AI Agent Hub
Back to skills
Internal Audit Mastery icon

Internal Audit Mastery

Professional Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Follow https://skillhub.cn/install/skillhub.md to install @user_15292d5a/yjkj-internal-audit-mastery into your AI assistant.

About this skill

Problem Addressed

Internal audit guidance is often split across IIA standards, competency frameworks, learning catalogs, and local case materials. Practitioners can end up focusing on checklists without a clear reference for governance positioning, risk-based planning, engagement delivery, reporting, and QAIP. This skill organizes IIA 2024-2026 materials and China-focused case notes into a readable structure for internal audit, IA engagement planning, and competency mapping.

Core Capabilities and Workflow

  • Standards alignment: Covers the five IIA global standard domains: Purpose, Ethics and Professionalism, Governing the Internal Audit Function, Managing the Internal Audit Function, and Performing Internal Audit Services. It clarifies CAE reporting lines, board communication, and external quality assessment requirements.
  • Competency mapping: Organizes four categories and 28 knowledge and skill subcategories, with Foundational, Intermediate, Advanced, and Expert levels. Useful for team capability reviews, hiring profiles, and CPE planning.
  • Engagement lifecycle: Connects risk assessment, objectives, scope, work programs, evidence collection, the five elements of findings, report content, and action tracking into a practical audit workflow.
  • Learning and certification: Lists CIA, CRMA, ESG, Cybersecurity, and Data Literacy tracks, helping place AI, cybersecurity, and data audit topics into a structured learning path.
  • China-focused practice: Adds local context around legal frameworks, governance structures, digital transformation, and remediation follow-up.

Boundaries and Caveats

The skill is a professional practice reference, not an audit evidence source, forensic tool, or legal advisory. Before using it in formal reports, verify against the organization's charter, applicable laws, industry regulation, and the IIA original texts. For emerging topics such as AI, ESG, and cybersecurity, treat it as a framework and learning index rather than a substitute for control testing or risk modeling.

Use Cases

  • Before drafting the annual IA plan, align risk assessment, scope, board approval, and assurance/advisory boundaries with IIA standards.
  • When writing audit findings, structure criteria, condition, cause, effect, and recommendation with references to Std 13.4 and 14.1-14.4.
  • When assessing an audit team, map 28 knowledge and skill subcategories to Foundational, Intermediate, Advanced, and Expert levels.
  • When planning CPE, select AI, ESG, cybersecurity, and data analytics courses and match them to CIA/CRMA requirements.

Best For

  • CAE drafting annual audit plans and risk assessments, needing to explain scope, resources, and quality requirements to the board.
  • Audit staff preparing for CIA or CRMA exams, needing to plan CPE across AI, ESG, data, and cybersecurity.
  • Audit managers delivering compliance, operational, or IT engagements, needing to document the five finding elements and action tracking.
  • HR or quality assessment owners doing capability reviews, needing to map 28 skill subcategories to four levels.