AUI3703 is a third‑year internal auditing module in the UNISA BCom Internal Auditing degree that focuses on applying internal audit methodology to specific engagement areas and on producing clear, impactful audit reports. These notes also help students from related courses such as UNISA AUE3703, CUT IAU30AS, and NWU IAAF 321 who cover similar content on internal audit engagements and reporting. The focus is on practical exam‑oriented understanding: planning and performing engagements in key risk areas, integrating IT and data analytics, and drafting examination‑ready internal audit reports compliant with the International Standards for the Professional Practice of Internal Auditing (Standards).
1. Core Framework: Internal Audit Engagements in AUI3703 (UNISA BCom Internal Auditing)
1.1 AUI3703 in the South African University Context
The University of South Africa (UNISA) offers AUI3703: Specific Internal Audit Engagements and Reporting as part of its BCom in Internal Auditing qualification. The module builds on earlier courses such as:
- AUI2602 – Internal Auditing: Governance and Control
- AUI2603 – Internal Auditing: Risk and Compliance
- AUI3701 – Internal Auditing: Advanced Governance
- AUI3702 – Internal Auditing: Advanced Risk and Control
At Central University of Technology (CUT), similar content appears in IAU30AS – Internal Auditing III and at other institutions (e.g., TUT IAD305D, NWU IAAF 321). Across these courses, the goal is the same: to move from theory to application in real‑world engagement scenarios.
AUI3703 assumes you already know:
- The role of internal auditing in governance (IIA Definition of Internal Auditing).
- The risk management process and COSO frameworks.
- Basics of internal control design and evaluation.
- The structure and requirements of the IIA International Professional Practices Framework (IPPF).
The module then applies these foundations to specific types of internal audit engagements and emphasizes professional reporting of results.
1.2 The Internal Audit Engagement Lifecycle
AUI3703 expects you to master the engagement lifecycle and apply it to various areas (procurement, payroll, IT, etc.). The typical steps, aligned with the Standards, are:
-
Engagement Planning
- Understand the context and objectives.
- Perform preliminary risk assessment.
- Define engagement objectives and scope.
- Develop an engagement work program.
-
Engagement Execution (Fieldwork)
- Gather sufficient, reliable, relevant and useful evidence (Standard 2310).
- Perform tests of controls and substantive procedures.
- Document work in working papers.
-
Evaluation and Conclusion
- Evaluate evidence against criteria (policies, laws, best practice).
- Formulate findings, root causes, effects, and recommendations.
- Determine an overall conclusion or rating.
-
Engagement Communication (Reporting)
- Draft a clear, concise, constructive report (Standard 2420).
- Agree findings with management where possible.
- Issue the final report to appropriate parties.
-
Follow‑up
- Monitor implementation of agreed actions (Standard 2500).
- Report on unresolved issues and their implications.
AUI3703 exam questions frequently ask students to apply this lifecycle to a given scenario: e.g., “You are the internal auditor at Company X. Draft the audit objectives, scope and procedures for an internal audit of the payroll process, and prepare suitable reportable findings.”
1.3 Key IPPF Standards Relevant to AUI3703
Certain IIA Standards come up repeatedly in AUI3703 and related modules like UNISA AUI3702 and CUT IAU30AS. Key standards to know and apply:
-
Standard 2000 – Managing the Internal Audit Activity
- Internal audit activities must be managed effectively to ensure they add value and improve the organisation’s operations.
- Link to AUI3703: How engagements fit into the overall internal audit plan and strategy.
-
Standard 2200 – Engagement Planning
- Internal auditors must develop and document a plan for each engagement.
- Requires consideration of objectives, scope, resources, and timing.
- Exam‑tip level detail: Be ready to list and apply planning steps.
-
Standard 2300 – Performing the Engagement
- Internal auditors must identify, analyze, evaluate, and document sufficient information to achieve the engagement’s objectives.
- Evidence must be sufficient, reliable, relevant, and useful.
-
Standard 2400 – Communicating Results
- Internal auditors must communicate the results of engagements.
- Comms must be accurate, objective, clear, concise, constructive, complete, and timely (Standard 2420).
-
Standard 2500 – Monitoring Progress
- CAE must establish and maintain a system to monitor the disposition of results.
Examination questions often embed these standards in practical contexts. For instance, a UNISA AUI3703 exam might present a case where communication of results is poor and ask: “Identify and explain the shortcomings in terms of the IIA communication requirements.”
1.4 Risk‑Based Internal Audit and Engagement Selection
Internal auditing in South Africa, particularly in institutions like UNISA and CUT, strongly emphasizes risk‑based internal audit (RBIA). In AUI3703, you must show how the selection and scope of engagements are driven by:
- Enterprise‑wide risk assessment results.
