IAU115D: Internal Auditing I Study Guide (TUT, UNISA & CUT Exam Notes)

This study guide provides integrated, exam-focused notes for IAU115D: Internal Auditing I within the National Diploma: Internal Auditing at Tshwane University of Technology (TUT), with cross‑referenced keywords and concepts relevant to UNISA Internal Auditing (e.g. AUE1501, AUI2601) and CUT Internal Auditing modules. It focuses on core internal auditing theory, the International Professional Practices Framework (IPPF), internal audit processes and techniques, and South African public- and private‑sector context. The guide is designed to help you prepare for semester tests, assignments and IAU115D exam questions that require application, not rote learning.

1. Internal Auditing Fundamentals (TUT IAU115D, UNISA AUE1501, CUT IAD5110)

1.1 Definition and Purpose of Internal Auditing

The starting point for IAU115D and similar modules like UNISA AUE1501 – Introduction to Auditing and CUT IAD5110 – Internal Auditing I is the formal definition of internal auditing issued by The Institute of Internal Auditors (IIA):

“Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organisation’s operations. It helps an organisation accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control and governance processes.”

Key phrases to unpack (often examined in “define and explain” questions):

  • Independent

    • Internal auditors must be independent of the activities they audit.
    • In practice at a South African manufacturing company, this means an internal auditor may not audit a stock count process they previously managed as a warehouse supervisor.
    • Independence is primarily safeguarded structurally (reporting line to the audit committee, not to line management).
  • Objective

    • Internal auditors must be unbiased, relying on evidence rather than personal relationships or pressure from management.
    • Objectivity is often tested with scenario questions (e.g. an internal auditor auditing a close friend’s department).
  • Assurance and consulting

    • Assurance services: Provide an independent opinion or conclusion on risk management, control and governance. Example: an internal audit of credit approval controls in a bank.
    • Consulting services: Advisory, not decision‑making. Example: advising a municipality on designing segregation of duties in its new ERP system.
    • Both must remain within the boundary of independence. Internal auditors advise, but line management retains responsibility for decisions and controls.
  • Add value and improve operations

    • Internal auditing is not merely about finding errors; it should improve efficiency, effectiveness and economy.
    • Examiners may ask for ways internal auditing adds value, such as reducing fraud risk, streamlining processes, improving reporting reliability, and reinforcing ethical culture.
  • Systematic, disciplined approach

    • Refers to using structured methodologies (risk assessments, audit programs, sampling, documentation standards) rather than ad‑hoc checks.
    • Links directly to the internal audit process (see Section 3).

1.2 Differences Between Internal and External Auditing

In South Africa, many TUT IAU115D and UNISA AUE1501/AFR1501 past papers test comparisons between internal and external auditing. Use a structured table and be able to expand each row:

Aspect Internal Auditing (IA) External Auditing (EA)
Main objective Improve operations; evaluate risk, control & governance Express opinion on financial statements
Primary user of reports Management & audit committee Shareholders & external stakeholders
Appointment By management / audit committee By shareholders (Companies Act)
Scope Determined by risk‑based internal audit plan Primarily financial statements and related controls
Standards IIA Standards (IPPF) ISA (International Standards on Auditing)
Frequency Continuous / according to internal plan Usually annual
Independence Independent within the organisation Independent from the organisation
Employment relationship Employees or in‑house function External firm / audit practice

Exam tip for IAU115D: when asked to explain differences, do not just list keywords; provide short explanatory sentences with simple examples. For example:

Internal auditors assess the efficiency and effectiveness of procurement processes (e.g. ensuring TUT’s stationery is procured competitively), while external auditors mainly focus on whether procurement transactions are correctly recorded in the financial statements.

1.3 Roles of the Internal Auditor in South African Organisations

Internal auditors fulfil multiple roles that often appear in application questions:

  1. Assurance provider

    • Evaluates the design and operating effectiveness of internal controls.
    • Example: At a Gauteng retailer, testing whether discounts over 20% are appropriately authorised by a sales manager.
  2. Risk advisor (but not risk owner)

    • Provides input into the organisation’s risk management framework, but does not own risks.
    • Example: Advising a university of technology on IT cybersecurity risks for its online learning platform.
  3. Fraud deterrence and investigation support

    • Internal audit is not primarily a fraud investigation unit, but it helps design anti‑fraud controls and occasionally performs investigations.
    • Scenario questions might involve whistle‑blowing reports that an internal auditor must handle confidentially and professionally.
  4. Governance and ethics champion

    • Monitors adherence to King IV corporate governance principles (highly examinable for South African students).
    • Example: Assessing whether the board committees operate effectively and report transparently.
  5. Consultant on process improvements

    • Internal auditors often recommend process redesigns that reduce duplication and improve turnaround time.
    • Example: Recommending automation of leave approvals in a provincial department.

1.4 Independence, Objectivity and Professional Ethics

Internal auditors at TUT, UNISA and CUT are expected to adhere to the IIA Code of Ethics and, where relevant, professional codes of bodies such as SAICA or SAIGA. Examination questions frequently require:

  • Listing and explaining the IIA ethical principles:

    1. Integrity – Perform work honestly and with responsibility. Example: Not manipulating audit findings to please a senior manager.
    2. Objectivity – Avoid conflicts of interest and bias in judgments. Example: Disclosing close family relationships before accepting an assignment in that unit.
    3. Confidentiality – Protect sensitive information obtained during audits and use it only for authorised purposes. Example: Not sharing payroll data with friends or family.
    4. Competency – Apply knowledge and skills competently and only accept work you are qualified to perform. Example: Seeking specialist IT audit support for complex cybersecurity reviews.
  • Threats to independence and objectivity:

    • Self‑review: auditing your own past work.
    • Familiarity: long association with a department leading to bias.
    • Intimidation: pressure from senior management to change findings.
    • Advocacy: promoting a project so strongly that you cannot later audit it objectively.
    • Self‑interest: financial or personal interest in audit outcomes.

For IAU115D exams, use short scenarios to illustrate each threat. For instance:

An internal auditor at a Johannesburg municipality is offered a generous “consulting fee” by a vendor whose tender process is under audit. Accepting the fee would create a self‑interest threat and breach integrity and objectivity.

1.5 The Place of Internal Auditing in the Organisational Structure

Internal auditing’s organisational placement determines its independence and effectiveness:

  • Functional reporting to the audit committee (a sub‑committee of the board) for:

    • Approval of the internal audit charter.
    • Approval of the risk‑based audit plan.
    • Review of significant audit findings.
    • Appointment and dismissal of the chief audit executive (CAE).
  • Administrative reporting to the CEO or equivalent for:

    • Budget approval and resource requirements.
    • Day‑to‑day administrative matters (leave, HR processes, etc.).

Common exam questions for TUT IAU115D and UNISA AUI2601:

  • Explain why functional reporting to an audit committee enhances independence.
  • Describe the typical composition and responsibilities of an audit committee in terms of King IV and the Companies Act.
  • Discuss the implications if an internal audit function reports directly to the CFO instead of the audit committee (risk of self‑review, conflict of interest, reduced independence).

2. The International Professional Practices Framework (IPPF) and Internal Audit Governance

2.1 Overview of the IPPF

The International Professional Practices Framework (IPPF) is a globally recognised framework issued by the IIA to guide internal auditing. South African universities, including TUT (IAU115D), UNISA (AUI2601, AUI3701) and CUT Internal Auditing modules, require students to know at least the high‑level structure.

Current IPPF elements relevant to introductory modules:

  • Mandatory Guidance:

    • Core Principles for the Professional Practice of Internal Auditing
    • Definition of Internal Auditing
    • Code of Ethics
    • International Standards for the Professional Practice of Internal Auditing (IIA Standards)
  • Recommended (Strongly Recommended) Guidance:

    • Implementation Guides (IGs)
    • Supplemental Guidance (practice guides and practice advisories)

For IAU115D, focus on the Standards, Code of Ethics, and how they interact with South African corporate governance (King IV).

2.2 Core Principles for the Professional Practice of Internal Auditing

The 10 Core Principles explain what makes internal audit effective. They are often examined in essay‑type questions. A typical list (paraphrased for study purposes):

  1. Demonstrates integrity.
  2. Demonstrates competence and due professional care.
  3. Is objective and free from undue influence (independent).
  4. Aligns with the strategies, objectives, and risks of the organisation.
  5. Is appropriately positioned and adequately resourced.
  6. Demonstrates quality and continuous improvement.
  7. Communicates effectively.
  8. Provides risk‑based assurance.
  9. Is insightful, proactive, and future‑focused.
  10. Promotes organisational improvement.

For exam answers:

  • Do not just list; explain with brief examples.
  • Example for Principle 8:

    “Provides risk‑based assurance” means that audit engagements are selected and prioritised according to the organisation’s key risks, such as credit risk in a bank or supply chain risk in a mining company, rather than auditing every area on a rotation without considering risk levels.

