Where This Lesson Fits
Lessons 34.1 and 34.2 established the governance structures and policies and procedures framework through which the investment management firm defines its operational standards and accountability architecture. Those lessons described what should be in place: governance committees with appropriate authority and composition, policies with clear requirements and lifecycle management, procedures that accurately describe and guide operational behavior.
The governance structures and policy framework are design elements — they describe the intended organizational and operational architecture. Internal audit is the verification function that independently assesses whether the intended architecture is actually operating as designed. Where governance committees receive management information about control quality, internal audit independently investigates whether that management information accurately represents operational reality. Where the policies and procedures framework defines what should happen, internal audit independently assesses whether it is happening. This independence — from both management and the second-line oversight functions — is what gives internal audit's assurance opinion its governance weight: it cannot be influenced by the same management pressures that might affect the accuracy of management information provided to governance committees.
For operations professionals, internal audit is the third-line review that most directly addresses the quality of their own operational functions. Understanding how internal audits are planned, what auditors look for, how findings are developed and rated, and how remediation commitments are tracked is essential for both preparing effectively for internal audit engagements and for using audit findings constructively as a continuous improvement mechanism rather than treating them as compliance burdens to be managed defensively.
Lesson Objective
By the end of this lesson, students should be able to describe the role and independence requirements of the internal audit function and explain how its structural independence from management enables genuine third-line assurance; explain the risk-based audit planning process — how the annual audit plan is developed from the firm's risk universe, how audits are prioritized, and how the plan is approved by the audit committee; describe the typical internal audit engagement lifecycle — planning, fieldwork, finding development, reporting, management response, and follow-up — and identify the key activities and governance interactions at each stage; explain what auditors are looking for when they assess control design adequacy and control operating effectiveness, and distinguish between a finding that the control is poorly designed and a finding that the control is well-designed but not consistently applied; describe how internal audit findings are rated for severity and how the rating affects the management response and follow-up requirements; explain how operations professionals should prepare for and engage with internal audit engagements — what preparation is productive, what responses are appropriate, and how to use audit findings constructively; and identify the principal internal audit process failure modes — scope capture, finding inflation, finding suppression, and follow-up failure — and explain how each undermines the assurance function.
Lesson Overview
Internal audit is the organized, independent, and objective assurance activity that evaluates the adequacy and effectiveness of an organization's governance, risk management, and internal control processes. In the three lines of defense model, internal audit is the third line — the function that independently verifies that the first-line operational controls and second-line risk and compliance oversight are working as designed. Its independence from management is structural: the internal audit function reports to the board audit committee, not to the chief executive or operations management; its scope is set by the board audit committee's risk-based priorities, not by management's preferences; and its findings cannot be suppressed or modified by management before they are reported to the board.
Internal audit adds value to the governance system in two distinct ways. First, it provides independent assurance — the board audit committee and senior management receive an assessment of control quality from a source that is not subject to the management pressures that can compromise the objectivity of management-provided information. A management risk report that says "controls are functioning effectively" and an internal audit report that independently verifies or contradicts that assertion carry very different governance weight. Second, it identifies improvement opportunities — audit findings that surface control weaknesses, process inefficiencies, or policy gaps provide the specific, evidence-based input that governance bodies need to direct remediation investment where it will produce the greatest control improvement.
For operations professionals in wealth and asset management, internal audit engagement is a regular experience — the back office, middle office, compliance, and client service functions are all within the scope of the annual audit plan. Understanding the audit process from the auditee's perspective — what auditors are assessing, what evidence they need, how they develop their findings, and how management responses to audit findings affect follow-up intensity — is practical knowledge that enables effective engagement with the audit function and productive use of audit findings as a control improvement mechanism.
Why This Matters in Wealth & Asset Operations
Internal audit findings in investment management operations functions have direct governance consequences. A significant audit finding in the compliance monitoring function — identifying that pre-trade compliance alerts are being cleared without adequate investigation — is reported to the board audit committee, becomes part of the firm's formal control weakness record, requires a management response with a specific remediation plan and timeline, and is tracked through to verified completion. Operations professionals whose functions receive significant audit findings are accountable to the board for remediation quality and timeline — the governance visibility of audit findings is direct and consequential in a way that internal management reviews typically are not.
Operations professionals who understand the audit process can engage with it more effectively on two levels. At the preparation level, they can ensure that their functions are genuinely audit-ready — that controls are documented, evidence is organized, and procedures accurately reflect actual practice — rather than scrambling to create documentation that should exist but does not. At the engagement level, they can understand what auditors are assessing well enough to provide substantive responses to audit questions rather than defensive or evasive ones, and to distinguish legitimate audit findings from findings based on misunderstood operational context.
Beyond examination readiness, operations professionals who embrace internal audit as a control improvement mechanism — who actively engage with audit findings, ask audit teams for their observations on emerging risks, and use the audit planning process to direct assurance attention to areas of genuine control concern — get disproportionately more value from the audit function than those who engage with it defensively. The internal auditor who is welcomed as an honest independent assessor produces better governance outcomes than the one who is managed as an adversary to be minimized.
Core Concept
Internal Audit — The organized, independent, and objective assurance and consulting activity that evaluates the adequacy and effectiveness of an organization's governance, risk management, and internal control processes, reporting its findings to the board audit committee and senior management. Internal audit's independence from management is its defining structural characteristic and the source of its governance credibility.
Risk-Based Audit Plan — The annual schedule of audit engagements developed by the internal audit function based on a systematic assessment of the firm's risk universe — identifying all auditable areas, assessing the inherent risk and current control quality of each, and prioritizing audit engagements based on the combination of risk and control adequacy. High-risk areas with weaker control environments receive more frequent and more intensive audit coverage; lower-risk areas with stronger control environments receive less intensive coverage. The risk-based audit plan is approved by the board audit committee, ensuring that audit coverage priorities reflect the board's governance concerns rather than management's preferences.
