IAU216D: Internal Auditing II Exam Pack – Comprehensive Study Guide (TUT)

This Exam Pack is a comprehensive, exam‑oriented study guide for IAU216D: Internal Auditing II as offered in the National Diploma: Internal Auditing at Tshwane University of Technology (TUT). It is written for South African students preparing for semester tests, assignments, and especially the IAU216D exam, and is also useful for related internal auditing modules at UNISA (e.g. AUE2602, AUI2601) and CUT (Central University of Technology). The focus is on the IIA International Professional Practices Framework (IPPF), the end‑to‑end internal audit process, risk‑based internal auditing, audit evidence, and exam‑style application.

1. Context, Syllabus Overview and Exam Strategy for IAU216D (TUT)

1.1 Where IAU216D Fits in the TUT National Diploma: Internal Auditing

In the Tshwane University of Technology (TUT) National Diploma: Internal Auditing, IAU216D: Internal Auditing II typically follows foundational modules such as:

  • IAU115D / IAU116D: Internal Auditing I (depending on year/structure)
  • Basic Accounting modules (e.g. ACC101D)
  • Business and Commercial Law basics (e.g. BWL101B)
  • Introductory Risk Management and Governance content

In many curricula, IAU216D is placed at NQF level 6 and forms part of the second‑year internal auditing stream. It builds on terminology and principles introduced in Internal Auditing I and moves into:

  • Applying the IIA Standards in more depth
  • Planning and performing risk‑based internal audits
  • Documenting work in working papers and audit files
  • Communicating results and following up on recommendations

For students who may later take courses at other universities (e.g. UNISA AUI3703 or AUI3704, CUT AUD26xx codes), mastering IAU216D gives a strong foundation for those more advanced modules.

1.2 Common Syllabus Themes in Internal Auditing II (SA Universities)

While each university uses its own module code and detailed outcomes, South African Internal Auditing II courses share common themes. For TUT IAU216D, UNISA AUE2602/AUI2601, and CUT Internal Auditing II equivalents, expect emphasis on:

  1. The Internal Audit Function in Context

    • Position in governance structure
    • Independence and objectivity
    • Roles vs external audit, management, and other assurance providers
  2. The IPPF and IIA Standards

    • Mandatory guidance: Definition of Internal Auditing, Code of Ethics, Standards
    • Attribute vs Performance Standards
    • Interpretation of key standards (e.g. 1100, 1220, 2010, 2130, 2400)
  3. Risk‑based Internal Auditing

    • Corporate governance and risk management overview
    • Types of risks (strategic, operational, financial, compliance, IT)
    • Risk assessment and prioritisation of audits
  4. The Internal Audit Process / Engagement Life Cycle

    • Planning the engagement (understanding the business, setting objectives, scope)
    • Performing fieldwork and testing controls
    • Evaluating evidence and forming conclusions
    • Reporting results and follow‑up
  5. Internal Control and Control Frameworks

    • Concepts of internal control (e.g. COSO)
    • Types of controls (preventive, detective, corrective)
    • Control deficiencies and recommendations
  6. Audit Evidence, Working Papers and Documentation

    • Types of audit evidence and sufficiency
    • Working paper preparation and review
    • Electronic audit documentation and audit software basics
  7. Ethics, Independence and Quality Assurance

    • IIA Code of Ethics in practice
    • Conflicts of interest
    • Quality assurance and improvement programmes

Certain lecturers may add case studies drawn from South African organisations and the King IV Report on Corporate Governance for South Africa, which is a common reference at TUT, UNISA, and CUT.

1.3 Typical Assessment Structure for IAU216D at TUT

Each semester offering may differ slightly, but a typical TUT IAU216D assessment structure is:

  • Continuous Assessment (CA):
    • Class tests (e.g. 2–3 tests making up 30–40% of semester mark)
    • Assignments or group projects (up to 20%)
  • Exam (Summative Assessment):
    • Final exam typically carrying 50–60% of the module mark
    • Mix of:
      • Multiple choice questions (MCQs)
      • Short questions (definitions, list and explain, advantages/disadvantages)
      • Application questions based on short case scenarios
      • Longer case study/essay questions (e.g. 20–40 marks)

Many IAU216D exam papers use scenarios where you are “the internal auditor at Company X” and need to:

  • Identify control weaknesses
  • Evaluate risks
  • Design audit procedures
  • Draft audit findings and recommendations

1.4 Exam‑Orientation: How Examiners Think

In Internal Auditing II, memorisation alone is not enough. Examiners at TUT, UNISA, and CUT increasingly focus on application. Understanding how they think helps you prepare answers that earn full marks.

