Internal Audit Process: Step-by-Step Guide
Table of Contents:-
The internal audit process is a structured approach used to evaluate an organisation’s internal controls, risks, compliance, governance and operational processes.
Although every internal audit engagement is different, most internal audits broadly follow four stages:
- Planning
- Fieldwork
- Reporting
- Follow-up
A well-designed internal audit process helps ensure that the audit remains focused on significant risks, obtains appropriate evidence, communicates meaningful observations and monitors implementation of corrective actions.
Companies looking for professional internal audit support can also refer to our Internal Audit Services in India.
What Is the Internal Audit Process?
The internal audit process refers to the sequence of activities followed by an internal auditor from the beginning of an audit engagement until closure of findings.
The process generally includes:
- Understanding the business and audit area
- Identifying risks
- Defining audit objectives and scope
- Preparing an audit plan and programme
- Performing fieldwork
- Testing transactions and controls
- Evaluating evidence
- Discussing observations with management
- Preparing the internal audit report
- Obtaining management responses
- Issuing the final report
- Following up corrective actions
The exact process may vary depending upon the organisation’s size, industry, risk profile, internal audit methodology and specific engagement objectives.
Why Is a Structured Internal Audit Process Important?
A structured process helps internal audit:
- focus on significant risks;
- define clear objectives;
- avoid unnecessary testing;
- maintain consistency;
- obtain adequate audit evidence;
- document work performed;
- communicate findings effectively;
- assign responsibility for corrective action;
- monitor unresolved observations; and
- improve governance and internal controls.
Without a structured methodology, internal audit may become a checklist exercise rather than a risk-focused assurance activity.
For a detailed operational checklist, see our Internal Audit Checklist for Companies in India.
Four Main Stages of the Internal Audit Process
The internal audit process can broadly be divided into:
Stage 1 – Planning
The auditor understands the business, objectives, risks, processes and controls and defines the scope of the audit.
Stage 2 – Fieldwork
The auditor performs walkthroughs, testing, interviews, observations and other procedures to obtain audit evidence.
Stage 3 – Audit Reporting
The auditor evaluates findings, discusses them with management and prepares the final internal audit report.
Stage 4 – Follow-Up
The auditor monitors whether management has implemented agreed corrective actions.
Each stage is explained below.
Stage One – Internal Audit Planning
Planning is one of the most important stages of the internal audit process.
An effective audit starts with a clear understanding of:
- why the audit is being conducted;
- what risks need to be evaluated;
- what processes will be covered;
- what period will be examined;
- which locations or entities are included; and
- what resources are required.
The planning stage ordinarily includes the following steps.
1. Understand the Business
The internal auditor should understand the organisation and the process being audited.
This may include:
- nature of business;
- organisational structure;
- business objectives;
- products and services;
- major customers;
- key suppliers;
- information systems;
- regulatory environment;
- financial significance;
- key personnel;
- operating locations; and
- major changes during the period.
The objective is to understand the context in which the audited process operates.
2. Understand the Process
The auditor should obtain an understanding of how the particular process works.
For example, for a procurement audit, the auditor may understand:
- purchase requisition;
- vendor selection;
- quotation process;
- purchase order;
- receipt of goods;
- invoice verification;
- payment approval; and
- vendor reconciliation.
This understanding may be obtained through:
- discussions;
- process walkthroughs;
- policies;
- SOPs;
- system demonstrations;
- organisation charts; and
- previous audit reports.
3. Identify Risks
The auditor should identify risks that may prevent the process from achieving its objectives.
For example, procurement risks may include:
- unauthorised purchases;
- excessive prices;
- related-party conflicts;
- duplicate payments;
- fictitious vendors;
- supply disruption; and
- poor-quality purchases.
The audit should then focus on evaluating controls designed to manage these risks.
For a detailed risk-focused approach, see our guide on Risk Based Internal Audit.
4. Define Audit Objectives
Audit objectives explain what the internal audit seeks to determine.
For example:
Procurement Audit Objective:
Evaluate whether procurement controls adequately manage risks relating to vendor selection, purchase approval, pricing, receipt of goods and payments.
