Finance, Accounting & Insurance

How to get hired as an internal auditor in 2026-27

The short answer

Internal auditing is not a licensed occupation in any US state: no board, no state exam, no apprenticeship hours, and nothing stops an employer putting you in the job tomorrow. What employers actually require is a bachelor's degree, two to four years of audit, accounting, risk or process experience, and usually a certification, most often the Certified Internal Auditor (CIA) from the Institute of Internal Auditors, a CPA for financial reporting work, or CISA for IT audit. Four routes reliably work: two to four years of external audit at a public accounting firm, a co-source internal audit practice (Protiviti, the Big Four risk practices, Grant Thornton, RSM, BDO, Crowe, Baker Tilly), a campus or rotational program inside a bank, insurer, utility or large manufacturer, or a sideways move from a business process you already run. The interview is not a recall test: given a process, it asks you to name the inherent risk, the control that addresses it, the test that proves the control operated, then write the result as a finding with condition, criteria, cause, effect and recommendation and defend it to the manager who owns the broken process.

License requiredNone. Internal auditing is not a licensed occupation in any US state. No board, no state exam, no registration, no apprenticeship hours, and nothing stops anyone using the job title. The gates are set by employers: a bachelor's degree appears in almost every posting, two to four years of relevant experience for a senior role, and a certification line that usually reads "required" but is frequently negotiable into a commitment to obtain it within a stated window after hire. The two real legal boundaries sit elsewhere: you may not call yourself a CPA or sign as one without a state license, and in banking a conviction involving dishonesty, breach of trust or money laundering can bar you from employment under section 19 of the Federal Deposit Insurance Act unless the FDIC consents.
The credential that matters most: the CIAThe Certified Internal Auditor, issued by the Institute of Internal Auditors, is the only certification written for this job and the only one universally recognized inside it. Three exams, takeable in any order: Part 1 Essentials of Internal Auditing, Part 2 Practice of Internal Auditing, Part 3 Business Knowledge for Internal Auditing. Eligibility requires a bachelor's degree or an IIA-recognized alternative, a character reference, and two years of internal audit or equivalent experience (one year with a master's, five with an associate degree). You can sit and pass all three exams before you have the experience; the experience is verified before the certificate is issued. The IIA has revised question counts, timings, syllabus and fees more than once in recent years, so confirm the current ones on theiia.org rather than from any summary, including this one.
Time to the CIASix to twelve months part time is the realistic range for someone already working in audit, taking one part at a time, and longer for a career changer who has never written a workpaper. Review providers scope each part at a few dozen hours of study. Exams are computer-based and offered year round at test centers, so the pace is yours. The real constraint is the IIA's program eligibility window: once you are approved into the program you have a limited period to finish all three parts, and missing it means paying to re-enter, so check the current window before you register. The IIA has also offered a single-exam entry-level designation, the Internal Audit Practitioner, which draws on Part 1 material, requires no experience and is time limited rather than permanent. Confirm it is still on offer before you build a plan around it.
CPA, CISA, CFE and the rest: when each mattersCPA: the strongest signal for SOX, financial reporting and controllership-adjacent audit, and effectively expected if the exit you want is controller or CFO. It needs a state license, 150 semester hours in most jurisdictions, the CPA Exam and an experience requirement, and several state boards have added or are considering a pathway pairing a bachelor's degree with additional experience, so read your own board's current rules. CISA (ISACA): the IT audit credential, and the one IT audit postings name by default. CFE (ACFE): investigations and fraud. CAMS (ACAMS): BSA and AML audit at banks, credit unions and money services businesses. CRMA (IIA): layered onto the CIA for risk-focused roles. Public sector auditors carry a continuing education obligation under the Yellow Book instead of a separate credential.
Who is required to have an internal audit functionNYSE listing standards require listed companies to maintain an internal audit function, which is why nearly every NYSE issuer has one and some Nasdaq-listed companies of similar size do not. Banks and savings institutions pick up requirements through FDICIA Part 363 above asset thresholds, and the largest national banks through the OCC's heightened standards, which name internal audit as the third line. Insurers pick them up through the NAIC Model Audit Rule above premium thresholds, adopted state by state. Federal agencies have offices of inspector general; states, counties, cities, school districts, universities and hospital systems run audit shops under the Yellow Book. That list is your employer map, and it is weighted heavily toward financial services, insurance, healthcare, energy and the public sector.
The hiring process, and where people get cutTypical corporate loop: recruiter screen, audit manager or senior manager interview, a panel of two to four audit managers sometimes with a business stakeholder, often a written exercise or case (here are the facts, draft the observation; or here is a process, tell us the risks and controls), then a director or the chief audit executive for senior roles, then background check and in financial services frequently a credit check. Three to six weeks is normal, faster at co-source firms. Public sector hiring through USAJOBS or a state portal runs months, with a scored application against stated criteria and a structured panel where answers are rated against a rubric. The two stages that eliminate most candidates are the process walkthrough question and the writing exercise, in that order.
What gets you past the screenAudits named, scoped and resolved, not duties listed. Per audit: process area, entities or sites covered, the scope figure that makes it real (annual spend, transaction count, headcount, revenue, loan balances), your role (led, co-led, tested), observations issued with their ratings, and whether management agreed at first draft. Then the systems you audited in (SAP, Oracle, Workday, NetSuite, Dynamics), the audit and GRC platform (AuditBoard, Workiva, TeamMate+, Diligent, Archer, ServiceNow IRM, Pentana), analytics tools named with the actual tests you built, frameworks (COSO 2013, COSO ERM, COBIT, NIST CSF 2.0, ISO 27001, the Global Internal Audit Standards, GAGAS), and a certification line with status and date. "Performed audits in accordance with professional standards" is read as having nothing to declare.
Pay: cite the source, not an averageThe US BLS Occupational Employment and Wage Statistics code covering this work is 13-2011 Accountants and Auditors. Audit directors and chief audit executives are usually captured under 11-3031 Financial Managers, and IT auditors fall under 13-2011 or under a computer occupation code such as 15-1212 Information Security Analysts depending on how the job is classified. Read OES by metro area and by industry rather than the national figure, because the spread between banking or energy and local government or nonprofit is larger than the spread between levels. For live numbers, use postings from pay-transparency jurisdictions (Colorado, California, Washington, New York, Illinois, Minnesota, Maryland, New Jersey, Massachusetts, Hawaii, Vermont and Washington DC among them, and the list keeps growing), the IIA's compensation study, and public sector salary schedules, which are published records naming the exact band for the exact job.

