Internal Auditor Job Description Template - 2026 Guide

Turn this article into takeaways for your work.

Each assistant summarizes the article only for you and suggests best practices for your work.

What You'll Get From This Guide

  • A ready-to-post internal auditor job description you can copy and customize
  • The reporting-line test that separates real internal audit from a controls clerk with an audit title
  • The three jobs hiring managers post under one "Internal Auditor" heading, so you pick one first
  • Real BLS wage data, and why this title is invisible inside it
  • Verified CIA, CISA, and CFE eligibility rules, including the experience candidates must document
  • Context variations, industry differences, and a compensation guide across three levels
  • 18 interview questions with an evaluation approach

Post "Internal Auditor" and you'll get three different candidates answering the same listing. One has spent four years testing controls for SOX compliance, chasing evidence from process owners. One has spent those years in operations, auditing why a warehouse loses two days per shipment, closer to an internal consultant than a compliance tester. And one sits with enterprise risk management, turning a risk register into an assurance plan the board reads twice a year, work that overlaps heavily with a dedicated risk manager. All three are internal auditors.

The fact most job ads bury decides which of those three jobs a candidate actually gets: who the audit function reports to. Internal audit's value rests on being able to examine a process and report what it found even when the answer embarrasses the executive who owns it. A function reporting to the CFO it may need to audit is not doing the same job as one reporting functionally to the audit committee. Postings that omit the reporting line are usually describing the weaker version, and experienced candidates read the omission correctly. For fundamentals that apply to any posting, start with our job description best practices guide.

Last updated: September 2026

Key Highlights

  • One title, three jobs: compliance and controls, operational, and risk and assurance auditors all get posted under one heading, which attracts the wrong pool.
  • The reporting line is the job: three of the fifteen principles in the IIA's 2024 Global Internal Audit Standards are board-facing, "Authorized by the Board," "Positioned Independently," and "Overseen by the Board" (IIA, 2024 Global Internal Audit Standards).
  • Internal audit is not accounting: the BLS defines internal auditors as workers "employed by the organization they are auditing," eliminating waste, fraud, and financial risk, not closing books (BLS).
  • The federal wage anchor is a blend: $83,680 median annual wage as of May 2025 across 1,595,200 accountant and auditor jobs, projected to grow 5 percent from 2025 to 2035 (BLS, Accountants and Auditors).
  • The CIA has a real experience gate: two years of internal audit experience with a bachelor's, one with a master's, and three years from acceptance to complete eligibility (IIA, Certified Internal Auditor).
  • Staffing data gives the title a band: Robert Half's 2026 guide puts internal auditor at $68,750 to $99,750, senior at $89,750 to $121,750, and manager at $115,500 to $157,750.

Why This Role Matters

Three Jobs, One Posting

Internal audit gets treated as one discipline, but the daily work splits into three variants that need different postings:

Variant What It Actually Does Primary Output Usually Reports Toward
Compliance and Controls Auditor Tests control design and operating effectiveness, runs walkthroughs, supports SOX and regulatory testing Control test results and remediation tracking Audit committee, coordinating closely with finance
Operational Auditor Examines procurement, logistics, and service delivery for waste, cycle time, and control gaps Process findings and efficiency recommendations Audit committee, with the business as the client
Risk and Assurance Auditor Builds the risk-based plan, maps assurance coverage against the enterprise risk register Annual audit plan and coverage view Audit committee directly, often alongside ERM

The distinction is not cosmetic. A controls-heavy candidate dropped into operational audit will document a process beautifully and say nothing the business finds useful. An operational auditor put on SOX testing finds the evidence discipline tedious and leaves inside a year. Decide which one you're hiring first.

The federal definition draws the outer boundary. The BLS describes internal auditors as workers who "have duties that are similar to external auditors, but these workers are employed by the organization they are auditing," and who "identify ways to improve the processes for finding and eliminating waste, fraud, and other financial risks to the organization" (BLS, Accountants and Auditors). Note what it does not contain: closing the books, preparing statements, owning a ledger. Internal audit examines the work of the people who do that. An auditor reporting to the controller whose close they audit is doing a smaller job, whatever the title says.

