Skip to main content
Image coming soon

The Internal Audit Manager's Third-Line Evidence Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Internal Audit Manager's Third-Line Evidence Playbook

Walk into the quarterly Audit Committee with a workpaper file the external assurance team cannot punch holes in.

Your workpaper file is going to be re-performed by an external assurance team that knows exactly where evidence dates drift, where walkthroughs document design but not operating effectiveness, and where deficiency aggregation logic falls apart. The Audit Committee read-out is on the calendar. The CAE wants one slide that lands.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Internal audit managers in retail brokerage and consumer financial services run a testing universe that does not forgive sloppy evidence. The SEC Reg S-P amendments tightened the customer-information control population. FINRA Reg BI and PTE 2020-02 expanded the conflicts-of-interest control set. SOX 404 still owns the financial reporting backbone. CCPA and the state privacy laws keep adding population scope. Every cycle a control owner hands over a screenshot dated three weeks before the test period started, or a walkthrough that documents design but not operating effectiveness, or a population pull that the external assurance team can prove is incomplete. The deficiency aggregation logic in the SOX testing memo does not match the external auditor's model, so a finding that looked clear-headed at the manager level becomes a debate at the partner level. The Audit Committee read-out happens regardless, and the question on the CAE's mind is the same one every quarter: which of these workpapers is going to come back. The playbook does not teach internal audit. It teaches the evidence discipline that lets a manager-level workpaper file survive partner-level scrutiny.

What you walk away with

  • A workpaper file that survives external auditor re-performance with zero population or evidence-date findings.
  • A walkthrough template that documents both design and operating effectiveness, defensible under PCAOB AS 2201.
  • A deficiency aggregation memo whose conclusion matches the external auditor's aggregation model.
  • An Audit Committee read-out that lets the CAE answer the deficiency question in one slide.
  • A population completeness test for every in-scope system that the external assurance team has tried to fail and cannot.

The 12 modules

Module 1. The testing universe and what changed this cycle
Maps your in-scope financial reporting systems to the current cycle's risk-rated control set. Names the regulatory moves that expand or contract the population this cycle (SEC Reg S-P amendments, FINRA Reg BI updates, PTE 2020-02 status, state privacy law additions). Produces the scoping memo the external auditor reviews first and the Audit Committee approves before testing starts.
Module 2. Population completeness testing for in-scope systems
The single most-failed test in retail brokerage and consumer financial services audits. Walks through population-of-one extraction, system query versus database query reconciliation, period cutoff verification, and the completeness assertion language that survives external auditor re-performance. Templates for the four most common system architectures (mainframe-of-record, modern brokerage platform, customer data lake, regulatory reporting warehouse).
Module 3. Sampling defensible to PCAOB AS 2315
Statistical and non-statistical sampling approaches that hold up when the external auditor pulls their own sample over the same population. Sample size determination, tolerable deviation rate selection, attribute versus monetary unit sampling, and the documentation the workpaper needs so the partner-level reviewer agrees with the conclusion. Includes the rework-avoidance checklist.
Module 4. Walkthrough evidence that proves operating effectiveness
Design effectiveness alone gets a partial pass. The walkthrough has to document the control operating as designed during the test period. Covers the four-element walkthrough structure, the screenshot-and-timestamp discipline that survives PCAOB inspection, control owner interview templates that surface workarounds, and the language to use when the control was operating but the evidence is thin.
Module 5. SOX 404 testing for the financial reporting backbone
Process-level testing for the key in-scope sub-processes (trade execution and settlement, customer reserve calculations, net capital reporting, FOCUS report generation, custody reconciliations). Test step design, sample selection, exception evaluation, and the testing memo structure that the external auditor accepts without rewrite.
Module 6. Customer-information controls under Reg S-P amendments
The expanded customer-information control population from the SEC Reg S-P amendments. Identifies the new in-scope controls (incident response, third-party service provider oversight, customer notification), the testing approach for each, and the population-completeness pitfalls specific to customer data. Includes the evidence package the privacy office needs from internal audit before the next FINRA exam.
Module 7. Conflicts-of-interest testing under Reg BI and PTE 2020-02
The conflicts-of-interest control set that has expanded most under Reg BI and PTE 2020-02. Covers compensation conflict identification, the Best Interest disclosure control, the mitigation testing approach, and the workpaper structure that documents both the policy compliance and the operating evidence. Pre-empts the question every external assurance team asks: how do you know mitigation actually mitigated?
Module 8. Broker-dealer net capital and customer reserve controls
The Rule 15c3-1 net capital and Rule 15c3-3 customer reserve controls that sit at the heart of broker-dealer audits. Test step design for the daily calculations, the deficit recognition controls, the segregation requirements, and the FOCUS report controls. Population approach, sampling approach, and the deficiency aggregation logic for findings in this domain.
Module 9. Cycle audit integration with SOX testing
Cycle audits that touch financial reporting need to integrate cleanly with the SOX testing universe to avoid duplicate work and conflicting conclusions. Covers the integration memo, the shared evidence approach, the differential testing scope, and the reporting structure that gives the Audit Committee one coherent view rather than two parallel narratives.
Module 10. Deficiency evaluation and aggregation that matches the external auditor
The deficiency aggregation logic where internal audit conclusions and external auditor conclusions diverge most often. Severity classification (control deficiency, significant deficiency, material weakness), compensating control analysis, prudent official test application, and the aggregation framework that pre-empts the management letter language. Includes the partner-level review template.
Module 11. The Audit Committee read-out that lands
The quarterly Audit Committee report structure that lets the CAE answer the obvious question in one slide. Covers the in-period testing summary, the deficiency disposition, the management response disposition, the open-finding tracker, and the regulatory exam readiness assessment. Templates for the deck, the briefing memo, and the one-page executive summary.
Module 12. External assurance re-performance survival
The final-line workpaper review before the external assurance team arrives. Self-assessment checklist for population completeness, evidence-date integrity, walkthrough sufficiency, sampling defensibility, and deficiency aggregation alignment. Pre-empts the specific re-performance findings that come back most often. Includes the partner-level interview prep for the questions the engagement partner is going to ask.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Module 2 + 12 together if a prior cycle had a population-completeness finding that the external auditor flagged.
Module 6 + 7 together if the next FINRA exam is on the calendar and the customer-information or conflicts-of-interest scope has shifted.
Module 4 + 10 together if the partner-level review historically rewrites the walkthrough conclusions or the deficiency aggregation memo.
Module 8 + 11 together if the broker-dealer net capital and customer reserve testing is the area the Audit Committee asks about most.