A clearly defined objective prevents unnecessary or unfocused testing.
5. Define Audit Scope
The scope may specify:
- business process;
- legal entity;
- branch/location;
- audit period;
- systems;
- transactions; and
- exclusions.
For example:
Scope: Procurement transactions of the Delhi office for April 2026 to June 2026.
A clear scope helps avoid misunderstandings between the auditor and management.
6. Initial Communication or Audit Announcement
Management should ordinarily be informed about the commencement of the audit.
The communication may state:
- audit area;
- objective;
- scope;
- period;
- proposed timing;
- information required;
- key contact persons; and
- expected cooperation.
The precise formality of the communication depends upon the organisation’s internal audit framework.
7. Opening Meeting
An opening meeting may be conducted with management and process owners.
The meeting may cover:
- objectives;
- audit scope;
- process overview;
- known risks;
- major changes;
- previous findings;
- documentation requirements;
- timelines; and
- key personnel.
The meeting helps establish expectations and improves coordination.
8. Preliminary Survey
A preliminary survey helps the internal auditor obtain sufficient understanding before detailed testing begins.
This may involve reviewing:
- process documents;
- policies;
- previous audit reports;
- management reports;
- financial data;
- organisation structure;
- key contracts; and
- regulatory requirements.
The purpose is to identify significant risks and determine areas requiring detailed examination.
9. Internal Control Review
The auditor should identify and evaluate relevant controls.
Examples include:
- segregation of duties;
- approval matrix;
- maker-checker controls;
- reconciliations;
- physical controls;
- system access controls;
- management reviews;
- exception reporting; and
- automated controls.
The auditor should consider both:
Design effectiveness: Is the control capable of preventing or detecting the risk?
Operating effectiveness: Did the control actually operate as intended?
10. Prepare the Audit Programme
The audit programme sets out procedures to be performed.
It may include:
- walkthroughs;
- transaction testing;
- sample selection;
- analytical review;
- physical verification;
- interviews;
- system testing;
- confirmations; and
- document inspection.
The programme should be directly linked to the audit objectives and identified risks.
Stage Two – Internal Audit Fieldwork
Fieldwork is the stage where the auditor performs detailed audit procedures and gathers evidence.
The auditor should obtain sufficient and reliable evidence to support observations and conclusions.
11. Conduct Process Walkthroughs
Walkthroughs help confirm whether the documented process reflects actual practice.
The auditor may:
- observe the process;
- interview employees;
- review sample transactions;
- trace transactions through systems; and
- understand control points.
Walkthroughs can identify differences between written policies and actual operations.
12. Test Transactions
Transaction testing may involve examining selected transactions to determine whether controls have operated effectively.
For example:
Purchase testing may review:
- purchase requisition;
- quotation;
- approval;
- purchase order;
- goods receipt;
- invoice;
- GST;
- TDS; and
- payment.
Sales testing may review:
- sales order;
- credit approval;
- dispatch;
- invoice;
- GST;
- collection; and
- credit notes.
13. Select Audit Samples
Where testing the entire population is impractical, audit sampling may be used.
Sample selection should consider:
- risk;
- population size;
- transaction value;
- unusual items;
- expected errors;
- audit objective; and
- professional judgement.
For detailed guidance, see Sampling in Internal Audit.
High-risk or significant transactions may require 100% testing.
14. Perform Analytical Procedures
Analytical review can help identify unusual trends or exceptions.
Examples include:
- expense trends;
- gross margin changes;
- inventory turnover;
- debtor ageing;
- vendor concentration;
- duplicate payments;
- unusual journal entries;
- overtime trends;
- changes in credit notes; and
- monthly fluctuations.
Unusual results may require additional investigation.
15. Conduct Interviews and Discussions
Internal auditors frequently interact with:
- process owners;
- finance staff;
- operational employees;
- management;
- IT personnel;
- HR;
- compliance teams; and
- other stakeholders.
Discussions help understand processes and obtain explanations, but significant matters should ordinarily be supported by appropriate evidence.
