Skip to main content

Bring Internal Audit in Earlier—With Boundaries

Share

Internal audit can be easy to miscast: the team that arrives late, asks for evidence at the worst possible time, and leaves behind a list of findings. When that happens, the relationship becomes defensive—and the institution loses a chance to use audit insight earlier in the risk cycle. 

In a recent ProSight webinar, Janice E. Harden, senior manager at Wipfli Advisory LLC, explained how financial institutions can bring internal audit into risk conversations earlier while preserving the independence that makes audit valuable. 

Her central point: “Independence and partnership are not opposites.” 

Harden’s advice comes down to a few habits that can make audit more useful without blurring accountability: 

Clarify the three lines. Management owns risks and controls. Risk and compliance establish the framework and challenge assumptions. Internal audit independently evaluates governance and controls. Those roles should be clear before an issue arises, especially in areas such as lending, payments, vendor management, and other higher-risk processes. 

Invite audit early, but define the role. Harden said internal audit can sit in early discussions, ask questions, share themes, and offer options. The boundary is ownership. Audit should not approve controls, operate controls, make management decisions, or own the business response. As she put it, “Partnership means shared visibility, not shared ownership.” 

Use better language. Some audit tension comes from wording that sounds personal or accusatory. Harden contrasted “Who made this mistake?” with “Where did the process or control environment allow this issue to occur?” The second version does more than soften the tone. “The revised wording is not softer,” she said. “It’s more specific about condition, evidence, and risk.” 

Reduce predictable friction. Evidence requests can feel like distrust. Challenges can sound like criticism. Late surprises make people defensive. Duplicate requests create burden. Harden’s message was that these pain points can be managed through clearer expectations, better timing, stronger coordination, and more consistent follow-through. 

Keep collaboration going through the full cycle. A kickoff meeting is not enough. Harden emphasized continuous dialogue through planning, understanding, testing, reporting, and follow-up. That dialogue can help management understand the issue, identify root causes, and develop a more realistic action plan. Internal audit still owns the conclusion; management owns the response. 

Know what success looks like. A better audit relationship is not measured by fewer findings or how much people like the auditor. Harden pointed instead to fewer late surprises, less duplication, clearer ownership, earlier risk signals, stronger themes, and protected credibility. 

The takeaway: Internal audit adds the most value when it is, in Harden’s words, “close enough to see the risk, independent enough to call it, and trusted enough to be heard.” That requires early engagement, clear boundaries, careful language, and a shared commitment to improving governance without blurring accountability. 

Related Articles

Login to View This Content

 

Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.