Skip to main content
Image coming soon

The Broker-Dealer Internal Audit Workpaper Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Broker-Dealer Internal Audit Workpaper Playbook

Scope, test, and write up SEC and FINRA audits at a retail broker-dealer so the audit committee reads the report once and signs off.

Workpapers that come back from QA with five rounds of reviewer comments are the actual cost of an internal audit team at a broker-dealer. Scope rationale, sampling basis, and assertion mapping are where the re-work lives.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Internal audit at a retail broker-dealer carries an audit universe built around customer-protection rules, net capital, Rule 17a-4 records retention, Reg BI, AML and BSA, custody and possession-or-control, third-party reliance on SOC reports, and SOX over financial reporting. The work is not the testing itself. The work is the workpaper file: control narrative current with the business owner's last process change, scope rationale that survives a SEC examiner question, sample selection note that names the population, the basis, the size, and the confidence interval, and an issue write-up that the first-line cannot reasonably reject. Senior reviewer cycles eat the calendar. Audit committee presentations need a one-pager that the chair reads once and the General Auditor does not have to walk through line by line. The skill the course teaches is how to produce that file and that one-pager at a quality the QA reviewer signs off on the first pass.

What you walk away with

  • Produce a workpaper file that passes QA review on the first cycle with one round of reviewer comments at most.
  • Write scope rationale, sample selection notes, and assertion mappings that survive a SEC or FINRA examiner read.
  • Convert a tested control to an audit committee one-pager the chair reads once.
  • Defend sampling basis for customer-protection rule testing, AML transaction surveillance, and SOX key controls under reviewer challenge.
  • Cut the senior-reviewer comment cycle from four rounds to one on each engagement going forward.

The 12 modules

Module 1. The broker-dealer audit universe and how to scope from it
The full audit universe at a retail broker-dealer carries customer-protection rules, net capital, Rule 17a-4 records retention, Reg BI, AML and BSA, custody and possession-or-control, and SOX over financial reporting. The module walks through how to build a risk-ranked universe, how to allocate the annual plan against it, and how to defend scope choices to the audit committee when a regulator asks why a particular area was not covered this cycle.
Module 2. Control narrative writing that survives the business owner's next process change
Most workpapers come back from QA because the control narrative is one process change behind the business owner. The module covers how to write narratives that name the trigger, the system, the role, the evidence, and the frequency so that a change to any one of them is visible at the next walk-through. Includes a template for the narrative, the change log, and the walk-through evidence the QA reviewer expects to find in the file.
Module 3. Scope rationale that a SEC examiner reads once
Scope rationale is the section reviewers and examiners read first. The module walks through how to express the population, the risk basis, the coverage choice, and the explicit exclusions in language that does not invite a follow-up question. Five worked examples cover Reg BI, customer-protection rule sampling, AML transaction-testing thresholds, third-party SOC report reliance, and a SOX key-control population call.
Module 4. Sample selection notes that pass QA on the first cycle
Judgmental sampling notes get bounced. The module covers how to write sample selection notes that name the population definition, the basis (random, stratified, judgmental with explicit risk factors), the size with the confidence interval, the exclusions, and the period coverage. Includes the standard QA reviewer challenges and how to pre-empt each of them in the note itself.
Module 5. Customer-protection rule and possession-or-control testing
The customer-protection rule and the possession-or-control workpapers are where internal audit and the regulator meet most often. The module covers how to scope the reserve formula computation review, how to test possession-or-control over fully paid securities, how to sample for excess margin lock-up violations, and how to write up findings so the first-line cannot reasonably argue the methodology.
Module 6. AML and BSA transaction surveillance audits
AML programme audits at a broker-dealer cover customer due diligence, transaction monitoring rule tuning, SAR filing timeliness, and look-back testing. The module walks through how to scope each of the four, how to set transaction-testing thresholds that survive examiner review, how to test alert-disposition quality, and how to express SAR-timeliness findings in language the financial crimes head will sign off rather than push back on.
Module 7. Rule 17a-4 records retention and electronic recordkeeping audits
Rule 17a-4 testing covers WORM storage, audit trail completeness, third-party access controls, and the retention schedule against the actual data destruction practice. The module covers how to test each control end to end, how to handle the cloud-storage attestation reliance question, and how to write up a retention-gap finding so that the technology owner accepts the remediation date the audit committee expects to see.
Module 8. Reg BI care obligation and disclosure testing
Reg BI audits land in care obligation, disclosure, conflict of interest, and compliance. The module covers how to scope the recommendation population, how to sample across product types and registered representatives, how to evidence the care obligation reasoning at the recommendation level, and how to write up a disclosure-gap finding that the chief compliance officer accepts on the first read.
Module 9. Third-party SOC 1 and SOC 2 report reliance workpapers
The third-party reliance file is where examiners look hardest because firms rely on SOC reports without testing the complementary user-entity controls. The module walks through how to read a SOC 1 type 2, how to identify the complementary user-entity controls that the firm itself must operate, how to evidence those controls in the workpaper file, and how to handle a qualified opinion or carve-out with a defensible compensating-control conclusion.
Module 10. SOX over financial reporting at a broker-dealer
SOX key controls at a broker-dealer cover trade booking, P&L reconciliation, customer cash segregation, and regulatory reporting accuracy. The module walks through how to scope key controls against the FOCUS report assertions, how to sample for design and operating effectiveness, how to handle a control deficiency aggregation question with the external auditor, and how to write up a material weakness assessment so that the audit committee chair signs off rather than re-opens the discussion.
Module 11. Findings write-up the first-line cannot reasonably reject
Most audit findings get rejected by the business owner because the condition, criteria, cause, consequence, and recommendation are not separated cleanly. The module covers how to write each of the five elements so that the first-line response is the agreed remediation date rather than an argument over the finding itself. Includes the standard pushback patterns and the language that closes each of them in the first round of management response.
Module 12. The audit committee one-pager the chair reads once
The audit committee one-pager is the only document the chair and the independent directors actually read. The module covers how to compress an engagement to one page that names the scope, the conclusion, the two or three findings the committee needs to know about, the management response status, and the next-cycle plan. Includes the layout, the language, and the two or three sentences the General Auditor needs to be able to read aloud without re-explanation.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Modules 1-3 cover the universe-to-scope-to-rationale chain that QA review and SEC examiners read first.
Modules 4-7 cover the regulatory-product workpapers that carry the most reviewer cycles (customer-protection, AML, 17a-4).
Modules 8-10 cover Reg BI, SOC report reliance, and SOX where examiner and external-auditor expectations land hardest.
Modules 11-12 cover the findings write-up and the audit committee one-pager that determine whether the engagement closes on the first cycle or runs into a second one.

