Ebuka Ajaegbu
Back to insights
Career Development

๐—›๐—ผ๐˜„ ๐—ฆ๐—ต๐—ผ๐˜‚๐—น๐—ฑ ๐—ช๐—ฒ ๐—ง๐—ต๐—ถ๐—ป๐—ธ ๐—ฎ๐˜€ ๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐—ฎ๐—น ๐—”๐˜‚๐—ฑ๐—ถ๐˜๐—ผ๐—ฟ๐˜€?

1 August 2026 6min read
๐—›๐—ผ๐˜„ ๐—ฆ๐—ต๐—ผ๐˜‚๐—น๐—ฑ ๐—ช๐—ฒ ๐—ง๐—ต๐—ถ๐—ป๐—ธ ๐—ฎ๐˜€ ๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐—ฎ๐—น ๐—”๐˜‚๐—ฑ๐—ถ๐˜๐—ผ๐—ฟ๐˜€?
EA

Ebuka Emmanuel Ajaegbu

Internal Audit Leader and Researcher focused on corporate governance, risk management, internal control and the development of forward-looking internal audit practices.

Lately, I have been reflecting on how a modern internal auditor should think.

The more I grow in this profession, the more I realise that internal auditing is not defined only by what we do.

It is also defined by how we think.

When I began my career, I believed that being a good internal auditor meant identifying exceptions, reviewing controls, documenting observations and writing strong reports.

Those responsibilities remain important.

Internal auditors must still understand processes, evaluate risks, test controls, obtain evidence and communicate findings clearly.

However, my understanding of the profession has changed.

Today, I believe that the strongest internal auditors do more than identify what is wrong.

They become deeply curious about why it is wrong, what allowed it to happen and what the issue reveals about the wider organisation.

That shift in thinking has changed the way I approach audit work.

Moving beyond the immediate exception

Traditional audit work can sometimes become centred on a narrow question:

Was the required control performed?

That question matters, but it may not be enough.

A modern internal auditor must also ask whether the control remains appropriate, sustainable and responsive to the organisationโ€™s current risks.

For example, instead of asking only:

Is the control working?

We should also ask:

Will this control continue to work if the business grows to twice its current size?

A process may function effectively today because transaction volumes are low, the team is small or a particular employee has extensive experience.

However, the same process may fail as the business expands.

A control that depends heavily on one individual, manual intervention or informal communication may not be sustainable in a larger and more complex organisation.

The auditor should therefore consider not only whether the control is operating now, but whether it is capable of supporting the organisationโ€™s future.

This is the difference between checking compliance and providing insight.

Policies should also be challenged

Internal auditors frequently assess whether employees are complying with policies and procedures.

However, compliance with an outdated policy does not automatically result in good governance.

Instead of asking only:

Is this policy being followed?

We should also ask:

Does this policy still make sense in todayโ€™s business environment?

A policy may have been appropriate when it was approved but become ineffective because the organisation, regulation, technology or risk environment has changed.

For example, approval limits may no longer reflect the companyโ€™s present size.

Reporting deadlines may not align with current regulatory requirements.

Manual procedures may remain in place even though the organisation has introduced automated systems.

Responsibilities may have changed without corresponding updates to the policy.

An internal auditor should therefore evaluate both compliance with the policy and the continuing relevance of the policy itself.

The objective is not simply to confirm that people are following rules.

It is to determine whether the rules are still capable of protecting and supporting the organisation.

Focus on the system, not only the individual

When an error occurs, the easiest question is often:

Who made the mistake?

There are situations where personal responsibility matters. Fraud, deliberate misconduct, negligence and repeated non-compliance should not be ignored.

However, stopping at individual blame can prevent an organisation from understanding the deeper cause of a problem.

A better question is:

What in the system allowed this mistake to happen?

Perhaps the employee was poorly trained.

Perhaps the process was unclear.

Perhaps responsibilities were not properly separated.

Perhaps the system permitted one person to initiate and approve the same transaction.

Perhaps unrealistic performance targets encouraged employees to take shortcuts.

Perhaps supervision was weak.

Perhaps previous warning signs were ignored.

When auditors examine the system, they move beyond identifying the person who made the error and begin to understand the conditions that made the error possible.

This is important because replacing or disciplining one employee may not prevent the problem from recurring.

Unless the underlying system is corrected, another person may make the same mistake.

Most findings do not begin with control failure

Audit findings are often presented as failures of internal control.

A reconciliation was not completed.

A transaction was not properly authorised.

A report was submitted late.

Supporting documentation was missing.

A regulatory return contained incorrect information.