- Risk registers and heat maps.
- Strategic and operational priorities of management and the audit committee.
Within the RBIA framework:
- Engagements are prioritised based on inherent risk, control effectiveness, and risk appetite.
- AUI3703 case studies often include:
- A list of auditable units (e.g., procurement, payroll, IT security, inventory).
- For each, a risk rating (high, medium, low) and last audit date.
- Limited audit resources and time.
You are then asked to:
- Select priority engagements.
- Justify the selection with RBIA principles.
- Propose engagement objectives for each selected area.
An example commonly tested across multiple universities (UNISA AUI3703, CUT IAU30AS, and NWU IAAF 321) is prioritising a high‑risk procurement process that has not been audited in three years over a medium‑risk petty cash process audited last year.
1.5 South African Regulatory Context for Internal Auditing
AUI3703 also expects awareness of the South African regulatory environment, especially in larger corporates and public entities:
-
King IV Report on Corporate Governance:
- Emphasises combined assurance, internal control, risk governance, and internal audit.
- Internal audit must provide objective assurance on the adequacy and effectiveness of risk management and internal controls.
- Internal audit reports often feed into the audit committee’s governance responsibilities.
-
Public Finance Management Act (PFMA) & Municipal Finance Management Act (MFMA):
- Require internal audit units and audit committees in public sector entities.
- Internal audit must assess compliance with PFMA/MFMA, Treasury Regulations, and supply chain management (SCM) frameworks.
- Public sector examples are common in UNISA exam questions (e.g., audits of municipal supply chain processes).
-
Companies Act and relevant sector codes:
- Impact how internal auditors evaluate compliance and governance in audits.
Knowing this context helps in framing engagement objectives (for example, including compliance with PFMA and National Treasury SCM instructions in a public sector procurement audit objective).
2. Planning and Performing Specific Internal Audit Engagements
2.1 General Engagement Planning Steps (Exam‑Focused)
For AUI3703 (and for related SA courses like UNISA AUI3701 and CUT IAU30AS), exam questions frequently ask for detailed planning steps. A strong answer systematically covers the following:
-
Obtain Background Information
- Understand the business unit/process: purpose, organisational structure, key activities.
- Review prior internal audit reports and external audit findings.
- Review relevant policies, procedures, and process flowcharts.
-
Identify and Understand Objectives and Risks
- Determine the process objectives (e.g., accurate and timely payroll, fair and transparent procurement).
- Identify key risks that threaten achievement of those objectives (fraud, error, non‑compliance, inefficiencies).
-
Preliminary Risk Assessment
- Assess inherent risk (volume, complexity, change, judgement).
- Consider existing controls and control environment.
- Determine residual risk and classify (high/medium/low).
-
Define Engagement Objectives
- Align with high‑risk areas.
- Objectives must be clear, measurable, and outcome‑oriented, e.g.:
- “To evaluate the adequacy and effectiveness of controls over the procurement process to ensure compliance with the SCM policy, PFMA, and prevention of irregular expenditure.”
-
Define Engagement Scope
- Processes, locations, and time period to be covered.
- Inclusion/exclusion of certain divisions or systems.
- Alignment with resource and time constraints.
-
Develop Engagement Work Program
- Convert objectives and scope into specific audit procedures.
- Assign responsibilities and timing.
- Include both control tests and substantive procedures.
-
Resource Planning
- Determine skills required (IT, forensic, technical).
- Assign team members and estimate hours.
- Consider the need for co‑sourcing or external expertise (e.g., specialised IT audits done with assistance from an external IT audit firm).
-
Communication and Approval
- Discuss scope and objectives with management and the CAE.
- Obtain necessary approvals (audit committee or CAE sign‑off).
- Issue an engagement notification to auditees, describing scope and expected timelines.
In the exam, answers are stronger when they use scenario‑specific detail. For instance, in a procurement case, mention reviewing the SCM policy and supplier masterfile, not just “policies and procedures”.
2.2 Specific Engagement: Procurement and Supply Chain Management
Procurement/Supply Chain Management (SCM) is one of the most frequently examined engagement areas in AUI3703 and at institutions like CUT and TUT (e.g., CUT IAU30AS, TUT IAD305D). South African public sector SCM is governed by PFMA/MFMA and National Treasury’s SCM Regulations, making it a high‑risk area.
Objectives of a Procurement/SCM Audit
Common engagement objectives:
- Determine whether procurement processes comply with:
- PFMA/MFMA (for public sector).
- National Treasury Regulations and SCM Instructions.
- Entity’s SCM policies and procedures.
- Assess whether there are adequate controls to:
- Prevent, detect, and correct fraud, corruption, and collusion.
- Ensure value for money (economy, efficiency, effectiveness).
