Skip to main content
Image coming soon

The Internal Audit Senior Manager Workpaper Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Internal Audit Senior Manager Workpaper Playbook

Run a broker-dealer internal audit engagement that survives QA re-performance, control-owner pushback, and the quarterly audit committee read-out without a single rewrite.

Your workpapers are the audit. When QA re-performs the test and the rationale is in your head instead of the file, the engagement gets re-opened, the audit committee read-out slips a cycle, and the next three engagements pile up behind it.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Internal Audit Senior Managers at a broker-dealer carry a workpaper standard that has to satisfy three audiences at once. The senior reviewer who QA-tests the file before sign-off. The external auditors who will use your SOX work as their reliance basis. The audit committee that wants a one-page issue summary that does not surface a control owner dispute three weeks later. The pressure is not the volume of engagements. The pressure is that one workpaper that does not document why you picked the sample, why you concluded the control was designed and operating, and why the issue rating is what it is, costs a re-perform, a rewrite, a delayed read-out, and a credibility hit with the CAE. The Senior Manager grade is where that quality bar gets set for the team. This course teaches the workpaper, sample-rationale, walkthrough, and issue-rating standards that hold up cold, every time.

What you walk away with

  • Workpaper templates documenting risk rating, sample rationale, test procedure, and conclusion in a format that survives a cold QA re-performance.
  • Sample-selection memos with documented selection method, population definition, and rationale for sample size that hold up to external auditor reliance testing.
  • Control-owner walkthrough scripts that surface design gaps in the first conversation, not three weeks later when the issue draft lands on their desk.
  • An issue-rating matrix calibrated to your firm's risk appetite that the audit committee reads without asking for a rewrite.
  • An engagement-level QA self-review checklist you run before handing the file to the senior reviewer.
  • A defensible reliance memo for the external auditors that documents which of your SOX workpapers they can use without re-performing the test.

The 12 modules

Module 1. The Workpaper Standard That Survives Re-Performance
What the senior reviewer is actually testing when they re-perform your work. Risk rating with documented rationale, not a number in a box. Control description that captures the design, not just the activity. Test procedure that another auditor could execute and reach the same conclusion. Conclusion that ties back to the risk and the test. Worked example of a passing workpaper next to a failing one.
Module 2. Sample Selection Rationale That Holds Up Cold
Population definition, sampling method, sample size justification, and the documented reason for each. Statistical versus judgmental sampling and when each is defensible at a broker-dealer. The memo template that external auditors will accept as reliance basis. How to defend a sample size of twenty-five when the external auditor asks for forty. Worked example from a trade allocation control test.
Module 3. Control-Owner Walkthroughs That Surface Design Gaps Early
The walkthrough script that gets the control owner to describe the control the way it actually runs, not the way the SOX narrative reads. The three questions that surface a design gap in the first conversation. How to capture the walkthrough in a workpaper that the external auditors can use. The follow-up email template that locks the control owner's description before they revise it later. Worked example from a wire transfer authorisation control.
Module 4. Issue Rating Calibrated to Audit Committee Read-Out
An issue-rating matrix that maps to the firm's risk appetite statement, the regulatory exposure, the financial reporting exposure, and the operational impact. How to defend a High rating when the control owner argues for Medium. The one-paragraph issue summary the audit committee actually reads. Worked example of an issue rated High, Medium, and Low so the difference is visible. The escalation path when the control owner disputes the rating.
Module 5. SOX Scoping Memos That External Auditors Rely On
Scoping the SOX universe at a broker-dealer where the financial statement line items map differently than at a manufacturer. Materiality calibration, in-scope process identification, and the documented rationale for excluding processes. The reliance memo that gives the external auditor a defensible basis to use your work and reduce their own testing. Worked example for a commission revenue control.
Module 6. Operational Audit of the Lending and Margin Process
How to scope and execute an operational audit of margin lending or securities-based lending without it collapsing into a credit review. The risk universe specific to a broker-dealer lending book. Customer suitability, collateral valuation, margin call execution, and the wind-down process. The test plan, sample, and conclusion structure. Worked example from a margin call exception test.
Module 7. Third-Party and Vendor Risk Audits Under SR 13-1 and OCC Bulletin 2023-17
The third-party risk universe at a broker-dealer. How to scope a vendor audit when the regulator has flagged third-party risk and the CAE wants it on the slate this cycle. The vendor risk assessment, the right-to-audit clause review, the SOC 2 reliance memo, and the on-site or virtual visit protocol. Worked example from a cloud infrastructure provider audit.
Module 8. Cybersecurity and Information Security Audits the Way IT Audit Actually Files Them
How to scope a cybersecurity audit that does not duplicate the IT auditor's work and does not get hand-waved. The intersection of the SEC Reg S-P amendments, FINRA cybersecurity expectations, and your firm's information security policy. Sample tests for identity and access management, change management, and incident response. Worked example from a privileged access management test.
Module 9. Regulatory Audit Track Aligned to FINRA and SEC Exam Priorities
How to align your annual audit plan to the published FINRA exam priorities and SEC OCIE risk alerts so the regulator sees a coordinated internal audit response. The audit plan footnote that documents the alignment. The engagement template for a regulatory-triggered audit. Worked example from a Reg BI compliance audit.
Module 10. Engagement-Level QA Self-Review Before the Senior Reviewer
The self-review checklist you run on every workpaper before the senior reviewer sees it. The five questions that catch ninety percent of QA re-performance findings. The file structure that makes the senior reviewer's job a sign-off, not a rewrite. The exception log that captures self-identified issues so the senior reviewer trusts your judgement. Worked example.
Module 11. Audit Committee Read-Out That Holds Up to Director-Level Questions
The one-page issue summary that lands. The escalation paragraph for issues the audit committee needs to know about before the formal report. The status dashboard format that the audit committee chair reads in two minutes. How to present a disputed issue when the control owner attends the committee meeting. Worked example of a quarterly read-out deck.
Module 12. Audit Plan Refresh and Continuous Auditing Build
How to refresh the annual audit plan mid-year when regulatory priorities shift, when an issue surfaces a new risk, or when the CAE adds an engagement on a week's notice. The continuous auditing build that runs against trade exception data, wire transfer data, and access log data between engagements. The dashboard that surfaces a control breakdown before the next scheduled audit. Worked example of a continuous monitoring routine on margin exception data.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

