Data as of Sep 14, 2026 · Based on 342 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
Brands AI recommends here
Named in 15% of answers
Named in 10% of answers
Named in 9% of answers
Named in 8% of answers
- Step 1. **Scoping and Planning** , where the compliance officer defines the audit objectives, scope (e.g., financial, operational, or data privacy), timeline, and regulatory frameworks involved (like HIPAA, GDPR, or SOX). - Step 2. **Risk Assessment** , identifying key compliance risks, high-risk areas, and past…
Would you like me to focus on a specific industry (like healthcare, finance, or tech) or provide a template for the corrective action plan?
No sources cited
An internal compliance audit is a structured, evidence-based review to determine whether an organization is meeting applicable laws, regulations, contractual obligations, industry standards, and its own policies—and whether its controls actually work in practice. A good audit is **risk-based, independent, documented,…
An internal compliance audit is a structured, evidence-based review to determine whether an organization is meeting applicable laws, regulations, contractual obligations, industry standards, and its own policies—and whether its controls actually work in practice. A good audit is risk-based, independent, documented, and followed through to remediation. ISO 19011:2026 emphasizes risk-based and evidence-based auditing, independence, due care, confidentiality, and fair presentation.
The compliance officer first establishes:
For example:
Objective: Determine whether the company's third-party due-diligence process complies with its anti-bribery policy and applicable requirements. The scope should be specific enough that someone reviewing the audit later can understand exactly what was tested.
The officer identifies the areas most likely to have significant compliance failures and prioritizes them.
Typical considerations include:
This is why compliance audits shouldn't simply check every policy equally. Higher-risk areas generally receive deeper or more frequent testing. DOJ guidance similarly emphasizes risk-based auditing, periodic testing, and whether the company adjusts its compliance program as risks change.
The compliance officer maps each requirement to the control intended to satisfy it.
A simple matrix might look like:
| Requirement | Risk | Control | Evidence | Test |
|---|---|---|---|---|
| All high-risk vendors require enhanced due diligence | Undue payments | Compliance approval before onboarding | Vendor files | Sample 30 vendors |
| Employees receive annual compliance training | Untrained employees | Annual mandatory training | Training records | Test completion rate |
| Gifts above $250 require approval | Improper benefits | Pre-approval workflow | Approval records | Sample gifts |
This step turns a broad question—"Are we compliant?"—into testable questions.
Before fieldwork, the officer determines:
An evidence request might include policies, training records, transaction data, approvals, contracts, investigation files, monitoring reports, access logs, certifications, and previous audit results.
The auditor speaks with people who operate the controls rather than relying exclusively on written policies.
For example:
"Walk me through what happens when a business unit wants to hire a new third party." The auditor follows the process from beginning to end and compares what employees say happens with what the policy says should happen and what the records demonstrate actually happened.
Interviews can also identify "workarounds" that aren't obvious from documentation.
This is the heart of the audit.
The officer determines whether controls are:
Testing can involve:
For example, rather than simply confirming that a gift-and-entertainment policy exists, the auditor might select 50 transactions and determine whether required approvals were obtained before the expenditure.
DOJ guidance specifically considers whether companies conduct periodic audits, test controls, analyze compliance data, interview employees or third parties, and use the results to improve their programs.
A finding should be supported by evidence—not merely an auditor's opinion.
A useful finding structure is:
Condition: What actually happened?
Criteria: What should have happened?
Cause: Why did the problem occur?
Risk/impact: What could happen as a result?
Recommendation: What should management do?
For example:
Finding: 8 of 50 sampled high-risk vendors lacked documented compliance approval before onboarding. Criteria: Company policy requires Compliance approval before onboarding. Cause: The procurement system does not prevent onboarding when the approval field is incomplete. Risk: Vendors may be engaged without required due diligence. Recommendation: Implement a system control preventing onboarding until required approval is recorded. Root-cause analysis is particularly important because fixing individual exceptions without addressing the underlying process can allow the problem to recur. DOJ guidance specifically looks at whether companies conduct meaningful root-cause analysis and remediate underlying misconduct.
