What should an internal financial audit checklist contain?

Applies to: United States · Updated 2026-09-27

An internal financial audit checklist is a work program that tests controls, not bookkeeping chores. It starts from a signed charter naming who commissions the audit, who leads it and who receives the report. It records a risk-based scope and exclusions, follow-up on last period's findings, then lines for each cycle: control objective, test step, population and sample, evidence, result and exception. Findings carry a cause, rating, owner and due date. It reports on controls, never on financial statements.

What is an internal financial audit, and who sets it up?

The Institute of Internal Auditors (IIA) Global Internal Audit Standards define internal auditing as an independent, objective assurance and advisory service designed to add value and improve an organization's operations. They say the audit receives its mandate (its authority, role and responsibilities) from the board, documented in an internal audit charter the board approves, and that the chief audit executive's responsibilities are performed by individuals the board designates. Without a board, the Standards read "board" as the person or group acting as the highest-level governing body, such as the head of the organization: usually the owner.

Before the pass, have the owner or board sign a one-page charter that names the audit lead, grants access to records, systems and people, says who receives the report and records any other role the lead holds; the IIA's charter guidance lists unrestricted access to data, records, information, personnel and physical properties. That lead carries the chief audit executive's duties below.

The audit tests whether financial controls work as intended. The AICPA's SAS No. 128 says the external auditor has sole responsibility for the audit opinion, and that internal auditors are not independent of the entity as an external auditor must be. It treats procedures like internal audit work as control activities unless an objective, competent function applying a systematic, disciplined approach, including quality control, performs them. An external auditor would therefore treat a controller's monthly review, or a pass that lacks those qualities, as a control activity rather than internal audit work. Your own pass must meet the IIA Standards, which apply to anyone providing internal audit services.

The IIA's glossary says internal auditors may provide limited or reasonable assurance, depending on the nature, timing and extent of procedures. The report says which, covers only the cycles and period tested, and lets a sampled line speak for the whole period only where the line is marked projected. It is not an opinion on the financial statements and does not show that no fraud occurred. Before it goes outside the organization, the Standards require the lead to seek the advice of legal counsel and/or senior management as required, unless laws or regulations require or restrict otherwise.

The Standards' guidance says stating that an engagement conformed with the Standards is appropriate only if engagement supervision and a quality assurance and improvement program support it, and a one-member function needs outside help for that program. Without both, make no such claim. Where work departs from the Standards, they require the report to disclose the standard not met, the reason and the impact on findings and conclusions.

Who can perform it without auditing their own work?

The IIA Standards require auditors to refrain from assessing activities they were previously responsible for, presume objectivity impaired for assurance on an activity they were responsible for within the previous 12 months, and require an impairment in fact or appearance to be disclosed promptly to the appropriate parties. The guidance says those performing and supervising the work should be independent of the activity. The performer decides what the report shows:

Who performsWhat the checklist and report show
An internal person independent of the processEach line records no responsibility for the area in the previous 12 months.
An outside practitioner engaged for the internal workThe Standards apply to contracted auditors too; the work reports to the owner or board and stays internal.
Someone involved in the processThe impairment is disclosed, their own work goes to another performer, and the report states each limitation as a nonconformance.

What if no one is fully independent?

Any line testing a control the performer operates, approves or can override needs another performer. The Standards' guidance lists options for an unavoidable impairment: reassigning auditors, rescheduling, adjusting the scope, or outsourcing performance or supervision. If the lead has other ongoing roles, such as controller, the Standards require those roles and their safeguards to be documented in the charter and, where those areas are audited, alternative assurance, such as an objective, competent external provider reporting independently to the board.

How do you choose what this pass covers?

The IIA Standards require auditors to understand the activity to assess its risks, considering risks related to fraud; the guidance prioritizes risks by likelihood and potential impact. Rate each cycle on both (for example volume, cash exposure, recent changes, open findings) and start with the highest.

The Standards require documented objectives and scope for each engagement, the scope specifying the activities, locations, processes, systems, components and time period covered, and the lead must approve them and any changes. The guidance says assurance scope is set primarily by the internal auditors, and that stakeholder requests to include or exclude items may be scope limitations: if an owner or board member who runs or approves a cycle asks to exclude it, record a scope limitation. The Standards require scope limitations to be discussed with management and, if unresolved, raised with the board.

The cover page records the charter date, the lead, the cycles and period with reasons, exclusions with reasons, scope limitations and each performer's relationship to the areas tested. For the annual plan, the Standards require the lead to tell the board and senior management why any high-risk area was left out. Rotate lower-risk cycles through later passes so coverage accumulates.

What goes on each checklist line?

The IIA Standards require a documented work program identifying the criteria for evaluating each objective, the tasks, the methodologies and tools, and the auditors assigned, approved by the lead before use and promptly when changed; the guidance adds who completed the work, when, and review and approval. Each line carries the columns below plus performer and reviewer initials and dates, with an objective that is either met or not.

Is the step testing design or operation?

The IIA's guidance says assurance engagements test whether controls are adequately designed and operating, and that design may be evaluated during planning. A design step (D) walks one item through and asks whether the control could meet the objective; an operation step (O) tests items from across the period. A control designed well but never performed passes D and fails O, so a design-only line records "design only", never "pass".

How much evidence, and which sample?

The IIA Standards require relevant, reliable and sufficient information: sufficient when it lets the auditor complete the analyses and could enable a prudent, informed and competent person to repeat the work program and reach the same conclusions; more reliable when obtained directly by the auditor or from an independent source, corroborated, or drawn from a well-controlled system. The guidance says a sampled program records the sampling methodology, population, sample size and whether results can be projected, with samples as representative as possible. Apply these rules to every line:

  • Build the population yourself for the whole period, recording its source and count and agreeing it to the ledger.
  • Draw it from where failure shows, such as payments rather than approved bills.
  • Before testing, fix each line's sample size (those below are illustrative) and how many exceptions fail it, and record why; the IIA's guidance says a satisfactory level could be a certain percentage of transactions done as the control requires.
  • In this checklist, any exception in an operation sample fails the line and goes to disposition.
  • Record the seed or interval, keep random and targeted items apart, and project only random results.
  • Treat a "yes, we do that" as a lead, and corroborate any record made by the person tested.

What does a checklist look like, cycle by cycle?

The objectives and steps below are this article's own illustration for a small company's January–August 2026 pass; no cited source lists them cycle by cycle, and all figures are invented. Follow-up comes first.

RefControl objectiveTest stepPopulation and sampleEvidenceResultException
F-1Finding C-2 (2025): bank reconciliations signed by a reviewer within 10 business days; July 2025 difference correctedO: inspect sign-off dates; trace the correction to support and approvalMarch–August reconciliations, all 6; the correcting entrySigned reconciliations, entry, support, approvalPass, 6 of 6; correction supported and approvedNone; closed
R-1Receipts are deposited intact and recordedO: trace to deposit slip, bank statement and ledgerReceipt log January–August, 1,214, agreed to ledger; 25 random (seed 4417); projectedDeposit slips; statements the auditor downloadedPass, 25 of 25None
D-1Each payment matches a bill, order and receiving record, and was approved beforehand, for that amount, by someone other than the preparerO: inspect all four; compare approval date and amount with the paymentAll 612 bank payments January–August, agreed to ledger; 25 random (seed 2093), projected; all 4 over 10,000.00, not projected; no overlapBank statements obtained directly, bills, orders, receiving records, approvalsRandom: fail, 24 of 25; over 10,000.00: pass, 4 of 4D-1a: preparer approved own bill
D-2Changed payment details (vendor or employee) are confirmed before any payment to them, by someone other than who entered them, by a call or meeting through contact details held before the request, never from an invoice, the request or any messageO: compare confirmation date with first payment to the new details; trace the contact used to its origin (onboarding record or an independently confirmed change); fail where it came from a message or was changed without independent confirmation before the payment-detail changeAll 4 payment-detail and 9 contact-detail (phone, email, address) changes January–August in the system audit log and bank payment portal, extracted by the auditorLog extracts, onboarding and pre-change records, confirmation notes, payment datesPass, 4 of 4None
D-3New vendors' payment details are confirmed before first payment, by someone other than who set them up, through contact details found independently of anything the vendor sent, source recordedO: compare confirmation date with first payment; check the recorded sourceAll 5 vendors added January–August, from the audit logLog extract, confirmation notes, payment datesPass, 5 of 5None
Y-1Additions and rate changes are approved by someone independent of payroll; each person paid exists; hours paid were supervisor-approvedO: inspect each addition and rate change for that approval; agree each employee's hours to an approved timesheet and name to the owner's staff listAll 7 additions and rate changes from the audit log; pay runs of 14 February, 23 May and 1 August, 3 of 17 random (seed 881), every employee; not projectedLog extract, approvals, timesheets, owner's staff listPass, 7 of 7; 3 runs agreeNone
B-1Deliveries are billed at approved pricesO: trace to invoices and price listDelivery log January–August, 980, agreed to shipping records; every 39th from item 12 (25); not projectedInvoices, price listPass, 25 of 25None
U-1Purchases are approved before orderingO: compare approval and order datesAll 540 bills January–August, agreed to payables; 25 random (seed 7310); projectedBills, approvals, ordersPass, 25 of 25None
A-1Recorded inventory exists, and inventory held is recordedO: attend the count; test ledger to floor and floor to ledgerJune 30 listing, 1,860 lines, agreed to ledger; 20 each way random (seed 5562); not projectedCount sheets, observation notesPass, 40 of 40None
J-1Manual entries are approved by someone other than the preparer and supportedO: select by risk characteristics plus random; inspect approval and supportAll 318 manual entries (journal entries of any user, System Administration included); all 12 with risk characteristics, not projected; 15 of the other 306 random (seed 6020), projectedApprovals, supportTargeted: fail, 10 of 12; random: pass, 15 of 15J-1a: two post-close entries unsupported
C-1Closed months stay locked; later changes are approvedD: inspect the lock setting; O: search the log for changes to closed months after each closeAll 9 such changes, January–July closesLog extract, setting, approvalsPass, 9 of 9None
S-1Only current staff have access, at the level their duties need; approvers sign in with a second verification step; includes the performer's own accessD and O: compare users and roles with staff list and duty matrix; check the log for sign-ins after each leaving dateAll 14 users; all 6 access changes; all 3 connected appsUser list, role and security settings, log extractFail, 1S-1a: departed employee still active; no sign-ins after leaving; raised with the owner and access removed 15 September

D-2 and D-3 test that new or changed payment details are confirmed through a channel independent of the one they arrived by; verifying a vendor's new bank details is a separate question. Where one person enters and confirms, both lines fail on segregation and the report says so, and a payment platform that lets payees change details the business cannot see is a design exception. S-1a stays an ordinary finding only because no sign-in followed the departure.

How do you test segregation of duties and system access?

COSO's Internal Control — Integrated Framework says segregation of duties is typically built into control activities and, where it is not practical, management selects and develops alternative control activities. Build a duty matrix from role settings and practice showing who can initiate, approve, record, pay, reconcile and change master data, and flag incompatible combinations.

For small clients with limited personnel, the Journal of Accountancy's article on fraud risk in CPA firm services suggests that the owner, as well as the reconciler, receive account statements directly from the financial institution, and that the owner or another senior employee make surprise reviews of reconciliations and account activity. Test such a compensating control across the period, counting an occurrence only with evidence of how the statement reached the owner (the bank's delivery setting, or the owner's own download), the owner's dated mark and questions, and a comparison with the reconciler's copy. Checks where one person records, pays and reconciles are a separate question.

What system evidence can a step rely on?

User lists and roles, change or audit logs, transaction histories and settings such as a closed-period lock can evidence several objectives. Intuit's help page on the QuickBooks Online audit log (updated 8/4/2026) says the log tracks all account activities, including sign-ins, settings changes, edits to customers, vendors and employees, and payroll submission; shows each change's date and user; keeps events for two years; cannot be turned off; and labels changes by a QuickBooks Online support consultant "Support Representative". It says data from connected third-party apps, automatically added recurring transactions and bank-feed updates can appear as System Administration, and automatic changes related to connected bank accounts as Online Banking Administration. Keep those in the C-1 and J-1 extracts, list connected apps in S-1, and record in J-1 how manual entries were identified. Intuit's page requires admin access: have the owner grant it for the pass only, recording who granted it, when, and when it was removed. In S-1, include a log extract showing the performer made no change; if they did, C-1, S-1, D-2 and D-3 go to another performer. Run extracts yourself and record who ran each, when, its filters and period, and where it is stored; the IIA's examples of evidence include a description with its source, the date gathered and the period covered.

How are reconciliations, the close and journal entries tested as controls?

For each sampled reconciliation, test that it was done on time, by whom and reviewed by whom, with reconciling items explained and cleared. Agree its bank balance to a statement you obtain from the bank, its book balance to the ledger, and reconciling items to the next statement; that inspects what the control used without redoing it, which belongs to a bookkeeping review. For the close, test that closed periods stayed locked and later changes were approved.

The PCAOB's AS 2401, written for auditors of financial statements, lists characteristics of inappropriate entries: made to unrelated, unusual or seldom-used accounts; made by individuals who typically do not make journal entries; recorded at period end or as post-closing entries with little or no explanation or description; or containing round numbers or a consistent ending number. It adds that they may be applied to accounts prone to errors, not reconciled on time, or carrying significant estimates and period-end adjustments. Use them here as selection criteria: pull every manual entry, select all that show them, and add a random sample. An entry lacking approval by someone other than the preparer, or lacking support, is an exception; one lacking both that touches cash or owner accounts is escalated at once.

How is an exception turned into a finding?

The IIA defines a finding as the determination that a gap exists between the evaluation criteria and the condition of the activity under review. The Standards require evaluating each potential finding's significance, collaborating with management to identify root causes when possible, determining potential effects, considering likelihood and impact, and prioritizing findings under the lead's methodology; a significant risk must be documented and communicated as a finding, and other risks are reported at the auditors' determination. The guidance calls the root cause an underlying or deeper issue that contributed to the condition. Fix a rating scale, such as High, Medium and Low, before testing.

The Standards require deciding whether to develop recommendations, request action plans or agree actions that resolve the difference, mitigate the risk, address the root cause and improve the activity, and require recommendations to be discussed with management. Each exception takes one route:

RouteWhen it fits, and the evidence it needs
FindingThe control is missing or failed. Evidence: criteria, condition, root cause, effect, rating, recommendation, owner and due date.
Immediate escalationPossible fraud, a legal violation or a continuing loss. Evidence: preserved records and a dated note of facts observed and who was told when.
Closed as isolatedOnly where the exception exposes the business to no significant risk, its one-off cause is shown and an expanded sample finds no other failure. Evidence: cause, added items and reviewer sign-off, entered in the findings log; the Standards require added analyses to be approved through an adjusted work program.

D-1a is a finding, not an isolated item: it shows the process lets a preparer approve their own bill. Raise each finding with the manager who can fix it before the report, as the IIA's guidance calls for prompt discussion. For live access or a similar open exposure, tell the owner at once so it can be removed, and acknowledge the removal in the report.

What does a worked finding look like?

This 2025 finding is re-tested as F-1 above:

FieldEntry
Failed stepC-2: bank reconciliations reviewed and signed by the controller within 10 business days; operation test, all 12 months
ConditionMarch, July and November unsigned; July carried a 1,840.00 difference into August, traced to a deposit recorded twice, with no cash missing
Root causeNo backup reviewer; all three months fell during the controller's leave
EffectErrors or misappropriation in the bank account could go unnoticed for over a month
RatingHigh: likely to recur, and bears directly on cash
RecommendationName a backup reviewer; hold the close until the review is signed
Owner and due dateController; by the February 2026 close
Management responseAgreed; the controller named the finance manager as backup reviewer and will post the July correction by the same date under a closed-period approval
Re-test (2026)March–August: 6 of 6 signed on time, two by the backup; July correction traced to support; correction to closed July 2025 approved under C-1 (owner, 12 February 2026). Closed

What goes in the report, and how is management's response recorded?

The IIA Standards require each final communication to include the objectives, scope, recommendations and/or action plans if applicable, and conclusions; for assurance, also the findings with significance and prioritization, any scope limitations, and a conclusion on the effectiveness of the processes reviewed. It must name who addresses each finding and by when, acknowledge actions management has already taken, be approved by the lead before it is issued, and go to parties who can ensure due consideration; the Standards require results to reach the board and senior management. It also states the assurance level, any independence limits, and that it is not an opinion on the financial statements. Record management's response beside each finding: the guidance has management confirm its action plans, timing and personnel responsible, and allows each party's formal statement to be attached where they disagree.

Why does follow-up on last period's findings come first?

An open finding changes this pass's risk ranking, and a repeat finding is the clearest signal an internal audit gives. The IIA Standards require confirming implementation by inquiring about progress, performing follow-up assessments using a risk-based approach and updating a tracking system, scaled to each finding's significance. Re-test with the original line on a new sample from after the due date. If management misses its dates, the Standards require its explanation to be documented and discussed with the lead, who decides whether it accepted a risk beyond tolerance; such a risk must be discussed with senior management and, if unresolved, escalated to the board. Mark each prior finding closed, in progress or repeat.

What happens when a step turns up something that cannot wait?

A pass prompted by a specific concern is scoped by that concern, covering the cycles, people and period it touches, and authorized by the owner or board. Evidence is then preserved, not merely recorded: before anyone connected with the concern learns of the work, the performer takes dated copies of extracts, logs and documents, notes source, date and period, and stores them beyond the reach of those involved, who neither perform, supply nor see the work.

Escalation does not wait for the report. The IIA Standards require internal auditors who identify legal or regulatory violations to report them to individuals or entities with authority to take appropriate action, as specified in laws, regulations and applicable policies and procedures. Take the matter to the owner or board at once, bypassing anyone it involves; if it involves the owner and there is no board, stop the pass, keep the preserved evidence secure, and get legal advice on who has that authority. The Journal of Accountancy's article "Fraud is suspected: Now what?" warns never to draw conclusions of guilt or innocence, orally or in writing, because a judge or jury makes that determination, and instead to advise seeking legal counsel on what steps to take. Write escalation notes and findings as facts observed. Removing anyone's authority or access is the owner's decision, not the performer's. Pause testing in that area until they decide. Working out from the books whether someone is stealing is a separate question.

What workpapers are kept, and who signs off?

The IIA Standards require documenting the evidence supporting the results to the repeatable standard above, review by the auditors and engagement supervisor for accuracy, relevance and completeness, review and approval by the lead, and retention according to relevant laws and/or regulations and the policies of the internal audit function and the organization. Keep the signed charter and cover page, the signed checklist, extracts with extraction records, sample selections with seeds, evidence copies, the findings log, the report with responses, and the follow-up tracker. Where the lead also performed the work, have someone able to judge it who ran no tested area, such as a board member or outside reviewer, approve it, and say so in the report. Set the retention period in the business's own records policy.

Sources
  1. The Institute of Internal Auditors — Global Internal Audit Standards, published January 9, 2024
  2. American Institute of Certified Public Accountants, Auditing Standards Board — Statement on Auditing Standards No. 128, Using the Work of Internal Auditors, February 2014
  3. Committee of Sponsoring Organizations of the Treadway Commission (COSO) — Internal Control — Integrated Framework: Executive Summary, May 2013
  4. Public Company Accounting Oversight Board — AS 2401: Consideration of Fraud in a Financial Statement Audit, undated
  5. Journal of Accountancy (AICPA & CIMA) — Fraud risk applies to all CPA firm services, October 1, 2022
  6. Journal of Accountancy (AICPA & CIMA) — Fraud is suspected: Now what?, August 1, 2022
  7. Intuit Inc. — Use the audit log in QuickBooks Online, updated 8/4/2026

Machine-readable: markdown · JSON