2.3 Categories of Standards: Attribute vs Performance

The IIA Standards are commonly split into:

  1. Attribute Standards (1000 series) – address the characteristics of organisations and individuals performing internal auditing.
    Key Attribute Standards you must know:

    • 1000 – Purpose, Authority, and Responsibility
      • Requires an internal audit charter approved by senior management and the board.
    • 1100 – Independence and Objectivity
      • Internal audit activity must be independent; internal auditors must be objective.
    • 1200 – Proficiency and Due Professional Care
      • Internal auditors must possess necessary knowledge, skills and demonstrate due professional care.
    • 1300 – Quality Assurance and Improvement Program (QAIP)
      • Internal audit activity must maintain a QAIP that covers all aspects of internal audit activity.
  2. Performance Standards (2000 series) – describe the nature of internal auditing and provide quality criteria against which performance can be measured.
    Important Performance Standards in IAU115D scope:

    • 2000 – Managing the Internal Audit Activity
    • 2100 – Nature of Work (risk management, control and governance)
    • 2200 – Engagement Planning
    • 2300 – Performing the Engagement
    • 2400 – Communicating Results
    • 2500 – Monitoring Progress
    • 2600 – Communicating the Acceptance of Risks

In TUT exam questions, you may be asked to:

  • Identify whether a standard is Attribute or Performance.
  • Explain the implications if the standard is not followed (e.g. no QAIP leads to lower audit quality and non‑compliance with professional expectations).

2.4 Internal Audit Charter and the Audit Committee

A common IAU115D and UNISA AUI2601 exam topic is the internal audit charter:

Definition: A formal document that defines the purpose, authority, and responsibility of the internal audit activity, consistent with the Definition of Internal Auditing, the Code of Ethics, and the Standards.

Key contents of an internal audit charter:

  • Statement of purpose in line with the IIA definition.
  • Organisational status and reporting lines of internal audit.
  • Authority to access records, personnel, and physical properties relevant to audits.
  • Responsibilities for assurance and consulting activities.
  • Independence guarantees (e.g. direct access to the audit committee).
  • Accountability of the Chief Audit Executive (CAE).
  • Scope of work, including risk management, internal control, and governance.

Audit Committee Responsibilities (aligned with King IV and covered across TUT, UNISA & CUT):

  • Approve the internal audit charter.
  • Approve the annual risk‑based internal audit plan.
  • Review internal audit reports and monitor remediation of findings.
  • Evaluate the performance and independence of internal audit.
  • Recommend appointment or dismissal of the CAE.

Exam‑style question example:

“Explain why it is important that the internal audit charter is approved by the audit committee, and not just by executive management.”

Expected points:

  • Ensures independence from management.
  • Aligns internal audit’s mandate with board expectations.
  • Provides formal authority for internal audit to access information.
  • Demonstrates governance oversight in line with King IV.

2.5 Quality Assurance and Improvement Program (QAIP)

Standard 1300 requires a QAIP. While more detailed coverage appears in later modules (e.g. UNISA AUI3701), IAU115D students must understand the basics:

  • Internal assessments:

    • Ongoing monitoring (supervision, workpaper review, client feedback).
    • Periodic self‑assessments or internal quality reviews.
  • External assessments:

    • At least once every five years by a qualified, independent reviewer or review team from outside the organisation.

Why QAIP matters:

  • Ensures that internal audit adds real value and meets professional standards.
  • Provides assurance to the audit committee that internal audit is effective.
  • Identifies training needs and process improvements.

Example: A large South African insurer conducts an external quality assessment every five years. The 2025 review identifies a weakness in root‑cause analysis of findings. Internal audit responds by adding a root‑cause methodology checklist to every engagement and training all auditors on its use.

3. Internal Audit Process: From Planning to Follow‑Up (TUT IAU115D Focus)

3.1 Overview of the Internal Audit Engagement Life Cycle

For IAU115D, UNISA AUI2601 and CUT Internal Auditing, a central theme is the internal audit process. Typical phases:

  1. Strategic planning of the internal audit activity (annual risk‑based plan).
  2. Engagement planning for each audit (defining objectives, scope, criteria).
  3. Fieldwork/execution (gathering evidence through tests and procedures).
  4. Reporting (writing the internal audit report and communicating findings).
  5. Follow‑up (monitoring implementation of recommendations).

Exam questions often describe a scenario (e.g. audit of the procurement process at a municipal entity) and require you to describe the steps and relate them to the scenario.

