Table of Contents
Chapter 1 – Introduction to Internal Auditing1
| Introduction | 1 |
| The Audit Committee | 2 |
| Assurance Services | 3 |
| Advisory Services | 3 |
| Special Public Company Services | 3 |
| Independence and Objectivity | 4 |
| Work Scheduling | 4 |
| The Differences Between Accounting and Internal Auditing | 5 |
| The Institute of Internal Auditors | 5 |
| Code of Ethics | 6 |
| Internal Audit Career Path | 7 |
| Summary | 8 |
Chapter 2 - Governance10
| Introduction | 10 |
| The Governance Concept | 10 |
| The Role of Internal Auditing | 12 |
| Summary | 13 |
Chapter 3 – Risk Management15
| Introduction | 15 |
| Benefits of Risk Management | 15 |
| The Interrelationship between Risk and Strategy | 16 |
| Risk Retention Strategy | 16 |
| Risk Analysis as an Opportunity | 17 |
| Special Risk Situations | 18 |
| Risk Management for the Enterprise | 18 |
| The Chief Risk Officer | 19 |
| Risk Management Committee | 20 |
| Responsibility for Risk | 20 |
| The Role of Internal Auditing | 21 |
| Types of Risks | 22 |
| Special Risk Situations | 23 |
| The Risk Management Process Flow | 24 |
| Risk Rankings | 25 |
| Risk Quantification Issues | 27 |
| The Risk Profile | 28 |
| Risk Management Themes | 29 |
| Summary | 32 |
Chapter 4 – Business Processes34
| Introduction | 34 |
| Business Processes | 34 |
| The Need for Systems Documentation | 37 |
| Business Process Documentation Activities | 38 |
| Flowcharts | 38 |
| Business Process Diagrams | 41 |
| The Role of Internal Auditing | 42 |
| Summary | 43 |
Chapter 5 – Internal Controls45
| Introduction | 45 |
| The Proper Balance of Control Systems | 45 |
| Control Principles | 47 |
| The Failings of Internal Controls | 48 |
| Preventive and Detective Controls | 49 |
| Manual and Automated Controls | 49 |
| Constructing a System of Controls | 50 |
| Special Case – Employee Turnover | 50 |
| Special Case – Rapid Growth | 51 |
| Terminating Controls | 51 |
| The Role of Internal Auditing | 52 |
| Summary | 53 |
Chapter 6 – Information Technology Auditing55
| Introduction | 55 |
| The Purpose of IT Auditing | 55 |
| Special Auditor Skills | 56 |
| Business Advisory Audits | 56 |
| Project Ranking Process | 57 |
| Auditing IT Governance | 58 |
| Auditing Entity-Level Controls | 59 |
| Auditing Cybersecurity Programs | 60 |
| Auditing Data Centers | 62 |
| Auditing Networking Devices | 64 |
| Auditing Databases | 66 |
| Auditing Storage | 67 |
| Auditing End-User Computing Devices | 68 |
| Auditing Applications | 69 |
| Auditing Outsourced Operations | 70 |
| Summary | 72 |
Chapter 7 – Fraud Prevention and Detection74
| Introduction | 74 |
| What is Fraud? | 74 |
| Fraud Triggers | 75 |
| Perceived Pressure | 75 |
| Opportunity | 76 |
| Rationalization | 77 |
| Types of Fraud | 78 |
| Financial Statement Fraud | 78 |
| Embezzlement | 78 |
| Supplier Fraud | 78 |
| Customer Fraud | 79 |
| Common Fraud Risk Indicators | 79 |
| Cultural Adjustment Activities | 80 |
| Combat Perceived Pressure | 80 |
| Hire Correctly | 81 |
| Communicate Expectations | 81 |
| Provide an Example | 81 |
| Establish the Work Environment | 81 |
| Handle Fraud Situations Correctly | 82 |
| Engage in Fraud Auditing | 82 |
| Fraud Detection - Symptoms | 83 |
| Accounting Anomalies | 83 |
| Analytical Anomalies | 85 |
| Lifestyle Symptoms | 86 |
| Unusual Behavior | 87 |
| Fraud Detection - Assistance in Spotting Fraud | 87 |
| Assistance from Employees | 87 |
| The Employee Hotline | 87 |
| Assistance from Auditors | 88 |
| Fraud Investigative Techniques | 88 |
| Documentary Evidence | 90 |
| Personal Observation | 90 |
| Physical Evidence | 90 |
| The Role of Internal Auditing | 90 |
| Summary | 91 |
Chapter 8 – Internal Audit Management93
| Introduction | 93 |
| Organizational Positioning | 93 |
| Departmental Evaluation | 93 |
| Responsibilities of the Internal Audit Manager | 93 |
| Just-in-Time Audit Scheduling | 94 |
| Departmental Structure | 95 |
| Staffing Issues | 95 |
| Quality Assurance | 96 |
| The Internal Audit Library | 96 |
| Budget Issues | 97 |
| Internal Audit Metrics | 97 |
| Board Reporting | 98 |
| Summary | 98 |
Chapter 9 – Audit Evidence100
| Introduction | 100 |
| The Nature of Audit Evidence | 100 |
| Relevance and Reliability | 101 |
| Reasonable Assurance | 101 |
| Professional Skepticism | 101 |
| Audit Procedures | 102 |
| Inspection | 102 |
| Observation | 102 |
| Confirmation | 102 |
| Vouching | 103 |
| Recalculation | 103 |
| Reperformance | 103 |
| Inquiry | 103 |
| Analytical Procedures | 103 |
| Scanning | 104 |
| Analytical Procedure Case Study | 104 |
| Trend Analysis | 105 |
| Ratio Analysis | 105 |
| Reasonableness Test | 106 |
| Summary | 106 |
Chapter 10 - Internal Audit Working Papers108
| Introduction | 108 |
| The Experienced Auditor Standard | 108 |
| Documentation of Procedures and Evidence | 108 |
| Working Paper Preparation | 109 |
| Working Paper Reviews | 111 |
| Working Paper Best Practices | 111 |
| Summary | 112 |
Chapter 11 - Audit Sampling114
| Introduction | 114 |
| Statistical and Nonstatistical Sampling | 114 |
| Audit Risk and Sampling Risk | 115 |
