Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Audit types

There are many types of audits and each of the audit types has a specific use in an audit engagement.

Audit TypeDescription
Internal AuditAn internal audit checks a company's internal controls, corporate governance, and accounting processes.
External AuditAn external audit is an independent examination of the financial statements prepared by the organisation.
SOX AuditA Sarbanes Oxley (SOX) compliance audit is a measure of how well your company manages its internal controls. While SOX doesn't specifically mention information security, for practical purposes, an internal control is understood to be any type of protocol dealing with the infrastructure that handles your financial data.
IT AuditAn IT audit is the examination and evaluation of an organization's information technology infrastructure, policies and operations.
Financial AuditA financial audit is an independent, objective evaluation of an organization's financial reports and financial reporting processes. The primary purpose for financial audits is to give regulators, investors, directors, and managers reasonable assurance that financial statements are accurate and complete.
Compliance AuditA compliance audit is an independent evaluation to ensure that an organization is following external laws, rules, and regulations or internal guidelines, such as corporate bylaws, controls, and policies and procedures.
Certification AuditA certification audit is an audit your registrar conducts to verify conformance against the ISO 9001 standard before they issue your official ISO 9001 certificate.
Regulatory AuditThe aim of a regulatory audit is to verify that a project is compliant with regulations and standards.
Operational AuditAn operational audit is an examination of the manner in which an organization conducts business, with the objective of pointing out improvements that will increase its efficiency and effectiveness.
Continuous AuditA continuous audit is an internal process that examines accounting practices, risk controls, compliance, information technology systems, and business procedures on an ongoing basis. Continuous audits are usually technology-driven and designed to automate error checking and data verification in real-time.
Vendor AuditA vendor audit is performed for a company that aims to attain an objective assessment of its contractors' or vendors' compliance to the terms, conditions and intent of the contracts or agreements between two entities.
Customer AuditA customer audit is a detailed review of how your company is perceived by its customers, a review of each customer's needs, and an evaluation of the role your company is playing in each of your customer's businesses.
Store AuditA store audit assesses the health of your retail location using hard data. Retailers, staff, or a third party combs through your store or pop-up shop to collect information on what's working and what's selling or what isn't.
Quality AuditA Quality audit is the process of systematic examination of a quality system carried out by an internal or external quality auditor or an audit team.
Project AuditA project audit is a formal review of a project, often intended to assess the extent to which project management standards are being upheld. Audits are generally carried out by a specially designated audit department, the Project Management Office, an approved management committee or an external auditor.