomalies a human would miss, and draft an observation in seconds. Used well, it moves the auditor up the value chain, from finding exceptions to judging them.
Used carelessly, it quietly corrodes the thing that makes audit worth anything: defensible judgement. Three guardrails are non-negotiable.
The judgement stays with the auditor
A model can surface an exception. It cannot decide the exception is a finding, weigh its significance, or own the conclusion. If you cannot explain why the tool flagged something, you cannot put it in a report over your name.
Evidence integrity is sacred
Anything AI produces — a summary, a draft observation, a risk rating — is a hypothesis until you have traced it to source. Treat it as a lead, not as evidence. The workpaper still has to stand on the underlying record.
Nothing goes in that you can’t defend
If a partner, an audit committee, or a court asked you to walk through how a conclusion was reached, “the AI said so” is not an answer. Explainability is not a nice-to-have. It is the price of using the tool at all.
Auditing AI is risk-based auditing with unfamiliar evidence. Anchor on ownership, data quality, monitoring and explainability, and the domain expertise is something you can bring in.
Auditing with AI is a force multiplier only if judgement, evidence integrity and explainability are non-negotiable. The moment they slip, you have automated the appearance of assurance without the substance.
The profession has absorbed disruptive tools before — spreadsheets, ERP, data analytics — and each time the answer was the same. The tool changes what is possible. It does not change who is accountable for the opinion.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
From sampling to full-population testing: why continuous monitoring stopped being optional
Sampling was a workaround for a data problem that no longer exists. The exceptions you most need to catch are exactly the ones a sample is built to miss.
Sampling was never a virtue. It was a concession. When testing meant a junior auditor pulling paper vouchers from a box, you tested twenty-five items because testing two hundred thousand was physically impossible. The statistics gave the compromise a respectable name. But the logic was always backwards: the low-frequency, high-impact events that keep a CAE awake — the single fraudulent override, the one payment above the approval threshold — are precisely the items a random sample is most likely to walk straight past.
Continuous control monitoring removes the concession. When the evidence lives in an ERP and can be queried by rule, testing twenty-five items instead of the whole population is no longer prudent. It is a choice to look away.
What actually changes
The obvious change is coverage. Instead of asking whether the twenty-five sampled purchase orders had dual approval, you ask whether every purchase order above the threshold had it, and you get a count of the ones that didn’t, with the transactions attached. Missing approvals, duplicate payments, breached limits, segregation conflicts — these become continuous readings rather than annual discoveries.
The subtler change is timing. Annual testing tells you about a control’s health eleven months after it started failing. Monitoring tells you this week. A weakness caught in near-real time can be fixed before it compounds; the same weakness caught in the year-end fieldwork is already a loss you are quantifying.
Testing twenty-five items when you could test all of them is no longer prudence. It is a choice to look away.
On sampling in a full-data worldThe auditor’s job doesn’t shrink. It moves.
The fear that monitoring automates auditors away has it exactly wrong. When the system flags four thousand transactions and a hundred and forty-seven exceptions, the machine has done the part that was always drudgery. What remains is the part that was always the job: deciding which exceptions matter, understanding why the control failed, distinguishing a genuine breakdown from a data artefact, and telling management something they can act on.
The post-run view an auditor should be working from is not raw data. It is a prioritised set of observations — control failures grouped, risk-rated, mapped to the specific procedure or SOP clause breached, evidence already linked. The auditor spends their hours on judgement, not on collection.
Full-population testing is not a bigger sample. It is a different posture — from periodic snapshot to always-on assurance.
It does not replace the auditor. It relocates the auditor to where the value always lived: judgement, root cause and the conversation with management.
The organisations still running purely periodic, sample-based assurance are not being careful. They are accepting a level of blindness that the data no longer requires them to accept.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
Most audit teams still run on spreadsheets. Here’s what it quietly costs them.
The spreadsheet is not free. Its price is paid in broken audit trails, version confusion and the one formula error nobody caught in time.
The spreadsheet feels free. It is already installed, everyone can use it, and it never sends an invoice. That is exactly why the costs go unexamined for years. Roughly three quarters of audit and controls functions still track their risk-and-control matrices, testing and issues in workbooks — and the bill is real, it just arrives in a currency nobody budgets for.