Audit Engagement — A discrete audit project covering a defined auditable area — a specific function, process, or control domain — within the scope of the annual audit plan. Each engagement has a defined scope, a defined timeline, a designated audit team, and a deliverable audit report. The engagement lifecycle moves through planning, fieldwork, reporting, and follow-up.
Control Design Adequacy — The assessment of whether a control is designed to address the risk it is intended to mitigate — whether, if operating as designed, the control would prevent or detect the relevant adverse event. A finding of control design inadequacy means the control would fail to address the risk even if followed perfectly: the settlement instruction review process requires checking the counterparty name but not the settlement account number, so it would not detect the most common settlement instruction error even if applied consistently.
Control Operating Effectiveness — The assessment of whether a control that is adequately designed is actually being applied consistently in practice — whether the people who are supposed to perform the control are performing it, with the required frequency, quality, and documentation. A finding of control operating ineffectiveness means the control design is adequate but its consistent application in practice is failing: the settlement instruction review process correctly requires checking both the counterparty name and account number, but evidence review shows that the account number check was not performed for 23% of instructions in the sample period.
Audit Finding — A specific observation developed by the internal audit team that identifies a control weakness, process gap, or policy non-compliance in the audited area, supported by evidence, rated for severity, and requiring a management response with a specific remediation plan. An audit finding is not an allegation — it is an evidence-based observation about a specific control or process deficiency. Auditors develop findings through structured testing of controls against defined criteria, not through general impressions of the audited function.
Finding Severity Rating — The classification of an audit finding based on the level of risk it represents — typically rated as significant (or high), moderate (or medium), or minor (or low). Severity ratings drive management response requirements and follow-up intensity: significant findings require immediate escalation to the audit committee, specific remediation timelines, and verification of completed remediation; minor findings typically require management acknowledgment and a standard review follow-up. Severity rating inflation (rating minor findings as significant) and deflation (rating significant findings as minor) are both governance distortions.
Management Response — The auditee management's formal written response to each audit finding, which must include: acceptance or rejection of the finding (with explanation if rejected), a description of the remediation action that will be taken, the individual responsible for implementing the remediation, and the target completion date. The management response is reviewed by the audit team for adequacy — a response that commits to "reviewing the process" rather than specifying what change will be made and by when is not an adequate management response.
Internal Audit Function Structure: Independence, Scope, and Governance Relationships
The internal audit function's effectiveness depends on its structural design — specifically on the independence arrangements, scope authority, and governance relationships that determine whether it can provide genuine third-line assurance.
- Reporting Line and Independence. Internal audit's independence is maintained through its reporting structure. The head of internal audit (sometimes called the Chief Audit Executive or Chief Internal Auditor) has a direct reporting line to the board audit committee — the committee receives and approves the annual audit plan, reviews audit reports, assesses the internal audit function's effectiveness, and approves the appointment and removal of the head of internal audit. The head of internal audit may also have an administrative reporting line to the chief executive for day-to-day operational management, but the primary accountability for independence purposes is to the board. This dual reporting structure — functionally to the board, administratively to the CEO — is the standard model for maintaining independence while preserving operational practicability. Internal audit functions that report only to management, without a direct board relationship, lack the structural independence required for genuine third-line assurance.
- Scope Authority and Audit Universe. Internal audit has the authority to audit any area within the firm — it cannot be restricted from auditing specific functions by management. The audit universe (all auditable areas within the firm) is defined by the internal audit function and approved by the board audit committee; management cannot remove areas from the audit universe or restrict the scope of an audit engagement without the board audit committee's approval. In practice, audit scope is often discussed and refined with management during engagement planning — this is appropriate collaboration; it becomes inappropriate if management uses the discussion to exclude areas that would reveal control weaknesses. The audit team's right to access any records, people, or systems relevant to an audit engagement is a structural right that cannot be overridden by management.
- Staffing and Competency. The internal audit function's ability to provide meaningful assurance depends on its auditors having sufficient expertise in the areas they audit. An internal audit team that lacks expertise in investment management operations cannot effectively assess the adequacy of trade lifecycle controls or compliance monitoring processes — its findings will be superficial, its risk assessments will be inaccurate, and its assurance opinion will lack the credibility that expertise-based assessment provides. Investment management internal audit functions require auditors with background in portfolio management operations, compliance monitoring, settlement processes, and risk management — either through recruitment of auditors with that background or through co-sourcing with external specialists for engagements requiring specific technical expertise.
The Audit Engagement Lifecycle: From Planning Through Follow-Up
Each internal audit engagement progresses through a defined lifecycle whose quality at each stage determines the value and credibility of the assurance it provides.
- Engagement Planning. Audit engagement planning begins several weeks before fieldwork starts. The audit team develops its understanding of the audited area through a preliminary review of relevant policies and procedures, prior audit reports, risk assessments, regulatory correspondence, and management information reports. The engagement planning produces: the audit scope (the specific processes, controls, and time periods to be reviewed), the audit objectives (the specific questions the engagement will answer), the key risks (the specific risk scenarios the audit will assess controls against), the audit program (the specific tests and procedures the team will perform), the resource plan (who will conduct the audit, how many days are required), and the preliminary materiality assessment (what level of control weakness or non-compliance would constitute a finding). The engagement planning is completed before fieldwork begins and is discussed with the auditee management to align on scope and logistics.
