FIELDWORK · SIX WEEKS · SELF-PACED
Internal Audit Lead — a six-week applied programme
In-house internal auditors running or growing into engagement leadership: seniors and managers who scope, lead and report their own audits, plus heads of function rebuilding a plan or a methodology. Written for a permanent function that answers to a committee, not for an external provider.
The platform hosts the spine — briefs, drills, sims, templates, progress — and structures the deep work. It does not host sixty hours of content. Plan roughly ten focused hours a week, most of it real work against your own function: your universe, your plan, your findings, your committee pack. Signify Fieldwork keeps the thread.
6 weeks~10h a week18 modules59 required steps20 drills
Week 1 of 6 · 10 hours · 3 modules
The function, and what it is for
Before the plan and before the first engagement: what independence actually buys, where it is threatened by the helpful work rather than the obvious kind, and what the universe has to cover before anything can be risk-based.
Week 1 of 6 · 10 hours · 3 modules
The function, and what it is for
Before the plan and before the first engagement: what independence actually buys, where it is threatened by the helpful work rather than the obvious kind, and what the universe has to cover before anything can be risk-based.
1.1Three lines, and the one you are on
3h
Where internal audit sits against management and the committee, what independence costs as well as what it buys, and the advisory work that quietly moves a function into the second line.
- learnRequired
The assurance you cannot give about work you did
Read the brief~2 min
The three-lines model is drawn as three neat columns and lived as a set of arguments about which column a particular piece of work belongs in. That argument is the useful part. Everything internal audit is for rests on being able to say, credibly, that you did not do the thing you are now assessing.
What independence actually buys
- The right to look. A function that has traded its independence for goodwill finds the access questions get harder every year, and cannot say why.
- The right to disagree in writing. Second line writes recommendations to management; you write findings about management, and the difference is the reporting line.
- A conclusion somebody outside can rely on. Regulators, external audit and the committee all discount assurance in proportion to how close the assurer sat to the work.
What it costs, which is discussed far less
Independence is not free and pretending otherwise is how functions end up defending it badly. You cannot design the control, you cannot run the workshop that sets the risk appetite, and you cannot be the person the CFO calls when a process has fallen over. Every one of those is real value the organisation does not get, and it is worth being able to say so out loud rather than treating independence as self-evidently worth any price.
The drift is always helpful
Nobody moves into the second line on purpose. It happens through a sequence of individually reasonable favours: you have the best view of the control environment, so you draft the matrix; you know the systems, so you sit on the design committee; you are trusted, so you own the remediation tracker. Three years later a third of the plan is work you cannot audit, and no single step in the sequence looked like a mistake.
The practical test is not “is this advisory or assurance”, which nobody agrees on. It is: if I put this in next year's plan, would I be assessing my own work? If the answer is yes, the decision is being made now, not next year.
Carry this into the drill
The Crossword covers the vocabulary an audit function is held to across governance, risk, audit and security. Play it for the terms you half-know rather than the ones you use daily — the half-known ones are what go wrong in a committee paper.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Practitioner's Crossword
Open the drillGeneral practitioner vocabulary rather than an audit-specific piece, and used here the way the cyber programme uses its word game: a week-one foundation. Four puzzles across governance, risk, audit and security, which is the language range a lead is expected to move through without stopping.
Ticks itself when the drill records a result
- applyRequired
A one-page mandate for your function, naming the two activities that sit closest to the line
Open the brief
Write your function's mandate on one page: what you provide assurance over, who you report to functionally and administratively, what you will not do, and how the plan gets approved.
Then the part that makes it worth doing — name the two activities your function currently performs that sit closest to the line, and say for each whether you would still be able to audit that area next year.
What to produce
- Purpose, and the standard or framework you hold yourself to
- Scope: what is in the universe, and what is explicitly excluded
- Reporting lines, functional and administrative, named
- Authority: access to records, people and systems
- What the function will NOT do, in specific terms rather than principles
- The two closest-to-the-line activities, each with the audit it would compromise
1.2Independence you can actually defend
3.5h
Self-review, self-interest, familiarity and advocacy as they arise in-house — the system you advised on, the friend who owns the process, the finding you championed last year.
- learnRequired
Declining work independence never barred has a cost too
Read the brief~2 min
Independence questions almost always arrive as a request for a favour from someone reasonable, and the failure mode is not corruption. It is that the threat gets noticed and then handled by feel — declined because it felt uncomfortable, or accepted because the person asking was senior and the work was interesting.
Four threats, and where they come from in-house
- Self-review: assessing work you did. In-house this arrives through advisory engagements far more often than through secondments — the control matrix you drafted, the policy you were asked to review before it went out.
- Self-interest: your position improves or suffers based on the outcome. The bonus set by the person you audit is the obvious case; the promotion that depends on being seen as a partner to the business is the common one.
- Familiarity: long association with the auditee. It builds slowly and nobody notices the year it became a problem, which is why the safeguard is a rotation schedule rather than a judgement call.
- Advocacy: you argued for an outcome and the audit could confirm or embarrass that argument. Rare, and the hardest to safeguard, because the report has to be read by someone who knows you took a position.
The test a safeguard has to pass
A safeguard is adequate if a sceptical, informed reader would accept it — not if it makes you feel better. “Someone else reviewed my work” fails that test when the someone else reports to you. “A different auditor led it and the report discloses that I designed the matrix” passes, because the reader can discount it themselves.
The failure nobody counts
Declining work independence never actually barred is also a failure, and it is invisible, because nothing goes wrong visibly. A function that refuses to facilitate a risk workshop, or to observe a steering committee, or to advise on options where management still decides, has not protected anything. It has removed itself from the rooms where it would have learned what next year's plan should contain.
Carry this into the drill
The drill runs twelve engagements an in-house function is really offered. Watch which direction your errors run — over-cautious and over-comfortable are both failures and only one of them ever shows up in an external quality assessment.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Independent Enough?
Open the drillBuilt for this module. Independence is usually taught as a rule and practised as a reflex; the drill forces the intermediate step — name the threat, then decide whether a safeguard reaches it — and counts the engagements you took unsafeguarded over work you had a hand in.
Ticks itself when the drill records a result
- applyRequired
A threat register for your next three engagements, with the safeguard for each
Open the brief
Take the next three engagements in your plan. For each, list every independence threat you can identify — including the ones you would normally not bother writing down — and the safeguard you would apply.
Where the safeguard is “none needed”, say why in one sentence. That sentence is the thing an external quality assessment will ask you for, and it is much easier to write now than in eighteen months.
What to produce
- One row per engagement per threat, not one row per engagement
- Threat type: self-review, self-interest, familiarity, advocacy
- The specific fact that creates it — names, dates, which piece of work
- The safeguard, and who would have to accept it
- Residual position: proceed, proceed with disclosure, or reassign
- Where you concluded no safeguard was needed, the one-sentence reason
- checkRequired
The one engagement you should not lead, and who should
Open the prompts
- Which engagement in your current plan should you personally not lead, and who in your function should?
