Audit Process: How to Successfully Plan Audit

Audit Process: How to Successfully Plan Audit
As defined by the Institute of Internal Auditors (IIA), internal audit is “an
independent, objective assurance and consulting activity designed to add
value and improve an organization's operations. It helps an organization
accomplish its objectives by bringing a systematic, disciplined approach to
evaluate and improve the effectiveness of risk management, control, and
governance processes.”
First-Party Audits: These are performed within an organization to measure its
strengths and weaknesses against its own procedures or methods and/or external
standards. Internal audits are first-party audits and are conducted by auditors who
are employed by the company being audited, but have no vested interest in the
audit results of the area(s) being audited.
Second-Party Audits: These are external audits performed on a supplier by a
customer or by a contracted firm (consulting firm) on behalf of a customer.
Third-Party Audits: These are external audit performed on a supplier or regulated
entity by an external participant other than a customer. They are conducted for
recognition or registration purposes are performed either by Extrinsic Regulatory
(FDA, FAA, NRC, USDA) or Registrars (ISO9001, AIB, JCAHCO ).
Plan
•Establishing the Audit Program
•Objectives and extent of audit
•Responsibilities, resources, and procedures related to the audit program
Do
•Implementing the Audit Program
•Scheduling audits and selecting the audit team
•Directing audit activities and maintaining records
Check
•Monitoring the Audit Program
•Monitoring and reviewing the audit program
•Identifying needs for corrective and preventive actions
Act
•Improvement
•Improving the Audit Program
•Identifying needs for continual improvement
During the planning phase, the following has to be done:
 The purpose of the audit
 A complete description of the GRC program. This should include details such as
the entity which is to be audited and the key measures of the program
 The scope of the audit and the scope exclusions
 The objective of the audit and the approach to be taken
 A high level schedule of the audit and a detailed timeline
 The necessary skills needed to complete the audit
 The selection of members of the internal audit team
 Any other resources required for successful completion of the audit
 Document management and archival/ retention policies and processes
 Defining the scope of the audit and its objectives is an important part of
planning the process, ensuring that the audit is carried out successfully.
 In order to conduct a successful GRC program audit, the auditors need to have a
thorough understanding of the following:
 The organization’s culture, business, strategic goals and objectives
 Key risks that the program and the organization face
 The organization and structure of the GRC program and its future evolution
 Auditors must determine the following:
 The major operational processes
 Various initiatives being implemented within the organization
 The IT systems that support the operation of the GRC program
An audit of a GRC program should have the following objectives:
 Evaluate the “tone at the top” – Is it proper and effective in promoting a culture that is ethical
and compliant?
 Check if the program provides reasonable assurance of compliance with organizational policies
and all applicable laws and regulations.
 Determine if the motivation/incentive/reward system is well planned and structured.
 Determine if the GRC program has a robust management framework that is well documented
and has enough resources to carry out its tasks.
 Check whether the GRC program has been implemented and if the program’s performance
reporting system accurately represented the end results of the program’s efforts.
 Conduct a cost-benefit analysis of the GRC program.
 Determine whether the program is up-to-date with prevailing industry practices and is adequate
for the size and complexity of the organization.
 Include other audit objectives that the board or management has requested.
Want to learn more about audit, its process and best practices
for auditing? ComplianceOnline webinars and seminars are a
great training resource. Check out the following links:
 Risk Based Internal Auditing (RBIA)
 Internal Auditing Essentials for Medical Device
Manufacturers
 How to Audit GRC Programs?
 Role of the Audit Committee in Corporate Governance
 Internal Audit's Role in Enterprise Risk Management
 OCEG Approved GRC (Governance, Risk and Compliance)
Professional Seminar
 Auditing Technology and IT Investment Management
1 von 8

Recomendados

MEASURING INTERNAL AUDIT PERFORMANCE von
MEASURING INTERNAL AUDIT PERFORMANCEMEASURING INTERNAL AUDIT PERFORMANCE
MEASURING INTERNAL AUDIT PERFORMANCEbbongio
33.9K views26 Folien
Basic internal auditing von
Basic internal auditingBasic internal auditing
Basic internal auditingKhalid Aziz
1.1K views28 Folien
Internal audit ppt von
Internal audit pptInternal audit ppt
Internal audit pptLetzconsult.com
33.7K views5 Folien
Standards of Internal Audit von
Standards of Internal AuditStandards of Internal Audit
Standards of Internal AuditKaran Puri
5.2K views118 Folien

Más contenido relacionado

Was ist angesagt?

