← All finance profiles
βœ…

Audit & Assurance

Independently verifying that the numbers β€” and the controls behind them β€” actually hold up.

Overview

Auditors (internal or external) test whether a company's financial statements and internal controls are accurate and reliable β€” sampling transactions, assessing risk areas, and forming an independent opinion. It's a role built on skepticism, methodology, and a genuinely thorough understanding of accounting standards and control frameworks like SOX.

Career path

Typically comes after

This profile

Audit & Assurance

Typically leads to

Audit ManagerPartner / Head of Internal Audit

Key skills required

Internal Controls TestingAudit SamplingRisk AssessmentSOX ComplianceGAAP/IFRS

Audit & Assurance interview questions

What's the difference between internal and external audit?+

Internal audit is an independent function within the company that evaluates risk management, controls, and governance processes, reporting to the audit committee or board β€” its purpose is improving the organization's own operations. External audit is performed by an independent outside firm to provide an opinion on whether the financial statements are fairly presented, primarily for the benefit of investors, regulators, and other outside stakeholders.

Walk me through the audit process from planning to issuing an opinion.+

Planning: understand the client's business, assess risk areas, and set materiality. Risk assessment: identify where financial statements are most likely to be materially misstated. Fieldwork: perform tests of controls and substantive procedures on account balances and transactions. Conclude: evaluate whether evidence gathered supports the financial statements, resolve any issues found, and issue the audit opinion based on the overall conclusion.

What is materiality in an audit context, and how is it determined?+

Materiality is the threshold at which a misstatement would be large enough to influence the decisions of someone relying on the financial statements. It's usually set as a percentage of a benchmark like pre-tax income, revenue, or total assets, chosen based on which metric users of the statements care most about, then adjusted with professional judgment for qualitative factors like fraud risk.

What's the difference between a test of controls and a substantive test?+

A test of controls checks whether a control is designed properly and operating effectively β€” for example, verifying that invoices actually require a second approval above a certain dollar amount. A substantive test directly examines the accuracy of an account balance or transaction, like confirming a receivable balance directly with a customer. Auditors rely more on substantive testing when controls are weak or unreliable.

Explain the concept of audit risk and its three components.+

Audit risk is the risk that the auditor issues an unqualified opinion on financial statements that are actually materially misstated. It's a function of inherent risk (susceptibility of an account to misstatement absent controls), control risk (the chance a control fails to prevent or detect a misstatement), and detection risk (the chance the auditor's own procedures fail to catch a misstatement) β€” audit procedures are designed to keep detection risk low enough to bring overall audit risk to an acceptable level.

What would you do if you found evidence of potential fraud during an audit?+

I'd document the evidence carefully, escalate immediately to the engagement manager/partner rather than investigating alone or confronting the client directly, and follow the firm's fraud response protocol β€” which typically involves expanding procedures, involving forensic specialists if needed, and considering reporting obligations. This isn't a judgment call to make solo at the staff level.

What's the difference between an unqualified, qualified, and adverse audit opinion?+

An unqualified (clean) opinion means the financial statements are fairly presented in all material respects. A qualified opinion means there's an exception β€” a specific area where the statements aren't fairly presented or where the auditor couldn't obtain sufficient evidence β€” but the rest of the statements are fine. An adverse opinion means the financial statements as a whole are materially misstated and not fairly presented.

How do you approach auditing an account balance that relies heavily on management estimates?+

I'd evaluate the reasonableness of the methodology and key assumptions management used, compare the estimate to independent data where available, look at how accurate similar estimates have been historically, and consider whether management has an incentive to bias the estimate in a particular direction β€” estimates are inherently more subjective, so they get more professional skepticism, not less.

What's the purpose of a management representation letter?+

It's a formal letter from management confirming, in writing, key representations made during the audit β€” that they've disclosed all relevant information, that the financial statements are their responsibility, and specific assertions about certain accounts. It doesn't replace audit evidence, but it documents management's accountability and is required audit evidence in itself.

Walk me through how you'd test the existence and valuation of inventory.+

For existence, I'd observe a physical inventory count (or test counts if I can't attend the full count), tracing selected items from the floor to the inventory records and vice versa. For valuation, I'd test that costs are calculated correctly per the company's stated method (FIFO, weighted average, etc.) and assess whether any inventory needs to be written down for obsolescence or below net realizable value.

What's SOX 404, and what does it require of management and auditors?+

Section 404 of the Sarbanes-Oxley Act requires management to assess and report on the effectiveness of internal controls over financial reporting, and for larger public companies, requires the external auditor to independently test and opine on that internal control effectiveness as well β€” not just on the financial statements themselves.

How do you maintain independence and objectivity when auditing a client you've worked with for years?+

By actively applying professional skepticism rather than assuming familiarity means lower risk β€” treating each year's evidence on its own merits, staying alert to changes in the client's business or incentives, and following firm rotation policies for engagement partners/staff, which exist precisely because long tenure can erode independence if not actively managed.

What's the difference between inherent risk and control risk?+

Inherent risk is the susceptibility of an account or transaction to material misstatement before considering any controls β€” for example, cash is inherently higher risk than fixed assets because it's more liquid and easier to misappropriate. Control risk is the risk that the client's own internal controls fail to prevent or detect a misstatement. Together they determine how much substantive testing the auditor needs to do.

How would you respond if a client pressured you to change a finding?+

I'd revisit the evidence to make sure the finding is correct, and if it is, I'd escalate the pressure to my engagement manager or partner rather than making a unilateral call β€” auditor independence exists precisely so individual staff aren't put in a position to cave to client pressure on their own.

What audit procedures would you perform to test revenue recognition?+

Understand the client's revenue recognition policy and whether it complies with the applicable standard (like ASC 606/IFRS 15), test a sample of transactions against contracts and shipping/delivery evidence to confirm revenue was recognized in the right period, and pay particular attention to transactions near period-end, since cutoff errors around revenue are a common area of both error and fraud risk.

What's a management letter, and what typically goes into one?+

A management letter (sometimes called a letter of recommendations) communicates control deficiencies or process improvement suggestions identified during the audit that don't rise to the level of a material weakness requiring formal reporting, but are still worth flagging to management β€” it's a value-add byproduct of the audit, separate from the audit opinion itself.

Tell me about a time you disagreed with a senior team member's audit conclusion. How did you handle it?+

A strong answer describes raising the disagreement directly and professionally, backed by the specific evidence or standard supporting your view, rather than either staying silent or escalating unnecessarily. Firms have formal disagreement-resolution processes for a reason β€” showing you'd use good judgment about when a concern is worth raising, and how to raise it constructively, matters more than being right.

Typical salary range

3–5 years

β‚Ή15-25 lakhs / year

5–10 years

β‚Ή20-45 lakhs / year

10–15 years

β‚Ή40-90 lakhs / year

15+ years

β‚Ή50-250 lakhs / year

Basic annual salary, India, excluding bonuses/incentives. Source: Michael Page India Salary Guide 2026 (Finance & Accounting). Get a personalized estimate from your resume β†’

Open roles

Get notified about new Audit & Assurance openings

Leave your email and resume β€” we'll reach out directly when a matching role opens.

Test your knowledge

A quick AI-generated quiz on the skills this profile actually needs.

AI isn’t configured for this app yet. Ask your admin to set it up β†’

Not sure this is the right fit for you?

Check your compatibility across all profiles β†’