Examiners look for:

  1. Correct use of terminology

    • Using terms like “reasonable assurance”, “sufficient and appropriate evidence”, “engagement”, “risk‑based approach”, “control activities”, etc., in the right context.
    • Citing relevant IIA Standards when required (even by number if you remember them).
  2. Logical structure

    • For calculation or sequence questions (e.g. stages of the internal audit process), examiners want clear steps in the right order.
    • For narrative questions, examiners want headings, bullet points, and coherent explanations with cause‑and‑effect logic.
  3. Application to the given scenario

    • If the question describes a manufacturing company, responses must refer to inventory, production, procurement, etc.
    • If the scenario is a municipality or government department, link answers to public sector issues like compliance with PFMA/MFMA, service delivery, and irregular expenditure.
  4. Balanced critical thinking

    • Recognising both strengths and weaknesses in controls or governance structures.
    • Not assuming every control is ineffective or that management is always wrong.
    • Showing professional scepticism but also fairness.
  5. Relevance and brevity

    • Including enough detail to show understanding, without writing irrelevant paragraphs.
    • Using bullet points for lists (e.g. “List FOUR advantages of risk‑based internal auditing”).

1.5 Core Exam Skills You Must Master

To succeed in IAU216D and similar modules like UNISA AUE2602 Internal Auditing or CUT Internal Auditing II (AUD206 or similar), prioritise the following abilities:

  • Define and explain:
    • Internal auditing, internal control, risk, governance, independence, objectivity.
  • Apply the IPPF:
    • Explain the difference between Attribute Standards and Performance Standards.
    • Provide examples of how specific standards are applied in real audit engagements.
  • Describe the internal audit process in sequence:
    • From planning to reporting and follow‑up, including key activities.
  • Plan a risk‑based internal audit:
    • Identify risks, controls, and suitable audit procedures based on a case study.
  • Evaluate internal controls:
    • Identify control weaknesses and recommend appropriate, practical improvements.
  • Prepare simple working paper entries:
    • Describe how to document objectives, procedures, results, and conclusions.
  • Draft clear findings and recommendations:
    • Using a structured format that includes condition, criteria, cause, effect, and recommendation.

2. The IPPF, Internal Audit Function and Ethics (TUT/UNISA/CUT Alignment)

2.1 Definition, Purpose and Scope of Internal Auditing

The Institute of Internal Auditors (IIA) defines internal auditing as:

“An independent, objective assurance and consulting activity designed to add value and improve an organisation’s operations. It helps an organisation accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control and governance processes.”

Key points examinable in IAU216D and in modules such as UNISA AUE2602 and CUT AUD206:

  • Independent and objective
    • Internal auditors must be free from interference in determining the scope of internal auditing, performing work, and communicating results.
  • Assurance and consulting
    • Assurance services: objective examination of evidence to provide an independent assessment (e.g. control testing).
    • Consulting services: advisory activities, such as training or facilitation, usually not involving the assumption of management responsibility.
  • Systematic, disciplined approach
    • Use of structured methodologies, documentation, and professional standards.
  • Focus on risk, control and governance
    • Internal auditing is not only about financial records. It covers all activities affecting organisational objectives.

2.2 The International Professional Practices Framework (IPPF)

The IPPF governs professional internal auditing worldwide and is heavily tested in IAU216D and UNISA AUI2601.

The IPPF consists of mandatory and recommended guidance.

2.2.1 Mandatory Guidance

  1. Core Principles for the Professional Practice of Internal Auditing

    • Examples:
      • Demonstrates integrity
      • Demonstrates competence and due professional care
      • Is objective and free from undue influence (independent)
      • Aligns with the strategies, objectives, and risks of the organisation
      • Is insightful, proactive, and future‑focused
    • Exams often ask you to list and briefly explain any FOUR core principles.
  2. Definition of Internal Auditing

    • Often tested directly (“State the IIA definition of internal auditing”) or indirectly (apply in a scenario).
  3. Code of Ethics

    • Four principles:
      • Integrity
      • Objectivity
      • Confidentiality
      • Competency
    • Each principle is supported by rules of conduct. For example:
      • Integrity: internal auditors shall perform their work with honesty, diligence and responsibility.
      • Confidentiality: internal auditors shall not disclose information without proper authority unless legally or professionally obligated.
  4. International Standards for the Professional Practice of Internal Auditing

    • Two main categories:
      • Attribute Standards (1000 series) – deal with characteristics of organisations and individuals performing internal audit.
      • Performance Standards (2000 series) – describe the nature of internal audit activities and criteria for evaluating performance.

2.2.2 Recommended Guidance

  • Implementation Guidance – helps apply specific standards.
  • Supplemental Guidance – practical tools and techniques, like practice guides.

Although exam questions in IAU216D typically focus on mandatory guidance, some lecturers may expect you to recognise the terms “Implementation Guidance” and “Supplemental Guidance”.

2.3 Key IIA Standards for IAU216D

You are not expected to memorise every standard number, but certain standards are frequently tested in TUT IAU216D, UNISA AUE2602, and CUT modules.

