Document

Simplify Your Tax & Accounting - The Right Way

From corporate tax registration to audits and bookkeeping, Young & Right offers personalized solutions that keep your business compliant and stress-free. Let’s take the complexity off your plate—starting with a free consultation.

Book Your Free Consultation

Internal Audit Process: Planning, Testing, Reporting and Follow-Up

Author 1
Written By Fayas Ismail,
Published on September 2, 2026
Internal Audit Process: Planning, Testing, Reporting and Follow-Up

An effective internal audit follows four principal stages: planning, testing, reporting and follow-up. During planning, auditors define the objectives, scope, risks and audit procedures. Testing determines whether controls are properly designed and operating effectively. Reporting communicates evidence-based findings and agreed actions. Follow-up confirms whether management has implemented those actions.

For UAE businesses, a structured internal audit can identify control weaknesses, reduce operational and financial risks, improve compliance and provide management with reliable information for decision-making.

Key Takeaways

  • Internal auditing evaluates governance, risk management and internal controls.
  • A risk-based plan focuses resources on the areas that matter most.
  • Testing should be supported by sufficient, reliable and relevant evidence.
  • Audit findings should explain the condition, criteria, cause, risk and required action.
  • An internal audit is not complete when the report is issued; corrective actions must be monitored.
  • Internal auditing does not replace an external statutory audit.

What Is an Internal Audit?

An internal audit is an independent and objective review of an organization’s processes, risks and controls. Its purpose is to help the organization protect value, improve operations and achieve its objectives.

An internal audit may examine:

  • Revenue and customer collections
  • Purchasing and supplier payments
  • Bank and cash controls
  • Payroll
  • Inventory
  • Fixed assets
  • Information-system access
  • VAT and Corporate Tax processes
  • Regulatory compliance
  • Related-party transactions
  • Data protection
  • Fraud risks
  • Business continuity
  • Management reporting

The precise scope depends on the company’s industry, size, risk profile and management concerns.

The Institute of Internal Auditors’ Global Internal Audit Standards provide the international professional framework for internal auditing. The current Standards were issued in 2024 and became effective on 9 January 2025. They organize internal audit practice around governance, ethics, management of the function and performance of internal audit services. The Institute of Internal Auditors

The Four Stages of the Internal Audit Process

Stage Primary purpose Main output
Planning Define the risks, objectives and scope Approved audit plan and work program
Testing Evaluate controls and supporting evidence Documented test results and potential findings
Reporting Communicate conclusions and agreed actions Final internal audit report
Follow-up Confirm that issues have been addressed Follow-up status report

Although shown as separate stages, communication with management should continue throughout the audit.

Stage 1: Internal Audit Planning

Planning establishes what the audit will cover, why the review is necessary and how the work will be performed.

A poorly planned audit may test areas that have little relevance while missing the risks that could materially affect the business.

1. Understand the business and process

The internal auditor begins by understanding the activity being reviewed. This may involve:

  • Interviewing process owners
  • Reviewing policies and procedures
  • Examining organizational charts
  • Understanding systems and data flows
  • Reviewing earlier audit findings
  • Identifying applicable laws and contractual obligations
  • Performing walkthroughs of key transactions
  • Examining management reports and performance indicators

For example, when auditing procurement, the auditor needs to understand the complete process—from requesting a purchase and selecting a supplier to approving the invoice and releasing payment.

2. Perform a risk assessment

The auditor identifies events that could prevent the process from achieving its objectives.

Common risks include:

  • Unauthorized payments
  • Duplicate supplier invoices
  • Revenue not recorded completely
  • Inventory theft or misstatement
  • Incorrect VAT treatment
  • Excessive user access
  • Payments to fictitious employees
  • Missing supporting documents
  • Unreliable management reports
  • Failure to comply with internal policies

Risks are normally evaluated by considering their likelihood and potential impact.

Higher-risk areas should receive more audit attention. This is why a risk-based internal audit is generally more useful than applying the same checklist to every business.

3. Define the audit objectives and scope

Audit objectives explain what the engagement is intended to determine.

An objective might be:

To assess whether purchasing and payment controls are adequately designed and operating effectively to prevent unauthorized, duplicate or unsupported payments.

The scope should identify:

  • Business units included
  • Locations included
  • Systems examined
  • Audit period
  • Processes covered
  • Specific exclusions

Clear scope boundaries reduce misunderstandings and prevent uncontrolled expansion of the engagement.

4. Establish evaluation criteria

Auditors need appropriate criteria against which actual performance can be evaluated.

Criteria may include:

  • Approved company policies
  • Delegation-of-authority limits
  • Contracts
  • Regulatory requirements
  • Accounting policies
  • System configurations
  • Industry practices
  • Defined control procedures

A finding should not be based solely on personal preference. There must be a reasonable basis for concluding that the observed condition is inappropriate or exposes the business to unnecessary risk.