Findings are typically categorized according to severity, such as:
The exact rating methodology should be defined before or independently of the results where possible.
The auditor should distinguish between:
A potential allegation of intentional misconduct may require a separate investigation rather than being handled as an ordinary audit finding.
Before issuing the final report, the compliance officer normally gives responsible management an opportunity to:
This is important because an apparent exception may have a legitimate explanation or additional evidence that the auditor didn't initially receive.
A typical report contains:
The most important question isn't simply "How many findings were there?" but:
Does the evidence demonstrate that the compliance controls are reasonably designed and operating effectively? That distinction is central to modern compliance-program evaluation. DOJ's framework asks, among other things, whether a program is well designed, effectively implemented and actually works in practice.
The audit isn't finished when the report is issued.
Each finding should have:
For example:
Finding → Implement automated approval control → Compliance/IT owner → 60 days → Auditor tests 25 subsequent transactions.
The compliance officer then determines whether remediation actually worked.
Simply receiving a memo saying "policy updated" isn't enough. The auditor may need to retest transactions or observe the new process.
This creates the cycle:
Risk assessment → audit → findings → remediation → retesting → updated risk assessment
That continuous-improvement cycle is an important characteristic of an effective compliance program.
A compliance officer can think of the process as:
1. Scope → 2. Risk assess → 3. Map requirements → 4. Identify controls → 5. Request evidence → 6. Interview → 7. Sample/test → 8. Document exceptions → 9. Root-cause analysis → 10. Report → 11. Remediate → 12. Retest
The key principle is don't audit whether paperwork exists; audit whether the compliance system actually prevents or detects the risk it was designed to address.
For a U.S. corporate compliance program, the current DOJ materials are also useful because they specifically address periodic testing, internal audit, data analysis, reporting mechanisms, investigations, and remediation.
If you're learning this for a compliance officer interview, certification, or an actual audit, I can also give you a realistic end-to-end sample audit (including audit plan, testing procedures, evidence request list, findings, and final report).
A typical report contains:
The most important question isn't simply "How many findings were there?" but:
Does the evidence demonstrate that the compliance controls are reasonably designed and operating effectively? That distinction is central to modern compliance-program evaluation. DOJ's framework asks, among other things, whether a program is well designed, effectively implemented and actually works in practice.
The audit isn't finished when the report is issued.
Each finding should have:
Conducting an internal compliance audit requires `a systematic approach to evaluate whether an organization's policies, procedures, and operations align with laws, regulations, and internal standards`. Here is how a compliance officer typically executes this process: 1. **Scoping and Planning**
Conducting an internal compliance audit requires a systematic approach to evaluate whether an organization's policies, procedures, and operations align with laws, regulations, and internal standards.
Here is how a compliance officer typically executes this process:
Would you like me to focus on a specific industry (like healthcare, finance, or tech) or provide a template for a risk assessment matrix to help structure your audit?
No sources cited
An internal compliance audit is essentially a **structured, evidence-based check that the organization is meeting its legal, regulatory, contractual, and internal-policy requirements—and that its controls actually work in practice**. A good audit is risk-based rather than simply checking every policy line by line.…
An internal compliance audit is essentially a structured, evidence-based check that the organization is meeting its legal, regulatory, contractual, and internal-policy requirements—and that its controls actually work in practice. A good audit is risk-based rather than simply checking every policy line by line.
| Requirement | Control | Test | Evidence |
|---|---|---|---|
| Employees must complete annual training | LMS assigns training | Sample 30 employees | Training records |
| Vendors must undergo due diligence | Compliance approval required | Sample 25 vendors | Due-diligence files |
| Gifts above $100 require approval | Approval workflow | Test sampled transactions | Approval records |
A strong compliance audit should answer three questions:
This aligns closely with the U.S. Department of Justice's framework for evaluating corporate compliance programs: whether the program is well designed, adequately resourced and implemented in good faith, and actually works in practice.
Suppose a company wants to audit its anti-bribery compliance program.
The compliance officer might:
The important distinction is that an internal compliance audit isn't simply "checking whether policies exist." It tests whether the organization has appropriate controls and whether those controls operate effectively in the real world.
A compliance officer conducting an **internal compliance audit** is essentially testing whether the organization is following the laws, regulations, policies, procedures, and controls that apply to its operations—and whether those controls actually work in practice. A good audit is **risk-based and evidence-based**,…
A compliance officer conducting an internal compliance audit is essentially testing whether the organization is following the laws, regulations, policies, procedures, and controls that apply to its operations—and whether those controls actually work in practice.
A good audit is risk-based and evidence-based, rather than simply checking whether policies exist. ISO 19011:2026, for example, emphasizes independence, evidence-based auditing, and a risk-based approach.
First, the compliance officer determines:
For example, an audit might focus specifically on:
“Whether the company’s third-party due-diligence process complies with applicable anti-bribery requirements and company policy.” The scope should be specific enough to produce meaningful findings.
The officer identifies the areas most likely to present compliance problems and prioritizes them.
Typical risk factors include:
This is important because an effective compliance program should be tailored to the organization's particular risks rather than being a generic "paper program." The DOJ, for example, specifically looks at whether a compliance program is designed around the company's actual risk profile and whether it is periodically tested.
The compliance officer identifies the requirements against which the organization will be tested.
These might come from:
The officer then turns those requirements into audit questions or test procedures.
For example:
| Requirement | Audit question | Evidence |
|---|---|---|
| Employees must complete annual training | Did employees complete required training? | Training records |
| High-risk vendors require due diligence | Was due diligence completed before onboarding? | Vendor files |
| Expenses require approval | Were expenses approved according to policy? | Expense reports |
| Complaints must be investigated | Were complaints appropriately investigated? | Case files |
The officer determines:
Auditor independence is important. Someone should not ordinarily be responsible for auditing controls they personally designed or operate if that creates a conflict of interest.
ISO 19011 identifies independence, integrity, due professional care, confidentiality, evidence-based auditing, and risk-based auditing as core auditing principles.
This is where the audit becomes more than a paperwork review.
The compliance officer may:
The key question is:
"Show me evidence that this control actually operated."
For example, a policy may say that every high-risk vendor must undergo enhanced due diligence.
The auditor doesn't stop at confirming that the policy exists. They might select 30 high-risk vendors and determine:
Interviews are particularly useful for discovering the difference between what the policy says and what actually happens.
Questions might include:
The auditor compares interview responses with documentary and system evidence.
The officer determines whether controls are actually operating effectively.
There are generally two important questions:
Design effectiveness: Would the control, if followed, reasonably prevent or detect the compliance risk?
Operating effectiveness: Is the control actually being performed consistently and correctly?
For example:
Policy: Payments over $25,000 require approval from the CFO. A design test asks whether requiring CFO approval is an appropriate control.
An operating test might select 50 payments over $25,000 and verify that the required approval actually occurred.
This type of control testing and analysis is specifically emphasized in the DOJ's current approach to evaluating corporate compliance programs.
When the auditor identifies a problem, they should document the evidence carefully.
A strong finding normally identifies:
Criteria → Condition → Cause → Effect/Risk → Recommendation
For example:
Criteria: Company policy requires enhanced due diligence before onboarding high-risk vendors.
Condition: 4 of 25 sampled high-risk vendors lacked documented enhanced due diligence before onboarding.
Cause: The vendor-management system does not prevent onboarding when the required review is incomplete.
Risk: The company could engage vendors without completing required compliance screening.
Recommendation: Implement a system control preventing activation of high-risk vendors until required approvals are completed. This is much stronger than simply saying, "Vendor due diligence needs improvement."
A good compliance audit doesn't just identify symptoms.
The auditor asks why the problem occurred.
For example:
Finding: Employees didn't complete required training.
Possible root causes:
The appropriate remediation depends on the root cause.
Before issuing the final report, the compliance officer normally gives responsible management an opportunity to:
This is sometimes called an exit meeting or closing meeting. ISO 19011 includes conducting audit activities and preparing/distributing the audit report as part of the audit process.
A typical report contains:
Findings may be categorized, for example, as:
The exact classification system depends on the organization.
This is one of the most important parts.
An audit isn't finished merely because the report was issued.
The compliance officer should maintain a remediation tracker showing:
| Finding | Risk | Action | Owner | Due date | Status | Evidence |
|---|---|---|---|---|---|---|
| Missing vendor due diligence | High | Implement automated onboarding block | Procurement | Oct. 30 | Open | — |
| Training gaps | Medium | Add automated reminders | HR | Oct. 15 | In progress | System report |
Once management says the problem is fixed, the compliance officer should obtain evidence and retest the control.
For example:
Management says the vendor onboarding system now blocks high-risk vendors without approval. The auditor should test the system and verify that it actually does so.
Only then should the finding be closed.
This "test → remediate → retest → close" cycle is fundamental to an effective audit program. The DOJ likewise looks at whether companies test their compliance programs and whether identified weaknesses result in meaningful remediation.
Risk assessment → Scope → Criteria → Audit plan → Evidence gathering → Interviews/testing → Findings → Root cause → Report → Corrective action → Retesting → Closure
The most important mindset is:
Don't audit whether the company has a policy. Audit whether the company is actually complying with the requirement and whether its controls can reliably detect or prevent violations. For a mature compliance function, the audit should ultimately answer three questions:
Those three questions closely mirror the framework the U.S. Department of Justice uses when evaluating corporate compliance programs.
If you're learning this for a compliance officer job/interview, I can also give you a realistic internal compliance audit example from start to finish, including the audit plan, checklist, sample testing, findings, and final report.
| Finding | Risk | Action | Owner | Due date | Status | Evidence |
|---|---|---|---|---|---|---|
| Missing vendor due diligence | High | Implement automated onboarding block | Procurement | Oct. 30 | Open | — |
| Training gaps | Medium | Add automated reminders | HR | Oct. 15 | In progress | System report |
Once management says the problem is fixed, the compliance officer should obtain evidence and retest the control.
For example:
Management says the vendor onboarding system now blocks high-risk vendors without approval. The auditor should test the system and verify that it actually does so.
Only then should the finding be closed.
This "test → remediate → retest → close" cycle is fundamental to an effective audit program. The DOJ likewise looks at whether companies test their compliance programs and whether identified weaknesses result in meaningful remediation.
Risk assessment → Scope → Criteria → Audit plan → Evidence gathering → Interviews/testing → Findings → Root cause → Report → Corrective action → Retesting → Closure
The most important mindset is:
Don't audit whether the company has a policy. Audit whether the company is actually complying with the requirement and whether its controls can reliably detect or prevent violations. For a mature compliance function, the audit should ultimately answer three questions:
This is one of the most important parts.
An audit isn't finished merely because the report was issued.
The compliance officer should maintain a remediation tracker showing:
| Finding | Risk | Action | Owner | Due date | Status | Evidence |
|---|---|---|---|---|---|---|
| Missing vendor due diligence | High | Implement automated onboarding block | Procurement | Oct. 30 | Open | — |
| Training gaps | Medium | Add automated reminders | HR | Oct. 15 | In progress | System report |
Once management says the problem is fixed, the compliance officer should obtain evidence and retest the control.
For example:
Management says the vendor onboarding system now blocks high-risk vendors without approval. The auditor should test the system and verify that it actually does so.
Only then should the finding be closed.
A compliance officer conducts an internal compliance audit by **systematically planning, executing, analyzing, and reporting on an organization’s adherence to external laws and internal policies**.[](https://www.vanta.com/collection/grc/internal-compliance-audit)…
A compliance officer conducts an internal compliance audit by systematically planning, executing, analyzing, and reporting on an organization’s adherence to external laws and internal policies.
Watch this detailed overview on how to effectively perform a compliance audit and minimize regulatory exposure:
01:02:47
How To Perform a Compliance Audit 4.5K views · 3 years ago
YouTube · TCN
If you'd like, let me know:
I can tailor the next steps directly to your compliance program.