Internal auditor is four different jobs: work out which one the posting means

The title covers at least four jobs that share a reporting line and very little daily work. SOX and internal control over financial reporting: a fixed universe of key controls tested on an annual cycle, walkthroughs, deficiency evaluation, and coordination with the external auditor who may rely on your testing. Operational and compliance audit: risk-based reviews of whole processes (procure to pay, order to cash, inventory, treasury, payroll, third-party management, health and safety, capital projects) against a plan the audit committee approved. IT audit: logical access, change management, software development, cloud configuration, backup and recovery, cybersecurity, and increasingly AI governance. Financial services regulatory audit: third-line work over BSA and AML, credit risk, model risk, fair lending and consumer compliance, where an examiner may read your workpapers after you do.

That distinction decides which resume you send. A candidate whose entire record is SOX key-control testing applies to an operational audit team and is read as someone who has only ever executed a program somebody else wrote. A career operational auditor applies to a SOX program manager role and is read as someone who has never evaluated a deficiency under pressure with a filing date approaching. Both are solvable, but only if you notice which one you are and write the bridge explicitly.

Read the posting's nouns. "Annual risk assessment", "audit plan", "process owner", "root cause", "operational efficiency" means operational audit. "Key controls", "walkthroughs", "test of design and operating effectiveness", "deficiency evaluation", "external auditor reliance", "PCAOB" means SOX. "Privileged access", "change management", "SOC 2", "ITGC", "segregation of duties ruleset" means IT audit. "Three lines", "regulatory examination", "issue validation", "MRA", "BSA" means a bank or a credit union.

The second axis is in-house versus co-source. Co-source and outsource providers (Protiviti, which is the largest firm specializing in this work, the Big Four risk and internal audit practices, Grant Thornton, RSM, BDO, Crowe, Baker Tilly, CBIZ, Riveron, Kroll, and strong regional firms) sell internal audit as a service to companies that do not staff the whole function. The work rhythm is consulting: utilization targets, several clients a year, more travel, faster promotion, and more audits on your resume in two years than an in-house auditor does in four. It is the best volume training ground in the field and it hires more often and more quickly than corporate departments do. One structural quirk worth knowing: an accounting firm cannot provide internal audit outsourcing to a company whose financial statements it audits, because Sarbanes-Oxley bars that service for audit clients. That is precisely why so much co-source work sits with firms outside the issuer's own auditor, and it is a sophisticated thing to mention in an interview.

The third axis is the size of the function, and it is the one candidates forget to ask about. A two-person department at a mid-sized company means you will build the annual risk assessment, run the audits, write the board report and manage the external quality assessment, all in your first eighteen months. A ninety-person function at a global bank means you will specialize, probably into one risk area, with a quality assurance team reviewing your files. Breadth and depth are both legitimate preferences. Say which you want in the interview, because the hiring manager is sorting for exactly that and cannot read your mind.

Travel and office days are real variables and postings understate both. Manufacturing, retail, energy, utilities, mining, hospitality and distribution all run site audits, and a plant or store visit cannot be done from a laptop. Financial services and software are mostly hybrid with occasional travel. Public sector is usually low travel and fixed hours. Most large corporate functions now run a fixed number of office days rather than the fully remote arrangements of a few years ago, and co-source work is governed by client site expectations rather than by your firm's policy. Ask for the number of audits per year that require site visits, the typical length of a visit, and the office day requirement in writing, because "flexible" in a posting and "three days, Tuesday to Thursday" in practice are both true at the same time.

What actually gates this job: no license, but a credential ladder employers read closely

Start with the plain fact, because it saves people money: there is no license. Internal auditing is not regulated at state level anywhere in the United States, there is no board to register with, no exam you must pass to practice and no protected title. Anyone can be hired as an internal auditor tomorrow. This is the opposite of the CPA, which is a state license with reserved activities, and it means every certification in this field is an employer-recognized credential rather than a legal requirement. Treat any course provider who describes internal audit certification as a license as someone who is selling to you.

Within that, the CIA does more work than any other line on the resume, because it is the only credential written for this specific job and the only one whose syllabus matches what the work actually is. Part 1 covers the foundations: the mandate, independence and objectivity, proficiency and due professional care, quality, governance and risk management, fraud risk, and the engagement lifecycle. Part 2 covers running engagements: planning, risk and control assessment, evidence, analytics, supervision, communicating results and monitoring progress. Part 3 is the business literacy exam: organizational structure, business processes, information security, IT, financial management and data analytics. Part 3 is where auditors with narrow experience fail, and it is also the part that makes the credential worth holding, because it is the material you need in order to scope an audit of a process you have never seen.

Employers enforce the CIA unevenly, and knowing where it is binding saves you from applying to the wrong places or from paying for it too early. Large financial services functions, insurers, healthcare systems and public sector shops often require it or require you to obtain it within a stated window after hire, and they commonly reimburse. Corporate functions outside financial services frequently accept "CIA, CPA or CISA" interchangeably and will hire a strong candidate with none of them if the experience is right. Co-source firms hire you without it and then push you toward it, because the percentage of certified staff is a number they quote in proposals. If you have no certification yet, the words that belong on the resume are the specific ones: "CIA, Parts 1 and 2 passed, Part 3 scheduled February 2027". A bare "CIA candidate" is read as not started.

The CPA sits alongside, not above. For SOX-heavy and financial-statement-adjacent audit, and for anyone whose intended exit is controller, assistant controller, technical accounting or CFO, it remains the credential with the most leverage, and the usual sequence is to earn it in public accounting and then move. If you are already in industry and not planning a finance leadership exit, the CIA is a far cheaper, faster and better-aimed investment than going back for 150 semester hours. The two together are common at director level in large functions, and nobody holds both because they needed both: they hold both because of the path they took.

For IT audit the ordering is different. CISA is the baseline credential and the one IT audit postings name by default, with CRISC, CISSP, cloud provider certifications and ISO 27001 lead auditor training as specializations on top. An IT auditor without CISA and with four years of real access, change and cloud testing experience will still get hired; an IT auditor with CISA and no hands-on technical depth will get through the screen and then fail the panel, because IT audit interviews ask you to describe how you actually tested privileged access in a named system.