The four hidden line items
You lose the audit trail
An evidence-first profession runs on traceability: this conclusion rests on that test, which rests on this record. A spreadsheet remembers none of it. Who changed the sample size, when, and why? The file cannot say. The moment a regulator asks you to reconstruct how an opinion was formed, the gaps become the finding.
You lose the single version
“Final,” “Final v2,” “Final USE THIS ONE.” Every audit team has lived this. When the same matrix exists in four inboxes, reconciling them by hand is not just tedious; it is where errors are born and where accountability dissolves.
You inherit formula risk
Some of the most expensive corporate mistakes on record trace back to a mis-dragged formula or a hidden row in a workbook. A tool built to be flexible is, by the same design, a tool with no guardrails. Nothing warns you that the range stopped one row short.
You lose the real-time view
Leadership wants to know, today, how many high-risk issues are open and overdue. If the answer requires someone to open six files and consolidate them, you do not have oversight. You have an archaeology project.
The spreadsheet’s flexibility is exactly its danger. A tool with no guardrails will let you do the wrong thing as smoothly as the right one.
On why the workaround persistsThe spreadsheet is not free. It defers its costs into version confusion, broken traceability, key-person risk and the error nobody caught.
The test is simple: if you were asked to prove, with evidence, how any conclusion in your last audit was reached, could you — in minutes, not days? If not, the workbook is already costing you more than a platform would.
None of this is an argument that auditors are careless. It is an argument that they have been asked to do regulator-grade work with a tool that was designed for household budgets. The mismatch is structural, and it is fixable.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
The audit talent gap is real — and data literacy is the new baseline
The shortage isn’t only headcount. It’s auditors who can interrogate data as fluently as they interrogate a control. That skill is now table stakes.
Ask a room of chief audit executives what keeps them up at night and “finding and keeping the right people” will be near the top every time. But the shortage is more specific than a headcount problem, and misreading it leads to hiring the wrong people faster.
The scarce commodity is not auditors. It is auditors who can sit in front of a full population of transactions and know what to ask it. The profession trained a generation to test controls beautifully and to test data barely at all. As the evidence moves from paper to systems, that imbalance has become the constraint.
What the job now demands
Data literacy does not mean every auditor becomes a data scientist. It means a floor of capability that used to be optional and is now assumed. Can you pull the population yourself rather than waiting three weeks for IT? Can you spot when a dataset is incomplete or the join is wrong, before you build a finding on it? Can you tell the difference between a real anomaly and an artefact of how the data was extracted? Can you read what an analytics routine did well enough to defend its output to an audit committee?
The profession trained a generation to test controls beautifully and to test data barely at all. That imbalance is now the constraint.
On the real shape of the gapThe shape to aim for
The most valuable auditor in the current market is what people clumsily call “T-shaped.” Deep in one thing — a process, a sector, a risk domain — and broad enough across data, technology and communication to be dangerous in the good sense. The pure specialist who cannot touch data is narrowing. The generalist who understands data but nothing deeply is a commodity. The combination is rare, and it is what functions are competing for.
Building rather than buying
Because that combination is rare, the market cannot supply it fast enough, and the functions that wait to hire it fully-formed will wait a long time. The ones pulling ahead are building it: pairing strong auditors with analytics tooling and letting the skill grow through the work, rather than treating data as a separate team that audit borrows from occasionally.
The talent gap is really a skills gap. Data literacy has moved from a differentiator to a baseline, and the org chart hasn’t caught up.
Don’t wait to hire the finished article. Give your good auditors the tools and the population, and let capability compound through real engagements.
Every technology shift in this profession has produced the same anxiety and the same answer. The tools raise the floor; the auditors who learn them raise the ceiling.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
From compliance checker to strategic advisor: earning the board’s attention
Every audit function says it wants a seat at the table. Fewer have asked what they’d say once they had it. Relevance is something you communicate, not something you’re owed.
There is a version of internal audit that boards tolerate and a version they rely on, and the distance between them is almost entirely a matter of what the function chooses to talk about. The tolerated function reports on last year: here are the controls we tested, here is what we found, here is who agreed to fix it. Useful, necessary, and easy to file under “done.” The relied-upon function reports on next year: here is where the organisation is most exposed, here is what we think leadership should be watching, here is the risk nobody has assigned an owner.
Same profession. Same standards. Radically different altitude.
