Internal Auditing 101: How New Auditors Can Communicate Better, Get to the Facts, and Overcome Competence Gaps
- John Blackshire
- Aug 3
- 13 min read
The New Auditor’s Biggest Challenges Are Not Usually the Audit Checklist
New internal auditors are frequently trained first on procedures:
How to complete a workpaper
How to select a sample
How to document a walkthrough
How to test an approval
How to write an exception
Those procedures matter. But they are rarely the hardest part of becoming an effective auditor.
The new auditor’s most difficult challenges are usually more fundamental:
Communicating effectively with audit clients
Getting beyond explanations and reaching the facts
Performing credibly while still developing professional competence
A new auditor may understand the audit program and still struggle during an interview.
The auditor may recognize a missing approval but fail to understand the control failure behind it. The auditor may obtain a management explanation and treat it as evidence.
The auditor may discover a process outside their experience and hesitate to ask questions because they do not want to appear unqualified.
These are not minor developmental problems.
They affect the quality of the risk assessment, the evidence obtained, the findings developed, and the credibility of the entire Internal Audit function.
Corporate Compliance Seminars’ Internal Auditing 101: Basic Training for Auditors directly addresses these challenges. The live, interactive course covers interpersonal and team-building skills, audit risk assessment, fieldwork, internal-control evaluation, evidence gathering, audit communication, interviewing, S.P.I.N. questioning, active listening, workpaper preparation, exit meetings, and rapport building.
The next program is scheduled for Wednesday and Thursday, September 30–October 1, 2026, and provides 8 NASBA-approved CPE credits in Auditing.
Challenge One: Communicating Without Damaging the Audit Relationship
Internal auditing is a communication-intensive profession.
Auditors must communicate with:
Executives
Process owners
Supervisors
Employees
Information technology personnel
Compliance officers
External auditors
Audit Committee members
Every one of those individuals may view the audit differently.
Some see Internal Audit as a source of independent assurance.
Others see it as:
A disruption
A compliance exercise
A search for mistakes
A threat to their reputation
A challenge to their authority
Additional work added to an already full schedule
The new auditor enters this environment without the organizational history, authority, or credibility of a more experienced professional.
That creates a practical problem:
The auditor must obtain cooperation from people who may be defensive, skeptical, or significantly more experienced in the process being reviewed.
The CCS Internal Auditing 101 program treats communication as part of audit methodology—not as an optional soft skill. Its learning objectives include interpersonal skills and the audit communication process, while the fieldwork agenda covers interviewing, S.P.I.N. questioning, active listening, exit meetings, and rapport building.
The New Auditor Must Learn the Difference Between Authority and Influence
Internal auditors often have broad access rights, but access authority does not automatically create cooperation.
An auditor can demand a report.
That does not mean the auditor will receive:
A complete explanation
Timely assistance
Candid discussion of problems
Information about informal workarounds
Insight into management concerns
The effective auditor learns to influence through:
Preparation
Professionalism
Respect
Clear explanations
Relevant questions
Consistent follow-through
Fair evaluation of evidence
A new auditor who relies too heavily on formal authority may create resistance.
A new auditor who avoids difficult questions to preserve the relationship may fail to complete the audit.
Professional communication requires both courtesy and persistence.
Explain the Purpose Before Requesting the Evidence
Audit clients are more cooperative when they understand why information is being requested.
Compare these two approaches.
Weak request
Send me the vendor-change report and ten supporting documents by Friday.
Stronger request
We are evaluating whether vendor banking changes are independently authenticated before payments are released. Please provide the complete vendor-change report for the audit period and the supporting evidence for the selected transactions.
The stronger request explains:
The audit objective
The risk being evaluated
Why the report is needed
Why supporting evidence is required
This reduces the impression that Internal Audit is requesting documents without understanding the process.
Neutral Questions Produce Better Information
New auditors sometimes unintentionally accuse the client while trying to obtain facts.
For example:
Why did you fail to follow the policy?
That question assumes:
The policy applied.
The individual was responsible.
The procedure was not performed.
No compensating control existed.
The failure was personal.