Two other credentials earn their place in specific corners. CFE (ACFE) is the one to hold if you want investigations work, and it is worth saying that fraud investigation is a genuinely different job from auditing: different interview technique, different evidence handling, different reporting line. CAMS (ACAMS) is close to expected for bank auditors covering BSA and AML programs. CRMA layers on the CIA for risk-focused roles. In the public sector none of these is required, but the Yellow Book continuing education obligation is: a set number of hours over each two-year period with a portion that must be government-audit specific, which your employer tracks and an external peer review checks. Confirm the current hour requirements in the current Yellow Book revision rather than from memory, including mine.

Continuing education applies on the private side too. Certified internal auditors report CPE to the IIA on a schedule that differs for practicing and non-practicing holders. It is administrative rather than difficult, but letting a certification lapse and leaving it on the resume is an avoidable integrity problem in a profession whose entire product is credibility.

The five routes in, and which one is actually open to you

Route one, and still the widest door: two to four years of external audit at a public accounting firm, then a move to a corporate internal audit team, usually landing at senior auditor. This works because the skills transfer cleanly on the technical side (sampling, documentation, materiality judgments, evidence discipline, managing a client request list, working to a deadline that does not move) and because hiring managers have made the hire many times and know it works. Time it for after busy season, which is when the market for experienced public accounting leavers is deepest and when internal audit functions are staffing up for the back half of their plan year. What does not transfer, and what you must therefore address directly in the interview, is risk-based scoping (external audit scopes to the financial statements; internal audit scopes to whatever the board is worried about), operational process knowledge, and writing for a business reader rather than for a file.

Route two, the fastest and the most underused: the co-source and outsource providers. Protiviti is the largest firm specializing in internal audit; the Big Four run internal audit inside their risk advisory practices; Grant Thornton, RSM, BDO, Crowe, Baker Tilly, CBIZ and dozens of strong regional firms all have internal audit teams. They hire at campus and experienced levels, they hire year round, they accept non-accounting degrees far more readily than corporate functions do, and they hire contract and interim staff through specialist finance and audit staffing agencies. Contract-to-hire for SOX testing season is a genuine entry point that almost nobody plans for deliberately: you work three to five months, you accumulate real audits on a real client, and a meaningful share of those engagements end with the client hiring the contractor.

Route three: campus and rotational programs. Large banks, insurers, utilities, retailers, healthcare systems and manufacturers run internal audit development programs that recruit undergraduates directly, train them, and then rotate many of them into the business after two or three years. These programs exist because internal audit is one of the few places a 23 year old can legitimately see every part of the company. They recruit early, often in the fall for the following summer or the following year, through campus career fairs, Beta Alpha Psi chapters and target-school pipelines. If you are a student reading this, that is the single highest-leverage application you can make, and the deadline is earlier than you think.

Route four, the most underrated: move from inside the business. If you already work in accounts payable, treasury, procurement, claims, branch operations, clinical revenue cycle, supply chain or plant operations at a company with an audit function, you hold the thing audit cannot hire from outside, which is knowledge of how the process really runs as opposed to how the policy says it runs. Audit managers hire these people deliberately for operational audits. The one constraint to know before you ask: professional standards require a cooling-off period before you audit an area where you had operational responsibility (commonly stated as at least one year), which is a scoping restriction on your first-year assignments, not a bar on the transfer. Say it yourself in the conversation. It demonstrates that you already understand objectivity, which is most of what they are checking.

Route five: the technical door. IT operations, infrastructure, identity and access management, information security, GRC analyst work and SOC 2 readiness all lead into IT audit, which frequently posts above general internal audit at the same level and competes for a smaller pool of candidates. The gap to close is audit method rather than technology: evidence, sampling, documentation and the discipline of testing a control rather than fixing the problem you found. CISA is the credential, and an IT audit interview will ask you to describe a specific test in a specific system, so prepare one on privileged access review and one on change management with the ticket evidence named.

Then there is the public sector, which is a parallel market with its own rules and which many private-sector candidates never look at. Federal auditing roles sit mostly in the GS-0511 auditing series, which carries a positive education requirement (a degree with a set number of semester hours in accounting, commonly stated as 24, or that coursework plus qualifying experience), and are posted on USAJOBS with a scored application process where under-describing your experience in the application text gets you screened out before a human reads it. Read the education requirement on the announcement itself, because the wording varies. Offices of inspector general, the Government Accountability Office, state auditors, city and county audit offices, school districts and public universities all hire. The work is often performance auditing, which is closer to policy analysis than to controls testing, the writing standard in a good performance audit shop is higher than in most corporate functions, salary bands are published, the pension is real, and the hiring takes months. Judge it on those terms rather than against a corporate timeline.

How internal audit hiring actually works in 2026-27

The first screen is keyword matching, and internal audit has an unusually mechanical vocabulary, which works in your favor if you use it and against you if you write around it. Recruiters and applicant tracking systems look for the process names (procure to pay, order to cash, record to report, hire to retire), the frameworks (COSO, COBIT, NIST, ISO 27001, SOX, GAGAS), the systems (SAP, Oracle, Workday, NetSuite), the audit platform, and the certification. A resume that describes the same work in your own company's internal language will be filtered out by a system that has never heard of your company's internal language. Translate.

The second screen is the audit manager reading for two things: scope and ownership. Scope means the size and nature of what you audited, which is how they calibrate your level. Ownership means whether you led the engagement, drafted the program, ran the opening and closing meetings and wrote the report, or whether you executed test steps someone else designed. These are completely different candidates and the resume usually blurs them. Be exact about which audits you led and which you tested on, and do not inflate, because the panel's follow-up questions find the seam in about four minutes.

The panel is typically two to four audit managers or seniors plus, in larger functions, someone from the business or from IT. Expect behavioral questions anchored in real engagements, at least one scenario on independence or on management pushback, and at least one technical sequence that starts with a process description and ends with you proposing tests. Bring a short list of audits you can discuss in detail, decide in advance which details are confidential and which are describable in generic terms, and discuss them at the level of "a large manufacturer's three-site procurement process" rather than naming the client.

The written exercise is where the most candidates die, and the most survivable thing about it is that it is predictable. Two formats dominate. In the first you are handed a short set of facts, often deliberately incomplete, and asked to draft an observation. Graders are looking for a clear condition (what you found), explicit criteria (the policy, standard, contract term, regulation or control design it fails against, named), a cause that goes past "the control was not performed", an effect quantified or at least bounded, and a recommendation that is actionable and owned. They are also looking at tone: whether a process owner could read it without getting defensive, whether you used adjectives where you should have used numbers, and whether the rating you assigned is justified by the effect you described. In the second format you are given a process narrative and asked to produce a risk and control matrix. There, graders check whether you can separate an inherent risk from a control, a control from a test, and a test from a finding. Candidates routinely list controls in the risk column.

Then references, a background check, and in financial services frequently a credit check, because audit staff get privileged access to systems and in banking certain convictions bar employment outright. If you have something in your history, the time to raise it is before the offer, with the facts stated plainly. Public sector roles add their own layers: suitability determinations, sometimes a clearance, and timelines measured in months.

Timing is a lever. SOX-heavy functions hire in late spring and summer, before scoping and testing season. Co-source firms hire continuously and surge before their clients' busy periods. Campus programs recruit in the autumn. Public sector hires when the budget appears, which is often tied to a fiscal year start. The least favorable moment to join any audit function is three weeks before the audit committee meeting at which plan status is reported, because nobody will have time to train you. That is worth nothing in your decision and a great deal in your first ninety days.

The internal auditor resume: what an audit manager reads, and what they skip

The failure mode is universal and easy to fix: internal audit resumes describe duties. "Performed walkthroughs and testing of internal controls." "Prepared workpapers in accordance with departmental standards." "Participated in the annual risk assessment." Every applicant writes these sentences, they distinguish nobody, and a manager reading forty resumes skips them. The resume that gets a call lists audits, with scope and resolution, in a repeatable format.

Use one line per audit, structured the same way every time: process and entity, scope figure, your role, result. The shape, with numbers you would replace with your own: "Led a procure-to-pay audit across three North American plants covering the site's full year of third-party spend; issued six observations including two rated high, on duplicate vendor records and on purchase orders split below the approval threshold; all six agreed at first draft and closed within the committed dates." Every element of that line is checkable in a reference call, which is precisely why it is persuasive. Use your own real figures and never a figure you cannot reconstruct if asked.

Four specifics raise a resume above the pile. First, the scope figure, because it calibrates your level instantly. Second, observation counts with ratings, because it shows you have issued findings rather than only tested. Third, agreement at first draft and remediation closed, because the thing that actually distinguishes a good auditor from an adequate one is whether findings get accepted and fixed, not whether they get found. Fourth, named analytics with named tests: not "performed data analytics" but "built a SQL extract of the full year of journal entries and tested for entries posted outside business hours, entries by users without posting authority, and round-dollar entries above threshold, which produced two of the six observations". The last one separates candidates more than any certification does.

Include a short technical block, because readers scan it. Systems audited in (SAP S/4HANA, Oracle Fusion, Workday, NetSuite, Dynamics 365, core banking or claims platforms by name). Audit and GRC platform (AuditBoard, Workiva, TeamMate+, Diligent HighBond, Archer, ServiceNow IRM, Pentana, MetricStream). Analytics (SQL, Alteryx, Power BI, Tableau, Power Query, Python, IDEA, ACL). Frameworks (COSO 2013 Internal Control Integrated Framework, COSO ERM, COBIT, NIST CSF 2.0, ISO 27001, SOC 2 trust services criteria, the IIA's Global Internal Audit Standards, GAGAS). Certifications with status and date. Languages, if you audit international entities, because that is a genuine scoping advantage and functions with foreign subsidiaries screen for it.

What gets skipped: a summary paragraph of adjectives, "strong attention to detail", "excellent communication skills", lists of training courses with no outcome, every individual walkthrough you performed, generic references to professional standards, and the phrase "assisted with", which reads as "did not own". Also skipped: a hobbies section, a photograph, and a skills bar chart rating your Excel at four stars out of five.

Two pages is normal and acceptable here, three if you are at director level with a long audit history, one if you are a graduate. If you are coming from external audit, reorganize by process area rather than by client, because the hiring manager cares that you have tested revenue recognition, inventory and ITGCs across industries, not that you served six clients. If you are coming from inside the business, lead with the processes you ran and the controls you operated, translated into risk language, and say what you had to fix when something went wrong, because operating a control badly and knowing why is excellent audit material.

Keep every number consistent across the resume, LinkedIn and what you say in the screen. Internal audit is a profession about verification, and a hiring manager who finds two different figures for the same audit has learned something about you that no interview answer repairs.

Internal auditor interview questions, and what they are really testing

Almost every internal audit interview contains one question that decides it: "walk me through an audit you ran, from planning to report." Weak answers describe what happened chronologically. Strong answers show judgment at each decision point: why this process was on the plan at all, what you scoped in and specifically what you scoped out and why, how you assessed risk before testing, how you selected the sample and why that basis, how you knew the population was complete, what you found, how the closing meeting went, what management committed to, and whether it actually got fixed. The chronology is the structure; the decisions are the content.

Expect a process-to-risk exercise. The interviewer describes a process (often a simple one: employee expense reimbursement, new vendor setup, cash handling at a retail location, user access provisioning) and asks what could go wrong. The discipline being tested is whether you can keep four things distinct. The inherent risk is what could go wrong absent any control. The control is the activity designed to prevent or detect it. The test is what you do to prove the control operated. The finding is the gap between how the control was designed or operated and the criterion it should meet. Candidates collapse these constantly: they answer the risk question with controls, and they answer the test question with recommendations.

The finding-writing question is the profession's standard technical test, and you should be able to produce the five elements on demand: condition, criteria, cause, effect, recommendation. Two of the five do most of the discriminating. Criteria, because an auditor who says "they weren't reconciling the account" without naming the policy, the contract term, the standard or the control design they failed against has stated an opinion rather than a finding, and a process owner can refuse an opinion. And cause, which is the acknowledged weak spot across the whole profession: most findings stop at a restatement of the condition ("the reconciliation was not performed") when the real cause is something structural, such as the only trained preparer having left, the system report that feeds the reconciliation having changed format, the control having no named owner after a reorganization, or an incentive that rewards closing fast over closing right. Prepare one real example where you found the structural cause and it changed the recommendation.

Independence and objectivity come up as scenarios and the interviewer is listening for a specific shape of answer. "The CFO asks you to drop a finding before the audit committee pack goes out." "You are assigned to audit the department you worked in last year." "You find an issue in an area run by a close friend." "Management wants to downgrade a rating." In each case the answer has the same skeleton: disclose the impairment or the pressure, escalate to the chief audit executive, document the facts, and remember that the function's functional reporting line runs to the audit committee rather than to management, which is the structural protection that exists precisely for this. Then say what you would do practically, because the abstract answer alone sounds rehearsed. Knowing that the chief audit executive's appointment, removal and compensation are typically matters for the audit committee is the detail that shows you understand why the reporting line is designed this way.