Internal Audit Report Writing Best Practice von
Internal Audit Report Writing Best PracticeInternal Audit Report Writing Best Practice
Internal Audit Report Writing Best PracticeDJones68
6.3K views20 Folien
The Role of Internal Audit von
The Role of Internal AuditThe Role of Internal Audit
The Role of Internal AuditArmeniaFED
3.5K views20 Folien
Internal audit department von
Internal audit departmentInternal audit department
Internal audit departmentPopun
1.9K views18 Folien
Internal audit procedure von
Internal audit procedureInternal audit procedure
Internal audit procedurebhavikjariwala
15.9K views9 Folien
Internal Process Audit von
Internal Process AuditInternal Process Audit
Internal Process Auditintellisenseit
1.8K views22 Folien

Was ist angesagt?(20)

Internal Audit Report Writing Best Practice von DJones68
Internal Audit Report Writing Best PracticeInternal Audit Report Writing Best Practice
Internal Audit Report Writing Best Practice
DJones686.3K views
The Role of Internal Audit von ArmeniaFED
The Role of Internal AuditThe Role of Internal Audit
The Role of Internal Audit
ArmeniaFED3.5K views
Internal audit department von Popun
Internal audit departmentInternal audit department
Internal audit department
Popun1.9K views
Internal audit procedure von bhavikjariwala
Internal audit procedureInternal audit procedure
Internal audit procedure
bhavikjariwala15.9K views
Internal Audit Strategic Framework von Jeremy Cheng
Internal Audit Strategic FrameworkInternal Audit Strategic Framework
Internal Audit Strategic Framework
Jeremy Cheng3.3K views
Internal audit report writing von Neha Kothari
Internal audit report writingInternal audit report writing
Internal audit report writing
Neha Kothari19.5K views
Process Audit and ISO von Sadafhazel
Process Audit and ISOProcess Audit and ISO
Process Audit and ISO
Sadafhazel1.6K views
Internal Audit Methodology von Manoj Agarwal
Internal Audit MethodologyInternal Audit Methodology
Internal Audit Methodology
Manoj Agarwal33.8K views
Internal Audit effectiveness von Karan Puri
Internal Audit effectivenessInternal Audit effectiveness
Internal Audit effectiveness
Karan Puri1.6K views
Basic Internal Auditing Presentation von Vernon Benjamin
Basic Internal Auditing PresentationBasic Internal Auditing Presentation
Basic Internal Auditing Presentation
Vernon Benjamin85.5K views
Compiling an internal audit universe von David Griffiths
Compiling an internal audit universeCompiling an internal audit universe
Compiling an internal audit universe
David Griffiths1.8K views
Auditing procedure & internal control system von RadhikaGupta215
Auditing procedure & internal control systemAuditing procedure & internal control system
Auditing procedure & internal control system
RadhikaGupta215215 views
planning process in audit ppt von KunalPatel257
planning process in audit pptplanning process in audit ppt
planning process in audit ppt
KunalPatel2579.4K views
Internal audit report writing.pdf von kavyashree k
Internal audit   report writing.pdfInternal audit   report writing.pdf
Internal audit report writing.pdf
kavyashree k2.4K views

Destacado

SEO Audit - Complete Checklist von
SEO Audit - Complete ChecklistSEO Audit - Complete Checklist
SEO Audit - Complete ChecklistJahid Hasan
2K views12 Folien
Auditing and Audit Process in Organization von
Auditing and Audit Process in OrganizationAuditing and Audit Process in Organization
Auditing and Audit Process in OrganizationAnas Mohammed MCILRM
4.5K views19 Folien
Techniques For Issue Analysis von
Techniques For Issue AnalysisTechniques For Issue Analysis
Techniques For Issue Analysiswilfredaquilina
5.7K views4 Folien
Stages of Development von
Stages of DevelopmentStages of Development
Stages of DevelopmentMechelle Tumanda
607 views23 Folien
Audit process von
Audit processAudit process
Audit processNext Generation Security Agency
41.8K views165 Folien
new Techniques at internal audit von
new Techniques at internal auditnew Techniques at internal audit
new Techniques at internal auditMohammad Draidi
817 views25 Folien

Destacado(15)

SEO Audit - Complete Checklist von Jahid Hasan
SEO Audit - Complete ChecklistSEO Audit - Complete Checklist
SEO Audit - Complete Checklist
Jahid Hasan2K views
Elements & Analysis Of Audit Findings & Respones von westcott_family
Elements & Analysis Of Audit Findings & ResponesElements & Analysis Of Audit Findings & Respones
Elements & Analysis Of Audit Findings & Respones
westcott_family2.5K views
Iso Process Audit Training von srmortensen
Iso Process Audit TrainingIso Process Audit Training
Iso Process Audit Training
srmortensen24.9K views

Similar a Audit Process: How to Successfully Plan Audit

Process Level Auditing Presentation von
Process Level Auditing   PresentationProcess Level Auditing   Presentation
Process Level Auditing PresentationVernon Benjamin
1.7K views15 Folien
Audits and Regulatory Compliance von
Audits and Regulatory ComplianceAudits and Regulatory Compliance
Audits and Regulatory Compliancesomeshwar mankar
3.3K views64 Folien
introduction on auditing von
introduction on auditingintroduction on auditing
introduction on auditingnikhilkumar640177
5 views50 Folien
CHAPTER-1 Management Audit and Planning procedure.pdf von
CHAPTER-1 Management Audit and Planning procedure.pdfCHAPTER-1 Management Audit and Planning procedure.pdf
CHAPTER-1 Management Audit and Planning procedure.pdfDr. Dinesh Mehta
1.2K views12 Folien
Quality Audit in pharmaceutical industry von
Quality Audit in pharmaceutical industryQuality Audit in pharmaceutical industry
Quality Audit in pharmaceutical industryHari Haran
2.1K views51 Folien
Risk based auditing von
Risk based auditingRisk based auditing
Risk based auditingTunde Elijah Kelani
866 views146 Folien

Similar a Audit Process: How to Successfully Plan Audit (20)

Process Level Auditing Presentation von Vernon Benjamin
Process Level Auditing   PresentationProcess Level Auditing   Presentation
Process Level Auditing Presentation
Vernon Benjamin1.7K views
CHAPTER-1 Management Audit and Planning procedure.pdf von Dr. Dinesh Mehta
CHAPTER-1 Management Audit and Planning procedure.pdfCHAPTER-1 Management Audit and Planning procedure.pdf
CHAPTER-1 Management Audit and Planning procedure.pdf
Dr. Dinesh Mehta1.2K views
Quality Audit in pharmaceutical industry von Hari Haran
Quality Audit in pharmaceutical industryQuality Audit in pharmaceutical industry
Quality Audit in pharmaceutical industry
Hari Haran2.1K views
Audit Framework presentation.pptx von OnwVinx
Audit Framework presentation.pptxAudit Framework presentation.pptx
Audit Framework presentation.pptx
OnwVinx42 views
Internal Audit’s Evolving Role in Corporate GRC Strategy von David Fernandes
Internal Audit’s Evolving Role in Corporate GRC StrategyInternal Audit’s Evolving Role in Corporate GRC Strategy
Internal Audit’s Evolving Role in Corporate GRC Strategy
David Fernandes507 views
Auditing Management systems based on ISO19011 By Eng. Karam Malkawi - Jordan von Eng. A.karam Al Malkawi
Auditing Management systems based on ISO19011 By Eng. Karam Malkawi - JordanAuditing Management systems based on ISO19011 By Eng. Karam Malkawi - Jordan
Auditing Management systems based on ISO19011 By Eng. Karam Malkawi - Jordan
Internal control and Control Self Assessment von Manoj Agarwal
Internal control and Control Self AssessmentInternal control and Control Self Assessment
Internal control and Control Self Assessment
Manoj Agarwal7K views
Evaluation and control in strategic management von Meenakshi1994
Evaluation and control in strategic managementEvaluation and control in strategic management
Evaluation and control in strategic management
Meenakshi19948.5K views
Introduction to cooperative auditing von efferson ramirez
Introduction to cooperative auditingIntroduction to cooperative auditing
Introduction to cooperative auditing
efferson ramirez29.3K views
Strategy Evaluation von Taher Ahmed
Strategy Evaluation Strategy Evaluation
Strategy Evaluation
Taher Ahmed100.6K views
Xybion - best practices for audit management - final von Xybion Corporation
Xybion -  best practices for audit management - finalXybion -  best practices for audit management - final
Xybion - best practices for audit management - final
Xybion Corporation714 views

