Skip to main content
Image coming soon

The Senior Manager Internal Audit Workpaper Quality Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Senior Manager Internal Audit Workpaper Quality Playbook

How a Senior Manager runs a brokerage internal audit so workpapers, issue ratings, and the closing memo survive QA and the audit committee read-out.

You sign off on workpapers your staff drafted. The QA inspector signs off on you. The gap between those two reviews is where careers stall.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

A Senior Manager in Internal Audit at a retail brokerage sits between two reviewers. Above, the Director and the QA function. Below, staff auditors and Senior Auditors whose workpapers you sign. The reviewable artefacts are concrete: the planning memo, the RCM, the test design, the sample selection rationale, the IPE attestation, the exception narrative, the issue rating worksheet, the closing memo, the audit committee one-pager. Each one has a quality threshold that is rarely written down. When QA returns a workpaper with comments, the comments are almost always about the same six things: insufficient rationale for sample size, IPE not addressed, test step does not match the control as written, exception not tied back to root cause, rating not calibrated against the rating definitions, evidence retained does not match what was tested. The skill is reviewing for those six things every time, on every workpaper, without slowing the audit down.

What you walk away with

  • Review a staff auditor's workpaper against six concrete quality criteria in under twelve minutes.
  • Write a planning memo and scoping document the Director signs without rework.
  • Calibrate issue ratings against written definitions so business owners stop negotiating the rating.
  • Defend sample selection logic and IPE controls in a QA inspection without follow-up.
  • Draft a closing memo and audit committee one-pager that names root cause, business impact, and remediation owner in plain English.

The 12 modules

Module 1. The planning memo a Director signs without rework
The planning memo is the artefact that frames the entire audit. This module walks through scope statement, objectives, risk linkage to the audit universe, in-scope and out-of-scope regulations specific to a retail brokerage (Reg BI, Reg S-P, 15c3-3, FINRA 3110, BSA/AML), preliminary RCM, staffing and hours budget, and the kickoff slide the business owner sees. Includes a worked planning memo for a Customer Protection Rule audit and a redline showing common Director rework comments.
Module 2. Scoping that survives the QA challenge
Most QA findings on scoping say the scope was too narrow or the rationale for excluding a process is missing. This module gives the Senior Manager a written scoping framework that ties each in-scope process to a specific risk in the audit universe and each excluded process to a documented rationale. Worked examples on scoping an AML transaction monitoring audit, an IT change management audit, and a new-account opening audit at a retail brokerage.
Module 3. Building an RCM that auditees recognise
The Risk Control Matrix is the spine of the audit. This module covers control identification (entity-level vs process-level vs IT general), control description writing in the active voice with named owner and frequency, mapping controls to risks rather than to assertions, and version control during fieldwork. Includes RCM templates for Reg BI suitability, Customer Protection Rule reserve computation, and the trading platform IT general controls.
Module 4. IPE controls that pass QA on the first read
Information Produced by the Entity is where workpapers fail QA most often. This module walks through the IPE control framework: source system identification, completeness and accuracy testing, parameter and filter review, and the IPE attestation memo. Worked examples on testing a customer transaction extract used to test AML alerts, a reserve computation feed used to test 15c3-3 compliance, and a privileged access listing used to test ITGC.
Module 5. Sample selection rationale that holds up in inspection
Sample size and selection rationale draws the most QA comments after IPE. This module covers attribute sampling for compliance testing, sample size tables tied to control frequency and risk rating, random vs judgemental selection, documenting the selection method, and the bridge from sample exceptions to population conclusions. Includes a sampling rationale template and worked examples on AML alert closure testing and Reg BI account opening testing.
Module 6. Test step design that matches the control as written
A common QA finding is that the test step does not test the control as described in the RCM. This module covers test step writing in the operative voice, mapping each test step to the control description word for word, designing reperformance vs inspection vs observation steps, and the workpaper layout that makes the match self-evident on review. Worked examples across compliance, operations, and IT general controls.
Module 7. Reviewing a staff auditor's workpaper in under twelve minutes
The Senior Manager review is the quality bottleneck. This module gives a six-point review checklist (control matches RCM, test matches control, IPE addressed, sample rationale documented, exception tied to root cause, evidence retained matches what was tested) and a review template that lets a Senior Manager close out a workpaper review in ten to twelve minutes per workpaper. Includes a worked review of a Reg BI suitability testing workpaper with the actual comments the reviewer left.
Module 8. Issue rating calibration that ends the negotiation
Business owners negotiate ratings. This module covers writing rating definitions that leave no room for debate, the rating worksheet that documents impact, likelihood, control failure type and remediation effort, the calibration meeting with the Director, and the language a Senior Manager uses with the business owner when the owner pushes back on a High rating. Worked rating worksheets for an AML monitoring gap, a Customer Protection Rule clerical error, and a privileged access control failure.
Module 9. Exception narrative that names root cause without blame
Exceptions in workpapers either name the root cause or describe the symptom. QA, management, and the audit committee all want the root cause. This module walks through the five-why technique applied to audit exceptions, the exception narrative template that separates observation, condition, criteria, cause, effect and recommendation, and the language that names cause without blaming a named individual. Worked exception narratives on AML, 15c3-3, and ITGC findings.
Module 10. Closing memo and management response that does not bounce
The closing memo is the artefact the business owner signs and the audit committee reads. This module covers the closing memo structure, the management response collection process, drafting the recommendation in language management can implement, the remediation owner naming convention, the target date setting calibration with the Director, and handling pushback from a business owner who wants the issue removed. Includes a worked closing memo for a Reg BI suitability audit.
Module 11. Audit committee one-pager and read-out
The audit committee reads a one-pager, not the workpapers. This module covers the one-pager layout (background, scope, what we tested, what we found, ratings summary, key themes, management response and remediation timeline), the language register the audit committee expects, the slide that names regulatory implications without overstating, and the practice run with the CAE. Includes a worked one-pager for an AML transaction monitoring audit.
Module 12. Preparing for the external QA assessment
Every five years the function gets an external QA assessment under IIA Standard 1312. This module walks the Senior Manager through what the external assessor looks at in workpapers, common findings from external assessments at retail brokerages, the self-assessment a Senior Manager runs on a sample of own audits ahead of the external review, and the remediation plan format. Includes a worked self-assessment on a completed Customer Protection Rule audit.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

A staff auditor's workpaper lands in your review queue and you have ten minutes between meetings.
The business owner pushes back on a High issue rating in the closing meeting.
QA returns three workpapers from the last audit with the same IPE finding.
The audit committee chair asks for the one-pager 48 hours before the meeting.

What you get with this course

  • 12 written modules, each with worked examples on a retail-brokerage audit topic.
  • Workpaper templates: planning memo, scoping document, RCM, IPE attestation, sampling rationale, test program, exception narrative, issue rating worksheet, closing memo, audit committee one-pager.
  • Six-point workpaper review checklist as a printable card.
  • A hand-built implementation playbook sized to your current audit plan, delivered alongside course access.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

Self-paced. Most Senior Managers work through one module per week alongside an active audit.

Templates are downloadable and editable for use on the next audit you scope.

Before and after

Before

You sign workpapers knowing the QA inspector will find the same six things again. Issue ratings get negotiated. The closing memo bounces back from the Director twice.

After

You review a workpaper in twelve minutes against a six-point checklist. Ratings stick because the definitions hold them up. The Director signs the closing memo on the first read.

What happens if you do not address this

Senior Managers who do not raise the quality floor on workpapers, ratings and the closing memo carry their staff's QA findings forward into their own career file. The next external QA assessment is the moment those findings become visible to the audit committee.

Who it is for

Senior Manager, Internal Audit at a U.S. retail brokerage or wealth management firm. Manages 2 to 6 staff and seniors. Owns 4 to 8 audits per cycle across operations, compliance, IT, and shared services. Reports to a Director or VP of Internal Audit who reports to the Chief Audit Executive. Subject to internal QA review and a periodic external QA assessment under IIA standards. CIA or CPA, three to seven years post-qualification.

Who this is NOT for. Not for first-year staff auditors who have not yet led a workpaper. Not for Chief Audit Executives setting strategy. Not for external auditors at a public accounting firm. Not for compliance officers in the first line. Not for SOX 404 process owners in a non-financial-services business.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. About 90 minutes per module. Twelve modules over six to twelve weeks works for a Senior Manager carrying a full audit plan.

Why $199 is the right number

IIA CPE covers theory. Big4 internal audit methodology decks cover process. Neither walks a Senior Manager at a retail brokerage through the actual six review criteria QA inspects, with worked examples on Reg BI, 15c3-3, AML and ITGC, plus the templates you can edit and use on the next audit.

FAQ

Is this CIA or CPE eligible?
The course is content-equivalent to internal audit CPE under IIA guidelines. The Art of Service does not directly issue CIA CPE credits. Your sponsor can recognise self-study hours under most CPE programmes.
Does this cover SOX 404?
The review criteria and workpaper quality framework apply to SOX testing, but the worked examples are on retail brokerage audits (Reg BI, 15c3-3, AML, ITGC), not on financial reporting controls.
Can I share the templates with my staff?
Yes. The templates are licensed for use across your audit team. The course access is per learner.
How is the implementation playbook tailored?
Before access is provisioned, the playbook is hand-built against your current audit plan and the two or three audit areas where workpaper quality matters most this cycle.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.