Guide · Internal Audit

Internal audit: planning, full-population testing, and continuous monitoring

Internal audit provides independent assurance over an organisation's risks and controls. This guide covers the annual process, risk-based planning, why full-population testing is replacing sampling, how auditors get and validate data, continuous control monitoring, and quality-assessment readiness.

What is the internal audit process?

Internal audit runs an annual cycle. It builds a risk-based plan from the audit universe and gets it approved by the audit committee. For each engagement it understands and documents the process, builds a risk and control matrix, designs and runs tests, dispositions the exceptions, and reports findings rated by risk with agreed management actions. It then tracks those actions to closure and reports ageing to the committee. A modern function also monitors key controls continuously between engagements.

What is risk-based audit planning?

Risk-based planning scores each auditable entity — processes, systems, locations, projects, third parties — on impact and likelihood, using enterprise risk data, prior findings, incident and loss data, regulatory change, management input, and data-driven risk indicators. The plan is mapped to the organisation's principal risks and to what the audit committee needs assurance on, resourced against available skills including data-analytics capability, approved by the committee, and revisited during the year as risks move.

Full-population testing vs sampling

Full-population testing runs each rule against every transaction. Sampling is designed to estimate the error rate in a routine process, which makes it a poor instrument for a deliberate, concealed, low-frequency issue that is likely to fall outside any sample.

The output is different too: sampling reports "the exception rate is within tolerance"; full-population testing produces a ranked list of specific items with reasons. Once the data pipeline exists, running the tests is cheap and repeatable, which is what makes continuous monitoring possible.

How auditors get and validate data

A repeatable model turns a one-off extract into a monitoring feed:

What is continuous control monitoring?

Continuous control monitoring runs defined checks on a cadence set per check — access and segregation-of-duties reviews might run daily, payment testing weekly, master-data monitoring on change. It alerts on new exceptions and on trend, because a rising exception rate matters as much as a single item. Every exception has an owner, a due date, and a recorded resolution, and the results feed back into risk assessment and the next plan. Typical checks by process cover procure-to-pay, order-to-cash, payroll, journal entries, access and segregation of duties, and master-data changes.

What is a QAIP?

A Quality Assurance and Improvement Programme covers ongoing monitoring of engagement quality, periodic internal self-assessment against the applicable internal audit standards, and an independent external quality assessment at least once every five years. Common non-conformances are no documented basis for the risk-based plan, weak workpaper support, follow-up not tracked, no periodic self-assessment, and competency gaps in data analytics.

Get the full Internal Audit Readiness Guide

An 8-page PDF: risk-based planning, engagement planning and the risk & control matrix, the five-step data-acquisition model, full-population test design by process, continuous control monitoring, working papers, reporting, QAIP readiness, and a printable pre-engagement checklist.

This guide is general information for professionals, not professional or legal advice. Requirements depend on your standards framework, sector, and jurisdiction.

© Livo Assistant · All guides · Internal Audit AI · Privacy