- September 7, 2026
- Sachin Aggrawal
- 0
Table of Content
- 1. What Are the Four Types of Audit Within Audit and Regulatory Compliance?
- 2. What Are the Four Stages of Compliance in an Audit and Regulatory Compliance Programme?
- 3. What Does Protiviti's Approach to Compliance Actually Look Like?
- 4. How Does AI Governance Fit Into Audit and Regulatory Compliance?
- 5. What Does a Genuinely Effective Programme Look Like Right Now?
- 6. Conclusion
Many organisations run two separate departments for audit and regulatory compliance. Quarterly meetings and shared risk registers are common, but they don’t automatically create alignment. The real challenge appears when a regulator or client asks for evidence on short notice and the disconnect between audit and compliance becomes apparent.
It doesn’t have to work that way. Audit and regulatory compliance function well together when someone actually designs them to. Audit gives independent assurance that controls work the way they’re supposed to. Compliance defines what those controls are meant to achieve in the first place. Line the two up around the same risk framework, the same control taxonomy, the same evidence standard, and the organisation can answer a regulator’s question in minutes, because the same paperwork backing an internal audit finding is also what backs the compliance certification.
This guide explains the four types of audit, the four stages of compliance, how Protiviti approaches modern compliance programmes, and the regulatory developments organisations should be preparing for today rather than reacting to later.
What Are the Four Types of Audit Within Audit and Regulatory Compliance?
Four types show up across most audit and regulatory compliance programmes: internal audit, external audit, compliance audit, and forensic audit. Different purpose, different team, different output, different standard, for each one.
This distinction isn’t academic. A compliance audit run by a regulator and an internal audit run by the company’s own team can look at the exact same control and produce very different conversations, because the evidence bar, the consequences of a finding, and the relationship between auditor and organisation are nothing alike.
- Internal audit helps boards understand whether controls are operating effectively rather than simply existing on paper. That responsibility is now guided by the IIA’s Global Internal Audit Standards, which came into effect in January 2025 and replaced the International Professional Practices Framework with 15 principles covering every aspect of the internal audit function. Internal audit today covers operational risk, environmental compliance, procedural efficiency, fraud management, health and safety, and regulatory obligations, and it’s usually where audit and regulatory compliance overlap most visibly. Run an internal audit of an organisation’s GDPR data handling controls, and you’re running an audit and a compliance review at the same time, whether anyone labels it that way or not.
- External audit is the statutory review of financial statements by an independent firm, producing an opinion on whether those statements give a true and fair view. It isn’t a full regulatory compliance review by design, but it increasingly bumps into compliance territory anyway, going concern assessments in regulated sectors, COSO reporting for listed companies, sector-specific disclosures for financial institutions.
- Compliance audit formally checks whether policies, processes, and controls actually meet outside requirements, statutory ones like data protection or financial services law, contractual ones like a customer’s supply chain standards, or voluntary ones like ISO certification. According to Vanta’s 2024 State of Trust report, 65% of organisations report stakeholders asking them to demonstrate compliance directly, and the compliance audit is the mechanism that produces that proof. It can run internally through the compliance function or externally through a regulator, a certifying body, or a client doing vendor due diligence, and the external version is where audit and regulatory compliance risk bites hardest, because the findings sit entirely outside the organisation’s control and can end in regulatory action, a lost certification, or a terminated contract.
- Forensic audit exists to investigate something specific, suspected fraud, financial misconduct, a regulatory breach, a dispute. It’s audit technique applied inside a legal evidentiary context, and the output often ends up in regulatory proceedings, litigation, or disciplinary action. Usually it’s triggered by something else first: an anomaly internal audit or compliance monitoring flags, a whistle-blower report, a customer complaint, a regulator’s inquiry.
What Are the Four Stages of Compliance in an Audit and Regulatory Compliance Programme?
The structure of an audit and regulatory compliance programme is consistent whether the review is internal or external. It begins with scoping and planning, moves through evidence gathering, testing, and reporting, and concludes with remediation and follow-up. Weakness at any stage reduces the value of the assessment as a whole.
Stage 1- Scoping and planning:
This decides what gets covered and what doesn’t, based on which regulations actually apply, which standards the organisation has signed up for (contractually or otherwise), and where the real risk sits so resources go to the right place. Bad scoping is probably the single most common failure across compliance programmes generally. Scope a GDPR audit to cover only customer-facing data and skip employee data, supplier contracts, and third-party processor transfers, and you’ve produced a review that’s accurate inside its own boundary and functionally useless, because the boundary was drawn around the wrong risks. For organisations spread across multiple jurisdictions, scoping has to account for overlapping but not identical regulatory frameworks in each location, a bank operating across the EU, the US, and Singapore is answering to three different rulebooks at once, and the audit and regulatory compliance scope needs to reflect that reality honestly.