- Name a piece of advisory work your function has taken on in the last two years that has since made an audit harder. What would you decide differently now?
- If your bonus or objectives are set wholly or partly by someone you audit, write down what that arrangement is. Not to change it today — to be able to describe it accurately when asked.
1.3The universe, before the plan
3.5h
A risk universe that is neither a process inventory nor an org chart — coverage, cyclical auditing, and the entity nobody has looked at in four years.
- learnRequired
An auditable universe is not a list of everything
Read the brief~2 min
Most risk universes are one of two things pretending to be a universe: a process inventory, which lists everything the organisation does at whatever level of detail somebody had time for, or an org chart with risk ratings on it, which audits departments rather than risks.
What an auditable universe has to be
- Complete at ITS level, not at every level. A universe of four hundred entities is a filing system; a universe of forty auditable units, each of which could be an engagement, is a plan waiting to happen.
- Composed of things you could actually audit. “Culture” is a risk and not an auditable unit. “The consequence management process” is both.
- Scored on something you can defend. Inherent risk, control maturity and time since last coverage will get you most of the way, and all three are arguable, which is the point — the committee should be able to disagree with your scoring.
- Owned. A universe that lives in one person's spreadsheet is re-derived from scratch every time that person is on leave.
The entity nobody has looked at in four years
Every universe has them, and they are rarely the risky ones — they are the ones that are hard to schedule, or whose sponsor is difficult, or which came in through an acquisition and never got mapped. The value of writing coverage dates into the universe is that it surfaces them without anyone having to make an accusation.
Scoring is a conversation, not an output
The number matters far less than the disagreements it produces. A universe you take to the executive and nobody argues with is a universe nobody read. Score it, take it round, and change it where someone tells you something you did not know — that is the actual mechanism by which the plan becomes risk-based.
Carry this into the drill
The drill is a general risk-rating piece rather than an audit one, and it is here for the calibration habit: the same scenarios rated by different people diverge more than anyone expects, which is exactly what happens to a universe scored by a team.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Which Is Riskier? — a calibration drill
Open the drillBorrowed from the control-risk path — a general risk-rating drill, not an audit-universe one. It is here because universe scoring fails the same way it does: two competent people rate the same thing differently and neither notices until the plan is challenged.
Ticks itself when the drill records a result
- applyRequired
Your risk universe on one page
Open the brief
Build or rebuild your risk universe on one page. Aim for somewhere between thirty and sixty auditable units — if you have more, you are inventorying processes; if fewer, your engagements will be too broad to conclude on.
Score each on inherent risk, control maturity and months since last coverage. Then look at what the scoring surfaced that you did not already know, because that is the only test of whether the exercise was worth doing.
What to produce
- Auditable units, at a level where each could be one engagement
- How you decided the level — stated, because it is the arguable part
- Inherent risk score, with the basis
- Control maturity, and where that assessment came from
- Months since last coverage, and by whom — including second line
- The three units the scoring surfaced that you would not have chosen
Week 2 of 6 · 10 hours · 3 modules
Planning, and the year you can defend
A plan is a set of refusals. This week is about making them deliberately, knowing what other assurance already covers, and bringing audit to the things the business is building right now.
Week 2 of 6 · 10 hours · 3 modules
Planning, and the year you can defend
A plan is a set of refusals. This week is about making them deliberately, knowing what other assurance already covers, and bringing audit to the things the business is building right now.
2.1The annual plan
4h
Risk-based planning against the universe, the difference between what is risky and what is auditable, and the plan a committee will actually approve.
- learnRequired
Every engagement in the plan displaced another one
Read the brief~2 min
A plan is a set of refusals. Twelve months of capacity divided by a universe of forty units means most of the universe is not audited this year, and the only interesting question about any plan is what it left out and why.
Risky is not the same as auditable
The highest inherent risk in most organisations is strategic — the market moves, the acquisition fails, the product does not land — and almost none of it is auditable in a way that produces a conclusion. A plan built purely on risk score will put those at the top and then quietly not do them. Better to screen the universe twice: once for risk, once for whether an engagement could conclude on anything, and be explicit that the second screen is why item one is not in the plan.
The four things every plan has to reserve for
- Mandatory coverage — whatever your sector obliges. Small, fixed, and it comes off the top.
- Follow-up. It is real work, it is not optional, and functions that leave it implicit find it consuming a quarter by October.
- Unplanned work. Something will happen. A plan with no contingency is a plan that gets abandoned in month five, which is worse than one that reserved fifteen per cent for it.
- Advisory, if you do any. Named, budgeted, and inside the independence position from week one.
The plan the committee will approve
Committees approve plans they can interrogate. That means showing the dropped engagements, not just the chosen ones — three lines on what you cut and what would have to change for it to come back. It converts the conversation from “why are you doing this” to “should we fund more of it”, which is a much better conversation to be having.
The engagement you kept for the wrong reason
Every plan has one: the audit that is in because it is always in, because the team likes it, because it is easy to staff, or because dropping it would upset someone. Naming it privately is the discipline; whether you actually cut it is a separate question with real politics in it.
Carry this into the drill
The simulation gives you a fixed budget and a universe that does not fit inside it. Notice what you protect under pressure — that is the actual revealed policy of your function.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Plan the Year — an audit-plan allocation sim
Open the drillWritten for annual audit planning and used here for exactly that. One of very few pieces in the catalogue that models the real constraint — finite days against an oversized universe — rather than asking what you would ideally do.
Ticks itself when the drill records a result
- applyRequired
A twelve-month plan with the three engagements you dropped, and why
Open the brief
Build a twelve-month plan from the universe you produced in week one. Show the reserves for mandatory work, follow-up, unplanned work and advisory before you allocate anything to engagements.
Then write the three engagements you dropped, and for each: what would have to change for it to come back into scope. That list is the most useful page in the pack.
What to produce
- Total capacity in days, honestly — net of leave, training and administration
- The four reserves, sized and justified
- Engagements, each with scope area, timing and days
- The linkage back to universe scores, so the committee can follow it
- Three dropped engagements, with the trigger that would restore each
- The one engagement you kept for a reason that is not risk
- checkRequired
The engagement you kept for the wrong reason
Open the prompts
- Which engagement is in your plan for a reason other than risk? Write the real reason down.
- If your capacity were cut by twenty per cent tomorrow, what comes out first — and does that match what your universe scoring says should?
- When did you last drop an audit that had been in the plan for three consecutive years, and what happened?
2.2Assurance mapping, and not auditing it twice
3h
Where second line already covers it, what their work is worth, and the combined assurance map that stops audit re-performing compliance's testing.