- Fieldwork and Evidence Collection. During fieldwork, the audit team gathers the evidence required to assess control design adequacy and operating effectiveness for each control within the audit scope. Evidence collection methods include document review (examining policies, procedures, and transaction records), inquiry (interviewing operational staff about their processes and controls), observation (directly observing operational processes as they occur), and analytical procedures (analyzing transaction data for patterns or anomalies that may indicate control failures). Each piece of evidence is documented in the audit working papers — the structured record of all evidence examined, its source, what it demonstrates, and the audit team's assessment. Working papers are the foundation of the audit's quality assurance and the primary support for any findings the audit develops.
- Finding Development and Validation. When the audit team identifies a potential control weakness, it develops the finding through a structured four-part framework: the condition (what was observed — the specific evidence of the control weakness), the criteria (what should have been in place — the policy requirement, regulatory standard, or control expectation against which the condition is assessed), the cause (why the gap exists — the root cause of the deviation between condition and criteria), and the effect (the risk consequence of the gap — what adverse outcome could occur or has occurred because of the weakness). Before the finding is finalized, the audit team validates it with the auditee management — presenting the draft finding and asking management to confirm the factual accuracy of the evidence and to provide any additional context. Validation is not an opportunity for management to negotiate the finding's conclusion; it is an opportunity to correct factual errors in the evidence before the finding is finalized.
- Draft Report and Management Response. The audit report is drafted by the audit team, reviewed by the head of internal audit for quality and consistency, and issued to the auditee management as a draft for management response. Management has a defined period (typically ten to fifteen business days) to provide written responses to each finding. The management response must address each finding specifically — accepting or rejecting it with explanation, committing to a specific remediation action, naming the responsible individual, and specifying the target completion date. The audit team reviews the management responses and assesses their adequacy — responses that are vague, non-committal, or addressed to the symptom rather than the root cause are returned to management for enhancement.
- Final Report and Board Reporting. The final audit report, incorporating management responses and any amendments arising from the management response review, is issued to the auditee management and provided to the board audit committee. The board audit committee reviews significant findings and management responses as part of its oversight function — it may ask management to explain the root cause of significant findings, to describe the remediation plan in more detail, or to commit to a shorter remediation timeline. The board reporting of significant audit findings is the accountability moment at which the governance hierarchy's visibility is brought directly to bear on control weaknesses in the audited function.
- Follow-Up and Remediation Verification. After the final report is issued, the internal audit function tracks the status of each finding's management remediation against the committed timeline. When the management-committed remediation date arrives, the audit team verifies whether the remediation has been completed as committed — reviewing the specific evidence that the remediation action was taken (updated procedures, completed training, system changes, additional controls) and assessing whether the remediation adequately addresses the root cause of the finding. Findings where remediation is not verified as effective are escalated to the board audit committee and remain open in the tracking system until effective remediation is confirmed.
Constructive vs. Defensive Engagement with Internal Audit: The Auditee's Choice
Operations professionals' approach to internal audit engagements — whether constructive and collaborative or defensive and adversarial — has a significant and measurable impact on the governance value the audit produces and on the audited function's own operational improvement trajectory.
A constructive auditee engagement is one where the operational management team welcomes the audit as an independent quality assessment, provides complete and accurate information in response to audit inquiries, engages substantively with draft findings (confirming accurate observations while providing genuine factual correction for inaccurate ones), provides specific and actionable management responses that commit to root cause remediation rather than symptomatic fixes, and uses the audit findings as structured input to the function's control improvement planning. Operational managers who engage constructively with audit typically receive audit reports that accurately identify their function's genuine control weaknesses — which is the information they need to make targeted investments in control improvement. They also receive credit from the board audit committee for the quality of their engagement and the seriousness of their remediation commitments.
A defensive auditee engagement is one where operational management treats the audit as a compliance burden to be managed, provides minimum information in response to audit inquiries, challenges findings based on interpretation rather than factual correction, provides management responses that commit to superficial remediation while avoiding the structural changes required for genuine root cause remediation, and treats audit completion as the end of the engagement rather than the beginning of an improvement process. Defensive engagement typically produces one of two outcomes: audit findings that are significantly more extensive than the functional management expected (because the defensive posture prevented the auditors from understanding the operational context that would have focused their assessment), or a misleadingly positive audit report (because the defensive information provision concealed the genuine control weaknesses from the auditors). Neither outcome serves the operational function's interests or the firm's governance quality.
Operational Workflow: Preparing for an Internal Audit Engagement
- Audit Notification and Scope Review. When notified of an upcoming internal audit engagement, the operations manager reviews the audit scope and objectives — confirming which processes, controls, and time periods will be reviewed — and identifies any scope elements that may require clarification or context for the audit team. Questions about scope that arise during scope review should be raised with the audit team lead before fieldwork begins, not after findings are developed based on an incorrect understanding of scope.
- Documentation Readiness Assessment. The operations manager conducts a pre-audit self-assessment of documentation readiness: are the policies and procedures governing the audited function current and accurate? Do the procedures accurately describe the actual operational process? Is evidence of control performance readily available for the audit period in question? Are exception and breach records complete and accessible? Documentation gaps identified before the audit engagement provide an opportunity to address genuine weaknesses before they become audit findings — not by creating documentation that does not reflect genuine operational activity, but by initiating the legitimate update processes that have been deferred.
- Staff Briefing. Operations staff who will be interviewed or whose work will be reviewed during the audit are briefed on the audit's scope and objectives, the types of questions they are likely to be asked, and the appropriate way to engage with auditors — providing accurate, complete answers to questions within their knowledge, not volunteering information beyond what is asked, and escalating questions outside their knowledge to the operations manager rather than speculating. Staff should not be coached to provide scripted answers — auditors are experienced at identifying coached responses and the impression it creates is more damaging than the candid response would be.
