See Audithink's Latest Events →

Audithink Internal Audit Glossary: 100 Audit Terms from A to Z

Internal audit terms glossary

Topic Recommendations

Share Article

Ready To Improve Your Internal Audit Process?

Discover Audithink's full features and choose a pricing plan that works for your audit team. Start audit transformation now!

A collection of 100 internal audit and GRC terms, from the basics of the auditor's role to specialized audit types by industry, each entry with a short definition and a link to the full article.
Table Of Contents

The world of internal audit has many technical terms that are not always clear to people outside the profession, from basic roles like auditor and auditee to specific terms like risk-based audit or audit trail. This glossary compiles the 100 most frequently searched internal audit and GRC terms, organized by category.

Each term is given a short one- to two-sentence definition, with a link to the full article on our site for a deeper discussion, complete with examples and steps.

Reference book of audit and GRC terms

A. Basics and Roles in Audit

TermsShort Definition
AuditA systematic and independent examination of an organization's records, processes, or performance to assess their compliance with specific criteria.
AuditorsAn individual who performs audits independently and objectively to assess the processes, records, or performance of an organizational unit.
AuditeeThe party, work unit, or process that is the subject of examination in an audit engagement.
Internal AuditAn independent assurance and consulting function within an organization designed to add value and improve company operations.
Audit TeamA group of auditors assigned together to carry out one audit engagement, usually consisting of a team leader and members.
PIC (Person in Charge)The individual designated as the main person responsible for a process, task, or audit finding follow-up.
Internal Audit StaffPersonnel in the internal audit unit who carry out day-to-day audit tasks, from preparation through fieldwork.
Admin AuditAn administrative role that supports the audit team's operations, including scheduling, documentation, and coordination with auditees.
Internal Audit ConsultantAn external professional who provides assurance or internal audit consulting services to organizations that do not yet have their own internal audit function.
Company AuditA general term for audit activities carried out on a company, whether by internal auditors or a public accounting firm.

B. Audit Process and Stages

TermsShort Definition
Audit ProcessThe overall series of audit activities, from planning through reporting and follow-up.
Audit StagesThe sequential steps in carrying out an audit, generally including planning, fieldwork, reporting, and follow-up.
Audit ProcedureThe specific techniques and steps auditors carry out to gather sufficient audit evidence.
Audit ProgramA work plan document detailing the procedures, scope, and time allocation for one audit engagement.
Internal Audit Work ProgramThe overall internal audit work plan for one period, listing the audits to be carried out.
Audit PlanningThe initial audit stage to determine objectives, scope, resources, and implementation schedule.
Audit PlanAn annual audit plan document listing the units or processes to be audited along with their priorities.
Audit UniverseA comprehensive list of all units, processes, or entities that could potentially become audit subjects within an organization.
Audit CycleThe recurring pattern of audit stages carried out periodically within one accounting period or fiscal year.
Audit ScopeThe boundaries of area, period, and aspects to be examined in an audit engagement.

C. Evidence, Documentation, and Audit Techniques

TermsShort Definition
Audit EvidenceInformation gathered by the auditor to support an opinion or conclusion on an examination.
Audit Working PapersWritten documentation recording the auditor's procedures, evidence, and conclusions during an audit.
Audit TrailA digital trail that records every data change, complete with who made the change and when.
Audit AssertionsManagement's implicit or explicit statements in a report that form the basis for the auditor's testing.
Audit JudgementThe auditor's professional judgement in evaluating evidence and reaching audit conclusions.
Audit TracingAn audit technique that traces source documents to accounting records to test the completeness of recording.
Audit VouchingAn audit technique that traces accounting records back to source documents to test the validity of transactions.
Audit TechniqueThe specific methods auditors use to gather and test evidence, such as inspection, observation, and confirmation.
Internal Audit ChecklistA structured list of inspection points that helps auditors ensure all important aspects have been examined.
Walkthrough AuditA procedure of tracing a single transaction from start to finish to understand and test the design of internal controls.