2.3.1 Attribute Standards (1000 Series)

  • 1000 – Purpose, Authority, and Responsibility

    • Must be formally defined in an internal audit charter, consistent with the definition of internal auditing, the Code of Ethics, and the Standards.
  • 1100 – Independence and Objectivity

    • Internal audit activity must be independent, and internal auditors must be objective in performing their work.
  • 1110 – Organisational Independence

    • Chief Audit Executive (CAE) must report functionally to the board to allow independence. Functionally often means:
      • Approval of internal audit charter, risk‑based audit plan, and budget.
      • Access to the board or audit committee.
  • 1130 – Impairment to Independence or Objectivity

    • If independence or objectivity is impaired in fact or appearance, details must be disclosed to appropriate parties.
  • 1200 – Proficiency and Due Professional Care

    • Internal auditors must possess the necessary knowledge, skills, and other competencies, and apply due professional care in all engagements.
  • 1210 – Proficiency

    • Internal auditors must have sufficient knowledge of accounting, auditing, risk management, information technology, etc.
  • 1220 – Due Professional Care

    • Internal auditors must apply care expected of a reasonably prudent and competent internal auditor.
    • Examiners often ask for examples of what constitutes due professional care.

2.3.2 Performance Standards (2000 Series)

  • 2000 – Managing the Internal Audit Activity

    • CAE must effectively manage the internal audit activity to ensure it adds value.
  • 2010 – Planning

    • CAE must establish a risk‑based plan to determine priorities of the internal audit activity, consistent with organisational goals.
  • 2020 – Communication and Approval

    • CAE must communicate the internal audit plan and resource requirements, including significant interim changes, to senior management and the board for review and approval.
  • 2040 – Policies and Procedures

    • CAE must establish policies and procedures to guide the internal audit activity.
  • 2100 – Nature of Work

    • Internal audit activity must evaluate and contribute to the improvement of governance, risk management, and control processes.
  • 2130 – Control

    • Internal audit must evaluate the adequacy and effectiveness of controls in responding to risks.
  • 2200 – Engagement Planning

    • Internal auditors must develop and document a plan for each engagement.
  • 2300 – Performing the Engagement

    • Internal auditors must identify, analyse, evaluate, and document sufficient information to achieve engagement objectives.
  • 2400 – Communicating Results

    • Internal auditors must communicate results of engagements.
  • 2500 – Monitoring Progress

    • CAE must establish and maintain a system to monitor disposition of results.
  • 2600 – Communicating the Acceptance of Risks

    • When senior management accepts a level of risk that the CAE believes may be unacceptable, the CAE must discuss with senior management and, if not resolved, report to the board.

Knowing how to summarise and apply these standards is crucial for IAU216D exam essays.

2.4 Position of the Internal Audit Function in the Organisation

Exams often ask: “Explain how the internal audit function should be positioned in an organisation to ensure its independence and effectiveness.”

Key points:

  • Functional vs administrative reporting
    • Functional reporting line: usually to the audit committee / board. This line ensures independence in approval of audit plan, access to information, and protection from management retaliation.
    • Administrative reporting line: can be to the CEO, CFO, or another senior executive for day‑to‑day matters (budget administration, HR processes, logistics).
  • Access and authority
    • Internal audit must have full, free, and unrestricted access to all records, personnel, and physical properties relevant to the performance of engagements.
  • Audit Charter
    • Approved by the board, clarifies authority and responsibilities.
    • Protects the internal audit activity from interference.

2.5 Ethics, Independence and Objectivity in Practice

Ethics and independence scenarios are common in IAU216D, UNISA AUE2602, and CUT exams.

2.5.1 Common Exam Scenarios

Examples:

  1. An internal auditor at a manufacturing company is given a performance bonus based on annual profits and is asked to audit the costing system that heavily influences profit calculations.

    • Threat: Self‑interest threat to objectivity.
    • Recommended response: Re‑assign the engagement to another auditor or adjust remuneration structure to reduce dependence on profits.
  2. An internal auditor is asked by the head of procurement (who is the auditor’s cousin) to “just sign off” on a compliance review without performing tests.

    • Threat: Familiarity and intimidation threats.
    • Response: Declare conflict of interest to CAE, recuse oneself from this engagement, follow formal channels.
  3. Internal audit is instructed by the CFO not to report a significant control weakness in the revenue cycle to the audit committee.

    • Threat: Management interference with scope and reporting.
    • Response: CAE must report impairment to the audit committee and, if unresolved, escalate as per Standard 2600.

2.5.2 Exam Answer Tips

When asked to address ethics or independence:

  • Refer to Code of Ethics principles (Integrity, Objectivity, Confidentiality, Competency).
  • Mention relevant Standards:
    • 1100 (Independence and Objectivity)
    • 1130 (Impairment to Independence or Objectivity)
  • Propose practical remedial actions, such as:
    • Reassignment of auditor
    • Disclosure of impairment to CAE and/or audit committee
    • Implementation of rotation policies
    • Enhanced conflict‑of‑interest declarations

3. Internal Control, Risk Management and Governance (TUT Focus with UNISA/CUT Linkages)

3.1 Internal Control: Concepts and Components

Internal control is a central theme in IAU216D. A widely used framework is COSO Internal Control – Integrated Framework.

3.1.1 Definition of Internal Control (COSO)

Internal control is:

“A process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories:

  • Effectiveness and efficiency of operations
  • Reliability of financial reporting
  • Compliance with applicable laws and regulations.”