- learnRequired
Reliance is a decision with evidence behind it
Read the brief~2 min
Somebody else is already testing a great deal of what is in your universe. Compliance monitoring, quality assurance, second-line control testing, external audit, regulatory inspections, certification bodies — and in most organisations no one has ever laid them side by side.
What a combined assurance map is for
- Finding duplication, which is money — three functions testing the same control to different standards and none of them relying on the others.
- Finding gaps, which is the more valuable half. Risks everyone assumed somebody was covering usually turn out to be covered by the function least equipped to do it.
- Making reliance a decision with evidence behind it rather than an assumption. If you are going to place reliance, you should be able to say what you looked at.
Reliance is not trust
Placing reliance on second line's testing means forming a view on their competence, their objectivity relative to the process owner, and the quality of their working papers — and then documenting that view. It is genuinely less work than re-performing, but it is not no work, and a function that “relies” without ever having read a second-line working paper is not relying, it is assuming.
When not to rely, even though you could
Where the risk is severe enough that the committee would expect you to have looked yourself, reliance is technically defensible and practically wrong. Financial statement fraud is the standard example. Say so in the map rather than leaving it looking like an oversight.
Carry this into the drill
Both drills are optional here and they answer different questions. The evidence one is about whether you can rely on somebody else's work; the maturity assessment is about whether the second line producing it is any good.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playOptionalTicks itself
Rely or Reject — an evidence-reliability drill
Open the drillOptional, and borrowed from the control-risk path where it is required. The reliance decision is one module here rather than a theme, and the drill is squarely about audit evidence provenance — exactly the judgement this module asks for, if you want to practise it.
Ticks itself when the drill records a result
- playOptionalTicks itself
GRC Maturity Assessment
Open the drillOptional. A structured pass over how a GRC programme is actually run, useful here as a way of forming a view on the second line you are considering relying on — read it as an assessment of them rather than of you.
Ticks itself when the drill records a result
- applyRequired
An assurance map for one significant risk
Open the brief
Pick one significant risk and map every source of assurance over it: first-line controls and self-testing, second-line monitoring, internal audit, external audit, regulators, certification bodies.
Then state, for each source, whether you would place reliance on it and what you would need to see first. The gaps and the triples will both be visible on one page.
What to produce
- The risk, stated at a level where assurance can attach to it
- Every assurance source, with what each actually tests
- Frequency and last performance date for each
- Your reliance position for each, with the evidence you would need
- Gaps: what no one is testing
- Duplication: what more than two functions are testing
2.3Auditing what the business is building now
3h
Bringing audit to AI, automation and cloud without either rubber-stamping or blocking.
- learnRequired
The control you cannot test yet is still in scope
Read the brief~2 min
The uncomfortable position on AI, automation and cloud is that the business is deploying faster than any assurance function can build a methodology, and the two available responses are both bad. Rubber-stamp it because you do not understand it, or block it because you do not understand it.
What is actually new, and what is not
Most of it is not new. Change control, access, data quality, third-party dependency, and whether anyone can explain the decision — you have audited every one of those before. What is new is narrower than the noise suggests: the model that changes behaviour without a change ticket, the training data whose provenance nobody recorded, the output that is confident and wrong in a way a human reviewer stops checking after a fortnight, and the vendor who will not tell you what is inside.
Three questions that reach almost any use case
- What decision does this make or influence, and what happens to a person or a pound as a result? If nothing, the risk is reputational at most and you can scale the work accordingly.
- Who reviews the output, how would they know it was wrong, and what is their incentive to look? Automation bias is the control failure, and it is measurable.
- If it were switched off tomorrow, what would happen? That is the dependency question, and it is usually the one nobody has asked.
Auditing the gate, not the model
You are unlikely to be able to test a model. You can almost always test whether the organisation has a gate that use cases pass through, whether the gate has ever refused anything, and whether the ones it approved match what was actually built. A gate that has approved everything it has ever seen is a finding you can evidence without understanding a single line of the model.
Carry this into the drill
The simulation walks an AI system through an audit rather than asking you to evaluate the technology. The transferable part is the sequencing — what you ask for, and in what order.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Auditing the Machine
Open the drillBorrowed from the control-risk and privacy paths. It is an internal-audit piece by topic and it is here for the sequence of questions rather than the technology: what you request, what the answer tells you, and what you do when the vendor will not answer.
Ticks itself when the drill records a result
- applyRequired
An audit approach for one AI or automation use case in your organisation
Open the brief
Choose one AI or automation use case that is live or nearly live in your organisation. Write the audit approach: objectives, what you would test, what evidence you would ask for, and what you would do if it does not exist.
Include the scope limitation you expect to hit. Naming it in advance is what separates a scoping decision from an explanation at the close meeting.
What to produce
- The use case, and the decision it makes or influences
- Two or three objectives you could conclude on
- Evidence requests, in the order you would make them
- The human review control, and how you would test whether it operates
- The dependency position if it were unavailable
- The scope limitation you expect, and how you would report it
Week 3 of 6 · 10.5 hours · 3 modules
Scoping and evidence
The two places an engagement is won or lost before any testing happens: what you said you would conclude on, and whether what you collected could survive being challenged.
Week 3 of 6 · 10.5 hours · 3 modules
Scoping and evidence
The two places an engagement is won or lost before any testing happens: what you said you would conclude on, and whether what you collected could survive being challenged.
3.1Scoping the engagement
3.5h
Objectives before procedures, why a scope that covers everything tests nothing, and the objective you cannot evidence and should therefore not write.
- learnRequired
Write what you will conclude, not what you will do
Read the brief~2 min
An engagement is won or lost at scoping, and the losses are invisible for about six weeks. A scope that covers everything tests nothing; a scope written as procedures cannot be reported against; a scope containing the most important question in the business, which you cannot conclude on, will spend the budget and produce a caveat.
Objectives, not procedures
“Select twenty-five purchase orders and agree them to approvals” is a procedure. “Whether purchases above the delegated limit were approved by someone with authority” is an objective. The difference matters because a procedure cannot be argued with at scoping and cannot be concluded on at reporting — so it sails through the planning meeting and produces a report that describes what you did rather than what you found.
The test that keeps a scope honest
- Could I write the sentence I would put in the report if this objective passed? If not, the objective is not concludable.
- What evidence would have to exist, and does it? An objective whose evidence lives only in people's heads produces an opinion with interviews behind it, which is worth saying out loud before you commit to it.
- Is somebody else already covering this adequately? Coverage is coverage — re-performing it spends the days you needed elsewhere.
- Does this carry the risk, or is it just the part I can measure? This is the one that catches most scopes.
