CS Professional · Internal and Forensic Audit
Emerging Issues and Challenges: formula sheet
Key formulas
- Traditional vs risk-based approach
- Traditional: compliance focus + past transactions + fixed plan. Risk-based: objectives focus + risk ranking + dynamic plan
- Use this as the core contrast in any comparison question.
- Risk priority idea
- Risk rating = Likelihood × Impact
- A common scoring method to rank audit areas. Some organisations use other scales, so state the method used.
- Continuous auditing cycle
- Define rules → Automate tests → Flag exceptions → Investigate → Report and fix
- A simple sequence to write in answers.
- Agile audit cycle
- Plan sprint → Fieldwork → Share findings → Review → Next sprint
- Short iterations with frequent auditee feedback.
- Risk rating
- Risk = Likelihood × Impact
- Used to rank cyber risks so audit effort goes to high-risk areas first. It is a scoring approach, not a statutory formula.
- CIA triad
- Confidentiality + Integrity + Availability
- The three goals of information security. Map every threat to the goal it breaks.
- Control chain
- Risk → Control → Test → Finding → Recommendation
- Use this sequence to structure any answer.
- Types of ITGC
- Access + Change management + Operations/Backup + Security
- Core ITGC areas to list in a checklist answer.
- Three lines
- Management (1st) → Risk and compliance (2nd) → Internal audit (3rd)
- Internal audit is independent assurance, not the owner of the control.
- Core ESG audit logic
- ESG risk → control → data → disclosure → evidence → report
- Use this chain to structure any answer. Break at the weakest link and name the control gap.
- Three pillars
- E (environment) + S (social) + G (governance)
- Give at least one risk and one test for each pillar when the question is general.
- BRSR structure
- Section A (general) + Section B (management and process) + Section C (principle-wise, nine principles)
- Section C has essential and leadership indicators. BRSR Core is a subset of key indicators for assurance.
- Assurance levels
- Reasonable assurance (positive opinion) > limited assurance (negative-form conclusion)
- Reasonable needs more testing. State which level applies and do not mix them up.
- Three lines model for ESG
- Line 1: operations own the data and controls; Line 2: sustainability and risk functions oversee; Line 3: internal audit gives independent assurance
- Useful for role-based questions.
- Fraud triangle
- Fraud = Pressure + Opportunity + Rationalisation
- Pressure and rationalisation sit with the person. Opportunity is the part internal controls can reduce, so auditors focus on it.
- Core ethical principles
- Integrity + Objectivity + Confidentiality + Competence
- Use these four as the base of any ethics answer. Add independence when the facts involve pressure from management.
- Reporting line rule
- Functional reporting → Audit Committee; Administrative reporting → Management
- This protects independence. A line reporting only to the CFO weakens it.
- Vigil mechanism features
- Safe channel + Confidentiality + No victimisation + Access to audit committee chair + Investigation and closure
- Use as a checklist to evaluate any whistle blower policy.
Quick revision
- Emerging trends push internal audit from after-the-event checking towards risk-based, forward-looking assurance.
- Data analytics lets auditors test whole populations instead of small samples, but results still need professional judgement.
- Technology tools improve coverage and speed, yet auditors must validate the data and the tool before relying on output.
- Cyber risk covers confidentiality, integrity and availability of information; audit tests the controls around them.
- IT general controls and application controls are different; know what each is meant to achieve.
- ESG audit extends scope to non-financial information, and its credibility depends on sound data and clear criteria.
- Fraud risk assessment is part of audit planning; internal audit does not guarantee that fraud will be detected.
- Ethics for auditors rests on integrity, objectivity, confidentiality and competence.
- Independence is protected by a reporting line to the audit committee, not only to management.
- Practice challenges include limited resources, skill gaps, access to data and management resistance.
- In every case answer, give provision or principle, facts, analysis, then a clear conclusion.
Common mistakes
- Saying risk-based audit means auditing only high-risk areas and ignoring the rest. Fix: Say low-risk areas get less frequent or lighter coverage, not none. The audit universe is still reviewed.
- Treating continuous auditing as a replacement for the internal auditor. Fix: Write that tools flag exceptions, while the auditor judges, investigates and reports.
- Saying analytics or AI replaces the internal auditor. Fix: State that tools handle volume and pattern detection, while the auditor interprets results, forms conclusions and reports.
- Treating RPA and AI as the same thing. Fix: RPA follows fixed rules for repetitive tasks. AI learns from data and finds patterns or predicts. Say this difference in one line.
- Saying the internal auditor is responsible for implementing cyber security controls. Fix: State that management owns controls. The auditor gives independent assurance and recommendations.
- Giving only generic points like 'use strong passwords' with no audit test. Fix: For each control, add what the auditor will inspect or test and what evidence will be kept.
- Treating ESG audit as just another financial audit. Fix: State that the subject matter is mostly non-financial, based on operational data, and covers frameworks beyond accounting standards.
- Saying internal audit gives the independent BRSR assurance. Fix: Say internal audit supports and reviews readiness. The independent assurance provider gives the formal conclusion on the specified indicators.
- Saying the internal auditor is responsible for preventing all fraud. Fix: Write that management owns fraud prevention. The auditor assesses risk, tests controls, stays alert to red flags and reports.
- Reporting a suspected fraud only to the manager who may be involved. Fix: When senior management may be involved, escalate to the audit committee, using the functional reporting line.
Exam tips
- Always write a contrast with the traditional approach; examiners expect it even when the question does not ask directly.
- In case questions, tie the trend to the named risk and give a practical action, not only a definition.
- Mention limits and conditions, such as data quality, cost and independence, to show balanced analysis.
- Use the terms RBIA, continuous auditing, agile audit and data analytics precisely, and do not mix their meanings.
- For short notes, a definition, two or three features, benefits and a limit is usually enough.
- Write short notes in a fixed pattern: meaning, use in audit, benefit, risk, safeguard.
- Always give one practical example, as answers are case-based and examiners reward application.
- Mention professional judgement and data validation in every answer; these are easy marks.