6.1 Required Competencies & Skills
Key Takeaways
- Competency means possessing the knowledge, skills, and abilities to perform internal audit responsibilities in conformance with the Global Internal Audit Standards
- Core behavioral skills for practitioners include communication, critical thinking, research, persuasion/negotiation, relationship-building, change management, and professional curiosity
- Communication must fit the audience: boards need concise risk-focused messages; process owners need clear, actionable findings with evidence
- Critical thinking and research turn raw evidence into risk-based conclusions; persuasion and negotiation secure agreed actions without compromising objectivity; curiosity and change awareness surface emerging risks without taking ownership of management decisions
- Continuing professional development (CPD) is mandatory when skills gaps exist: skills decay, standards evolve, and engagement risk profiles change—document learning that maps to your role and exam pathway
Competency as a Professional Obligation
Under Domain II (Ethics and Professionalism) of the 2024 Global Internal Audit Standards, internal auditors must demonstrate competency. Competency is not a résumé claim or a one-time exam score—it is the ongoing ability to apply knowledge, skills, and abilities so that engagements conform to the Standards and produce reliable, useful results for the board and management.
For the Internal Audit Practitioner (IAP) / CIA Part 1 candidate, competency questions usually test whether you can recognize the skill needed in a scenario, spot a skills gap, and choose the appropriate response (develop yourself, obtain help, or decline/scope carefully)—not whether you can list every soft-skill buzzword.
Competency has two intertwined layers:
| Layer | What it covers | Exam signal |
|---|---|---|
| Technical / methodological | Risk assessment, controls, GRC concepts, audit procedures, evidence evaluation, Standards knowledge | Wrong procedure, weak criteria, unsupported conclusion |
| Behavioral / interpersonal | How you inquire, explain, influence, and collaborate without losing objectivity | Tone-deaf reporting, stalled recommendations, damaged access |
Both layers matter. A technically brilliant auditor who cannot communicate findings or build working relationships still fails the purpose of internal auditing—enhancing and protecting organizational value through assurance, advice, insight, and foresight.
Communication Skills
Communication is the skill most often tested because nearly every engagement outcome travels through spoken or written messages: opening meetings, walkthroughs, interviews, status updates, draft reports, and board presentations.
Effective audit communication is:
- Audience-aware — The audit committee wants residual risk, root causes, and management’s response quality. A plant supervisor needs concrete process gaps and practical fixes. Reusing the same dense technical draft for both audiences is a competency failure.
- Evidence-linked — Statements about control weakness or noncompliance must tie to criteria, condition, cause, and effect (or the engagement’s equivalent structure). Opinion without support is not professional communication.
- Balanced and precise — Avoid both alarmist wording that overstates risk and soft wording that hides a material issue. Precision protects credibility.
- Two-way — Listening during fieldwork is communication. Auditors who only broadcast checklists miss context, compensating controls, and emerging risks.
Practical patterns:
- Open interviews with purpose and scope so interviewees know why questions are asked.
- Confirm understanding (“Let me restate the control as I heard it…”) before concluding a walkthrough.
- Escalate timing risks early (delays, access problems) rather than surprising stakeholders in the final report.
Critical Thinking
Critical thinking is the disciplined evaluation of information against criteria and risk. It separates “we completed the program” from “we reached a supportable conclusion.”
Internal auditors apply critical thinking when they:
- Challenge whether the engagement objective still matches the risk that justified the work.
- Distinguish symptoms (late reconciliations) from root causes (unclear ownership, inadequate system access design, tone that rewards speed over accuracy).
- Weigh competing explanations instead of anchoring on the first management narrative.
- Judge whether evidence is sufficient and appropriate—relevant, reliable, and enough to support the rating or opinion.
- Recognize bias in their own testing choices (for example, sampling only convenient locations).
On the exam, critical thinking often appears as a stem where an auditor accepts management’s explanation without corroboration, expands scope without risk rationale, or issues a clean opinion despite contradictory evidence. The competent response is to reassess evidence quality, adjust procedures, or escalate limitations—not to “keep the timeline.”
Research Skills
Research turns questions into criteria and context. Practitioners research:
- Laws, regulations, and contractual obligations that define compliance expectations.
- Internal policies, standards, and prior audit results.
- Industry frameworks and leading practices used as evaluative criteria (when appropriate and disclosed).
- Data sources, system documentation, and process narratives needed to design tests.
