Internal Audit Process
Definition
The Institute of Internal Auditors (IIA) defines Internal Auditing as: “Internal auditing is an independent, objective assurance and advisory service designed to add value and improve an organization’s operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of governance, risk management, and control processes.”
Purpose
The purpose of the Office of Internal Audit (OIA) is to provide independent and objective assurance and advisory services to Valdosta State University in order to add value and improve operations while promoting accountability and transparency to maintain public trust. The Office of Internal Audit (OIA) helps the institution accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of governance, risk management, compliance, and internal control processes.
Types of Audits
Services provided by Internal Audit can take the form of various engagement types:
• Operational Audit – Operational audits are comprehensive examinations of an operating unit or a complete organization to evaluate its performance, as measured by management’s objectives and key performance indicators. An operational audit focuses on the efficiency, effectiveness, and economy of operations.
• Financial Audit – Financial audits determine the accuracy and propriety of financial transactions and reporting.
• Compliance Audit – Compliance audits determine whether, and to what degree, there is conformance to specific requirements of policies, procedures, standards, or laws and governmental regulations. The auditor must know what policies, procedures, standards, and other criteria are applicable. Compliance audits require little preliminary survey work or review of internal controls, except to outline precisely what requirements are being audited. The audit focuses almost exclusively upon detailed testing of conditions.
• Presidential Transition Audit – Presidential transition audits are used to inform an incoming President at an institution of any major control, financial, and/or operational issues and risks that may need to be addressed at the outset of the new institutional administration.
• Information Technology Audit – Information technology audits evaluate the accuracy, effectiveness, efficiency and security of electronic and information processing systems that are in production or under development.
• Advisory Services – Advisory services engagements are client-directed activities where the nature and scope are agreed with the client and are intended to add value and improve an organization’s governance, risk management, and control processes without the internal audit assuming management responsibility. Examples include counsel, advice, facilitation, and training.
• Special Projects – non-routine requests from management to answer questions or assist in an advisory capacity that doesn’t result in a formal audit report.
• Investigations – Investigations are designed to identify responsibility for and measure the impact of an alleged act of wrongdoing that has allegedly occurred. This act often will be a violation of state laws and/or regulations; BOR policies and USG procedures; or, waste and/or the inefficient use of resources. Investigations are not subject to the Standards.
Internal Audit Process & Quality Assurance Program
Valdosta State University Office of Internal Audit
Valdosta State University’s Office of Internal Audit provides independent and objective assurance and advisory services designed to strengthen governance, risk management, compliance, and internal controls. Our work follows a disciplined, risk‑based methodology consistent with the IIA Global Internal Audit Standards, the USG Business Procedures Manual (BPM), and the VSU Internal Audit Charter.
Risk-Based Engagement Selection
Internal Audit uses a structured, risk‑based approach to determine which areas will be audited. Risk factors include:
-
Financial exposure and liquidity
-
Regulatory compliance requirements
-
Information technology reliance
-
Organizational change and operational complexity
-
Public scrutiny and reputational considerations
-
Time since the last audit
Our risk assessment process includes:
-
Collecting information from multiple sources
-
Analyzing and synthesizing information into potential risks
-
Assessing risks by likelihood, impact, breadth, and velocity
This approach aligns with the Standards requirement that internal auditors “identify the potentially significant risks to the objectives of the activity under review” and “evaluate the significance of the risks and prioritize them for review.”
Audit Process
Engagement Notification & Pre-Engagement Communication
If your area is selected for audit, Internal Audit will notify you in advance and provide an engagement letter outlining the engagement’s objectives, scope, and timing, consistent with BPM 16.04.02.
The Standards state:
“Before starting an engagement, internal auditors must communicate the engagement objectives, scope, and timing to management.”
All pre‑engagement communication is documented in the audit workpapers.
Entrance Conference
Internal Audit conducts an entrance conference with leadership and key staff to:
-
Review the engagement objectives and scope
-
Discuss risks, processes, and criteria
-
Clarify expectations for communication and information requests
-
Establish a collaborative, transparent working relationship
Engagement Planning and Risk Assessment
Internal Audit performs a structured engagement planning process that includes:
Understanding the Activity
Internal auditors gather reliable, relevant, and sufficient information regarding:
-
Organizational strategies, objectives, and risks
-
Governance, risk management, and control processes
-
Applicable laws, regulations, policies, and frameworks
-
Prior audit results and risk assessments
The Standards require internal auditors to “identify and gather reliable, relevant, and sufficient information” to understand how processes are intended to operate.
Risk Identification and Prioritization
Internal Audit identifies:
-
Significant risks to activity objectives
-
Fraud risks
-
Compliance risks
-
Operational and technology risks
Setting Engagement Objectives and Scope
Objectives and scope are documented and approved by the AVC/ICA. Scope includes:
-
Activities, processes, systems, and locations
-
Time period covered
-
Criteria for evaluation
-
Resource requirements
Scope limitations are documented and escalated per BPM 16.04.01.
Work Program Development
Internal Audit develops a formal work program that identifies:
-
Evaluation criteria
-
Tasks and testing procedures
-
Sampling methodologies
-
Analytical procedures and tools
-
Assigned personnel
Work programs are reviewed and approved by the AVC/ICA before fieldwork begins.