- Manage supplier performance and conflicts of interest.
- Verify the accuracy and completeness of procurement records and approvals.
- Evaluate whether procurement practices support strategic sourcing objectives and B‑BBEE compliance (where applicable).
Key Risks in Procurement
Typical high‑risk areas examined across UNISA and CUT exam papers:
- Uncompetitive or irregular procurement:
- Bypassing tender requirements.
- Splitting orders to stay below tender thresholds.
- Fraud and corruption:
- Kickbacks, bid‑rigging, collusion, bribes.
- Ghost suppliers or suppliers linked to employees.
- Non‑compliance:
- With PFMA/MFMA.
- With SCM policy (e.g., lack of three quotations where required).
- Supplier masterfile risks:
- Duplicate suppliers.
- Incomplete supplier vetting (tax compliance, B‑BBEE status).
- Poor contract management:
- Expired contracts still used.
- Inadequate performance monitoring and penalties not enforced.
Procurement Audit Procedures (Typical Exam Content)
When required to “design internal audit procedures to test controls over procurement”, structure the answer around procurement stages:
-
Supplier Selection and Approval
- Inspect evidence of supplier due diligence (tax clearance, bank details verification, blacklist checks).
- Perform data analytics on supplier masterfile:
- Identify duplicates and related‑party suppliers (compare with employee database).
- Test a sample of newly added suppliers for appropriate approvals.
-
Tendering/ Quotation Process
- Review a sample of tenders/quotations:
- Evidence of advertising where required.
- Bid evaluation committee minutes.
- Score sheets and conflict of interest declarations.
- Reperform scoring for a sample of bids to validate correctness.
- Review a sample of tenders/quotations:
-
Purchase Requisition and Order
- Test a sample of purchase requisitions:
- Authorization by responsible officials.
- Justification, budget availability, and adherence to procurement plan.
- Trace requisitions to purchase orders to ensure:
- Sequential numbering.
- Proper approval and match with supplier quotation/tender award.
- Test a sample of purchase requisitions:
-
Receipt of Goods/Services
- Compare goods received notes (GRNs) with purchase orders and invoices.
- Inspect evidence of inspection of goods/services (quality checks, service level evaluations).
- Test for segregation of duties between ordering, receiving, and recording.
-
Payments
- Perform 3‑way match tests (PO, GRN, invoice).
- Review a sample of payments to ensure:
- Paid only to approved suppliers.
- Amounts are correct and supported.
- Use data analytics to identify:
- Duplicate payments.
- Round‑sum and weekend payments.
-
Compliance and Irregular Expenditure
- For public sector: reconcile irregular, fruitless, and wasteful expenditure registers to procurement transactions.
- Verify correct classification and reporting of such expenditures.
Exam answers should mention population definition, sampling technique (e.g., judgmental or systematic sampling), and sample sizes where appropriate, even if approximate.
2.3 Specific Engagement: Payroll and HR
Payroll audits are common in AUI3703 exam scenarios, often tied to fraud risks and control weaknesses. UNISA, CUT, and other South African universities such as UJ (ACCT4007) include payroll tests in their internal auditing syllabi because payroll is a high‑value transaction cycle with significant fraud risk.
Objectives of a Payroll Audit
- Evaluate whether payroll transactions are:
- Authorised, complete, and accurate.
- Compliant with HR policies, labour laws, and tax regulations.
- Verify that:
- Only bona fide employees are paid.
- Overtime, allowances, and bonuses are properly approved.
- Payroll masterfile changes are legitimate and authorised.
- Assess segregation of duties and access controls over payroll systems.
Key Payroll Risks
- Ghost employees:
- Salaries paid to fictitious or resigned employees.
- Unauthorised changes to salary rates or bank details.
- Incorrect calculation or payment of:
- PAYE, UIF, SDL, and other statutory deductions.
- Excessive or fraudulent overtime claims.
- Poor segregation of duties between HR, payroll processing, and banking.
Payroll Audit Procedures
When asked in an exam to design audit procedures for payroll, structure around:
-
Understanding and Documentation
- Obtain HR and payroll process flowcharts.
- Identify key staff and systems used (e.g., VIP, SAP, SAGE).
-
Masterfile Controls
- Test a sample of new employees:
- Existence of approved appointment letters and signed contracts.
- HR approval and supporting documentation (ID, qualifications).
- Test a sample of terminations:
- Termination forms, exit interviews, and final pay calculations.
- Review change reports (salary adjustments, bank changes):
- Evidence of proper authorisation.
- Segregation between capturing and approving changes.
- Test a sample of new employees:
-
Payroll Calculations and Payments
- Recalculate gross pay, deductions, and net pay for a sample of employees.
- Verify compliance with tax tables and statutory rates.