The workpaper that came back from QA with rationale gaps gets rebuilt to the standard in modules 1 and 2.
The control owner dispute over an issue rating gets resolved by the walkthrough script in module 3 and the rating matrix in module 4.
The SOX reliance request from the external auditor gets answered by the scoping and reliance memo templates in module 5.
The CAE's mid-year ask for a third-party risk audit or a Reg BI audit gets executed using modules 7 and 9.

What you get with this course

  • Twelve written modules with worked examples drawn from broker-dealer internal audit engagements.
  • Workpaper templates for risk rating, sample rationale, walkthrough capture, test procedure, and conclusion.
  • Sample-selection memo templates for statistical and judgmental sampling.
  • Control-owner walkthrough script and follow-up email template.
  • Issue-rating matrix and one-paragraph issue summary template.
  • SOX scoping memo, reliance memo, and external auditor reliance file structure.
  • Engagement-level QA self-review checklist.
  • Audit committee read-out deck template and quarterly status dashboard.
  • Annual audit plan template aligned to FINRA and SEC exam priorities.
  • Continuous auditing routine examples for trade exception, wire, and access log data.
  • Hand-built implementation playbook tailored to your specific engagement slate and reporting line.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours: course access provisioned and the hand-built implementation playbook delivered alongside it.

Week 1: workpaper, sample memo, and walkthrough modules applied to the next engagement that starts.

Week 2-3: issue rating matrix and SOX scoping memo templates rolled into the engagements already in fieldwork.

Week 4-6: third-party risk, cybersecurity, and regulatory audit module templates queued for the engagements scheduled in the next quarter.

Ongoing: engagement-level QA self-review run before every senior reviewer hand-off; audit committee read-out deck used for the next quarterly meeting.

Before and after

Before

Workpapers that re-open at QA. Sample rationale that lives in your head. Control owners who dispute issue ratings three weeks after the walkthrough. SOX reliance conversations with the external auditor that turn into re-performance. Audit committee read-outs that get rewritten the day before the meeting. Engagements that finish on time but trail follow-up rework for two more weeks.

After

Workpapers that pass QA on first review. Sample memos that the external auditors use as reliance basis. Walkthroughs that lock the control description before the issue draft. Issue ratings the audit committee reads and accepts. Audit committee decks that go in unchanged. An engagement slate that closes on time and stays closed.

What happens if you do not address this

Workpaper rework consumes the senior reviewer's time, slips the audit committee read-out by a cycle, and signals to the CAE that the Senior Manager grade is not yet at the firm's standard. External auditor reliance on SOX work falls to the next engagement, which means more re-performance and longer audit timelines. Regulatory-triggered audits get added to the slate without the bandwidth to run them well, and the next FINRA or SEC exam surfaces an internal audit coverage gap.

Who it is for

Internal Audit Senior Manager at a US broker-dealer or wealth management firm, six to twelve years of audit experience, supervising two to four staff or seniors, owning four to eight engagements per fiscal year across SOX, operational, and regulatory tracks, reporting to a Director or VP of Internal Audit who reports to the CAE.

Who this is NOT for. External audit partners. Audit committee members. First-year staff auditors. Internal audit leaders who only own the audit plan and do not personally review workpapers. The course assumes you are still in the file, still running walkthroughs, and still defending engagement conclusions to a senior reviewer.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly eight to twelve hours of reading and template review across the twelve modules, plus the time it takes to apply each template to a live engagement. Most Senior Managers work through it across two to three weeks alongside their normal engagement load.

Why $199 is the right number

The IIA standards, the AICPA auditing literature, and your firm's audit methodology cover the standards a workpaper has to meet. They do not give you the templates calibrated to a broker-dealer engagement, the walkthrough script for a wire transfer control, or the reliance memo the external auditor will actually accept. Internal audit Big Four secondments give you the templates but cost a year of your time. This course gives you the templates and the worked examples without the secondment.

FAQ

Is this CPE eligible?
The course is structured as twelve modules and is suitable for self-study CPE under most state board rules. CPE certification is buyer-managed; the course content meets the technical-knowledge requirement for internal audit and SOX-related CPE categories.
Does this cover IT audit?
Module 8 covers the intersection of cybersecurity audit work with the IT auditor's scope. The course is written for the financial and operational internal auditor who has to coordinate with IT audit, not for the IT auditor running infrastructure tests.
Will the templates work for a wealth management firm or RIA, not a clearing broker-dealer?
Yes. The implementation playbook is hand-built for your specific firm structure and engagement slate. The wealth management and RIA risk universes are covered, including the SEC examination priorities specific to those firm types.
What if my firm uses a specific audit management system like AuditBoard or TeamMate?
The templates are workpaper-format-agnostic. They drop into AuditBoard, TeamMate, Workiva, or any other system. The implementation playbook calls out where the templates need adjustment for your firm's system.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.