The question you cannot answer and should still write down
Value for money, culture, whether the team is adequately resourced — these come up in every engagement and none of them can carry an audit conclusion. The move is not to ignore them. It is to audit the process that should produce the outcome, evidence the consequences you can measure, and let the reader draw the inference themselves. A report that establishes turnaround times, retrospective PO rates and backlog has said something about resourcing without claiming to have concluded on it.
Scope limitations are a scoping output
If you already know you have no IT auditor and the portal security question needs one, that is a decision to make now — ask for the specialist, or exclude it and say so. Discovering it in week four means either a thin test that implies assurance you did not obtain, or a limitation paragraph that reads as an excuse.
Carry this into the drill
The drill puts thirteen candidate objectives in front of you for one procure-to-pay audit. The counted mistake is scoping in something you could never have evidenced — which always sounds like the most important item on the list.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Scope the Audit
Open the drillBuilt for this module. Scoping is normally taught as a template and learned by having a scope go wrong; the drill compresses that into thirteen decisions and counts the objectives you took on that no evidence could have supported.
Ticks itself when the drill records a result
- applyRequired
A scoping memo with three objectives and the two you rejected
Open the brief
Write a scoping memo for your next engagement: three objectives, each phrased so you could write the conclusion sentence today if it passed.
Then the part that matters — the two objectives you rejected, and why. One should be something you rejected as unconcludable, and you should say what you will do instead.
What to produce
- Background: why this engagement, and what changed since last time
- Three objectives, each concludable, each with the conclusion sentence drafted
- For each: the evidence that would have to exist, and whether it does
- Two rejected objectives, with the reason for each
- For the unconcludable one: what you will evidence instead
- Known scope limitations, and what you have asked for
- checkRequired
The objective you kept because it was easy to test
Open the prompts
- Look at your last completed engagement. Which objective was in scope because it was easy to test rather than because it carried the risk?
- When did you last decline to conclude on something and say so in the report? How did the committee react?
- Which of your standard scope templates contains a procedure masquerading as an objective?
3.2Sampling, and what a sample can carry
3.5h
Population, stratification and coverage — what a sample of twenty-five entitles you to say, and what it does not.
- learnRequired
The conclusion is bounded by the population, not the sample
Read the brief~2 min
Twenty-five is the most-used number in internal audit and the least-defended. It is a reasonable default for a moderate-assurance test over a large population of homogeneous items, and it becomes indefensible the moment any part of that sentence is untrue.
The population comes first, and it is where the errors are
Almost every sampling failure is a population failure. The export covers ninety days when the cycle is quarterly. The system list excludes manual journals. The extract was produced by the person under review and you never reconciled it to a control total. Whatever you conclude is a statement about the population you actually sampled from, not the one you meant to — and nobody reading the report will know the difference unless you say.
Stratify before you increase
- High-value or high-risk items tested separately, often exhaustively. Twelve payments over a million pounds should not be sampled, they should be looked at.
- The exception path tested as its own stratum. Emergency awards, manual overrides and out-of-hours changes behave nothing like the main population and are where controls are deliberately bypassed.
- The remainder sampled for the rate. This is where twenty-five belongs, and where it is defensible.
What a sample entitles you to say
Three exceptions in twenty-five is not “twelve per cent of transactions are wrong”. It is evidence that the control did not operate consistently, at a rate that warrants either extending the test or reporting the breakdown. The precision you are entitled to depends on how you selected — and if selection was judgemental, you are entitled to say the control failed in the cases you looked at and nothing about the rate at all.
When zero exceptions means nothing
A clean sample of twenty-five from a population where the control fails five per cent of the time comes up clean about twenty-eight per cent of the time. Zero exceptions is genuine evidence and it is not proof, and a report that says “no exceptions were noted” is more honest than one that says the control operated effectively.
Carry this into the drill
The drill is a risk-assessment and sampling piece: what to look at, what to skip, and what you are entitled to conclude from either.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Rate the Risk
Open the drillBorrowed from the control-risk path, where it was the only sampling piece in the catalogue. It belongs at least as much here — deciding what to test and what to leave is the sampling judgement, and it is the one this module is built on.
Ticks itself when the drill records a result
- applyRequired
A sampling approach for your next test, with the conclusion it would support
Open the brief
Design the sampling approach for your next substantive test. Define the population precisely enough that someone else could reproduce it, including how you will confirm it is complete.
Then write the conclusion the sample would support if it came back clean, and the one it would support at two exceptions. Both sentences, in advance.
What to produce
- The control and the assertion you are testing
- The population: source, period, and what it excludes
- How you will establish completeness — the reconciliation, not the assumption
- Strata, with the basis for each
- Selection method per stratum, and sample sizes with the reason
- The two conclusion sentences: clean, and two exceptions
3.3Evidence that survives being challenged
3.5h
Sufficiency, reliability, source and date — the screenshot from the person under review, and the control statement nobody wrote well enough to test.
- learnRequired
Evidence produced by the auditee is still evidence, and it is not the same evidence
Read the brief~2 min
Evidence has four properties worth arguing about: is there enough of it, is it reliable, where did it come from, and when. Working papers fail on the third and fourth far more often than the first two, and they fail silently, because a screenshot in a file looks exactly as authoritative as a system extract you reconciled.
Provenance changes what evidence is worth
- Generated by you, from the system, with the query recorded — the strongest thing available to an in-house function.
- Generated by the auditee at your request, reconciled by you to something independent. Fine, and the reconciliation is the evidence, not the extract.
- Generated by the auditee, unreconciled. Common, weak, and frequently the whole basis of a conclusion.
- Produced by the person whose work is under review, undated, as an image. This is not evidence of the control; it is evidence that someone said something.
Undated is the quiet killer
A screenshot of a current access list tells you about today. The control operated across a period. If the finding was that four people had administrator rights, and the evidence of remediation is a list showing four names, the document is consistent with nothing having happened at all — and it will be filed as evidence of closure unless somebody notices.
The control statement problem
You cannot test what nobody wrote down properly. “Management reviews the reconciliation” omits who, how often, against what, what they do when it does not agree, and what evidences that they looked. Six months later two people will have different views on whether the control failed, and both will be reading the same sentence. Rewriting control statements so a tester could execute them is not documentation hygiene, it is the precondition for testing anything.
The five things a testable statement contains
- Who performs it, by role rather than by name
- How often, and triggered by what
- What they compare against — the source of truth
- The threshold or criterion for an exception
- What happens when there is one, and what records that it happened
Carry this into the drill
The clinic gives you real control statements to rewrite. The counted mistake is shipping one as written — accepting a statement you could not have tested, which is how an engagement ends up concluding on the auditee's description of their own control.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Control Statement Clinic — make it testable
Open the drillBorrowed from the control-risk and privacy paths. Control design is common ground; read here from the tester's seat rather than the designer's — the question is not whether the statement is well-written but whether you could execute it without asking what it meant.