- Trace net pay amounts to bank transfer listings and bank statements to ensure completeness and accuracy.
-
Ghost Employee Testing
- Compare payroll list to:
- HR approved staff list.
- Physical headcount (if practicable).
- Access control logs (building access cards).
- Investigate any employees without supporting HR files or who cannot be physically located.
- Compare payroll list to:
-
Analytical Review
- Trend analysis of payroll expenses by department, month, and category.
- Identify anomalies, such as sudden spikes in overtime or allowances.
-
Segregation of Duties and Access Controls
- Confirm that:
- HR cannot process payroll payments.
- Payroll staff cannot add employees without HR documentation.
- Banking signatories are independent of payroll input.
- Confirm that:
Clear linkage between each procedure and the risk addressed is important for exam answers.
2.4 Specific Engagement: Inventory and Fixed Assets
Many UNISA AUI3703 and CUT IAU30AS case studies involve manufacturing or retail entities where inventory and fixed assets are significant.
Objectives of Inventory Audits
- Ensure that recorded inventory exists, is complete, and is accurately valued.
- Assess controls over:
- Receiving, storage, movement, and dispatch.
- Inventory count processes and reconciliations.
- Evaluate handling of obsolete and slow‑moving stock.
Objectives of Fixed Asset Audits
- Verify existence and condition of recorded assets.
- Confirm completeness and proper recording of acquisitions, disposals, and depreciation.
- Assess safeguarding controls and asset tagging.
Typical Procedures (Inventory)
- Observe physical stock counts:
- Review instructions, counting procedures, and segregation.
- Perform test counts and reconcile count sheets to inventory records.
- Test write‑offs and adjustments:
- Check approvals and rationale (damage, obsolescence).
- Review cut‑off around year‑end:
- Trace goods received and dispatched before/after period end to correct recording.
Typical Procedures (Fixed Assets)
- Conduct physical verification:
- Select a sample of assets from the register and locate them.
- Trace a sample from floor to register (completeness).
- Review acquisitions and disposals:
- Supporting invoices, board approvals, and disposal records.
- Recalculate depreciation for a sample of assets.
AUI3703 exams sometimes combine inventory and fixed assets into a single scenario, expecting students to differentiate between their risks and procedures.
2.5 Specific Engagement: Revenue and Receivables
Revenue and receivables audits focus on recording accuracy, completeness, and existence of debtors.
Objectives
- Ensure all revenue earned is recorded (completeness).
- Ensure all recorded revenue is valid and accurate (occurrence and accuracy).
- Assess credit management controls and debt collection effectiveness.
- Evaluate segregation of duties in billing, recording, and collections.
Key Procedures
- Walk‑through from order to cash:
- From customer order → credit approval → delivery → invoice → receipt.
- Sample test of sales transactions:
- Match orders, delivery notes, and invoices.
- Check pricing and discounts vs price lists and approvals.
- Test of receivables:
- Confirm balances with customers (debtor confirmations).
- Review age analysis and evaluate adequacy of impairment provisions.
In exams, students may be asked to contrast the risks and audit approach in revenue vs procurement, reinforcing the need to show understanding of business cycles.
3. IT‑Enabled Internal Audit Engagements and Data Analytics
3.1 IT and Internal Audit in AUI3703 and Related Courses
IT‑related content appears in AUI3703 as applied, engagement‑level coverage, rather than as a pure IT audit course like UNISA AUI4861 or CUT IIA40AS. However, internal auditors are expected to:
- Understand basic IT general controls (ITGCs) and application controls.
- Recognise IT‑related risks within specific processes.
- Use Computer‑Assisted Audit Techniques (CAATs) and data analytics to enhance engagements.
At universities such as UNISA, CUT, and NWU, examinations increasingly incorporate short cases where auditors must propose data analytics procedures for cycles like payroll, procurement, or revenue.
3.2 IT General Controls (ITGCs) and Application Controls
When auditing a specific business process (e.g., payroll), internal auditors cannot ignore IT environment controls.
IT General Controls
These are controls over the overall IT environment. Key categories:
-
Access Controls
- User account management (creation, modification, deletion).
- Password parameters.
- Privileged access monitoring.
-
Change Management
- Authorisation and testing of system changes.
- Segregation between developers and production environments.
- Change logs and approvals.
-
Operations Controls
- Backup and restore procedures.
- Batch job monitoring.
- Incident management and problem resolution.
An AUI3703‑style exam question might provide a description of weak password policies and ask you to identify risks and recommend improvements.
Application Controls
These are embedded in individual systems and processes, such as:
- Input Controls
- Field validations, mandatory fields, reasonableness checks.
- Processing Controls
- Automated calculations, data completeness checks.
- Output Controls
- Review of reports for accuracy and integrity.