| Tests of Controls Using Statistical Audit Sampling | 115 |
| Audit Sampling in Tests of Controls | 116 |
| Test Objectives | 116 |
| Deviation Conditions | 116 |
| Population | 116 |
| Sampling Unit | 117 |
| Method of Sample Selection | 117 |
| Sample Size | 119 |
| Tolerable Rate of Deviation | 119 |
| Effect of Population Size | 119 |
| Sampling Plan Performance | 120 |
| Reaching a Conclusion | 120 |
| Sequential Sampling | 120 |
| Summary | 121 |
Chapter 12 - Data Analytics123
| Introduction | 123 |
| Potential Uses of Data Analytics | 123 |
| Considerations When Selecting a Data Analytics Procedure | 124 |
| Data Access Concerns | 124 |
| Identification of Many Exceptions | 125 |
| Data Analytics Documentation | 125 |
| Conducting a Data Analytics Procedure | 126 |
| Case Study – Account Balances | 127 |
| Case Study – Discount Rates | 129 |
| Case Study – Revenue Process | 130 |
| Summary | 131 |
Chapter 13 - Conducting Internal Audit Engagements133
| Introduction | 133 |
| Types of Internal Audit Engagements | 133 |
| The Assurance Engagement Process | 133 |
| Engagement Scope Issues | 135 |
| Understanding the Auditee Issues | 136 |
| Plan Development Issues | 136 |
| Assurance Engagement Communication Issues | 137 |
| The Assurance Engagement Monitoring Function | 140 |
| The Consulting Engagement | 141 |
| Summary | 142 |
Answers to Chapter Questions144
Glossary155
Index158
Course Details
Author: Steven M. Bragg, CPA
Steven Bragg, CPA, has been the chief financial officer or controller of four companies, as well as a consulting manager at Ernst & Young. He received a master’s degree in finance from Bentley College, an MBA from Babson College, and a Bachelor’s degree in Economics from the University of Maine. He has been a two-time president of the Colorado Mountain Club, and is an avid alpine skier, mountain biker, and certified master diver. Mr. Bragg resides in Centennial, Colorado. He has written more than 300 books and courses, including New Controller Guidebook, GAAP Guidebook, and Payroll Management.
Publication/Revision Date: 7/24/2026
Course Exam Questions (online): 50 (multiple-choice)
Program Delivery Method: NASBA QAS Self-Study
Available Formats of Course Text: PDF or PDF plus printed copy sent in the mail
Course Level, Prerequisites, and Advance Preparation Requirements
| License | Course Level | Prerequisites | Advance Preparation Requirements |
|---|
| CPA | Overview | None | None |
* This program is appropriate for professionals at all organizational levels.
Sponsor ID Numbers
National Registry of CPE Sponsors ID: 107615
State CPA Board Sponsor ID Numbers (where applicable)
Florida Division of Certified Public Accounting: 0004761
Hawaii Board of Public Accountancy: 14003
New York State Board for Public Accountancy: 002146
Ohio Accountancy Board: CPE .51 PSR
Pennsylvania State Board of Accountancy: PX178025
Texas State Board of Public Accountancy: 009349
Learning Objectives
As a result of studying the course material, you should be able to meet the objectives listed below:
- Recognize the responsibilities and reporting relationships of the internal audit staff.
- Identify the components of the Institute of Internal Auditors' code of ethics.
- Specify the components of the three lines model.
- Identify the situations under which a business should and should not retain risk.
- Specify the characteristics of an enterprise risk management system.
- Recognize the members and responsibilities of the risk management committee.
- Recognize the information contained within a risk profile.
- Identify the characteristics of a "perfect storm" event.
- Identify the reasons why a firm's systems should be documented.
- Specify the different types of flowcharts and how they are used.
- Describe the circumstances under which weak controls may be acceptable.
- Recognize the methods used to quantify risk.
- Specify the characteristics of the different types of controls.
- Recognize the different types of control deficiencies.
- Identify the ranking criteria for IT audits.
- Identify the audit tests used to examine IT controls.
- Specify the reason for weaknesses in database security.
- Specify the reports associated with the controls of an IT vendor.
- Identify the various opportunities to commit fraud.
- Recognize the rationalizations for committing fraud.
- Specify the types of fraud encountered by a business.
- Specify the methods used to reduce the perceived pressure on employees.
- Recognize response options when an employee has committed fraud.
- Cite the indicators of fraud.
- Identify the various fraud investigation techniques.
- Specify the metrics that may be used to measure the internal audit department.
- Recognize the sources of audit evidence.
- Describe the relevance and reliability concepts.
- Identify the normal contents of audit working papers.
- Specify the characteristics of the different types of sampling.
- Recognize the issues associated with sampling units.
- Identify the conditions under which sampling variances are acceptable.
- Identify the characteristics of high-validity data.
- Specify the characteristics of the different types of deficiencies.