Interview questions

Internal auditor screening questions: SOX testing, walkthroughs and CIA status

On this page
  1. Which internal audit seat: SOX-only, operational, IT, or co-source
  2. Knockout questions
  3. SOX testing and walkthrough questions
  4. Risk assessment and audit planning questions
  5. Findings, remediation and stakeholder pushback questions
  6. CIA and other credentials
  7. How internal audit experience gets overstated
  8. Scoring rubric and checklist
  9. Questions people ask

Internal auditor screening questions need to establish what kind of audit work the candidate has actually done: SOX control testing, operational audits, IT general controls, or some combination, and how independent their role really was. Ask for a specific control they tested recently, what evidence they gathered, and what happened when the control failed. A resume that says "internal audit experience" can mean running full risk-based audits with an audit committee relationship, or executing test steps a senior auditor designed; the interview should make that difference obvious.

This is a different function from the team whose numbers get tested. If the order is for the person who owns the close and the controls themselves, use controller screening questions. If the role is closer to ongoing regulatory compliance monitoring rather than periodic independent testing, use compliance analyst screening questions.

Which internal audit seat: SOX-only, operational, IT, or co-source

SeatWhat the work looks likeA question that tests it
SOX / financial controlsTests internal control over financial reporting on a defined annual cycle tied to the external audit"How many controls were in your SOX testing scope, and how were they selected?"
Operational auditReviews processes outside financial reporting: procurement, HR, IT operations, against efficiency and risk, not just financial accuracy"Describe an operational audit that was not about financial controls. What was the objective?"
IT / IT general controls (ITGC)Tests access controls, change management and system operations, often alongside or as part of SOX scope"What ITGCs have you tested: user access reviews, change management, backups?"
Co-source or outsourced (via a public accounting or advisory firm)Works on internal audit engagements for client companies rather than as an employee of the company being audited"Were you employed by the company you audited, or by a firm engaged to do the work?"

Knockout questions

QuestionWhat a strong answer sounds likeRed flags
This role covers [SOX / operational / IT / a mix]. What has your scope actually included?A direct, specific answer matched to the order, or an honest statement of a gap.Claims broad audit experience with no ability to describe a single specific engagement.
Have you designed test procedures yourself, or executed steps someone else designed?An honest answer about their actual level of independence and seniority.Claims to have designed testing approaches but cannot describe how a sample size or test attribute was chosen.
This role reports to [audit committee / controller / VP of internal audit]. Have you worked in a reporting structure like that?A clear answer about the reporting line they actually worked under.No understanding of why the reporting line matters to independence.
This role requires travel to [locations/business units] during testing cycles. Is that workable for you?Yes, or a specific limitation stated now.Raises a travel conflict only after an offer is close.

SOX testing and walkthrough questions

Section 404 of the Sarbanes-Oxley Act requires public companies to file an annual management assessment of internal control over financial reporting, and accelerated filers must have an external auditor attest to that assessment (as of September 2026). Internal audit teams typically do the underlying control testing that supports management's assessment. Ask a candidate to walk through the actual mechanics, not just to name SOX as an area of the resume.

  1. "Walk me through a walkthrough: how do you confirm a control is designed and operating as documented?"
    • Strong answer: traces one transaction through the process end to end, interviews the control owner, observes the control being performed if possible, and compares what actually happens against the documented process narrative, updating the narrative if it is stale.
    • Red flags: describes only reading a policy document with no interview or transaction trace.
  2. "How do you select a sample for testing, and how do you decide the sample size?"
    • Strong answer: describes the control's frequency (daily, monthly, annual) driving sample size, and a selection method (random, or targeting higher-risk items) rather than picking whatever is convenient.
    • Red flags: cannot explain why sample size differs between a daily control and an annual one.
  3. "Describe a control you tested that failed. What did you do next?"
    • Strong answer: documents the exception, determines whether it is isolated or a broader pattern, potentially expands the sample, and writes up the finding with the control owner's response.
    • Red flags: "It never happened" across a real testing career, or describes quietly dropping an exception from the sample.

Risk assessment and audit planning questions

QuestionWhat a strong answer sounds likeRed flags
How was the annual audit plan built, and were you involved in that process?Describes a risk assessment feeding into the plan (interviews with management, prior findings, industry risk factors) and their specific role in it.No awareness of how audits got selected, only that they were assigned to one.
Describe an audit you scoped yourself. How did you decide what was in and out of scope?A specific engagement, tied to a stated objective and risk, with clear boundaries explained.Has never scoped an engagement, for a role that expects it.
How do you document your work so someone else could review it later?Describes a structured workpaper format, referencing evidence clearly enough for a reviewer to follow without asking the tester questions.Vague description of "notes" with no structure.

