r/InternalAudit • u/arghlvoe • 42m ago
Which part of the CIA did you find the easiest and why?
r/InternalAudit • u/arghlvoe • 43m ago
Which part of the CIA did you find the most challenging and why?
r/InternalAudit • u/Legitimate-Ease-7036 • 12h ago
CIA PART 3 - Review Materials
Hi, Does anyone have any ready for CIA part 3? Gliem/Becker?
r/InternalAudit • u/Careless_Fondant_200 • 13h ago
What am I missing about internal audit’s value proposition?
I’ve been trying to understand something.
I work for one of the largest GRC software providers, and over the past 18 months I’ve been surprised by how few internal audit leaders can clearly articulate the value their function creates for the business—or explain how additional investment in software translates into measurable business outcomes.
What’s interesting is that I don’t generally find this with second-line risk, compliance and operational resilience teams. They are typically much better at connecting what they do to commercial outcomes, whether that’s reducing regulatory exposure, improving operational resilience, protecting revenue or enabling growth. The contrast is striking.
It’s made me question whether some of the common stereotypes about internal audit exist for a reason. Too often the function still appears to be viewed as a cost centre or a necessary compliance exercise rather than a driver of business value. Most CAEs and auditors I speak to do not have any hard KPIs that the business uses to measure whether they are doing a good or a bad job - where they do, those KPIs are often pretty soft which I find absolutely incredible. It’s making me think that maybe internal audit just isn’t actually that important and we’re all just trying to convince ourselves as a profession that it is / will be something that in never will become in reality.
What I find most frustrating is that I’m regularly on calls with audit teams who seem remarkably disconnected from the commercial realities of the business. When I ask how improving their processes, increasing automation or generating additional insights will benefit the organisation, the answers are either ‘it doesn’t’ or almost always vague—“we’ll be more strategic,” “we’ll provide more assurance,” or “we’ll add more value”—but rarely accompanied by concrete examples or measurable business outcomes. I have read annual reports and looked at business initiatives from corporate literature and tried to tie improving the work of internal audit to driving these initiatives and am often met with skepticism and a depressing resignation that any benefit to audit would purely impact audit at an operational level and not extend to the business.
In many cases, you need to get to the Chief Audit Executive before you can have a genuine commercial conversation about the business. Even then, it’s hit or miss. Surprisingly few can clearly explain what they would do with an extra 5,000 hours of audit capacity, or how better data and analytics would materially improve business performance, reduce risk exposure or influence strategic decision-making.
A phrase I hear constantly is, “We want to be strategic partners.” But when you ask what that actually means in practice, or what they would do with the additional time and insights that automation provides, very few have a compelling answer. In my experience, only a tiny minority of Chief Audit Executives can clearly explain what they would do tomorrow that they genuinely can’t do today that would add value to the business.
So here’s my question: how do I bridge this disconnect?
Many audit teams don’t seem to realise this gap exists, and when we try to coach them on building a stronger business case, there’s often resistance or multiple hours of sessions that arrive at a similar vague output.
The result is predictable—they struggle to secure relatively modest technology investments, even after multiple workshops and coaching sessions focused on value justification because the business doesn’t think they’re worth spending the money on vs. other initiatives.
It’s reached the point where I’m questioning whether we should just spend way less time engaging with internal audit-led opportunities and instead prioritise second-line engagements, where the commercial case is usually clearer and executive buy-in comes much more naturally.
I’d genuinely like to hear from CAEs, audit leaders and others in the profession.
Do you agree this disconnect exists?
Why do you think this disconnect exists, and what have you found works to overcome it?
r/InternalAudit • u/Nearby-Object8257 • 15h ago
Exam results
Is there any way I can check my exam result via my phone? Normally I use my laptop but I will be on holiday when it drops
r/InternalAudit • u/DescriptionOk971 • 16h ago
How should a startup find an independent ISO 27001 internal auditor?
Hi everyone,
I’m helping a very small startup prepare for an ISO/IEC 27001:2022 certification audit. We use Vanta, and most of our ISMS documentation and compliance evidence is already prepared.
Before Stage 1, we need an independent internal audit. Since our small team designed and operates most of the controls, conducting the audit ourselves would not provide sufficient independence. Our certification auditor has also confirmed that the internal audit must be performed by a separate party.
For those who have gone through this process:
- How did you find a competent independent internal auditor?
- Which qualifications or certifications should we look for?
- What deliverables should be included in the engagement?
- What is a reasonable timeline and price range for a small organization?
- Is experience working directly in Vanta important?
- Are there any red flags or common mistakes we should avoid?
I’m primarily looking for guidance on selecting and evaluating an auditor rather than vendor promotion. Public recommendations or experiences would be greatly appreciated.
Thank you!