Training module
Auditing Internal Audit & Assurance
Assess whether internal audit and related assurance mechanisms cover risk credibly and provide meaningful assurance
Do internal audit and related assurance mechanisms provide real assurance or simply complete routines?
Internal audit programs and adjacent assurance mechanisms often appear well structured while findings remain weak, risks go unchallenged, or systemic issues persist. This module develops the capability to test whether these mechanisms credibly evaluate the management system and provide meaningful oversight.
Overview
What this module is about
Internal audit is usually the central assurance mechanism explicitly required in ISO management systems, but it rarely operates in isolation. Related assurance mechanisms should reinforce risk awareness, test system effectiveness, and support organisational learning.
In practice, internal audit programs and related assurance mechanisms often focus on schedules, routines, and procedural compliance while avoiding difficult questions about effectiveness, governance, and systemic weaknesses. This module develops the capability to audit whether internal audit and related assurance mechanisms credibly evaluate management system performance. Participants first review how internal audit and adjacent assurance mechanisms are expected to function within management systems and then learn how auditors test risk-based coverage, independence, findings quality, and follow-up effectiveness.
Audience
Who it is for
Management system implementers and coordinators
Executives and department heads accountable for management system performance
Those responsible for processes, policies, assets, risks and controls
Auditors seeking insight into management-side practice, not audit technique
Consultants working on management system design, governance or improvement
Decision supportIs this module for you?
It is a good fit if you…
need to audit whether internal audit and related assurance mechanisms provide credible, risk-based coverage.
want to test independence, findings quality, follow-up effectiveness, and governance value.
need to judge whether related assurance mechanisms complement internal audit or leave gaps and duplication.
want stronger audit conclusions on internal oversight and assurance effectiveness.
It may not be the best fit if you…
prefer to design internal audit programmes, methodologies, or report templates.
are looking for training on audit execution techniques or interviewer behaviour.
focus primarily on improving internal audit delivery rather than auditing it as an assurance mechanism.
do not intend to audit internal audit or related assurance mechanisms within a management system.
Agenda
What is taught
7 parts01Foundations of internal audit and assurance in management systems
How internal audit and related assurance mechanisms provide independent assurance, evaluate system performance, and support organisational governance
02What effective auditing of internal audit and assurance mechanisms looks like
How auditors judge whether internal audit and related assurance mechanisms provide credible oversight rather than procedural compliance
03Testing risk-based audit program coverage
How to evaluate whether audit programs address organisational risks, system priorities, and critical processes
04Building the audit evidence trail across internal audit and assurance mechanisms
How to trace audit planning, execution, findings, and follow-up across internal audit records, related assurance mechanisms, and governance routines
05Detecting internal audit and assurance failure patterns
How auditors recognise weak findings, procedural routines, compromised independence, and systemic issues that remain unchallenged across internal audit and related assurance mechanisms
06Judging credibility of internal oversight and assurance
How auditors determine whether internal audit results and related assurance outputs influence decisions, priorities, and improvement actions
07Case-based audit simulation
Applying the learned concepts, methods, and approaches in a realistic case setting
Outcomes
Learning outcomes
01
Assess whether internal audit and related assurance mechanisms credibly evaluate management system performance and risks
02
Test risk-based audit program coverage against organisational priorities and critical processes
03
Judge whether internal audit and related assurance mechanisms provide meaningful assurance and oversight
Detect common internal audit and assurance failure patterns such as procedural routines or weak findings
Trace internal audit and related assurance mechanisms from planning through findings and follow-up
Select meaningful sampling targets when auditing internal audit records
Formulate defensible audit conclusions on internal audit and assurance effectiveness
Materials
The content and the assessment
Written module
The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.
Exercises
Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.
On completion
The assessed exercises must be passed before the certificate is issued.
Scheduling
No public run of Auditing Internal Audit & Assurance is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.
Module facts
- Module ID
- HAM-AG-A-08
- Discipline
- Cross-discipline
- Part of tracks
- Management System Auditor
Case organisation
You work inside a company that already has the problem
Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.
Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.
Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes
Not a case study
Nothing is summarised for you; the evidence is where it would really be
It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after
It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions
Why it matters
Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.
Delivery & dates
How this module reaches you
Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.
No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.
Want this module scheduled?
We will tell you when the next run is scheduled, or run this module in-house with your own case material.
Not sure it is the right module?
Describe your context in a short message and we will tell you honestly.