- Evidence Organization. For the time period covered by the audit, the operations manager ensures that the evidence supporting each control's operation is organized and accessible. This means: transaction records for sampled periods are retrievable; exception and escalation records are complete and accurately reflect the timing and disposition of each exception; system logs relevant to the audited controls are available; and training records for relevant staff are accessible. Well-organized evidence reduces the time auditors spend on administrative evidence requests and focuses the audit on substantive control assessment.
- Control Self-Assessment. Before or during the early fieldwork phase, the operations manager conducts a frank internal assessment of the function's control environment: which controls are genuinely strong and consistently applied, which are adequate but inconsistently applied, and which have known weaknesses that have not yet been fully remediated. This self-assessment serves two purposes: it prepares the manager to engage substantively with audit findings when they are raised, and it provides the manager with the honest picture of the function's control quality that should inform their management response and remediation commitments.
- Constructive Engagement During Fieldwork. During fieldwork, the operations manager maintains regular communication with the audit team lead — providing context for operational practices, responding promptly to document and interview requests, and escalating any scope or methodology concerns to the head of internal audit rather than attempting to manage them directly with the field team. When auditors are developing potential findings, the operations manager engages substantively: confirming the factual accuracy of the evidence, providing genuine context that affects the finding's interpretation, and distinguishing between factual corrections (appropriate) and disagreements with the audit team's assessment conclusions (to be addressed in the management response, not during finding development).
- Management Response Development. When the draft report is received, the operations manager reviews each finding carefully — not for arguments against accepting them but for genuine factual errors in the evidence that require correction and for the substance of the remediation plan that will address each finding's root cause. The management response commits to specific, achievable actions that genuinely address the root cause of each finding, names the responsible individual, and specifies a realistic completion timeline. Management responses that commit to root cause remediation produce fewer follow-up audit findings than those that commit to symptomatic fixes.
Real-World Example
An internal audit engagement covers the trade lifecycle controls of an investment management firm's back office, with particular focus on the settlement instruction generation and pre-settlement review process. The engagement is planned for three weeks of fieldwork and covers the prior twelve months of settlement activity.
During fieldwork, the audit team reviews a sample of 120 settlement instructions across all custodians and asset classes. For each instruction in the sample, the team reviews the pre-settlement review documentation — the record that a second person verified the instruction's correctness before transmission to the custodian. The team finds that 38 of 120 instructions (32%) have no pre-settlement review documentation, and 14 of 120 (12%) have review documentation that was completed after the instruction was transmitted to the custodian — indicating that the review occurred after the control was supposed to prevent errors.
The audit team validates the finding with the back office manager, presenting the specific instructions with missing or post-transmission review documentation. The manager confirms the evidence is accurate and provides context: the pre-settlement review requirement was added to the procedure 18 months ago in response to a prior audit finding, but the team was not provided with additional staffing to perform the review, and on high-volume days the review either does not occur or occurs after transmission because the transmission deadline takes priority over the review. The audit team acknowledges the context but notes that it does not change the finding — the control is not operating as designed regardless of the operational reason.
The finding is rated as significant: a 32% gap in a pre-settlement review control creates material risk of settlement instruction errors reaching the custodian without detection. The draft report is issued with this finding and two minor findings. The back office manager's management response accepts the finding and commits to two remediation actions: an immediate process change to make pre-settlement review a mandatory step that the OMS system enforces before permitting instruction transmission (so that the transmission cannot be completed without the review being recorded), and a staffing review to assess whether additional capacity is required for the review to be performed within the pre-transmission window on all volume levels. The target completion date for the OMS system change is 45 days; the staffing review is 30 days. The board audit committee reviews the significant finding and management response at its next meeting, the chair specifically asking whether the 32% gap reflects a systemic process failure or a training issue — satisfied by the manager's explanation that it is primarily a capacity and system design issue being addressed by the committed remediation actions.
Common Mistakes
Mistake 1: Treating Internal Audit Preparation as Documentation Creation Rather Than Genuine Readiness Assessment
Operations managers who respond to upcoming audit notifications by creating or updating documentation — drafting procedures that do not reflect actual practice, generating evidence of controls that have not been performed — are creating the documentation equivalent of decorating a property for a sale viewing. The inspection reveals the decoration; experienced auditors are skilled at identifying documentation created for audit purposes rather than as part of a functioning control environment. Pre-audit preparation should focus on genuine readiness: identifying controls whose documentation is incomplete or inaccurate and initiating the legitimate update process, organizing genuine evidence of control performance, and conducting a candid self-assessment of the control environment. Genuine readiness produces a better audit outcome than documentation creation, because it addresses the underlying control quality rather than creating a cosmetic layer over genuine weaknesses.
Mistake 2: Challenging Audit Findings Based on Interpretation Rather Than Factual Accuracy
Management responses that challenge audit findings by disputing the audit team's assessment conclusions — arguing that the control weakness identified is not really a weakness, or that the finding's severity rating is too high — without providing factual evidence that the finding's underlying observations are incorrect are not genuine management responses. They are negotiations dressed as corrections. Auditors are trained to distinguish factual corrections (the evidence shows X, but what actually happened is Y, as demonstrated by this additional evidence) from interpretive disagreements (we believe our controls are adequate even though the evidence shows the gap you identified). Factual corrections are appropriate and welcomed — they improve the accuracy of the finding. Interpretive disagreements belong in the management response section of the audit report, where the auditee's view can be noted without modifying the finding itself.
Mistake 3: Providing Symptomatic Management Responses Rather Than Root Cause Remediation Commitments
Management responses that commit to symptomatic remediation — "we will remind staff of the requirement," "we will add the procedure step to our training materials" — when the root cause of the finding is a capacity constraint, a system design gap, or a process architecture weakness are management responses that will not produce genuine remediation. The audit team reviews management response adequacy precisely because symptomatic responses are a common pattern: they create the appearance of substantive remediation without addressing the structural condition that produced the finding. The internal audit team that accepts a symptomatic response without requiring root cause remediation has failed its follow-up responsibility; the operational management team that offers a symptomatic response has avoided the structural improvement required to prevent the finding from recurring.
Mistake 4: Restricting Auditor Access to Avoid Uncomfortable Findings
Operations managers who limit auditor access to staff, records, or systems — through informal unavailability, slow document provision, or discouraging candid staff responses during auditor interviews — are creating a more serious governance problem than the findings they are attempting to prevent. Scope restriction, whether formal or informal, is itself a significant audit finding and a board-level governance concern. Auditors who encounter resistance during fieldwork escalate the restriction to the head of internal audit and to the board audit committee; the escalation of a scope restriction finding is a more severe governance outcome than any of the operational findings the restriction was attempting to prevent. The appropriate response to a sensitive operational area within the audit scope is candid engagement with the audit team, not access restriction.
Mistake 5: Treating Audit Completion as the End of the Engagement
Operations managers who treat the issuance of the final audit report as the end of the engagement — providing remediation responses and then returning to normal operational priorities without actively managing the remediation timeline — discover at the follow-up audit that the remediation they committed to has not been completed. Audit follow-up is a governance accountability mechanism: the internal audit team tracks committed remediation timelines and reports overdue items to the board audit committee. Management that misses its committed remediation deadlines receives a follow-up audit finding more severe than the original, because the missed deadline demonstrates that the remediation commitment was not genuine. Treating the committed remediation timeline as a genuine operational priority — actively managing the remediation actions through to completion and verifying their effectiveness before the follow-up date — is the operational discipline that converts audit findings from accountability events into genuine control improvements.
Practical Exercises
Exercise 1: Finding Development Practice
Using the four-part finding framework (condition, criteria, cause, effect), develop audit findings for each of the following control observations. For each finding, identify whether the primary issue is control design inadequacy or control operating ineffectiveness. Observation A: The compliance monitoring policy requires pre-trade compliance review to be completed before any trade instruction is released to the trading desk. A review of 90 trade instructions shows that 7 were released to the trading desk while the compliance alert was still in "pending review" status in the compliance system. Observation B: The reconciliation procedure requires all position breaks to be escalated to the team lead if not resolved within one business day. A review of 60 position breaks over a 30-day period shows that 14 breaks aged beyond one business day without documented escalation; of these 14, the team lead was verbally informed of 9 but no written escalation documentation exists. Observation C: The settlement instruction transmission procedure requires a second person to verify the account number and SWIFT code before transmission. A review of the procedure shows that only one verification point is specified — the counterparty name — and no mention of account number or SWIFT code verification is included.
Exercise 2: Management Response Quality Assessment
Assess each of the following management responses to a significant audit finding (finding: 32% of settlement instructions lack pre-settlement review documentation) and classify each as adequate, borderline, or inadequate. For each inadequate or borderline response, identify specifically what is missing and how the response should be enhanced. Response A: "Management accepts this finding. We will remind settlement staff of the pre-settlement review requirement and update the procedure to emphasize its importance. Target completion: 30 days." Response B: "Management accepts this finding. The back office team lead will conduct a training session for all settlement staff covering the pre-settlement review requirement. Additionally, we will implement a daily monitoring report tracking review completion rates. The root cause is insufficient training emphasis on the review requirement. Target for training: 14 days; target for monitoring report: 21 days." Response C: "Management accepts this finding. The OMS workflow will be modified to require completion of the pre-settlement review checklist before the system will permit transmission of any settlement instruction. The checklist will capture the reviewer's identity, timestamp, and the specific verification steps completed. The system change will be developed, tested, and deployed within 45 days. In parallel, a staffing review will assess whether additional capacity is required to perform the review within the pre-transmission window during peak volume periods; the review will be completed within 30 days with findings reported to the operations director."
Exercise 3: Risk-Based Audit Plan Prioritization
An investment management firm's internal audit function is developing its annual audit plan. The firm's audit universe includes: the pre-trade compliance screening process, the settlement instruction generation and review process, the fund administrator oversight program, the OMS system access controls, the performance calculation and reporting process, the client mandate documentation process, the reconciliation function, and the vendor risk management program. The firm recently received a regulatory letter noting concerns about the adequacy of its pre-trade compliance screening documentation; the settlement function has had three significant audit findings in the prior two years, one of which has an open remediation action; the fund administrator oversight program was last audited three years ago and has not been covered since; and the vendor risk management program was implemented 18 months ago and has never been audited. Using a risk-based prioritization approach, rank these eight audit areas by priority for the current audit year, explain your prioritization rationale for each, and estimate the relative audit depth (number of engagement days) appropriate for each based on its risk level and prior audit history.
Exercise 4: Constructive Audit Engagement Simulation
You are the operations director of a back office settlement function preparing for an internal audit of the settlement instruction process. The audit scope covers the prior 12 months. You know that: the pre-settlement review procedure was updated six months ago and the new procedure accurately reflects current practice; settlement instruction error rates have improved over the year but three instructions in the early part of the year were transmitted without pre-settlement review because the prior procedure was ambiguous about the review requirement; the settlement instruction template was updated four months ago and is more comprehensive than the version used in the first eight months of the audit period; and the team lead escalation log for settlement fails is complete and well-organized for the past eight months but sparse for the first four months of the year, when escalation documentation was inconsistently maintained. Design your pre-audit preparation plan and your engagement strategy: what you will do to prepare, what you will disclose proactively to the audit team and when, and how you will respond if the audit team develops findings about the pre-review gap and the early-period escalation log sparseness.
Key Terms
Internal Audit — The independent, objective assurance and consulting activity that evaluates the adequacy and effectiveness of governance, risk management, and internal control processes, reporting to the board audit committee.
