Thank You!

You are attempting to access subscriber-restricted content.

Are You Ready to Experience Everything Internal Auditor (Ia) Has to Offer?

​The Need for Integration

Internal audit functions should adopt a holistic approach to engagements.

Comments Views

​In an era when IT is embedded in almost every process, trying to audit operational, financial, and technology controls independently is not an efficient use of resources. Beyond the redundancy of effort, it results in fractured reporting to both the board and senior management. Yet many practitioners continue to use this fragmented approach, despite its numerous disadvantages. To add value and improve the organization's operations — as mandated by The IIA's Definition of Internal Auditing — audit functions should instead adopt an integrated audit approach.

Integrated auditing, as described in an IIA Practice Guide, refers to a holistic approach to internal audit engagement planning and execution that helps ensure all aspects impacting the quality or efficiency of a process are considered. The approach often requires auditors with different backgrounds and areas of expertise, at least during the planning phase, to identify all the risks and exposures that should be part of the audit engagement, including operational, financial, environmental, technological, and regulatory concerns.​

Adopting an integrated audit approach focuses the chief audit executive (CAE) on developing auditors who can plan and perform engagements that consider any activity with the potential to prevent the achievement of organizational objectives. These integrated practitioners can provide an end-to-end understanding that includes policies, procedures, inputs, people, technology, outputs, environmental impacts, regulatory requirements, and more importantly their connection to organizational goals. 

Integrated auditors, though, should not be expected to possess expertise in every area. In fact, part of being an effective integrated auditor involves knowing when to call the experts and ask for help. However, integrated auditors should be expected to possess the core competencies needed to plan and perform an internal audit, and to be proficient in applying the International Professional Practices Framework's Mandatory Guidance.

They also should have a deep understanding of the organization, including its core business and strategic goals, policies and culture, and technology (information and operational). Moreover, they should be well-versed in industry-specific issues, such as those pertaining to geographic location or the market in which the organization operates.

Integrated auditing is a winning proposition for the internal audit activity, individual auditors, and the organization. Integrated audits are more effective because they simultaneously assess financial, operational, and IT risk and controls, and they produce more timely recommendations to improve risk management, operational, and governance controls. The approach may help discover deficiencies that could go unnoticed when performing individual audits, and it can increase internal audit's relevance by providing a more comprehensive view of organizational risk. 

Eva Sweet
Internal Auditor is pleased to provide you an opportunity to share your thoughts about the articles posted on this site. Some comments may be reprinted elsewhere, online or offline. We encourage lively, open discussion and only ask that you refrain from personal comments and remarks that are off topic. Internal Auditor reserves the right to remove comments.

About the Author



Eva SweetEva Sweet<p>​Eva Sweet, CISA, CISM, is director, IT and public sector standards and guidance, at The IIA.</p>


Comment on this article

comments powered by Disqus
  • IDEA_CaseWare_May 2020_Blog 1
  • Galvanzie_May 2020_Blog 2
  • IIA CIA LS_May 2020 Blog 3