Examples

Internal Auditor CV Example

Last updated:

Internal auditors are judged on independence, methodology, and whether their findings actually change anything. So your CV is measured by the number of audit engagements you've completed and the kind of risks you surfaced — not by how long you sat in the department.

Copy-ready professional summary

Copy it, then swap the numbers and details for your own.

Internal auditor with six years' experience in internal control evaluation and risk management, having completed 40+ audit engagements across finance, procurement and HR cycles. Identified control gaps whose remediation cut risk exposure by 30%. CIA certified.

Skills employers look for

  • Risk assessment and internal controls
  • Planning and executing audit engagements
  • Audit reporting and recommendations
  • Compliance and governance
  • Data analysis — IDEA and ACL
  • IIA internal auditing standards

Ready-made experience bullets

Replace anything in brackets with your own details, and keep the numbers — they're what sets your CV apart.

  • Completed 40+ internal audit engagements across financial and operational cycles.
  • Identified gaps in procurement controls and tracked remediation through to full closure.
  • Built an annual risk matrix adopted by the audit committee as the basis for the audit plan.
  • Trained five new joiners on audit methodology and IIA standards.

Education

BSc Accounting or Finance — [University], with CIA.

ATS keywords

Include these terms exactly as written — applicant tracking systems match on literal text.

  • internal audit
  • risk assessment
  • internal controls
  • compliance
  • CIA
  • audit committee

Tips specific to this role

Engagements count for more than years

"40+ audit engagements" paints a far clearer picture of your practical experience than "six years in audit".

Connect the finding to the outcome

Don't stop at "identified control gaps". Say what followed: was the policy changed? Did exposure fall? An audit with no consequence doesn't count.

Independence is a skill worth naming

Noting that you reported directly to the audit committee shows you understand where internal audit sits in the governance structure.

Licences and certificates employers ask for

Name in full any you hold, with the number where there is one — many postings screen on these.

  • Certified Internal Auditor (CIA) — the reference qualification for this role, and many postings name it as a requirement.
  • SOCPA — accepted as an alternative or a complement by most local organisations.
  • Certified Information Systems Auditor (CISA) — if you are heading into systems auditing, the highest-demand and best-paid corner of the field.
  • A risk qualification such as CRMA, or accredited COSO training.
  • Anti-money-laundering and compliance training — asked for specifically by banks, finance companies and insurers.

Mistakes specific to this role's CV

  • Writing "performed audit assignments" with no count and no scope. How many a year? Over which cycles — procurement, payroll, inventory?
  • Omitting the impact of findings. A finding that was never closed is worth nothing. Give your recommendation closure rate, or a saving that came out of one.
  • Blurring internal and external audit. The first assesses controls and reports to the audit committee; the second gives an opinion on the statements. Two different jobs.
  • Not mentioning dealings with the audit committee or the board. That is what separates a senior auditor from an auditor, and saying it raises your bracket.
  • Leaving out analytics. Auditing a manual sample is not testing a full population through Excel, IDEA or Power BI.
  • Apologetic language around findings. Audit is a profession of independence, and a CV that hints at accommodation weakens its author.

Questions that come up in this role's interviews

Prepare an example from your own work for each — a generic answer is what every other applicant gives.

How do you prioritise the annual audit plan?

The answer is risk, not rotation. Explain: a risk assessment per cycle by impact and likelihood, input from management and the audit committee, then allocating hours to the highest risk. Anyone who says "we rotate through every department" has missed the profession.

You find a breach that implicates an executive. What do you do?

This is the independence question. Document with evidence, then report through the functional reporting line to the audit committee rather than to executive management. Audit independence means precisely that this route is open.

What is the difference between a preventive and a detective control?

Preventive stops the error before it happens — segregation of duties, authorisation limits. Detective surfaces it afterwards — reconciliations, reviews. Follow with a case where you recommended converting a detective control into a preventive one; that shows maturity.

How do you write an audit finding?

With its five elements: criteria, condition, gap, root cause, and effect. Then an actionable recommendation with an owner and a date. A finding without a root cause recurs next year.

How do you handle management rejecting your finding?

Neither escalate immediately nor concede. Discuss the facts first — they may hold information you lack — and if the disagreement stands, record management's response verbatim in the report and let the audit committee decide.

Where this job leads

Inside audit: auditor, senior auditor, audit manager, then head of internal audit reporting directly to the audit committee. The field's advantage is that it opens more doors outside itself than any other finance role — an auditor sees every department — so many move into risk, compliance, governance, or into an operational function they came to know from the inside. The highest-demand direction today is information systems and cybersecurity audit.