Stage 2- Evidence gathering and testing:
Gathering means pulling together documentation, system records, whatever demonstrates a control is working as required. Testing means actually checking whether that control does its job, not just confirming the policy exists on paper. This is where a lot of compliance work quietly falls short. A policy exists, the procedure describes the control, the log shows it ran, fine, but did the control actually catch what it was built to catch? Testing that stops at documentation review and skips outcome checking produces evidence that looks thorough and isn’t.
Stage 3- Analysis and reporting:
Here the evidence gets mapped against requirements to find the gaps, and a good analysis separates three distinct situations, controls designed properly and working well, controls designed properly but running inconsistently, and controls that were never designed to meet the requirement in the first place regardless of how smoothly they’re running. The report itself needs to be specific enough to actually drive action. “Data protection controls need improvement” tells nobody anything useful. “The data retention deletion process misses structured CRM backup data in 23% of tested cases, breaching Article 5(1)(e) of GDPR” is the kind of finding that gets fixed.
Stage 4- Remediation and follow-up:
Fixing gaps through control redesign, process changes, system updates, or training, then confirming it actually worked. A programme that produces solid findings but has no real remediation tracking just lets the same gaps carry across audit cycles year after year, with a management comment that says “in progress” every single time. Real remediation in an audit and regulatory compliance context needs a named owner, a real deadline, and someone independent of that owner confirming closure actually happened.
|
Stage |
Core Question |
|
Scoping and planning |
Which requirements apply, and where should effort concentrate? |
|
Evidence gathering and testing |
Do the documented controls actually work in practice? |
|
Analysis and reporting |
Where exactly are the gaps, evidenced specifically? |
|
Remediation and follow-up |
Was the fix real, and who verified it independently? |
What Does Protiviti’s Approach to Compliance Actually Look Like?
Protiviti is one of the leading advisory firms in internal audit and regulatory compliance. Its approach centres on three practical questions: Which regulatory risks matter most? Are existing controls working consistently? And what new requirements are likely to affect the organisation next?
Looking ahead to 2025 and 2026, Protiviti expects financial services firms to focus on AI governance, cybersecurity and privacy, FATF-aligned financial crime compliance, ESG reporting, and operational resilience as regulators continue to raise expectations in these areas.
The FATF angle matters more than it might seem right now. Italy, Singapore, Canada, Mexico, China, Australia, the UAE, and the US are all on the schedule for FATF assessment visits, which tends to push domestic regulators into sharper scrutiny mode in the run-up. Financial services firms in these countries are already feeling their home regulator lean in harder, purely because that regulator is preparing for its own FATF review. Protiviti’s horizon scanning discipline is built specifically to catch this kind of thing early, spotting the regulatory calendar events that will drive heightened attention and getting the audit and regulatory compliance response ready before the scrutiny actually lands.
AI governance is the newer piece, shaped heavily by the EU AI Act, in force since August 2024 and generally considered the first comprehensive AI regulation anywhere. For EU financial services firms, it sorts AI systems into risk tiers and attaches specific obligations to the high-risk ones, risk assessments, bias testing, documented human oversight, data quality standards, cybersecurity controls. An audit and regulatory compliance programme for an EU institution now needs an AI systems inventory and AI-specific control assessment sitting alongside the usual financial controls and AML work, not bolted on as an afterthought.
Protiviti’s 2025 internal audit whitepaper also gets into something worth flagging: agile auditing and AI-human collaboration inside the audit function itself. Teams are using AI for continuous controls monitoring, transaction analysis, and anomaly detection now, which is genuinely changing how the evidence gathering and testing stage works, not just speeding it up.
How Does AI Governance Fit Into Audit and Regulatory Compliance?
A few years ago, AI governance sat on the edge of most compliance programmes. In 2025, it has become a central part of audit and regulatory compliance. The EU AI Act and guidance from regulators such as the FCA, MAS, and SEC reflect a broader shift: organisations are now expected to identify, assess, and monitor AI risks separately rather than treating them as just another technology issue.
The EU AI Act’s risk tiers create a real compliance obligation for every AI system an in-scope organisation runs. Unacceptable risk systems are banned outright. High-risk systems need documented risk assessments, bias audits, human oversight, and cybersecurity controls before they ever go live. Limited risk systems need transparency disclosures. Minimal risk systems carry no mandatory requirement at all.
At a bank, that means AI used for credit scoring, fraud detection, or regulatory reporting decisions lands squarely in the high-risk bucket. Each one needs its own compliance file, proof the risk assessment happened, proof it was tested for bias, proof human oversight is documented and genuinely occurs, proof the data feeding it meets quality standards. And this isn’t a one-time box to tick. It’s a recurring obligation tied to how long the system stays in production.