An internal compliance audit is a structured review to determine whether an organization is **following applicable laws, regulations, policies, contractual requirements, and its own controls**. A good audit is risk-based rather than simply a checklist exercise. The Institute of Internal Auditors (IIA) describes…
An internal compliance audit is a structured review to determine whether an organization is following applicable laws, regulations, policies, contractual requirements, and its own controls. A good audit is risk-based rather than simply a checklist exercise. The Institute of Internal Auditors (IIA) describes internal auditing as involving planning, performing engagement work, developing findings/conclusions, communicating results, and monitoring action plans.
The compliance officer first determines:
For example:
Objective: Determine whether the company complies with its customer due-diligence requirements. Scope: Customer onboarding transactions from January–June 2026. Criteria: Applicable regulations + company AML policy + documented procedures. The IIA recommends understanding the area, performing a preliminary risk assessment, establishing objectives and scope, allocating resources, and documenting the audit plan.
The auditor creates a requirements/control matrix mapping each requirement to the organization's control.
| Requirement | Internal control | Evidence | Test |
|---|---|---|---|
| Employees must complete annual training | LMS training requirement | Training records | Sample employees |
| Managers must approve expenses | Approval workflow | Expense reports | Transaction testing |
| Customer identity must be verified | KYC procedure | KYC files | File sampling |
This is often the most important preparation step because it establishes what "compliant" actually means.
Not every requirement deserves equal audit attention.
The compliance officer considers factors such as:
Higher-risk areas receive more extensive testing. The IIA's current guidance specifically emphasizes risk-based audit planning to focus resources on an organization's most significant risks.
The officer translates the scope into specific procedures.
For example:
Evidence can come from:
The auditor should obtain sufficient, reliable, and relevant evidence rather than relying solely on management's assertions. Internal audit guidance describes conducting engagement work to develop findings and conclusions.
This is where the auditor determines whether controls actually work.
There are two related questions:
Design effectiveness:
If the control operates as written, would it adequately address the compliance risk? Operating effectiveness:
Did the control actually operate consistently during the audit period? For example, a company may have a policy requiring two approvals for payments over $10,000. The auditor might sample 30 payments over $10,000 and verify whether both approvals actually occurred.
When the auditor finds a problem, it should be supported by evidence and clearly distinguish between:
Example:
Requirement: All employees handling personal data must complete annual privacy training. Condition: 12 of 100 sampled employees had not completed the required training. Cause: The training system did not automatically escalate overdue assignments. Risk: Employees may handle personal information without required training, increasing regulatory and privacy risk. Recommendation: Implement automated escalation and monthly compliance reporting.
Before issuing the final report, the compliance officer normally discusses findings with the responsible business owners.
This gives management an opportunity to:
This isn't about allowing management to eliminate unfavorable findings; it's about ensuring the final audit record is accurate and fair.
A typical report contains:
The IIA's current standards specifically address communicating engagement results and monitoring action plans, and its recent guidance emphasizes effective communication of findings and conclusions.
The audit isn't really finished when the report is issued.
The compliance officer records each remediation item and tracks:
| Finding | Owner | Action | Due date | Status |
|---|---|---|---|---|
| Missing training | HR | Implement automated reminders | Oct. 15 | In progress |
| Inadequate approvals | Finance | Modify workflow | Nov. 1 | Open |
Importantly, the officer should verify effectiveness, not merely accept a statement that something was fixed. Follow-up monitoring is an established part of the internal audit cycle.
The process can be remembered as:
Plan → Identify requirements → Assess risk → Test → Gather evidence → Identify gaps → Report → Remediate → Verify
A strong compliance audit therefore isn't simply "Do we have the right policies?" It asks:
What requirement applies? → What control addresses it? → Does the control exist? → Does it actually operate? → What evidence proves that? → If it failed, what is the risk and how will it be fixed? The applicable regulatory framework will determine the specific requirements and testing methodology—for example, an AML audit will look very different from a HIPAA, SOX, environmental, or workplace-safety audit. The IIA's 2024 Global Internal Audit Standards became effective January 9, 2025 and provide the current professional framework for internal audit work.
If you'd like, I can also give you a practical internal compliance audit checklist/template that a compliance officer could use from planning through the final report.