5. Prepare the audit work program

The work program lists the procedures required to achieve the audit objectives. It may include:

  • Interviews
  • Document inspection
  • Transaction sampling
  • System-access review
  • Data analysis
  • Reperformance
  • Observation
  • Balance reconciliation
  • Process walkthroughs

The IIA’s standards on performing internal audit services address risk assessment, engagement objectives, scope, evaluation criteria, resources and documented work programs. Global Internal Audit Standards

6. Hold an opening meeting

The auditor discusses the engagement with management and relevant employees.

The opening meeting usually covers:

  • Audit objectives
  • Scope and period
  • Required documents
  • Key contacts
  • Expected timeline
  • Communication process
  • Reporting arrangements
  • Known challenges or recent changes

Early communication helps establish cooperation and reduces delays during fieldwork.

Stage 2: Audit Testing and Fieldwork

During testing, the auditor gathers and evaluates evidence to determine whether controls are appropriately designed and operating effectively.

Design effectiveness versus operating effectiveness

These are different questions.

Design effectiveness asks whether the control, if followed correctly, is capable of addressing the identified risk.

Operating effectiveness asks whether the control was actually performed consistently by the right person during the period reviewed.

For example, a company policy may require two approvals for payments above AED 25,000. The control may be well designed, but it is not operating effectively if payments are regularly processed with only one approval.

Common internal audit testing methods

Inspection

The auditor examines invoices, contracts, approvals, bank records, reconciliations and other supporting documents.

Observation

The auditor watches employees perform a procedure, such as counting inventory or handling petty cash.

Inquiry

Employees and managers are asked how a process works. Inquiry is valuable, but verbal explanations should usually be supported by other evidence.

Reperformance

The auditor independently performs a control or calculation to determine whether the original result was correct.

Data analysis

A complete transaction population may be analyzed to identify:

  • Duplicate payments
  • Unusual transaction values
  • Weekend postings
  • Repeated round-number payments
  • Transactions above approval limits
  • Dormant or duplicate suppliers
  • Changes to bank details
  • Gaps in invoice sequences

Sampling

When examining every transaction is impractical, the auditor selects a sample.

The sample should reflect the audit objective and the characteristics of the population. High-value, unusual and high-risk transactions may be selected separately from a representative sample.

What makes good audit evidence?

Audit evidence should be:

  • Relevant to the audit objective
  • Reliable
  • Sufficient to support the conclusion
  • Properly documented
  • Traceable to its source

An unsupported allegation should not become an audit finding. Auditors must distinguish between confirmed facts, management explanations and matters requiring further investigation.

Developing audit findings

A well-structured finding normally explains:

  1. Condition: What did the auditor identify?
  2. Criteria: What should have happened?
  3. Cause: Why did the problem occur?
  4. Risk or effect: What could result from the weakness?
  5. Recommendation or action: What should be done?
  6. Owner and deadline: Who will act, and by when?

Practical example

Condition: Nine of 25 supplier payments tested did not contain documented approval.

Criteria: The company’s payment policy requires approval from the finance manager before payment release.

Cause: Approval was provided through informal messages that were not retained.

Risk: The company may process unauthorized or unsupported payments.

Recommended action: Introduce approval through the accounting or banking workflow and retain an electronic audit trail.

This structure makes the finding clear, actionable and easier to verify during follow-up.

Discuss findings before reporting

Potential findings should be discussed with process owners during fieldwork. This allows management to:

  • Correct factual inaccuracies
  • Provide missing evidence
  • Explain the root cause
  • Assess the practical consequences
  • Suggest an appropriate corrective action

Discussion does not mean that management can remove a valid finding merely because it is uncomfortable. The final conclusion should remain objective and evidence-based.

Stage 3: Internal Audit Reporting

The internal audit report communicates the results to management, the board or those responsible for governance.

A useful report should be clear enough for a reader who was not involved in the fieldwork.

What should an internal audit report contain?

A typical report includes:

  • Executive summary
  • Audit objectives and scope
  • Period reviewed
  • Methodology
  • Overall conclusion
  • Key findings
  • Risk ratings
  • Recommendations
  • Management responses
  • Agreed action owners
  • Implementation deadlines
  • Scope limitations, if any

The IIA identifies final engagement communication and monitoring action plans as core parts of performing internal audit services. Its supporting reporting resources are intended to assist with clear communication of engagement results. IIA audit-report resource

How should findings be rated?

Organizations may use ratings such as:

  • Critical
  • High
  • Medium
  • Low

The rating should reflect clearly defined criteria, including:

  • Financial exposure
  • Regulatory impact
  • Operational disruption
  • Fraud potential
  • Data or cybersecurity consequences
  • Likelihood of occurrence
  • Existing mitigating controls

A dramatic label without defined criteria can reduce trust in the report. Consistency matters more than the names assigned to the ratings.

Recommendations should address root causes

A recommendation should do more than correct one transaction.

If an invoice was paid twice, recovering the duplicate payment addresses the immediate error. The underlying issue may still remain—for example, the accounting system allows duplicate invoice numbers, or employees do not review the supplier ledger before payment.

