中文

Insight · Internal Audit & Assurance

Scoping a first internal audit in a mid-market group

The reason a first internal audit disappoints is rarely weak testing. It is a scope decided by convenience rather than by risk.

21 September 2026Internal Audit5 min read
This article describes professional practice in scoping an internal audit. It is general information, not professional advice for a particular organisation.

The most common reason a first internal audit disappoints is not weak testing. It is scope decided by convenience rather than by risk: the audit lands on the processes whose owners happened to be available, produces findings those owners already knew about, and is not repeated.

For a mid-market group — one with several entities, a lean finance function and no dedicated audit team — the first review has a second job beyond its findings. It has to prove to the board and the owners that the function is worth having.

Start with what can actually go wrong

Before writing a scope, hold short conversations with management and the board and ask a single question: where would a loss hurt most? Not "what are our risks" in the abstract, but which of these would materially damage the business within a year — a cash-handling process with one person controlling it end to end, a supplier paid in advance across a border, a revenue stream recognised on a spreadsheet, an entity nobody consolidates in practice. Rank them.

Then be honest about a constraint that mid-market groups face: if the same small team performs the process and would be audited on it, the audit's independence depends on how it reports, not on the org chart. Report to the board or the owners directly, and say so in the terms of reference.

Scope by process, not by department

Departments are political boundaries; processes cross them. "Order to cash" or "procure to pay" gives you a scope you can walk from end to end, which is also the only way to see where a control is duplicated or missing at the seam. Write the scope as a list of processes with their boundaries made explicit — where each starts, where it ends, and what is deliberately excluded.

Set the exclusion list in writing and have it approved. Scope creep in a first audit is usually the product of an undocumented exclusion, and it is what turns a six-week review into a four-month one.

Test design first, then operation

For each key control, ask two separate questions. Is it designed to prevent or detect the risk it is supposed to address? And does it actually operate that way — every time, and can you prove it? Many first audits collapse these two and end up describing the policy rather than the practice. For operating effectiveness, define your sample size before you start and pick your selections from a complete population, not from what is easiest to retrieve.

Write findings that someone can act on

A finding without a cause becomes a complaint. Use the same four-part structure every time: observation (what you saw, with the evidence), risk (what could happen, and roughly how bad), recommendation (what to do), and management response with an owner and a date. Sort by severity, not by the order you happened to test things.

Keep the language of the report in proportion to the evidence. An audit that phrases a minor documentation gap in the same terms as a control failure trains readers to ignore severity ratings altogether.

Make follow-up part of the scope

Agree at the planning stage when management actions will be tracked and how the board hears about overdue ones. A first audit followed by no follow-up teaches an organisation that the exercise is optional, and the second audit starts from a weaker position than the first.

A scope that earns a second year

If you keep the first review to two or three high-risk processes, test design and operation separately, and report in a consistent format with owners and dates attached, the outcome is a board that can see what changed since last time. That is the argument for the second year — and it is made by the first year's report, not by the terms of reference.

Ask about internal audit support