In a payroll system, for example:
- Input controls could include validation of bank account formats and tax numbers.
- Processing controls might be automatic recalculation of PAYE according to updated tax tables.
- Output controls might include exception reports highlighting negative net pay or unusually high overtime.
3.3 Using Data Analytics in Internal Audit Engagements
AUI3703 students should be able to propose practical data analytics tests, even if they are not writing SQL queries or using tools themselves.
Advantages of Data Analytics in Internal Auditing
- 100% population testing instead of small samples.
- Enhanced ability to identify anomalies and red flags.
- Higher efficiency in large, transaction‑intensive processes.
Typical Data Analytics Tests by Cycle
-
Procurement/Payments
- Identify duplicate invoices:
- Same supplier, same amount, same date.
- Identify weekend or public holiday payments.
- Identify round‑sum payments above set thresholds.
- Supplier‑employee matching:
- Compare supplier bank accounts and addresses to employee details.
- Identify duplicate invoices:
-
Payroll
- Identify multiple employees using the same bank account.
- Identify employees without valid ID numbers.
- Overtime analysis by department and employee:
- Flag employees with consistently high overtime.
-
Revenue/Receivables
- Identify negative sales entries.
- Analyse credit notes by employee/branch.
- Detect unusual patterns in discounts and price overrides.
Exam answers should show awareness that data analytics does not replace professional judgement; it enhances risk identification and supports further investigation.
3.4 IT‑Focused Internal Audit Engagements
In some cases, AUI3703 or CUT IAU30AS exam questions may involve more direct IT process audits, for instance:
-
Information security audit:
- Assess policies and procedures for managing user access and passwords.
- Test compliance with password requirements and user access reviews.
-
Business continuity and disaster recovery audit:
- Evaluate the existence and adequacy of disaster recovery plans.
- Review backup schedules, offsite storage, and periodic testing of recovery procedures.
When answering such questions:
- Describe the objective of the IT‑focused engagement (e.g., to assess adequacy and effectiveness of controls over logical access to critical financial systems).
- Identify key risks (unauthorised access, data breach, data loss).
- Propose controls and audit tests (user access reviews, log monitoring, backup verification).
3.5 Integration of IT and Business Process Audits
Strong exam answers recognise that IT controls and business process controls are interdependent. For example:
- In a procurement audit, weak user access controls in the ERP system (e.g., one user can both create suppliers and process payments) directly impact fraud risk.
- In a payroll audit, IT application controls (automated calculation of deductions) support the overall reliability of payroll figures.
Students should be ready to:
- Highlight where IT risks increase process risks.
- Recommend both process‑level and IT‑related control improvements.
4. Internal Audit Reporting: Structure, Quality and Exam‑Style Drafting
4.1 Purpose and Principles of Internal Audit Reporting
In AUI3703 and similar modules across South African universities (e.g., UNISA AUE3703, CUT IAU30AS), reporting is a major focus. The main purposes of internal audit reports are to:
- Communicate what was audited, how, what was found, and what is recommended.
- Enable management and the audit committee to make informed decisions about risk and control.
- Provide a basis for follow‑up and accountability for remediation.
Under Standard 2420 – Quality of Communications, internal audit communications must be:
- Accurate – free from errors and distortions.
- Objective – fair, unbiased, and impartial.
- Clear – easily understandable.
- Concise – to the point, yet complete.
- Constructive – helpful and oriented toward improvement.
- Complete – includes all significant matters.
- Timely – communicated in time to be effective.
Exams often include a poorly written report extract and ask you to improve it according to these qualities.
4.2 Typical Internal Audit Report Structure
Internal audit reports in AUI3703‑style questions usually expect the following core components:
-
Title and Addressees
- Clear title indicating type of report and the area audited.
- Addressed to relevant management and, where applicable, the audit committee.
-
Executive Summary
- Brief overview of engagement objectives, scope, methodology.
- Summary of overall conclusion/opinion and high‑risk findings.
-
Background
- Context of the audit area (purpose, strategic importance).
- Key processes, systems, and responsibilities.
-
Objectives and Scope
- Specific audit objectives.
- Period covered, locations, and processes included/excluded.
-
Methodology
- Primary techniques used (interviews, walkthroughs, sampling, data analytics).
- Standards and frameworks referenced (IIA Standards, PFMA, policies).
-
Overall Conclusion/Opinion
- Clear statement on the adequacy and effectiveness of controls in the audited area.
- Sometimes expressed as a rating (e.g., “Satisfactory”, “Needs Improvement”).
-
Detailed Findings, Risk, and Recommendations
- For each finding:
- Condition – what was found.
- Criteria – what should be (policy, law, best practice).
- Cause – why the issue occurred.
- Effect – impact on objectives, risk, compliance.