These may appear to be control failures.

However, many control failures begin much earlier.

They begin with weak thinking.

They begin with poor decisions, unclear accountability, misaligned incentives and a culture in which people stop asking difficult questions.

A manager may decide that speed is more important than proper review.

An employee may believe that completing a task is more important than documenting it.

A team may assume that a recurring exception is normal because it has existed for a long time.

Senior management may reward performance without considering how the results were achieved.

Employees may remain silent because raising concerns is perceived as disloyalty.

By the time the control fails, the underlying problem may already be deeply embedded in the organisationโ€™s behaviour and culture.

This is why internal auditors must look beyond procedures.

We must understand the decisions, incentives and behaviours surrounding those procedures.

Internal auditors should think in systems

A modern internal auditor should be a systems thinker.

Systems thinking means recognising that organisational issues rarely exist in isolation.

Governance affects risk.

Risk affects the design of controls.

Controls influence behaviour.

Behaviour shapes culture.

Culture affects organisational performance.

Consider a company that has repeated delays in completing reconciliations.

The immediate finding may be that the reconciliation control is not operating effectively.

However, a systems-thinking approach would explore the wider context.

Are there enough employees to perform the work?

Are roles and responsibilities clear?

Is the accounting system producing reliable information?

Does management review outstanding items?

Are delayed reconciliations escalated?

Are employees rewarded for resolving old items or only for processing new transactions?

Has the board been informed of the recurring delays?

The reconciliation problem may therefore be connected to staffing, systems, supervision, accountability, management priorities and governance oversight.

The auditor who sees only the missed control may recommend that reconciliations should be completed promptly.

The auditor who sees the wider system may recommend changes that address the real cause of the problem.

Connect governance to operational reality

Internal auditors are often positioned between strategy and operations.

The board and senior management establish expectations through policies, risk appetite statements, strategic plans and performance objectives.

Employees translate those expectations into daily activities.

Internal audit helps determine whether the organisationโ€™s actual behaviour aligns with its stated intentions.

This requires auditors to connect high-level governance structures to operational reality.

For example:

  • Does the organisationโ€™s risk appetite influence actual decision-making?
  • Do approved policies reflect the way work is really performed?
  • Are management reports supported by reliable operational data?
  • Are employees held accountable for unresolved control weaknesses?
  • Are performance incentives encouraging excessive risk-taking?
  • Does the board receive an accurate picture of recurring operational problems?

These questions help internal audit move from process-level testing to governance-level insight.

Curiosity is a professional skill

Curiosity is sometimes treated as a personal characteristic.

For internal auditors, it is a professional skill.

Curiosity encourages us to look beyond the first explanation.

It pushes us to ask why a process was designed in a particular way, why an exception continues to recur and why management accepts a risk that appears inconsistent with the organisationโ€™s objectives.

A curious internal auditor does not accept information simply because it appears in a report.

The auditor seeks evidence, context and consistency.

When management states that an issue has been resolved, the auditor asks:

  • What action was taken?
  • Is there evidence that the action was implemented?
  • Has the revised control operated successfully?
  • Has the original risk been reduced?
  • Could the issue recur elsewhere?

Curiosity should not become unnecessary suspicion.

The goal is not to assume that every explanation is false.

The goal is to develop a disciplined habit of inquiry.

Professional scepticism should remain constructive

Internal auditors need professional scepticism.

We must be willing to question assumptions, challenge unsupported conclusions and investigate inconsistencies.

However, scepticism does not require hostility.

An auditor can challenge management respectfully.

A difficult question can be asked constructively.

A disagreement can be handled professionally.

The objective is not to prove that management is wrong. It is to obtain a reliable understanding of the issue and help the organisation respond appropriately.

Constructive scepticism allows the auditor to preserve objectivity while maintaining productive working relationships.

The question behind the finding

Every audit finding should encourage deeper reflection.

If a control was bypassed, why was bypassing it possible?

If an approval was obtained late, why did the process continue before approval?

If a report was inaccurate, what data or review weakness caused the error?

If management repeatedly extends an action deadline, what does that suggest about accountability?

If employees do not escalate issues, what does that reveal about culture?

If a policy is consistently ignored, is the problem the employees, the policy, management enforcement or all three?

These questions help auditors understand that findings are often signals.

A finding may be the visible evidence of a much deeper problem.

The role of the internal auditor is not only to report the signal but to investigate what lies beneath it.

Audit reports should reflect the quality of our thinking

A strong audit report is not necessarily the longest report.

It is the report that helps decision-makers understand the issue clearly.