Ticks itself when the drill records a result
- applyRequired
Re-write three control statements from your last engagement so a tester could execute them
Open the brief
Take three control statements from your last engagement and rewrite them so a tester who has never met the process could execute them. Use the five elements: who, how often, against what, the exception criterion, and what records it.
For each, note what you actually tested last time and whether the rewritten statement would have changed the test.
What to produce
- Original statement, verbatim
- What is missing, against the five elements
- Rewritten statement
- The test that follows from it
- What you tested last time, and whether it matches
- For one of them: the evidence that would now be required, and whether it exists
Week 4 of 6 · 10 hours · 3 modules
Testing, and what you found
Into the estate: the IT controls an auditor without an IT background still has to reach, the change the business will not pause for you, and the point where an exception becomes a finding.
Week 4 of 6 · 10 hours · 3 modules
Testing, and what you found
Into the estate: the IT controls an auditor without an IT background still has to reach, the change the business will not pause for you, and the point where an exception becomes a finding.
4.1Testing IT general controls without an IT background
3h
Access, change and operations as an auditor sees them — what to ask for, and what the answer should look like.
- learnRequired
Three questions that reach any access control
Read the brief~2 min
Most in-house functions have more IT in their universe than IT auditors on the team, and the usual responses are to skip it or to outsource it. There is a third option, which is that the core of IT general controls is auditable by anyone who can ask a precise question and read the answer.
Three domains, and what each is really asking
- Access: does the right set of people have the right set of rights, and would you know if that changed? Provisioning, modification, removal, and periodic review.
- Change: does anything reach production without somebody with authority having agreed, and is there a record? Including the emergency path, which is where the answer is usually no.
- Operations: do the jobs that have to run, run — and does anyone find out when they do not? Backups, batch, monitoring, and whether the alert goes anywhere a human reads.
The questions that reach any access control
You do not need to know the system. You need: show me how someone gets access, show me the last ten people who got it and the approval for each, and show me the last person who left and when their access went. Three requests, and the gaps between the documented process and those ten cases are where the findings are.
The non-human identity nobody reviews
Service accounts, API keys, integration users and tokens are in scope of every access control policy and in almost no access review population. They outlive the people who created them, they frequently hold more privilege than any individual, and the leaver process does not touch them. Asking for the list of non-human identities and their owners is one question, and it produces a finding in most organisations.
Where a review becomes a rubber stamp
An access review that approves everything is not evidence the access was right; it is evidence that a reviewer clicked. The test is what the reviewer was given — if the pack is group identifiers with no descriptions, no owners and no last-use data, the control could not have operated as designed however diligent the person was, and that is a design finding rather than a performance one.
Carry this into the drill
The required drill puts twelve entitlement review rows in front of you. The third option — cannot judge — is right more often than anyone uses it, and the counted mistake is the approval on evidence that never reached the question.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Grant or Revoke — an access review drill
Open the drillWritten for the cyber path and used here as an audit test rather than an administration one. Access review is the single most commonly tested IT general control in internal audit, and the drill is about whether the evidence supports a decision — which is the auditor's question, not the reviewer's.
Ticks itself when the drill records a result
- playOptionalTicks itself
Who Can See This — a cloud exposure drill
Open the drillOptional, and the cloud and SaaS angle on the same question. Configuration grants access as surely as a group membership does, and it is usually outside the population an access review samples from. Worth it if your estate has meaningful SaaS.
Ticks itself when the drill records a result
- applyRequired
A walkthrough script for access provisioning on one system
Open the brief
Write a walkthrough script for access provisioning on one system: the questions in order, what document you expect at each step, and what you would do if it does not exist.
Then run it, on ten real cases. The script is the deliverable; what the ten cases showed is the reason it was worth writing.
What to produce
- The system, and why it is in scope
- The documented process, from the policy
- Ten questions in the order you would ask them
- The evidence expected at each step
- Ten real cases, with what was actually produced
- Non-human identities: the list, the owners, and the last review
4.2Auditing a change the business cannot pause
3.5h
Project and cutover assurance: pre-implementation review, the go/no-go you were not invited to, and the audit that arrives after the decision.
- learnRequired
Assurance before the decision is worth ten reports after it
Read the brief~2 min
Programme assurance is the part of the plan most functions under-serve, because the work is hardest exactly when it is most valuable and easiest when it is worthless. An audit that arrives after go-live can write an excellent report about decisions nobody can now change.
Three windows, and what each can do
- Before design freezes: you can influence controls, and you are closest to the independence line. This is where advisory work belongs, and where the week-one decision about what it costs you has to be made deliberately.
- Pre-implementation, before go/no-go: the highest-value assurance window in the whole engagement. Data migration integrity, cutover plan, rollback, access design, and whether the criteria for go-live are written down and measurable.
- Post-implementation: real, useful, and it cannot change the decision. Benefits, residual controls, and what the programme left behind.
The go/no-go you were not invited to
Being outside the decision is normal and is not itself a finding. What is a finding is a go/no-go with no written criteria, or with criteria that were not met and were waived by someone without the authority to waive them, or where the rollback plan says “restore from backup” and nobody has tested how long that takes. All three are auditable in advance and unarguable afterwards.
Data migration is where the money goes missing
Reconciliation of record counts and control totals before and after, the treatment of records that failed to migrate, and who signed that the result was complete. It is unglamorous and it is the single most common source of material error in a cutover, because everyone is watching the functionality.
The audit that has no way back
Ask early what happens if this goes wrong on day three. If the answer is that the legacy system is decommissioned on day one, you are auditing a programme with no rollback, and that fact belongs in front of the committee before go-live rather than in a post-implementation review.
Carry this into the drill
The simulation runs a real ERP cutover with the decisions in sequence. Play it from the assurance seat: at each point, ask what you would have wanted evidenced before that decision was taken.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
S/4HANA Cutover Sim
Open the drillAn ERP programme simulation, written for the delivery seat and played here from the assurance one. It is the only piece in the catalogue that models a cutover with its dependencies intact, and the transferable part is where the decision points are — not the SAP specifics.
Ticks itself when the drill records a result
- applyRequired
A pre-implementation review plan for a live programme in your organisation
Open the brief
Take a live or upcoming programme in your organisation and write the pre-implementation review plan: objectives, timing relative to go/no-go, and what you would need from the programme to do it.
Be specific about timing. “Before go-live” is not a date; a review that reports two days before the decision cannot change it.
What to produce
- The programme, its go-live date, and the go/no-go date
- Your reporting date, working backwards from when it could still matter
- Three or four objectives, weighted to migration and cutover
- Evidence requests, with lead times
- The rollback position, and what you would ask to see tested
- What you will do if the programme cannot give you what you asked for
4.3From exception to finding
3.5h
What an exception has to clear to become a finding, the finding that is really a design gap, and writing the condition before the cause.