Strong research habits include verifying that criteria are current, identifying the authoritative source, and documenting where criteria came from so conclusions remain defensible. Weak research shows up as citing outdated policies, applying another country’s regulation without checking applicability, or treating informal hallway guidance as binding criteria.
Persuasion and Negotiation
Internal auditors do not “win arguments”; they persuade with evidence and negotiate constructive paths to action while protecting objectivity and the integrity of findings.
| Skill | Appropriate use | Boundary |
|---|---|---|
| Persuasion | Helping management see why a risk matters and why a control response is needed | Do not shade findings to make agreement easier |
| Negotiation | Agreeing timelines, owners, and practical remediation approaches | Do not negotiate away factual conditions or materiality of the issue |
Competent persuasion uses risk language stakeholders care about (customer impact, regulatory exposure, financial misstatement, safety, reputation). Competent negotiation focuses on how and when to remediate, not on whether a verified control failure “counts.”
If management disputes a finding, the auditor re-examines evidence and criteria. If the finding stands, document the disagreement and communicate it through the agreed reporting line—do not silently drop it to preserve relationships.
Relationship-Building
Relationship-building creates the trust and access that make audits efficient and advice credible. It is not friendship-as-independence-waiver. Healthy relationships look like:
- Predictable, respectful fieldwork that minimizes unnecessary disruption.
- Transparency about objectives and timelines.
- Credit for strong controls when earned—credibility grows when auditors are fair.
- Separate channels for informal questions versus formal conclusions.
Relationship risk appears when an auditor becomes so close to a process owner that skepticism fades, or so adversarial that information is withheld. Competency includes managing that tension consciously.
Change Management Awareness
Organizations constantly change: system implementations, reorganizations, mergers, new products, outsourcing, and regulatory shifts. Change management competency means understanding how change creates risk—and how internal audit can provide assurance or advice without owning the change program.
Auditors with change awareness:
- Ask how governance, roles, and controls are redesigned during transitions.
- Watch for “temporary” manual workarounds that become permanent control gaps.
- Time assurance work so it informs go-live or post-implementation decisions when risk warrants it.
- Advise on control design options while leaving decision rights with management.
Exam stems often pair a major system conversion with an auditor who either ignores transition risk or starts directing project decisions. The competent path is risk-based coverage and clear advisory boundaries.
Curiosity
Professional curiosity is a disciplined habit of asking “what else could go wrong?” and “what changed?” It fuels better risk assessment and keeps programs from becoming rote. Curiosity without method becomes fishing; method without curiosity becomes checkbox auditing.
Curious auditors notice anomalies in data, inconsistencies between policy and practice, and silent process changes after reorganizations. They follow up with targeted procedures rather than ignoring outliers that do not fit the original test sheet.
Continuing Professional Development (CPD) Situations
Competency erodes without maintenance. Continuing professional development keeps knowledge current as Standards, technology, fraud schemes, and regulations evolve. Typical CPD-relevant situations on the exam include:
- An auditor assigned to cybersecurity or data analytics without relevant skills—options include training, co-sourcing, or CAE reassignment, not silent improvisation.
- New Standards or methodology updates that require team training before the next cycle.
- Industry or regulatory change affecting the audit universe (for example, new privacy rules).
- Career progression toward CIA or specialty credentials that deepen assurance quality.
Document CPD that maps to actual responsibilities. Hours alone are not the point; capability for the work you perform is. When a skills gap is material to engagement quality, the ethical path is to obtain competent assistance or adjust staffing—not to hope inexperience will go unnoticed.
Putting the Skills Together on an Engagement
A mid-cycle inventory audit illustrates the blend: research establishes valuation and cutoff criteria; curiosity questions unusual adjustments; critical thinking tests whether cycle-count exceptions are isolated or systemic; communication frames findings for operations and the audit committee differently; persuasion helps agree a sustainable remediation owner; relationship-building keeps warehouse access open; change awareness flags a WMS upgrade mid-count; CPD after the job might include deeper inventory fraud red-flag training if gaps appeared. Competency is this integrated performance—not any single soft skill in isolation.
An internal auditor is assigned to an advisory engagement on a major ERP go-live but has never audited system implementations and has no training in IT general controls. Which action best demonstrates competency?
Management agrees that a control failure occurred but wants the finding removed from the draft report in exchange for an aggressive 30-day fix. What is the most appropriate use of persuasion and negotiation?
Which behavior best illustrates professional curiosity during fieldwork?