Good audit reporting begins with good audit thinking.

If the analysis is shallow, the finding will also be shallow.

An observation such as โ€œreconciliations were not completedโ€ describes what happened.

A stronger analysis may explain that reconciliations were delayed because of inadequate staffing, poorly configured systems, weak supervisory review and the absence of an effective escalation mechanism.

The second observation provides management and the board with a clearer basis for corrective action.

Internal auditors should therefore aim to explain:

  • what happened;
  • why it happened;
  • how the system allowed it;
  • what risk it creates;
  • whether the issue is isolated or recurring;
  • what wider governance concern it may indicate; and
  • what sustainable action is required.

The report is the final output.

The thinking behind it is the real work.

The impact of technology and artificial intelligence

Technology is changing internal auditing.

Data analytics can review entire transaction populations.

Automated tools can identify unusual patterns.

Continuous monitoring systems can alert management when a control fails.

Artificial intelligence can analyse documents, compare data, summarise information and support risk assessments.

These developments will improve audit efficiency.

They may also reduce the time auditors spend on routine testing.

However, technology does not eliminate the need for human judgement.

A system may identify an unusual transaction, but an auditor must determine whether it represents fraud, error, a business exception or an emerging risk.

Artificial intelligence may summarise a policy, but an auditor must assess whether the policy is appropriate for the organisationโ€™s circumstances.

A dashboard may show that a control was completed, but an auditor must consider whether the control was meaningful and whether the evidence can be relied upon.

Technology can tell us that something happened.

Professional judgement helps us understand why it matters.

What technology cannot replace

Artificial intelligence can analyse data.

Technology can automate testing.

Dashboards can monitor controls.

However, these tools cannot fully replace:

  • curiosity;
  • professional judgement;
  • ethical courage;
  • contextual understanding;
  • empathy;
  • constructive challenge;
  • awareness of organisational culture; and
  • the ability to connect seemingly unrelated issues.

An internal auditor may observe that a control appears effective on paper but recognise through conversations and experience that employees routinely work around it.

That insight may not be visible in the data.

An auditor may sense that managementโ€™s explanation is technically correct but incomplete.

An auditor may recognise that several minor findings collectively represent a serious cultural or governance problem.

These capabilities depend on human judgement.

The future internal auditor will therefore not compete with technology by trying to process information faster than a machine.

The auditor will create value by asking better questions, applying context and interpreting what the information means for the organisation.

Ethical courage is part of audit thinking

Good thinking is not enough if the auditor is unwilling to communicate difficult conclusions.

Internal auditors may encounter pressure to reduce the severity of a finding, delay a report or accept weak management responses.

They may identify issues involving influential people or strategically important business areas.

In such circumstances, professional courage becomes essential.

The auditor must remain fair, evidence-based and respectful.

However, the auditor must also be willing to report significant matters accurately.

The quality of an audit is weakened when the auditor recognises the truth but avoids communicating it.

Modern internal auditing therefore requires both intellectual quality and ethical courage.

Becoming better thinkers

The profession may be moving towards a future in which routine testing becomes increasingly automated.

Internal auditors will still need technical knowledge.

We must understand governance, risk management, controls, financial reporting, technology, regulation and business operations.

However, technical knowledge alone will not distinguish the most valuable auditors.

The difference will increasingly be found in how we think.

Can we identify the issue behind the issue?

Can we connect control failures to governance weaknesses?

Can we distinguish an isolated error from a systemic problem?

Can we challenge a long-standing practice that everyone else has accepted?

Can we explain complex risks in a way that helps the board make better decisions?

Can we remain objective while understanding managementโ€™s perspective?

Can we use technology without surrendering professional judgement?

These are the questions that will shape the future of internal auditing.

Final thoughts

When I began my career, I believed that strong internal auditing was primarily about performing the right procedures.

Today, I see it differently.

Procedures matter.

Evidence matters.

Documentation matters.

Reports matter.

But all of them are shaped by the quality of the thinking that comes before them.

The strongest internal auditors do not simply identify exceptions.

They investigate causes, challenge assumptions, examine systems, understand behaviour and connect individual findings to wider organisational risks.

They do not ask only whether a control is working today.

They ask whether it will remain effective tomorrow.

They do not ask only whether employees followed the policy.

They ask whether the policy still supports the organisation.

They do not ask only who made the mistake.

They ask what made the mistake possible.

Perhaps the future of internal auditing is not simply about becoming better report writers.

Perhaps it is about becoming better thinkers.

Because the quality of our audits will always be limited by the quality of our thinking.

Share: