What is Internal Auditing?
Internal auditing is an independent, objective assurance and consulting activity performed within an organization to evaluate and improve the effectiveness of its risk management, internal control, and governance processes. The IIA defines it as a function "designed to add value and improve an organization's operations."
The Internal Audit lifecycle
- Planning: risk-based identification of audit priorities; building the annual audit plan
- Fieldwork: testing controls, interviewing process owners, reviewing documentation and transaction data
- Findings: documenting control deficiencies, gaps, and exceptions with supporting evidence
- Reporting: communicating results to management and the audit committee with recommendations
- Follow-up: verifying that management has implemented corrective actions within agreed timelines
The risk-based approach
Modern internal auditing is risk-based — audit resources are directed toward areas of highest exposure, not distributed equally across all departments. This requires a robust risk assessment process that maps the audit universe and scores risks by likelihood and impact.
Internal Auditing vs. Internal Controls
Internal controls are the policies, procedures, and mechanisms management puts in place to manage risk. Internal auditing is the independent function that evaluates whether those controls are well designed and actually working. Management owns controls. Internal audit evaluates them.
Internal Auditing and Supervizor
Supervizor provides the analytics layer that transforms internal auditing from periodic, sample-based engagements to continuous monitoring that tests 100% of transactions and surfaces risk in real time — giving internal audit functions broader coverage and faster detection.
Related Supervizor pages
→ Internal audit framework — definition and components
→ Internal audit planning — step-by-step guide