The Reporting Line Is the Job

This is the part candidates evaluate and most postings skip. The IIA's 2024 Global Internal Audit Standards, issued January 9, 2024 and effective January 9, 2025, put the question at the centre of the framework: three of the fifteen principles are board-facing, "Authorized by the Board," "Positioned Independently," and "Overseen by the Board" (IIA, 2024 Global Internal Audit Standards). The predecessor wording was blunter, requiring that "The chief audit executive must report to a level within the organization that allows the internal audit activity to fulfill its responsibilities," though the IIA now publishes that 2017 text for research and study only, superseded by the 2024 framework (IIA, 2017 Attribute Standards, superseded).

That produces three arrangements, and they are not equivalent:

Reporting Arrangement What It Looks Like What the Candidate Should Expect
Functional to the board, administrative to the CEO The audit committee approves the plan, the budget, and the CAE's appointment; daily admin sits with the CEO Findings reach the board unfiltered; scope disputes have a referee above management
Reporting to the CFO Finance sets the plan, the budget, and the auditor's review Audits of finance-owned processes are compromised; scope drifts toward safe areas
Reporting to a controller or accounting manager Audit sits inside the function it is meant to examine Internal control support with an audit title, not internal audit in any real sense

None of these is disqualifying, and plenty of good careers start in the second row at a company with no audit committee yet. What is disqualifying is hiding it. Say so, explain the plan, price the role honestly. Candidates who have worked under a board reporting line ask in the first interview anyway.

Independence also has an external audience. Under PCAOB standards the external auditor assessing internal control may use internal audit's work, but "should not use the work of persons who have a low degree of objectivity, regardless of their level of competence" (PCAOB, AS 2201). Bad positioning does not only demoralize the auditor. It reduces how much of their work anyone outside the company may lean on.

If the role is really about policy, filings, and training rather than independent testing, you want a compliance manager. Compliance builds the control environment; internal audit tests whether it works. Combining both is common at smaller companies and is a real independence compromise, worth naming.

Primary Job Description Template

About the Role

We're hiring an Internal Auditor to provide independent assurance over [Company Name]'s controls, processes, and risk management. You'll run audits from scoping through fieldwork to final report, test whether controls operate the way the documentation claims, and write findings the process owner can act on and the audit committee can understand.

This role reports [functionally to the Audit Committee of the Board and administratively to the Chief Audit Executive]. That line is deliberate: it lets you report what you find without routing it through the function you just examined. You'll work alongside the compliance manager who owns the policy environment, the controller and assistant controller whose close falls in scope, and the IT manager when an audit touches systems access.

The ideal candidate has run audits end to end, can hold a finding under pressure, and knows the difference between a poorly designed control and a well-designed one nobody follows.

Key Responsibilities

  • Audit Planning: Scope audits against the risk-based plan, defining objectives, testable criteria, and required evidence before fieldwork.
  • Control Testing: Test design and operating effectiveness of financial, operational, and IT controls, with sampling that survives review.
  • Process Walkthroughs: Interview owners, trace transactions end to end, document what happens rather than what the procedure says.
  • Evidence and Workpapers: Keep workpapers complete enough for a reviewer or external auditor to follow the reasoning unaided.
  • Findings and Reporting: Write risk-rated findings with condition, criteria, cause, effect, and a recommendation a non-specialist can act on.
  • Remediation Follow-Up: Track action plans to closure and re-test remediated controls instead of accepting a status update.
  • Fraud Awareness: Stay alert to fraud, waste, and abuse indicators and escalate under the established protocol.
  • Regulatory and SOX Support: Execute control testing supporting SOX or sector-specific requirements where applicable.
  • Risk Assessment Input: Contribute to the annual risk assessment driving plan coverage, including emerging risks.
  • Stakeholder Management: Keep owners informed so the report holds no surprises, without softening findings to do it.