Speak in the board’s currency
A board does not think in control deficiencies. It thinks in outcomes, exposures and decisions. An observation that reads “three of twelve reconciliations lacked evidence of review” is true and, to a director, nearly inert. The same fact reframed — “our controls over cash would not currently catch a material misstatement before it left the building” — lands, because it is expressed as consequence rather than as procedure.
The tolerated function reports on last year. The relied-upon function reports on next year. Same profession, radically different altitude.
On what earns the seatMap your assurance, then talk about the gaps
The most strategic conversation an audit function can have with a board is often about what is not being assured. An assurance map — laying the organisation’s principal risks against who provides comfort over each — almost always reveals a few significant risks with nobody credible watching them. Surfacing that is worth more than another well-executed audit of a well-controlled process. It tells the board something it did not know and could not have seen.
Be willing to measure yourself
Strategic relevance cuts both ways. A function that wants to be taken seriously as an advisor has to be able to answer “are you any good?” with something better than a count of completed audits. The current Standards expect a genuine performance measurement approach, and that expectation is a gift: it forces the function to define the outcomes it is actually accountable for, which is the same question the board is quietly asking.
Relevance is a communication discipline before it is a capability. Report consequences and exposures, not procedures and sample sizes.
Lead with what isn’t assured. The uncovered risk you name is worth more to a board than the covered one you audited well.
None of this means abandoning the assurance work. It means refusing to let the assurance work be the whole conversation. The board already has people to tell it what happened. What it lacks, usually, is someone independent enough to tell it what it is not looking at.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
Assurance vs. advisory: the distinction that changes how you run an engagement
Many auditors treat the two as one activity with different labels. They aren’t. The choice quietly reshapes your independence, your evidence and your report.
A colleague once described the difference like this: in an assurance engagement you are a judge, and in an advisory engagement you are a coach. It is a rough analogy, but it captures the thing most auditors blur. The two services share tools and skills, and are governed by the same Standards, but they answer to different masters. Miss the distinction and you will run one as if it were the other — usually giving advice with the detachment of a judge, or an opinion with the warmth of a coach, and satisfying nobody.
What separates them
Assurance is a three-party arrangement. There is the subject (a process, a control, a risk), the auditor forming an independent conclusion about it, and the party relying on that conclusion — typically management and the board. The whole value comes from the auditor’s independence from what they are assessing.
Advisory is a two-party arrangement. The client asks, the auditor helps — designing a control, reviewing a process before it goes live, giving a view on a proposed change. The nature and scope are agreed with the client, and no independent opinion is issued to a third party. The value is the expertise, not the detachment.
| Assurance | Advisory | |
|---|---|---|
| Parties | Three: subject, auditor, user | Two: auditor and client |
| Output | An independent conclusion | Advice, options, or design input |
| Scope set by | The auditor, per a risk assessment | Agreed with the client |
| Independence | The whole point | Managed, so it isn’t compromised later |
| The auditor is | A judge | A coach |
Give advice with the detachment of a judge, or an opinion with the warmth of a coach, and you satisfy nobody.
On running one as the otherThe trap: advising your way into a conflict
Advisory work is genuinely valuable, and the Standards endorse it. The danger is subtle. If you help design a control this year, you cannot credibly provide independent assurance over that same control next year — you would be auditing your own work. This is the single most common way audit functions compromise their objectivity without noticing, one helpful favour at a time.
The safeguard is not to avoid advisory work. It is to see the conflict coming and manage it — disclose it, rotate who performs the later assurance, or have someone else own the design. The Standards ask you to protect objectivity, not to hide from usefulness.
Decide which service you are providing before you start, because it sets your independence posture, your evidence bar and what you can promise the reader.
Advisory is not lesser work — but every piece of it is a potential future conflict. Log it now, and protect the assurance you may need to give later.
Both services belong in a mature function. The professionalism is in never confusing which one you are delivering.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
Independence and objectivity aren’t the same thing. Here’s why it matters.
Auditors use the words interchangeably and lose something important in the swap. One is about where you sit. The other is about how you think.
Here is a question that separates people who have thought about this from people who have only recited it: can an auditor be independent but not objective, or objective but not independent? The answer to both is yes, and understanding why is the whole point.
Independence is structural. It is about where the function sits and to whom it answers. Does the chief audit executive report functionally to the board rather than to the executives whose work they audit? Is the function free from operational responsibilities that would put it in the position of auditing itself? Independence is arranged in the org chart and the charter. It is a property of the function.