Risk-Based Audit Plan — The annual schedule of audit engagements developed by prioritizing auditable areas based on inherent risk and current control quality, approved by the board audit committee.
Audit Engagement — A discrete audit project covering a defined auditable area, moving through planning, fieldwork, reporting, and follow-up stages.
Control Design Adequacy — The assessment of whether a control is designed to address the risk it is intended to mitigate — whether it would be effective if consistently applied.
Control Operating Effectiveness — The assessment of whether an adequately designed control is actually being applied consistently in practice, confirmed through evidence review and testing.
Audit Finding — An evidence-based observation developed by the internal audit team identifying a control weakness, rated for severity, and requiring a specific management response with remediation commitments.
Finding Severity Rating — The classification of an audit finding as significant, moderate, or minor based on the risk level it represents, driving management response requirements and follow-up intensity.
Management Response — The auditee management's formal written response to each audit finding, accepting or rejecting the finding and committing to a specific remediation action with a named owner and target completion date.
Four-Part Finding Framework — The structured development approach for audit findings comprising condition (what was observed), criteria (what should be in place), cause (why the gap exists), and effect (the risk consequence of the gap).
Follow-Up Audit — The audit team's verification, at the management-committed completion date, that remediations have been completed as committed and are effective in addressing the root cause of the original finding.
Knowledge Check
Question 1
What is the governance significance of internal audit's structural independence from management, and what specifically would compromise it?
- A. Independence ensures auditors are not biased by personal relationships with the staff they audit
- B. Structural independence — the head of internal audit reporting to the board audit committee rather than to management for functional accountability — is the feature that gives internal audit's findings their governance credibility: the audit opinion cannot be influenced by management's institutional pressure to present the control environment favorably. Independence is compromised when management has authority over the internal audit function's budget, scope, staffing, or reporting content — any of these management authorities creates institutional pressure that can affect audit quality even without explicit instruction
- C. Independence ensures auditors can access all firm systems without manager approval
- D. Independence ensures the audit plan is set by the board rather than by the operations functions being audited
Correct Answer: B — Independence's governance value is the ability to provide an assessment of control quality that is not subject to the same management pressures that affect management-provided information. A board audit committee that receives internal audit findings knows those findings represent the auditor's genuine assessment rather than the assessment management would prefer the board to receive. This credibility evaporates when management controls the audit function — through budget authority (the chief financial officer who controls the audit budget can effectively constrain audit scope by limiting resources), through reporting authority (management that reviews audit reports before board distribution can suppress or soften findings), or through staffing authority (management that influences the appointment or performance evaluation of audit staff can create implicit pressure on audit conclusions). Any of these authorities compromises the structural independence that gives internal audit its governance value.
Question 2
What is the difference between a finding of control design inadequacy and a finding of control operating ineffectiveness, and why does the distinction matter for remediation?
- A. Design inadequacy is more severe; operating ineffectiveness is less severe and requires less intensive remediation
- B. A design inadequacy finding means the control would not address the risk even if perfectly applied — the control itself is deficient; an operating ineffectiveness finding means the control design is adequate but is not being consistently applied in practice. The distinction determines the remediation: design inadequacy requires redesigning the control (changing what is done); operating ineffectiveness requires improving the consistent application of an adequate control (improving how it is done through training, monitoring, or process reinforcement). Applying training-based remediation to a design inadequacy finding produces no improvement because the control being more consistently applied is still not capable of addressing the risk; redesigning a control for an operating effectiveness finding is disproportionate because the design is already adequate
- C. Design inadequacy findings are reported to the board while operating ineffectiveness findings are managed at the management level
- D. Design inadequacy affects all transactions while operating ineffectiveness affects only the transactions where the control failed
Correct Answer: B — The design-versus-effectiveness distinction has a direct implication for remediation appropriateness. A settlement instruction review process that checks only the counterparty name (design inadequacy) cannot prevent account number errors regardless of how consistently it is applied — the remediation is redesigning the checklist to include account number verification. A settlement instruction review process that correctly specifies checking both counterparty name and account number but is only completed on 68% of instructions (operating ineffectiveness) requires remediation that improves consistent application — process redesign to make completion mandatory before transmission, additional monitoring, or training on the importance of the requirement. These are different problems requiring different solutions; misidentifying which type of finding is present leads to remediation investment in the wrong solution.
Question 3
Why is a management response that commits to "reminding staff of the requirement" typically inadequate as a remediation for a significant audit finding?
- A. Reminder-based remediation is inadequate because it does not involve the audit committee in the remediation process
- B. Significant findings are rated significant because they represent control weaknesses with material risk consequences — a reminder that the failed control exists is not a structural change to the condition that caused the control to fail. If the control failed because staff were unaware of the requirement, training may be adequate; but if it failed because the process makes compliance impractical, because system design prevents consistent application, or because staffing is insufficient for the workload, reminding staff of the requirement addresses none of these root causes. Audit follow-up teams assess whether the remediation action addresses the root cause of the finding — symptomatic remediation produces follow-up findings at the next verification date
- C. Reminder-based remediation is inadequate because it is not a documented control change
- D. Significant findings always require system changes as remediation; process-based remediations are only adequate for minor findings
Correct Answer: B — The root cause is the determinant of remediation adequacy. Management responses that commit to root cause remediation — addressing the process design, system capability, staffing level, or workflow structure that made the control failure possible — produce genuine improvement that is confirmed at follow-up. Management responses that commit to symptomatic remediation — reminding staff, adding to training materials, updating procedures without changing the underlying conditions that made the procedure impossible to follow — produce compliance documentation without operational improvement. Experienced audit follow-up reviewers are specifically trained to assess whether management responses address root causes; they have seen the pattern of symptomatic remediation followed by finding recurrence often enough to recognize it immediately.
Question 4
An operations manager, faced with an upcoming audit, updates several procedure documents to describe controls that have been informally discontinued but are still formally documented. What governance risk does this create?
- A. The updated procedures will create confusion among staff who are not following the new documentation
- B. If the audit team tests the controls described in the updated procedures and finds evidence that they are not being performed (because the operational practice discontinued them), the audit will generate findings for operating ineffectiveness of controls that were actually informally discontinued — producing a more misleading audit picture than an accurate disclosure would have. More significantly, if the documentation creation is identified as specifically pre-audit preparation, the audit team will assess whether other documentation has been similarly created, producing a scope expansion and a finding about the integrity of the firm's documentation management practices — a governance finding more severe than any of the operational findings the documentation was intended to prevent
- C. The updated procedures will require additional staff training before the audit
- D. Creating documentation before an audit is a standard preparation activity and creates no governance risk
Correct Answer: B — The governance risk of creating documentation for audit purposes is that experienced auditors look for this pattern specifically. When they find updated documentation whose metadata shows recent modification dates shortly before audit commencement, they test the documented controls more intensively — looking for operational evidence that the control is being applied as described in the recently updated document. If the testing reveals that the control is not being applied (because it was informally discontinued), the finding is more significant than if the documentation had honestly reflected the current operational reality, because it involves both a control operating effectiveness failure and a documentation integrity concern. The honest approach — acknowledging during the audit scope discussion that a previously documented control has been discontinued and providing the operational context — produces a more proportionate finding.
Question 5
What is the governance consequence of an internal audit function that is funded and resourced by the chief financial officer rather than through a board-approved budget?
- A. No governance consequence — the source of the audit budget does not affect the independence of audit findings
- B. Management's authority over the audit function's budget creates institutional pressure on the scope, intensity, and conclusions of audit work — the head of internal audit who depends on the CFO's budget approval for their function's resources has an implicit incentive to avoid audit findings that are unwelcome to the CFO or to the finance function the CFO manages. Even without explicit instruction, this dependency compromises the structural independence that gives internal audit's findings their governance credibility — the board audit committee cannot be confident that audit scope and conclusions are free from management influence when management controls the resources the audit function depends on
- C. The governance consequence is regulatory — most jurisdictions require audit budget authority to reside with the board rather than management
- D. The consequence is operational efficiency — board budget approval is slower than management budget authority, reducing the audit function's operational flexibility
Correct Answer: B — Budget authority is a form of management authority over the audit function that compromises structural independence. Independence does not require that the head of internal audit has no administrative relationship with management — administrative reporting lines to the CEO are standard. It requires that management does not have authority over the functional aspects of the audit role: scope determination, staffing decisions, finding conclusions, and report content. Budget authority falls within the scope of functional authority — a CFO who approves the audit budget can constrain audit scope by approving fewer resources, can influence staff composition by restricting hiring authority, and creates an institutional dependency that the head of internal audit must navigate in every budget cycle. Board-approved audit budgets remove this dependency and preserve the functional independence that the board audit committee relationship is designed to create.
Lesson Summary
Internal audit is the third-line assurance function that independently evaluates whether the governance structures and policies and procedures framework described in Lessons 34.1 and 34.2 are operating as designed. Its structural independence from management — through its reporting relationship to the board audit committee and its authority over scope, staffing, and findings — is the feature that gives its assurance opinions their governance credibility and distinguishes them from management-provided assessments of control quality.
The internal audit engagement lifecycle — from risk-based planning through fieldwork, finding development, reporting, management response, and follow-up verification — is a structured governance process whose quality at each stage determines the accuracy and completeness of the assurance it provides. Finding development through the four-part framework (condition, criteria, cause, effect) ensures that findings identify root causes rather than symptoms. Management response adequacy review ensures that remediation commitments address root causes rather than providing symptomatic fixes. Follow-up verification ensures that committed remediations are genuinely completed rather than acknowledged and deferred.
Operations professionals who engage constructively with internal audit — preparing genuinely rather than creating documentation for appearances, engaging candidly rather than defensively, providing root cause management responses rather than symptomatic commitments, and treating audit completion as the beginning of the improvement process rather than its end — consistently achieve better audit outcomes and better control quality than those who treat internal audit as a compliance burden to be managed. The audit function's value as a control improvement mechanism is fully realized only when operational management engages with it as an honest independent quality assessor.
Looking Ahead
Lesson 34.4 examines external audit requirements — the engagement of the firm's external auditors in the annual financial statement audit and related assurance activities. While internal audit provides ongoing, risk-based assurance across the full scope of the firm's operations throughout the year, external audit provides a focused, specific assurance on the accuracy of the firm's financial statements and the adequacy of the controls supporting financial reporting. The external audit relationship involves different preparation disciplines, different evidence requirements, and different governance interactions from internal audit — and the external auditor's independence obligations are more formally regulated than those of internal audit, with specific prohibitions on the services external auditors may provide to audit clients.
Study Support
How to Approach This Lesson
The most effective approach to internal audit process content is to practice finding development using the four-part framework and management response assessment against the root cause adequacy standard. Exercise 1 and Exercise 2 in this lesson are specifically designed for this practice. Work through them before reviewing the discussions, developing your own findings and response assessments before comparing against the analytical framework provided. This builds the audit thinking skill that both audit preparation and audit finding response require.
Key Patterns to Recognize
- Control design adequacy and operating effectiveness are different problems requiring different remediation approaches — misidentifying which type of finding is present leads to ineffective remediation investment.
- Symptomatic management responses (training, reminders, procedure emphasis) are inadequate for root causes that are structural (process design, system capability, staffing capacity).
- Documentation created for audit preparation purposes is detectable by experienced auditors and creates more serious governance concerns than the underlying control weakness the documentation was intended to conceal.
- Audit follow-up failure (missed remediation timelines, symptomatic remediation accepted without verification of effectiveness) produces finding recurrence — the same finding appearing in successive audit cycles.
- Constructive audit engagement consistently produces better audit outcomes than defensive engagement — experienced auditors produce more comprehensive findings in adversarial environments than in collaborative ones.
Questions to Test Your Understanding
- Can you describe the full audit engagement lifecycle and identify the primary governance activity at each stage?
- Can you apply the four-part finding framework to develop a structured audit finding from a described control observation?
- Can you distinguish between a design adequacy finding and an operating effectiveness finding and explain the different remediation implications of each?
- Can you assess a management response for root cause adequacy and explain what would need to change for an inadequate response to become adequate?
- Can you describe what structural arrangements compromise internal audit independence and explain why each creates governance risk?
Common Areas of Confusion
A common confusion is between the internal audit function's role and the compliance function's role. Both provide oversight of operational control quality, but from different perspectives and with different structural relationships. The compliance function (second line) monitors adherence to regulatory requirements and internal policies on an ongoing basis, is operationally embedded in the firm's day-to-day activities, and provides advice and guidance as well as monitoring. Internal audit (third line) periodically and independently reviews whether the first line's controls and the second line's oversight are functioning as designed, does not provide advice or guidance during the audit (because doing so would compromise its independence in subsequently auditing those functions), and reports to the board rather than to management. The compliance function can be audited by internal audit. Another common confusion is treating audit findings as performance evaluations of individual staff. Audit findings assess control design and operating effectiveness — systemic organizational conditions — not individual performance. A finding that the pre-settlement review is only performed on 68% of instructions is a finding about the settlement process and its governance, not about the performance of individual settlement analysts who may be doing their best within a poorly designed process. This distinction matters for management response design — a finding about systemic process design requires systemic remediation, not individual performance management.
How This Connects to the Larger System
Internal audit is the third-line verification function that assesses whether the governance structures established in Lesson 34.1 are functioning as designed, whether the policies and procedures framework of Lesson 34.2 is accurate and followed, and whether the control quality across all operational functions examined in the Wealth and Asset Operations Track is genuinely adequate. Internal audit findings are the primary input to the external audit assessment of key controls supporting financial reporting (Lesson 34.4), provide evidence of control quality for regulatory examiners (Lesson 34.5), and generate the documentation and evidence requirements that the records management system of Lesson 34.6 must organize and preserve. The capstone Lesson 34.7 will show how all six governance dimensions — including internal audit — form the closed-loop oversight system that maintains institutional control integrity.
Practical Application
Application 1: Control Self-Assessment Program
A control self-assessment (CSA) program enables operations functions to assess their own control environment between internal audit engagements, identifying control weaknesses before they become audit findings and providing the internal audit function with current-period management views on control quality that can be compared against audit observations. An effective CSA program for an operations function includes: a structured questionnaire covering the function's key controls; a periodic completion schedule (quarterly for high-risk functions, semi-annually for lower-risk functions); a process for escalating identified control weaknesses to the operations director and, for significant weaknesses, to the second-line risk function; and a mechanism for tracking identified weaknesses through to remediation. Operations directors who maintain a functioning CSA program demonstrate continuous self-monitoring to governance committees and provide the internal audit function with a candid self-assessment that can be used as an audit planning input.
Application 2: Audit Readiness Review
An audit readiness review is a structured pre-audit self-assessment that the operations function conducts before an internal audit engagement to identify genuine readiness gaps. The review covers documentation completeness (are policies and procedures current and accurate?), evidence availability (can control performance evidence for the audit period be readily retrieved?), exception record completeness (are all exceptions documented and their dispositions recorded?), staffing familiarity (do operational staff know the policies and procedures governing their work?), and known control gaps (are there control weaknesses the function is already aware of that are likely to be identified in the audit?). Known control gaps identified in the audit readiness review are disclosed proactively to the audit team at the engagement planning meeting — proactive disclosure of known issues typically results in the audit team focusing on understanding the remediation plan rather than developing the gap as a finding, producing a better finding quality than the audit team would if it discovered the gap independently without management awareness.
Application 3: Finding Remediation Project Management
Treating audit finding remediations as structured projects — with a project scope, a project plan, a named project owner, defined milestones, and verification checkpoints — rather than as items on a to-do list consistently produces more complete and more timely remediations. The project scope defines what specifically needs to change and what evidence of the change is required. The project plan defines the sequence of activities, responsible parties for each, and target completion dates for each activity. The verification checkpoint defines what the operations director will review before declaring the remediation complete. Operations functions that manage audit remediations with this project discipline consistently close findings on time and with verified effectiveness; those that manage remediations informally consistently miss deadlines and provide symptomatic remediations that do not survive follow-up verification.
Application 4: Constructive Audit Relationship Maintenance
Building a constructive, professional relationship with the internal audit function between engagements produces significantly better audit quality than managing the audit team as an adversarial oversight body that appears only during engagements. Constructive relationship maintenance includes: periodic meetings with the head of internal audit to discuss the operations function's risk profile and control concerns (not to influence audit scope, but to ensure the audit function has accurate intelligence about emerging risks); proactive disclosure of significant control weaknesses and the remediation actions underway when they arise (not waiting for the audit to identify them); and following up on the previous audit's remediation actions before the follow-up verification date to confirm genuine completion. Operations directors who maintain these practices are consistently assessed as governance partners by audit functions — they receive the benefit of the doubt in ambiguous finding situations and are more likely to receive collaborative engagement from audit teams that view them as partners in control improvement.