Two technical questions separate experienced auditors sharply. "How did you know the population was complete?" is the sharpest, and most candidates have no answer at all. A good one: the extract was reconciled to a system-generated control total and tied to the general ledger balance, the query logic was documented and independently rerun, and the person who ran the extract was not the person who owned the data. "How did you set your sample size?" is the second, and the answer should name the basis (statistical with a stated confidence and tolerable rate, or judgmental with the rationale and the risk acceptance that goes with it) rather than a number pulled from a table nobody can explain.

Expect a fraud question, and know that it tests restraint rather than enthusiasm. If something you find looks like fraud, you stop, you do not start interviewing people, you do not alert the suspected party, you preserve what you have, and you escalate under the fraud policy to the chief audit executive and from there to legal, investigations or the audit committee as that policy directs. Auditors who answer with "I would dig in and find out" are describing the behavior that destroys evidence and collapses cases.

Then there is the conversation question, in some form: tell me about a time management disagreed with a finding. Pick the one you lost, or the one that got downgraded, not the triumphant one. What they want to see is whether you can hold a position under pressure, separate the facts from the rating, accept a legitimate counter-fact that changes the finding, and leave the relationship intact, because an auditor who wins every argument and is never invited back has failed at the job. Half of this work is persuading people who did not ask for you to agree in writing that something they own is broken.

Finally, ask good questions, because in this field they are read as a work sample. How is the annual audit plan built, and how much of capacity is unplanned work? How many audits does an auditor lead per year? What is the state of overdue remediation and who chases it? Does the chief audit executive have a private session with the audit committee without management present? When was the last external quality assessment, and what did it say? The Standards require an independent external assessment at least every five years, so the answer is either a date and a result or a revealing silence.

Levels, internal auditor salary, and what the job is actually a route to

The ladder is consistent across employers: staff or associate auditor, senior auditor, audit manager, senior manager or director, then chief audit executive. Two to three years to senior is typical, three to four more to manager, and the step to director usually requires either ownership of the annual risk assessment and the audit committee reporting or deep specialization in a risk area the business cares about. Co-source firms move people faster, with the usual consulting trade of utilization pressure and travel. Public sector grades move on published schedules with step increases, which is slower on the way up and far more predictable.

For pay, name the source rather than a band. Internal auditors are reported under BLS Occupational Employment and Wage Statistics code 13-2011 Accountants and Auditors, audit directors and chief audit executives usually under 11-3031 Financial Managers, and IT auditors under 13-2011 or a computer occupation code depending on how the job is classified. Read OES by metro area and by industry, because the spread between a money-center bank and a county government is wider than the spread between two levels inside either. Supplement it with postings from pay-transparency jurisdictions, which now cover enough of the country that you can construct a current range for your exact title and metro in an hour of reading, with the IIA's compensation study, and with published public sector salary schedules. IT audit and financial services audit consistently post above general corporate internal audit at the same level, and chief audit executive pay at a large listed company is a different market entirely.

Negotiating in this field has one unusual feature worth using: the certification. Many functions pay a certification differential or a one-off bonus for the CIA, CISA or CPA, and many reimburse exams, materials, membership and CPE. These are often separate budget lines from salary, which means they are negotiable when the salary band is not. Ask about them explicitly and ask whether study time is on the clock.

Now the part that should influence your decision more than the salary does. Internal audit is one of the only jobs in a company that carries a standing mandate to examine every process, meet every process owner and read every policy, with a reporting line that reaches the board. Used deliberately, three to five years in it leaves you with a map of how the business actually runs that almost nobody else at your level has. That is why rotational programs exist, and why the common exits are strong: controllership and technical accounting, financial planning and analysis, enterprise risk management, compliance, business operations, program and transformation management, SOX program ownership, and in financial services the first-line risk and control functions that pay well and hire ex-auditors constantly.

It is also why staying is a real career rather than a holding pattern. Chief audit executive is a board-facing role with a seat in the rooms where governance actually happens, and the path to it runs through the work described in this article rather than through a detour into management elsewhere. The honest caveat is that the function's independence is only as real as the organization lets it be, and the single question that tells you most about where you are joining is who the chief audit executive reports to administratively and whether they hold a private session with the audit committee without management in the room.

No audit experience yet: ninety days to being a credible candidate

If you are coming from outside the profession, the gap is not intelligence or diligence, it is that you cannot yet speak the language and have no artifact to point at. Both are fixable in a quarter, and the plan below is specific enough to execute.

First, read the IIA's Global Internal Audit Standards end to end. They replaced the previous International Standards for the Professional Practice of Internal Auditing and they are what a quality assessment now measures a function against. They are shorter than you expect and they are the source of the vocabulary every interviewer uses: mandate, independence, objectivity, due professional care, engagement planning, communicating results, monitoring progress. Read the Three Lines Model alongside them, and the COSO 2013 Internal Control Integrated Framework at least to the level of the five components and seventeen principles, because a SOX interview will assume them.

Second, build one artifact. Take a process you genuinely know from your current or previous job (invoice approval, new hire onboarding, cash handling, inventory counts, user access provisioning) and write a risk and control matrix for it: inherent risks, the controls that address each, control owner, frequency, and how you would test design and operating effectiveness. Then write one observation in the five-element format against a weakness you actually know exists. Three pages total. Do not use your employer's confidential data or documents; describe the process generically and invent the numbers, and say in the interview that you did so. You now have something to put on the table, and almost no other career changer will.

Third, build one data test. Learn enough SQL or Power Query to extract a transaction population and run a duplicates test, a weekend-and-after-hours test, a round-number test and a threshold-splitting test on public or synthetic data. This is a weekend of work and it is the single most leverageable technical skill in the field right now, because functions are being asked to cover more with the same headcount, and the person who can test a whole population instead of 25 items is who they want.

Fourth, take one exam. CIA Part 1 if you are eligible, or the Internal Audit Practitioner designation if it is still on offer, gives you a verifiable line on the resume and forces you through the vocabulary. Register, pick the date, and work backwards from it.

Fifth, apply where the volume is. Co-source firms, finance and audit staffing agencies, contract SOX testing season work, campus programs if you are eligible, and the audit function at the company you already work for. Do not spend the quarter applying only to corporate senior auditor postings that ask for five years of internal audit experience; that is the narrowest door in the building. And go to your local IIA chapter meeting, because the people in that room run the teams you are applying to.

Working with AI in this role

What AI has actually changed for internal auditors, and what it has not

The honest headline first, because it is not the one you will read elsewhere: the core of this job has not been automated and there is no credible sign it is about to be. Evidence, independence, judgment about what matters enough to report, and a difficult conversation with the person who owns a broken process are what internal audit is, and none of those four are model-shaped. What has genuinely changed is the sample, the first draft, the cycle time, and above all the scope of what boards now ask internal audit to cover, which has grown rather than shrunk. Anyone telling you the profession is being replaced is selling a course; anyone telling you nothing has changed has not looked at an audit plan recently.

Start with how audits are executed. The largest practical change is the move from sampling to full population testing. Where an auditor once pulled 25 purchase orders and tested them, the whole year's population can be extracted and tested, which makes certain tests both cheaper and far more conclusive: duplicate payments, purchase orders split just below an approval threshold, vendor bank-account changes followed quickly by a payment, segregation of duties conflicts in an ERP role matrix, journal entries posted outside business hours or by users without posting authority, employees and vendors sharing an address or bank account, expense claims that cluster just under the receipt limit. The practical consequence for a candidate is blunt: the person who can only test a sample of 25 is worth less than the person who can write the query. That shift predates generative AI, which has mostly made the query easier to write rather than making the test newly possible.

On top of that, the drafting layer. Audit and GRC platforms (AuditBoard, Workiva, Diligent, TeamMate+, ServiceNow IRM among them) and ledger anomaly tools such as MindBridge have added AI features that summarize prior-year files and policy documents, suggest risks and test steps for a process, draft the first version of an observation, produce meeting notes, and answer questions about a data set in plain language. Used well, this takes hours out of documentation and gives junior auditors a usable starting point. Adoption is wildly uneven: plenty of capable functions still run Excel, a shared drive and a well-maintained template, and will tell you so. Ask in the interview what the function actually uses day to day, because the answer tells you both what you will learn there and how honest they are.

What has not changed is the evidence standard, and interviewers listen for whether you understand that. A workpaper has to let another auditor reperform your test and reach the same conclusion, which means the query, the population, the extract date, the control totals and the judgment calls must all be documented. "The tool flagged it" is not a conclusion, and a model's output is an input to testing rather than evidence. If you used a model to draft an observation, you own every sentence in it, including the criterion it invented. There is a confidentiality boundary here too that costs people jobs: pasting employee, customer or client data into a general-purpose chatbot is a disciplinary matter in many functions and a contractual breach in co-source work. Know your function's approved-tool list, say that you check it, and describe how you documented the human review of anything a model produced.

The larger change is on the demand side, and it is where the new jobs are: AI has become a major audit subject. Boards and audit committees are asking internal audit for assurance over how their own company adopts it, and that work has a recognizable shape. Is there a complete inventory of AI use cases, including the ones that arrived inside a SaaS product nobody classified as AI? Who owns each one, and what approval gate did it pass before deployment? Where did the training data come from and was the company permitted to use it? Is there validation before go-live and monitoring for drift afterwards? Is there genuine human oversight where the decision is consequential to a person (hiring, credit, claims, pricing, clinical triage), or is the human a rubber stamp? Are inputs and outputs logged well enough to reconstruct a decision after a complaint? What do the vendor contracts say about data use and about the vendor's own subprocessors? And how much unapproved tool use is happening because the approved path is too slow?

Name the right frameworks and you will sound current without overclaiming: the NIST AI Risk Management Framework and its generative AI profile, ISO/IEC 42001 as the certifiable AI management system standard, model risk management expectations in banking under SR 11-7 which many firms have extended to AI systems that are not models in the classic sense, and the IIA's own AI guidance. For regulation, be careful in exactly the way an auditor should be. The EU AI Act creates obligations for high-risk systems (a risk management system, governance over training and validation data, technical documentation, logging, human oversight, accuracy and robustness, post-market monitoring) and separate obligations for general-purpose models, and its application dates are staggered and have been revisited since the text was adopted. Start dates for several US state AI laws have also moved. Do not quote a date in an interview. Name the obligation, say which classification triggers it, and say you would confirm current applicability against the current text. An auditor who confidently states a wrong effective date has just demonstrated the exact failure the profession exists to catch.

One last thing, because it is the part that affects people trying to get in rather than people already here. The tasks being automated are disproportionately the ones that used to train juniors: pulling the sample, tying out, formatting the workpaper, chasing the request list. That makes the first job harder to get, and it makes the first two years require more deliberate effort to learn what used to be absorbed by repetition. The counter is to arrive able to do what the automation does not: scope an audit to a real risk, test a full population, write a finding a process owner will sign, and hold the conversation when they do not want to.

Testing a full population instead of a sample

It is the change with the most direct effect on who gets hired. Functions are being asked to cover more risk with the same headcount, and testing 100 percent of a defined population is both more conclusive and, once the query exists, cheaper than sampling. An auditor who can only execute test steps on 25 items is competing on a shrinking skill.

Show it: Name one test you built end to end: the source system and table, the extract and how you proved the population was complete, the logic, the exceptions it produced, and the observation that resulted. For example a duplicate-payment test across a full year of AP lines, or a segregation of duties conflict test against an ERP role matrix. One real example beats listing five tools.

Using AI to draft, and owning the second draft

Drafting assistance genuinely saves hours on observations, summaries and prior-year file review, and functions that have adopted it expect you to use it. The risk is that a drafted finding carries an invented criterion, an overstated effect or a tone that makes a process owner defensive, and the auditor whose name is on it owns all three.

Show it: Say how you use it and where you stop: draft the structure, then verify the criterion against the actual policy or standard, quantify the effect yourself from the data, and rewrite the tone for the specific reader. Mention that you document the review. Interviewers are far more reassured by a candidate with a stated boundary than by one who claims not to use it at all.

Auditing the AI inventory and its governance

This is where new audit plan capacity is going. Most companies cannot produce a complete list of where AI is in use, because much of it arrived embedded inside purchased software, which makes inventory completeness the first and most frequently failed test in the whole area.

Show it: Describe the audit the way you would scope it: how you would establish completeness of the inventory (procurement records, expense data, network and SaaS discovery, survey, contract review), then approval gates, ownership, data provenance, validation and drift monitoring, human oversight on consequential decisions, logging, and incident handling. Name the NIST AI Risk Management Framework and ISO/IEC 42001 as criteria.

