Skip to main content
Image coming soon

The Brokerage Internal Audit Manager's Workpaper Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Brokerage Internal Audit Manager's Workpaper Playbook

Workpapers, sampling logic, and IA committee reporting that hold up to a SEC/FINRA visit and to your own QAR.

The Customer Protection Rule workpaper, the Reg BI suitability sample, the supervisory controls review, the cyber third-party file, and the IA committee deck all sit in the same Q2 plan. Every one of them has to read clean to a SEC/FINRA examiner who pulls it next year and to the QAR reviewer who pulls it sooner.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Internal audit managers in retail brokerages run a plan that touches SEC Rule 15c3-3 (Customer Protection), SEC Rule 17a-4 (records retention), Reg BI (Best Interest), FINRA Rule 3110 (supervision), FINRA Rule 4511 (books and records), and the cyber third-party assessment cycle. The technical testing is the smaller half of the job. The bigger half is making the workpaper readable to four very different audiences: the examiner from the SEC OCIE / FINRA Risk Monitoring team who reviews it cold, the external auditor who reperforms a sample, the QAR peer reviewer who tests the IIA Standards conformance, and the IA committee that needs a one-page risk picture. A weak scope memo, a missing sample-selection rationale, an exception write-up without a re-performed retest, or a management response loop that closed without evidence is what gets surfaced in a closing meeting. The same problems repeat across audits because the workpaper template carries them. The fix is a tighter template, a tighter narrative shape per audit type, and a tighter handoff from manager to senior to staff.

What you walk away with

  • A scope memo template per audit type that names the rule, the population, the sample basis, and the control owners up front.
  • A workpaper narrative shape that reads clean to a FINRA examiner, an external auditor, and a QAR peer reviewer.
  • A sample-selection rationale per audit (Customer Protection, Reg BI, supervisory controls, cyber third-party) that cites the rule and the population logic.
  • An exception write-up format that closes the management response loop with re-performed evidence rather than an email confirmation.
  • An IA committee one-pager per audit that ties residual risk to the brokerage's risk appetite statement.

The 12 modules

Module 1. The annual plan and the brokerage risk universe
The course opens with the annual plan as the source artefact. The risk universe for a retail brokerage covers Customer Protection (Rule 15c3-3), Net Capital (Rule 15c3-1), Reg BI, supervision under FINRA 3110, books and records under 17a-4 and 4511, AML, cyber, and third-party risk. The module walks how the audit manager scores residual risk per universe entry, defends the plan to the audit committee, and writes the scope memos that turn the plan into testable audits.
Module 2. The Customer Protection Rule (15c3-3) audit, end to end
The reserve formula computation, the possession-or-control test, the bank account reconciliation, and the segregation of fully-paid securities. The module gives the audit manager a scope memo, a control-design narrative, a sampling rationale tied to daily reserve computations, an exception write-up template, and the IA committee one-pager. Every workpaper section is grounded in a SEC citation and the typical examiner question that follows from it.
Module 3. The Reg BI suitability sample and the documentation trail
Reg Best Interest covers care, disclosure, conflicts of interest, and compliance obligations. The audit manager designs a sample of customer accounts and recommended transactions, tests against the four obligations, and writes the workpaper so that an examiner pulling the file can trace each conclusion back to the customer profile, the recommendation, and the rep's documented rationale. The module ships the sampling matrix and a tested exception narrative.
Module 4. The FINRA Rule 3110 supervisory controls review
Supervisory written procedures, designation of principals, transaction review, correspondence review, internal inspections, and the annual supervisory controls report under Rule 3120. The audit manager walks the testing of supervisory evidence, the sampling of supervisor sign-offs, the gap analysis against the WSP, and the handoff to the compliance department for remediation. The module includes a worked WSP gap matrix.
Module 5. Books and records under 17a-4 and 4511
Records retention obligations, format requirements, accessibility tests, and the WORM-equivalent storage logic. The audit manager designs an audit that exercises the records repository against actual examiner-style retrieval requests, documents the test in a way that satisfies both the SEC books-and-records rules and the FINRA 4511 retention requirements, and reports on the third-party storage vendor's attestation.
Module 6. Net Capital (15c3-1) computation review
The audit of the net capital computation is its own discipline. Haircuts on securities positions, undue concentration, subordinated borrowings, the minimum net capital requirement, and the early warning thresholds under FINRA 4120 and 4140. The audit manager designs the testing, reviews the computation back to the trial balance, and writes the workpaper for an examiner who will reperform the calculation.
Module 7. The cyber third-party assessment file
Reg S-P, Reg S-ID, and the SEC's cybersecurity risk management rules apply to the brokerage's vendor population. The audit manager scopes the third-party file (clearing firm, transfer agent, custody bank, market data vendors, customer portal vendor, cloud provider), tests the contractual cyber controls, reviews the vendor's SOC 2 Type II report and bridge letter, and writes the assessment so the examiner can trace each vendor's residual risk to a mitigating control.
Module 8. AML and the SAR sample
Bank Secrecy Act and FINRA Rule 3310. The audit manager scopes the AML programme audit (CIP, ongoing monitoring, SAR filing, OFAC screening), designs a sample of alerts and SAR decisions, tests the disposition narrative, and writes the workpaper so the BSA officer's judgement is documented and the audit trail is defensible to FinCEN, the SEC, and FINRA.
Module 9. Sample selection rationale that survives reperformance
A separate module on the sampling logic itself because this is where most QAR findings land. Population definition, sampling approach (random, judgmental, stratified), sample size derivation, exception rate calculation, and the documentation of the rationale. The audit manager walks an audit-by-audit template so a peer reviewer cannot rewrite the sample basis after the fact.
Module 10. Exception write-ups and the management response loop
An exception is only closed when re-performed evidence shows the control is operating, not when the control owner emails 'fixed'. The audit manager learns to write the exception in a four-part shape (condition, criteria, cause, effect), draft the recommendation, manage the agreement-disagreement loop with the first and second line, and document the closure with the retested evidence pinned to the workpaper.
Module 11. The IA committee one-pager and the residual-risk picture
The audit committee does not read the workpaper. They read the one-pager. The audit manager walks how to tie each audit's residual risk to the brokerage's risk appetite statement, surface the cross-audit themes (governance, supervision, vendor risk), and write the recommendation so the audit committee can hold the CEO and CRO accountable at the next quarterly meeting.
Module 12. QAR readiness and the IIA Standards conformance file
Every five years the function sits a Quality Assessment Review against the IIA Standards. The audit manager walks the standards (Attribute Standards 1000-1322, Performance Standards 2000-2600), maps each audit's workpaper to the standards it evidences, and builds the conformance file so the external QAR team has a paper trail rather than a recreation exercise. The module ships the standards-to-workpaper mapping template.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