Key points:

  • Process – not a single event or policy.
  • Effected by people – not just manuals or systems.
  • Reasonable assurance – not absolute; there are limitations.
  • Objectives – operations, reporting, compliance.

3.1.2 COSO Components

  1. Control Environment

    • Tone at the top, integrity and ethical values, competence, board/audit committee effectiveness, organisational structure, HR policies.
  2. Risk Assessment

    • Identification and analysis of relevant risks to achieving objectives, basis for determining how risks should be managed.
  3. Control Activities

    • Policies and procedures that ensure management directives are carried out.
    • Examples: authorisations, verifications, reconciliations, segregation of duties, physical controls, IT controls.
  4. Information and Communication

    • Systems and processes that capture and communicate information in a form and timeframe that enable people to carry out responsibilities.
  5. Monitoring Activities

    • Ongoing evaluations, separate evaluations, or some combination, to ensure internal controls are present and functioning.

In exams, you may be asked to describe each component and give examples in a particular organisational context (e.g. a retail store or municipality).

3.2 Types of Internal Controls

Internal controls can be classified in various ways. Exams frequently ask you to categorise and provide examples.

3.2.1 By Objective

  • Preventive controls

    • Aim to prevent errors or irregularities from occurring.
    • Examples: segregation of duties, access controls, pre‑approval of transactions.
  • Detective controls

    • Detect errors or irregularities that have already occurred.
    • Examples: bank reconciliations, monthly variance analyses, internal audit reviews.
  • Corrective controls

    • Correct errors or irregularities once detected.
    • Examples: backup data restoration, changes to policies, disciplinary action.

3.2.2 By Nature

  • Manual controls
    • Performed by people (e.g. review and sign‑off of reconciliations).
  • Automated controls
    • Performed by IT systems (e.g. system‑calculated credit limits).
  • IT‑dependent manual controls
    • Require both people and systems (e.g. manager reviews automated exception report).

3.3 Risk Management and Risk‑Based Internal Auditing

Risk‑based internal auditing aligns internal audit activities with the organisation’s risk profile. It is a major focus in IAU216D and parallel modules such as UNISA AUI2601.

3.3.1 Risk Management Process

Many organisations use frameworks such as COSO Enterprise Risk Management or ISO 31000. A simplified risk management process includes:

  1. Establish context

    • Understand organisational objectives, internal and external environment.
  2. Risk identification

    • Identify events that could affect achievement of objectives (positive or negative).
  3. Risk analysis

    • Assess likelihood and impact (inherent and residual).
  4. Risk response

    • Decide to accept, avoid, reduce, or transfer risks.
  5. Risk monitoring and reporting

    • Track risk indicators, audit results, and changes in risk profile.

3.3.2 Role of Internal Audit in Risk Management

According to the IIA:

  • Assurance role:
    • Evaluate the effectiveness of risk management processes.
    • Assess risk identification, assessment, and response activities.
  • Consulting role (provided safeguards for independence are maintained):
    • Facilitate risk assessment workshops.
    • Advise on development of a risk management framework.

Internal audit should not take ownership of risk management decisions, as this would impair independence.

3.4 Governance and the Role of Internal Audit

Governance in South Africa is strongly influenced by the King IV Report on Corporate Governance. In IAU216D, exams may expect you to:

  • Explain corporate governance as the system by which organisations are directed and controlled.
  • Identify key governance structures:
    • Board of directors
    • Audit committee
    • Risk committee
    • Internal audit
    • External audit
    • Management

Internal audit’s governance role includes:

  • Evaluating whether organisational ethics, values, and governance processes are effective.
  • Assessing whether IT governance supports organisational strategies.
  • Ensuring that information used for decision‑making is reliable and timely.

3.5 Case Study Example: Risk and Control at a South African Retailer

Consider a hypothetical retailer, Mzansi Superstores (Pty) Ltd, with stores across Gauteng and a head office in Pretoria. The TUT IAU216D exam could present a scenario based on Mzansi Superstores and require you to:

  1. Identify major risks

    • Theft of cash and inventory
    • Incorrect pricing leading to loss of revenue
    • Non‑compliance with VAT regulations
    • IT system downtime affecting sales
    • Fraudulent returns
  2. Relate risks to internal controls

    • For theft:
      • CCTV cameras (detective)
      • Security guards (preventive)
      • Inventory reconciliations (detective)
    • For incorrect pricing:
      • Price master file approvals (preventive)
      • Price change authorisation procedures (preventive)
      • Daily sales exception reports (detective)
  3. Evaluate control weaknesses

    • Example: Same person who sets prices in the system also approves discounts and reconciles sales.
      • Weakness: Poor segregation of duties.
      • Risk: Fraudulent pricing or discounts leading to revenue loss.
  4. Recommend improvements

    • Segregate pricing setup from discount approval.
    • Implement automated approval workflows for price changes.
    • Enhance monitoring of high‑risk items (e.g. electronics).

By walking through this logic, you practice both risk and control evaluation, which will feature in IAU216D and in modules like UNISA AUE2602 and CUT equivalents.