Objectivity is mental. It is an unbiased state of mind that lets an individual auditor form a conclusion on the evidence without being swayed — by a friendship with the auditee, by a fear of the consequences, by a preference for a tidy answer. Objectivity is a property of the person, in the moment.
Independence is arranged in the org chart. Objectivity is practised in the moment. You can have one without the other.
On the real distinctionWhy keeping them separate protects you
Conflate the two and you lose sight of the fact that each is threatened differently and defended differently. A perfectly independent function — pristine reporting lines, a model charter — can still produce a biased audit if the auditor on the job is protecting a colleague or has already decided the answer. And a structurally awkward situation — a small function, a solo auditor who once worked in the area under review — does not automatically destroy objectivity if the threat is disclosed and safeguarded.
That is why the Standards treat impairment as something you identify and manage rather than something you simply avoid. When an objectivity threat appears — you are asked to review a process you built, or the auditee is a close friend — the professional response is to name it and put a safeguard in place, not to pretend it away.
Independence is about the function’s position; objectivity is about the individual’s mindset. Defend both, but don’t assume one guarantees the other.
Threats to objectivity are managed, not hidden. Disclose them, safeguard them, and the work stays credible — even in a small or awkwardly-placed function.
The next time someone uses the two words as synonyms, it is worth a gentle correction. The distinction is not pedantry. It is the difference between an audit that is well-placed and one that is well-judged.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
Anatomy of a strong audit finding: condition, criteria, cause, effect, recommendation
A weak finding tells the reader what you saw. A strong one tells them why it matters and what to do about it. The difference is five elements, and most drafts are missing at least one.
Read enough audit reports and you can sort the findings into two piles without thinking. One pile makes management defensive and changes nothing. The other gets fixed. The difference is almost never the severity of the issue. It is whether the finding was built properly.
A complete finding has five elements. Leave one out and the reader has to supply it themselves, which they will do in whichever direction is most convenient for them.
The five elements, and what each one prevents
Condition is what you found — the current state, stated as fact. “Nineteen of sixty payments above ₹5 lakh were released without the second approval the policy requires.” Specific, countable, hard to argue with.
Criteria is what should be true — the policy, standard or expectation the condition is measured against. Without it, “nineteen payments lacked a second approval” is just a number. With it, it is a gap. The criterion is what makes the condition a problem rather than a fact.
Cause is why the gap exists. Not the symptom — the root. “The approval workflow allows release once a single approver acts, so the second approval is optional in practice.” Skip this and every recommendation you write will be a guess.
Effect is the consequence — the “so what” that earns management’s attention. “₹2.1 crore was released this year without the control the policy relies on to prevent unauthorised or fraudulent payment.” This is the element weak findings drop most often, and it is the one that decides whether anyone acts.
Recommendation is what to do. Practical, and specific enough that someone could be held to it: who does what, by when.
A weak finding tells the reader what you saw. A strong one tells them why it matters and what to do — and leaves them nothing to argue with.
On the difference that gets things fixedIf a finding doesn’t explicitly carry all five elements, the reader fills the gaps — and rarely in your favour.
The two that get dropped most are cause and effect. Cause is what makes your recommendation right. Effect is what makes anyone care.
The five-element model is not bureaucracy. It is the structure of a persuasive argument, which is what a finding actually is: a case that something is wrong, that it matters, and that it can be fixed.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
Root cause, not symptom: writing recommendations management will actually implement
“Increase oversight” is not a recommendation. It’s an admission that you stopped asking why one question too early.
There is a particular kind of recommendation that appears in weak reports, and once you notice it you cannot unsee it. “Management should enhance monitoring.” “Controls should be strengthened.” “Staff should be reminded of the policy.” They sound reasonable. They are almost always useless, and they share one origin: the auditor treated a symptom as if it were the disease.
Why weak recommendations happen
Say you find that expense claims are routinely approved without receipts. The lazy recommendation writes itself: “approvers should check for receipts before approving.” But that is just the condition restated as an instruction. It tells management to want the right outcome without touching whatever is producing the wrong one.
Ask why once. Approvers don’t check because the system lets them approve without the receipt attached. Ask why again. It lets them because the receipt field was never made mandatory. Now you have somewhere to stand. The recommendation is not “check more carefully.” It is “configure the workflow to block approval until a receipt is attached” — a fix that survives the departure of the diligent approver and the arrival of the careless one.