Model and vendor risk, including unapproved AI tools

Most of the AI a company relies on is somebody else's, which makes this a third-party risk problem as much as a technology one. In regulated financial services, existing model risk management expectations are being stretched over AI systems, and the gaps between the two regimes are exactly where findings live.

Show it: Talk about contract terms you would test for (data use and retention, training on customer data, subprocessors, audit rights, incident notification), what you would ask the vendor for (an independent assessment, model documentation, validation evidence), and how you would detect unapproved tool use. In banking, say how you would reconcile the AI inventory to the model inventory and explain what falls between them.

Evidence and reperformance for AI-assisted testing

Workpapers are the product. If a reviewer, an external auditor relying on your work, a regulator or a peer reviewer cannot reperform your test and reach your conclusion, the work does not count no matter how good the insight was.

Show it: Describe your documentation standard out loud: query logic retained, extract date and parameters, reconciliation of the population to a system control total and to the ledger, who ran the extract, what judgment calls you made and why, and a record that a human reviewed any model-generated content. This answer reliably separates experienced auditors from confident ones.

Data confidentiality discipline

The fastest way to lose an audit job is to put employee, customer or client data somewhere it was not approved to go. In co-source and consulting work it is a contractual breach, not just a policy one, and audit staff hold privileged access to exactly the data that would do the most damage.

Show it: Say that you work from the approved-tool list, that you check whether a tool retains or trains on inputs before using it, and that you de-identify where the test does not need identifiers. If your current employer has no list, say that and say what rule you applied instead. Honest and specific beats a confident generality.

Continuous monitoring rather than one-off audits

Once a test is written against a full population it can be rerun monthly for near zero marginal cost, which is pushing functions from annual point-in-time audits toward continuous control monitoring. The auditors who build those recurring tests become disproportionately valuable because their work keeps producing after the engagement closes.

Show it: Describe a test you turned into something repeatable: what triggered a rerun, who received the exceptions, how false positives were tuned down over time, and what happened to the exceptions operationally. If the business took it over as a first-line control, say so, because handing a test to the process owner is a stronger outcome than keeping it.

What a screen is looking for

These are the terms that a resume screen, human or automated, is matching against for this role. Use the ones that are true of you, in the words the posting uses.

Mistakes that cost people this job

Writing a resume of duties: "performed walkthroughs and testing of internal controls in accordance with departmental standards".

List audits, not activities. One line each: process and entity, the scope figure that makes it real, whether you led or tested, observations issued with their ratings, and whether management agreed at first draft and closed on time. Every element is checkable in a reference call, which is exactly why it persuades.

Claiming SOX experience without being able to distinguish a control deficiency from a significant deficiency from a material weakness.

Know the escalation logic and be able to talk through one real evaluation you participated in: what the deficiency was, how severity was assessed against the possible magnitude and the likelihood of a misstatement, who decided, and what the external auditor did with it. This is the most common technical bluff in the field and it is caught with one follow-up question.

Answering the risk question with controls. "What could go wrong in vendor setup?" "Well, there should be a second approver."

Keep the four concepts separate out loud. Inherent risk is what could go wrong with no control at all (a fictitious vendor is created and paid). The control is the activity that prevents or detects it. The test is how you prove the control operated. The finding is the gap against the criterion. Collapsing them is the clearest inexperience signal in an internal audit interview.

Writing findings with no criteria: "the reconciliation was not performed".

Name the criterion explicitly: the policy and its section, the contract clause, the regulation, the framework principle, or the documented control design. Without it you have stated an opinion, and a process owner is entitled to decline an opinion. With it you have stated a gap against a standard the company set for itself, which is much harder to argue with.

Stopping root cause at a restatement of the condition. "The cause was that the control was not performed."

Push to something structural: the only trained preparer left and nobody was cross-trained, the feeder report changed format after an upgrade, the control lost its owner in a reorganization, the deadline incentive rewards speed over accuracy, or the system permits the action the policy forbids. Weak root cause analysis is the profession's acknowledged soft spot, so a candidate who does it well stands out immediately.

Treating the writing exercise as a formality and dashing it off.

Treat it as the deciding stage, because in many loops it is. Report writing is the function's actual deliverable and poor writing is a common reason a technically capable candidate is passed over. Practice producing a 250-word observation with all five elements, a justified rating, numbers instead of adjectives, and a tone a process owner could read without becoming defensive.

Having no answer to "how did you know the population was complete?"

Prepare a real one: the extract was reconciled to a system-generated control total and tied to the general ledger, the query logic was documented and independently rerun, and the extract was not run by the person who owns the data. This is the sharpest technical question in the loop and most candidates have never been asked it before the interview.

Describing yourself as the company's police, or as the person who catches people.

Describe yourself as the person who gets things fixed. Say it in outcome terms: observations agreed at first draft, remediation closed on time, a control the business took over and now runs itself. An auditor who wins arguments and is never invited back has failed; half this job is persuading people who did not ask for you.

Telling only the story where management agreed with you and thanked you.

Bring the one you lost or the one that got downgraded. Say what the counter-argument was, which part of it was legitimate, what you escalated and what you let go, and what the relationship looked like afterwards. That is the story that shows judgment and the one experienced interviewers are listening for.

Answering the fraud scenario with "I would investigate and find out what happened".

Stop, preserve what you have, do not interview anyone and do not alert the suspected party, and escalate under the fraud policy to the chief audit executive and from there to legal, investigations or the audit committee. Enthusiasm here destroys evidence and collapses cases, and the interviewer is testing restraint.

Only applying to corporate senior internal auditor postings that ask for five years of internal audit experience.

Apply where the hiring volume is: co-source and outsource firms, finance and audit staffing agencies, contract SOX testing season work, campus and rotational programs, and the audit team at the company you already work for. The narrowest door in the building is the one most career changers spend six months knocking on.

Saying "performed data analytics" with no test named.

Name one test and its result. Duplicate payments across a full year of AP lines. Purchase orders split just below the approval threshold. Journal entries posted outside business hours by users without posting authority. Vendor bank-account changes followed by a payment inside seven days. The specific test is the whole demonstration.

Quoting a regulatory effective date from memory, especially for AI or privacy rules.

State the obligation without the date, name what triggers it, and say you would confirm current applicability against the current text. Start dates for AI legislation have been revisited after adoption in more than one jurisdiction. An auditor who confidently asserts a wrong date has just failed a live demonstration of the profession's core discipline.

Taking a role that reports to the controller, audits the controller's processes, and is called internal audit.

Ask early who the chief audit executive reports to functionally and administratively, and whether there is a private session with the audit committee without management present. The job may still be worth taking, but know whether you are joining an independent audit function or an internal controls team inside finance, because the career ladders differ.

Questions people ask

Do you need a license to be an internal auditor?

No. Internal auditing is not a licensed occupation in any US state. There is no board to register with, no state exam, no required apprenticeship hours and no protected title, so an employer can hire anyone into the role tomorrow. What employers require instead is a bachelor's degree, relevant experience, and usually a certification: most commonly the Certified Internal Auditor (CIA) from the Institute of Internal Auditors, or a CPA for finance-heavy audit work, or CISA for IT audit. The only hard legal limits nearby are that you cannot call yourself a CPA without a state license, and that in banking a conviction involving dishonesty, breach of trust or money laundering can bar employment under section 19 of the Federal Deposit Insurance Act unless the FDIC consents.

Do employers require the CIA, or just prefer it?

Whether an internal auditor needs the CIA depends on the employer, and the posting usually overstates it. Large financial services functions, insurers, healthcare systems and public sector audit shops commonly require the CIA or require you to obtain it within a stated window after hire, and they usually reimburse the cost. Corporate functions outside financial services typically accept "CIA, CPA or CISA" interchangeably and will hire a strong candidate with none of them if the audit experience is right. Co-source and consulting firms hire you without it and then push you toward it. If you do not have it yet, write the precise status on your resume ("CIA, Parts 1 and 2 passed, Part 3 scheduled March 2027"), because a bare "CIA candidate" is read as not having started.

How long does the CIA take, and how hard is it?

Six to twelve months part time is the realistic range for someone already working in audit, taking one part at a time, and longer for a career changer. There are three exams, takeable in any order: Part 1 Essentials of Internal Auditing, Part 2 Practice of Internal Auditing, and Part 3 Business Knowledge for Internal Auditing. Part 3 is where auditors with narrow experience most often fail, because it is a business literacy exam rather than an audit exam: organizational structure, business processes, information security, IT and financial management. Exams run year round at test centers, but the IIA limits how long you have to complete the program after approval, and it has revised question counts, timings and fees more than once, so confirm the current rules on theiia.org before registering.

Can I get into internal audit without working in public accounting first?

Yes, and a large share of working internal auditors did exactly that. Four routes work without public accounting. Co-source and outsource firms (Protiviti, the Big Four risk practices, Grant Thornton, RSM, BDO, Crowe, Baker Tilly and strong regional firms) hire in volume, year round, and accept non-accounting degrees more readily than corporate departments do. Campus and rotational internal audit programs at banks, insurers, utilities, retailers and health systems recruit undergraduates directly. Moving sideways from inside a business process you already run is common for operational audit, because process knowledge is the thing audit teams cannot hire externally. And IT operations, security or GRC work leads into IT audit, where CISA is the credential and postings often pay above general internal audit.

Do I need an accounting degree to be an internal auditor?

Not for most internal auditor jobs. Accounting, finance, information systems, business, economics and data analytics degrees all appear in internal audit teams, and IT audit in particular recruits from computer science and information security. Accounting matters most for SOX and financial reporting audit, and it is genuinely required for some federal auditing roles: the GS-0511 auditing series carries a positive education requirement, typically a degree including a set number of semester hours in accounting, stated on each job announcement. If your degree is in something else and you want SOX work, a few accounting courses plus the CIA closes the gap faster and more cheaply than a second degree.

What is the difference between internal audit and external audit?

External auditors are engaged on behalf of shareholders through the audit committee to give an opinion on whether the financial statements are fairly stated, their scope is driven by financial statement materiality, and they work for an independent firm. Internal auditors are employees or contracted staff of the organization, report functionally to the audit committee of the board and administratively to a senior executive, and their scope is whatever the board and the risk assessment say it is: operations, compliance, IT, fraud, culture, capital projects and third parties, as well as financial controls. External audit produces an opinion for outsiders; internal audit produces assurance and recommendations for the board and management. In a SOX environment the two overlap, because the external auditor may rely on internal audit's testing.

What questions does an internal audit interview ask?

One central skill, asked several ways: given a process, can you name what could go wrong, identify the control that should address it, design a test that proves the control operated, and write the result as a finding with condition, criteria, cause, effect and recommendation. Around that, expect "walk me through an audit from planning to report", at least one independence or management-pressure scenario, a fraud escalation question, and two technical questions that separate experienced auditors sharply: how you set your sample size, and how you knew the population was complete. Many loops also include a written exercise, which is where capable candidates most often lose the job, because report writing is the function's actual deliverable.

How long does internal audit hiring take?

Three to six weeks is normal for a corporate internal audit role: recruiter screen, audit manager interview, a panel of two to four auditors and sometimes a business stakeholder, often a written exercise or case, a director or chief audit executive conversation for senior roles, then background check and in financial services frequently a credit check. Co-source and staffing firms move faster, sometimes in under two weeks, and contract SOX season roles faster still. Public sector hiring runs months: applications on USAJOBS or a state portal are scored against stated criteria before a human reads them, so write them long and specific, and structured panels rate answers against a rubric.

Is internal audit a good career, or a dead end?

Working as an internal auditor is a strong career, and the exit options are one of the main reasons to take it. Internal audit is one of the only roles that carries a standing mandate to examine every process, meet every process owner and read every policy, with a reporting line that reaches the board. Three to five years in it leaves you with a map of how the business works that almost nobody at your level has, which is why large companies run internal audit rotational programs explicitly as leadership pipelines. Common exits are controllership and technical accounting, FP&A, enterprise risk management, compliance, business operations, transformation programs, SOX program ownership, and first-line risk roles in banking. Staying is also a real career: chief audit executive is a board-facing position.

Will AI replace internal auditors?

Not at the core of the job, and claims to the contrary do not survive contact with how the work is evidenced. Evidence standards require that another auditor can reperform your test and reach your conclusion, independence is a structural property of the function rather than a task, judgment about what is material enough to report is contested rather than computed, and persuading a process owner to sign up to a remediation date is a conversation. What has changed is real but narrower: full population testing instead of samples, faster workpaper and first-draft writing, and shorter cycle times. The bigger shift is on the demand side, with boards asking internal audit to provide assurance over the company's own AI adoption, which has created work rather than removing it. The painful part is that the tasks being automated are the ones that used to train juniors, which makes the first job harder to get.

Put this on a resume in about a minute

Paste your history once and point it at the Internal Auditor posting you are looking at. No account, no card.

Build my resume free More roles