4. The Internal Audit Process: Planning, Fieldwork and Evidence

4.1 Overview of the Internal Audit Engagement Life Cycle

Most Internal Auditing II courses structure the audit engagement life cycle into four main phases:

  1. Planning the Engagement
  2. Performing the Engagement (Fieldwork / Execution)
  3. Communicating Results (Reporting)
  4. Follow‑up

Each phase links to relevant IIA Standards.

4.2 Engagement Planning

4.2.1 Objectives of Planning

The planning phase aims to:

  • Ensure the engagement addresses relevant risks and adds value.
  • Define scope, objectives, and resources.
  • Understand the business processes and internal controls.
  • Design audit procedures that will obtain sufficient and appropriate evidence.

4.2.2 Pre‑engagement Activities

Before detailed planning, the CAE and internal audit team should:

  • Confirm the engagement from the approved risk‑based audit plan (Standard 2010).
  • Communicate with the auditee (e.g. send an engagement notification letter).
  • Review prior audit reports, management letters, and external audit findings.
  • Identify any independence or objectivity issues (Standard 1130).

4.2.3 Understanding the Process and Environment

To properly plan, internal auditors gather background information:

  • Organisational structure and reporting lines
  • Policies and procedures relevant to the area audited
  • Information systems and technology used
  • Key performance indicators (KPIs) and management reports
  • Regulatory and compliance requirements

Techniques include:

  • Interviews with process owners
  • Walkthroughs of transactions
  • Observation of operations
  • Review of process flowcharts and narratives

4.2.4 Defining Engagement Objectives and Scope

Examples of engagement objectives:

  • Evaluate adequacy and effectiveness of internal controls over the procurement and payment cycle.
  • Assess whether the inventory management process ensures reliable stock records and prevents losses.
  • Review compliance with PFMA/MFMA in a provincial government department.

Scope defines:

  • Processes to be covered (e.g. purchase requisitions, orders, receiving, invoices, payments).
  • Locations and periods (e.g. all branches or selected sample branches; transactions for the last financial year).
  • Exclusions, if any (e.g. contract management may be covered in a separate audit).

In exams, you may be asked to draft objectives and scope for a given case study.

4.2.5 Risk and Control Assessment in Planning

Planning includes:

  • Identifying risks related to the engagement objectives.
  • Identifying key controls that management has put in place.
  • Assessing inherent and control risk to determine where to focus testing.

Example for receivables:

  • Risks:

    • Sales recorded but goods not delivered (overstated revenue).
    • Unauthorised credit sales to customers with poor credit ratings.
    • Failure to write off bad debts timeously.
  • Key controls:

    • Credit checks and approvals.
    • Separation of duties between credit approval, invoicing, and cash receipts.
    • Periodic review of ageing analysis and allowance for doubtful debts.

The auditor uses this to design a risk‑based programme.

4.2.6 Developing the Audit Programme

An audit programme or engagement work programme lists, for each objective:

  • Audit procedures to be performed
  • Nature, timing, and extent of tests
  • Responsible auditor
  • Referenced working papers for documentation

Example snippet of an audit programme for credit sales:

Objective Procedure Nature Extent
Confirm that all credit sales are authorised Select a sample of credit sales and inspect credit approval documentation Test of control 25 new customers and 25 limit changes
Ensure invoices are accurate Recalculate invoice totals and compare to price list and delivery notes Substantive test 30 invoices

Exams may ask you to outline or design an audit programme for a specific cycle (purchases, payroll, inventory, etc.).

4.3 Performing the Engagement: Fieldwork and Testing

4.3.1 Types of Audit Procedures

Common procedures taught in IAU216D, UNISA AUE2602, and CUT modules:

  • Inquiry
    • Asking questions of knowledgeable persons inside or outside the entity.
  • Observation
    • Watching processes (e.g. stock counts).
  • Inspection
    • Examining records or tangible assets.
  • Recalculation
    • Checking mathematical accuracy (e.g. payroll calculations).
  • Reperformance
    • Independently executing procedures that were originally performed by client staff.
  • Analytical procedures
    • Analysing relationships among data (trends, ratios, comparisons).

4.3.2 Tests of Controls vs Substantive Tests

  • Tests of Controls

    • Aim to evaluate the design and operating effectiveness of controls.
    • Example: Check if orders over a certain amount have authorized signatures.
  • Substantive Tests

    • Aim to detect material misstatements or irregularities in account balances or transactions.
    • Example: Confirm receivable balances with customers.

Risk‑based internal auditing balances both, depending on assessment of control effectiveness.

4.3.3 Sampling

Although detailed sampling theory might be covered more deeply in later modules, IAU216D requires basic understanding:

  • Why sample?
    • Time and resource constraints mean not every transaction can be tested.
  • Sampling approaches:
    • Random sampling – each item has an equal chance of selection.
    • Judgemental sampling – auditor selects items based on professional judgement (e.g. high‑value items, unusual transactions).

In exam answers:

  • Explain that sampling must be representative of the population.
  • Justify choice of sampling method for a given scenario.

4.4 Audit Evidence: Sufficiency and Appropriateness

4.4.1 Characteristics of Good Audit Evidence

The IIA Standards require internal auditors to obtain sufficient and appropriate evidence.

