top of page
Search

Internal Auditing 101: How New Auditors Can Communicate Better, Get to the Facts, and Overcome Competence Gaps

The New Auditor’s Biggest Challenges Are Not Usually the Audit Checklist

New internal auditors are frequently trained first on procedures:

  • How to complete a workpaper

  • How to select a sample

  • How to document a walkthrough

  • How to test an approval

  • How to write an exception


Those procedures matter. But they are rarely the hardest part of becoming an effective auditor.


The new auditor’s most difficult challenges are usually more fundamental:

  1. Communicating effectively with audit clients

  2. Getting beyond explanations and reaching the facts

  3. Performing credibly while still developing professional competence


A new auditor may understand the audit program and still struggle during an interview.


The auditor may recognize a missing approval but fail to understand the control failure behind it. The auditor may obtain a management explanation and treat it as evidence.


The auditor may discover a process outside their experience and hesitate to ask questions because they do not want to appear unqualified.


These are not minor developmental problems.


They affect the quality of the risk assessment, the evidence obtained, the findings developed, and the credibility of the entire Internal Audit function.

Corporate Compliance Seminars’ Internal Auditing 101: Basic Training for Auditors directly addresses these challenges. The live, interactive course covers interpersonal and team-building skills, audit risk assessment, fieldwork, internal-control evaluation, evidence gathering, audit communication, interviewing, S.P.I.N. questioning, active listening, workpaper preparation, exit meetings, and rapport building.


The next program is scheduled for Wednesday and Thursday, September 30–October 1, 2026, and provides 8 NASBA-approved CPE credits in Auditing.


Challenge One: Communicating Without Damaging the Audit Relationship

Internal auditing is a communication-intensive profession.


Auditors must communicate with:

  • Executives

  • Process owners

  • Supervisors

  • Employees

  • Information technology personnel

  • Compliance officers

  • External auditors

  • Audit Committee members


Every one of those individuals may view the audit differently.


Some see Internal Audit as a source of independent assurance.


Others see it as:

  • A disruption

  • A compliance exercise

  • A search for mistakes

  • A threat to their reputation

  • A challenge to their authority

  • Additional work added to an already full schedule


The new auditor enters this environment without the organizational history, authority, or credibility of a more experienced professional.


That creates a practical problem:

The auditor must obtain cooperation from people who may be defensive, skeptical, or significantly more experienced in the process being reviewed.

The CCS Internal Auditing 101 program treats communication as part of audit methodology—not as an optional soft skill. Its learning objectives include interpersonal skills and the audit communication process, while the fieldwork agenda covers interviewing, S.P.I.N. questioning, active listening, exit meetings, and rapport building.


The New Auditor Must Learn the Difference Between Authority and Influence

Internal auditors often have broad access rights, but access authority does not automatically create cooperation.


An auditor can demand a report.


That does not mean the auditor will receive:

  • A complete explanation

  • Timely assistance

  • Candid discussion of problems

  • Information about informal workarounds

  • Insight into management concerns


The effective auditor learns to influence through:

  • Preparation

  • Professionalism

  • Respect

  • Clear explanations

  • Relevant questions

  • Consistent follow-through

  • Fair evaluation of evidence


A new auditor who relies too heavily on formal authority may create resistance.


A new auditor who avoids difficult questions to preserve the relationship may fail to complete the audit.


Professional communication requires both courtesy and persistence.


Explain the Purpose Before Requesting the Evidence

Audit clients are more cooperative when they understand why information is being requested.


Compare these two approaches.


Weak request

Send me the vendor-change report and ten supporting documents by Friday.

Stronger request

We are evaluating whether vendor banking changes are independently authenticated before payments are released. Please provide the complete vendor-change report for the audit period and the supporting evidence for the selected transactions.

The stronger request explains:

  • The audit objective

  • The risk being evaluated

  • Why the report is needed

  • Why supporting evidence is required


This reduces the impression that Internal Audit is requesting documents without understanding the process.


Neutral Questions Produce Better Information

New auditors sometimes unintentionally accuse the client while trying to obtain facts.


For example:

Why did you fail to follow the policy?

That question assumes:

  • The policy applied.

  • The individual was responsible.

  • The procedure was not performed.

  • No compensating control existed.

  • The failure was personal.


A better question is:

Walk me through how this transaction was processed and identify any steps that differed from the documented procedure.

The second question remains direct, but it allows the auditor to understand the circumstances before reaching a conclusion.


