Audit CVs are read by people who assess evidence for a living, which makes vagueness unusually costly. Reviewers want to know what you audited, under which standards, at what level of independence, and what happened to your findings afterwards. A finding that was raised and never closed is a different story from one that changed a control.
The internal and external distinction matters more than most applicants assume. External audit is a statutory opinion under ISA, delivered against a deadline and reviewed by a partner. Internal audit is an assurance function reporting to an audit committee, with a risk-based annual plan. The skills overlap; the CVs should not read the same.
The strongest audit CVs also show planning judgement. Anyone can execute a work programme. Deciding where the risk sits, choosing a sample that supports the conclusion, and being able to defend that choice in review is the part that takes years to develop.
This example is written for an internal auditor with five years of experience in financial services who trained in external audit.
hamza.qureshi@example.co.uk+44 7700 900377London, United Kingdomlinkedin.com/in/example-hamza-qureshi
Profile
Internal auditor with five years of experience, trained in external audit at a mid-tier firm and now leading risk-based reviews in a retail bank. Deliver six to eight audits a year across treasury, procurement and third-party management, present findings to the audit committee, and have introduced full-population testing using IDEA.
Professional Qualifications
ACCA (Association of Chartered Certified Accountants) – QualifiedMarch 2022
ACCA
Certified Internal Auditor (CIA) – Parts 1 and 2 passed, Part 3 bookedJune 2025
IIA
IDEA Data Analysis – Level 2October 2023
CaseWare
Core Skills
Audit PracticeRisk-based planning, Scoping and terms of reference, Walkthroughs, Controls testing, Sampling methodology
Standards & FrameworksIIA International Standards, ISA (UK), COSO, Three lines model
Risk & ComplianceRisk assessment, Fraud risk indicators, AML control testing, Policy compliance
Tools & AnalyticsIDEA, Excel (Power Query), SQL extraction, TeamMate+, Power BI
Professional Experience
Senior Internal AuditorJune 2022 – Present
Cavendish Retail Bank · London, United Kingdom
•Lead six to eight risk-based internal audits a year across treasury, procurement and third-party management, covering business units with £30m to £120m of annual spend.
•Tested the payment authorisation control across a stratified sample of 60 transactions selected by value band, identifying nine payments above the £50k threshold released on a single approval.
•Built an IDEA routine testing the full population of 240,000 expense claims against duplicate, weekend-submission and round-sum criteria, replacing a 40-item sample and identifying £62k of claims for recovery.
•Presented four high-rated findings to the audit committee, agreed remediation dates with process owners, and confirmed through follow-up testing that three were closed within the agreed period.
•Rewrote the third-party assurance programme after a supplier incident, introducing tiering by criticality so that annual review effort is concentrated on the 12 suppliers that matter most.
•Supervise one auditor on fieldwork and review their working papers before manager review.
Audit Senior (External Audit)September 2019 – May 2022
Broadmere & Hale LLP · Birmingham, United Kingdom
•Ran fieldwork on statutory audits under ISA (UK) for manufacturing, charity and owner-managed clients with turnover from £4m to £85m.
•Owned the revenue, inventory and payroll cycles on eight audits a year, including cut-off testing and stock attendance at four sites.
•Prepared the audit files reviewed by the engagement manager and partner; two files were selected for internal quality review and passed without significant points.
•Supervised two trainees on site and set their work programmes for the smaller cycles.
•Drafted the management letter points for three clients, including a segregation of duties weakness in purchase ordering that was remediated before the following year end.
Education
BSc (Hons) Accounting and FinanceSeptember 2016 – June 2019
University of Birmingham · Birmingham, United Kingdom
First Class Honours
Professional Memberships
ACCAApril 2022 – Present
Member
Chartered Institute of Internal AuditorsAugust 2022 – Present
Affiliate
Languages
EnglishNative
UrduC1
PunjabiB2
Audit Officer / Auditor example on the Executive layout. All details are fictional and shown for demonstration only.
What recruiters expect
Before writing anything, it helps to know what the person reading is checking for. In this field that is usually a short, specific list:
A clear statement of internal versus external audit, and the standards you work under (ISA, IIA Standards, or local equivalents).
Portfolio detail: how many audits a year, what size, which business areas, whether you led or supported.
Sampling and testing approach, including why the sample was chosen.
What happened to your findings - agreed actions, remediation tracking, follow-up testing.
Stakeholder level. Reporting to a head of department is different from presenting to an audit committee.
Recommended CV structure
This is the running order the example uses. It is a starting point rather than a rule, but the order reflects what tends to be read first in this profession.
Profile — Three or four lines positioning you for the role.
Professional Qualifications — Completed certifications with the issuing body.
Core Skills — Grouped skills, for example "Languages" and "Tooling".
Professional Experience — Paid roles, in reverse chronological order.
Education — Degrees, diplomas and school-leaving qualifications.
Professional Memberships — Bodies you belong to, with membership numbers where relevant.
Continuing Professional Development — Structured training posts and courses.
Languages — Spoken languages with CEFR levels.
Sections worth adding
Special Reviews — Use for investigations, data analytics pilots or first-time audits of a new area.
Skills worth including
Grouped rather than listed in one block. Grouping makes a long list readable and shows that you can tell the difference between the things you use daily and the things you have touched.
Audit Practice
Risk-based audit planning · Scoping and terms of reference · Walkthroughs · Controls design and effectiveness testing · Sampling methodology · Working paper documentation
Standards & Frameworks
IIA International Standards · ISA (UK) · COSO Internal Control Framework · IFRS · SOX 404 · Three lines model
Audit findings and root cause analysis · Management action tracking · Audit committee papers · Follow-up testing · Closing meetings
Tools & Analytics
IDEA · ACL Analytics · Excel (Power Query, pivot analysis) · SQL for data extraction · TeamMate+ · Power BI
Beyond the technical list: Delivering unwelcome findings without losing the relationship, Interviewing process owners, Writing clearly for a non-specialist audit committee, Holding a position under challenge, Coaching junior auditors through fieldwork. These belong inside your experience bullets, demonstrated, rather than in a list of adjectives.
Example professional summary
Three or four lines, positioned for the role rather than describing your personality. Two versions you can adapt:
Internal auditor with five years of experience, trained in external audit at a mid-tier firm and now leading risk-based reviews in a retail bank. Deliver six to eight audits a year across treasury, procurement and third-party management, present findings to the audit committee, and have introduced full-population testing using IDEA.
ACCA-qualified auditor with external audit experience across manufacturing and not-for-profit clients under ISA (UK), currently completing the Certified Internal Auditor qualification. Comfortable running fieldwork independently and supervising a junior on site.
Writing your experience
The difference between a CV that gets a call and one that does not is almost always in the bullet points. Each pair below shows a real rewrite of the kind of line that appears on most CVs in this field.
Weak
Performed internal audits across the business.
Stronger
Lead six to eight risk-based internal audits a year across treasury, procurement and third-party management, each covering business units with £30m to £120m of annual spend.
Volume, business areas and scale, which together let a reviewer place your level immediately.
Weak
Tested internal controls.
Stronger
Tested the payment authorisation control across a stratified sample of 60 transactions selected by value band, and identified that 9 payments above the £50k threshold had been released on a single approval.
Shows sampling rationale and a concrete finding rather than an assertion of testing.
Weak
Reported findings to management.
Stronger
Presented four high-rated findings to the audit committee, agreed remediation dates with the process owners, and confirmed through follow-up testing that three were closed within the agreed period.
Carries the finding all the way through to verified closure, which is what assurance actually means.
Weak
Used data analytics in audits.
Stronger
Built an IDEA routine to test the full population of 240,000 expense claims against duplicate, weekend-submission and round-sum criteria, replacing a 40-item sample and identifying £62k of claims for recovery.
Full-population testing versus sampling is a genuine methodological upgrade, and the recovery figure makes it tangible.
Taken from the example
The sample CV for this profession is fully written. A few sections from it, so you can see the level of specificity that works:
Experience
Senior Internal Auditor, Cavendish Retail Bank
Lead six to eight risk-based internal audits a year across treasury, procurement and third-party management, covering business units with £30m to £120m of annual spend.
Tested the payment authorisation control across a stratified sample of 60 transactions selected by value band, identifying nine payments above the £50k threshold released on a single approval.
Built an IDEA routine testing the full population of 240,000 expense claims against duplicate, weekend-submission and round-sum criteria, replacing a 40-item sample and identifying £62k of claims for recovery.
Presented four high-rated findings to the audit committee, agreed remediation dates with process owners, and confirmed through follow-up testing that three were closed within the agreed period.
Education
BSc (Hons) Accounting and Finance, University of Birmingham — First Class Honours
Certifications and registration
ACCA (Association of Chartered Certified Accountants) – Qualified — ACCA
Certified Internal Auditor (CIA) – Parts 1 and 2 passed, Part 3 booked — IIA
IDEA Data Analysis – Level 2 — CaseWare
Common mistakes
Findings with no outcome
Raising an issue is half the job. Say what was agreed, by when, and whether follow-up testing confirmed it was fixed.
No sense of audit volume or size
Six audits a year on £50m business units is a different profile from twenty compliance checks. Give the numbers.
Blurring internal and external audit
They are hired for separately. If you have done both, present them as distinct phases rather than merging the vocabulary.
Listing standards without applying them
"COSO, ISA, IIA Standards" as a bare list is unconvincing. One sentence showing you used a framework to scope a review is worth more than the list.
Confidentiality breaches
Never name the client, the amount of a fraud, or specific control weaknesses in a way that identifies the organisation. Reviewers notice, and it counts against you.
ATS considerations
Applicant tracking systems behave differently by sector, and generic advice is often wrong for a given field. These points are specific to audit officer / auditor applications:
Use the words "internal audit" and "external audit" explicitly, even if the distinction seems obvious from context.
Spell out qualification names in full: "Certified Internal Auditor (CIA)", "ACCA".
Include "internal controls" and "controls testing" as separate phrases - adverts split between them.
Name the audit management system (TeamMate+, AuditBoard, Pentana) if you have used one; it is a common differentiator.
Write "anti-money laundering (AML)" in full once if you have AML audit experience.
The Minimal ATS layout is built for this, and the ATS guide covers what parsers do to a file in more detail.
Questions about audit officer / auditor CVs
Should I move from external audit to internal audit on my CV?
Present the external audit years as training and technical grounding, then show risk-based thinking in your recent work. Employers value the transition; they just need to see you have adjusted from opinion work to assurance work.
Which qualification carries the most weight?
For internal audit, the CIA is the specialist qualification and the IIA membership matters. For external audit, ACA or ACCA is the standard route. Many auditors end up holding one of each.
How do I write about a fraud investigation?
Describe your role, the methodology and the outcome category, without the amount, the client name or details that identify individuals. "Supported a payroll fraud investigation, including full-population analysis of duplicate bank details" is enough.
How much detail about working papers is useful?
Enough to show you document to a reviewable standard. One line about working paper quality or review notes is sufficient; a paragraph is not.
Is IT audit experience worth mentioning?
Yes - access controls, change management and segregation of duties testing are in demand and often missing from finance-trained auditors. Say what you tested rather than claiming general IT audit capability.