Skip to content

Guide to the audit process

Helpful information regarding the reasons for auditing, types of audits and their scope, and details on the audit process.

Topics on this page:

The audit process typically involves several key steps to evaluate an organization’s financial, operational, or compliance performance. These steps include:

  • Planning – where the audit scope, objectives, and criteria are defined
  • Data collection – involving the review of documents, records, and systems
  • Testing and analysis – to assess controls, processes, and compliance
  • Reporting – where findings and recommendations are documented and
  • Follow-up – to ensure compliance and ensure corrective actions are implemented.

The process aims to identify risks, ensure compliance, and improve organizational efficiency.

Why audit?

Internal controls and regular audits validate that processes and procedures utilize best practices, are effective, and compliant. These help ensure good stewardship of University assets, reliable and secure financial and data management, efficient resource deployment, and regular business process improvement.

Types of audits

Financial

WHAT

Financial audits are concerned primarily in the review of specific financial transactions and the adequacy of controls.

HOW

During financial audits, we determine whether historical financial information fairly presents the financial position and results of operations.

In order to form an opinion, we examine the internal control structure and test transactions surrounding economic events.

RESULT

Recommendations about operational matters are byproducts of a financial audit rather than the main objective and are not primarily intended to evaluate management’s effectiveness or efficiency.

Operational

WHAT

Operational audits, also known as performance or managerial audits, are aimed at assessing an operation’s administrative efficiency and effectiveness.

HOW

An operational audit measures and evaluates administrative control against standards set by management. It includes long range plans, budgets, and operating policies and procedures.

RESULT

Although financial data continues to be the base of reference, we look beyond the figures to provide assistance toward improving operations.

Compliance

WHAT

Compliance audits seek to determine the degree of adherence to institutional policies and procedures, applicable statutory laws and regulations, and terms of contracts.

HOW

During an audit, we gather relevant documentation, records, and evidence to evaluate compliance against, for example, policies and procedures, regulatory requirements, contracts, billing, data security, etc. The collected data is analyzed against the established criteria to identify any gaps or non-compliance issues.

RESULT

Findings are documented in a report, highlighting areas of compliance and non-compliance, along with recommendations for corrective actions.

Construction

WHAT

Review of construction and renovation related costs and contracts with a focus on ensuring that projects are managed efficiently, comply with contractual agreements, and adhere to financial, regulatory, and operational standards.

HOW

Steps to complete a typical Construction audit include:

• Collect and examine project-related documents, including contracts, purchase orders, payment applications, schedules, and change orders.

• Review financial records to ensure accuracy and compliance with budgets.

• Conduct physical inspections of the construction site.

• Test financial transactions for accuracy, such as verifying invoices, payments and cost allocation.

RESULT

A typical construction audit report includes findings related to financial accuracy, compliance, operational efficiency, and risk management. These results help identify areas for improvement, ensure accountability, and mitigate risks.

Information Technology (IT)

WHAT

IT audits are conducted to evaluate the effectiveness, security, and compliance of an organization’s information technology systems, processes, and controls. The goal is to ensure that IT systems align with business objectives, comply with regulations, and mitigate risks.

HOW

For IT audits, we identify areas of system-related risk, assess the control environment, and evaluate the adequacy of controls and integrity of data

RESULT

We will appraise the economy and effective use of computer resources, and determine whether organizational units of Information Systems are conducting their operations or control activities in compliance with standard electronic data processing practices and established policies/ procedures.

Investigative

WHAT

An investigation is a structured process used to examine allegations or indicators of fraud by gathering, analyzing, and validating evidence to determine whether misconduct occurred, how it happened, and what controls were affected.

HOW

Coordination of this audit type would be made with Senior Management, Legal Counsel, and the Department of Public . Investigative audits differ from other audits because they are normally conducted without first notifying the personnel who may be affected by the findings.

RESULT

Typical results include identifying fraudulent activities, quantifying financial losses, analyzing root causes, and collecting evidence for legal or disciplinary actions. These audits may also reveal compliance violations and weaknesses in internal controls, with recommendations for corrective actions to strengthen oversight and prevent future incidents. Findings often lead to improved risk management and enhanced organizational policies.

Follow-Up

WHAT

Most audits require a follow-up review completed between 6 to 12 months after the issuance of the original report. The purpose of a follow-up audit is to understand whether the reported recommendations have been implemented.

HOW

The scope of the follow-up review consisted of requests for written explanations and supporting documentation to address the recommendations noted in the original report. This information is reviewed to determine if the appropriate actions were implemented.

RESULT

The goal is to evaluate the status of corrective actions taken by management in response to the previous audit’s recommendations.

The audit process

A collaborative approach

A successful audit is built on constructive and cooperative engagement between the auditor and the audited department.  The audit process actively involves management at every stage, as effective communication is essential to its success. This collaborative approach helps to mitigate the negative perceptions often associated with the term “audit”.  The goal of the Office of University Audit is to be a partner, not an adversary, to the departments it audits, with open and effective communication serving as a cornerstone of this partnership.

Duration

The duration of an audit can vary significantly, ranging from a few hours to several weeks, depending on its scope and objectives.  Efforts are made to ensure that departmental activities experience minimal disruption during this time.  Additionally, much of the audit work is conducted outside the department, meaning direct interaction with departmental employees is not required throughout the entire process.

  1. Scheduling

Scheduling an internal audit is a collaborative process designed to ensure transparency, efficiency, and alignment between the audit team and the client.  The process involves defining the audit’s scope and objectives, notifying the client, and coordinating logistics to ensure a smooth, effective review.  Open communication and mutual understanding are key to establishing a clear timeline, addressing any concerns, and preparing for the audit activities.  By following a structured approach, the Office of University Audit ensures the client is fully informed and ready to participate in the audit.

2. Planning

During the planning phase of an audit, the objectives are clearly defined, and the audit techniques are determined.  A preliminary meeting is scheduled with the department or area to be audited.  During the meeting, the audit team and department personnel discuss the purpose and objectives of the audit, as well as any specific concerns the department wishes to address as part of the process.

As part of planning, the audit team conducts a risk assessment, performs an analytical review of its ledger accounts, and designs audit techniques to achieve the defined objectives.  An audit program is then developed, serving as a detailed plan of action to guide the audit process.

3. Field Work

The auditor proceeds to the measurement and evaluation phase of the audit, commonly referred to as fieldwork.  During this phase, the auditor gathers and assesses information, including evaluating the strengths and weaknesses of internal controls and determining adherence with University policies and applicable government regulations. Testing of departmental records is conducted as necessary to enable the auditor to form an opinion and provide recommendations for improvement.

Upon completion of the fieldwork, an exit meeting is held with relevant management to review the audit findings, observations, and recommendations.  Additionally, progress meetings are informally conducted throughout the audit process to keep administrators informed of any significant findings as they arise.

4. Audit Report

The final result of each audit is a comprehensive written report provided to senior management.  This report outlines the audit background, scope, conclusions, significant audit findings, and recommendations for improvement.

We request that management provide a written response to all findings that include recommended actions. Management’s detailed plans for addressing audit findings are incorporated into the final audit report, which is then distributed to senior management.

Additionally, the Chief Audit Executive prepares an annual report summarizing all completed audits.  This report includes significant findings, audit conclusions, and management responses.  The Chief Audit Executive meets with the Audit Committee of the Board of Trustees four times per year to review the Office of University Audit’s activities, discuss significant findings, and provide updates on audit outcomes.

5. Follow-Up

Within a reasonable time after completion of an audit, a follow up review is completed. The primary objectives of this review are to determine whether recommended procedures have been implemented and to evaluate whether the intended results are being achieved.

Related offices and departments

Other resources