‘Approvers should check more carefully’ is the condition restated as an instruction. It tells management to want the right outcome without touching what produces the wrong one.
On the symptom trapThe discipline: keep asking why
The technique is old and unfashionable and it works: keep asking why until the answer stops being about a person and starts being about the process, the system, or the design. People fail unpredictably. Processes fail for reasons, and reasons can be engineered out.
A root cause you can fix is almost always structural — a missing system control, an incentive pointing the wrong way, an unclear ownership, a design that makes the wrong action easier than the right one. A “cause” that is really just “someone didn’t do their job” means you stopped one question too early.
Then make it actionable
A recommendation management can implement passes a blunt test: could someone be held accountable for it at the next follow-up? That requires three things to be unambiguous — who owns it, what specifically changes, and by when. “Strengthen controls over vendor onboarding” fails all three. “Procurement to enable mandatory bank-detail verification in the vendor master by 30 September” passes all three, and can actually be closed.
If your recommendation is the finding rephrased as a good intention, you found a symptom. Keep asking why until the answer is structural.
Every recommendation needs an owner, a specific action and a date. If it can’t be closed at follow-up, it was never really a recommendation.
Management does not resist good recommendations. It resists vague ones, because a vague recommendation is impossible to finish — there is always more monitoring to do, more strengthening to attempt. A precise one, aimed at the root, can be done. And things that can be done, get done.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
Inherent vs. residual risk, and why your risk-and-control matrix depends on getting it right
Confuse the two and every risk rating in your matrix is quietly wrong. It’s a five-minute concept that underpins the whole of risk-based auditing.
Two auditors rate the same risk. One calls it high, the other low, and both are right — because they are answering different questions without realising it. One is describing the risk before controls; the other, after. Until you make that distinction explicit, your risk-and-control matrix is built on an ambiguity, and ambiguity at the foundation propagates all the way up.
The two questions
Inherent risk is the exposure that exists before you do anything about it — the raw danger baked into the activity itself. Handling large volumes of cash is inherently risky whether or not you have controls, because cash is portable, anonymous and desirable. Inherent risk asks: how bad could this be, left alone?
Residual risk is what remains after the controls have done their work. You cannot make cash un-stealable, but dual custody, daily reconciliation and CCTV bring the realistic exposure down to something the organisation can live with. Residual risk asks: how bad is it, given what we actually do?
Controls don’t remove risk. They move it — from what you would face to what you choose to accept.
On what a control actually doesWhy the matrix depends on it
Risk-based auditing means putting your finite hours where the exposure is greatest. But greatest by which measure? If you plan against inherent risk, you will keep auditing well-controlled, low-residual areas simply because they are inherently scary — and starve the areas where inherent risk is moderate but the controls are weak, so residual risk is actually high. That second category is where the real surprises live.
A properly built matrix holds both. It records the inherent rating, the controls that address it, and the residual rating that results. The gap between inherent and residual is a measure of how much work your controls are doing — and a residual rating that barely moves from inherent is itself a finding, because it means the controls aren’t earning their keep.
And residual meets appetite
Residual risk only means something against a second number: how much risk the organisation is willing to accept — its appetite. A residual risk sitting comfortably inside appetite needs no action. One sitting outside it demands either stronger controls or a conscious, documented decision to accept the excess. Without an appetite, “residual risk is medium” is a fact with no consequence attached.
Inherent is before controls; residual is after. Every rating in your matrix should be explicit about which one it is.
Plan against residual risk, not inherent — and read the gap between them. A residual that barely moves off inherent means the controls aren’t working.
It is a small distinction that does enormous load-bearing work. Get it right and your matrix directs attention honestly. Get it wrong and you will spend your best people guarding the doors that are already locked.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
Design vs. operating effectiveness: testing controls the right way
A control can be perfectly designed and still fail every day. If you only test one of these things, you’re giving assurance over half a control.
Imagine a beautifully written control. Every payment above a threshold requires two approvers; the policy is clear, the roles are defined, the workflow is documented to the last step. On paper it is flawless. Now imagine that in practice one of the two approvers left six months ago, and the remaining approver has been clicking through both steps ever since because nobody reassigned the role. The design is perfect. The operation is a fiction. And a control that only works on paper doesn’t work.
This is why competent controls testing always asks two separate questions, in order.
First: is it designed to work?