16. Inspect Documentation
Documents may include:
- policies;
- approvals;
- invoices;
- contracts;
- bank records;
- system reports;
- reconciliations;
- legal documents;
- payroll records; and
- statutory filings.
The auditor should consider the reliability and completeness of evidence.
17. Perform Physical Verification
Where relevant, internal audit may verify:
- inventory;
- fixed assets;
- cash;
- security arrangements;
- warehouses;
- records; and
- operational controls.
Physical verification can provide evidence about existence and condition of assets.
18. Use Data Analytics
Modern internal audits may analyse full transaction populations using spreadsheets or specialised audit tools.
Data analytics may identify:
- duplicate invoices;
- duplicate payments;
- weekend or holiday transactions;
- payments below approval limits;
- unusual journal entries;
- round-value transactions;
- vendor bank changes;
- dormant vendors;
- abnormal credit notes; and
- other unusual patterns.
This can make fieldwork more targeted and risk-focused.
19. Identify Audit Exceptions
An exception occurs when actual practice differs from:
- policy;
- procedure;
- expected control;
- legal requirement;
- contract; or
- good governance practice.
The auditor should determine whether the exception is:
- isolated;
- recurring;
- systematic;
- financially significant;
- control-related;
- compliance-related; or
- indicative of fraud.
20. Determine Root Cause
A good internal audit observation should identify why the issue occurred.
Possible root causes include:
- inadequate policy;
- inadequate training;
- unclear responsibility;
- poor supervision;
- lack of segregation;
- system limitations;
- management override;
- insufficient resources; or
- ineffective monitoring.
Recommendations that address root causes are more likely to produce lasting improvement.
21. Discuss Findings During Fieldwork
Significant observations should normally be discussed with relevant management before finalisation.
This helps:
- verify facts;
- obtain explanations;
- identify missing evidence;
- understand root causes;
- avoid misunderstandings; and
- develop practical recommendations.
However, management disagreement should not prevent the auditor from reporting a properly supported finding.
22. Maintain Internal Audit Working Papers
Working papers should document:
- procedures performed;
- samples tested;
- evidence obtained;
- analysis;
- findings;
- management explanations; and
- conclusions.
Adequate documentation helps support the internal audit report and facilitates review.
ICAI publishes Standards on Internal Audit and related professional guidance through its Internal Audit & Assurance Standards Board.
Stage Three – Internal Audit Reporting
After completing fieldwork, the auditor evaluates findings and prepares the audit report.
The purpose of reporting is to communicate significant risks and control issues clearly and constructively.
23. Prepare an Audit Summary
Before drafting the report, the auditor may summarise:
- scope;
- work performed;
- major findings;
- risk implications;
- root causes;
- recommendations; and
- overall conclusions.
This helps ensure that significant matters are captured before reporting.
24. Prepare the Draft Internal Audit Report
A draft report may include:
- audit objective;
- scope;
- executive summary;
- observations;
- risk ratings;
- implications;
- root causes;
- recommendations;
- management responses;
- responsible persons; and
- target completion dates.
Observations should be clear, factual and supported by audit evidence.
25. Risk-Rate Audit Findings
Findings may be classified as:
- Critical;
- High;
- Medium; or
- Low.
The organisation should use clearly defined criteria for assigning ratings.
A high-risk issue may involve:
- significant financial exposure;
- fraud;
- regulatory violation;
- material control failure;
- cybersecurity risk; or
- serious governance weakness.
26. Conduct Closing or Exit Meeting
The draft observations may be discussed with management during an exit meeting.
The meeting may address:
- factual accuracy;
- root cause;
- risk implications;
- proposed recommendations;
- management response;
- responsible person; and
- implementation timeline.
The objective is not necessarily to obtain agreement on every finding, but to ensure that management understands the issue and has an opportunity to respond.
27. Obtain Management Response
Management responses should ideally specify:
- whether the finding is accepted;
- corrective action;
- responsible person;
- expected completion date; and
- explanation where management does not agree.
Management responsibility should be clearly distinguished from internal audit responsibility.