- Recommendation – specific, actionable steps.
- Management response and action plan.
- For each finding:
-
Appendices
- List of documents reviewed.
- Detailed test results or supporting analysis.
4.3 Example of a Well‑Structured Finding (Exam Format)
AUI3703 exams often require students to draft findings based on a scenario. A model structure is the “4Cs + R” approach: Condition, Criteria, Cause, Consequence (Effect), Recommendation.
Example: Procurement Audit Finding
-
Condition
During testing of 40 purchase orders exceeding R500 000, it was found that 6 (15%) were awarded without evidence of approval by the Bid Adjudication Committee as required. In all 6 instances, documentation was limited to a recommendation from the Bid Evaluation Committee, with no signed minutes or resolution approving the awards. -
Criteria
Section 5.3.2 of the organisation’s Supply Chain Management Policy requires that all awards above R500 000 be approved by the Bid Adjudication Committee and that decisions be properly minuted. In addition, National Treasury Instruction Note 3 of 2016/17 requires appropriate committee oversight for high‑value tenders. -
Cause
There is no control in place to prevent procurement staff from issuing purchase orders prior to formal approval by the Bid Adjudication Committee, and the procurement checklist does not require evidence of such approval before processing. -
Consequence (Effect)
- Increased risk of irregular expenditure.
- Potential non‑compliance with National Treasury requirements and SCM policy.
- Possible perception of bias or favouritism in award decisions.
-
Recommendation
Management should enhance controls to ensure that no purchase orders above R500 000 are issued without documented Bid Adjudication Committee approval. This may include:- Updating procurement checklists to require signed minutes or resolutions before PO issuance.
- Configuring the ERP system to block POs above R500 000 where an approval reference number is not captured.
- Periodic internal reviews of large awards to confirm compliance.
-
Management Response and Action Plan
[To be completed by management: typically includes acceptance/rejection, responsible person, and target date.]
This structure is universally applicable to UNISA AUI3703, CUT IAU30AS, and related courses, and is the format markers expect in exams.
4.4 Drafting an Executive Summary (Exam‑Style)
An effective executive summary:
- Is brief (usually one page or less).
- Highlights:
- Scope and objectives.
- Overall assessment.
- Number and severity of findings.
- Key themes.
Example Executive Summary Extract (Payroll Audit)
The internal audit of the payroll function was performed as part of the approved 2026 risk‑based internal audit plan. The objective was to evaluate the adequacy and effectiveness of controls over the payroll process to ensure that all salary payments are accurate, valid, and properly authorised, and that statutory deductions are correctly calculated and remitted.
The audit covered the period 1 January 2026 to 30 June 2026 and included all permanent and contract staff. The audit was conducted in accordance with the International Standards for the Professional Practice of Internal Auditing.
Based on the procedures performed, internal audit concludes that controls over the payroll process are partially effective. While key controls over payroll processing and statutory deductions are generally operating as designed, the audit identified significant weaknesses in payroll masterfile changes and overtime approvals. Specifically, there is insufficient segregation of duties in the processing of bank detail changes, and there is inadequate supporting documentation for overtime claims.
Five findings were raised, of which:
- 2 are rated High (payroll masterfile changes and overtime authorisation).
- 2 are rated Medium.
- 1 is rated Low.
Management has agreed to address all findings by 31 December 2026. Internal audit will perform a follow‑up review in the first quarter of 2027.
In an exam, marks are awarded for clarity, coverage of key points, and alignment with scenario details.
4.5 Language and Tone in Internal Audit Reports
Internal audit reports must be:
- Professional and objective – avoid emotional or accusatory language.
- Evidence‑based – avoid speculation without supporting facts.
- Balanced – acknowledge strengths as well as weaknesses, especially in the executive summary.
Poor style examples and improvements (often tested in AUI3703 and CUT IAU30AS):
| Poor Wording | Improved Wording |
|---|---|
| “The SCM unit is completely incompetent and does not follow any policy.” | “The audit identified significant non‑compliance with key aspects of the SCM policy, particularly regarding quotation processes and conflict of interest declarations.” |
| “Management seems not to care about internal controls.” | “There is insufficient monitoring by management of the implementation and effectiveness of internal controls in the area reviewed.” |
4.6 Reporting to Different Stakeholders
Stakeholders for internal audit reports include:
- Process owners and line management – for operational detail.
- Senior management – for high‑level risk and control environment.
- Audit committee – for oversight and governance.
Reports may be:
- Detailed engagement reports – for management.
- Summary reports – for audit committee, highlighting significant themes and trends.
AUI3703 exam questions can include:
- Drafting a covering letter or memo to the audit committee summarising key outcomes.
- Explaining what information from a detailed report would be escalated to the audit committee vs remaining at management level.