  • Sufficiency

    • Quantity of evidence; influenced by risk of misstatement and quality of controls.
  • Appropriateness

    • Quality, relevance, and reliability of evidence.

Evidence is more reliable when:

  • Obtained from independent external sources.
  • Generated by effective internal controls.
  • Obtained directly by the auditor (e.g. observation, reperformance).
  • In documentary form rather than oral.
  • Original documents rather than copies.

4.4.2 Types of Evidence with Examples

  • Physical evidence
    • Observing inventory in warehouses.
  • Documentary evidence
    • Invoices, contracts, policies, minutes of meetings.
  • Analytical evidence
    • Ratio analysis, trend analysis.
  • Oral evidence
    • Explanations from staff members.
  • Electronic evidence
    • Logs, databases, system configurations.

Exams may present specific evidence and ask you to comment on its reliability or evaluate whether it is sufficient and appropriate.

4.5 Working Papers and Documentation

4.5.1 Purpose of Working Papers

Working papers are the audit records that:

  • Support the conclusions and report.
  • Demonstrate compliance with the IIA Standards.
  • Provide evidence of planning, performance, and supervision.
  • Facilitate reviews by supervisors and external quality assessors.

4.5.2 Content and Structure

Good working papers include:

  • Heading
    • Client/area, title, period, working paper reference, preparer, date, reviewer, and review date.
  • Objective
    • Specific objective of tests documented in the working paper.
  • Procedures performed
    • Step‑by‑step details of what was done.
  • Results
    • Observations, exceptions, and supporting details.
  • Conclusion
    • Overall assessment regarding the objective.

Example of a simple working paper entry:

Objective: To determine whether all purchases above R50 000 were properly authorised.
Procedures performed: Selected a random sample of 30 purchase orders above R50 000 from the financial year 2025. Inspected each purchase order for evidence of approval by the Procurement Manager or higher authority as per policy FIN‑PROC‑001.
Results: 28 out of 30 purchase orders had proper approvals. Two purchase orders (PO 4567 and PO 4821) for amounts of R65 000 and R72 000 respectively had no evidence of approval.
Conclusion: Control is generally effective, but exceptions indicate non‑compliance with the approval policy. Further investigation and recommendation required.

Exams may ask you to prepare or critique working paper content.

4.5.3 Review and Supervision

Standard 2340 requires that engagements are properly supervised. Supervisory review ensures:

  • Objectives are met.
  • Work is properly documented.
  • Conclusions are supported by evidence.
  • Internal audit methodology is followed.

Review notes should be documented and cleared by staff.

4.6 Example: Planning and Performing a Payroll Audit

To consolidate the audit process concepts, consider a payroll audit at a medium‑sized company in Pretoria employing 500 staff.

  1. Planning

    • Obtain payroll policies, organisational chart, previous payroll audit reports.
    • Understand payroll cycle: hiring, time recording, payroll processing, payment, and post‑payroll analysis.
    • Identify risks:
      • Ghost employees.
      • Incorrect pay rates or overtime calculations.
      • Unauthorised changes to bank details.
    • Define objectives and scope:
      • Evaluate effectiveness of controls to prevent and detect payroll fraud and errors for the period 1 Jan to 31 Dec 2025.
    • Develop audit programme:
      • Test controls over master file changes.
      • Reperform payroll calculations for sample employees.
      • Analytical review of overtime and allowances.
  2. Fieldwork

    • Conduct interviews with HR and payroll staff.
    • Inspect HR files for documentation supporting employment of selected employees.
    • Observe payroll run processes.
    • Recalculate salary for selected employees and compare to employment contracts.
    • Perform data analytics to identify duplicate bank accounts, unusual overtime.
  3. Evidence and Documentation

    • Maintain detailed working papers for each procedure.
    • Document exceptions, such as employees paid without contracts or suspicious bank account patterns.
  4. Conclusion

    • Assess whether evidence supports the conclusion that payroll controls are adequate and effective.
    • Prepare findings and recommendations for inclusion in the audit report (discussed in the next section).

5. Reporting, Follow‑up, and Exam‑Focused Application (Case Scenarios, UNISA/CUT Comparisons)

5.1 Communicating Results: Structure and Content of Internal Audit Reports

IIA Standard 2400 requires internal auditors to communicate engagement results. Internal audit reports must be:

  • Accurate
  • Objective
  • Clear
  • Concise
  • Constructive
  • Complete
  • Timely

5.1.1 Typical Internal Audit Report Structure

Internal audit reports at TUT‑type settings and in South African organisations often follow a template along these lines:

  1. Cover Page

    • Title (e.g. “Internal Audit Report: Procurement and Payments Process – April 2025”)
    • Organisation name
    • Date
    • Prepared by and approved by
  2. Executive Summary

    • Overall conclusion (e.g. “Satisfactory”, “Needs Improvement”, “Unsatisfactory”).
    • Key high‑risk findings and overall control rating.
    • Summary of management’s commitment to corrective actions.
  3. Background

    • Brief description of the area audited, its importance, and context.
    • Objectives and scope of the engagement.
    • Period covered.
  4. Objectives, Scope and Methodology

    • Detailed engagement objectives.
    • Scope boundaries (processes, locations, time period).
    • Methods used (interviews, document reviews, testing, data analytics, etc.).
  5. Detailed Findings and Recommendations

    • For each finding:
      • Condition – what is the problem?
      • Criteria – what should be happening (policy, regulation, best practice)?
      • Cause – why did the problem occur?
      • Effect – impact or potential impact (financial, compliance, reputational).
      • Recommendation – what should be done to fix it?
      • Management response – agreed action, responsible person, due date.
  6. Conclusion

    • Overall assessment of control and risk management in the area.
    • Any qualifications or limitations.