Internal audit identifies and evaluates issues; management is responsible for implementing corrective actions.
28. Issue the Final Internal Audit Report
After considering management responses and completing internal review, the final report may be issued to appropriate stakeholders.
Depending upon the organisation, recipients may include:
- process owner;
- senior management;
- CEO/CFO;
- Audit Committee; and
- Board of Directors.
Significant findings should be escalated to an appropriate level.
What Makes a Good Internal Audit Observation?
A strong observation commonly contains:
Condition
What was found?
Criteria
What should have happened?
Cause
Why did the issue occur?
Effect or Risk
What could happen because of the issue?
Recommendation
What corrective action should management consider?
For example:
Condition: Vendor bank details could be changed without independent approval.
Risk: Fraudulent bank details may be inserted, resulting in unauthorised payments.
Root Cause: No maker-checker control exists over vendor master changes.
Recommendation: Introduce independent approval and system logs for vendor bank-account changes.
This structure makes internal audit findings more useful to management.
Stage Four – Internal Audit Follow-Up
Follow-up is an essential part of the internal audit process.
The audit does not create value merely because a report has been issued. The organisation benefits when significant findings are appropriately resolved.
29. Maintain an Audit Action Tracker
The tracker may contain:
- audit report;
- observation;
- risk rating;
- agreed action;
- responsible person;
- due date;
- present status;
- evidence of implementation; and
- revised closure date.
This provides visibility over outstanding issues.
30. Perform Follow-Up Review
Internal audit may verify whether management actions have actually resolved the issue.
The auditor may:
- inspect supporting evidence;
- retest controls;
- perform sample testing;
- obtain system reports;
- conduct interviews; and
- verify implementation.
A management statement that an issue is “closed” should not automatically be treated as sufficient evidence.
31. Report Outstanding Findings
Overdue or unresolved findings may be periodically reported to senior management or the Audit Committee.
Special attention should be given to:
- critical findings;
- high-risk findings;
- repeated observations;
- long-overdue actions; and
- findings where management has accepted the risk.
32. Close Audit Findings
An observation should generally be closed only when adequate evidence demonstrates that corrective action has been implemented and the relevant risk has been appropriately addressed.
Where management consciously accepts the residual risk, such acceptance should follow the organisation’s governance process.
33. Report to the Audit Committee or Board
Periodic internal audit reporting may summarise:
- audits completed;
- major findings;
- overdue actions;
- recurring control weaknesses;
- emerging risks;
- management responses;
- status of the annual audit plan; and
- significant changes to audit scope.
This enables those charged with governance to monitor significant risks and internal control issues.
Internal Audit Process and Risk Based Internal Audit
The internal audit process should increasingly be risk-driven.
Instead of auditing processes merely because they were included in previous years’ audit plans, internal audit should consider:
- strategic risks;
- financial exposure;
- regulatory risk;
- fraud risk;
- cybersecurity;
- operational disruption;
- previous findings; and
- emerging risks.
A risk-based methodology helps allocate audit resources to matters of greater significance.
Read our detailed guide on Risk Based Internal Audit.
Internal Audit Process and Internal Audit Charter
The Internal Audit Charter provides the authority and framework under which the internal audit function operates.
The internal audit process describes how individual engagements are actually planned, conducted, reported and followed up.
The charter may define:
- mandate;
- authority;
- organisational position;
- independence;
- reporting relationships;
- scope; and
- responsibilities.
Read more in our Internal Audit Activity Charter Guide.
Internal Audit Process and Audit Documentation
Documentation should support every stage of the internal audit process.
Typical internal audit documentation may include:
- engagement communication;
- risk assessment;
- scope;
- audit programme;
- control matrix;
- walkthroughs;
- sample selection;
- working papers;
- audit evidence;
- draft observations;
- management responses;
- final report; and
- follow-up records.
Adequate documentation supports audit quality, supervision and consistency.
Internal Audit Process for Foreign-Owned Companies in India
The internal audit process may require additional focus for foreign-owned Indian subsidiaries.