Then there’s shadow AI, something Protiviti’s recent publications flag repeatedly. It’s the AI tools individual teams pick up on their own, marketing, legal, operations, without anyone in governance ever signing off. An organisation can have a tight AI governance framework for its official systems and still have zero visibility into what its own people are quietly feeding company data into. Any serious audit and regulatory compliance scope for AI has to cover both the sanctioned systems and the ones nobody officially approved.
What Does a Genuinely Effective Programme Look Like Right Now?
A strong audit and regulatory compliance programme in 2025 pulls internal audit, compliance monitoring, and regulatory horizon scanning into one connected framework rather than three separate ones. It treats statutory, contractual, and voluntary compliance under the same control taxonomy. It runs continuous monitoring alongside the usual periodic cycles. It gives AI governance its own lane. And it produces evidence built to answer a regulator’s question directly, not just to satisfy an internal reporting checklist.
The piece most programmes still get wrong is connecting risk assessment to audit planning. If the compliance risk assessment says financial crime controls in the digital banking channel are the biggest exposure, the internal audit plan for that year should actually reflect that and go deep there. Where the two functions run separate risk assessments and build separate workplans, you end up with audit and regulatory compliance coverage that’s wide but shallow, and worse, concentrated in the wrong spots entirely.
Whether documentation is actually organised is the real test of whether a programme holds up under pressure. A regulator doesn’t ask for a nice summary of the compliance programme. They ask for the specific evidence that a specific control was operating on a specific date. An organisation that can pull that up cleanly from a well-kept evidence repository gets through the examination without much disruption. One that has to go digging through emails, shared drives, and half a dozen people’s personal folders is already behind before the examination has even really started.
Conclusion
Audit and regulatory compliance isn’t something you build once and leave alone. The environment is moving too fast for that approach to survive. The EU AI Act, the FATF review calendar, ESG reporting, cybersecurity mandates, all of it is adding requirements that simply didn’t exist in their current shape two years ago. The IIA’s 2025 Global Internal Audit Standards have already reshaped the framework internal audit teams operate under.
The organisations that handle audit and regulatory compliance well aren’t necessarily the ones with the biggest compliance headcount. They’re the ones where audit planning, compliance risk assessment, and regulatory horizon scanning are genuinely woven together instead of running on parallel tracks. Where the four stages of compliance get applied properly rather than rushed through as a template before a filing deadline. Where findings actually get tracked to real remediation instead of another year of “in progress.” And where the evidence is organised from day one to answer the questions a regulator will actually ask.
Frequently Asked Questions
The four types are internal audit, which provides independent assurance to the board on risk management and controls; external audit, which provides the statutory opinion on financial statements; compliance audit, which assesses adherence to specific regulatory, contractual, or voluntary standards; and forensic audit, which investigates specific suspected incidents of fraud, misconduct, or regulatory violation. Each operates under different standards, is conducted by different parties, and produces outputs for different audiences.
The four stages are: scoping and planning, which defines which requirements apply and where audit effort will concentrate; evidence gathering and testing, which collects documentation and tests whether controls are actually operating as required; analysis and reporting, which maps findings against requirements and identifies specific, evidenced gaps; and remediation and follow-up, which addresses gaps through control improvement and independently verifies that the remediation was effective.
Protiviti is a global consulting firm specialising in internal audit, risk management, and regulatory compliance. Its compliance services cover compliance risk assessment, ongoing monitoring, and regulatory horizon scanning. Current Protiviti compliance priorities for 2025 and 2026 include AI governance under the EU AI Act, cybersecurity and data privacy, financial crime compliance and FATF-aligned AML frameworks, ESG reporting, and operational resilience. Protiviti’s 2025 whitepaper on internal audit also addresses the shift toward AI-assisted auditing and agile audit methodologies.
AI governance is now a discrete compliance domain driven by the EU AI Act (August 2024), sector-specific regulator guidance, and the expanding use of AI in consequential business decisions. An audit and regulatory compliance programme must include an AI systems inventory, risk classification of each AI system against the applicable regulatory framework, documented risk assessments and bias testing for high-risk systems, human oversight documentation, and coverage of shadow AI tools deployed without central governance oversight.
For an otherwise eligible independent Indian entity, the current criteria include being within 10 years of incorporation/registration, having turnover of not more than ₹200 crore in any financial year since incorporation/registration (₹300 crore for DeepTech startups), and undertaking innovation, development or improvement of products, processes or services, or having a scalable business model with high potential for employment generation or wealth creation
The difference is integration and evidence quality. An effective programme aligns internal audit planning with compliance risk assessment priorities rather than running independent workplans. It produces evidence organised to answer regulatory questions, not just internal reporting requirements. It applies the four compliance stages rigorously, with genuine control testing rather than documentation review only. And it tracks findings to actual remediation with independent verification, rather than accumulating recurring findings with management comments noting that action is in progress.