Internal audit methodology and internal audit testing: the sequence from criteria to evidence to finding

A methodology is what makes two different auditors reach roughly the same conclusion about the same process, and it is the difference between an audit function and a series of opinions. It does not need to be long. It needs to fix the order of the work, define what counts as evidence, and set out how a finding is written and graded. Without it, internal audit testing drifts toward whatever the auditor personally finds interesting, results are not comparable between cycles, and process owners learn to argue with the auditor rather than with the evidence, which is the point at which the audit function stops being useful.

The sequence, in the order it has to happen

Fix the criteria first: the exact clauses, procedures or requirements this audit judges against. Then map the process as it is described, so you know what should be happening. Then choose the sample, from the complete population, before you start looking at records. Then gather evidence by walking the process with the people who run it rather than by reading the folder. Then compare what you found against the criteria. Then write the findings. Doing any of these out of order, especially choosing a sample after seeing some records, quietly destroys the audit's independence.

What counts as evidence, and what does not

Evidence is something you observed, something you were shown, or a record you examined, and it is identifiable afterwards: a document with a reference and a date, a named person's statement, an observation with a time and a place. What is not evidence is an assurance that something normally happens, a screenshot with no context, or your own recollection. The test that keeps internal audit testing honest is whether another auditor could pick up your working paper and re-perform the test, and reach the same conclusion, without asking you anything.

Grading findings so the grade means something

Two or three grades is plenty, and each one needs a written definition that can be applied without judgement calls about how annoyed anybody is. A common split is a failure to meet a requirement at all, a failure of a control that operates but not reliably, and an observation which is not a failure but will become one. Fixing the definitions in the methodology is what stops grade inflation in a difficult year and grade deflation in an easy one, and it is what makes trends across cycles worth reading.

Sizing the testing before it starts

Methodology decides how the work is done; arithmetic decides whether it can be done at all. The volume is processes times requirements per process times samples per requirement, in minutes, plus interviews and write-up. Doing that arithmetic in advance is what turns a methodology from a document into a plan, and it is where most internal audit programmes are quietly unrealistic. The free internal audit template on this site works the figures through to hours per auditor and days, so the scope can be cut before the audit rather than during it.

Questions people ask about internal audit methodology

How long should an internal audit methodology document be?

A few pages. It has to fix the order of work, the definition of evidence, the sampling approach and the finding grades. Anything longer tends to be a restatement of the standard, which nobody reads twice.

What is internal audit testing, exactly?

It is the part of the audit where a sample of real records or observations is compared against the criteria. Everything before it is preparation and everything after it is reporting; the testing is the only part that produces evidence.

Do interviews count as audit evidence?

Yes, if they are recorded as statements from named people at a known time, and preferably corroborated by a record. An interview alone can establish what someone believes the process is; it cannot establish that the process ran.

Should the methodology change between audits?

The sequence and the definitions should not. The sampling depth and the criteria change every time, because they come from the audit plan and the risk ranking. A methodology that changes each cycle makes results incomparable, which defeats the purpose.

Sources

Related answers

Start Capanix ProKeep the findings, not the binder