CS Professional · Internal and Forensic Audit
Internal Audit Tools and Techniques: formula sheet
Key formulas
- Choice of technique
- Technique = f(audit objective, risk, volume, data form, cost and time)
- A guide to reasoning, not a numerical formula. Link your choice to these factors in the answer.
- Classification to remember
- Evidence-gathering + Documentation aids + Testing and sampling + Technology-based
- Use this four-part frame to structure any 'classify or explain' answer.
- Evidence reliability rule of thumb
- External and auditor-generated evidence is generally more reliable than oral or internally generated evidence
- A general guide, not an absolute rule. Reliability also depends on the strength of controls over the source.
- Sampling interval (systematic selection)
- Sampling interval = Population size ÷ Sample size
- Choose a random starting point within the first interval, then pick every nth item. For monetary unit sampling, use total book value ÷ sample size.
- Deviation rate
- Sample deviation rate = Number of deviations found ÷ Sample size × 100
- Used in tests of controls. Compare it with the tolerable deviation rate.
- Projected misstatement (simple projection)
- Projected misstatement = (Misstatement found ÷ Value of items tested) × Total population value
- Used in substantive tests. Compare it with tolerable misstatement. Add any known misstatement in items not sampled.
- Sample size drivers
- Larger sample when: risk is higher, tolerable error is lower, expected error is higher, population is more varied
- A rule of direction, not a fixed figure. Population size has little effect once the population is large.
- Acceptance rule
- Accept result if projected error or deviation rate ≤ tolerable level
- If it exceeds the tolerable level, extend testing, revise the risk assessment or report the weakness.
- Evidence quality test
- Audit evidence = Sufficiency (quantity) + Appropriateness (relevance + reliability)
- Use this to judge whether evidence collected is enough to support a finding.
- Reliability ranking
- External > Internal; Auditor-obtained > Entity-supplied; Original > Copy; Written > Oral
- A general guide, not an absolute rule. Reliability depends on the circumstances and the source's controls.
- Variance in analytical procedures
- Variance = Actual − Expected; Variance % = (Actual − Expected) ÷ Expected × 100
- Investigate variances above the threshold you set for the engagement.
- ICQ reading rule
- Yes = control present; No = possible weakness; N/A = question not relevant
- Questions must be framed so that Yes is the good answer. Every No needs follow-up and a recommendation.
- Questionnaire vs checklist
- ICQ = questions on control quality; Checklist = list of items to confirm as done
- An ICQ evaluates the system. A checklist ensures completeness of work.
- Flowchart purpose
- Flowchart = diagram of the process: activities, documents, decisions, checks, flow
- Shows the sequence and the segregation of duties at a glance.
- Common flowchart symbols
- Oval = start or end; Rectangle = process step; Diamond = decision; Arrow = flow; Document shape = document
- Symbol sets can vary. State the key you use on the chart.
- Order of use
- Understand → Document → Evaluate → Test → Report
- These tools serve the documenting and evaluating stages. Testing comes after.
- Risk score
- Risk score = Likelihood rating × Impact rating
- Use the same scale for all risks, for example 1 to 5. The maximum on a 5 × 5 scale is 25.
- Residual risk (conceptual)
- Residual risk = Inherent risk − effect of controls
- This is a concept, not an arithmetic rule. Some entities use a control effectiveness factor, but the method must be stated in your answer.
- Typical rating bands (illustrative)
- 1–5 Low; 6–12 Medium; 15–25 High
- Bands are set by each entity. State them as an assumption in your answer; they are not fixed by law.
- Test data logic
- Expected result (worked out by auditor) vs Actual result (from system) → difference = control or processing weakness
- Include both valid and invalid transactions so you test whether the system accepts correct items and rejects wrong ones.
- Coverage with GAS
- Population tested = 100% of records (not a sample)
- This is the main advantage over manual sampling. It is valid only if the file is complete and reconciled to the books.