- learnRequired
Condition, criteria, cause, effect — in that order
Read the brief~2 min
An exception is a fact about a case. A finding is a statement about a control. Turning one into the other is a judgement, and it is made badly in both directions — functions that raise every exception as a finding, and functions that quietly absorb exceptions until a pattern is undeniable.
Condition, criteria, cause, effect — and the order matters
Write the condition first: what you observed, factually, with the population and the rate. Then the criteria: what should have happened, and where that requirement comes from. Only then the cause, because writing it earlier means you will describe the condition in a way that fits the cause you already decided on. Effect last, because it depends on all three.
What an exception has to clear
- Is it actually a breach of a criterion, or of your expectation? The second one is a discussion, not a finding.
- Is it isolated or systematic? One instance with a plausible one-off explanation is different from three in twenty-five, and the report should say which.
- Is the control design at fault, or its operation? A control that cannot work as written fails differently from one that people did not perform, and the action is different.
- Does the effect reach anything? An exception with no plausible consequence is worth reporting as an observation and is not worth a finding rating.
Aggregation, and why SOX taught everyone this
Individually minor deficiencies in the same process, or affecting the same assertion, can aggregate into something worse than any of them. That logic was formalised in financial reporting and it applies everywhere: four small access weaknesses on one system are not four low findings, they are a statement about access management on that system. Reporting them separately is technically accurate and practically misleading.
The finding that is really a design gap
If your condition is that people did not do the thing, and your cause is that the thing is impossible to do in the time available or with the information given, then it is not a performance finding however you wrote the condition. Week five is about getting that right.
Carry this into the drill
Two drills here. The first is detail testing — tying reported numbers back to source, which is where most exceptions are actually found. The second is aggregation: several small deficiencies, and the judgement about what they add up to.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Tie-Out — a forensic deduction
Open the drillA forensic detail-testing game, used here for the step before the finding exists. Tying a reported figure back to source is the commonest way an exception surfaces, and it is a skill that degrades quickly once you stop doing fieldwork yourself.
Ticks itself when the drill records a result
- playRequiredTicks itself
The Material-Weakness Memo — SOX 404 disclosure sim
Open the drillA SOX 404 aggregation game, read here as issue severity rather than as financial reporting. The judgement it drills — when several individually minor deficiencies become one serious statement — is the same one this module is about, and it is the direct set-up for the rating work in week five.
Ticks itself when the drill records a result
- applyRequired
Three findings written to condition-criteria-cause-effect
Open the brief
Take three findings from your most recent engagement and rewrite them to condition, criteria, cause, effect — in that order, with the condition written before you decided the cause.
At least one of the three should turn out to be a design gap you had written as a performance failure. If none of them does, look again at the ones where the cause names a person.
What to produce
- Condition: what you observed, with population and rate
- Criteria: the requirement, and its source
- Cause: why it happened — not who
- Effect: what it exposes, stated in something the reader cares about
- Design or operation, decided explicitly
- For one: what changed when you wrote the condition first
- checkRequired
The exception you would previously have raised as a finding
Open the prompts
- Which exception would you previously have raised as a finding, and what does it look like now against the four tests?
- Look at your last report. Are there small findings on one process that should have been aggregated into one statement?
- Where in your last report did the cause name a person or a team? Rewrite that cause without naming anybody and see whether it still holds.
Week 5 of 6 · 10 hours · 3 modules
Cause, rating and the argument
The three things that decide whether a finding changes anything: why it happened, how badly it matters, and whether the person who has to fix it agrees.
Week 5 of 6 · 10 hours · 3 modules
Cause, rating and the argument
The three things that decide whether a finding changes anything: why it happened, how badly it matters, and whether the person who has to fix it agrees.
5.1Root cause, not proximate cause
3.5h
Why 'the reviewer did not check' is a symptom — capacity, incentive, design and awareness as cause families, and the action that fixes nothing.
- learnRequired
If a diligent person would have failed too, it is not the person
Read the brief~2 min
The commonest cause written in internal audit reports is a version of “the control was not performed”. It is true, it restates the condition, and the action that follows from it — remind people, retrain people, monitor people — has a success rate you can observe in your own follow-up register.
The test
Could a diligent, competent person have failed here anyway? If yes, the cause is not the person, and any action aimed at the person will close and recur. That single question does most of the work, and it is worth asking out loud in the close meeting because the process owner usually knows the answer.
Four families, and what each looks like
- Design — the control cannot work as built. The reviewer is given group identifiers with no descriptions; the procedure requires a callback and the system has no field to record one; the checklist omits the step entirely. Fix the mechanism.
- Capacity — there is not enough time or enough people. Forty reconciliations in two days; the post-mortem team is the firefighting team; volume doubled and headcount did not. Add time, remove work, or accept the risk knowingly.
- Incentive — doing it properly is penalised. Commission on booked date, approval measured on turnaround, exceptions granted by whoever is measured on ticket closure. Money and metrics win, always. Move the decision or change the measure.
- Awareness — nobody knew it was theirs. An unowned control, a distribution list three reorganisations out of date, a task introduced in one all-staff email. This is the only family where communication genuinely is the fix, which is precisely why it is over-diagnosed everywhere else.
Why awareness is the default, and why that is a problem
It produces the cheapest action to write, the easiest for management to accept, and the one nobody argues with in a close meeting. Training and communication are the path of least resistance for both sides. The cost appears eighteen months later as a repeat finding, and by then the connection to the original cause statement is invisible.
Stop before the cause becomes a personality
The other failure mode is going one step too far, past design and capacity into culture. “The organisation does not take controls seriously” may be true and it is not actionable, it cannot be evidenced, and it will make the report about the argument rather than the finding. The useful cause is the last one somebody could do something about.
Carry this into the drill
The drill gives you twelve findings, each carrying the operating detail that reveals the cause — the hours, the commission basis, the missing field. The counted mistake is reaching for awareness where the cause was structural.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Root or Symptom
Open the drillBuilt for this module. Root cause is normally taught as a technique — five whys, fishbone — and fails in practice at the point of classification, not technique. The drill supplies the operating detail and asks only for the family.
Ticks itself when the drill records a result
- applyRequired
Re-cause three of your closed findings
Open the brief
Take three findings you closed in the last two years and re-cause them using the four families. Use what you now know about whether the action held.
For each, write the action you would have agreed under the new cause, and compare it to the one you did agree.
What to produce
- The finding as originally written, with its stated cause
- The operating detail you had at the time that pointed elsewhere
- The cause family, on the new reading
- The action you agreed, and whether it held
- The action the new cause implies
- Which of the three would still have recurred either way — be honest, some do
- checkRequired
The action you agreed last year that did not hold
Open the prompts
- Which action you agreed last year did not hold? Go back to the cause statement and see whether it named a person.