Conducting an internal compliance audit requires a structured, methodical approach to ensure an organization adheres to external laws, regulations, and internal policies. A compliance officer typically follows a phased lifecycle to execute this effectively: 1. **Preparation and Scoping** - **Define Scope:** Determine…
Conducting an internal compliance audit requires a structured, methodical approach to ensure an organization adheres to external laws, regulations, and internal policies. A compliance officer typically follows a phased lifecycle to execute this effectively:
Would you like me to focus on:
No sources cited
Conducting an **internal compliance audit** is a systematic process to evaluate whether a company’s operations, policies, and procedures align with external laws, regulations, and internal standards. Here is how a compliance officer typically conducts an audit, broken down into sequential phases: 1. Preparation and…
Conducting an internal compliance audit is a systematic process to evaluate whether a company’s operations, policies, and procedures align with external laws, regulations, and internal standards.
Here is how a compliance officer typically conducts an audit, broken down into sequential phases:
If you'd like, I can:
No sources cited
A compliance officer typically conducts an internal compliance audit as a **structured, risk-based review of whether the organization is following applicable laws, regulations, internal policies, and control requirements**. A good audit doesn't merely look for violations—it tests whether the compliance program…
A compliance officer typically conducts an internal compliance audit as a structured, risk-based review of whether the organization is following applicable laws, regulations, internal policies, and control requirements. A good audit doesn't merely look for violations—it tests whether the compliance program actually works.
A useful framework is ISO 19011:2026, which organizes auditing around planning, conducting, reporting, evidence, independence, and risk-based auditing.
First, the compliance officer determines:
For example:
Objective: Determine whether the company's third-party due-diligence process complies with applicable anti-corruption requirements and the company's own third-party policy. The scope should be specific enough that the auditor can make a defensible conclusion.
The auditor creates an audit criteria matrix showing what the organization is supposed to do.
Sources might include:
The auditor then translates those requirements into testable questions.
For example:
| Requirement | Control | Audit test |
|---|---|---|
| High-risk vendors require enhanced due diligence | Compliance approval required | Select high-risk vendors and verify approval |
| Employees must complete annual training | LMS tracks completion | Test a sample of employees |
| Gifts above $250 require approval | Gifts must be logged | Review gift records and supporting approvals |
The auditor normally doesn't test everything equally. Higher-risk areas receive more attention.
Factors might include:
The U.S. Department of Justice, for example, specifically considers whether a company's internal-audit process identifies and audits high-risk areas and whether audit findings are reported to management and the board.
The compliance officer documents:
They may create a compliance audit checklist or testing workbook.
Importantly, the auditor should maintain appropriate independence. ISO 19011:2026 identifies independence, evidence-based auditing, and risk-based auditing among its core principles.
This is the heart of the audit.
The compliance officer gathers objective, verifiable evidence, such as:
They may also interview employees and observe processes.
The key question is:
"Show me evidence that this requirement is actually being followed." A policy saying employees must obtain approval is not enough. The auditor tests actual transactions to see whether approval occurred.
The auditor compares what should happen against what actually happened.
Common testing techniques include:
For example, select 30 vendor files from the audit period and determine whether each contains the required due diligence.
Review documents, records, approvals, logs, and system configurations.
Ask employees how the process actually works.
Watch employees perform the process.
Independently perform the control or calculation to determine whether it produces the expected result.
Search large datasets for anomalies—for example:
When something doesn't comply, the auditor documents the condition, rather than simply saying "the company is noncompliant."
A strong finding generally answers:
For example:
Finding: 7 of 50 sampled high-risk vendors did not have documented compliance approval before onboarding. Then the auditor determines whether this is an isolated error, a recurring control failure, or evidence of a systemic problem.
A sophisticated compliance audit doesn't stop at identifying the violation.
The officer asks why it occurred.
Possible root causes include:
For example:
Problem: Employees aren't completing required training.
Root cause: The company sends reminders but has no escalation mechanism and managers aren't held accountable.
That leads to a much better remediation plan than simply saying "retrain employees."
