| Title | Internal Auditor |
|---|---|
| Department | Internal Audit |
| Reports to | [Internal Audit Manager / Director of Internal Audit / Chief Audit Executive] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Internal Auditor provides independent, objective assurance over [Company]'s governance, risk management, and control processes. The role plans and executes audits, tests controls, evaluates findings, and reports results that help management strengthen the control environment.
The Internal Auditor works across finance, operations, technology, and compliance to assess whether controls are designed and operating effectively, whether risks are managed, and whether processes meet policy and regulatory requirements. As AI and automated systems become part of operations, auditors increasingly assess the controls around them.
This role suits a disciplined, objective professional who is skilled in testing, documentation, and communicating findings with evidence and independence.
Key responsibilities
Audit planning
- Support risk-based audit planning and scoping.
- Develop audit programs, objectives, and test steps.
- Identify key risks and controls for each engagement.
- Coordinate timing and resources with stakeholders.
Fieldwork and testing
Execute audit fieldwork with rigor and independence:
- Perform walkthroughs and test control design and operation.
- Gather and document evidence in clear workpapers.
- Evaluate exceptions and determine root causes.
- Assess process, financial, operational, and technology controls.
SOX and controls assurance
- Support SOX testing of internal control over financial reporting.
- Evaluate control gaps and deficiencies.
- Test IT general controls and application controls.
- Track remediation of identified control issues.
Findings and reporting
Document findings, risks, and recommendations clearly, discuss results with management, and prepare audit reports supported by evidence.
Technology and AI audits
Support audits of technology, data, and increasingly AI and automated systems, assessing governance, controls, and alignment with frameworks such as the NIST AI RMF where relevant.
Follow-up and standards
Track management action plans to closure, and perform work in line with the IIA International Professional Practices Framework and applicable standards.
Required qualifications
- Bachelor's degree in Accounting, Finance, Information Systems, Business, or a related field.
- 3 to 6+ years of internal or external audit experience.
- Knowledge of the IIA Standards, COSO, and internal control concepts.
- Experience with control testing, SOX, or IT audit.
- Strong analytical, documentation, and workpaper skills.
- Ability to communicate findings clearly and maintain independence.
Preferred certifications
One or more of: CIA, CISA, CPA, CFE, CRMA, depending on audit focus.
Technical knowledge
Internal audit, risk-based audit planning, control design and operating effectiveness testing, SOX and internal control over financial reporting, IT general and application controls, data analytics, workpaper documentation, and audits of technology and AI systems.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in internal audit and controls assurance rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does an Internal Auditor do?
An Internal Auditor provides independent assurance over an organization's controls, risks, and processes. They plan and execute audits, test controls, document evidence, and report findings and recommendations that help management strengthen the control environment.
What qualifications and certifications does an Internal Auditor need?
Most Internal Auditors have a bachelor's degree in accounting, finance, or information systems and 3 to 6 or more years of audit experience. Common certifications include the CIA, CISA, and CPA, plus CFE or CRMA depending on focus.
Who does an Internal Auditor report to?
An Internal Auditor typically reports to an Internal Audit Manager, a Director of Internal Audit, or the Chief Audit Executive, and internal audit generally maintains a reporting line to the Audit Committee.
What frameworks and standards does an Internal Auditor use?
Internal auditors work under the IIA International Professional Practices Framework and IIA Standards, use COSO for internal control, and reference the NIST Cybersecurity Framework and SOX requirements, with growing attention to AI system controls.