- What proportion of the actions in your register are training, communication or reminders? That number is your awareness-default rate.
- Where have you stopped at a cause because the real one was politically expensive to write?
5.2Rating an issue consistently
3h
Severity by exposure rather than by irritation, the scale nobody applies the same way twice, and what inflation does to every other rating in the report.
- learnRequired
An inflated High is borrowed from every honest one
Read the brief~2 min
Ratings are the part of the report everyone reads and the part with the least methodology behind it. Most functions have a three or four-level scale, a definition of each level that sounds objective, and an actual practice of rating by how the finding feels in the room.
Inflation is directional and it compounds
Nobody under-rates. The pressure runs one way: a High gets attention, gets resourced and demonstrates that the audit found something. So the marginal finding drifts up, then the next one, and within two years the scale carries no information. The cost is not paid on the inflated finding — it is paid on the next genuinely serious one, which now looks like all the others.
Rate by exposure, and say what exposure means
- What could happen — the specific consequence, not a category.
- To what, and how much. Population size, value, duration and whether it is live.
- How likely, on evidence you have. Eighteen months of clean operation is real evidence about likelihood, and ignoring it because the design is wrong is how a Low becomes a High.
- What already reduces it. A tested compensating control is a fact. Ignoring it is as dishonest as ignoring the gap it compensates for.
The fourth option most scales do not have
Some findings cannot be rated on what you have. The policy gap whose consequences depend on data you have not asked for; the application holding personal data where nobody could say which fields or how many records. The absence of the answer is itself a finding, and it is also the reason you cannot size this one yet. Recording a Medium to have a number in the column is exactly how a rubric stops meaning anything.
A report with no Lows has inflated them
If every finding in your report is Medium or above, either your fieldwork only looks at serious things or your scale has drifted. Honest Lows are what make a reader believe your Highs, and they cost almost nothing to include.
Carry this into the drill
Fifteen findings to rate. Four of them cannot be rated on what you are given, and the fourth option exists to say so — the counted mistake is rating above what the evidence supports.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Rate the Issue
Open the drillBuilt for this module. A rating rubric is easy to write and hard to apply consistently; the drill is the application, and it includes the cases where the honest answer is that exposure has not been established.
Ticks itself when the drill records a result
- applyRequired
An issue-rating rubric with worked examples at each level
Open the brief
Write your function's issue-rating rubric with a worked example at each level — drawn from your own reports, not invented.
Include the rule for what happens when exposure cannot be established from what you have. If your current scale has no such rule, that is the most useful thing this exercise will produce.
What to produce
- Each level, defined by exposure rather than by adjectives
- A real worked example at each level, from your own reports
- The treatment of compensating controls, stated
- The treatment of likelihood evidence — clean operating history
- The rule for findings that cannot be rated yet
- Two findings from last year you would now rate differently, and why
5.3Agreeing it with the owner
3.5h
The negotiation where you hold the finding and they hold the context — what is negotiable, what is not, and management response as an owned commitment rather than a paragraph.
- learnRequired
The facts are not negotiable and almost everything else is
Read the brief~2 min
The close meeting is where a good engagement is most often damaged, in both directions: findings softened into meaninglessness to preserve a relationship, or defended so rigidly that the owner disengages and the action is written by you and owned by nobody.
What is negotiable, and what is not
- The facts are not negotiable. If the condition is wrong, it is not a negotiation, it is a correction, and you should want it.
- The criteria are not negotiable, though which criterion applies sometimes is — and that is a legitimate argument worth having before the report is drafted.
- The cause is genuinely negotiable, and the owner usually knows more than you do. Most of the real value in a close meeting is here.
- The rating is negotiable at the margin and should not be traded. If you move a rating to get an action agreed, you have sold the only thing that makes the rating mean anything.
- The action is theirs to write. Yours to test for whether it addresses the cause.
The owner is not the adversary
They hold context you do not: why the control was designed that way, what was tried before, what the constraint actually is. An auditor who arrives with the cause already fixed and the action already drafted gets compliance rather than agreement, and compliance closes on assertion twelve months later.
A management response is a commitment, not a paragraph
“Management acknowledges the finding and will review the process” is not an action. An action has a named owner who knows they own it, a date that somebody chose rather than defaulted to, and a description specific enough that both sides would agree afterwards whether it had been done. If you cannot picture the evidence that would close it, it is not written yet — which is next week's module in advance.
Disagreement is an outcome, not a failure
Sometimes management will not accept the finding or will accept the risk. That is their right, and the reporting line exists precisely for it. A clean escalation with both positions stated fairly is a better outcome than a watered-down finding both sides can live with, and functions that have never escalated anything are usually the ones doing the watering.
Carry this into the drill
The role-play runs the negotiation with an owner who has real context and real reasons. Watch what you concede and whether it was a fact, a cause or a rating.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Agree the Finding — an audit negotiation
Open the drillWritten as an internal audit negotiation and used here for exactly that — one of the few pieces in the catalogue that is native to this programme rather than borrowed into it.
Ticks itself when the drill records a result
- applyRequired
A management action for your hardest open finding, with owner and date
Open the brief
Take your hardest currently open finding and draft the management action you would want: named owner, date, and a description specific enough that you could both agree afterwards whether it was done.
Then write the evidence you would require to close it. If you cannot describe that evidence, the action is not specific enough yet.
What to produce
- The finding, with its cause as you now understand it
- The action, addressing the cause rather than the condition
- Named owner — a person, not a function
- Date, and who chose it
- The evidence that would close it, described in advance
- What you would do if the owner declines and accepts the risk
Week 6 of 6 · 9.5 hours · 3 modules
Reporting, follow-up and the committee
The year lands in one room, in front of people who have forty minutes and one hard question. Everything before this week is only worth what survives into it.
Week 6 of 6 · 9.5 hours · 3 modules
Reporting, follow-up and the committee
The year lands in one room, in front of people who have forty minutes and one hard question. Everything before this week is only worth what survives into it.
6.1Writing for the committee, not the auditee
3.5h
The report that is complete and unreadable, the summary that survives being the only page read, and what a non-executive needs in order to ask a good question.
- learnRequired
Write the half page first and let the report follow
Read the brief~2 min
Audit reports are written for the person who will argue with them and read by the person who will act on them, and those are different people. The auditee will read every word of the detail; the committee member will read the summary on a train, twenty minutes before the meeting, alongside eleven other papers.
Write the half page first
Not as a summary of a finished report — as the first thing you write, before the detail. If you cannot say what the engagement found in half a page, the fieldwork has not concluded yet, and discovering that while you still have the team is worth a great deal more than discovering it in review.
