Audit - Fault Finding or Issuing Opinion?

Audit - Fault Finding or Issuing Opinion?

One question I hear often is, "Is audit just about finding mistakes?" It’s a common misconception. From my experience, audit goes much deeper than fault-finding.

When I worked as an internal auditor for a tech company, the focus was always on improving the organization.

My job was to look at technology systems, identify risks, and suggest ways to strengthen processes.

For example, if I found that certain users had inappropriate access to systems, it wasn’t just about pointing out the issue.

I worked with the team to find solutions, ensuring we aligned with the organization's goals.

The role was very hands-on, aimed at helping the business get stronger and more secure over time.

Now, as an external auditor, my role has shifted. It’s no longer about helping the organization improve but about providing an independent, unbiased assessment.

My job is to test controls, check if they are designed to address risks, and evaluate their effectiveness. I issue an opinion based on the evidence provided. Unlike internal audit,

I don't give recommendations or solutions. Staying independent is critical here—giving advice could compromise that independence.

Our main job is to provide assurance, not to guide on improvements.

Here’s the bottom line: Internal audit focuses on supporting the business from within, helping it achieve its goals.

External audit, on the other hand, provides an outside view, ensuring that the organization’s controls are working as intended without crossing the line into consulting.


One Thing I Learned This Week

This week, I had a discussion with my senior about some updates I made to work papers after their review.

While addressing the feedback, I also made a few other changes I thought were necessary.

These updates were correct, but I realized something important.

"How would my senior know about the extra changes if they weren’t part of their original comments?"

Here’s the takeaway: always communicate your updates clearly.

If you make changes that aren’t directly related to the reviewer’s comments, add a note or comment in your work paper explaining what you updated and why.

If you're using Excel, take advantage of its commenting feature.

It only takes a couple of minutes but can save time and confusion for whoever is reviewing your work.

A small habit like this goes a long way in keeping things transparent and making collaboration smoother.


CISA Question Clarification: Audit Charter vs. Engagement Letter

In a recent poll, 59% of voters correctly selected the Engagement Letter as the document that covers the scope of an audit for a particular exercise. However, 31% of participants mistakenly chose the Audit Charter, so let's clarify the distinction.

The Correct Answer: Engagement Letter

The Engagement Letter is specific to each audit engagement. It outlines the audit activities, scope, and objectives for a particular audit exercise. This document is akin to a chapter-wise test in school, where the test focuses on questions for a specific chapter. It helps auditors and the audited entity agree on what will be covered in that specific audit.

Why Not the Audit Charter? The Audit Charter is a broader document. It defines the overarching authority, responsibility, and scope of the internal audit function for the organization. This is like your final exam in school, which covers multiple chapters or subjects, detailing the broader scope of your education.

Conclusion For CISA exams and professional audits, always remember that while the Audit Charter gives you the overall mission, the Engagement Letter focuses on the specifics of a single audit engagement.

This distinction is key in answering this type of question correctly.

Thanks for reading, and hit me up if you have any other questions!

Until next time,

Signing Off

Chinmay Kulkarni


Thank you for being a part of our IT auditing community! Elevate your IT Audit game by following me on LinkedIn.

Want to learn IT Audit for FREE? Click here

Let's continue this journey together.

Tanushree Bhattacharjee

Business Operations Manager - Risk & Change, PMP®

4mo

Great post Chinmay Kulkarni! Great explanation of the key difference between Internal Audit and External Audit. I wanted to know from you basis your experience what are the key skills that one needs to become an auditor (both internal and external)?

Like
Reply
VENUGOPAL G

Senior Risk Analyst,Expertise in GRC ,Vmware and cloud.

4mo

Nice initiative Chinmay Kulkarni, you are touching unique topics.

Like
Reply
Himanshu Jha

Cybersecurity Specialist🔸 MBA | MSc | CDPSE | CCSP | CISSP | CISM | CRISC | CISA | ISO 27001LA | CEH | CFE

4mo

Great Initiative Chinmay Kulkarni , wishing you continued success.

To view or add a comment, sign in

More articles by Chinmay Kulkarni

  • Issue #3 Clarity with Chinmay

    Issue #3 Clarity with Chinmay

    What's Next in Access Control Testing? Welcome to another edition of Clarity with Chinmay! Last time, we kicked off our…

  • Issue #43

    Issue #43

    Understanding IT Application Controls (ITAC): My Key Learnings In the world of IT audit, IT Application Controls…

    5 Comments
  • Top 10 Questions for Access Control Walkthroughs - Part 1

    Top 10 Questions for Access Control Walkthroughs - Part 1

    Let's discuss the ten essential access control questions you should ask during your next audit. Access control is a…

    5 Comments
  • How to Conduct Effective IT Audits?

    How to Conduct Effective IT Audits?

    In this newsletter, we're diving into a topic critical for both seasoned auditors and those just starting their audit…

    1 Comment
  • The #1 Habit That Separates Top Auditors

    The #1 Habit That Separates Top Auditors

    Today's newsletter is one of the most important I've written on any topic. Understanding this topic will set you for…

    1 Comment
  • Top 3 Considerations when evaluating IT Application Controls

    Top 3 Considerations when evaluating IT Application Controls

    Do you know the top three key considerations when evaluating IT application controls? This newsletter dives into the…

    2 Comments
  • ITGC - Job Scheduling & Monitoring

    ITGC - Job Scheduling & Monitoring

    Remember the satisfaction of receiving your paycheck on time, every other Friday? It might seem like magic, but a…

    4 Comments
  • The Two-Step Secret for Control Assessment

    The Two-Step Secret for Control Assessment

    What is the 2-step approach for evaluating a control? A large part of IT Auditor's job involves assessing the…

    3 Comments
  • Top 10 Audit Interview Questions You Shouldn't Miss (Part 1)

    Top 10 Audit Interview Questions You Shouldn't Miss (Part 1)

    Can you walk me through your resume? We've all been there: staring at a blank page, trying to craft the perfect…

    1 Comment
  • What Does an IT Auditor Do?

    What Does an IT Auditor Do?

    Audit an IT system? What do these folks even do with IT? Hey LinkedIn, welcome to Issue #34 of the "Chinmay's IT Audit…

    7 Comments

Insights from the community

Others also viewed

Explore topics