A better question is:
Walk me through how this transaction was processed and identify any steps that differed from the documented procedure.
The second question remains direct, but it allows the auditor to understand the circumstances before reaching a conclusion.
Other useful neutral phrases include:
“Help me understand how this process normally operates.”
“What happens when the assigned reviewer is unavailable?”
“Which evidence demonstrates that the review occurred?”
“How are exceptions escalated?”
“What changed during the audit period?”
“What would prevent this control from operating consistently?”
Neutral language does not weaken professional skepticism.
It improves evidence gathering.
Active Listening Is More Than Remaining Quiet
A new auditor may be so focused on asking the prepared questions that they fail to listen to the answers.
Active listening requires the auditor to:
Allow the client to complete the response.
Identify vague or incomplete statements.
Restate important information.
Ask logical follow-up questions.
Recognize contradictions.
Separate factual statements from opinions.
Determine what evidence should exist.
Suppose the client says:
We normally perform an independent callback before changing vendor bank information.
The word normally should immediately trigger additional questions:
What circumstances allow the callback to be skipped?
Who authorizes an exception?
Where is the callback documented?
Which telephone number is used?
Is that number obtained independently?
How does management monitor compliance?
Can you show me the most recent completed callback?
Internal Auditing 101 includes active listening and effective questioning as core fieldwork skills because interviews are not simply conversations. They are evidence-gathering procedures.
Using S.P.I.N. to Improve Audit Interviews
The course introduces the S.P.I.N. questioning methodology, which gives new auditors a practical structure for conducting interviews.
Situation Questions
Situation questions establish how the process works.
Examples:
Who performs the control?
Which systems are used?
How often is the report prepared?
Who approves an exception?
What changed during the year?
These questions create the factual foundation.
Problem Questions
Problem questions identify difficulties and weaknesses.
Examples:
Which steps create the most delays?
Where are responsibilities unclear?
Which controls are most difficult to perform?
What exceptions occur repeatedly?
Where does actual practice differ from written procedure?
These questions identify possible breakdowns.
Implication Questions
Implication questions explore why the problem matters.
Examples:
What happens when the reconciliation is late?
Could an unauthorized transaction remain undetected?
How could this affect financial reporting?
What regulatory exposure could result?
Could the problem exist in other locations?
These questions connect the process weakness to organizational risk.
Need Questions
Need questions focus on improvement.
Examples:
What information would help management identify exceptions sooner?
How would automated monitoring improve oversight?
Which corrective action would reduce the risk most quickly?
What resources would be required to sustain the improved process?
This approach helps the new auditor move beyond a checklist and conduct a purposeful audit interview.
Challenge Two: Getting to the Facts
Internal auditors work in an environment filled with explanations, interpretations, opinions, and assumptions.
The auditor’s responsibility is to determine what the evidence supports.
That sounds straightforward. In practice, it is one of the hardest professional skills to develop.
New auditors may hear statements such as:
“We have always done it this way.”
“The system would not allow an error.”
“The manager reviews everything.”
“That was an isolated event.”
“The amount was not material.”
“The external auditor never questioned it.”
“No one has ever complained.”
“The employee knows the procedure.”
None of these statements proves that the control operated effectively.
They may be relevant explanations. They are not automatically audit evidence.
Inquiry Is Evidence, but It Is Usually Not Enough
Interviews help auditors understand:
The process
Responsibilities
Control design
Expected evidence
Known problems
Recent changes
But inquiry alone often provides limited assurance about operating effectiveness.
If a manager states that monthly reconciliations are reviewed, the auditor should determine:
Which reconciliations?
Who prepares them?
Who reviews them?
What does the reviewer examine?
What threshold triggers follow-up?
How is review documented?
What happens to unresolved differences?
Did the review occur throughout the period?
The CCS course teaches participants to evaluate and document internal controls, gather audit evidence, test controls, consider sample size, and prepare reviewable workpapers.
The new auditor must learn a critical distinction:
What the client says happens is the starting point. What the evidence demonstrates happened is the audit conclusion.
Separate Facts, Criteria, and Conclusions
A disciplined auditor separates three different elements.
Fact
What did the auditor observe?
Five of the 30 sampled vendor changes did not contain evidence of an independent callback.
Criteria
What should have occurred?
The vendor-maintenance procedure requires independent verification before banking information is changed.
Conclusion
What does the evidence mean?
The verification control did not operate consistently during the audit period, increasing the risk that fraudulent banking changes could be processed.
New auditors often move too quickly from an isolated exception to a broad conclusion.
Others do the opposite: they document the exception but avoid stating what it means.
Internal Auditing 101 connects fieldwork, audit evidence, testing, exceptions, findings, and reporting so participants understand how conclusions develop from facts.
Ask for the Evidence That Should Exist
A useful audit question is:
What evidence would demonstrate that this control was performed?
That question forces the process owner and auditor to distinguish between an intended control and an evidenced control.
Possible evidence may include:
Approval records
System logs
Reconciliations
Exception reports
Review notes
Meeting minutes
Electronic workflow history
Access-change tickets
Confirmation records
Data-analysis results
When no evidence exists, several possibilities must be considered:
The control was not performed.
The control was performed but not documented.
The evidence was not retained.
The documented control does not reflect actual practice.
Another control may address the risk.
The auditor should not automatically choose the most favorable—or most critical—explanation.
The auditor should investigate.
Follow the Transaction Through the Process
Walkthroughs are one of the most effective ways for new auditors to move from policy to fact.
During a walkthrough, the auditor follows one transaction or activity from beginning to end.
The auditor observes:
Who initiates it
Which systems are used
Who approves it
What information is reviewed
Where evidence is retained
How exceptions are handled
Where manual workarounds exist
How the transaction reaches the general ledger or final report
The CCS course specifically includes audit walkthroughs as a core fieldwork method.
A process narrative may state that all transactions follow the automated workflow.
A walkthrough may reveal that urgent transactions are handled by email.
That difference may be where the real risk exists.
Do Not Confuse Confidence with Accuracy
Experienced managers often speak confidently.
New auditors may assume that confidence reflects reliability.
It does not.
A statement can be:
Confidently delivered
Technically detailed
Supported by years of experience
Completely incorrect
Auditors should evaluate the evidence, not the speaker’s title, confidence, or personality.
Professional respect does not require unquestioning acceptance.
A useful response is:
I understand the process as you have described it. Let us review the supporting evidence so I can document it accurately.
This keeps the discussion professional while moving toward verification.
Contradictory Evidence Must Be Resolved
Suppose:
The policy requires monthly review.
The manager says the review occurred monthly.
The system log shows only four reviews.
The employee says reviews were performed informally.
The workpaper contains no retained evidence.
The auditor cannot simply select the explanation that is easiest to document.
The contradictory information must be resolved.
Possible follow-up procedures include:
Interviewing additional personnel
Reviewing alternative records
Expanding the sample
Reperforming the control
Examining system configurations
Reviewing subsequent corrective action
Consulting the audit supervisor
Getting to the facts requires the auditor to remain with the issue until the evidence supports a defensible conclusion.
Challenge Three: Overcoming Competence Issues
Every new auditor faces a competence gap.
That is unavoidable.
The new auditor may understand accounting but know little about:
Cybersecurity
Banking operations
Insurance claims
Procurement
Payroll systems
Construction
Regulatory compliance
Data analytics
Information technology
Government grants
The process owner may have spent 20 years working in the area the auditor has been assigned to review for the first time.
This creates a predictable fear:
How can I audit a process when the client knows far more about it than I do?
The answer is not pretending to know more than the client.
The answer is learning how to audit systematically.
The Auditor Does Not Need to Be the Process Expert
The process owner is usually the subject-matter expert.
The auditor’s role is different.
The auditor brings expertise in:
Risk
Internal control
Evidence
Governance
Compliance
Fraud indicators
Process evaluation
Professional skepticism
Reporting
The process owner may know exactly how a transaction is processed.
The auditor asks:
What objective does the process support?
What could prevent success?
Which controls address those risks?
What evidence demonstrates control performance?
