Why pre-screen internal auditors before the audit committee interview
Internal audit is unusual in that a comfortable auditor is a warning sign. The function exists to surface what the business has not, which means the work involves telling senior people something they did not want reported. Candidates who describe only positive relationships with management, and audits that consistently found things well controlled, may have been effective or may have been managed. A short screen asks for the finding that was resisted, which is the fastest way to tell.
What actually matters when screening Internal Auditor candidates
- 01
Technical command
Check command of IIA Standards, COSO framework, SOX 404 control testing, walkthroughs, sampling methodology, and whether they can define control design versus operating effectiveness testing.
- 02
Deals and deliverables that closed
Probe completed audits: scope, entity or process (procure-to-pay, revenue recognition, IT general controls), findings raised, and management action plans they tracked to closure.
- 03
Risk judgement
Assess how they build the annual audit plan from a risk assessment, rate findings as high or moderate, and handle pushback from a defensive process owner.
- 04
Explaining it to decision-makers
Test how they present issues to the audit committee, CFO, or external auditors: draft report clarity, root cause framing, and negotiating realistic remediation dates.
Pre-screening questions to ask Internal Auditor candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
Controls and standards
3 questions01Can you describe your experience designing, implementing or testing internal controls?
Listen forSpecific control types tested with the method named, plus awareness of the difference between a control existing and operating effectively.
Controls described as documented procedures, with no distinction between design and operating effectiveness.
02Which kinds of audit are you most experienced in?
Listen forA clear primary area among operational, financial, compliance and technology, with an honest level on the rest rather than claiming all.
Claims equal depth across every audit type, or an area named with no engagements to describe.
03Which audit software are you familiar with, and how do you use it?
Listen forNamed tooling used for working papers and testing, plus any data analysis they perform themselves rather than requesting from another team.
Tooling named with no working use, or all data extraction dependent on someone else.
Audits with findings
3 questions04Can you describe a situation where you identified a significant control weakness and how you addressed it?
Listen forA real weakness with the exposure quantified, the recommendation made, and whether it was implemented rather than only accepted.
Findings raised with no follow-up, or weaknesses described in general terms with no exposure attached.
05Can you describe a time your attention to detail led to detecting a discrepancy?
Listen forA specific discrepancy with what they were testing against when they found it, and how they escalated once it looked material.
Attention to detail claimed as a trait with no example, or a discrepancy that someone else identified first.
06What is your approach to investigating suspected fraudulent activity?
Listen forEvidence preserved before anyone is alerted, the right people involved early, and awareness of where audit stops and investigation begins.
Would confront the individual directly, or no awareness of when to hand over to a specialist function.
Rating real risk
3 questions07What is your process for planning an audit?
Listen forScope built from where the business is exposed, with something deliberately excluded and a reason given for the exclusion.
Plans driven entirely by rotation, or scope determined by what management suggested should be looked at.
08Do you have experience developing an annual audit plan?
Listen forA risk assessment behind the plan with coverage decisions explained, plus how they handled a request to add or drop an area mid-year.
Annual plans copied forward, or areas dropped at management request with no committee visibility.
09Can you describe your experience with risk management and process improvement?
Listen forRecommendations that were practical enough to be implemented, with a case where they moderated a recommendation after hearing the operational cost.
Recommendations that were never implemented, or no engagement with whether a control was workable.
Facing management
3 questions10Are you comfortable presenting your findings to senior management?
Listen forA finding that was resisted, with how they held it, what evidence they relied on, and how it was ultimately reported upward.
Only positive relationships described, or a finding softened after management objected to it.
11How do you ensure objectivity and impartiality during an audit?
Listen forPractical safeguards such as declaring prior involvement or rotating off an area, rather than a general commitment to independence.
Objectivity asserted with no safeguards, or auditing an area they previously worked in with no disclosure.
12Describe a challenging audit you conducted and what made it challenging.
Listen forDifficulty such as withheld information or an uncooperative area, with how they got what they needed and who they escalated to.
Challenge described as volume or deadline alone, or an audit abandoned because access was refused.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical command
35%5Cites COSO components by name, explains attribute sampling sizes, and distinguishes design from operating effectiveness testing without prompting.
Deals and deliverables that closed
25%5Names specific audits led end to end, quantifies findings by rating, and shows remediation verified rather than just reported.
Risk judgement
25%5Links audit coverage to a documented risk universe and defends a high-rated finding with evidence rather than softening it.
Explaining it to decision-makers
15%5Writes findings with condition, criteria, cause, effect, and recommendation; explains impact in business terms owners accept.
A comfortable auditor is a warning sign in this function, and interviews reward comfort. A one-way video screen asks for the finding that management pushed back on.
Try it on HirevireScreening FAQ
Process basics
How long should a pre-screening round for an internal auditor take?
Fifteen minutes across eight to ten questions, answered async. Enough to establish audit type and depth, hear one significant control weakness they found, and check how they handled management resistance.
How much should certifications count?
They confirm methodology and are often expected for the role. They tell you nothing about whether someone will report an uncomfortable finding. Ask about a disputed finding directly rather than reading the qualification as evidence of independence.
Evaluating answers
What is the strongest signal when screening an internal auditor?
A finding management resisted. Auditors doing the job properly have all had one, and can describe how they held it, what evidence they relied on, and how it was ultimately reported. An unbroken record of agreed findings is worth asking about.
How do I judge their risk rating?
Ask how they built an audit plan. The useful answer starts from where the business is actually exposed, not from what is easy to test or what was audited last year. Plans driven by rotation alone tend to miss the areas nobody has looked at.
























