CORAA
CORAA University / Free programme builder

Internal audit programme generator

Build a cycle-wise internal audit work programme with objectives, procedures, evidence, sample basis, data requests, analytics, red flags and reviewer prompts.

Programme profile
Cycles
4
Procedures
16
Data requests
16
Analytics
20
Hours guide
128
Select cycles
Procedure matrix preview
CycleAreaObjectiveProcedureEvidenceSample basis
Procure to Pay Internal Audit ProgrammeVendor master and onboardingOnly valid, approved and independently verified vendors are active.Reconcile vendor master to new-vendor and change logs. Test PAN, GSTIN, Udyam, bank proof and approval evidence. Search duplicate GSTIN, PAN, bank account, address and contact fields.Vendor master, change log, KYC pack, approval workflow, related-party list.New vendors and master changes during the period, plus high-value active vendors.
Procure to Pay Internal Audit ProgrammePR, RFQ and PO approvalPurchases are approved before commitment and within delegated authority.Trace selected PRs to budget, RFQ, comparative statement and PO. Identify PO-after-invoice, PO-after-GRN and split-purchase exceptions. Test single-source and emergency purchase approvals.PR, budget file, RFQ, comparative, PO, approval matrix, exception log.Risk-based PO sample, all high-value/emergency items.
Procure to Pay Internal Audit ProgrammeGRN, service entry and invoice matchInvoices are booked only for accepted goods or services.Reperform PO-GRN-invoice match. Trace service invoices to completion or user acceptance. Review open GRN, unmatched invoice and quality rejection reports.GRN, service entry, invoice, quality note, match exception report.Sample across goods, services, non-PO and period-end items.
Procure to Pay Internal Audit ProgrammeGST, TDS, MSME and payment releaseTax and payment controls operate before cash leaves the company.Match invoice GSTIN, tax invoice and ITC support. Test TDS/RCM coding and MSME ageing review. Trace payment run to invoice approval, bank authorisation and BRS clearance.Tax invoice, GSTR-2B/recon, TDS working, MSME ageing, payment file, UTR, BRS.High-value tax-coded invoices, MSME suppliers and payment runs.
Order to Cash Internal Audit ProgrammeCustomer master and creditCustomers and credit limits are valid, approved and current.Test new customer approvals and KYC fields. Compare invoices/orders to credit limits and blocked-customer status. Review credit-limit override logs.Customer master, credit approval, override log, block/unblock report.New customers, high-limit customers and override exceptions.
Order to Cash Internal Audit ProgrammeOrder, dispatch and billingBilling is complete, accurate and supported by delivery or service evidence.Trace sales orders to dispatch/service proof and invoice. Review pricing, discount and manual invoice overrides. Test cut-off around period end.Sales order, dispatch/POD/service proof, invoice, price master, discount approval.High-value invoices, manual invoices, period-end sample.
Order to Cash Internal Audit ProgrammeCollections and receivablesReceipts are matched and overdue balances are followed up.Trace receipts to bank and customer ledger. Review ageing, dispute notes and collection actions. Test write-off and provision approvals.AR ageing, collection register, bank statement, dispute tracker, write-off memo.Top balances, overdue buckets and write-offs.
Order to Cash Internal Audit ProgrammeCredit notes, GST and accessReversals and tax reporting are authorised and complete.Test credit notes to approval and return/service dispute support. Match e-invoice/GST reporting to sales register. Review users with customer master, pricing and credit-note rights.Credit note listing, approvals, GST/e-invoice reports, user access listing.All high-value credit notes plus risk-based GST/access samples.
Record to Report Internal Audit ProgrammeChart of accounts and GL governanceGL accounts are approved, mapped and restricted.Review new/changed GL accounts. Map TB to reporting heads and Schedule III/management reporting. Check posting restrictions on sensitive accounts.COA, GL master change log, mapping file, user roles.All new GLs and sensitive account changes.
Record to Report Internal Audit ProgrammeManual journal testingManual journals are supported, approved and posted in the correct period.Extract all manual journals. Test late, weekend, round-sum, senior-user and no-attachment entries. Trace support and approval to posting.JE dump, attachments, approval workflow, close calendar.Exception-based full population plus high-value sample.
Record to Report Internal Audit ProgrammeBalance-sheet reconciliationsReconciliations are prepared, reviewed and cleared.Inspect reconciliation pack and sign-offs. Age reconciling items and trace old items to clearance. Compare subledger to GL.Recon pack, ageing, subledger reports, reviewer sign-off.High-risk accounts, aged items and material balances.
Record to Report Internal Audit ProgrammeClose, provisions and reportingClose entries and reporting outputs are complete and reviewed.Compare close calendar to actual completion. Test accrual/provision workings and reversals. Review reporting adjustments and access to reopen periods.Close tracker, provision workings, reporting pack, period control log.Selected close months and material estimates.
Hire to Retire and Payroll Internal Audit ProgrammeHiring and onboardingHiring is approved and new employees are valid.Trace manpower requisition to approval and offer. Check BGV and joining document completion. Match new joiners to employee master creation.MRF, offer letter, BGV, joining checklist, HRMS log.New joiners and lateral hires during the period.
Hire to Retire and Payroll Internal Audit ProgrammeEmployee master and payroll changesSalary and bank changes are authorised.Review employee master changes. Test salary revision, incentive and bank changes. Search duplicate bank/PAN/UAN fields.Employee master, change log, revision letter, bank proof, approval.All high-risk changes plus random sample.
Hire to Retire and Payroll Internal Audit ProgrammeAttendance, payroll and statutoryPayroll is computed from approved inputs and statutory deductions are supported.Match attendance/leave/overtime to payroll. Recompute selected payroll cases. Review PF, ESI, PT and salary TDS evidence.Attendance report, payroll register, deduction workings, challans/returns.Selected months and employee categories.
Hire to Retire and Payroll Internal Audit ProgrammeExit, FNF and access removalLeavers are settled and removed from systems promptly.Trace exits to last payroll and FNF approval. Check recoveries and asset return. Match leavers to HRMS, ERP, email and bank access removal.Exit checklist, FNF sheet, payroll register, access logs, bank upload.All leavers or risk-based leaver sample.
Risk focus add-ons
  • Confirm population completeness before selection.
  • Tie each test to evidence, owner and reviewer conclusion.
Where it fits

