See Audithink's Latest Events →

Audit: Definition, Functions, Types, and the Stages of the Process

audit is

Topic Recommendations

Share Article

Ready To Improve Your Internal Audit Process?

Discover Audithink's full features and choose a pricing plan that works for your audit team. Start audit transformation now!

An audit is a systematic, objective, and independent examination that assesses whether a process conforms to established criteria. Read on for the definition, functions, types, and stages of the process.
Table Of Contents

An audit is a systematic, objective, and independent examination of an organisation's reports, processes, or activities to assess their conformity with established criteria. The results are set out as an opinion or as findings, which become the basis for decision-making and improvement.

Although often associated with financial statements, the scope of auditing is far broader — from regulatory compliance and operational effectiveness through to information system security. In Indonesia, audit practice is governed by various standards such as the Internal Audit Professional Standards (SPAI), the IAPI Auditing Standards (SA), and the SPIP framework for government institutions.

This article covers the meaning of auditing in full: its constituent elements, functions and objectives, types, process stages, the parties who carry it out, and the standards that apply in Indonesia.

Definition of Audit

An audit is the systematic process of gathering and evaluating evidence to determine the degree of conformity between actual conditions and established criteria, and then communicating the results to interested parties.

Several definitions from applicable standards and literature:

  • The Institute of Internal Auditors (IIA) defines internal audit as an assurance (assurance) and consulting activity that is independent and objective, designed to add value and improve an organisation's operations through a systematic approach to evaluating and improving the effectiveness of risk management, control, and governance.
  • ISO 19011:2018 defines an audit as a systematic, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled.
  • Arens, Elder, and Beasley describe an audit as the gathering and evaluation of evidence about information in order to determine and report the degree of conformity between that information and established criteria, carried out by a competent and independent person.

The common thread across all three definitions is the same: an audit is not merely a "check" but an evidence-based process carried out independently against clear criteria.

Elements of an Audit

An activity can only be called an audit when it meets the following elements.

1. Audit Criteria

The standards, policies, procedures, or regulations that serve as the benchmark for assessment. Without clear criteria, an auditor has no basis for declaring something fair or unfair. Examples of criteria: SAK for financial statements, Government Regulation 60/2008 for government internal control, or ISO 27001 for information security.

2. Bukti Audit

Information gathered by the auditor to support conclusions; it may take the form of documents, interview results, field observation, third-party confirmation, or system data. Evidence must be sufficient (sufficient) and appropriate (appropriate).

3. Independence and Objectivity

The auditor must be free of any conflict of interest regarding the object being audited. This is what distinguishes an audit from a mere internal review by the people running the process themselves.

4. Auditor Competence

The auditor must have adequate knowledge, skills, and experience in the field being audited.

5. Reporting

Audit results must be communicated formally to interested parties, generally in the form of an audit report setting out the findings, conclusions, and recommendations.

Audit, Review, and Inspection: What Is the Difference?

AspectAuditReviewInspection
Level of assuranceReasonable (reasonable assurance)Limited (limited assurance)Provides no assurance
ProcedureIn-depth testing of evidenceLimited to analytics & enquiryDirect observation of the object
OutputFormal opinion/findingsNegative conclusionRecord of conditions
IndependencyMandatoryMandatoryNot always

Functions and Objectives of an Audit

An audit is a governance instrument that performs several key functions at once.

1. Ensuring Reliable Information

The most fundamental function of an audit is to ensure that the information an organisation presents — financial statements, performance reports, or operational data — is accurate and reliable. For shareholders, creditors, regulators, and other stakeholders, audited reports provide a safer basis for decision-making.

2. Ensuring Regulatory Compliance

An audit tests whether an organisation has carried out its activities in line with legislation, internal policy, and binding contracts. For state-owned enterprises, regionally owned enterprises, and government institutions, this function is crucial because it relates directly to accountability for the use of public funds.

3. Evaluating the Effectiveness of Internal Control

Through control testing, an audit identifies gaps in the internal control system that could give rise to error, inefficiency, or fraud. The auditor's recommendations then form the basis for strengthening those controls.

4. Detecting and Preventing Fraud

Although fraud prevention is management's responsibility, the audit acts as a line of defence that raises the risk of irregularities being detected. The existence of the audit function itself has a preventive effect.

5. Providing Recommendations for Improvement

A modern audit does not stop at the findings. Internal auditors provide concrete recommendations for improving process efficiency, optimising the use of resources, and strengthening governance.

6. Enhancing the Organisation's Credibility

A favourable audit opinion is a positive signal to investors, creditors, business partners, and the public. For public sector organisations, an unqualified opinion from the BPK is a widely watched indicator of the quality of financial management.

Types of Audits

Audits can be classified from several perspectives. Understanding these classifications helps an organisation determine the right type of examination for its needs.

1. Based on Auditor's Opinion

This classification refers to the final result the auditor expresses on the financial statements.