3.2 Risk‑Based Internal Audit Planning

Although strategic audit planning is sometimes introduced in later modules, many TUT IAU115D lecturers test it at an introductory level:

Steps in developing a risk‑based internal audit plan:

  1. Understand the organisation and its environment

    • Industry, regulatory environment (e.g. PFMA/MFMA for public sector), key processes, IT systems.
  2. Identify risks and processes

    • Use interviews, risk workshops, review of risk registers, and prior audit findings.
  3. Assess risk

    • Consider impact and likelihood.
    • High‑risk areas might include:
      • Revenue recognition in a retail chain.
      • Cash management in a university.
      • Procurement and contract management in a municipality.
  4. Prioritise and allocate resources

    • Focus on high‑risk areas within resource constraints.
    • Example: A small internal audit unit with 5 auditors cannot review all branches annually; it focuses on branches with highest transaction volumes or highest fraud history.
  5. Develop the annual internal audit plan

    • Document engagements, estimated audit hours, timing, and responsible auditors.
    • Submit to the audit committee for approval.

3.3 Engagement Planning: Terms of Reference and Audit Program

For each engagement, Standard 2200 requires formal planning. Key documents:

  • Engagement letter / Terms of Reference (ToR) (especially in outsourced/co‑sourced arrangements).
  • Audit planning memorandum.
  • Audit program.

Core elements of engagement planning:

  1. Define audit objectives

    • Example: “To evaluate the effectiveness of controls over the accounts payable process at TUT.”
  2. Define scope

    • Processes covered (e.g. invoice processing, supplier master data changes).
    • Time period (e.g. 1 January 2025 to 31 December 2025).
    • Locations (e.g. Pretoria Campus, Ga‑Rankuwa Campus).
  3. Identify criteria

    • Policies, procedures, legislation (e.g. PFMA, MFMA, Treasury Regulations), King IV, and best practices.
  4. Perform preliminary risk assessment

    • Identify inherent and control risks in the process.
    • For example, in accounts payable:
      • Risk of duplicate payments.
      • Risk of payments to fictitious suppliers.
      • Risk of unauthorised changes to bank details.
  5. Develop an audit program

    • List of specific procedures to address each risk and objective.
    • Example test: “Select a sample of 30 payments exceeding R50 000 and inspect evidence of proper supplier approval and authorisation according to the delegation of authority.”

Exam tip: When asked to draft parts of an audit program, always link procedure → evidence → objective.

3.4 Evidence, Working Papers and Sampling

Audit evidence is any information used by the internal auditor to reach conclusions. Characteristics:

  • Sufficient (quantity).
  • Relevant (links to objective).
  • Reliable (from credible sources).

Types of evidence:

  • Physical – observing assets such as inventory.
  • Documentary – invoices, purchase orders, contracts.
  • Analytical – ratios, trend analyses.
  • Oral – interviews with staff (must be corroborated).

Working papers:

  • Provide a record of planning, procedures performed, evidence obtained, and conclusions reached.
  • Must be clear enough that another internal auditor can understand what was done and why.

Typical working paper content:

  • Heading with engagement name, area, and period.
  • Objective of the procedure.
  • Detailed description of tests.
  • Sample size and sampling method.
  • Actual results, including exceptions.
  • Conclusion and reference to issue log or report.

Audit sampling (introductory level for IAU115D):

  • Two main approaches:
    • Statistical sampling – uses probability theory; allows quantification of sampling risk.
    • Non‑statistical (judgmental) – uses auditor’s professional judgment.

Common exam tasks:

  • Explain why sampling is used instead of examining all transactions (time, cost, practicality).
  • Differentiate between:
    • Random sampling – each item has an equal chance of selection.
    • Haphazard sampling – non‑random selection without structure (not recommended if it introduces bias).
    • Systematic sampling – selecting every nth item.

Example scenario: In an audit of travel claims at a government department, the internal auditor uses random sampling of 60 claims out of 6,000 processed in the year. The objective is to test compliance with travel policies and verify supporting documentation.

3.5 Fieldwork Techniques

Internal audit fieldwork typically involves:

  1. Enquiry (interviews)

    • Asking process owners and staff to explain processes and controls.
    • Must be corroborated by other evidence.
  2. Observation

    • Watching processes in operation (e.g. stock counts, cash counts, receiving goods).
  3. Inspection

    • Examining documents and records for evidence of authorisation, completeness and accuracy.
  4. Re‑performance

    • Internal auditor independently executes a control or calculation to verify it works as described.
  5. Analytical procedures

    • Comparisons, ratios, trend analysis, reasonableness tests.
    • Example: Comparing monthly overtime costs over twelve months to identify anomalies at a particular depot.

Examiners often use application questions such as:

“Describe the audit procedures you would perform to test controls over petty cash at a university campus.”

