What it means
The job is part detective, part diplomat. An internal auditor plans a review, gathers evidence by testing samples of real transactions, works out what the evidence means, then has to persuade busy managers to accept and act on findings they would often rather not hear.
Qualifications vary more than people expect. Many internal auditors hold an accounting or internal audit qualification, but larger teams increasingly include IT specialists, data analysts and people with operational backgrounds in areas such as supply chain or clinical services.
Independence and objectivity are the professional obligations that define the role. An internal auditor should not review a process they recently ran, should declare conflicts, and should have the standing to escalate a serious finding to the audit committee even when senior management would prefer it stayed quiet.
Day to day, the work is evidence-driven rather than opinion-driven. Instead of asking whether a control exists, the auditor pulls a sample of transactions and tests whether it was actually applied every time, then quantifies the exposure created by the exceptions found.
The economics of the role are usually measured in productive days. Because a salaried auditor is available for a limited number of working days once holidays, training and administration are removed, planning a realistic annual audit plan means knowing the true cost and capacity of each auditor.
Communication skills matter as much as technical ones. A finding that is technically correct but written as an accusation gets argued about rather than fixed, so experienced auditors describe the exposure, quantify it where they can, and let the manager own the solution.
The measure of a good internal auditor is how many agreed actions are actually completed, not how many issues were raised.
In practice
Real-world examples.
Example
An internal auditor at an insurance company samples 60 claims settled above $10,000 and finds four settled without the required second signature. The exposure is quantified at $180,000 and the claims system is reconfigured to block single-approver settlements. The report is rated high risk and goes to the audit committee with a named owner and a six-week deadline.
Example
A hospital's internal auditor reviews controlled drug records across three wards, testing physical counts against the register. Two discrepancies lead to a change in the handover procedure rather than to disciplinary action, because the root cause was a badly designed form.
Example
A manufacturer's IT-focused internal auditor reviews user access and finds 47 active accounts belonging to people who left the business. The finding is rated high risk, and leaver notifications are automated within the quarter.
Formula
Calculation
Fully loaded cost per productive audit day = (Salary x (1 + Overhead rate)) / Productive days available
An internal auditor is paid $95,000 a year, and the employer adds 40% for pension, benefits, software and office costs, giving a fully loaded cost of $95,000 x 1.40 = $133,000. From 260 working days, subtract 25 days of leave, 15 days of training and 20 days of administration, leaving 200 productive days. The cost per productive day is $133,000 / 200 = $665. A review budgeted at 24 days therefore costs 24 x $665 = $15,960, which the audit committee can weigh against the risk being examined.Case study
Seen in the real world.
Merrow Retail Holdings is a fictional company invented for this illustrative example. Its sole internal auditor was, on paper, responsible for reviewing 22 stores, three warehouses and the head office functions, and she was quietly drowning.
She rebuilt her plan around capacity rather than ambition. With 200 productive days at a fully loaded cost of $665 each, she had roughly $133,000 of audit capacity, and she allocated it by risk: 70 days to stock and cash handling, 45 days to payroll and supplier payments, 40 days to IT access, and the rest to follow-up work.
The audit committee accepted that eleven stores would not be visited that year, which felt uncomfortable but was at least honest. Two of the reviews she did run found a stock loss pattern worth $260,000 a year. The illustrative lesson is that an internal auditor who spreads themselves evenly finds nothing, while one who follows the risk finds what matters.
Watch out
Common mistakes.
- Asking the internal auditor to fix the process they have just criticised, which quietly turns an independent reviewer into a member of management.
- Expecting an internal auditor to detect all fraud, when reviews are based on samples and reasonable assurance rather than on checking every transaction.
- Judging performance by how many findings are raised, which rewards nitpicking over identifying the few issues that actually threaten the business.
Questions
People also ask.
Does an internal auditor need to be a qualified accountant?
Not necessarily, since many hold internal audit, IT or data qualifications instead, depending on what the team reviews.
Who does an internal auditor report to?
Functionally to the audit committee for independence, and administratively to a senior executive for day-to-day management.
Can one person be both internal auditor and financial controller?
In a very small business it happens, but it removes independence and should be disclosed to the board.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%