Build the audit scope to fieldwork

The programme generator sits after the SOW and RCM. It converts selected cycles into fieldwork procedures, evidence expectations, data requests and reviewer prompts before samples are selected.

How an internal audit programme generator works

An internal audit programme translates approved scope into testable fieldwork steps. It should state the objective, procedure, evidence expected, sample basis, data request and reviewer expectation for each process area.

This generator uses CORAA’s cycle programme library to assemble selected P2P, O2C, R2R, H2R, cash, inventory, fixed assets, treasury, statutory compliance and ITGC procedures into one downloadable work programme.

The output is deliberately not a substitute for judgement. The auditor still tailors the programme to the entity’s ERP, delegation matrix, locations, data quality, prior findings, SOW and current legal position.

Worked example - standard P2P and ITGC programme

A CA firm starts a quarterly internal audit covering procurement leakage and finance-system access.

Inputs
CyclesP2P and ITGC
DepthStandard
Risk focusFraud leakage
Output
ProgrammeVendor master, PR/PO, invoice match, tax/payment, user access, privileged access, change and report-reliance procedures
ExportsProcedure matrix, PBC requests, analytics, red flags and reviewer checklist
The programme gives the fieldwork team a scoped starting file before samples and evidence follow-up begin.

Common mistakes

Using a generic programme unchanged
Every row should be tailored to the approved SOW, ERP reports, delegation matrix, locations and current risk assessment.
Skipping population completeness
A procedure cannot be relied on if the source report, extraction filters and period coverage are unclear.
Confusing analytics with evidence
Analytics identify exceptions. The file still needs retained population, rule logic, exception follow-up and reviewer conclusion.
Not linking exceptions to reporting
Exceptions should flow into evidence escalation, fieldwork testing, observation drafting or ATR tracking depending on status.

Frequently asked questions

What should an internal audit programme include?+
It should include objective, risk, procedure steps, evidence expected, sample basis, data requests, analytics or red flags, owner and reviewer sign-off expectations.
Is this the same as an internal audit checklist?+
No. A checklist lists areas to consider. A programme should be executable fieldwork: what to test, from which evidence, over what population and how results will be reviewed.
Can this be used for P2P, O2C, R2R and ITGC?+
Yes. The generator covers P2P, O2C, R2R, H2R/payroll, cash and bank, inventory, fixed assets, treasury, statutory compliance and ITGC cycles.
Can I export the programme to Excel?+
Yes. The Excel export includes a programme summary, procedure matrix, data request list, analytics/red flags and reviewer checklist.

Authoritative sources

ICAI
ICAI IASB - Standards on Internal AuditICAI publishes Standards on Internal Audit covering planning, evidence, documentation, reporting and follow-up.
MCA
Companies (Accounts) Rules, 2014 - Rule 13Rule 13(2) refers to internal audit scope, functioning, periodicity and methodology through Audit Committee or Board consultation.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
Cycle audit programme libraryInternal audit SOW generatorInternal audit RCM builderSampling plan generatorInternal Audit module
Share this tool
Last reviewed: 2026-08-30 · For informational purposes only — not professional advice.