- Data completeness check
- Control total of file extracted = Control total in books
- Do this before running any analysis. Compare record count and value.
- Parallel simulation
- Auditor's programme output = Entity's programme output on the same data
- Differences point to errors in the entity's programme logic.
- Purpose of working papers
- Plan and supervise + Support the report + Enable review + Provide evidence of work done + Aid future audits
- Use this list to open any answer on why working papers are kept.
- Core features of a good working paper
- Heading + Objective + Work done + Source + Result + Conclusion + Preparer and reviewer sign-off + Index reference
- Tick these off when asked for features or a model format.
- Ownership rule
- Working papers belong to the internal audit function or the organisation, not to the individual auditor
- For outsourced work, state that the engagement terms should settle ownership.
- Retention rule
- Retention period = longer of the policy or charter period and any period required by law
- Do not quote a fixed number of years unless the question gives one.
Quick revision
- Match each tool to its purpose: evidence, sampling, process recording, risk focus, data analysis, documentation.
- Evidence should be relevant, reliable and sufficient to support the auditor's conclusion.
- Sampling tests part of a population to reach a conclusion about the whole; know statistical and non-statistical approaches.
- Sampling carries risk, so the sample must be representative and the selection method justified.
- Flowcharts show process flow visually and help spot gaps in controls.
- Checklists ensure steps are not missed; questionnaires collect information about controls.
- Risk-based audit directs effort to areas with higher risk.
- CAATs use software to test large volumes of data, often the whole population.
- CAATs still need auditor judgement and checks that the data is complete and accurate.
- Working papers record the work done, evidence seen, conclusions and reviewer sign-off.
- Documentation should allow another person to follow what was done without extra explanation.
- In every answer, link the tool to the facts of the case.
Common mistakes
- Listing technique names with no meaning or example. Fix: Give a one-line meaning and one practical example for each technique. Marks go to explanation, not to names.
- Treating inquiry as sufficient evidence. Fix: State that inquiry must be corroborated by inspection, observation or reperformance.
- Saying statistical sampling is always better or always required. Fix: Say both are acceptable. Statistical sampling gives a measurable risk, but it needs more effort. Choose by cost, population and risk.
- Calling non-statistical sampling unplanned or random. Fix: Non-statistical sampling is planned by judgment on size and items. Its results cannot be given a probability level.
- Treating inspection and observation as the same thing. Fix: Inspection is of records or assets. Observation is of a process being performed. Use a one-line example for each.
- Relying on inquiry alone as sufficient evidence. Fix: Say inquiry must be corroborated by inspection, observation or re-performance.
- Treating a checklist and an ICQ as the same thing Fix: Say that an ICQ asks whether a control exists and works, while a checklist confirms that tasks or items are done.
- Framing ICQ questions so that No is the good answer Fix: Frame every question so Yes shows a control, such as "Are orders approved by someone other than the person who raised them?"
- Adding likelihood and impact instead of multiplying. Fix: Write the formula first: score = likelihood × impact. Then calculate each risk on a separate line.
- Treating RCSA as a replacement for audit testing. Fix: State that RCSA is self-reported and may be biased. The internal auditor reviews, challenges and tests a sample independently.
Exam tips
- Open with a one-line definition and purpose, then use the four-part classification to organise the answer.
- For case questions, always link each technique to the stated objective and risk. Generic lists score less.
- Give a short practical example for every technique, using Indian entities and rupee figures where the facts allow.
- Mention the limits of each technique and say that auditors combine them.
- Keep the answer within the marks: a few lines per technique for long answers, and name plus one line for short ones.
- For a difference question, write two or three points of contrast, such as selection basis, risk measurement and effort, and avoid saying one is better.
- Always name the test type in case questions. State whether the objective is a control check or an amount check.
- Show the calculation in numbers when data is given. Interval, deviation rate or projection earns marks even if the conclusion is simple.