How are exceptions detected?
Who can override the process?
What happens when the system fails?
How does management know the process remains effective?
The auditor does not compete with the client’s operational knowledge.
The auditor applies an independent risk-and-control perspective to that knowledge.
Competence Begins with Knowing What You Do Not Know
A dangerous new auditor is not one who lacks experience.
It is one who lacks experience but is unwilling to admit it.
Competent professional behavior includes:
Identifying knowledge gaps
Researching applicable guidance
Asking foundational questions
Consulting experienced auditors
Involving specialists
Documenting assumptions
Avoiding unsupported conclusions
The CCS course reviews major guidance sources, including the IIA’s professional framework, the Code of Ethics, COSO, Sarbanes-Oxley, and external-audit concepts. It also distinguishes Internal Audit from External Audit and introduces financial-statement assertions, materiality, risk assessment, control testing, and audit software.
This gives new auditors a structured foundation for determining:
What criteria apply
Which risks matter
What evidence is required
When additional expertise is necessary
Use a Repeatable Audit Methodology
A new auditor cannot rely on years of pattern recognition.
The auditor therefore needs a disciplined method.
A practical sequence is:
Define the objective.
Identify the risks.
Identify the expected controls.
Understand the actual process.
Determine what evidence should exist.
Test the control or transaction.
Investigate exceptions.
Evaluate the consequence.
Document the conclusion.
Obtain supervisory review.
The CCS course organizes audit planning around the Internal Audit lifecycle, risk assessment, the risk-control-objective relationship, individual audit planning, fieldwork, evidence, testing, workpapers, findings, and reporting.
A repeatable methodology gives the new auditor a reliable structure even when the subject matter is unfamiliar.
Prepare Before Meeting the Client
Competence is visible in preparation.
Before an interview, the auditor should review:
Policies and procedures
Prior audit reports
Organizational charts
Process narratives
Applicable laws and regulations
Performance reports
System descriptions
Known incidents
Open corrective actions
The auditor should enter the meeting knowing:
The engagement objective
The major risks
What information is already available
Which facts remain unclear
What evidence will likely be required
Which questions should be asked first
A client will tolerate a new auditor who asks thoughtful questions.
Clients become frustrated by auditors who ask them to explain information already contained in the documents provided.
Ask Basic Questions Without Apologizing for Them
New auditors sometimes avoid foundational questions because they fear appearing inexperienced.
That is a mistake.
Basic questions frequently reveal important assumptions.
Examples include:
What is the purpose of this report?
Who relies on this information?
Where does the data originate?
Who can change the calculation?
How do you know the population is complete?
What happens when the control identifies an exception?
Who reviews the reviewer?
What would happen if this process stopped tomorrow?
A clear foundational question is better than an unsupported assumption.
The auditor should not say:
This may be a stupid question, but …
There is no reason to weaken the question before asking it.
State the question professionally and listen to the answer.
Use Supervisory Review as a Competence Control
New auditors are not expected to work without review.
Supervision helps ensure that:
The scope is appropriate.
Risks have been identified.
Procedures address the objective.
Evidence is sufficient.
Exceptions are investigated.
Conclusions are supported.
Reporting is fair and accurate.
The Internal Auditing 101 agenda includes workpaper characteristics and workpaper review because review is not merely a final administrative step. It is a control over audit quality and a primary method of developing auditor competence.
A strong reviewer does more than correct the workpaper.
The reviewer explains:
Why additional evidence is needed
Why a conclusion is too broad
Why the risk has been misstated
Why a question should be reframed
Why an exception may require expanded testing
That feedback builds professional judgment.
Competence Includes Knowing When to Use a Specialist
Some subjects require specialized knowledge.
Examples include:
Cybersecurity
Actuarial estimates
Complex tax matters
Artificial intelligence
Environmental compliance
Advanced data analytics
Engineering
Valuation
Legal interpretation
The new auditor should know when the audit team requires additional expertise.
Using a specialist is not an admission that Internal Audit is incapable.
It is evidence that the engagement is being conducted responsibly.