Design effectiveness asks whether the control, as conceived, is actually capable of addressing the risk it is meant to address. If the risk is unauthorised payments and the control is a manager glancing at a monthly summary, the design is weak regardless of how diligently that glance happens — a summary review cannot catch an individual unauthorised item. You establish design effectiveness by understanding the control and typically walking a single transaction through it end to end. One instance is enough, because you are testing the concept, not the consistency.
Then: does it actually run that way?
Operating effectiveness asks whether the well-designed control genuinely operated as intended, throughout the period, every time it should have. This is where the departed approver is exposed. One walkthrough would never reveal it; you have to test across the period — a sample of instances, or with the right tooling, the whole population. Here the question is not “could it work?” but “did it, consistently?”
A control that only works on paper doesn’t work. Design tells you it could. Only operating tells you it did.
On why one test is never enoughThe order matters
Test design first, always. There is no point sampling a hundred instances of a control operating faithfully if the control was never capable of catching the risk in the first place — you would be carefully proving that a broken concept ran reliably. If the design fails, the finding is written and you stop; operating tests on a badly-designed control are wasted effort. Only once design holds does it make sense to ask whether operation held too.
Design asks “could this control work?” Operating asks “did it, every time, all period?” They are different questions with different tests.
Test design first. A well-operated bad control is still a bad control — and a perfectly designed control that stopped running is the failure people miss.
When someone says a control “passed testing,” the right follow-up is always: which test? Half an answer to a controls question is often more dangerous than no answer, because it wears the confidence of a conclusion it hasn’t earned.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.
What ‘reasonable assurance’ actually means — and why audit never promises certainty
The phrase sounds like a hedge. It isn’t. It’s an honest description of what any assurance can and cannot deliver — and getting it wrong sets a trap for everyone.
A board member once asked me, not unreasonably, why the audit couldn’t just guarantee there was no fraud. It is the most natural question in the world, and the answer sits at the centre of what our profession is and isn’t. Internal audit provides reasonable assurance, never absolute assurance. Understanding why is not a disclaimer to bury in a footnote. It is a promise you make honestly at the start, so that nobody mistakes what they are getting.
Why absolute assurance is impossible
Three limits make certainty unattainable, and they are structural, not a matter of trying harder.
You test evidence, not everything. Even full-population testing examines the transactions that were recorded. It cannot see the transaction that was deliberately kept off the books. Assurance is always bounded by the evidence that exists.
Controls can be beaten. Two people who agree to collude can defeat a segregation of duties designed to keep them apart. Management can override the very controls it built. No control system is proof against a determined, senior, collaborating adversary, and honest assurance says so.
Certainty isn’t worth its price. You could, in theory, chase certainty by testing every item, re-performing every calculation, and re-verifying every record with its counterparty. Nobody does, because the cost would dwarf the value. Assurance is deliberately calibrated to a sensible balance of cost and confidence.
Reasonable assurance isn’t a hedge you slip into a footnote. It’s a promise you make honestly at the start.
On setting expectationsWhat “reasonable” actually claims
Reasonable assurance is a high level of confidence — not a shrug. It says: we designed and performed enough work that, in our professional judgement, we would have detected significant issues in the areas we examined, if they existed. It is a strong statement. It is simply not an infinite one, and the honesty is in marking the boundary rather than pretending there isn’t one.
Why the honesty protects everyone
Auditors who let stakeholders believe an unqualified report is a guarantee of no problems are setting a trap that springs on both sides. When something surfaces later — and in a large organisation, something always eventually does — the audit is blamed for a promise it never actually made. Naming the limits of assurance at the outset is not defensiveness. It keeps the reliance the board places on your work proportionate to what your work can bear.
Reasonable assurance is a high bar, not a low one — but it is bounded by available evidence, the possibility of collusion and override, and sensible cost.
Set the expectation early and plainly. A clean report means no significant issues were found in what was examined — not that none exist anywhere. That honesty is what makes the assurance trustworthy.
So the honest answer to that board member is this: we cannot guarantee there is no fraud, and any auditor who tells you otherwise is selling you a comfort that doesn’t exist. What we can do is give you a well-founded, independent, high level of confidence about the risks we examined — and be precise about where that confidence ends. In a world without certainty, that precision is the most valuable thing we have to offer.
Facing something similar in your audit function?
Talk to the team behind AuditNexia and Audytr AI. We’re glad to compare notes — no pitch required.