Expected procedures:

  • Observe surprise cash count.
  • Reconcile cash on hand to the petty cash book and general ledger.
  • Inspect a sample of vouchers for approval and supporting receipts.
  • Review frequent replenishment patterns that may indicate misuse.

3.6 Communicating Results: The Internal Audit Report

The internal audit report is the primary deliverable of an engagement. Common required elements for TUT IAU115D and UNISA modules:

  • Title and distribution list.

  • Background to the area audited.

  • Objectives and scope of the audit.

  • Methodology (brief).

  • Audit opinion/conclusion (if applicable).

  • Findings, each including:

    • Condition (what is).
    • Criteria (what should be).
    • Cause (why the difference exists).
    • Effect (so what – risk/impact).
    • Recommendation (what should be done).
    • Management response and implementation date.
  • Overall rating (e.g. satisfactory, needs improvement, unsatisfactory), if the organisation uses a rating system.

Example of a concise finding (typical exam style):

Finding 2: Lack of segregation of duties in supplier master file maintenance
Condition: In the Finance Department, the same clerk can both create and approve new supplier accounts in the ERP system.
Criteria: Best practice and TUT’s financial policies require that supplier creation and approval be performed by different individuals.
Cause: System user roles were not properly configured during the ERP implementation.
Effect: Increased risk of fictitious suppliers and fraudulent payments.
Recommendation: Configure system roles to ensure that no user can both create and approve a supplier. Implement a periodic review of user access rights.
Management Response: Accepted. ERP support team to update roles and run user access review by 30 June 2026.

3.7 Follow‑Up and Monitoring

Standard 2500 requires internal auditors to monitor management’s action plans:

  • Track implementation status of recommendations (open, in progress, implemented, rejected).
  • Periodically report unresolved high‑risk issues to the audit committee.
  • Conduct follow‑up audits for critical issues to verify that corrective actions are effective.

Exam points:

  • Explain why follow‑up is an essential part of the internal audit process:
    • Without follow‑up, identified risks may persist.
    • It demonstrates internal audit’s commitment to value adding.
    • It provides accountability for management’s commitments.

Example: An internal audit of IT backups finds that offsite backups were not regularly tested. Management commits to quarterly recovery testing. Six months later, internal audit reviews logs and test results to confirm that recovery tests were done and documented.

4. Risk Management, Internal Control and Governance (with South African Context)

4.1 Understanding Risk and Its Types

Risk is central to IAU115D and related modules such as UNISA AUI2601 – Internal Auditing. Risk can be defined as:

The possibility that an event will occur and adversely affect the achievement of objectives.

Common risk categories tested in exams:

  • Strategic risk – relating to high‑level goals and strategy (e.g. declining student enrolment at a university).
  • Operational risk – arising from day‑to‑day operations (e.g. breakdowns in manufacturing machinery).
  • Financial risk – credit risk, liquidity risk, market risk (e.g. interest rate fluctuations affecting loan portfolios).
  • Compliance risk – failure to adhere to laws and regulations (e.g. PFMA, Companies Act, tax laws).
  • Reputational risk – negative public perception (e.g. media exposure of corruption in a municipality).

Exam tasks often require classification of risks in a scenario, and suggestions for controls to mitigate them.

4.2 Components of the Internal Control System

Most South African curricula use variations of COSO Internal Control – Integrated Framework. Five components:

  1. Control Environment

    • Tone at the top, integrity, ethical values, governance structure.
    • Example: The board’s commitment to ethical behaviour and zero tolerance for fraud.
  2. Risk Assessment

    • Process of identifying and analysing risks to achievement of objectives.
  3. Control Activities

    • Policies and procedures that ensure management directives are carried out.
    • Examples: approvals, authorisations, verifications, reconciliations, segregation of duties.
  4. Information and Communication

    • Systems to capture, process and report information; channels for communication to staff and stakeholders.
  5. Monitoring Activities

    • Ongoing and separate evaluations of controls; includes internal audit and line management reviews.

Understanding types of control activities is important:

  • Preventive controls – prevent errors/fraud before they occur (e.g. segregation of duties, password controls).
  • Detective controls – identify errors/fraud after they occur (e.g. bank reconciliations, exception reports).
  • Corrective controls – fix the problem identified (e.g. restoring data from backups, disciplinary actions).

Typical exam question:

“List and explain four types of internal control activities and provide an example of each in the context of a university’s payroll system.”

Sample answer elements:

  • Authorisation: HR approves all new employees and salary changes.
  • Recording: Payroll department records transactions into the payroll system.
  • Reconciliation: Monthly reconciliation between payroll reports and the general ledger.
  • Access control: User access in the HR system restricted to authorised staff.