The auditor still must understand:
The specialist’s objective
The work performed
The evidence obtained
How the results affect the audit conclusion
Communication, Facts, and Competence Are Connected
These three challenges should not be treated separately.
They reinforce one another.
Weak competence damages communication
An unprepared auditor asks irrelevant questions, wastes client time, and loses credibility.
Weak communication limits access to facts
A defensive or confused client may provide incomplete information or minimal cooperation.
Weak fact-finding damages competence
The auditor cannot develop sound professional judgment when conclusions are based on assumptions and unverified explanations.
The new auditor therefore needs an integrated approach:
Prepare thoroughly.
Ask structured questions.
Listen actively.
Verify explanations.
Evaluate evidence.
Seek review.
Communicate conclusions clearly.
That is how technical knowledge becomes competent audit performance.
From Exception to Finding: Where the Three Challenges Converge
Assume the auditor identifies three terminated employees whose system access remained active.
A weak approach might state:
IT failed to remove terminated users promptly.
A stronger auditor works through the issue.
Communication
The auditor interviews Human Resources, IT, the system owner, and the employee’s manager without assigning blame prematurely.
Getting to the facts
The auditor determines:
Termination dates
Access-removal dates
Systems involved
Whether the accounts were used
Who received the termination notice
Whether the automated feed operated
Whether compensating monitoring existed
Competence
The auditor understands enough about user-access risk, system logs, identity management, and control ownership to evaluate the condition—or seeks assistance from an IT auditor.
The resulting finding may conclude:
The termination process did not consistently communicate employee status changes to system administrators. Three former employees retained access from four to eleven days after termination, increasing the risk of unauthorized access to company information.
That finding is stronger because it is:
Factually supported
Process-focused
Risk-based
Professionally communicated
Within the auditor’s demonstrated competence
What Internal Auditing 101 Provides
Corporate Compliance Seminars’ Internal Auditing 101: Basic Training for Auditors is designed to give new and developing auditors a practical foundation in the complete engagement process.
Participants examine:
The purpose of Internal Audit
Internal-control fundamentals
Applicable professional guidance
Internal versus External Audit
Risk assessment
Individual audit planning
Walkthroughs
Audit interviews
S.P.I.N. questioning
Active listening
Audit evidence
Control testing
Sample size
Workpapers
Audit software
Findings
Reporting
Exit meetings
Client rapport
The course is presented through two live, interactive webinar sessions and provides 8 CPE credits in Auditing. It is offered at the basic level, with no prerequisites or advance preparation required.
Who Should Attend?
The program is particularly relevant for:
New internal auditors
Aspiring auditors
Accountants transitioning into Internal Audit
Compliance professionals
Risk-management personnel
Government auditors
Bank auditors
Insurance auditors
Nonprofit auditors
Professionals needing a practical audit refresher
The course is intended to help participants develop not only audit knowledge, but also the confidence to apply that knowledge during real engagements.
The New Auditor Does Not Need All the Answers
New auditors sometimes believe competence means entering every meeting with the answer already known.
That is not auditing.
Auditing begins with questions.
The competent auditor knows:
What needs to be understood
What evidence should exist
Which explanations require verification
When contradictory evidence must be resolved
When additional help is required
How conclusions should be communicated
The new auditor will make mistakes.
The objective of training, supervision, and experience is to prevent those mistakes from becoming unsupported audit conclusions.
The strongest new auditors are not those who pretend to know everything.
They are the ones who prepare carefully, ask direct questions, listen closely, verify the facts, accept constructive review, and continue developing their competence.
Attend Internal Auditing 101
Internal Auditing 101: Basic Training for Auditors will be presented on Wednesday and Thursday, September 30–October 1, 2026.
The live webinar is designed to help participants address the most difficult parts of becoming an auditor:
Communicating with clients
Asking better questions
Obtaining reliable evidence
Separating facts from explanations
Evaluating internal controls
Documenting conclusions
Building competence through a disciplined methodology
New auditors do not create value by completing the most checklists.
They create value by understanding the objective, recognizing the risk, getting to the facts, and communicating what management needs to know.
Comments