Findings, remediation and stakeholder pushback questions

  1. "Describe writing up a finding that the process owner disagreed with. How did that go?"
    • Strong answer: describes standing behind evidence-based conclusions while remaining open to new information, and a specific resolution (the finding stood, was revised with new evidence, or a management response was documented alongside it).
    • Red flags: either caves on every disagreement or describes no process for handling disagreement at all.
  2. "How do you track whether a prior finding was actually remediated?"
    • Strong answer: describes a follow-up process (a tracker, a retest at a defined interval) and an example of a finding that was not actually fixed on first claim.
    • Red flags: takes a process owner's word that something was fixed with no verification step.

CIA and other credentials

The Certified Internal Auditor (CIA), issued by the Institute of Internal Auditors, is the field's globally recognized credential, earned through a traditional three-part exam path, an accelerated path, or a challenge exam for qualified professionals such as CPAs. It is a separate credential from the CPA, and holding one does not require the other. The IIA also publishes the profession's standards; a full revision, the 2024 Global Internal Audit Standards, became mandatory for conformance statements as of January 9, 2025 (as of September 2026). Ask whether a candidate's team has adopted the current standards, since it is a reasonable proxy for how current their process knowledge is.

How internal audit experience gets overstated

  • Execution called design. Running test steps someone else wrote, described as designing the audit approach.
  • SOX named without mechanics. "SOX experience" with no ability to describe sample selection or a walkthrough.
  • Exceptions minimized. A testing career with no described control failures, which is unlikely at any real scale.
  • Scope inflated. A narrow, assigned testing role described as owning the full audit plan.
  • Independence blurred. Reporting structure and objectivity glossed over, when it is central to whether the work counts as internal audit at all.
  • Remediation assumed rather than verified. Findings described as "closed" with no described follow-up testing.

Scoring rubric and checklist

Knockouts are pass or fail. Score the rest 0 to 2 each.

Pass or fail

  • Audit scope (SOX, operational, IT, or a mix) matches or is closely adjacent to the order.
  • Can describe an honest, specific level of seniority and independence.
  • Can work the required travel expectations, if any.
  • Understands the reporting structure and why it matters to objectivity.

Scored, 0 to 2 each (10 possible)

  • Testing mechanics: can walk through sample selection and evidence gathering for a real control.
  • Walkthrough fluency: describes a real, complete walkthrough, not just a policy review.
  • Exception handling: has a real story of a control failing and knows what happened next.
  • Stakeholder management: has a concrete example of standing behind or revising a finding under pushback.
  • Credential and standards awareness: CIA held or in progress, and awareness of current standards.

Send the client a short auditor note with the submittal:

Auditor: [name]
Scope: [SOX / operational / IT / mix], [months], [how recent]
Reporting line worked under: [audit committee / controller / VP internal audit]
Testing depth: [design vs execution], sample selection method: [described]
Exception example: [control that failed, what happened next]
Remediation follow-up: [described process]
Credential: [CIA - status] / [CPA] / [neither]
Candidate's own gap: [e.g. "no ITGC testing experience, financial controls only"]
Available to start: [date]

A focused audit screen covers scope, one testing story from selection through conclusion, one exception, and independence; anything beyond that is worth a second conversation with the audit committee chair or controller. Interview Signal keeps the transcript on your computer during the call and ticks off each question as it is covered, so the auditor note above is built from what the candidate actually said.

Questions people ask

What is the difference between internal audit and a controller's team?

A controller's team owns the close, the books and the internal controls themselves. Internal audit independently tests whether those controls actually work, usually reporting to an audit committee rather than to the finance organization it reviews. See controller screening questions for the role that owns the numbers being tested.

Does an internal auditor need to be a CPA?

No. The relevant credential is the IIA's Certified Internal Auditor (CIA), a separate designation from the CPA. Some internal auditors, especially those from a public accounting background, hold both, but neither is a strict requirement at most companies.

What does SOX testing actually involve day to day?

It means testing whether a specific internal control operated as designed over a period, usually by selecting a sample of transactions, gathering evidence (a document, a system log, an approval), and comparing what happened against what the control says should happen. Ask a candidate to describe testing one control from selection through conclusion, not just to name SOX as an area of experience.

How is a walkthrough different from testing?

A walkthrough traces one transaction from start to finish through the control, usually through interviews and observation, to confirm the process is documented accurately and the control exists as described. Testing comes after, checking a sample of transactions against that documented control to see whether it actually operated consistently.