Limit of Liability/Disclaimer of Warranty: While the publisher and author have used their best efforts in preparing this book, they make no representations or warranties with respect to the accuracy or completeness of the contents of this book and specifically disclaim any implied warranties of merchantability or fitness for a particular purpose. No warranty may be created or extended by sales representatives or written sales materials. The advice and strategies contained herein may not be suitable for your situation. You should consult with a professional where appropriate. Neither the publisher nor author shall be liable for any loss of profit or any other commercial damages, including but not limited to special, incidental, consequential, or other damages.
For general information on our other products and services or for technical support, please contact our Customer Care Department within the United States at (800) 762‐2974, outside the United States at (317) 572‐3993 or fax (317) 572‐4002.
Wiley also publishes its books in a variety of electronic formats. Some content that appears in print may not be available in electronic formats. For more information about Wiley products, visit our web site at
Library of Congress Cataloging‐in‐Publication Data
Names: Catlin, Raven, author. | Watkins, Ceciliana, author.
Title: Agile auditing : fundamentals and applications / Raven Catlin and Ceciliana Watkins.
Description: Hoboken, New Jersey : Wiley, [2021] | Includes bibliographical references and index.
Identifiers: LCCN 2021015254 (print) | LCCN 2021015255 (ebook) | ISBN 9781119693321 (hardback) | ISBN 9781119693482 (adobe pdf) | ISBN 9781119693468 (epub)
Subjects: LCSH: Auditing. | Agile project management.
Classification: LCC HF5667 .C325 2021 (print) | LCC HF5667 (ebook) | DDC 657/.45–dc23
LC record available at
LC ebook record available at
Cover Design: Wiley
Cover Image: © Casper1774 Studio / Shutterstock
We dedicate this book to our families and all auditors in search of knowledge and making the world a better place.
Serving as a chief audit executive and then CEO of The Institute of Internal Auditors (IIA), I have strived to learn new concepts, develop new ideas, and advocate for new ways to approach challenges and opportunities. Continuous learning is what brings me to this book, Agile Auditing: Fundamentals and Applications, by Raven Catlin and Ceciliana Watkins, two remarkable individuals who epitomize the internal auditors of today and the future. In this book, Raven and Ceciliana offer a fresh approach to what our profession must do to become and remain relevant to our stakeholders by adopting an Agile mindset.
I have discussed the importance of being nimble and turning problems into opportunities over more than a decade, through my books, in presentations around the world, and in my weekly blog Chambers on the Profession. To implement Agile auditing, internal auditors must demonstrate intellectual curiosity and open‐mindedness, two attributes discussed in my book Trusted Advisors: Key Attributes of Outstanding Internal Auditors. Additionally, Agile auditors must have the relational and professional attributes addressed in the book.
After reading Agile Auditing: Fundamentals and Applications, I gained new perspectives and reinvigorated my firm belief that, to be relevant, we must continuously evolve who we are as internal auditors and how we add value.
We are at a critical juncture in our profession. Being Agile also means being resilient amid every advancing risk. We must embrace fresh ideas and perspectives to execute bold, decisive, and Agile strategies to address the new frontier. Amid the COVID‐19 pandemic, the need for social distancing around the globe challenged the management of audit activities, from risk assessments to testing, reporting, and the administration of the audit activity, including recruiting, retention, and training.
In a virtual environment, internal auditors face myriad challenges in how they address and complete their work, from different methods of communications to limitations on travel and physical access. The pandemic has certainly tested the concept of Agile auditing, but the good news is that, amid a changing risk landscape, we've learned that it actually can be most effective.
I met Raven Catlin in 2002 at The IIA's Volunteer Instructor Development Program. Raven stood out. She successfully completed the program and impressed me as a knowledgeable, articulate, experienced, and innovative auditor. As an instructor, Raven presents an effective method to deliver concepts and influence others to adopt new practices. This book showcases those attributes. It offers a framework for audit functions to add value and remain relevant. I find Raven and Ceciliana's Agile audit framework to be distinct in that it is not a method that simply provides ideas. It is truly a framework that's adaptable and allows audit teams to incorporate practices and tools into an Agile audit methodology they create and customize.
Moreover, the framework provides a structure and guidance for greater collaboration with audit customers/clients, a critical tenet of internal auditing. It integrates clients as members of the team from day one, and it acknowledges that, without this fully involved engagement, the audit cannot proceed as an Agile audit. Further, the framework focuses on creating value from the audit client's perspective. It centers the Agile audit on the value proposition, which makes achieving organizational objectives a foundation point.
It also helps organizations increase overall resiliency, which is critical in this new normal. The audit must deliver results more quickly and provide insights that will help reduce detrimental risks and achieve objectives. The flexibility provided by implementing this Agile approach helps management and auditors collaborate in risk identification, resulting in better‐managed businesses and organizations. A vital aspect of this framework is that it uses a risk universe, rather than an audit universe, to determine priorities and an Agile audit plan.
As I have discussed in many of my blogs, tweets, and books, adapting and keeping an eye out for the most critical risk is crucial for our profession and our organizations. Continuous risk thinking is a lesson I learned early in my career and is vital to Agile auditing success. Conventional planning for internal auditing doesn't hold up in today's environment because it cannot deal with unexpected risks.
In 1990, I was in the middle of an old‐school, annual plan as chief audit executive for the U.S. Army when Iraq invaded Kuwait. Risks that very few saw coming had suddenly appeared. I had to toss my annual audit plan and assess risks continuously, so that I could identify and reset our internal audit priorities. Traditional methods and routines of conducting audits based on plans that are six months to a year old are in the past. We need to assess risk continuously, and we must have new information to keep our audit plan up to date.
I wish that I had had this book back in 1990 as a guide not only for myself but also for my audit department and colleagues. The framework and information provided in this book provide the tools and ideas to spark your creative juices to make your audit activities successful today and in the future. In turn, it will allow you to continuously set your antenna high and be better prepared to address new risks