4.3 The Role of Internal Auditing in Risk Management

According to IPPF Standard 2120 and IIA position papers, internal audit’s role is to evaluate and improve risk management, not to own it:

  • Assurance roles:

    • Assess whether risks are correctly identified and evaluated.
    • Evaluate risk responses (accept, mitigate, transfer, avoid).
    • Provide assurance that key risks are managed within appetite.
  • Consulting roles (provided independence is preserved):

    • Facilitate risk assessment workshops.
    • Provide training on risk concepts and methodologies.
    • Advise on embedding risk management in performance measures.

Prohibited roles (which would impair independence):

  • Setting risk appetite and tolerance.
  • Managing or owning specific risks.
  • Implementing risk responses on behalf of management.
  • Deciding which risks are acceptable.

Exam question style:

“Distinguish between appropriate and inappropriate roles for internal audit in risk management, giving examples.”

Expected answer:

  • Appropriate: Reviewing the adequacy of a bank’s credit risk management framework.
  • Inappropriate: Approving credit limits for large customers.

4.4 Governance and King IV in the South African Context

King IV Report on Corporate Governance for South Africa is heavily referenced in many South African internal auditing modules, including TUT IAU115D and UNISA AUE2601/AUI2601. Key exam topics:

  • Governance definition: The exercise of ethical and effective leadership by the governing body towards achieving desired governance outcomes (ethical culture, good performance, effective control, legitimacy).

  • Roles of the board (governing body):

    • Strategy and policy oversight.
    • Risk governance.
    • Technology and information governance.
    • Compliance governance.
    • Stakeholder relationships.
  • Audit committee roles (already discussed in Section 2.4) but emphasised under King IV:

    • Overseeing financial and integrated reporting.
    • Overseeing internal audit and external audit.
    • Ensuring combined assurance model is effective.
  • Combined assurance:

    • Coordination of assurance activities from management, internal audit, external audit, regulators, and other assurance providers.
    • Aim: reduce duplication and gaps in assurance.

Internal auditors must assess whether governance structures are effective. Example tasks:

  • Reviewing the charters of the board and its committees.
  • Evaluating meeting minutes for evidence of robust challenge to management.
  • Assessing whether governance practices align with King IV principles.

4.5 Fraud Risk and Internal Auditing

Fraud is a high‑profile topic and often appears in IAU115D, UNISA AUE1501 and CUT Internal Auditing exams.

Definition of fraud (adapted to internal audit context):

An intentional act by one or more individuals among management, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage.

Categories:

  • Fraudulent financial reporting – deliberate misstatements or omissions in financial statements.
  • Misappropriation of assets – theft of cash, inventory or other assets.
  • Corruption – bribery, kickbacks, conflicts of interest.

Internal auditors’ roles regarding fraud:

  • Evaluate the adequacy of fraud risk management (policies, hotline, training).
  • Assess the effectiveness of anti‑fraud controls (segregation of duties, approvals, monitoring).
  • Participate in or support fraud investigations when requested, but not replace specialised forensic experts.

Exam practice:

  • Provide examples of fraud in different environments:

    • Public sector: fictitious suppliers for grants.
    • Higher education: manipulation of student marks for bribes.
    • Retail: collusion between cashiers and customers in refund scams.
  • Suggest internal controls to mitigate each example.

    • Mandatory rotation of staff in sensitive positions.
    • Vendor verification processes.
    • Data analytics on unusual transactions.

4.6 Case Study: Procurement in a South African Municipality

A common exam approach is a case study focusing on procurement in a municipality, a state‑owned entity, or a large corporate. Key risks:

  • Conflict of interest in awarding tenders.
  • Non‑compliance with PFMA/MFMA and Supply Chain Management (SCM) regulations.
  • Splitting of orders to avoid competitive bidding.
  • Poor record‑keeping.

Internal audit engagement objectives might include:

  • Assessing compliance with legislative requirements.
  • Evaluating the adequacy of tender evaluation processes.
  • Testing payments for evidence of delivery and receipt of goods/services.

Examples of audit procedures:

  • Review a sample of tenders above a threshold (e.g. R1 million) for proper advertising, evaluation, and approval.
  • Verify that declarations of interest were obtained from bid committee members.
  • Review contracts for key clauses (performance guarantees, penalties).
  • Test a sample of payments to confirm goods or services were received and matched to approved contracts.

Examiners may ask you to:

  • Identify control weaknesses from a scenario.
  • Suggest recommendations to strengthen procurement controls.
  • Discuss how internal audit should report serious instances of irregular, fruitless and wasteful expenditure.

