Walk the Risk Assessment Before Fieldwork
Apply context, risk identification, and risk evaluation before choosing audit procedures.
Audit fork The board asks for an audit of "AI use" after one vendor demo and two worried headlines. The topic is broad enough to waste 6 weeks unless the team defines objectives, risks, and assurance boundaries. The internal audit skill is deciding what evidence would change a governance decision, not collecting comfort material. Practice the choices that turn a vague audit topic into a risk-tested engagement. ISO 31000 risk assessment sequence ISO 31000-style thinking starts with context before assessment. Internal audit should understand objectives, stakeholders, risk criteria, and existing controls before designing tests. Fieldwork gets sharper when risk assessment…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in