Whoever hires an auditor, in a public accounting firm or on an internal audit team, is buying independent assurance: testing that stands up to review, findings that hold when management pushes back, and documentation a regulator or an external firm can follow. The resume is read for what was audited, at what size, under which framework, and what the work actually surfaced.
This page covers what carries weight in an audit read, the SOX and control-testing keywords postings filter on, how to write bullets about engagements and findings, what separates a staff auditor from a senior or manager, and a complete sample within the administration field.
In this guide
What matters on an auditor resume
Scope and framework come first. Each position should state the type of audit (financial statement, internal, operational, IT, compliance), the standard applied (US GAAP and GAAS, PCAOB standards, the IIA International Professional Practices Framework, SOX Section 404), and the size of the entity or process tested. "Audited a $180M manufacturer under PCAOB standards" and "tested 60 key controls across order-to-cash for a SOX-compliant public company" describe two very different candidates, and both descriptions are usable.
Findings and their consequences are the second axis. A hiring manager wants to know what the testing produced: control deficiencies identified and their severity, remediation recommendations accepted, recovery or savings quantified, repeat findings closed. Auditors often hesitate here out of confidentiality habit, but describing a finding by type and dollar magnitude, without naming the client, is standard practice and is what makes the resume specific.
Credentials matter more in this role than almost anywhere else in administration. CPA, CIA, CISA and CFE are filtered on by name, and the exact status (licensed, sections passed, candidate with an exam date) belongs in education. Public accounting experience should name the firm tier and the industries served, since internal audit teams recruit heavily from it.
Keywords job postings look for
These terms appear consistently in US auditor postings, public accounting and internal audit alike:
- Internal controls and control testing
- Sarbanes-Oxley (SOX) Section 404 compliance
- Risk assessment and risk-based audit planning
- Walkthroughs and process narratives
- Test of design and test of operating effectiveness
- Sampling methodology and population testing
- Audit workpapers and documentation standards
- Control deficiencies, significant deficiencies and material weaknesses
- Remediation testing and follow-up
- COSO framework
- IIA standards and the audit charter
- PCAOB and GAAS
- Segregation of duties and user access reviews
- Fraud risk and forensic procedures
- Data analytics in audit (IDEA, ACL, Alteryx, Excel)
- AuditBoard, Workiva, TeamMate or Pentana
- CPA, CIA, CISA or CFE
The terms belong in bullets tied to a count ("tested 60 key controls across 4 cycles"), with the platforms and the framework repeated in the skills section. The tool to tailor the resume to the job posting compares the document against a specific ad and lists the required terms that are absent.
Experience bullets that work
Audit bullets improve when the cycle, the count and the outcome of the testing are all present:
| Avoid | Better |
|---|---|
| Performed audit procedures | Executed SOX 404 testing on 60 key controls across order-to-cash, procure-to-pay and financial close for a $900M public filer, with zero PCAOB inspection comments |
| Identified control weaknesses | Identified 2 significant deficiencies in vendor master maintenance and segregation of duties, both remediated and retested clean within the same fiscal year |
| Prepared workpapers | Documented 140 workpapers under PCAOB standards for 9 engagements, all reviewed with no second-round comments from the engagement partner |
| Worked with clients | Ran walkthroughs with 18 process owners across 5 business units and delivered narratives and risk-control matrices for 4 newly in-scope cycles |
| Used data analysis tools | Replaced manual sampling with full-population testing in Alteryx on 240,000 journal entries, cutting fieldwork on the close cycle from 3 weeks to 6 days |
| Presented findings to management | Presented 11 findings to the audit committee, of which 10 were accepted with owners and due dates, closing 8 within 90 days |
In audit, confidentiality does not require vagueness. Industry, entity size, cycle, control count and finding severity can all be stated without naming the client, and a resume that omits them is indistinguishable from every other auditor's.
Junior vs. senior
A staff auditor is evaluated on execution and documentation. The resume should carry the number of engagements worked, the cycles tested, the industries seen, the sample sizes handled and the review record (workpapers passing with few comments is a real and quantifiable signal). CPA or CIA progress belongs near the top, with sections passed and dates. For a first audit role, internships, a forensic accounting course sequence or an accounting degree with an audit elective carry the page, as covered in the guide to a recent graduate resume.
A senior auditor or audit manager is read for ownership and judgment: engagements led end to end, budgets and hours managed, staff supervised and reviewed, the annual risk assessment contributed to, the scoping decisions made, and the relationship with external auditors or regulators. Bullets about building something (an analytics routine reused across engagements, a new continuous monitoring test, a revised risk-control matrix) distinguish a manager from a very experienced tester. Audit committee exposure should be stated plainly when it exists.
Common mistakes in this role
Auditor resumes fail in predictable ways:
- Confidentiality used as an excuse for vagueness. "Performed audits for various clients" removes every fact the reader needs. Industry, revenue range and cycle are not confidential.
- No findings. A resume full of procedures and empty of results reads like someone who ticked boxes rather than tested anything.
- Framework never named. SOX, COSO, IIA standards, PCAOB and GAAS are screened for by name, and a resume that names none of them looks like bookkeeping.
- Credential status buried or vague. "CPA eligible", "pursuing CIA" and an actual license are three different things, and the reader should not have to guess which one applies.
- Public accounting hours described as achievements. Busy-season hours are not a result. Engagements completed, clean reviews and findings closed are.
- A layout that breaks the detail. Dense control counts and dollar figures need a clean single-column template; the guide to an ATS-friendly resume explains what screening software does to sidebars and tables.
Sample auditor resume
The example condenses the advice into a one-page resume for a mid-career internal audit profile. Names and companies are fictional.
Internal auditor with 7 years across public accounting and corporate audit, covering SOX 404 testing for a $900M public filer and operational audits in manufacturing and retail. Led 14 engagements, closed 2 significant deficiencies with clean retesting and moved journal entry testing to full population in Alteryx. CPA and Certified Internal Auditor.
Senior Internal Auditor, Trinity Industrial Group, Dallas, TX. 2021 - Present
- Execute SOX 404 testing on 60 key controls across order-to-cash, procure-to-pay and financial close for a $900M filer, with zero PCAOB inspection comments in three cycles.
- Identified 2 significant deficiencies in vendor master maintenance and segregation of duties, both remediated and retested clean within the same fiscal year.
- Replaced manual sampling with full-population testing in Alteryx on 240,000 journal entries, cutting close-cycle fieldwork from 3 weeks to 6 days.
Audit Associate, Whitfield & Barnes LLP, Fort Worth, TX. 2018 - 2021
- Worked 9 financial statement engagements a year for private companies with $20M to $300M in revenue under GAAS, across manufacturing, distribution and nonprofit clients.
- Documented 140 workpapers under firm and PCAOB standards, with no second-round review comments on the last 4 engagements.
- Ran walkthroughs with 18 process owners and drafted narratives and risk-control matrices for 4 cycles newly in scope after a client acquisition.
Bachelor of Business Administration in Accounting, Texas A&M University, 2018. CPA, Texas State Board of Public Accountancy, 2020. Certified Internal Auditor (CIA), 2023.
SOX 404, COSO framework, IIA standards, GAAS, risk assessment and audit planning, control testing and walkthroughs, AuditBoard, Alteryx, IDEA, SAP, Excel (Power Query, pivot tables), audit committee reporting.
Frequently asked questions
How much detail about clients can an auditor resume include?
Enough to be useful without identifying anyone: industry, revenue range, public or private, the cycles tested and the type of finding. Client names, specific deficiencies tied to an identifiable company and any nonpublic figure stay off the page. This is the standard convention in both public accounting and internal audit.
Is a CPA required for an internal audit role?
Not always. Many internal audit teams accept a CIA, a CISA for IT audit or a CFE for investigative work, and some hire strong candidates with none of them. A CPA remains the most recognized credential and is effectively expected in public accounting, so the status should be stated exactly whichever path applies.
How should a move from public accounting to internal audit be framed?
By emphasizing transferable scope: cycles tested, industries seen, engagement ownership, review responsibility and analytics work, rather than firm rank or busy-season volume. The summary should name the target (internal audit, SOX, operational audit) so the reader does not have to infer it, and the guide on how to tailor a resume to the job helps align the vocabulary to each posting.
Should busy-season hours appear on the resume?
No. Hours worked describe effort, not outcome, and every auditor has them. Engagement counts, clean reviews, findings accepted and process improvements deliver the same message about capacity with evidence attached.