CS Professional · Internal and Forensic Audit
Internal Audit of Specific Functions: CS Professional Study Guide
Internal audit of specific functions means applying the audit method to one business area at a time, such as purchase, inventory, sales, payroll, fixed assets, treasury, IT and production. For each, you state the objective, key risks, controls, tests and reporting points. In the exam, you answer with this same structure, applied to the facts given.
What this chapter covers
This chapter takes the general internal audit method from earlier chapters and applies it to individual functions of a business. For each function you work through the same chain: what the function does, what can go wrong, which controls should exist, what the auditor tests, and what the auditor reports.
The functions covered are procurement, inventory and stores, sales and marketing, human resources and payroll, fixed assets and capital expenditure, treasury, finance and banking, IT and information systems, and production, compliance and other functions. The processes differ, but the audit logic is the same. Once you learn that logic, each function is mostly a change of vocabulary and risks.
The chapter connects to the rest of the paper in three ways. Risk assessment, planning, sampling and working papers decide how you audit a function. Reporting and follow-up decide how you present findings. Forensic audit later in the paper draws on the same weak controls, since fraud usually enters through gaps in these functions. Because Internal Audit carries 60 marks in this elective, which is open book, you must know where to find material fast and how to structure an answer from it.
Questions on this chapter are practical and case-based, so they reward structure more than memory. If you can set out risk, control, test and finding for any function in a clear format, you can handle an unfamiliar case. The material is also repetitive across functions, so effort spent on one function pays off in the others. Since the paper is open book, the marks go to those who apply the facts and draw a sound conclusion, not those who copy text.
Internal Audit of Specific Functions: topics in the order to study them
- 1Internal Audit of Procurement and PurchaseIt starts the business cycle and introduces the core pattern of requisition, approval, order, receipt and payment controls that later topics reuse.
- 2Internal Audit of Inventory and StoresIt follows naturally from purchase: goods received must be stored, recorded, counted and valued.
- 3Internal Audit of Sales and MarketingIt covers the revenue side of the cycle, including pricing, credit, billing, returns and collection.
- 4Internal Audit of Human Resources and PayrollIt is a self-contained area with its own controls on hiring, attendance, payroll and statutory deductions.
- 5Internal Audit of Fixed Assets and Capital ExpenditureIt builds on purchase controls and adds approval of capital budgets, asset registers, verification and disposal.
- 6Internal Audit of Treasury, Finance and BankingIt needs your grounding in cash flows from earlier topics and covers fund management, bank reconciliation and borrowing controls.
- 7Internal Audit of IT and Information SystemsEvery earlier function runs on systems, so you can now see general and application controls in context.
- 8Internal Audit of Production, Compliance and Other FunctionsIt is the widest topic and works best last, once you can reuse the audit pattern on any function.
How to prepare Internal Audit of Specific Functions
Prepare this chapter with one template and apply it to every function. Do not learn eight separate lists.
- Write a one-page template: objective, key risks, controls, audit tests, typical findings, recommendations. Use it for every function.
- Read each function and fill the template in your own words. Keep each entry to a short phrase.
- Link the functions in a cycle: purchase to stores to production to sales to collection to treasury. This shows where controls hand over.
- For each function, note two or three red flags that also signal fraud. This prepares you for the forensic part of the paper.
- Practise case questions. Read the facts, pick the control gaps, state the risk each creates, then suggest the test and the recommendation.
- Tab your open-book material by function and by template heading, so you can find a checklist in seconds. Do not rely on the book to write the answer.
- Before the exam, rewrite each template from memory and compare it with your sheet.
Common mistakes in Internal Audit of Specific Functions
Writing generic audit points that fit any function.
Fix: Name the function's specific documents and steps, such as goods receipt note, asset register or payroll master, and link each point to the facts given.
Listing controls without stating the risk they address.
Fix: Write each point as risk, then control, then test. This shows reasoning and earns more marks.
Confusing the internal auditor's role with that of management or the statutory auditor.
Fix: Frame outputs as findings and recommendations to management. State that management owns the controls and the auditor evaluates them.
Treating IT audit as only a list of software terms.
Fix: Organise IT answers by general controls and application controls, and always link them to a business risk such as unauthorised access or data loss.
Skipping the conclusion and recommendation in case answers.
Fix: Reserve the last few minutes of each answer for a clear conclusion and two or three practical recommendations.
Depending on the open book to find answers during the exam.
Fix: Practise under time limits, index your material by function, and use the book only to confirm details, not to build the answer.
Last-day revision: Internal Audit of Specific Functions
- Use the same flow for every function: objective, risk, control, test, finding, recommendation.
- Purchase: check requisition, approval, vendor selection, order, goods receipt and invoice matching before payment.
- Segregation of duties between ordering, receiving and paying is the main purchase control.
- Inventory: check physical verification, records, valuation, slow-moving stock, safe custody and cut-off.
- Sales: check credit approval, pricing, billing completeness, returns, discounts and collection follow-up.
- Payroll: check that employees are genuine, changes are authorised and statutory deductions are correct and paid on time.
- Fixed assets: check approval of capital spending, the asset register, physical verification, capitalisation and disposal.
- Treasury: check authority limits, bank reconciliations, borrowing terms and investment policy compliance.
- IT audit: separate general controls such as access and change management from application controls such as input and processing checks.
- Production: review planning, capacity use, wastage, quality control and cost records.
- A finding is complete only with the condition, criteria, cause, effect and recommendation.
- In case answers, tie every conclusion to a fact given in the question.
Internal Audit of Specific Functions practice questions
- Internal auditors of Ganga Pharma Ltd attend a physical stock count at year end. Several count sheets show round figures, and a few high-val…
- During an internal audit of Kaveri Engineering Ltd., the auditor selects a machine from the fixed asset register and traces it to the shop f…
- A bank's internal auditor reviews the IT general controls over a core system. Users report that the system was down for two days after a ser…
- A company's payroll is processed by software. The internal auditor prepares dummy employee records with known inputs, runs them through the …
- In auditing the loan portfolio of Gomti Finance Ltd, an internal auditor finds that interest on several term loans has not been serviced for…
- In an internal audit of the maintenance function at Godavari Steels Ltd, the auditor wants to assess whether preventive maintenance is effec…
- While testing purchases at Ganga Foods Pvt Ltd, an internal auditor notices many orders of ₹4,90,000 each to one vendor, just below the ₹5,0…
- At Narmada Steels Ltd, the internal auditor observes that slow-moving and obsolete items are carried in the stores at original cost, with no…
Internal Audit of Specific Functions in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Internal Audit of Specific Functions: frequently asked questions
Is this chapter theory or practical?
It is mostly practical. The exam is written and case-based, so you must apply audit steps to given facts. Knowing the structure matters more than word-for-word recall.
Do I need to study all eight functions equally?
Prepare all of them, because a case can come from any function. Because the method repeats, you can give the most time to the functions where you find the controls hardest, usually IT and treasury.
How do I answer a case question on a function?
Identify the control gaps in the facts, state the risk each gap creates, suggest the audit test and finish with a recommendation. Keep the answer in short, numbered points.
Does the open book format make this chapter easier?
It helps with details, but it does not write the answer for you. Time is limited, so you need a clear structure and an indexed book to save minutes.
How does this chapter link to forensic audit?
Fraud usually exploits weak controls in functions such as purchase, payroll and treasury. Knowing the control gaps and red flags here makes the forensic part easier to understand.