What a non-executive needs in order to ask a good question
- What you looked at, and what you did not — scope limitations belong near the top, not in an appendix.
- What you concluded, in a sentence that could be wrong. “Controls require improvement” cannot be wrong and therefore says nothing.
- The one thing that would change their view of the risk, if there is one.
- Whether this is new, or the same as last time. Repeat findings are the most important signal a committee gets about the control environment and they are routinely buried.
The complete and unreadable report
Length is a proxy for effort and it is read as a proxy for rigour, which is why reports grow. But a fourteen-page report with three findings in it has hidden the three findings, and the committee's attention is a fixed budget you are spending on their behalf. Detail belongs in an appendix the auditee will read and the committee will not.
Language that survives translation
Every term of art in an audit report is a place where a non-specialist reader can quietly form the wrong impression. Segregation of duties, compensating control, design effectiveness, material weakness — all precise to you, all approximate to them. Either define it in the sentence or use a plainer phrase; the report is not the place to defend the vocabulary.
Carry this into the drill
The piece is about getting useful, well-structured output from an AI tool in an audit context — and the discipline it drills, being precise about what you want and what good looks like, is the same discipline that produces a readable summary.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
The Prompt Lab — prompting for internal auditors
Open the drillAn AI prompting piece set in an internal audit context. Used here for a reason that is not about the technology: the skill it exercises — stating precisely what you want, in what shape, and what would make it wrong — is the same one that separates a half-page summary that works from one that does not.
Ticks itself when the drill records a result
- applyRequired
Rewrite one report summary to a half page
Open the brief
Take one of your recent reports and rewrite the executive summary to half a page, written for a non-executive who will read nothing else.
Then give both versions to someone outside audit and ask them one question: what should the committee do about this? If they cannot answer from the new one, it is not finished.
What to produce
- The conclusion, in a sentence that could be wrong
- Scope, and what you did not cover
- The two or three things that matter, with their ratings
- Whether any of it is a repeat
- The one thing that would change a reader's view of the risk
- What you want from the committee — noting, challenge, or a decision
6.2Follow-up that closes on evidence
3h
The action closed on assertion, the overdue register nobody looks at, and re-testing versus confirming.
- learnRequired
Ask what document would exist if this were really done
Read the brief~2 min
Follow-up is the least audited process in most audit functions. It runs on a spreadsheet, it is nobody's favourite work, and its failure mode is silent — a register showing everything green is indistinguishable from a register that is accurate.
The question that does all the work
What document would have to exist if this action were genuinely done? Ask it before you ask for evidence and it will tell you what to ask for. An action to update a procedure produces a procedure. An action to remove twelve accounts produces a before-list, an after-list, or a change record. An action to implement quarterly reviews produces review packs.
Four ways an action gets closed wrongly
- Closed on assertion — an email from the owner saying it is done. The commonest, and the easiest to fix, because the real evidence usually takes one minute to attach.
- Closed on partial completion — 340 of 380 managers trained is not ‘all managers’, and 89% feels enough like success that nobody pushes.
- Closed on evidence that cannot distinguish — a current admin list showing four names, where the finding said there were four. Consistent with nothing having happened.
- Closed on something else — management implemented dual approval at five times the agreed threshold. They did something, it is not what was agreed, and both closing quietly and carrying it forever lose information.
Close and raise, which most registers cannot express
When management deliberately does something different, the honest record is that the action is discharged and a new exposure exists. Same when a required test is performed and fails — the action was to test, they tested, and the failure is a new finding. Carrying the original open punishes the honesty of reporting a failed test, which is the last behaviour you want to discourage.
The overdue register nobody looks at
Past a certain age an overdue action stops being tracked and starts being furniture. Two practices help: report age rather than count, because thirty actions averaging four months old is a different message from thirty averaging three years; and make re-acceptance explicit — an action twice past its date goes back to the committee as a risk acceptance decision rather than sitting in amber forever.
Carry this into the drill
Twelve actions and the evidence actually offered for each. The counted mistake is closing on evidence that did not establish it — and one of the twelve is the case where management did something other than what was agreed.
Go deeper — with your own AICopy-paste prompt
The brief above is the spine. This is a full study prompt for whichever assistant you already use — it carries your programme, this module and what the brief just covered, so the lesson comes back tailored rather than generic. Pick how you want it, edit anything, then copy.
Yours to edit — changes stay in this box
- playRequiredTicks itself
Close or Carry
Open the drillBuilt for this module. Follow-up is where the value of a whole year's work is either realised or quietly lost, and the judgement — does this evidence establish that this action was done — is made dozens of times a year, usually at speed.
Ticks itself when the drill records a result
- applyRequired
A follow-up register with the three actions you would re-open
Open the brief
Take your current follow-up register and re-test the closure evidence on ten actions closed in the last twelve months. For each, ask what document would have to exist, and whether it does.
Name the three you would re-open. Then decide what you are actually going to do about them, because re-opening a closed action is a conversation with a senior person.
What to produce
- Ten closed actions, with the evidence held on file for each
- For each: the document that should exist if it were done
- Whether that document is what was accepted
- The three you would re-open, and why
- Any that should have been closed-and-raised
- One process change to your follow-up standard
- checkRequired
The action you closed on a verbal
Open the prompts
- Which action did you close on a verbal or an email? What would you have needed instead, and could you still get it?
- What is the average age of the overdue actions in your register, as opposed to the count?
- When did an action last go back to the committee as a risk acceptance rather than staying amber?
6.3Capstone — the committee session
3h
A year of work brought to a committee that has forty minutes and one hard question.
- applyRequired
Capstone: a committee pack — plan status, thematic findings, and the one risk you would escalate
Open the brief
Bring the six weeks together into one committee pack: where the plan stands, what the year's work says thematically rather than engagement by engagement, and the one risk you would escalate.
Write it for forty minutes and one hard question. Everything you have built — the universe, the plan, the rating rubric, the follow-up standard — exists to make this document defensible.
What to produce
- Plan status: delivered, in progress, dropped, and the reason for each drop
- Thematic view: what this year's findings say about the control environment as a whole
- Repeat findings, named as repeats
- Follow-up position, reported by age
- The one risk you would escalate, and what you want the committee to do
- Your own function: independence position, capacity, and what you need
- checkRequired
Sign-off against the six-week outcomes
Open the prompts
- Against the seven outcomes for this programme, which two are now genuinely part of how you work, and which two did you understand but not change anything for?
- What is the single change to your function you would make first, and what is stopping you?
- If your committee chair read your capstone pack and asked one hard question, what would it be — and can you answer it?
Finish it, and it is on the record
When every required step is done, a printable completion certificate appears on your profile — self-attested, honest about what it is, and yours to keep. Apply and Check steps are yours to mark; Play steps tick themselves when a drill records a result.
Open your profile