The annual plan reads thin to the audit committee. Modules 1 and 11 give you the residual-risk scoring and the one-pager template that make the plan defensible.
The Customer Protection workpaper falls apart under reperformance. Modules 2 and 9 give you the scope memo, the sample rationale, and the narrative shape that hold up to a SEC reperformance.
The Reg BI sample is hard to defend because the four obligations are interpretive. Module 3 gives you the sampling matrix and the documentation pattern that ties each conclusion back to the customer profile.
The QAR cycle is approaching and the workpaper-to-Standards map does not exist. Module 12 builds it once, then it lives as a maintained file across every audit.

What you get with this course

  • 12 written modules in the Art of Service learning environment, each with a worked example from a brokerage audit cycle.
  • Scope memo templates for Customer Protection, Reg BI, supervisory controls, net capital, books and records, AML, and cyber third-party.
  • Sampling rationale matrix per audit type, tied to the population definition and the SEC/FINRA citation.
  • Exception write-up template with the four-part shape (condition, criteria, cause, effect) and the management response loop.
  • IA committee one-pager template that ties residual risk to the brokerage's risk appetite statement.
  • QAR conformance file template mapping workpapers to IIA Attribute and Performance Standards.
  • The hand-built implementation playbook delivered alongside course access, tuned to the audits on your current annual plan.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours: account provisioned in the learning environment, the hand-built implementation playbook delivered alongside.

Week 1: Modules 1-3 (annual plan, Customer Protection, Reg BI).

Week 2: Modules 4-6 (supervisory controls, books and records, net capital).

Week 3: Modules 7-9 (cyber third-party, AML, sampling logic).

Week 4: Modules 10-12 (exceptions, IA committee one-pager, QAR conformance).

Before and after

Before

Workpapers that pass internal review but read thin to a reperforming examiner or a QAR peer reviewer. Sample rationales that the peer reviewer rewrites after the fact. Exception write-ups closed on the strength of an email. An IA committee deck that recites testing rather than surfacing residual risk against the appetite statement.

After

A workpaper template per audit type that names the rule, the population, the sample basis, and the control owners up front. A sampling rationale that survives reperformance. An exception write-up closed on retested evidence. An IA committee one-pager that ties residual risk to the appetite statement. A QAR conformance file built once and maintained across the cycle.

What happens if you do not address this

A FINRA Risk Monitoring or SEC examination cycle that surfaces a workpaper-quality finding. A QAR result that flags non-conformance with Performance Standard 2300 (Performing the Engagement) or 2400 (Communicating Results). An audit committee that loses confidence in the function because the residual-risk picture is buried in technical narrative.

Who it is for

Internal Audit Manager in a U.S. retail brokerage or broker-dealer. Runs 4-8 audits per cycle. Reviews workpapers from seniors and staff. Owns the IA committee section for those audits. Reports to a Director or Chief Auditor. Holds CIA, CISA, or CPA; coaches the next cohort through the QAR cycle.

Who this is NOT for. First-year audit staff who have not run a workpaper end to end. Audit directors who delegate workpaper review entirely. Compliance officers in the first line of defence. Buy-side asset management audit teams whose rule set is the Advisers Act rather than the broker-dealer rules.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Six to eight hours per week across four weeks. The implementation playbook is tuned to the specific audits on your current annual plan so the time invested compounds into the cycle in front of you.

Why $199 is the right number

IIA training courses cover the standards in the abstract; this course grounds the standards in brokerage workpapers an SEC/FINRA examiner will pull. CPA-firm internal audit guides cover assurance methodology generically; this course names the brokerage rules (15c3-3, 15c3-1, Reg BI, 3110, 4511) and the typical examiner questions per rule. The implementation playbook is tuned to your specific plan, which neither alternative offers.

FAQ

Does the course cover the buy-side investment adviser rules (Advisers Act, custody rule, marketing rule)?
No. The course is tuned to the broker-dealer side (SEA Rules 15c3-3, 15c3-1, 17a-4, Reg BI, FINRA 3110, 4511). The buy-side rule set is a separate audit programme.
Does the course cover the operational risk capital computation under Basel rules?
No. The brokerage's net capital computation under SEC Rule 15c3-1 is covered in Module 6. Basel operational risk capital is a banking rule set, not a broker-dealer rule set.
Does the course cover the audit of the clearing relationship?
The clearing firm is treated as a third-party vendor in Module 7. The introducing-broker / clearing-broker agreement, the customer asset segregation evidence, and the clearing firm's SOC 2 are covered there.
Is the implementation playbook generic or tuned to my audit plan?
Tuned. Within 24 hours of purchase, the playbook is hand-built around the audits on your current annual plan so the templates land on the audits you are about to start.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.