What you get with this course

  • Twelve text-based modules in the Art of Service learning environment.
  • Workpaper templates for population completeness, walkthrough evidence, sampling, and deficiency aggregation.
  • Audit Committee deck template, briefing memo template, executive summary template.
  • Partner-level review checklist for each module's deliverable.
  • Hand-built implementation playbook mapped to your specific testing universe and sub-process coverage.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours: course account provisioned, hand-built implementation playbook delivered alongside.

First two weeks: modules 1-4, scoping memo and population-completeness rework.

Weeks three to six: modules 5-9, the SOX and regulatory control testing modules.

Weeks seven to eight: modules 10-12, deficiency aggregation, Audit Committee read-out, external assurance re-performance prep.

Before and after

Before

Workpapers that pass internal QAR but come back from external assurance with population, evidence-date, and walkthrough findings. Deficiency aggregation memos that get rewritten at the partner level. Audit Committee read-outs where the CAE answers a deficiency question and the room shifts.

After

Workpapers that survive external assurance re-performance with no population or evidence findings. Deficiency aggregation that the external auditor accepts. An Audit Committee read-out the CAE delivers in one slide because the workpaper file behind it cannot be punched.

What happens if you do not address this

The next FINRA exam, SEC exam, or external assurance review surfaces a population-completeness or deficiency-aggregation finding that should have been caught at the manager level. The CAE walks into the Audit Committee with a finding to explain. The next cycle the entire testing universe is re-scoped under tighter assumptions and the manager loses the latitude that made the work efficient.

Who it is for

Internal Audit Manager owning a slice of the financial reporting testing universe at a retail brokerage or consumer financial services firm. Three to seven staff and senior auditors. Reports through a Senior Manager or Director to the CAE. Walks into the quarterly Audit Committee with a workpaper trail that has already been through internal QAR and is about to be re-performed by the external assurance team. Owns SOX 404 testing for a defined sub-process (treasury, custody, customer data, conflicts of interest, broker-dealer net capital, or similar) and the cycle audits that sit alongside it.

Who this is NOT for. Not for first-year staff auditors learning the basics of testing. Not for CAEs writing the annual plan. Not for IT auditors running pure SOC 2 or ISO 27001 engagements without a financial reporting overlay. Not for external auditors. Not for forensic investigators.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly six to eight weeks at three to four hours a week, plus the integration time to land the templates inside your existing testing cycle.

Why $199 is the right number

The IIA practice guides cover the principles but stop short of the workpaper-level templates that survive external auditor re-performance. The Big Four internal audit transformation decks cover the operating model but not the population-completeness assertion language. CPE courses on PCAOB AS 2315 sampling cover the standard but not the brokerage and consumer financial services population shapes. This playbook is the workpaper-level execution layer that sits underneath those.

FAQ

Is this a SOX 404 course or a broader internal audit course?
Both. SOX 404 is the backbone, but the customer-information, conflicts-of-interest, and broker-dealer specific modules address the cycle audits that sit alongside SOX in retail brokerage and consumer financial services.
Will the templates work for non-brokerage firms?
The population-completeness, walkthrough, sampling, and deficiency aggregation modules are general. The Reg S-P, Reg BI, PTE 2020-02, and Rule 15c3-1 or 15c3-3 modules are specific to brokerage and consumer financial services. If you are not in that sector the implementation playbook will swap those for your equivalent regulatory control set.
How is the implementation playbook tailored?
It is hand-built against your testing universe, your in-scope sub-process coverage, and the specific regulatory exam cadence you face. Provided alongside course access.
What if the external auditor changes their re-performance approach mid-cycle?
Module 12 covers the standing dialogue with the engagement partner that surfaces approach changes early. The templates are designed to flex to the most common re-performance approaches without rework.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.