Requirements

Must-Have Qualifications:

  • Bachelor's degree in accounting, finance, or business, the typical entry-level education for this occupation (BLS)
  • 2+ years of internal audit, external audit, or comparable assurance experience
  • Working knowledge of internal control frameworks and risk-based audit methodology
  • Proven ability to plan and execute an audit end to end, not only run assigned test steps
  • Ability to write a finding that survives challenge from the audited function
  • Data analysis skills sufficient to test populations, not only judgmental samples
  • Professional skepticism plus the judgment to keep working relationships intact

Nice-to-Have Qualifications:

  • Certified Internal Auditor (CIA), or documented progress toward it
  • CPA, CISA, or CFE depending on this role's audit mix
  • Experience in [industry], particularly with [sector-specific regulatory regime]
  • Exposure to IT general controls: access management, change management, backup and recovery

Certifications Worth Knowing

Certifications matter more here than in most finance roles, because the work product is a judgment rather than a reconciled number. What each demands, per the issuing bodies:

Credential Issued By Exam Structure Experience Requirement Best Fit For
CIA The IIA Three parts: Part 1 is 125 questions in 2.5 hours, Parts 2 and 3 are 100 questions in 2 hours each. "The IIA does not prescribe the order in which to take exams" 1 year of internal audit experience with a master's, 2 with a bachelor's, or 5 with no degree via an active Internal Audit Practitioner designation, 2 of those within the past 3 Career internal auditors
CPA State Boards of Accountancy Four-section national exam "All states require CPA candidates to complete 150 semester hours of college coursework to be licensed" Statement-heavy audit and finance leadership
CISA ISACA Computer-based, at PSI centers or remotely proctored 5 years of information systems auditing, control, or security experience, gained "within the 10-year period preceding the application date" IT general controls and systems audits
CFE ACFE Covers fraud schemes, investigations and legal issues, prevention and deterrence 40 qualifying points to sit and 50 to be certified, plus "at least two years of professional experience in a field either directly or indirectly related to the detection or deterrence of fraud" Fraud-focused audit work

Two details before you write "CIA required" into a posting. The IIA gives candidates "three years from the date you are accepted into the CIA program to complete the eligibility requirements," so a mid-program candidate has a clock running. And qualifying experience is broader than the name suggests, covering quality assurance, risk management, compliance, external audit, and internal control, so a compliance analyst may already be eligible (IIA).

What We Offer

  • Competitive Compensation: Base salary aligned to experience, scope, and certification (see below), reviewed annually
  • Genuine Independence: A functional line to the audit committee, an approved plan, and management response tracked to closure
  • Comprehensive Benefits: Medical, dental, and vision coverage, retirement plan with employer match, and paid time off
  • Certification Support: Exam fees, materials, and paid study time for the CIA, CPA, CISA, or CFE
  • Business Exposure: Scope reaching operations, IT, and finance, the fastest legitimate way to learn how a company works
  • Growth Path: A defined track to Senior Internal Auditor and Internal Audit Manager, plus laterals into risk or finance leadership

Context Variations

Corporate Environment

At a larger company, internal audit is a standing department with a charter, an annual risk-based plan, and a quality assurance program. An auditor owns two to five audits a year in a defined area and rarely designs methodology. Regulatory testing takes a fixed share of the calendar, which makes the year predictable but limits how much of the plan is genuinely risk-driven.

Startup Environment

Most startups have no internal audit function and do not need one. The first hire arrives when an event forces it: an IPO track, a large regulated customer, a private-equity owner, or a control failure that cost real money. That auditor is a builder more than a tester, writing the charter and often reporting to the CFO because no audit committee exists yet. Say so plainly and hire someone who wants to build. Early-stage versions blend into a business analyst or compliance scope, which works as long as everyone understands the trade.

Remote or Hybrid Environment

Internal audit is one of the more location-flexible finance roles, though less so than bookkeeping. Workpapers, evidence requests, testing, and report writing all work remotely. The exceptions are narrow and worth naming: inventory observation, cash counts, site walkthroughs, and any audit where seeing the floor is the point. What works is remote fieldwork plus a defined number of travel weeks, stated as a number rather than "occasional travel."

Industry Considerations

Industry changes this job, not just its vocabulary. Regulated sectors bring mandatory scope that consumes plan capacity before risk-based work begins.

Industry Key Requirements Unique Considerations
Banking & Financial Services Credit and lending controls, anti-money-laundering testing, model risk Examiners review internal audit's own work, so methodology faces outside scrutiny
Healthcare Patient privacy controls, billing accuracy, payer contract compliance Findings carry regulatory and reimbursement exposure, so escalation protocols matter
Insurance Reserving and claims controls, underwriting limits, broker compensation Actuarial judgment sits next to the controls tested, so auditors need literacy to ask well
Public Companies SOX-scoped testing, external auditor coordination, audit committee reporting External auditors may use internal audit's testing, but only where objectivity is high (PCAOB, AS 2201)
Manufacturing Inventory existence and valuation, procurement controls, plant-level audits Real site travel, and audits needing physical process flow understood, not system records
Government & Public Sector Grant compliance, procurement rules, statutory audit mandates Statute sets scope rather than risk, limiting how much of the plan the function controls

The method is identical across all six rows. What changes is how much of the plan is mandatory, who reads the report, and what a missed finding costs.

Compensation Guide

How the Federal Data Maps to This Title

There is no federal wage series for "Internal Auditor." The BLS folds the title into "Accountants and Auditors," reporting a median annual wage of $83,680 as of May 2025 across 1,595,200 jobs, with growth of 5 percent projected from 2025 to 2035, faster than average, producing about 79,400 new jobs and roughly 115,300 openings a year (BLS). Typical entry-level education is a bachelor's degree.

Treat $83,680 as a directional anchor, not a market rate for this title. It blends staff accountants, audit associates, and tax preparers into one number, and internal audit generally prices above it at equivalent tenure. Robert Half's 2026 guide gives figures per rung:

Data Point Accountants and Auditors (BLS) Internal Auditor (Robert Half 2026) Senior Internal Auditor (Robert Half 2026) Internal Audit Manager (Robert Half 2026)
Pay Anchor $83,680 median annual wage $68,750 to $99,750 $89,750 to $121,750 $115,500 to $157,750
Midpoint Not published $85,750 $105,750 $135,000
Reference Date May 2025 2026 guide 2026 guide 2026 guide
Level This Maps To Whole occupation, entry through senior Independent execution, 2 to 5 years Ownership and review, 5 to 8 years Plan ownership, team leadership

Sources: Robert Half, Internal Auditor; Senior Internal Auditor; Internal Audit Manager.

Use the BLS figure to sanity-check your finance band, and the Robert Half figures to price the rung you're posting.

Market Compensation by Experience Level

The ranges below are employer-set market planning bands built around the data above, not a salary database quote. Validate locally before making an offer; certification, regulated-industry experience, and a board reporting line push toward the higher end.

Level Years of Experience Base Salary Range Total Compensation Range
Entry 0-2 years $62,000 - $75,000 $64,000 - $80,000
Mid (Internal Auditor) 2-5 years $70,000 - $100,000 $74,000 - $108,000
Senior (Senior Internal Auditor) 5-8 years $90,000 - $122,000 $96,000 - $134,000
Lead (Internal Audit Manager) 8-12 years $115,000 - $158,000 $126,000 - $178,000

Factors that move a candidate within these bands: whether they've owned audits end to end, CIA or CISA certification, regulated-industry exposure, and whether they've presented findings to an audit committee.

Metro Adjustment Guide

Cost of living moves these bands. The adjustment below is a planning heuristic, not a location-specific quote.

Market Tier Example Markets Adjustment vs. National Base
Tier 1 (major hub) New York, San Francisco, Boston, Washington D.C. +15% to +25%
Tier 2 (secondary metro) Chicago, Dallas, Atlanta, Charlotte Baseline, no adjustment
Tier 3 (lower cost-of-living) Smaller metros and non-metro areas -10% to -15%

Two role-specific notes. Financial-services and insurance hubs price internal audit above their local tier, because regulatory testing demand concentrates there. And a role with a functional audit committee line often closes candidates slightly below a comparable CFO-reporting role, because the positioning is part of the offer.

Experience Level Requirements Matrix

Level Years of Experience Typical Scope Common Titles
Entry 0-2 years Executes assigned test steps and documents workpapers under review Audit Associate, Staff Auditor
Mid 2-5 years Runs an audit end to end, scoping through fieldwork to draft findings Internal Auditor, IT Auditor
Senior 5-8 years Owns complex audits, reviews workpapers, presents findings to owners Senior Internal Auditor, Audit Supervisor
Lead 8-12 years Owns the annual plan, manages the team, reports to the audit committee Internal Audit Manager, Audit Director
Executive 12+ years Owns the charter, the function, and the board relationship Chief Audit Executive, CFO in smaller structures

For candidates who don't want the management track, two laterals work well: risk or compliance leadership, or finance via financial analyst and finance director roles.

Interview Questions

Technical/Functional Questions

  1. Audit Scoping: "How do you scope an audit when the process owner says everything is fine?" Look for risk-based reasoning, not accepting the assertion or auditing everything.
  2. Design vs. Operating Effectiveness: "What's the difference between a poorly designed control and a well-designed one that isn't operating?" Look for a clean distinction and different remediation for each.
  3. Sampling: "How do you set sample size and selection method for a control test?" Look for population, frequency, and risk driving it, not a fixed number.
  4. Evidence Quality: "A process owner sends a screenshot as evidence. Is that enough?" Look for judgment about source and reperformance, not a yes or no.
  5. Writing a Finding: "Walk me through a finding you wrote: condition, cause, effect." Look for a real example with a clear effect.
  6. Root Cause: "How do you get past the symptom to the cause of a control failure?" Look for a method, not "I ask why a few times."
  7. Remediation Follow-Up: "Management says a finding is remediated. What do you do?" Look for re-testing, not accepting a status update.
  8. IT General Controls: "What would you look at in an access management review?" Look for provisioning, deprovisioning, privileged access, periodic review.

Behavioral Questions

  1. Holding a Finding: "Tell me about a senior stakeholder pushing back hard on a finding." Look for holding the position on evidence, not caving or escalating first.
  2. Being Wrong: "Describe a finding of yours that turned out to be overstated." Look for someone who has one and handled it cleanly.
  3. Scope Creep: "Tell me about an audit that grew beyond its scope." Look for a decision to extend or defer, not just absorbing it.
  4. Difficult Access: "Describe a time you couldn't get the evidence you needed." Look for escalation through the right channel, not dropping the test.
  5. Delivering Bad News: "How did you tell an owner something they didn't want to hear?" Look for no-surprises communication, not an ambush at report stage.
  6. Working Independently: "Describe an audit with little supervision." Look for self-directed structure and voluntary review checkpoints.

Culture Fit Questions

  1. Understanding of Independence: "What does independence mean in practice at your level?" Look for a definition tied to reporting lines and scope, not a textbook phrase.
  2. Auditor as Partner: "How do you avoid being seen as the police?" Look for usefulness to the business without softening findings.
  3. Confidentiality: "How do you handle something you learn mid-audit that isn't in scope?" Look for discretion plus an escalation instinct for anything serious.
  4. Staying Current: "How do you keep up with standards and emerging risks?" Look for a specific habit, not "I read the news."

Evaluation Tips: The strongest candidates name a finding they defended, the evidence behind it, and what happened next. Weak candidates describe audits in the passive voice, where testing was performed and findings issued but nobody appears to have decided anything.

Hiring Tips

Quick Sourcing Guide

  • External Audit Firms: Associates and seniors at public accounting firms are the deepest pool, especially at the two-to-four-year mark when travel fatigue sets in
  • IIA Chapters: Local chapters and their events surface certified, actively networking auditors better than job boards
  • Adjacent Functions: Compliance, quality assurance, and internal control staff already hold experience the IIA counts toward CIA eligibility
  • Regulated-Industry Competitors: Candidates who have worked under your regulatory regime cut ramp time sharply
  • Staffing Firms: Robert Half and specialist audit recruiters place this title regularly and can benchmark your band

Red Flags to Avoid

  • No Independent Findings: A candidate who can't name a finding they raised and defended may have only executed someone else's steps
  • Vague on Sampling: Sample size given as a fixed number, with no reference to population or risk, means the methodology depth isn't there
  • Compliance Framed as Audit: Policy writing and training offered as audit experience signals a compliance profile, a different hire
  • Only Documented, Never Tested: Process mapping without evidence testing is business analysis, not assurance
  • Uninterested in the Reporting Line: Strong candidates ask who the function reports to in the first interview; not asking suggests limited exposure

About the author

Tara Minh

Tara Minh

Senior Operations & Growth Strategist

Tara Minh is Senior Operations & Growth Strategist at Rework, helping B2B SaaS leaders scale without breaking their teams. With 8+ years in revenue operations and process optimization, Tara turns messy workflows into systems people actually follow. Readers get practical frameworks they can use to cut waste, align teams, and grow on purpose.