An effective action should reduce the likelihood of the problem recurring.

Management action plans

Management should provide:

  • Its response to the finding
  • The corrective action
  • The responsible person
  • A realistic deadline
  • Any accepted residual risk

Internal auditors may recommend solutions, but management remains responsible for designing and implementing operational controls.

Stage 4: Follow-Up and Monitoring

Follow-up determines whether management implemented the agreed action and whether the action addressed the identified risk.

A finding should not be closed merely because its deadline has passed or management states that it has been completed.

What happens during follow-up?

The auditor may:

  • Request updated policies
  • Inspect system screenshots
  • Review approval records
  • Retest transactions
  • Confirm revised user access
  • Examine reconciliation reports
  • Interview responsible employees
  • Verify that the control has operated for a reasonable period

The amount of testing should be proportionate to the risk. A high-risk finding normally requires stronger evidence than a low-risk administrative issue.

Follow-up status categories

Common categories include:

  • Implemented
  • Partially implemented
  • In progress
  • Overdue
  • Not implemented
  • Risk accepted
  • No longer applicable

Any risk acceptance should be approved at an appropriate level of authority.

Why follow-up is essential

Without follow-up:

  • Findings may remain unresolved
  • Temporary fixes may be mistaken for permanent solutions
  • Deadlines may repeatedly move
  • Management may not know its remaining risk exposure
  • Similar problems may recur

The IIA’s Standard 15.2 addresses confirming the implementation of recommendations or management action plans. Follow-up therefore forms part of a complete internal audit process—not an optional administrative exercise. Complete Global Internal Audit Standards

Common Internal Audit Mistakes

Businesses and auditors should avoid:

  • Using a generic checklist without assessing risk
  • Defining an unclear or excessively broad scope
  • Relying only on verbal explanations
  • Failing to document evidence
  • Reporting findings before confirming the facts
  • Giving recommendations that are impractical
  • Ignoring the underlying cause
  • Assigning actions without an owner or deadline
  • Closing findings without verification
  • Allowing the person responsible for a process to audit their own work

Independence and objectivity are essential. If an auditor designed or operates the process being reviewed, safeguards may be required.

Internal Audit vs External Audit

Internal audit External audit
Reviews risks, controls and operations Primarily examines financial statements
Scope can be tailored to business priorities Scope follows applicable reporting and auditing requirements
May be conducted throughout the year Commonly performed annually
Reports to management or those charged with governance Provides an independent auditor’s report
Focuses on improvement and risk management Focuses on the financial-statement audit objective

An internal audit does not replace an external statutory audit when an external audit is required.

How Often Should a UAE Business Conduct an Internal Audit?

There is no single frequency suitable for every company. The schedule should reflect risk.

High-risk areas may require quarterly or continuous review. Lower-risk processes may be reviewed annually or through a multi-year audit cycle.

A review may also be appropriate following:

  • Rapid business growth
  • Implementation of new software
  • Acquisition or restructuring
  • Significant employee turnover
  • Suspected fraud
  • Repeated accounting errors
  • Expansion into a new market
  • A major regulatory change
  • Weaknesses identified by an external auditor

Internal Audit Services from Young and Right

Young and Right supports businesses in Dubai and across the UAE with risk-focused internal audit services.

Our internal audit support can include:

  • Process and risk assessment
  • Internal-control reviews
  • Procurement and payment audits
  • Revenue and collection reviews
  • Payroll audits
  • Inventory and fixed-asset reviews
  • VAT and Corporate Tax process reviews
  • Financial-reporting control reviews
  • Audit findings and recommendations
  • Corrective-action follow-up

The audit scope should be tailored to the company’s activities, systems, risks and management priorities.

Contact Young and Right to discuss an internal audit plan designed around your business.

 


Akshaya Ashok
Reviewed By
Fahadh Ismail

FAQ

The four main stages are planning, testing, reporting and follow-up. Planning defines the risks and scope, testing evaluates controls, reporting communicates findings, and follow-up verifies corrective action.
The duration depends on the scope, number of locations, transaction volume, system complexity, availability of documents and cooperation from employees. A focused review may take a few weeks, while a company-wide engagement may require considerably longer.
Documents may include policies, organization charts, ledgers, invoices, contracts, bank statements, approval records, payroll files, inventory reports, system-access lists and previous audit reports. Requirements depend on the process being audited.
Not every UAE business is required to maintain an internal audit function. Requirements may depend on the entity’s legal form, regulator, industry or governance arrangements. Even when it is not mandatory, internal auditing can help management identify risks and strengthen controls.
The unresolved finding should remain open and be reported to the appropriate level of management or governance. Management may implement another suitable control or formally accept the residual risk through the organization’s authorized risk-acceptance process.

Need Help With Internal Audit?

Get expert support to strengthen controls, identify risks and improve your business processes.

Talk to an Audit Expert