Skip to content

CS Professional · Internal and Forensic Audit

Emerging Issues and Challenges: formula sheet

Full chapter guide

Key formulas

Traditional vs risk-based approach
Traditional: compliance focus + past transactions + fixed plan. Risk-based: objectives focus + risk ranking + dynamic plan
Use this as the core contrast in any comparison question.
Risk priority idea
Risk rating = Likelihood × Impact
A common scoring method to rank audit areas. Some organisations use other scales, so state the method used.
Continuous auditing cycle
Define rules → Automate tests → Flag exceptions → Investigate → Report and fix
A simple sequence to write in answers.
Agile audit cycle
Plan sprint → Fieldwork → Share findings → Review → Next sprint
Short iterations with frequent auditee feedback.
Risk rating
Risk = Likelihood × Impact
Used to rank cyber risks so audit effort goes to high-risk areas first. It is a scoring approach, not a statutory formula.
CIA triad
Confidentiality + Integrity + Availability
The three goals of information security. Map every threat to the goal it breaks.
Control chain
Risk → Control → Test → Finding → Recommendation
Use this sequence to structure any answer.
Types of ITGC
Access + Change management + Operations/Backup + Security
Core ITGC areas to list in a checklist answer.
Three lines
Management (1st) → Risk and compliance (2nd) → Internal audit (3rd)
Internal audit is independent assurance, not the owner of the control.
Core ESG audit logic
ESG risk → control → data → disclosure → evidence → report
Use this chain to structure any answer. Break at the weakest link and name the control gap.
Three pillars
E (environment) + S (social) + G (governance)
Give at least one risk and one test for each pillar when the question is general.
BRSR structure
Section A (general) + Section B (management and process) + Section C (principle-wise, nine principles)
Section C has essential and leadership indicators. BRSR Core is a subset of key indicators for assurance.
Assurance levels
Reasonable assurance (positive opinion) > limited assurance (negative-form conclusion)
Reasonable needs more testing. State which level applies and do not mix them up.
Three lines model for ESG
Line 1: operations own the data and controls; Line 2: sustainability and risk functions oversee; Line 3: internal audit gives independent assurance
Useful for role-based questions.
Fraud triangle
Fraud = Pressure + Opportunity + Rationalisation
Pressure and rationalisation sit with the person. Opportunity is the part internal controls can reduce, so auditors focus on it.
Core ethical principles
Integrity + Objectivity + Confidentiality + Competence
Use these four as the base of any ethics answer. Add independence when the facts involve pressure from management.
Reporting line rule
Functional reporting → Audit Committee; Administrative reporting → Management
This protects independence. A line reporting only to the CFO weakens it.
Vigil mechanism features
Safe channel + Confidentiality + No victimisation + Access to audit committee chair + Investigation and closure
Use as a checklist to evaluate any whistle blower policy.

Quick revision

  • Emerging trends push internal audit from after-the-event checking towards risk-based, forward-looking assurance.
  • Data analytics lets auditors test whole populations instead of small samples, but results still need professional judgement.
  • Technology tools improve coverage and speed, yet auditors must validate the data and the tool before relying on output.
  • Cyber risk covers confidentiality, integrity and availability of information; audit tests the controls around them.
  • IT general controls and application controls are different; know what each is meant to achieve.
  • ESG audit extends scope to non-financial information, and its credibility depends on sound data and clear criteria.
  • Fraud risk assessment is part of audit planning; internal audit does not guarantee that fraud will be detected.
  • Ethics for auditors rests on integrity, objectivity, confidentiality and competence.
  • Independence is protected by a reporting line to the audit committee, not only to management.
  • Practice challenges include limited resources, skill gaps, access to data and management resistance.
  • In every case answer, give provision or principle, facts, analysis, then a clear conclusion.

Common mistakes

  • Saying risk-based audit means auditing only high-risk areas and ignoring the rest. Fix: Say low-risk areas get less frequent or lighter coverage, not none. The audit universe is still reviewed.
  • Treating continuous auditing as a replacement for the internal auditor. Fix: Write that tools flag exceptions, while the auditor judges, investigates and reports.
  • Saying analytics or AI replaces the internal auditor. Fix: State that tools handle volume and pattern detection, while the auditor interprets results, forms conclusions and reports.
  • Treating RPA and AI as the same thing. Fix: RPA follows fixed rules for repetitive tasks. AI learns from data and finds patterns or predicts. Say this difference in one line.
  • Saying the internal auditor is responsible for implementing cyber security controls. Fix: State that management owns controls. The auditor gives independent assurance and recommendations.
  • Giving only generic points like 'use strong passwords' with no audit test. Fix: For each control, add what the auditor will inspect or test and what evidence will be kept.
  • Treating ESG audit as just another financial audit. Fix: State that the subject matter is mostly non-financial, based on operational data, and covers frameworks beyond accounting standards.
  • Saying internal audit gives the independent BRSR assurance. Fix: Say internal audit supports and reviews readiness. The independent assurance provider gives the formal conclusion on the specified indicators.
  • Saying the internal auditor is responsible for preventing all fraud. Fix: Write that management owns fraud prevention. The auditor assesses risk, tests controls, stays alert to red flags and reports.
  • Reporting a suspected fraud only to the manager who may be involved. Fix: When senior management may be involved, escalate to the audit committee, using the functional reporting line.

Exam tips

  • Always write a contrast with the traditional approach; examiners expect it even when the question does not ask directly.
  • In case questions, tie the trend to the named risk and give a practical action, not only a definition.
  • Mention limits and conditions, such as data quality, cost and independence, to show balanced analysis.
  • Use the terms RBIA, continuous auditing, agile audit and data analytics precisely, and do not mix their meanings.
  • For short notes, a definition, two or three features, benefits and a limit is usually enough.
  • Write short notes in a fixed pattern: meaning, use in audit, benefit, risk, safeguard.
  • Always give one practical example, as answers are case-based and examiners reward application.
  • Mention professional judgement and data validation in every answer; these are easy marks.