5.2 Writing Audit Findings Using the 5Cs

Many IAU216D exam questions require you to formulate audit findings based on a scenario. The 5Cs structure (Condition, Criteria, Cause, Consequence, Corrective action) is a helpful framework.

5.2.1 Example Finding: Procurement Authorisation Weakness

Condition:
During testing of 30 purchase transactions above R50 000, it was found that 8 purchase orders were processed and paid without the required approval from the Procurement Manager or higher authority as per company policy.

Criteria:
Policy FIN‑PROC‑001 requires that all purchases exceeding R50 000 must be authorised by the Procurement Manager or, in his/her absence, the Finance Director.

Cause:
The procurement system does not enforce approval limits automatically, and staff are able to override the system by manually processing purchase orders.

Consequence (Effect):
There is an increased risk of unauthorised or fraudulent purchases, potentially leading to financial losses and non‑compliance with internal procurement policies.

Corrective Action (Recommendation):
It is recommended that system‑based approval workflows be implemented to enforce authorisation levels. In the interim, management should introduce additional monitoring controls to review all purchases above R50 000 for proper authorisation.

Examiners at TUT, UNISA and CUT award marks for:

  • Correct identification of each component.
  • Relevance to the given scenario.
  • Clear, concise language.

5.3 Follow‑up (Monitoring Progress)

IIA Standard 2500 requires the CAE to monitor the disposition of audit results to ensure management has implemented agreed‑upon actions or that senior management has accepted the risk.

5.3.1 Follow‑up Activities

  • Maintain a register of findings and recommendations, indicating:
    • Priority (e.g. High/Medium/Low).
    • Responsible manager.
    • Agreed implementation date.
  • Periodically obtain updates from management:
    • Status (implemented, in progress, not implemented).
    • Evidence of implementation (revised procedures, system changes, training records).
  • Perform limited testing to confirm implementation for high‑risk findings.
  • Report outstanding high‑risk items to the audit committee.

Exams might ask:

  • “Explain the importance of follow‑up in the internal audit process.”
  • “Describe the steps internal auditors should take to follow up on audit recommendations.”

5.4 Integrated Case Study: Complete Internal Audit Cycle (Exam‑Style)

To consolidate your understanding for IAU216D and similar modules like UNISA AUE2602 Internal Auditing and CUT Internal Auditing II, consider an integrated case.

5.4.1 Scenario: City of Tshwane Water Billing Department

The City of Tshwane Water Billing Department has been receiving complaints from residents about incorrect water bills, delayed adjustments, and poor customer service. The internal audit unit of the City must conduct an internal audit of the water billing process.

Exam‑style questions may include:

  1. Identify and explain FIVE key risks in the water billing process.
  2. Propose internal controls to mitigate these risks.
  3. Outline the audit objectives, scope and procedures for this audit.
  4. Draft TWO audit findings and recommendations based on hypothetical control weaknesses.

5.4.2 Sample Answer Elements

  1. Key Risks

    • Incorrect meter readings lead to over‑ or under‑billing.
    • Delayed processing of meter reading data causes late bills.
    • Fraudulent adjustments to customer accounts (e.g. unauthorised write‑offs).
    • Poor data integrity in billing system leading to duplicate or missing accounts.
    • Non‑compliance with municipal regulations regarding tariffs and debt collection.
  2. Controls

    • Meter reading:
      • Use of digital meter reading devices with GPS tagging.
      • Regular training and supervision of meter readers.
    • Data processing:
      • Automated validation controls (e.g. flagging abnormal consumption patterns).
      • Segregation of duties between data capture and billing approval.
    • Adjustments:
      • Authorisation of adjustments above a set threshold by senior management.
      • System logs and periodic management review of adjustment reports.
    • Data integrity:
      • Regular data cleansing and reconciliation of billing system to customer master records.
  3. Audit Objectives, Scope and Procedures

    • Objectives:
      • Evaluate the adequacy and effectiveness of controls over water meter reading, billing, and account adjustments.
      • Assess whether billing is accurate, complete, and timely, and complies with municipal by‑laws and policies.
    • Scope:
      • Period: 1 July 2024 to 30 June 2025.
      • Processes: meter reading, data capture, bill generation, adjustments, and customer complaints handling.
    • Procedures:
      • Interviews with relevant staff (meter readers, billing clerks, supervisors).
      • Walkthroughs of meter reading and billing cycles.
      • Sample testing of bills and adjustments.
      • Analytical procedures (e.g. analysing consumption trends, ageing of receivables).
  4. Example Finding (Billing Accuracy)