Other useful neutral phrases include:

  • “Help me understand how this process normally operates.”

  • “What happens when the assigned reviewer is unavailable?”

  • “Which evidence demonstrates that the review occurred?”

  • “How are exceptions escalated?”

  • “What changed during the audit period?”

  • “What would prevent this control from operating consistently?”


Neutral language does not weaken professional skepticism.


It improves evidence gathering.


Active Listening Is More Than Remaining Quiet

A new auditor may be so focused on asking the prepared questions that they fail to listen to the answers.


Active listening requires the auditor to:

  • Allow the client to complete the response.

  • Identify vague or incomplete statements.

  • Restate important information.

  • Ask logical follow-up questions.

  • Recognize contradictions.

  • Separate factual statements from opinions.

  • Determine what evidence should exist.


Suppose the client says:

We normally perform an independent callback before changing vendor bank information.

The word normally should immediately trigger additional questions:

  • What circumstances allow the callback to be skipped?

  • Who authorizes an exception?

  • Where is the callback documented?

  • Which telephone number is used?

  • Is that number obtained independently?

  • How does management monitor compliance?

  • Can you show me the most recent completed callback?


Internal Auditing 101 includes active listening and effective questioning as core fieldwork skills because interviews are not simply conversations. They are evidence-gathering procedures.


Using S.P.I.N. to Improve Audit Interviews

The course introduces the S.P.I.N. questioning methodology, which gives new auditors a practical structure for conducting interviews.


Situation Questions

Situation questions establish how the process works.


Examples:

  • Who performs the control?

  • Which systems are used?

  • How often is the report prepared?

  • Who approves an exception?

  • What changed during the year?


These questions create the factual foundation.


Problem Questions

Problem questions identify difficulties and weaknesses.


Examples:

  • Which steps create the most delays?

  • Where are responsibilities unclear?

  • Which controls are most difficult to perform?

  • What exceptions occur repeatedly?

  • Where does actual practice differ from written procedure?


These questions identify possible breakdowns.


Implication Questions

Implication questions explore why the problem matters.


Examples:

  • What happens when the reconciliation is late?

  • Could an unauthorized transaction remain undetected?

  • How could this affect financial reporting?

  • What regulatory exposure could result?

  • Could the problem exist in other locations?


These questions connect the process weakness to organizational risk.


Need Questions

Need questions focus on improvement.


Examples:

  • What information would help management identify exceptions sooner?

  • How would automated monitoring improve oversight?

  • Which corrective action would reduce the risk most quickly?

  • What resources would be required to sustain the improved process?


This approach helps the new auditor move beyond a checklist and conduct a purposeful audit interview.


Challenge Two: Getting to the Facts

Internal auditors work in an environment filled with explanations, interpretations, opinions, and assumptions.


The auditor’s responsibility is to determine what the evidence supports.

That sounds straightforward. In practice, it is one of the hardest professional skills to develop.


New auditors may hear statements such as:

  • “We have always done it this way.”

  • “The system would not allow an error.”

  • “The manager reviews everything.”

  • “That was an isolated event.”

  • “The amount was not material.”

  • “The external auditor never questioned it.”

  • “No one has ever complained.”

  • “The employee knows the procedure.”


None of these statements proves that the control operated effectively.


They may be relevant explanations. They are not automatically audit evidence.


Inquiry Is Evidence, but It Is Usually Not Enough

Interviews help auditors understand:

  • The process

  • Responsibilities

  • Control design

  • Expected evidence

  • Known problems

  • Recent changes


But inquiry alone often provides limited assurance about operating effectiveness.


If a manager states that monthly reconciliations are reviewed, the auditor should determine:

  • Which reconciliations?

  • Who prepares them?

  • Who reviews them?

  • What does the reviewer examine?

  • What threshold triggers follow-up?

  • How is review documented?

  • What happens to unresolved differences?

  • Did the review occur throughout the period?


The CCS course teaches participants to evaluate and document internal controls, gather audit evidence, test controls, consider sample size, and prepare reviewable workpapers.


The new auditor must learn a critical distinction:

What the client says happens is the starting point. What the evidence demonstrates happened is the audit conclusion.

Separate Facts, Criteria, and Conclusions

A disciplined auditor separates three different elements.


Fact

What did the auditor observe?

Five of the 30 sampled vendor changes did not contain evidence of an independent callback.

Criteria

What should have occurred?

