17.2 Coordinating Assignments and Reviewing Workpapers and Conclusions
Key Takeaways
- Coordinating assignments means matching auditor skills to the tests in the work program and avoiding team-level segregation-of-duties and objectivity conflicts.
- The engagement supervisor reviews workpapers and evaluates whether information, testing, and evidence are relevant, reliable, and sufficient to support conclusions.
- Standard 14.6 requires internal auditors and the engagement supervisor to review documentation for accuracy, relevance, and completeness; the CAE must review and approve the documentation.
- Review notes are a quality control: they must be timely, cleared, and resolved; uncleared disagreement must not remain in the final file as two competing conclusions.
- Unreviewed conclusions must not be communicated to the client or the activity under review.
C1b and C1c sit together because assignment and review are one control loop. Coordinating work assignments is how the supervisor turns an approved program into named people, named tests, and named reviewers. Reviewing workpapers and engagement conclusions is how the supervisor proves those tests produced relevant, reliable, and sufficient evidence before anyone outside the team hears a result. CIA Part 2 2025 will punish a file that is busy but unsupervised: the wrong person ran the test, the reviewer was the preparer, review notes aged in the binder, and the client already has the rating.
Coordinating assignments: skills, capacity, and segregation of duties
The work program under Standard 13.6 identifies the internal auditors assigned to each task. Coordination is not a calendar exercise. It is a competence and objectivity exercise. Match skills to tests. A walk-through of a warehouse cutoff needs someone who can recognize shipping documents and inventory movement, not only someone who can format a workpaper. A test of application access needs someone who can read role design, not only someone who can export a user list. If the team lacks the skill, the supervisor procures help, changes the procedure, or raises a resource limitation — the same Standard 13.5 problem from planning — rather than hoping a generalist figures it out in the field.
Avoid segregation-of-duties failures on the team itself. Two patterns show up on exams. First, objectivity: do not assign an auditor to test a control the same person recently designed, performed, or supervised in operations. That is a self-review impairment, not a staffing convenience. Second, review independence: the person who prepared the test cannot be the only reviewer of that test. A peer glance after the client meeting is not a review. Dual-purpose staff on small teams still need a designated reviewer who did not perform the procedure. For data-heavy tests, do not let the same person extract the population, write the exception script, and issue the conclusion with no independent look at completeness of the population or reasonableness of the script. Sensitive client data and privileged access should follow the same dual-control logic the team would expect of the auditee.
Capacity is part of coordination. Stacking every high-risk sample on one overloaded senior while a junior sits on low-value ticking invites both quality failure and silent scope reduction. The supervisor rebalances before the due date, not in the review notes after the exit meeting.
Reviewing workpapers and conclusions
GIAS describes the supervisor's review in operational language. The engagement supervisor should maintain ongoing communication with the internal auditors assigned to the engagement and with management of the activity under review. The supervisor reviews workpapers that describe procedures performed, information identified, and findings and preliminary conclusions. The supervisor evaluates whether the information, testing, and resulting evidence are relevant, reliable, and sufficient to achieve the engagement objectives and support the engagement conclusions. Standard 14.6 Engagement Documentation requires internal auditors to document information and evidence so that an informed, prudent internal auditor, or a similarly informed and competent person, could repeat the work and derive the same results. Internal auditors and the engagement supervisor must review the engagement documentation for accuracy, relevance, and completeness. The CAE must review and approve the engagement documentation.
Review is therefore a control, not a courtesy. It asks: Did we do the procedure in the program? Did we do a different procedure that was never approved? Does the evidence actually support the tick mark? Is the conclusion narrower or broader than the test? Are exceptions isolated, projected, or ignored? Could a competent person reperform this?
Review notes: timely, cleared, resolved
Review notes are how that control operates. They should be issued while the tester can still fix the work — as tests complete, not as a single dump the night before the exit meeting. Typical notes demand missing population completeness, additional samples, corroboration beyond inquiry, corrected exception evaluation, or a conclusion rewritten to match the evidence. Staff respond in the file. The supervisor clears the note only when the response actually resolves the issue. A note that says see discussion with no change to evidence or conclusion is not cleared.
Do not leave uncleared disagreement in the final file as two competing conclusions. If the tester still believes the control is effective and the supervisor believes the evidence is inquiry-only, that is an unresolved quality exception, not documentation of professional judgment. Resolve it: more work, a revised conclusion, or escalation to the CAE. Then clear the note so the releasable results contain one supported conclusion. Deleting the notes to make the file look clean, without showing how the conclusion changed, destroys the evidence of supervision. Keeping a bitter argument in the workpapers forever, after the CAE has already decided the issue, is not transparency; it is an uncleared control exception.
Unreviewed conclusions must not reach the client
The hard operational rule: conclusions do not leave the team until review is complete enough to support what is being said. Status meetings can report progress — we are still testing overtime samples — without broadcasting a rating. They must not preview that controls are effective if the overtime workpaper is unreviewed or sitting under an open note. Once the activity under review hears a conclusion, the team has created expectations that a later review reversal will turn into a negotiation. Part 2 is not testing the full Part 3 protocol for final reports and action plans. It is testing whether the supervisor kept fieldwork communications from getting ahead of the file.
Worked example: an accounts-payable engagement assigns a former AP supervisor, now a first-year auditor, to test invoice-approval limits she designed last year. She emails the controller that three-way match looks strong before anyone reviews her sample. A teammate later glances at the workpaper and leaves a note that the population excluded rush vouchers; the note is still open at wrap-up, sitting next to her original effective conclusion. Every C1b–c control in this section failed: skill and objectivity matching, preparer-versus-reviewer segregation, timely review, note clearance, and keeping unreviewed conclusions off the client's desk. The repair is reassignment or added independent testing, a real review of a complete population, a cleared note, and no client-facing rating until the file supports it.
| Supervisor duty | In-control practice | Out-of-control practice |
|---|---|---|
| Skill-to-test matching | Assign procedures the person can actually perform; procure specialists when needed | Give the open slot to whoever is free |
| Team SOD and objectivity | Separate preparer and reviewer; keep recent operators off their old controls | Former process owner tests her own design; self-review only |
| Timely review | Review workpapers as tests finish; notes while repair is still possible | Batch-review the night before the exit meeting |
| Clearing notes | Each note closed with evidence or a revised conclusion | See verbal discussion left uncleared |
| Disagreement | Escalate and resolve; one supported conclusion remains | Two competing conclusions sit in the final file |
| Client-facing conclusions | Share ratings only after review supports them | Staff email a draft rating for reaction |
A supervisor assigns a former accounts-payable manager, now a first-year auditor, to test invoice-approval controls she designed last year, and asks a peer to glance at her workpapers after the client has already been told the control looks strong. What is the primary supervision failure?
What is the correct treatment of review notes that record a disagreement between the tester and the supervisor about whether evidence is sufficient?
Which review practice best prevents unreviewed conclusions from reaching the client?