A
AcadiFi
CO
ControlsPlannerAri2026-05-20
ciaCIA Part 2Engagement PlanningInternal Control

Where should an auditor begin a full-company internal control audit?

51 upvotes
AcadiFi TeamVerified Expert
AcadiFi Certified Professional

Begin by defining the engagement objective and scope. "Full-company controls audit" is too broad unless it is translated into a specific purpose, such as documentation, design assessment, operating effectiveness testing, or readiness review. Once the objective is clear, perform a risk assessment to decide which processes deserve first-wave coverage.

The next step is process mapping. Identify major processes, owners, objectives, risks, systems, evidence, and existing controls. Then perform walkthroughs before testing. Walkthroughs show whether the controls are real, assigned, evidenced, and connected to the risk.

For the CIA exam, the strongest answer starts with scope and risk. It does not jump straight into sample testing or try to document every control in the company with equal depth.

🔍

Master CIA Part 2 with our CIA Course

45 lessons · 90+ hours· Expert instruction

#internal-control-audit#scoping#risk-assessment#audit-plan