The vendor-maintenance procedure requires independent verification before banking information is changed.

Conclusion

What does the evidence mean?

The verification control did not operate consistently during the audit period, increasing the risk that fraudulent banking changes could be processed.

New auditors often move too quickly from an isolated exception to a broad conclusion.


Others do the opposite: they document the exception but avoid stating what it means.


Internal Auditing 101 connects fieldwork, audit evidence, testing, exceptions, findings, and reporting so participants understand how conclusions develop from facts.


Ask for the Evidence That Should Exist

A useful audit question is:

What evidence would demonstrate that this control was performed?

That question forces the process owner and auditor to distinguish between an intended control and an evidenced control.


Possible evidence may include:

  • Approval records

  • System logs

  • Reconciliations

  • Exception reports

  • Review notes

  • Meeting minutes

  • Electronic workflow history

  • Access-change tickets

  • Confirmation records

  • Data-analysis results


When no evidence exists, several possibilities must be considered:

  1. The control was not performed.

  2. The control was performed but not documented.

  3. The evidence was not retained.

  4. The documented control does not reflect actual practice.

  5. Another control may address the risk.


The auditor should not automatically choose the most favorable—or most critical—explanation.


The auditor should investigate.


Follow the Transaction Through the Process

Walkthroughs are one of the most effective ways for new auditors to move from policy to fact.


During a walkthrough, the auditor follows one transaction or activity from beginning to end.


The auditor observes:

  • Who initiates it

  • Which systems are used

  • Who approves it

  • What information is reviewed

  • Where evidence is retained

  • How exceptions are handled

  • Where manual workarounds exist

  • How the transaction reaches the general ledger or final report


The CCS course specifically includes audit walkthroughs as a core fieldwork method.


A process narrative may state that all transactions follow the automated workflow.


A walkthrough may reveal that urgent transactions are handled by email.


That difference may be where the real risk exists.


Do Not Confuse Confidence with Accuracy

Experienced managers often speak confidently.


New auditors may assume that confidence reflects reliability.


It does not.


A statement can be:

  • Confidently delivered

  • Technically detailed

  • Supported by years of experience

  • Completely incorrect


Auditors should evaluate the evidence, not the speaker’s title, confidence, or personality.


Professional respect does not require unquestioning acceptance.


A useful response is:

I understand the process as you have described it. Let us review the supporting evidence so I can document it accurately.

This keeps the discussion professional while moving toward verification.


Contradictory Evidence Must Be Resolved

Suppose:

  • The policy requires monthly review.

  • The manager says the review occurred monthly.

  • The system log shows only four reviews.

  • The employee says reviews were performed informally.

  • The workpaper contains no retained evidence.


The auditor cannot simply select the explanation that is easiest to document.


The contradictory information must be resolved.


Possible follow-up procedures include:

  • Interviewing additional personnel

  • Reviewing alternative records

  • Expanding the sample

  • Reperforming the control

  • Examining system configurations

  • Reviewing subsequent corrective action

  • Consulting the audit supervisor


Getting to the facts requires the auditor to remain with the issue until the evidence supports a defensible conclusion.


Challenge Three: Overcoming Competence Issues

Every new auditor faces a competence gap.


That is unavoidable.


The new auditor may understand accounting but know little about:

  • Cybersecurity

  • Banking operations

  • Insurance claims

  • Procurement

  • Payroll systems

  • Construction

  • Regulatory compliance

  • Data analytics

  • Information technology

  • Government grants


The process owner may have spent 20 years working in the area the auditor has been assigned to review for the first time.


This creates a predictable fear:

How can I audit a process when the client knows far more about it than I do?

The answer is not pretending to know more than the client.


The answer is learning how to audit systematically.


The Auditor Does Not Need to Be the Process Expert

The process owner is usually the subject-matter expert.


The auditor’s role is different.


The auditor brings expertise in:

  • Risk

  • Internal control

  • Evidence

  • Governance

  • Compliance

  • Fraud indicators

  • Process evaluation

  • Professional skepticism

  • Reporting


The process owner may know exactly how a transaction is processed.


The auditor asks:

  • What objective does the process support?

  • What could prevent success?

  • Which controls address those risks?

  • What evidence demonstrates control performance?

  • How are exceptions detected?

  • Who can override the process?

  • What happens when the system fails?

  • How does management know the process remains effective?


The auditor does not compete with the client’s operational knowledge.


The auditor applies an independent risk-and-control perspective to that knowledge.


Competence Begins with Knowing What You Do Not Know

A dangerous new auditor is not one who lacks experience.


It is one who lacks experience but is unwilling to admit it.


Competent professional behavior includes:

  • Identifying knowledge gaps

  • Researching applicable guidance

  • Asking foundational questions

  • Consulting experienced auditors

  • Involving specialists

  • Documenting assumptions

  • Avoiding unsupported conclusions


The CCS course reviews major guidance sources, including the IIA’s professional framework, the Code of Ethics, COSO, Sarbanes-Oxley, and external-audit concepts. It also distinguishes Internal Audit from External Audit and introduces financial-statement assertions, materiality, risk assessment, control testing, and audit software.


This gives new auditors a structured foundation for determining:

  • What criteria apply

  • Which risks matter

  • What evidence is required

  • When additional expertise is necessary


Use a Repeatable Audit Methodology

A new auditor cannot rely on years of pattern recognition.


The auditor therefore needs a disciplined method.


A practical sequence is:

  1. Define the objective.

  2. Identify the risks.

  3. Identify the expected controls.

  4. Understand the actual process.

  5. Determine what evidence should exist.

  6. Test the control or transaction.

  7. Investigate exceptions.

  8. Evaluate the consequence.

  9. Document the conclusion.

  10. Obtain supervisory review.


The CCS course organizes audit planning around the Internal Audit lifecycle, risk assessment, the risk-control-objective relationship, individual audit planning, fieldwork, evidence, testing, workpapers, findings, and reporting.


A repeatable methodology gives the new auditor a reliable structure even when the subject matter is unfamiliar.


Prepare Before Meeting the Client

Competence is visible in preparation.


Before an interview, the auditor should review:

  • Policies and procedures

  • Prior audit reports

  • Organizational charts

  • Process narratives

  • Applicable laws and regulations

  • Performance reports

  • System descriptions

  • Known incidents

  • Open corrective actions


The auditor should enter the meeting knowing:

  • The engagement objective

  • The major risks

  • What information is already available

  • Which facts remain unclear

  • What evidence will likely be required

  • Which questions should be asked first


A client will tolerate a new auditor who asks thoughtful questions.


Clients become frustrated by auditors who ask them to explain information already contained in the documents provided.


Ask Basic Questions Without Apologizing for Them

New auditors sometimes avoid foundational questions because they fear appearing inexperienced.


That is a mistake.


Basic questions frequently reveal important assumptions.


Examples include:

  • What is the purpose of this report?

  • Who relies on this information?

  • Where does the data originate?

  • Who can change the calculation?

  • How do you know the population is complete?

  • What happens when the control identifies an exception?

  • Who reviews the reviewer?

  • What would happen if this process stopped tomorrow?


A clear foundational question is better than an unsupported assumption.


The auditor should not say:

This may be a stupid question, but …

There is no reason to weaken the question before asking it.

State the question professionally and listen to the answer.


Use Supervisory Review as a Competence Control

New auditors are not expected to work without review.


Supervision helps ensure that:

  • The scope is appropriate.

  • Risks have been identified.

  • Procedures address the objective.

  • Evidence is sufficient.

  • Exceptions are investigated.

  • Conclusions are supported.

  • Reporting is fair and accurate.


The Internal Auditing 101 agenda includes workpaper characteristics and workpaper review because review is not merely a final administrative step. It is a control over audit quality and a primary method of developing auditor competence.


A strong reviewer does more than correct the workpaper.


The reviewer explains:

  • Why additional evidence is needed

  • Why a conclusion is too broad

  • Why the risk has been misstated

  • Why a question should be reframed

  • Why an exception may require expanded testing


That feedback builds professional judgment.


Competence Includes Knowing When to Use a Specialist

Some subjects require specialized knowledge.


Examples include:

  • Cybersecurity

  • Actuarial estimates

  • Complex tax matters

  • Artificial intelligence

  • Environmental compliance

  • Advanced data analytics

  • Engineering

  • Valuation

  • Legal interpretation


The new auditor should know when the audit team requires additional expertise.


Using a specialist is not an admission that Internal Audit is incapable.


It is evidence that the engagement is being conducted responsibly.


The auditor still must understand:

  • The specialist’s objective

  • The work performed

  • The evidence obtained

  • How the results affect the audit conclusion


Communication, Facts, and Competence Are Connected

These three challenges should not be treated separately.


They reinforce one another.


Weak competence damages communication

An unprepared auditor asks irrelevant questions, wastes client time, and loses credibility.


Weak communication limits access to facts

A defensive or confused client may provide incomplete information or minimal cooperation.


Weak fact-finding damages competence

The auditor cannot develop sound professional judgment when conclusions are based on assumptions and unverified explanations.


The new auditor therefore needs an integrated approach:

  • Prepare thoroughly.

  • Ask structured questions.

  • Listen actively.

  • Verify explanations.

  • Evaluate evidence.

  • Seek review.

  • Communicate conclusions clearly.


That is how technical knowledge becomes competent audit performance.


From Exception to Finding: Where the Three Challenges Converge

Assume the auditor identifies three terminated employees whose system access remained active.


A weak approach might state:

IT failed to remove terminated users promptly.

A stronger auditor works through the issue.

Communication

The auditor interviews Human Resources, IT, the system owner, and the employee’s manager without assigning blame prematurely.


Getting to the facts

The auditor determines:

  • Termination dates

  • Access-removal dates

  • Systems involved

  • Whether the accounts were used

  • Who received the termination notice

  • Whether the automated feed operated

  • Whether compensating monitoring existed


Competence

The auditor understands enough about user-access risk, system logs, identity management, and control ownership to evaluate the condition—or seeks assistance from an IT auditor.


The resulting finding may conclude:

The termination process did not consistently communicate employee status changes to system administrators. Three former employees retained access from four to eleven days after termination, increasing the risk of unauthorized access to company information.

That finding is stronger because it is:

  • Factually supported

  • Process-focused

  • Risk-based

  • Professionally communicated

  • Within the auditor’s demonstrated competence


What Internal Auditing 101 Provides

Corporate Compliance Seminars’ Internal Auditing 101: Basic Training for Auditors is designed to give new and developing auditors a practical foundation in the complete engagement process.


Participants examine:

  • The purpose of Internal Audit

  • Internal-control fundamentals

  • Applicable professional guidance

  • Internal versus External Audit

  • Risk assessment

  • Individual audit planning

  • Walkthroughs

  • Audit interviews

  • S.P.I.N. questioning

  • Active listening

  • Audit evidence

  • Control testing

  • Sample size

  • Workpapers

  • Audit software

  • Findings

  • Reporting

  • Exit meetings

  • Client rapport


The course is presented through two live, interactive webinar sessions and provides 8 CPE credits in Auditing. It is offered at the basic level, with no prerequisites or advance preparation required.


Who Should Attend?

The program is particularly relevant for:

  • New internal auditors

  • Aspiring auditors

  • Accountants transitioning into Internal Audit

  • Compliance professionals

  • Risk-management personnel

  • Government auditors

  • Bank auditors

  • Insurance auditors

  • Nonprofit auditors

  • Professionals needing a practical audit refresher


The course is intended to help participants develop not only audit knowledge, but also the confidence to apply that knowledge during real engagements.


The New Auditor Does Not Need All the Answers

New auditors sometimes believe competence means entering every meeting with the answer already known.


That is not auditing.


Auditing begins with questions.


The competent auditor knows:

  • What needs to be understood

  • What evidence should exist

  • Which explanations require verification

  • When contradictory evidence must be resolved

  • When additional help is required

  • How conclusions should be communicated


The new auditor will make mistakes.


The objective of training, supervision, and experience is to prevent those mistakes from becoming unsupported audit conclusions.


The strongest new auditors are not those who pretend to know everything.


They are the ones who prepare carefully, ask direct questions, listen closely, verify the facts, accept constructive review, and continue developing their competence.


Attend Internal Auditing 101


The live webinar is designed to help participants address the most difficult parts of becoming an auditor:

  • Communicating with clients

  • Asking better questions

  • Obtaining reliable evidence

  • Separating facts from explanations

  • Evaluating internal controls

  • Documenting conclusions

  • Building competence through a disciplined methodology


New auditors do not create value by completing the most checklists.


They create value by understanding the objective, recognizing the risk, getting to the facts, and communicating what management needs to know.

 
 
 

Recent Posts

See All
How Arizona CPAs Actually Get in Trouble

Lessons From the Arizona State Board of Accountancy Most CPAs do not begin their careers expecting to face professional discipline. They pass the CPA examination. They satisfy experience requirements.

 
 
 

Comments


Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page