5. Exam Strategy, Typical Questions and Integrated Revision (TUT IAU115D, UNISA & CUT Alignment)

5.1 Linking IAU115D Content to Other Modules (UNISA & CUT Keywords)

Although this guide is categorised under Tshwane University of Technology (TUT): National Diploma: Internal Auditing – IAU115D: Internal Auditing I, the core concepts strongly overlap with:

  • UNISA:

    • AUE1501 – Principles of Auditing (basic audit concepts, differences between internal and external auditing, evidence, sampling).
    • AUI2601 – Internal Auditing: Risk and Internal Control (IPPF, risk management, internal control frameworks).
    • AUI3701 – Governance, Risk and Compliance (advanced governance and combined assurance).
  • Central University of Technology (CUT):

    • IAD5110 – Internal Auditing I (definition, internal control, audit process).
    • IAD5211 – Internal Auditing II (expands on risk‑based planning and advanced techniques).

Students searching for “IAU115D study notes”, “UNISA AUI2601 exam tips”, “CUT IAD5110 internal auditing notes” will benefit from understanding that the same IIA and King IV frameworks underpin all these modules, even if assessment styles differ.

5.2 Common Exam Question Types in Internal Auditing I

Across TUT, UNISA and CUT, introductory internal auditing modules typically use:

  1. Definitions and theory questions

    • E.g. “Define internal auditing according to the IIA and explain two key elements of the definition.”
    • Strategy: Memorise core definitions and be able to explain in your own words with a short example.
  2. Short essay questions (10–20 marks)

    • Compare internal and external audit.
    • Describe the internal audit process phases.
    • Explain the components of internal control.
    • Strategy: Use structured headings and bullet points.
  3. Scenario‑based application questions

    • Given a description of a process (e.g. cash receipts at a campus cafeteria), identify risks and controls or design audit procedures.
    • Strategy: Identify core risks, then structure answers around risk → control or objective → test.
  4. Case studies (often 20–40 marks in final exams)

    • Multi‑page scenario of an organisation with governance, risk, control, and audit issues.
    • Questions may span:
      • Risk assessment.
      • Audit planning.
      • Findings and recommendations.
      • Ethics and independence.

5.3 How to Answer Scenario Questions Effectively

To score well in IAU115D and similar modules, focus on application:

  1. Read the scenario carefully

    • Underline or highlight:
      • Key processes (e.g. payroll, inventory).
      • Mentioned weaknesses (e.g. “no formal policy”, “one person does everything”).
      • References to legislation (PFMA, Companies Act, tax acts).
  2. Identify the required perspective

    • Are you answering as an internal auditor, management, or audit committee?
    • Many marks are lost by giving generic answers not tailored to the role.
  3. Structure your answer

    • Use headings:
      • “Risks”
      • “Controls”
      • “Audit procedures”
      • “Findings and recommendations”
    • Within each heading, use bullet points.
  4. Apply core theory

    • Link back to IPPF standards, risk management, internal control concepts, and ethics.
    • For instance, when asked to comment on independence, mention Standard 1100 and governance practices.

Example: Scenario – The internal audit function at a medium‑sized manufacturing company reports administratively and functionally to the CFO. The CFO reviews and approves all internal audit reports before they are presented to the audit committee.

Possible question: “Identify and explain any weaknesses in internal audit’s organisational status and make recommendations.”

Answer framework:

  • Weakness: Functional reporting to CFO, not audit committee – independence compromised.
  • Weakness: Reports filtered by CFO – risk of suppression or alteration of findings, especially when findings relate to finance processes.
  • Recommendation:
    • Internal audit should report functionally to the audit committee.
    • Audit committee should approve internal audit charter and receive reports directly from the CAE.
    • CFO involvement limited to administrative matters.

5.4 Study Plan and Revision Strategy for IAU115D

A disciplined plan is essential, especially for students balancing work and study (common at UNISA and TUT).

1. Map the syllabus

Break content into manageable blocks:

  • Week 1–2:

    • Definition of internal auditing, differences from external auditing, roles of the internal auditor, ethics and independence.
  • Week 3–4:

    • IPPF: Definition, Code of Ethics, Standards, core principles, internal audit charter, audit committee.
  • Week 5–6:

    • Internal audit process (planning, fieldwork, evidence, sampling, working papers, reporting, follow‑up).
  • Week 7–8:

    • Risk management, internal control frameworks (COSO), governance and King IV, fraud risk.
  • Week 9–10:

    • Integration, past exam questions, case studies.

