Office of Internal Audit
Evaluating Processes. Delivering Insights.
As an independent function within the Division of Enterprise Risk & Integrity (ERI), the Office of Internal Audit provides objective assurance, constructive feedback, and proactive insights designed to protect and improve Virginia Tech’s operational health.
Demystify the audit process from the initial notification to the collaborative final report and follow-up phase.
Review a list of areas that often fall within our engagements and some possible questions to consider.
Ensure your team is aligned with university standards, business conduct, department management responsibilities, IT minimum security standards, and university policies.
Our Services and Review Areas
Risk-Based Audits
We conduct objective evaluations of university activities to assess risk management, internal controls, and governance processes. These reviews help management validate their operational and financial controls are functioning as intended.
Special Reviews & Investigations
We provide evaluations in response to emerging operational issues or management requests. This includes partnering with university leadership to investigate and resolve potential compliance or resource concerns.
Mandated & Regulatory Compliance
We perform independent verifications to ensure university programs align with federal, state, and institutional requirements, protecting Virginia Tech’s public funding, research grants, and institutional standing.
Proactive Advisory Services
You don't have to wait for a scheduled audit to work with us. We provide consulting services for departments undergoing major software implementations, organizational restructuring, or policy changes to help design strong, efficient controls and workflows from day one.
Our Philosophy
An audit is a collaborative evaluation of our university's systems, processes, and controls. By providing independent validation, we strive to create collaborative working relationships with our clients. By focusing on clear communication, we work to ensure there are no surprises in the final product. Our goal is not just a final audit report, but ultimately improved business processes that management chooses to implement to better manage their business risks.
Our Process
We engage with your team through a structured, predictable five-stage process:
During the planning phase, contact with the client is initiated and background information is gathered to gain an understanding of the risks and controls in place. Typically completed through a risk assessment process, this phase is critical to ensure the engagement is appropriately scoped and is initiated with the objectives in mind that will produce the most impact. Once audit objectives and scope are defined, the audit program is created, which is the blueprint for conducting the audit and accomplishing the audit objectives. During this phase you can expect the following:
Notification email and letter: With a few exceptions, clients are notified in writing when their areas is selected for review. This letter may contain a preliminary survey or request for information and typically a request for an entrance conference meeting.
Entrance conference: Depending on the type of engagement, often we will plan an in-person meeting to introduce the audit staff, review the audit process, and discuss our preliminary deadlines. It is also a time for the client to bring concerns forward for consideration.
The evaluation phase of the audit is referred to as fieldwork. This phase includes assessing the adequacy of internal controls and compliance; testing of transactions, records, and resources; and performing other procedures necessary to accomplish the objectives of the audit.
It may be necessary for the audit team to conduct interviews with departmental personnel and to review departmental records and practices; however, efforts will be made to minimize disruptions and cooperate with audit clients to make the audit process as smooth as possible.
Throughout the audit, audit clients will be informed of the audit process through regular status meetings and/or communications. The audit team makes every effort to discuss audit observations, potential issues, and proposed recommendations as they are identified. In some instances, it is necessary to work directly with audit clients to determine or validate the root cause and discuss ways to improve the process.
The final result of every audit is a written report that details the audit scope and objectives, results, recommendations for improvement, and the management corrective action plans.
Draft Report – Audit reports are typically prepared in draft form and distribution is initially limited to the immediate manager of the area so it can be reviewed prior to further distribution of the audit report. If recommendations are made, written responses detailing the following are requested of the audit client and are included in the final audit report. Corrective actions includes:
- A corrective action plan to resolve the issue and its root cause,
- The person responsible for implementing the corrective action, and
- An expected implementation date.
Closing Meeting – If necessary, a closing meeting will be held to provide an opportunity to resolve any questions or concerns the audit client may have about the audit results and to resolve any other issues before the final audit report is released.
Final Audit Report – The final audit report is addressed to the leadership of the area/process under review and the relevant senior management. The final report distribution will be discussed during the closing meeting. Lastly, final audit reports are provided to the next Board of Visitors' Compliance, Audit, and Risk Committee at the next appropriate meeting.
Internal Audit performs a limited follow-up review to verify the completion of the action plans and report their completion to executive management and the Compliance, Audit, and Risk Committee of the Board of Visitors. The timing of this review is based on the time frames included in management’s action plans included in the final report.