Possible areas include:
- group policies;
- delegation of authority;
- inter-company transactions;
- transfer pricing;
- FEMA compliance;
- overseas payments;
- related-party transactions;
- GST and TDS;
- group reporting;
- cybersecurity;
- local statutory compliance; and
- reconciliation between local and overseas reporting systems.
Internal audit can help overseas headquarters obtain greater assurance regarding the Indian subsidiary’s processes, compliance and internal controls.
Role of Management in the Internal Audit Process
Management plays an important role by:
- providing information;
- explaining processes;
- identifying risks;
- responding to findings;
- implementing corrective action; and
- monitoring operational controls.
However, management remains responsible for operating the business and internal controls.
Internal audit must maintain appropriate independence and objectivity while working constructively with management.
Role of the Internal Auditor
The internal auditor is responsible for:
- planning audit work;
- evaluating risks and controls;
- obtaining appropriate evidence;
- exercising professional judgement;
- documenting procedures;
- communicating findings;
- making practical recommendations; and
- monitoring agreed corrective actions.
The internal auditor should not assume management responsibility for the activities being audited.
Frequently Asked Questions
What are the main stages of the internal audit process?
The four broad stages are planning, fieldwork, reporting and follow-up.
What happens during internal audit planning?
The auditor understands the business and process, identifies risks, defines objectives and scope, reviews controls and prepares the audit programme.
What is internal audit fieldwork?
Fieldwork is the stage in which the auditor performs audit procedures such as walkthroughs, transaction testing, sampling, interviews, analytical review and physical verification.
What is included in an internal audit report?
The report may include audit scope, observations, risk implications, root causes, recommendations, management responses, responsible persons and implementation dates.
Why is follow-up important?
Follow-up verifies whether management has implemented agreed corrective actions and whether significant risks have been appropriately addressed.
Is an internal audit process the same for every company?
No. The broad stages may be similar, but audit scope, procedures, frequency and reporting depend on the organisation’s size, industry, risks and objectives.
What is the difference between internal audit process and internal audit checklist?
The internal audit process describes how the audit is conducted from planning to follow-up. An internal audit checklist identifies specific areas and controls that may be examined.
See our Internal Audit Checklist for Companies in India.
Does internal audit always require sampling?
No. Depending upon the risk and population, auditors may use sampling, data analytics, full-population testing or other procedures.
Read our guide on Sampling in Internal Audit.
Who receives the internal audit report?
Depending upon the organisation, the report may be provided to process owners, senior management, the Audit Committee or the Board.
Can the internal audit process be outsourced?
Yes, subject to applicable requirements and the organisation’s circumstances, internal audit may be performed by internal personnel or outsourced professionals.
For professional assistance, see our Internal Audit Services in India.
Internal Audit Services in India
EzyBiz India Consulting LLP assists Indian and foreign-owned companies with internal audit, risk assessment, internal control reviews, process audits and compliance reviews.
Our internal audit approach covers planning, risk assessment, transaction testing, internal control evaluation, reporting and follow-up of significant observations.
For professional assistance, visit our Internal Audit Services in India or explore our broader Audit and Assurance Services in India.
Related Services
- Internal Audit Services in India
- Internal Audit Checklist for Companies in India
- Risk Based Internal Audit
- Sampling in Internal Audit
- Internal Audit Activity Charter
- Audit and Assurance Services in India
Authoritative References
- ICAI – Internal Audit & Assurance Standards Board
- ICAI – Compendium of Standards on Internal Audit
- The Institute of Internal Auditors – Global Internal Audit Standards
Prepared By: EzyBiz India Consulting LLP
Reviewed By: Anil Agrawal, Chartered Accountant
Last Updated: August 2026
Disclaimer
The information provided on this page is for general informational and educational purposes only and should not be construed as audit, accounting, legal or regulatory advice. The scope, procedures, frequency and documentation of internal audit depend upon the nature, size, industry, risk profile, internal controls and specific circumstances of each organisation. Professional judgement should be applied while designing and conducting internal audit engagements, and appropriate professional advice should be obtained based on the facts and circumstances of each case.