Work Team Meetings
Before fieldwork, Internal Audit may meet with staff and management to:
-
Identify key processes and risks
-
Discuss internal controls
-
Determine practical testing approaches
Fieldwork
Fieldwork consists of gathering relevant, reliable, and sufficient evidence to support engagement conclusions. The Standards specify that evidence must be:
-
Relevant – aligned with objectives and scope
-
Reliable – factual, current, and corroborated
-
Sufficient – adequate to support conclusions
Internal Audit performs activities such as:
-
Interviews with staff and management
-
Examination of documentation and records
-
Observation of operations
-
Review of internal controls
-
Compliance and substantive testing
-
Data analysis
If evidence is insufficient, Internal Audit expands procedures or adjusts the work program with AVC/ICA approval.
Analyses, Findings, and Recommendations
Internal auditors analyze evidence to determine whether a difference exists between criteria and condition. A difference indicates a potential finding.
The Standards require internal auditors to:
-
Identify root causes
-
Assess likelihood and impact
-
Prioritize findings using BPM 16.04.06 rating scale
-
Develop recommendations or request action plans
If disagreements arise, they are documented and escalated per BPM and the USG CAO process.
Draft Report and Exit Conference
Internal Audit prepares a draft report that includes:
-
Objectives and scope
-
Observations and findings
-
Ratings (for assurance engagements)
-
Recommendations or action plans
-
Background and context
The draft is shared with management before the exit conference. BPM 16.04.04 states that the draft report must be reviewed with management “with specific emphasis on areas where improvement is needed.”
During the exit conference, Internal Audit and management:
-
Review findings and recommendations
-
Discuss management’s responses
-
Agree on action plans and completion dates
Final Report
The final report incorporates management’s responses and is reviewed and approved by the USG CAO before release.
Per the VSU IA Charter, “The institutional areas… will respond within 30 days… A final written report will be prepared and issued by the Valdosta State University Office of Internal Audit.”
Final reports are distributed to:
-
Area Vice President/Director
-
VSU President
-
USG Chief Audit Officer
-
Other stakeholders as appropriate
Follow-Up and Monitoring
Internal Audit monitors the implementation of action plans using Onspring. Follow‑up includes:
-
Inquiry into progress
-
Review of evidence of corrective action
-
Additional testing for significant or material issues
-
Documentation of status updates
If management delays or declines implementation, Internal Audit evaluates whether the risk exceeds tolerance and escalates to the USG AVC, and USG CAO as required.
The Standards require that “open or partially resolved engagement issues/findings will be maintained and periodically updated in Onspring.”
Customer Satisfaction Survey
After the final report is issued, Internal Audit requests completion of the Customer Satisfaction Survey to support continuous improvement and Institutional Effectiveness reporting.
Quality Assurance & Improvement Program (QAIP)
Valdosta State University’s Office of Internal Audit participates in a comprehensive Quality Assurance and Improvement Program (QAIP) established by the USG Chief Audit Officer. This program ensures that Internal Audit consistently meets the requirements of the IIA Global Internal Audit Standards (2024) and maintains the highest levels of professionalism, independence, and objectivity.
The VSU IA Charter states:
“The Valdosta State University Office of Internal Audit will participate in a quality assurance and improvement program (QAIP) created by the BOR CAO that covers all aspects of the internal audit process.”
Purpose of the QAIP
The QAIP evaluates:
-
Conformance with the Global Internal Audit Standards
-
Application of the IIA Code of Ethics
-
Efficiency and effectiveness of audit processes
-
Opportunities for continuous improvement
Ongoing Monitoring
Internal Audit continuously evaluates its performance through:
-
Engagement‑level supervisory reviews
-
Workpaper quality checks
-
Monitoring of engagement timelines
-
Stakeholder feedback
-
Internal process reviews
Periodic Internal Assessments
Structured internal assessments evaluate:
-
Conformance with the Standards
-
Alignment with the VSU IA Charter
-
Effectiveness of planning, fieldwork, reporting, and follow‑up
-
Adequacy of documentation and evidence
External Quality Assessments
Per the Charter:
“External assessments… will be conducted at least every five years as required by Global Internal Audit Standards.”
These reviews, conducted by the USG Office of Internal Audit, Ethics & Compliance, assess:
-
Independence and objectivity
-
Audit planning and risk assessment practices
-
Engagement execution and documentation
-
Reporting quality
-
Follow‑up processes
The ICA reports results to the President.
Commitment to Excellence
Through the QAIP, Internal Audit demonstrates its commitment to:
-
Independence and objectivity
-
Standards‑aligned methodology
-
Continuous improvement
-
High‑quality assurance and advisory services
-
Strengthening institutional governance and accountability
Office of Internal Audit
- West Hall Office 1301A 1500 N. Patterson St. Valdosta, Georgia 31698
-
Mailing Address
1500 N. Patterson St.
Valdosta, GA 31698 - Phone
- Phone: 229.245.2491
- 8:00AM-5:00PM Monday - Friday