    • Condition: In a sample of 40 water bills, 7 were found to contain meter readings that did not match the physical meter readings recorded on site visits.
    • Criteria: Municipal billing policy requires that actual meter readings be used wherever meters are accessible, and that estimated readings be clearly indicated and supported by calculation methodology.
    • Cause: Meter readers are under pressure to meet daily targets and sometimes estimate readings instead of physically reading the meters. There is no independent verification of extreme readings.
    • Effect: Risk of incorrect billing, reputational damage, customer complaints, and potential revenue loss for the municipality.
    • Recommendation: Introduce stricter supervision and quality checks, such as random verification of readings, and adjust meter readers’ performance targets to emphasise accuracy as well as volume.

This style of answer uses the concepts learned across the entire IAU216D syllabus and shows the examiner your ability to apply theory in a realistic public‑sector context.

5.5 Cross‑University Keyword and Exam Alignment

While this guide is focused on Tshwane University of Technology (TUT): National Diploma: Internal Auditing – IAU216D Internal Auditing II, similar topics appear in:

  • UNISA AUE2602 / AUI2601 Internal Auditing modules
  • Central University of Technology (CUT) Internal Auditing II (e.g. AUD206, AUD216)
  • Other South African qualifications in internal auditing, including BCom in Internal Auditing and diplomas at universities of technology.

Common search terms and topic clusters include:

  • “IAU216D exam pack TUT”
  • “Internal Auditing II past papers and memos”
  • “UNISA AUE2602 study notes pdf”
  • “UNISA AUI2601 risk‑based internal audit”
  • “CUT Internal Auditing II past exam questions”

For all these modules, students are expected to demonstrate:

  • Understanding of the IIA IPPF and Standards.
  • Ability to describe and perform the internal audit process from planning to follow‑up.
  • Knowledge of risk, control, and governance.
  • Skills in collecting and evaluating audit evidence.
  • Competence in writing clear audit findings, recommendations, and reports.

5.6 Exam Technique and Time Management for IAU216D

To maximise marks in the IAU216D: Internal Auditing II exam:

  1. Analyse the mark allocation

    • If a question is worth 10 marks, aim for at least 10 quality points or fewer but well‑developed points with explanations and examples.
  2. Use headings and bullet points

    • Clearly label sections like “Definitions”, “Advantages”, “Disadvantages”, “Recommendations”.
    • This mirrors how internal audit reports are structured and makes it easier for markers.
  3. Answer the question asked

    • If the question says “Explain SIX benefits of risk‑based internal audit planning”, do not write generic definitions of risk or internal control.
    • Tailor your answer to the exact wording.
  4. Incorporate examples

    • Where possible, include short, relevant examples from public sector, retail, manufacturing, or service industries to demonstrate application.
  5. Link to the IPPF and Standards where appropriate

    • Mention specific standards (e.g. 2010, 2200, 2400) when discussing planning or reporting.
    • Refer to the Code of Ethics for ethics/independence questions.
  6. Use professional language

    • Write as if you are an internal auditor preparing a report for management or the audit committee.
    • Avoid slang; use terms like “engagement”, “control activities”, “assurance”, “due professional care”.
  7. Plan before you write

    • For longer questions, spend 3–5 minutes planning your structure (headings, subheadings, bullet points) before writing full answers.

5.7 Summary and Final Revision Checklist

For IAU216D: Internal Auditing II (TUT), make sure you can confidently do the following before walking into the exam:

  • IPPF and Standards

    • State the definition of internal auditing.
    • List and explain the IIA Code of Ethics principles.
    • Distinguish between attribute and performance standards and cite key standards (1000, 1100, 1220, 2010, 2200, 2400, 2500, 2600).
  • Internal Audit Function

    • Describe how the internal audit activity should be positioned to ensure independence and objectivity.
    • Explain the difference between internal and external audit.
  • Risk and Control

    • Define risk and internal control.
    • Explain the COSO internal control components and provide practical examples.
    • Describe risk‑based internal auditing and internal audit’s role in risk management.
  • Internal Audit Process

    • Outline each stage: planning, fieldwork, reporting, follow‑up.
    • Draft a simple engagement objective, scope and audit programme for a common business cycle (e.g. purchases, payroll, inventory).
  • Audit Evidence and Working Papers

    • Define sufficient and appropriate evidence.
    • Identify strengths and weaknesses in different types of evidence.
    • Prepare and evaluate basic working paper content.
  • Reporting and Findings

    • Structure an internal audit report (executive summary, objectives, detailed findings, recommendations).
    • Draft clear findings using the 5Cs: condition, criteria, cause, consequence, corrective action.

Working systematically through this checklist and practicing with past papers from TUT (IAU216D), as well as similar questions from UNISA AUE2602/AUI2601 and CUT Internal Auditing II, will help you convert your theoretical knowledge into exam‑ready skills and, later, into professional internal audit practice in South Africa.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare