modern auditing

Reference

Glossary

33 terms, defined the way a practitioner would explain them to a colleague — including the ones that mostly exist to be sold.

Where a term is contested or has been stretched by marketing, the entry says so. Where a term is genuinely useful, the entry says what it costs to actually do.

Practice

  • Continuous auditing

    Assurance performed on a short, repeating cycle rather than annually — testing that re-runs as a definition instead of being rebuilt as a project each period.

  • Continuous controls monitoring (CCM)

    Also: CCM, continuous monitoring

    Management's own automated, ongoing surveillance of whether its controls are operating — a first- and second-line activity, not an audit one.

  • IPE

    Also: information produced by the entity, IPE testing

    Reports and data generated by the organisation being audited, which must be tested for completeness and accuracy before they can be relied on as evidence.

  • Key control

    Also: key controls

    A control relied on to address a risk to the point that its failure would, on its own, mean the risk is not adequately mitigated.

  • Material weakness

    Also: significant deficiency, control deficiency

    The most severe classification of internal control deficiency — one where there is a reasonable possibility that a material misstatement would not be prevented or detected on a timely basis.

  • PBC list

    Also: prepared by client list, evidence request list

    The list of documents an auditor asks the business to produce — an artifact that exists only because auditors historically could not reach the systems themselves.

  • Population testing

    Also: full-population testing, 100% testing

    Testing every item in a population rather than a sample, which becomes the default once tests are executed by software against the system of record.

  • Sampling

    Also: audit sampling, statistical sampling

    Selecting a subset of a population to test, using the result to infer a conclusion about the whole — a workaround for human throughput that automation makes largely unnecessary.

  • Test of design (ToD)

    Also: ToD, design effectiveness

    An assessment of whether a control, if it operated as described, would actually prevent or detect the failure it is meant to address.

  • Test of operating effectiveness (ToE)

    Also: ToE, operating effectiveness

    Evidence that a control actually operated as designed, at the required frequency, throughout the period — by whom, how consistently, and with what result.

  • Walkthrough

    Tracing a single transaction end-to-end through a process to confirm the process works the way it is documented and the controls sit where they are said to sit.

  • Workpaper

    Also: working paper, audit documentation

    The record of what was tested, how, and what was concluded — and, structurally, the single biggest determinant of whether audit work can be automated or re-run.

Technology

  • Agent-native GRC

    Also: agent-native governance, risk and compliance

    Governance, risk and compliance software designed from the data model up so that software agents can do the work, with human approval built into the record rather than bolted on afterwards.

  • Agentic AI

    Also: AI agents, autonomous agents

    AI systems that plan and carry out multi-step work using tools, rather than only producing text in response to a prompt.

  • Approval gate

    Also: human-in-the-loop gate, HITL gate

    A required, recorded human decision that stands between machine-performed work and the audit record.

  • Audit analytics

    Also: data analytics in audit, CAATs

    Applying queries, statistics and visualisation to full datasets to identify exceptions, patterns and risk — the bridge between sampling and genuinely continuous assurance.

  • Model Context Protocol (MCP)

    Also: MCP

    An open protocol that lets an AI assistant discover and call the tools and data a system exposes — increasingly how audit systems make themselves usable by agents.

  • Supervised autonomy

    Also: human-in-the-loop autonomy

    An operating model where software agents execute audit work end-to-end but no conclusion becomes part of the record until a named human approves it.

Frameworks & standards

  • Control crosswalk

    Also: control mapping, framework mapping

    A mapping between the requirements of different frameworks, showing where one control satisfies obligations under several at once.

  • COSO Internal Control Framework

    Also: COSO IC, COSO 2013

    The internal control framework used by the overwhelming majority of SOX programmes, structured as five components and seventeen principles.

  • EU AI Act

    Also: Artificial Intelligence Act, Regulation (EU) 2024/1689

    The EU's risk-tiered regulation of AI systems, imposing obligations that scale from transparency duties to extensive conformity requirements for high-risk uses.

  • ISO/IEC 27001

    Also: ISO 27001, ISMS

    The international standard for an information security management system, certified against by an accredited body, with 93 Annex A controls in the 2022 revision.

  • ISO/IEC 42001

    Also: AI management system, AIMS

    The international standard for an artificial intelligence management system — the certifiable counterpart to ISO 27001 for organisations building or deploying AI.

  • ITGC

    Also: IT general controls

    The controls over the IT environment that financial and operational controls depend on — access, change management, and operations — and the most commonly failed area in SOX programmes.

  • NIST Cybersecurity Framework 2.0

    Also: NIST CSF, CSF 2.0

    A voluntary framework organising cybersecurity outcomes into six functions — Govern, Identify, Protect, Detect, Respond, Recover — widely used as a common language between technical and board audiences.

  • SOC 2

    Also: SOC 2 Type II, Trust Services Criteria

    An AICPA attestation report on a service organisation's controls against the Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy.

  • SOX 404

    Also: Section 404, ICFR

    The Sarbanes-Oxley requirement that management assess, and (for accelerated filers) the external auditor attest to, the effectiveness of internal control over financial reporting.

  • Unified control

    Also: common control, harmonised control

    A single control definition satisfying requirements from several frameworks at once, so one test produces evidence for many obligations.

Governance

  • Audit universe

    Also: auditable universe

    The full inventory of entities, processes, systems and risks that could be audited, from which the annual plan is selected.

  • QAIP

    Also: quality assurance and improvement program

    The IIA-required programme of internal and external assessments covering whether an internal audit function conforms to the Standards and operates effectively.

  • Risk appetite

    Also: risk tolerance

    The amount and type of risk an organisation is willing to accept in pursuit of its objectives — and, when expressed properly, the input that sets audit cadence.

  • Three Lines Model

    Also: three lines of defence, 3LOD

    The IIA's model distinguishing management's ownership of risk (first line), its oversight functions (second line), and internal audit's independent assurance (third line).

Roles

  • Chief Audit Executive (CAE)

    Also: CAE, head of internal audit

    The person with overall responsibility for the internal audit function, reporting functionally to the board or audit committee and administratively to management.