4.7 Rating of Findings and Overall Opinions
Many organisations use a rating scale for findings and for overall audit opinion. Common scales include:
- Finding ratings: High, Medium, Low.
- Overall audit opinion: Effective, Partially effective, Ineffective, or colour codes (Green/Amber/Red).
In exam answers:
- Clearly define what each rating implies.
- Align the overall conclusion with the distribution and severity of findings. For example, multiple High‑risk findings usually preclude an “Effective” rating.
Understanding these rating practices helps students answer case‑based questions where they must justify an overall opinion.
5. Follow‑Up, Quality Assurance, and Exam Preparation Strategies for AUI3703
5.1 Follow‑Up on Audit Recommendations (Standard 2500)
The CAE is responsible for establishing a follow‑up process to monitor the implementation of management actions. This is covered under Standard 2500 – Monitoring Progress and frequently examined in UNISA AUI3703 and CUT IAU30AS.
Key aspects:
-
Tracking of Action Plans
- Use of an audit issues log or database.
- Fields include:
- Finding description.
- Risk rating.
- Agreed actions.
- Responsible person.
- Target dates.
- Implementation status.
-
Follow‑Up Procedures
- Obtain management self‑assessments and evidence of implementation.
- Perform selective testing to verify that controls have been implemented and are operating as intended.
- Re‑rate residual risk where appropriate.
-
Reporting Follow‑Up Results
- Summaries to management and the audit committee on implementation status.
- Focus on overdue high‑risk issues and their impact.
Exam questions may present a list of outstanding recommendations with status updates and ask students to:
- Identify weaknesses in follow‑up (e.g., many high‑risk issues unaddressed).
- Suggest how the CAE should report this to the audit committee.
- Propose improvements to the follow‑up process.
5.2 Quality Assurance and Improvement Programme (QAIP)
While AUI3703 is focused on specific engagements and reporting, quality considerations from Standard 1300 – Quality Assurance and Improvement Program are relevant to engagement‑level work:
-
Internal assessments
- Ongoing supervision of engagements.
- Periodic file reviews.
-
External assessments
- Typically every five years.
- Evaluate conformance with Standards and the Code of Ethics.
Within an engagement:
-
Supervision and Review
- Engagement supervisor reviews working papers.
- Ensures objectives are met, evidence is sufficient, and conclusions are supported.
-
Engagement Quality
- Adequate planning and documentation.
- Clear linkage between risks, procedures, findings, and recommendations.
Exam‑type scenario: Students may get an extract from an internal audit file or report and be asked to identify quality deficiencies, such as:
- Lack of evidence to support a major finding.
- Missing documentation of planning or scope.
- Unclear or generic recommendations.
5.3 Ethics and Independence in Specific Engagements
Ethical considerations and independence (from the IIA Code of Ethics and Standards 1100‑1130) underpin all engagements. In AUI3703, you might face scenarios where independence is threatened, e.g.:
- Internal auditor previously worked in the payroll department being assigned to audit payroll.
- Internal audit involvement in designing controls in a new system then later auditing that system.
Students must show they can:
- Identify threats to independence and objectivity.
- Propose appropriate safeguards:
- Assign different auditors.
- Use external providers for certain reviews.
- Limit the scope of work where advisory roles were performed.
An example question might be: “Discuss the appropriateness of the internal audit activity conducting a review of the payroll controls three months after having designed and implemented those controls.”
A strong answer references Standard 1130 – Impairment to Independence or Objectivity and explains how internal audit must not assume management responsibilities.
5.4 Linking AUI3703 to Other Internal Auditing Modules
Students in the UNISA BCom Internal Auditing and similar programmes at CUT, TUT, and NWU often take:
- UNISA AUI3701 – Advanced Governance
- UNISA AUI3702 – Advanced Risk and Control
- UNISA AUI3703 – Specific Internal Audit Engagements and Reporting
- UNISA AUI4861 – Advanced Internal Auditing (postgraduate)
- CUT IAU30AS – Internal Auditing III
- CUT IAU40AS – Internal Auditing IV
AUI3703 specifically:
- Builds on risk and control knowledge from AUI2602 and AUI3702.
- Applies governance principles addressed in AUI3701.
- Prepares students for more complex engagements and reporting in AUI4861 or workplace practice.
In an exam, you might be asked to integrate concepts, for example:
- Using a risk and control matrix (from AUI3702) to plan a procurement engagement (AUI3703).
- Explaining how audit findings on governance (AUI3701) should be structured in a report (AUI3703).
5.5 Exam Preparation Strategies for AUI3703 (UNISA, CUT, and Similar Courses)
Given the practical, case‑study nature of AUI3703 exams, preparation should be active and application‑oriented rather than purely theoretical.
