Back to resources
Internal auditGuide

How to run an internal audit engagement

An engagement has four stages. Without a mandate, evidence and a closure date, the report only gets reread next year.

9 min readSeptember 2026

The annual program says which engagements will happen. The engagement itself has a start and an end. It tests a defined scope against named criteria, it keeps the evidence, and it closes only when the recommendation has been carried out. Here is a sequence teams can follow, whether the audit covers ISO 27001, Law 25 or an internal process.

The four stages

1. Mandate

A short document: objective, scope, criteria, team, dates, and what is out of scope. Criteria are texts you can cite, for example an ISO 27001:2022 control, a clause of your policy, or a Law 25 duty. The person who audits should not be the person who runs the process day to day.

2. Preparation

Send the evidence list before the meetings: current policies, log extracts, tickets, access records. An interview with nothing to look at produces impressions, not a finding.

3. Finding

Each gap is one sentence: the criterion, the fact observed, the evidence, and the gap between them. "The control is weak" is not a finding. Attach the record, or say where it is kept.

4. Closure

The recommendation names an owner and a date. It closes when proof of implementation is in the file, not when the owner says it is planned. The final report lists findings that are still open and those that are closed.

What to ask for in the field

The current document

Not the draft. Check the approval date and that teams are using that version.

A sample, not a promise

Five access records, five files, five changes. The number depends on the volume. Write the sample down so it can be repeated.

The exception

Ask for a case that did not follow the process. That is often where the control stops.

After the report

Open findings go into follow-up, with the same identifier as in the report. The next engagement starts with that list. A finding that returns two years in a row with no named owner is a program problem, not a writing problem.

Mandate, evidence and closure in the same file

CapAUDIT links the program, the engagement, the findings and the proof that closes the recommendation.