2. Use active learning techniques

  • Summarise each topic in your own words.
  • Create diagrams (e.g. a simple flowchart of the internal audit process).
  • Develop your own examples relevant to South African contexts you know (universities, municipalities, retail stores, banks).

3. Practise exam‑style questions

  • Write at least one full‑length essay per week under timed conditions.
  • Use online resources and past papers for TUT IAU115D, UNISA AUE1501/AUI2601 and CUT IAD5110 if available.
  • After writing your answer, compare to model solutions or marking rubrics.

4. Memorise key lists and structures

Some things must be known almost word‑for‑word:

  • IIA definition of internal auditing.
  • Four principles of IIA Code of Ethics.
  • Five components of internal control (COSO).
  • Key IPPF elements (mandatory vs recommended).
  • Core phases of the internal audit process.

Create flashcards (physical or digital) and review them regularly.

5.5 Example Integrated Exam Question and Model Answer Outline

Question (30 marks)

You are an internal auditor at a South African public university. The university’s cafeteria operations have expanded rapidly, with new outlets on three campuses. Management is concerned about possible theft of cash and stock. You are requested to perform an internal audit of cafeteria operations.

Required:

  1. Identify and explain five significant risks relating to cafeteria cash and stock. (10 marks)
  2. For each risk identified in (1), recommend one suitable internal control to mitigate the risk. (10 marks)
  3. Describe four audit procedures you would perform to evaluate the effectiveness of the controls you recommended. (10 marks)

Model answer outline:

  1. Risks:

    • Theft of cash from tills (employees under‑ringing sales, skimming).
    • Theft of inventory (stock taken without paying).
    • Inaccurate recording of sales (manual errors, manipulation).
    • Inadequate segregation of duties (same person ordering, receiving and recording stock).
    • Unauthorised price discounts or giveaways to friends.
  2. Controls:

    • Installing POS systems and reconciling daily till readings to bank deposits and sales summaries.
    • Regular stock counts by independent staff, with investigation of variances.
    • Training staff and using standardised procedures for recording sales.
    • Segregation of responsibilities: one person orders, another receives and records stock.
    • Authorisation codes in POS system for discounts; exception reports for unusual discount patterns.
  3. Audit procedures:

    • Reconcile a sample of daily cash‑up sheets to bank deposits, investigating discrepancies.
    • Observe stock counts at two campuses and perform independent re‑counts of selected items.
    • Review user access rights on the POS system to verify proper segregation of roles.
    • Perform analytical procedures (gross profit margin comparison across outlets and months) to detect anomalies suggesting possible theft or misrecording.

Marks are awarded for clarity, application to the cafeteria context, and linking risks to specific controls and procedures.

5.6 Integrating Ethics and Professionalism in Answers

Ethics is cross‑cutting across all topics. When scenarios raise ethical issues:

  • Identify which IIA Code of Ethics principles are at stake (integrity, objectivity, confidentiality, competency).
  • Describe how the internal auditor should respond (e.g. disclose conflicts, refuse inappropriate assignments, escalate serious matters to the audit committee).
  • In public sector environments, mention broader obligations under PFMA/MFMA and whistle‑blower protections (Protected Disclosures Act).

Example: If an internal auditor at a provincial department uncovers evidence of irregular expenditure personally authorised by the head of department, they should:

  • Document findings objectively.
  • Report through the established chain (CAE → audit committee), bypassing those implicated.
  • Ensure confidentiality while following internal protocols and applicable legislation.

5.7 Final Consolidation for IAU115D: Key Take‑Away Points

For final revision, focus on:

  • Core definitions:

    • Internal auditing (IIA).
    • Internal control.
    • Risk.
    • Governance.
  • Frameworks:

    • IPPF (definition, Code of Ethics, Standards).
    • COSO Internal Control – five components.
    • King IV – board and audit committee roles, combined assurance.
  • Internal audit process:

    • From planning, through fieldwork, reporting, to follow‑up.
    • Types of evidence and sampling methods.
    • Structure and content of audit reports.
  • Application skills:

    • Identifying risks and suitable controls.
    • Developing basic audit procedures.
    • Recognising independence and ethical dilemmas.

Students preparing for TUT IAU115D: Internal Auditing I, as well as aligned modules such as UNISA AUE1501/AUI2601 and CUT IAD5110, should use this guide as a comprehensive conceptual framework and then deepen their understanding with prescribed textbooks, lecture notes, and past examination papers specific to their institution. Consistent practice in writing structured, applied answers under exam conditions will convert this theoretical knowledge into exam success.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare