The world of internal audit has many technical terms that are not always clear to people outside the profession, from basic roles like auditor and auditee to specific terms like risk-based audit or audit trail. This glossary compiles the 100 most frequently searched internal audit and GRC terms, organized by category.
Each term is given a short one- to two-sentence definition, with a link to the full article on our site for a deeper discussion, complete with examples and steps.

A. Basics and Roles in Audit
| Terms | Short Definition |
|---|---|
| Audit | A systematic and independent examination of an organization's records, processes, or performance to assess their compliance with specific criteria. |
| Auditors | An individual who performs audits independently and objectively to assess the processes, records, or performance of an organizational unit. |
| Auditee | The party, work unit, or process that is the subject of examination in an audit engagement. |
| Internal Audit | An independent assurance and consulting function within an organization designed to add value and improve company operations. |
| Audit Team | A group of auditors assigned together to carry out one audit engagement, usually consisting of a team leader and members. |
| PIC (Person in Charge) | The individual designated as the main person responsible for a process, task, or audit finding follow-up. |
| Internal Audit Staff | Personnel in the internal audit unit who carry out day-to-day audit tasks, from preparation through fieldwork. |
| Admin Audit | An administrative role that supports the audit team's operations, including scheduling, documentation, and coordination with auditees. |
| Internal Audit Consultant | An external professional who provides assurance or internal audit consulting services to organizations that do not yet have their own internal audit function. |
| Company Audit | A general term for audit activities carried out on a company, whether by internal auditors or a public accounting firm. |
B. Audit Process and Stages
| Terms | Short Definition |
|---|---|
| Audit Process | The overall series of audit activities, from planning through reporting and follow-up. |
| Audit Stages | The sequential steps in carrying out an audit, generally including planning, fieldwork, reporting, and follow-up. |
| Audit Procedure | The specific techniques and steps auditors carry out to gather sufficient audit evidence. |
| Audit Program | A work plan document detailing the procedures, scope, and time allocation for one audit engagement. |
| Internal Audit Work Program | The overall internal audit work plan for one period, listing the audits to be carried out. |
| Audit Planning | The initial audit stage to determine objectives, scope, resources, and implementation schedule. |
| Audit Plan | An annual audit plan document listing the units or processes to be audited along with their priorities. |
| Audit Universe | A comprehensive list of all units, processes, or entities that could potentially become audit subjects within an organization. |
| Audit Cycle | The recurring pattern of audit stages carried out periodically within one accounting period or fiscal year. |
| Audit Scope | The boundaries of area, period, and aspects to be examined in an audit engagement. |
C. Evidence, Documentation, and Audit Techniques
| Terms | Short Definition |
|---|---|
| Audit Evidence | Information gathered by the auditor to support an opinion or conclusion on an examination. |
| Audit Working Papers | Written documentation recording the auditor's procedures, evidence, and conclusions during an audit. |
| Audit Trail | A digital trail that records every data change, complete with who made the change and when. |
| Audit Assertions | Management's implicit or explicit statements in a report that form the basis for the auditor's testing. |
| Audit Judgement | The auditor's professional judgement in evaluating evidence and reaching audit conclusions. |
| Audit Tracing | An audit technique that traces source documents to accounting records to test the completeness of recording. |
| Audit Vouching | An audit technique that traces accounting records back to source documents to test the validity of transactions. |
| Audit Technique | The specific methods auditors use to gather and test evidence, such as inspection, observation, and confirmation. |
| Internal Audit Checklist | A structured list of inspection points that helps auditors ensure all important aspects have been examined. |
| Walkthrough Audit | A procedure of tracing a single transaction from start to finish to understand and test the design of internal controls. |
D. Risk and Control
| Terms | Short Definition |
|---|---|
| Audit Risk | The risk that an auditor issues an inappropriate opinion because the report contains an undetected material misstatement. |
| Risk Assessment | The process of identifying, analyzing, and evaluating risk to determine audit priorities and focus. |
| Risk-Based Audit (RBIA) | An audit approach that builds the audit plan and priorities based on the risk level of each unit or process. |
| Inherent Risks | The inherent risk of an account or transaction before considering the effectiveness of existing internal controls. |
| Control Risk | The risk that an organization's internal controls fail to prevent or detect a material misstatement in a timely manner. |
| Internal Control | A process designed by management to provide reasonable assurance over reliable reporting, compliance, and operational efficiency. |
| COSO Framework | An internal control framework widely adopted globally, consisting of five main components. |
| ISO 31000 | An international standard providing general principles and guidelines for organizational risk management. |
| Risk Management | The process of identifying, assessing, and managing risk so its impact on organizational objectives can be minimized. |
| Risk Management Audit | An examination of the effectiveness of an organization's risk management process. |
E. Types of Audit by Function
| Terms | Short Definition |
|---|---|
| External Audit | An independent examination of financial statements carried out by a public accounting firm outside the organization. |
| ISO Internal Audit | An internal audit that assesses an organization's management system compliance against specific ISO standard requirements. |
| Operational Audit | An examination of the efficiency and effectiveness of a unit's or organization's operational processes. |
| Financial Audit | An examination of the fairness of financial statement presentation in accordance with applicable accounting standards. |
| Compliance Audit | An examination to assess an organization's compliance with applicable regulations, policies, or contracts. |
| Performance Audit | An examination of the economy, efficiency, and effectiveness of a program or work unit in achieving its objectives. |
| Management Audit | A comprehensive examination of an organization's management practices to assess the effectiveness of its management. |
| Forensic Audit | A special examination aimed at uncovering indications of fraud for legal purposes. |
| Investigative Audit | An in-depth examination of alleged violations or fraud based on existing initial indications. |
| Special Audit | An audit that focuses on a specific area or issue outside the regular audit cycle, usually at management's request. |
| General Audit | A comprehensive audit of an entity's financial statements for one full accounting period. |
| Interim Audit | An audit carried out before the end of the accounting period to test internal controls earlier. |
| Combined Audit | An audit that combines more than one type of examination, such as financial and compliance, in a single engagement. |
| Agile Audit | An audit approach that adopts iterative and collaborative principles from agile methodology to speed up the audit cycle. |
| Probity Audit | An audit that assesses the integrity and fairness of a procurement process or specific business decision. |
F. Audit by Industry and Domain
| Terms | Short Definition |
|---|---|
| Clinical Audit | A systematic examination of the quality of clinical services at a healthcare facility compared against established standards. |
| Medical Audit | An examination of the quality and compliance of medical services with practice standards and health regulations. |
| Payroll Audit | An examination of the accuracy and compliance of an employee payroll process against policies and regulations. |
| HR Audit | An examination of an organization's human resource management policies, processes, and practices. |
| Human Resource Audit | Another term for an HR audit, assessing the overall effectiveness of the human resources function. |
| Payroll and personnel Audit | A combined examination of an organization's payroll process and personnel administration. |
| Tax Audits | An examination of a taxpayer's compliance with tax calculation and reporting requirements under applicable tax regulations. |
| An IT Audit | An examination of the controls, security, and governance of an organization's information technology systems. |
| Information Systems Audit | An examination of the reliability, security, and effectiveness of the information systems an organization uses. |
| ERP Audit | An examination of the configuration, access controls, and data integrity within a company's ERP system. |
| Audit SMK3 | An examination of the implementation of an occupational health and safety management system at a company. |
| SMKP Audit | An examination of the implementation of a mining safety management system at a company in the mining sector. |
| Sharia Audit | An examination of the compliance of financial transactions and products with sharia principles. |
| Bank Audit | An examination of the operations, compliance, and internal controls of a banking institution. |
| Legal Audit | An examination of a company's legal compliance and risk, including contracts and licensing. |
G. Modern Audit, Fraud, and Technology
| Terms | Short Definition |
|---|---|
| Fraud Audit | An examination focused on detecting and uncovering indications of fraud within an organization. |
| Fraud Triangle | A conceptual framework explaining three conditions that drive fraud: pressure, opportunity, and rationalization. |
| Fraud Investigation | An in-depth investigation process to gather evidence on suspected fraudulent acts that have already been identified. |
| Continuous Audit | An audit approach that monitors data and controls continuously, not only at a specific point in time. |
| SOX Audit | A compliance audit against the Sarbanes-Oxley Act, a US regulation governing internal controls over financial reporting. |
| Shadow IT Audit | An examination of the use of IT systems or applications running outside the official oversight of the IT department. |
| GRC Audit | An examination of the effectiveness of an organization's integrated implementation of governance, risk, and compliance. |
| GRC (Governance, Risk, Compliance) | A framework that unifies governance, risk management, and compliance into a single integrated approach. |
H. Findings, Reporting, and Follow-up
| Terms | Short Definition |
|---|---|
| Audit Report | An official document containing the auditor's results, findings, and recommendations for an audit engagement. |
| Audit Opinion | The auditor's professional conclusion on the fairness of the financial statements examined. |
| Unqualified Opinion | The best type of audit opinion, stating that the financial statements are fairly presented in accordance with accounting standards. |
| Audit Finding Follow-up | The process of monitoring the auditee's completion of audit recommendations until the status is fully resolved. |
| Notice | An official notification from the auditor to the auditee about an audit finding that requires a response or follow-up. |
| Internal Audit Management Review | A periodic evaluation meeting where top management reviews the performance and effectiveness of the internal audit function. |
| Internal Control (in Audit) | The policies and procedures auditors test to assess the reliability of an organization's internal controls. |
I. Governance, Compliance, and Standards
| Terms | Short Definition |
|---|---|
| ESG | A framework for assessing company performance on environmental, social, and governance aspects. |
| Compliance Management System | A framework of policies and processes that ensures an organization complies with applicable regulations and standards. |
| Internal Audit Code of Ethics | Professional conduct principles that internal auditors must uphold, including integrity, objectivity, and confidentiality. |
| Audit Standards | A professional reference framework that governs the quality of audit execution and reporting. |
| Internal Audit Standards in Indonesia | The internal audit profession's guidelines that apply nationally to internal auditors in Indonesia. |
| Quality Standards Of Internal Audit Reports | Criteria that determine whether an internal audit report is clear, accurate, objective, and timely. |
| Internal Audit Scope | The boundaries of work that fall under the responsibility of an organization's internal audit function. |
| Types of Audits | The classification of audits based on purpose, subject, and the party carrying them out, such as internal, external, and special audits. |
J. Audit Metrics and Operational Aspects
| Terms | Short Definition |
|---|---|
| Internal Audit KPIs | Key performance indicators used to measure the effectiveness and productivity of the internal audit function. |
| Audit Tenure | The length of an auditor's or public accounting firm's engagement with the same client. |
| Audit Delay | The span of time between the end of the accounting period and the date the audit report is issued. |
| Audit Report Lag | Another term for audit delay, measuring the delay in issuing the audit report from the closing date. |
| Audit Fee | The compensation a client pays to an auditor or public accounting firm for audit services. |
| Audit Rotation | The periodic replacement of an auditor or public accounting firm to maintain independence. |
| Stock Opname | The process of physically counting inventory to reconcile actual quantities with bookkeeping records. |
FAQ About the Internal Audit Glossary
Does this glossary cover every audit term that exists?
Not all of them, but this glossary covers the 100 terms most frequently searched for and most relevant to internal audit teams in Indonesia. We will update this list periodically.
What is the difference between internal audit and external audit?
Internal audit is carried out by a function within the organization for ongoing assurance and consulting purposes, while external audit is carried out by an independent public accounting firm mainly to assess the fairness of financial statements.
Where do the definitions in this glossary come from?
The definitions are compiled from commonly used audit literature and professional standards, then summarized into easy-to-understand language. For a full discussion of each term, visit the linked article.
Conclusion
Mastering audit terminology helps enable more precise communication between auditors, auditees, and management. Save this page as a quick reference, and explore the full article for each term for a deeper understanding.
If your organization is looking for a way to manage this entire audit process within one system, schedule an Audithink demo and see for yourself how these terms translate into real workflows.