Findings are usually classified according to severity, such as:
The rating considers factors such as regulatory exposure, likelihood, potential impact, duration, number of affected transactions, and whether the problem is systemic.
Before issuing the final report, the auditor typically discusses significant findings with the responsible business owners.
This gives management an opportunity to:
This isn't supposed to turn into management negotiating away legitimate findings. The auditor's conclusions should remain evidence-based.
A typical internal compliance audit report contains:
A useful conclusion might be:
Overall assessment: Partially effective. The organization has established appropriate third-party due-diligence controls, but testing identified recurring deficiencies in documentation and approval. These weaknesses increase the risk that high-risk third parties could be onboarded without appropriate compliance review.
This is one of the most important parts.
The compliance officer assigns each finding to an owner and establishes:
Then compliance follows up.
For example:
| Finding | Corrective action | Owner | Due date | Status |
|---|---|---|---|---|
| Missing vendor approvals | Implement system approval workflow | Procurement | Oct. 15 | Open |
| Incomplete training | Add manager escalation | HR | Sept. 30 | In progress |
| Weak monitoring | Quarterly compliance testing | Compliance | Nov. 1 | Open |
The auditor should eventually verify that the corrective action actually fixed the problem, rather than simply accepting management's statement that it was fixed.
Plan → Assess risk → Identify requirements → Gather evidence → Test controls → Identify findings → Determine root cause → Report → Remediate → Validate → Monitor
This is consistent with the broader audit approach in ISO 19011:2026, which covers establishing an audit program, planning and conducting audits, reporting results, and monitoring/improving the audit program.
Suppose you're auditing an anti-bribery compliance program.
You might:
The fundamental principle is: don't audit whether the organization has a policy; audit whether the organization actually follows it, whether the controls work, and whether there is evidence demonstrating that they work.
If you're learning this for a compliance officer job/interview, I can also give you a realistic internal compliance audit checklist and sample audit report.
When something doesn't comply, the auditor documents the condition, rather than simply saying "the company is noncompliant."
A strong finding generally answers:
For example:
Finding: 7 of 50 sampled high-risk vendors did not have documented compliance approval before onboarding. Then the auditor determines whether this is an isolated error, a recurring control failure, or evidence of a systemic problem.
A sophisticated compliance audit doesn't stop at identifying the violation.
The officer asks why it occurred.
Possible root causes include:
For example:
Problem: Employees aren't completing required training.
Root cause: The company sends reminders but has no escalation mechanism and managers aren't held accountable.
That leads to a much better remediation plan than simply saying "retrain employees."
Findings are usually classified according to severity, such as:
The rating considers factors such as regulatory exposure, likelihood, potential impact, duration, number of affected transactions, and whether the problem is systemic.
Before issuing the final report, the auditor typically discusses significant findings with the responsible business owners.
This gives management an opportunity to:
This isn't supposed to turn into management negotiating away legitimate findings. The auditor's conclusions should remain evidence-based.
A typical internal compliance audit report contains:
A useful conclusion might be:
Overall assessment: Partially effective. The organization has established appropriate third-party due-diligence controls, but testing identified recurring deficiencies in documentation and approval. These weaknesses increase the risk that high-risk third parties could be onboarded without appropriate compliance review.
This is one of the most important parts.
The compliance officer assigns each finding to an owner and establishes:
Then compliance follows up.
For example:
| Finding | Corrective action | Owner | Due date | Status |
|---|---|---|---|---|
| Missing vendor approvals | Implement system approval workflow | Procurement | Oct. 15 | Open |
| Incomplete training | Add manager escalation | HR | Sept. 30 | In progress |
| Weak monitoring | Quarterly compliance testing | Compliance | Nov. 1 | Open |
The auditor should eventually verify that the corrective action actually fixed the problem, rather than simply accepting management's statement that it was fixed.
Plan → Assess risk → Identify requirements → Gather evidence → Test controls → Identify findings → Determine root cause → Report → Remediate → Validate → Monitor
This is consistent with the broader audit approach in ISO 19011:2026, which covers establishing an audit program, planning and conducting audits, reporting results, and monitoring/improving the audit program.