Más de complianceonline123

Fda adverse event reporting requirements for otc drugs von
Fda adverse event reporting requirements  for otc drugsFda adverse event reporting requirements  for otc drugs
Fda adverse event reporting requirements for otc drugscomplianceonline123
1K views10 Folien
Social media risks rules policies procedures von
Social media risks rules policies  proceduresSocial media risks rules policies  procedures
Social media risks rules policies procedurescomplianceonline123
474 views11 Folien
Fmla ada overlap von
Fmla  ada  overlapFmla  ada  overlap
Fmla ada overlapcomplianceonline123
929 views14 Folien
Hipaa enforcement examples von
Hipaa enforcement examplesHipaa enforcement examples
Hipaa enforcement examplescomplianceonline123
362 views9 Folien
Excel spreadsheets how to ensure 21 cfr part 11 compliance von
Excel spreadsheets  how to ensure 21 cfr part 11 complianceExcel spreadsheets  how to ensure 21 cfr part 11 compliance
Excel spreadsheets how to ensure 21 cfr part 11 compliancecomplianceonline123
6.3K views8 Folien
Retail loss von
Retail lossRetail loss
Retail losscomplianceonline123
1.3K views18 Folien

Más de complianceonline123(20)

Fda adverse event reporting requirements for otc drugs von complianceonline123
Fda adverse event reporting requirements  for otc drugsFda adverse event reporting requirements  for otc drugs
Fda adverse event reporting requirements for otc drugs
Excel spreadsheets how to ensure 21 cfr part 11 compliance von complianceonline123
Excel spreadsheets  how to ensure 21 cfr part 11 complianceExcel spreadsheets  how to ensure 21 cfr part 11 compliance
Excel spreadsheets how to ensure 21 cfr part 11 compliance
complianceonline1236.3K views
Out in the open protecting your privacy in the digital age von complianceonline123
Out in the open  protecting your privacy in the digital ageOut in the open  protecting your privacy in the digital age
Out in the open protecting your privacy in the digital age
Reaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s Potential von complianceonline123
Reaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s PotentialReaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s Potential
Reaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s Potential

Último

TQM ASSIGMENT 3.pdf von
TQM ASSIGMENT 3.pdfTQM ASSIGMENT 3.pdf
TQM ASSIGMENT 3.pdfد حاتم البيطار
11 views11 Folien
3rd lecture PCR-Presentation.ppt von
3rd lecture PCR-Presentation.ppt3rd lecture PCR-Presentation.ppt
3rd lecture PCR-Presentation.pptgayubshah
6 views31 Folien
Obesity.pdf von
Obesity.pdfObesity.pdf
Obesity.pdfRutvikunvar Raualji (PT)
112 views30 Folien
Explore new Frontiers in Medicine with AI.pdf von
Explore new Frontiers in Medicine with AI.pdfExplore new Frontiers in Medicine with AI.pdf
Explore new Frontiers in Medicine with AI.pdfAnne Marie
12 views31 Folien
PATIENTCOUNSELLING in.pptx von
PATIENTCOUNSELLING  in.pptxPATIENTCOUNSELLING  in.pptx
PATIENTCOUNSELLING in.pptxskShashi1
26 views16 Folien
Nidanarthakara Roga.pptx von
Nidanarthakara Roga.pptxNidanarthakara Roga.pptx
Nidanarthakara Roga.pptxAkshay Shetty
38 views23 Folien

Último(20)

3rd lecture PCR-Presentation.ppt von gayubshah
3rd lecture PCR-Presentation.ppt3rd lecture PCR-Presentation.ppt
3rd lecture PCR-Presentation.ppt
gayubshah6 views
Explore new Frontiers in Medicine with AI.pdf von Anne Marie
Explore new Frontiers in Medicine with AI.pdfExplore new Frontiers in Medicine with AI.pdf
Explore new Frontiers in Medicine with AI.pdf
Anne Marie12 views
PATIENTCOUNSELLING in.pptx von skShashi1
PATIENTCOUNSELLING  in.pptxPATIENTCOUNSELLING  in.pptx
PATIENTCOUNSELLING in.pptx
skShashi126 views
FAT ATER SOND WALUBLE VITAMINS von BeshedaWedajo
FAT ATER SOND WALUBLE VITAMINS  FAT ATER SOND WALUBLE VITAMINS
FAT ATER SOND WALUBLE VITAMINS
BeshedaWedajo7 views
Fetal and Neonatal Circulation - MBBS, Gandhi medical College Hyderabad von Swetha rani Savala
Fetal and Neonatal Circulation - MBBS, Gandhi medical College Hyderabad Fetal and Neonatal Circulation - MBBS, Gandhi medical College Hyderabad
Fetal and Neonatal Circulation - MBBS, Gandhi medical College Hyderabad
Diagnosis of tumor.ppt von Sekaran T
Diagnosis of tumor.pptDiagnosis of tumor.ppt
Diagnosis of tumor.ppt
Sekaran T6 views
Save 20% on our supplements for kids von novaferrum
Save 20% on our supplements for kidsSave 20% on our supplements for kids
Save 20% on our supplements for kids
novaferrum7 views
Top Ayurvedic PCD Companies in India Riding the Wave of Wellness Trends von muskansbl01
Top Ayurvedic PCD Companies in India Riding the Wave of Wellness TrendsTop Ayurvedic PCD Companies in India Riding the Wave of Wellness Trends
Top Ayurvedic PCD Companies in India Riding the Wave of Wellness Trends
muskansbl0143 views
Cholera Romy W. (3).pptx von rweth613
Cholera Romy W. (3).pptxCholera Romy W. (3).pptx
Cholera Romy W. (3).pptx
rweth61354 views
When HER2 Is Low or Negative: Emerging Evidence on Antibody-Drug Conjugates f... von PeerVoice
When HER2 Is Low or Negative: Emerging Evidence on Antibody-Drug Conjugates f...When HER2 Is Low or Negative: Emerging Evidence on Antibody-Drug Conjugates f...
When HER2 Is Low or Negative: Emerging Evidence on Antibody-Drug Conjugates f...
PeerVoice6 views

