Skip to main content

    Internal Audit

    Internal and operational assurance for the processes that matter

    Add agreed operational reviews to the engagements your firm leads or the plan your internal audit team owns. We examine transactions, approvals and business controls, with professional procedures and traceable working files.

    Agree the coverage

    Start with a process, not a generic checklist.

    Select the areas that answer your engagement objectives. The scope can follow a transaction across teams or examine one control at a hand-off. It does not need to cover every cycle at once; agreed boundaries make the evidence requests and review responsibilities clearer.

    Revenue and receivables
    Trace selected transactions from the agreed revenue process through billing, adjustments and collection. Review approval of credit notes, customer master changes and AR reconciliations, distinguishing a timing difference from a missing control.
    Procurement, AP and vendors
    Follow purchase requests, supplier onboarding, purchase orders, receipt records and payment approval. Compare vendor changes with supporting authorisation and examine how duplicate invoices, bank-detail changes and unresolved AP items are handled.
    Payroll, time and expense
    Inspect selected payroll changes, timesheet approvals and expense claims against the organisation's rules. Review who can change employee records, approve their own submissions or override a payment check, and what evidence the reviewer sees.
    Close, journals and operational controls
    Review reconciliations, journal preparation and approval, close responsibilities and outstanding items. Assess segregation of duties across business processes, including compensating review where roles overlap. Agree any wider operational-control testing around the risks in your audit plan.

    From scope to review

    Analysis is preparation. People make the judgment.

    1. Define the process and the question

      Your team identifies the objective, period, entities and criteria. We agree the procedures, populations, evidence requests and escalation route before access is arranged. A walkthrough establishes how the control is intended to work and where records should exist.

    2. Prepare evidence, then perform procedures

      Professionals inspect records, interview process owners and perform agreed testing. RiskAssist™ supports evidence intake, control mapping, consistency checks and draft analysis, operated by our professionals. AI-assisted preparation is used only where agreed; incomplete exports and unexplained differences are raised rather than treated as reliable inputs.

    3. Review exceptions and document the limits

      A professional checks the working file before anything reaches the firm's reviewer. We distinguish control design, evidence of operation and unanswered questions. Workpapers record the source, procedure, result and review, with limitations where the evidence does not permit a conclusion. Your responsible reviewer decides how findings enter the engagement's reporting.

    Exceptions need context

    An unusual transaction is a question to examine.

    Where agreed, anomaly and fraud-risk reviews consider patterns such as repeated payment details, unusual journal timing, approval overrides or expenses outside policy. We agree the population, review rules and known business explanations with your responsible team. A flagged item is not proof of misconduct.

    Professionals follow selected exceptions back to records and ask for explanations through the agreed channel. Findings distinguish the observed fact, the control concern and what remains unresolved. Sensitive findings go to the responsible team using the escalation route agreed at the outset, not directly to people outside the engagement.

    This is not a forensic-accounting practice or litigation support. If a concern needs investigation beyond the agreed procedures, your responsible team determines the next step and the appropriately qualified support.

    Delivery responsibilities

    Your plan and reporting line stay in place.

    Co-source with an internal audit team to its methodology and reporting line, or agree delivery support for a firm-led engagement. Start with one process: establish the review criteria, file format, milestones and who resolves exceptions. Delivery personnel, qualifications, location and availability are agreed per engagement.

    AuditPartners is not a CPA firm or a certification body and does not issue audit opinions, SOC reports or certificates. The responsible firm or body retains engagement responsibility, professional judgment, review, report issuance and certification decisions.

    Co-delivery, white-label presentation, client protection and confidentiality are offered subject to the applicable agreement for each engagement.

    For enterprises arranging a direct internal audit or a framework gap assessment, agree the purpose and independence requirements separately from implementation work.

    Choose one operational process to review.

    Bring the objective, the period and your review expectations. We can discuss the procedures, evidence and professional capacity for an agreed pilot.