  • Unqualified Opinion (WTP/Unqualified): The highest opinion. The financial statements are presented fairly, in all material respects, in accordance with the applicable accounting standards.
  • Qualified Opinion (WDP/Qualified): There are discrepancies in certain items, but they do not affect the statements as a whole.
  • Unreasonable (Adverse): There are material and pervasive misstatements, so the financial statements as a whole cannot be relied upon.
  • Not Expressing an Opinion (TMP/Disclaimer): The auditor could not obtain sufficient evidence and therefore cannot express an opinion.

2. By the Object Examined

This classification distinguishes audits according to what is being examined.

  • Financial Statement Audit: Tests the fairness of the presentation of financial statements against accounting standards.
  • Compliance Audit: Tests the organisation's adherence to regulations, legislation, or contracts.
  • Operational Audit: Evaluates the effectiveness and efficiency of business processes in achieving the organisation's objectives.
  • Information Systems Audit: Assesses the security, reliability, integrity, and availability of the organisation's IT systems and data.
  • Investigative Audit: Traces suspected fraud, irregularities, or specific violations.

3. By the Party Carrying It Out

This classification distinguishes audits by the auditor's position relative to the organisation.

  • Internal Audit: Carried out by an internal audit unit that is part of the organisation but functionally independent, reporting to the Audit Committee or the most senior leadership.
  • External Audit: Carried out by a Public Accounting Firm (KAP) that is entirely independent of the organisation.
  • Government Audit: Carried out by the Audit Board of Indonesia (BPK) as the state's external auditor, or by the BPKP and the Inspectorate as the Government Internal Supervisory Apparatus (APIP).

4. By the Subject Being Audited

This classification refers to the type of entity that is the auditee.

  • Business Entities: Private companies, state-owned enterprises, regionally owned enterprises, cooperatives, and other business bodies.
  • Non-Profit Organisations: Foundations, NGOs, and social organisations.
  • Public Entities: Ministries and agencies, regional governments, and other public institutions.

5. By Approach

This classification distinguishes audits by the methodology used to determine the focus of the examination.

  • Risk-Based Audit (Risk-Based Internal Audit/RBIA): Audit planning and execution are directed at the areas of highest risk to the achievement of the organisation's objectives. This approach has become the standard in modern internal audit practice.
  • Compliance-Based Audit: Focuses on comprehensively testing adherence to procedures and regulations, without risk weighting.

Stages of the Audit Process

Whatever its type, an audit runs through a structured series of stages. The following are the general stages that apply in internal audit practice.

1. Audit Planning (Audit Planning)

This stage sets the overall direction of the engagement. Its main activities include:

  • Preparing the Annual Audit Work Programme (PKAT) based on risk assessment
  • Determining the scope, objectives, and criteria of the audit
  • Allocating resources and drawing up the schedule
  • Developing an initial understanding of the auditee's business processes
  • Preparing the Audit Work Programme (PKA) for the specific engagement

The quality of planning determines the effectiveness of the whole process. Weak planning produces an audit that targets immaterial areas.

See also: The importance of Audit planning and its steps in the examination

2. Conducting the Audit (Fieldwork)

The auditor gathers and tests evidence in the field through:

  • Testing of controls (test of control) to assess whether controls are operating effectively
  • Substantive testing of transactions and balances
  • Interviews with process owners
  • Direct observation and inspection of documents
  • Analytical procedures and data testing (Computer-Assisted Audit Techniques/TABK)

All procedures and their results are documented in the Audit working paper (KKA) as the supporting basis for the findings.

3. Reporting the Audit Results (Reporting)

Findings are formulated and communicated through:

  • Formulating findings using the condition–criteria–cause–effect–recommendation structure
  • Confirming the findings with the auditee (exit meeting)
  • Issuing the official Audit Report (LHA)
  • Submitting the report to leadership and the Audit Committee

4. Follow-Up (Follow-Up)

The stage most often neglected, yet the one that determines whether an audit genuinely adds value. Its activities include:

  • Monitoring the auditee's implementation of the recommendations
  • Verifying evidence of follow-up
  • Reporting the status of recommendation completion at regular intervals
  • Escalating recommendations that have not been acted on

An audit whose findings are never acted on produces no improvement at all — it merely adds another document.

Who Carries Out an Audit?

Who performs an audit varies according to the context and the mandate.

Internal Auditors are part of the organisation and are responsible for providing assurance and consulting to management and the Audit Committee. In state-owned enterprises, this function generally sits with the Internal Supervisory Unit (SPI).

Public Accountants work through Public Accounting Firms (KAP) and are tasked with giving an opinion on financial statements. Their practice is governed by the Indonesian Institute of Certified Public Accountants (IAPI) and overseen by the Ministry of Finance.

Badan Pemeriksa Keuangan (BPK) is the state body authorised to examine the management of, and accountability for, state finances, covering financial, performance, and special-purpose examinations.

The Government Internal Supervisory Apparatus (APIP) consists of the BPKP, the Inspectorates General of ministries and agencies, and Regional Inspectorates. APIP carries out internal oversight of the conduct of government duties.

Information Systems Auditors specialise in assessing IT governance and controls, are generally CISA certified, and use frameworks such as COBIT or ISO 27001.

Audit Standards and Regulations in Indonesia

Audit practice in Indonesia does not operate without rules. The following are the standards and regulations that serve as reference points.

Internal Audit Standards

  • Internal Audit Professional Standards (SPAI) issued by the Consortium of Internal Audit Professional Organisations, is the main reference for internal audit practice in Indonesia.
  • Global Internal Audit Standards from the IIA, which has come into effect and serves as the international reference for the internal audit function.
  • Internal Auditor Code of Ethics which governs the principles of integrity, objectivity, confidentiality, and competence.

External Audit Standards

  • Standard Audit (SA) issued by IAPI and adopting the International Standards on Auditing (ISA), is the mandatory reference for public accountants.

Public Sector Regulations

  • Government Regulation No. 60 of 2008 on the Government Internal Control System (SPIP), which provides the internal control framework for all government institutions.
  • State Financial Audit Standards (SPKN) issued by the BPK as the reference for examining state finances.
  • Ministry of State-Owned Enterprises Regulations which govern the application of good corporate governance (GCG) and the Internal Supervisory Unit function at state-owned enterprises.

Supporting Standards

  • ISO 19011 — guidelines for auditing management systems.
  • ISO/IEC 27001 — the information security management system standard, frequently used as a criterion in information systems audits.
  • COBIT 2019 — the framework for enterprise IT governance and management.

Because regulations can change, organisations are advised to refer to the latest version from the official source of each issuing body.

Common Challenges in Carrying Out an Audit

Clear as the framework is, carrying out an audit in practice often runs into the following obstacles.

Documentation is scattered across many places. Audit working papers are stored in Excel and Word files spread across each auditor's own device, so tracing supporting evidence takes a long time.

Follow-up on recommendations is not monitored. Once the audit report is issued, the completion status of recommendations is often tracked only through a manual spreadsheet that is rarely updated. As a result, the same findings reappear in the following period.

Consolidating findings across units is difficult. For organisations with many units or branches, building a comprehensive risk picture requires manual collation that is prone to error.

Risk-based planning is hard to apply consistently. Without a structured database of risks and historical findings, the annual audit work programme tends to repeat the previous year's pattern rather than follow the current risk profile.

Reporting to the Audit Committee eats up time. Periodic reports are compiled manually from various sources, so auditors spend more time on administration than on analysis.

Most of these obstacles are structural — not a matter of auditor competence, but of a way of working that still rests on separate documents. This is why many organisations are beginning to consolidate their audit cycle into a single integrated system.

Frequently Asked Questions

What is meant by an audit?

An audit is a systematic, objective, and independent examination of an organisation's reports, processes, or activities to assess their conformity with established criteria. The result takes the form of an opinion or findings reported to interested parties as a basis for improvement.

What is the main purpose of an audit?

The main purpose of an audit is to provide reasonable assurance about the reliability of information, compliance with regulations, and the effectiveness of internal control. An audit also produces recommendations for improvement that help an organisation manage risk and strengthen governance.

What is the difference between an internal audit and an external audit?

An internal audit is carried out by a unit within the organisation and focuses on evaluating risk management, control, and governance on an ongoing basis. An external audit is carried out by an independent party outside the organisation, generally a public accounting firm, with the main focus of giving an opinion on the fairness of the financial statements for the benefit of third parties.

What are the stages of the audit process?

The audit process generally consists of four stages: planning (determining the scope and a risk-based work programme), execution (gathering and testing evidence in the field), reporting (formulating findings and issuing the audit report), and follow-up (monitoring the implementation of recommendations).

Who is authorised to carry out audits in Indonesia?

It depends on the context. Internal audits are carried out by the internal audit unit or the SPI. Audits of financial statements for public purposes are carried out by Public Accountants through a KAP. Examining state finances is the authority of the BPK, while internal government oversight is carried out by APIP, which covers the BPKP and the Inspectorates.

Which standards govern internal audit in Indonesia?

Internal audit in Indonesia refers to the Internal Audit Professional Standards (SPAI) and the Global Internal Audit Standards from the IIA. For the government sector, the internal control framework is set out in Government Regulation No. 60 of 2008 on SPIP.

Does auditing only concern financial statements?

No. Financial statements are only one object of audit. Auditing also covers regulatory compliance, operational effectiveness, information system security, and investigation of suspected fraud.

Read also — types of audit by sector:

Manage the Entire Audit Cycle on One Platform

An effective audit takes more than a competent auditor — it takes a system able to connect risk-based planning, working paper documentation, the drafting of findings, and follow-up monitoring in one integrated flow.

Audithink is an integrated internal audit platform designed to support the implementation of SPIP, Risk-Based Internal Audit, risk management, and Good Corporate Governance at state-owned enterprises, regionally owned enterprises, and government institutions.

Discuss your audit team's needs with our team to see how Audithink can be applied to the audit process in your organisation.

Schedule a Demo and see for yourself how Audithink works within your team's workflow; Consultation with Product Expert, and discuss your organisation's specific needs.

Find out how the implementation of the audit application can have a positive impact on the company on an ongoing basis.

Consultation on Your Needs

Related Articles

Getting the Most Out of Manufacturing Internal Audits
control risk audit
compliance audit application recommendations