D. Risk and Control

TermsShort Definition
Audit RiskThe risk that an auditor issues an inappropriate opinion because the report contains an undetected material misstatement.
Risk AssessmentThe process of identifying, analyzing, and evaluating risk to determine audit priorities and focus.
Risk-Based Audit (RBIA)An audit approach that builds the audit plan and priorities based on the risk level of each unit or process.
Inherent RisksThe inherent risk of an account or transaction before considering the effectiveness of existing internal controls.
Control RiskThe risk that an organization's internal controls fail to prevent or detect a material misstatement in a timely manner.
Internal ControlA process designed by management to provide reasonable assurance over reliable reporting, compliance, and operational efficiency.
COSO FrameworkAn internal control framework widely adopted globally, consisting of five main components.
ISO 31000An international standard providing general principles and guidelines for organizational risk management.
Risk ManagementThe process of identifying, assessing, and managing risk so its impact on organizational objectives can be minimized.
Risk Management AuditAn examination of the effectiveness of an organization's risk management process.

E. Types of Audit by Function

TermsShort Definition
External AuditAn independent examination of financial statements carried out by a public accounting firm outside the organization.
ISO Internal AuditAn internal audit that assesses an organization's management system compliance against specific ISO standard requirements.
Operational AuditAn examination of the efficiency and effectiveness of a unit's or organization's operational processes.
Financial AuditAn examination of the fairness of financial statement presentation in accordance with applicable accounting standards.
Compliance AuditAn examination to assess an organization's compliance with applicable regulations, policies, or contracts.
Performance AuditAn examination of the economy, efficiency, and effectiveness of a program or work unit in achieving its objectives.
Management AuditA comprehensive examination of an organization's management practices to assess the effectiveness of its management.
Forensic AuditA special examination aimed at uncovering indications of fraud for legal purposes.
Investigative AuditAn in-depth examination of alleged violations or fraud based on existing initial indications.
Special AuditAn audit that focuses on a specific area or issue outside the regular audit cycle, usually at management's request.
General AuditA comprehensive audit of an entity's financial statements for one full accounting period.
Interim AuditAn audit carried out before the end of the accounting period to test internal controls earlier.
Combined AuditAn audit that combines more than one type of examination, such as financial and compliance, in a single engagement.
Agile AuditAn audit approach that adopts iterative and collaborative principles from agile methodology to speed up the audit cycle.
Probity AuditAn audit that assesses the integrity and fairness of a procurement process or specific business decision.

F. Audit by Industry and Domain

TermsShort Definition
Clinical AuditA systematic examination of the quality of clinical services at a healthcare facility compared against established standards.
Medical AuditAn examination of the quality and compliance of medical services with practice standards and health regulations.
Payroll AuditAn examination of the accuracy and compliance of an employee payroll process against policies and regulations.
HR AuditAn examination of an organization's human resource management policies, processes, and practices.
Human Resource AuditAnother term for an HR audit, assessing the overall effectiveness of the human resources function.
Payroll and personnel AuditA combined examination of an organization's payroll process and personnel administration.
Tax AuditsAn examination of a taxpayer's compliance with tax calculation and reporting requirements under applicable tax regulations.
An IT AuditAn examination of the controls, security, and governance of an organization's information technology systems.
Information Systems AuditAn examination of the reliability, security, and effectiveness of the information systems an organization uses.
ERP AuditAn examination of the configuration, access controls, and data integrity within a company's ERP system.
Audit SMK3An examination of the implementation of an occupational health and safety management system at a company.
SMKP AuditAn examination of the implementation of a mining safety management system at a company in the mining sector.
Sharia AuditAn examination of the compliance of financial transactions and products with sharia principles.
Bank AuditAn examination of the operations, compliance, and internal controls of a banking institution.
Legal AuditAn examination of a company's legal compliance and risk, including contracts and licensing.

G. Modern Audit, Fraud, and Technology

TermsShort Definition
Fraud AuditAn examination focused on detecting and uncovering indications of fraud within an organization.
Fraud TriangleA conceptual framework explaining three conditions that drive fraud: pressure, opportunity, and rationalization.
Fraud InvestigationAn in-depth investigation process to gather evidence on suspected fraudulent acts that have already been identified.
Continuous AuditAn audit approach that monitors data and controls continuously, not only at a specific point in time.
SOX AuditA compliance audit against the Sarbanes-Oxley Act, a US regulation governing internal controls over financial reporting.
Shadow IT AuditAn examination of the use of IT systems or applications running outside the official oversight of the IT department.
GRC AuditAn examination of the effectiveness of an organization's integrated implementation of governance, risk, and compliance.
GRC (Governance, Risk, Compliance)A framework that unifies governance, risk management, and compliance into a single integrated approach.

H. Findings, Reporting, and Follow-up

TermsShort Definition
Audit ReportAn official document containing the auditor's results, findings, and recommendations for an audit engagement.
Audit OpinionThe auditor's professional conclusion on the fairness of the financial statements examined.
Unqualified OpinionThe best type of audit opinion, stating that the financial statements are fairly presented in accordance with accounting standards.
Audit Finding Follow-upThe process of monitoring the auditee's completion of audit recommendations until the status is fully resolved.
NoticeAn official notification from the auditor to the auditee about an audit finding that requires a response or follow-up.
Internal Audit Management ReviewA periodic evaluation meeting where top management reviews the performance and effectiveness of the internal audit function.
Internal Control (in Audit)The policies and procedures auditors test to assess the reliability of an organization's internal controls.

I. Governance, Compliance, and Standards

TermsShort Definition
ESGA framework for assessing company performance on environmental, social, and governance aspects.
Compliance Management SystemA framework of policies and processes that ensures an organization complies with applicable regulations and standards.
Internal Audit Code of EthicsProfessional conduct principles that internal auditors must uphold, including integrity, objectivity, and confidentiality.
Audit StandardsA professional reference framework that governs the quality of audit execution and reporting.
Internal Audit Standards in IndonesiaThe internal audit profession's guidelines that apply nationally to internal auditors in Indonesia.
Quality Standards Of Internal Audit ReportsCriteria that determine whether an internal audit report is clear, accurate, objective, and timely.
Internal Audit ScopeThe boundaries of work that fall under the responsibility of an organization's internal audit function.
Types of AuditsThe classification of audits based on purpose, subject, and the party carrying them out, such as internal, external, and special audits.

J. Audit Metrics and Operational Aspects

TermsShort Definition
Internal Audit KPIsKey performance indicators used to measure the effectiveness and productivity of the internal audit function.
Audit TenureThe length of an auditor's or public accounting firm's engagement with the same client.
Audit DelayThe span of time between the end of the accounting period and the date the audit report is issued.
Audit Report LagAnother term for audit delay, measuring the delay in issuing the audit report from the closing date.
Audit FeeThe compensation a client pays to an auditor or public accounting firm for audit services.
Audit RotationThe periodic replacement of an auditor or public accounting firm to maintain independence.
Stock OpnameThe process of physically counting inventory to reconcile actual quantities with bookkeeping records.

FAQ About the Internal Audit Glossary

Does this glossary cover every audit term that exists?

Not all of them, but this glossary covers the 100 terms most frequently searched for and most relevant to internal audit teams in Indonesia. We will update this list periodically.

What is the difference between internal audit and external audit?

Internal audit is carried out by a function within the organization for ongoing assurance and consulting purposes, while external audit is carried out by an independent public accounting firm mainly to assess the fairness of financial statements.

Where do the definitions in this glossary come from?

The definitions are compiled from commonly used audit literature and professional standards, then summarized into easy-to-understand language. For a full discussion of each term, visit the linked article.

Conclusion

Mastering audit terminology helps enable more precise communication between auditors, auditees, and management. Save this page as a quick reference, and explore the full article for each term for a deeper understanding.

If your organization is looking for a way to manage this entire audit process within one system, schedule an Audithink demo and see for yourself how these terms translate into real workflows.

Find out how the implementation of the audit application can have a positive impact on the company on an ongoing basis.

Consultation on Your Needs

Related Articles

Internal audit statistics and data in Indonesia
Audit produksi
Environmental Health and Safety Audit of Palm Oil Plantations