Audit Process: How to Successfully Plan Audit

  • 2. As defined by the Institute of Internal Auditors (IIA), internal audit is “an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.”
  • 3. First-Party Audits: These are performed within an organization to measure its strengths and weaknesses against its own procedures or methods and/or external standards. Internal audits are first-party audits and are conducted by auditors who are employed by the company being audited, but have no vested interest in the audit results of the area(s) being audited. Second-Party Audits: These are external audits performed on a supplier by a customer or by a contracted firm (consulting firm) on behalf of a customer. Third-Party Audits: These are external audit performed on a supplier or regulated entity by an external participant other than a customer. They are conducted for recognition or registration purposes are performed either by Extrinsic Regulatory (FDA, FAA, NRC, USDA) or Registrars (ISO9001, AIB, JCAHCO ).
  • 4. Plan •Establishing the Audit Program •Objectives and extent of audit •Responsibilities, resources, and procedures related to the audit program Do •Implementing the Audit Program •Scheduling audits and selecting the audit team •Directing audit activities and maintaining records Check •Monitoring the Audit Program •Monitoring and reviewing the audit program •Identifying needs for corrective and preventive actions Act •Improvement •Improving the Audit Program •Identifying needs for continual improvement
  • 5. During the planning phase, the following has to be done:  The purpose of the audit  A complete description of the GRC program. This should include details such as the entity which is to be audited and the key measures of the program  The scope of the audit and the scope exclusions  The objective of the audit and the approach to be taken  A high level schedule of the audit and a detailed timeline  The necessary skills needed to complete the audit  The selection of members of the internal audit team  Any other resources required for successful completion of the audit  Document management and archival/ retention policies and processes
  • 6.  Defining the scope of the audit and its objectives is an important part of planning the process, ensuring that the audit is carried out successfully.  In order to conduct a successful GRC program audit, the auditors need to have a thorough understanding of the following:  The organization’s culture, business, strategic goals and objectives  Key risks that the program and the organization face  The organization and structure of the GRC program and its future evolution  Auditors must determine the following:  The major operational processes  Various initiatives being implemented within the organization  The IT systems that support the operation of the GRC program
  • 7. An audit of a GRC program should have the following objectives:  Evaluate the “tone at the top” – Is it proper and effective in promoting a culture that is ethical and compliant?  Check if the program provides reasonable assurance of compliance with organizational policies and all applicable laws and regulations.  Determine if the motivation/incentive/reward system is well planned and structured.  Determine if the GRC program has a robust management framework that is well documented and has enough resources to carry out its tasks.  Check whether the GRC program has been implemented and if the program’s performance reporting system accurately represented the end results of the program’s efforts.  Conduct a cost-benefit analysis of the GRC program.  Determine whether the program is up-to-date with prevailing industry practices and is adequate for the size and complexity of the organization.  Include other audit objectives that the board or management has requested.
  • 8. Want to learn more about audit, its process and best practices for auditing? ComplianceOnline webinars and seminars are a great training resource. Check out the following links:  Risk Based Internal Auditing (RBIA)  Internal Auditing Essentials for Medical Device Manufacturers  How to Audit GRC Programs?  Role of the Audit Committee in Corporate Governance  Internal Audit's Role in Enterprise Risk Management  OCEG Approved GRC (Governance, Risk and Compliance) Professional Seminar  Auditing Technology and IT Investment Management

Hinweis der Redaktion

  1. Narration: The audits of a GRC program have to be planned well in advance so they are executed effectively. <Read text as it is>
  2. Narration: <Read text as it is>
  3. Narration: <Read text as it is>