What you get with this course

  • Twelve written modules in the Art of Service learning environment, each with downloadable workpaper templates and worked examples.
  • A hand-built implementation playbook tuned to your specific audit universe and the engagements on your next-cycle plan.
  • Worked-example workpaper files for customer-protection rule testing, AML alert disposition, Rule 17a-4 retention, Reg BI care obligation, SOC report reliance, and SOX key controls.
  • Audit committee one-pager template with the language and layout that lands on the first read.
  • 30-day refund window if the materials do not match the work product the QA reviewer expects.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours: account in the learning environment is provisioned and the hand-built implementation playbook for the broker-dealer internal audit context is delivered alongside it.

Week 1: work through modules 1-3 (universe, control narratives, scope rationale) against one engagement on your current plan.

Week 2-3: work through modules 4-7 (customer-protection, AML, 17a-4) against the regulatory workpapers carrying the most QA cycles.

Week 4-5: work through modules 8-10 (Reg BI, SOC reliance, SOX) and modules 11-12 (findings write-up, audit committee one-pager) on the next engagement closing for sign-off.

Before and after

Before

Workpaper files come back from QA review with four rounds of reviewer comments per engagement. Scope rationale and sample selection notes are the most-bounced sections. Audit committee write-ups need a walk-through with the General Auditor before the chair will sign off.

After

Workpaper files pass QA on the first cycle with one round of reviewer comments at most. Scope rationale and sample selection notes are written in language that survives examiner read. Audit committee one-pager lands and the chair signs off without a walk-through.

What happens if you do not address this

Senior-reviewer comment cycles continue to eat the engagement calendar. Examiner findings on workpaper quality become a recurring observation. The annual audit plan slips because the workpaper-to-sign-off cycle is twice as long as the plan assumed.

Who it is for

An internal audit senior associate, manager, or senior manager at a retail broker-dealer or wealth management firm carrying owner-level accountability for several engagements per cycle. Comfortable with the auditing standards, the regulatory landscape, and the testing mechanics, looking to compress the workpaper-to-sign-off cycle and produce audit committee write-ups that land on the first read.

Who this is NOT for. First-line compliance testers, external audit partners, or anyone outside the internal audit function. Not for audit committee members reviewing the work product. Not for staff associates in the first two years of training who are still learning the basics of risk-based audit scoping.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable workpaper templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly four to six hours per module. Most senior associates and managers complete the twelve modules across four to six weeks of part-time study against live engagements.

Why $199 is the right number

IIA general practice content covers risk-based audit at the standards level but does not carry broker-dealer regulatory specifics. SIFMA and FINRA Institute material covers the regulatory landscape but not the workpaper craft. Big-firm internal-audit training is built for the consulting context, not the in-house General Auditor reporting line. This course sits at the intersection: in-house internal audit at a broker-dealer, workpaper quality as the deliverable.

FAQ

Is this for second-line compliance or third-line internal audit?
Third-line internal audit. The deliverable is a workpaper file that passes QA review and an audit committee report that lands on the first read. Compliance testing is a different discipline.
Does the implementation playbook cover my specific audit universe?
Yes. The playbook is hand-built against the broker-dealer audit universe described in module 1 and tuned to the engagements on your next-cycle plan.
How current is the regulatory content?
Customer-protection rule, Reg BI, Rule 17a-4, AML and BSA, custody and possession-or-control coverage tracks the standing rules. Notable amendments are flagged in the relevant module rather than re-versioning the whole course.
Is this useful for an audit team at a wealth management firm rather than a pure broker-dealer?
Yes. Wealth firms operating under broker-dealer registration carry the same workpaper expectations. The custody and possession-or-control modules also cover wealth-side custody arrangements.
What if QA review is run by an outsourced provider rather than in-house?
The workpaper standards are the same. The outsourced reviewer is reading against the same scope rationale, sampling basis, and assertion mapping expectations covered in the course.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.