5.5.1 Focus Areas Based on Past Papers
Across UNISA AUI3703, CUT IAU30AS, and similar modules, exam patterns show recurring themes:
- Planning and designing audit procedures for:
- Procurement/SCM.
- Payroll.
- Inventory and fixed assets.
- Revenue and receivables.
- Drafting reportable findings and recommendations from mini‑cases.
- Evaluating and improving internal audit reports.
- Discussing data analytics and CAATs in specific engagements.
- Explaining and applying key IIA Standards, especially 2200, 2300, 2400, 2500.
Reviewing past papers (from myUNISA, CUT e‑learning portals, or NWU eFundi) helps identify typical question formats.
5.5.2 Building a Personal “Engagement Template”
To respond quickly and effectively, many top students create structured templates for:
-
Planning
- A standard list of planning steps.
- Space to adapt to scenario details.
-
Risk and Procedure Mapping
- Small tables where each risk is mapped to:
- Related control.
- Proposed audit procedure.
- Small tables where each risk is mapped to:
-
Finding Structure
- A standard Condition–Criteria–Cause–Effect–Recommendation layout.
-
Report Outline
- Executive summary bullet points.
- Background, objectives, scope, methodology headings.
Practising with these templates until they are almost automatic helps significantly under time pressure.
5.5.3 Practical Application and Case Writing
Exams in courses like UNISA AUI3703 and CUT IAU30AS are often 70–100% case‑based. To prepare:
-
Take textbook and tutorial examples and rewrite them as your own cases:
- Change the industry (e.g., from retail to a municipality).
- Draft your own findings, recommendations, and report sections.
-
Work with peers (on myUNISA or CUT WhatsApp groups) to:
- Exchange and critique mock findings.
- Practice improving poorly written reports.
5.5.4 Memorising vs Understanding
While some memorisation is necessary (IIA Standards, key definitions), examiners look for understanding and application:
-
Instead of just memorising “Standard 2400 – Communicating Results”, ensure you can:
- Identify flaws in report extracts (e.g., lack of clarity or objectivity).
- Rewrite them in line with the Standard.
-
Instead of memorising generic procedures, understand why each procedure is performed and what risk it addresses.
5.6 Common Mistakes in AUI3703 Exams and How to Avoid Them
Across UNISA, CUT, and other universities in South Africa, examiners frequently note similar weaknesses in student scripts:
-
Vague, Generic Procedures
- “Check that all purchases are authorised.”
- Improvement:
- Specify what documents to inspect, how many, and which attributes to test (e.g., authorisation signatures, date stamps).
-
Mixing Up Risks and Controls
- Stating a control as a risk, e.g., “Segregation of duties is a risk.”
- Improvement:
- Phrase risks as potential negative events (e.g., “Unauthorised payments due to lack of segregation of duties”).
-
Unstructured Findings
- Jumping directly to recommendations without clearly describing the condition and criteria.
- Improvement:
- Use the Condition–Criteria–Cause–Effect–Recommendation structure.
-
Overly Long Background and Theory
- Spending too many lines rewriting textbook definitions instead of applying them to the case.
- Improvement:
- Limit theory to a few concise sentences; focus on application.
-
Missing Links to Standards
- Not referencing relevant IIA Standards where appropriate.
- Improvement:
- Integrate standards naturally (e.g., “In line with Standard 2200, the engagement plan should include…”).
-
Ignoring the Mark Allocation
- Writing one page for a 5‑mark question and two lines for a 15‑mark question.
- Improvement:
- Use mark allocations as a guide for depth (roughly 1 mark per well‑made point).
5.7 Integrating AUI3703 Knowledge into Professional Practice
For students aiming at professional qualifications (e.g., Certified Internal Auditor – CIA or IIA South Africa’s professional certifications), AUI3703 content is directly relevant:
- Engagement planning and execution map to CIA Part 2 topics.
- Internal audit reporting and communication features heavily in both CIA Part 2 and Part 3.
- South African‑specific governance and regulatory knowledge (King IV, PFMA/MFMA) is crucial for local internal audit roles.
By mastering AUI3703 engagements and reporting, students not only prepare for exams at UNISA, CUT, and similar institutions, but also build a strong foundation for entry‑level internal audit positions, where work often begins with specific audits of payroll, procurement, inventory, or revenue cycles and the preparation of high‑quality internal audit reports.
These notes align with the UNISA BCom Internal Auditing curriculum for AUI3703: Specific Internal Audit Engagements and Reporting, while also supporting related modules at Central University of Technology (e.g., IAU30AS) and comparable South African universities. They emphasise the practical, exam‑oriented application of engagement planning, execution, IT integration, reporting, and follow‑up – all essential skills for success in AUI3703 and for a professional career in internal auditing.
