Hi. Sam here.
Last week, I got a message from another auditor. Experienced, smart, and to the point:
“There are already so many audit frameworks. What’s the point of yours?”
Fair question. And if you’ve been reading my work, or following along with the field stories, you know I’m not one to dodge a question.
So let me tell you why the Five Pillars exist, and why I use them every time I go into the field.
The Five Pillars weren’t built to compete with COSO, COBIT, ISO, or The IIA’s Global Internal Audit Standards. Those frameworks are well-built. They’re thorough. Built for orgs with structure, clean data, and layers of review.
That’s not the terrain I usually work in.
Sometimes I walk into a site with no tech support, no clean data, and no roadmap. Just me, a few pages I printed before the plane ride, and a team that may or may not be expecting me.
And in those conditions, I need a system I can carry in my head, or, worst case, in my back pocket.
That’s what the Five Pillars from Auditing Without Power are for.
They’re lean. Flexible. Scalable. They don’t care if you’ve got a laptop or a LAN. They work in a swamp, a school, a state agency, or a shipping dock.
And most importantly, they work for people who aren’t auditors too.
IIA’s 2024 Global Internal Audit Standards
These are the new gold standards for internal auditors, built around five core domains: Purpose, Ethics & Professionalism, Governing, Managing, and Performing. Principle-based, globally vetted.
They define internal auditing as providing independent, objective assurance designed to improve governance, risk management, and controls.
I don’t disagree, but when I’m debriefing after a flash flood with a contractor, a FEMA rep, and, a site coordinator all in the same room, I still need something simpler. Here’s how I translate it:
“Our job is to notice what others don’t and to say it clearly enough that someone can act on it.”
That’s what the pillar Translate the Impact is all about.
COSO – Internal Control Framework
COSO gives us five categories of control: Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring. It’s a cornerstone of financial and operational auditing.
I’ve worked with COSO, and it’s good, especially in structured environments. But if I’m tracing the path of emergency procurement forms through five tents and two trailers in a swamp, I don’t ask, “What’s the control environment?” I ask:
“Where’s the decision? Where’s the risk? Who could bypass this?”
That’s Trace the Controls and Track the Trail in action. Same intent, different speed.
COSO introduces concepts like segregation of duties, making sure no one person can authorize, execute, and record a transaction alone. But in the field, I just zero in:
“Who can skip the step?”
COBIT – IT Governance Framework
COBIT 2019, from ISACA, is basically a full toolbox for IT governance: five domains headed by governance (EDM), then alignment (APO), build (BAI), delivery (DSS), and monitoring (MEA) covering 40 governance and management objectives. It’s perfect when you're auditing complex IT environments with lots of moving parts.
But when I’m in the field, and the system is a spreadsheet and a verbal sign-off, that level of formality feels like overkill. So I ask:
“If someone wanted to cheat this, how would they do it?”
That’s Trace the Controls (spotting weak links) and Track the Trail (following the evidence). COBIT may frame it as segregation of duties or access privileges, but in real life? The question is simply: Who can skip the steps?
That’s the field-speed version of COBIT’s intent. Solid, practical, and immediate.
ISO 31000 – Risk Management
ISO 31000 is a global, principle-based framework for risk management. It guides organizations to identify, assess, treat, monitor, and communicate risks in a structured way. It’s elegant and useful... until you’re in the field with no charts or formal sit-downs. So I skip straight to:
“What is likely to go wrong, and who will feel it first?”
That’s Zoom Out in action. It’s not about mapping all risk types, it’s about catching the risk that lands fastest and hurts hardest.
Mini‑Tool: Field Risk Radar
Take out 1 page in your notebook.
Draw three columns titled: “What Could Break”, “Who’s Impacted”, “Can We Fix It?”
As you walk the site, jot what stands out (no matter how small).
Quickly spot the high‑hurt risks that need eyes now.
This simple tool gets the ISO mindset working and it fits in your pocket.
Let me be clear. I’m not against any of the existing frameworks. If you live inside an internal audit shop, these standards help keep the work honest and aligned. I’d never tell you to ignore them. But I needed something more adaptable.
That’s why I keep going back to the Five Pillars:
Zoom Out – See the big picture before you poke the process.
Trace the Controls – Don’t just ask what’s there. Ask what can be bypassed.
Track the Trail – Follow the evidence. Where does the story break?
Check Yourself – Slow your bias before it skews the work.
Translate the Impact – Say what matters. Make it land.
That’s it. No special license. No plug-in required. Just you, thinking clearly.
And it’s not just for auditors.
I’ve seen school principals use it to audit their own spending.
I’ve seen HR directors use it to rethink how complaints are handled.
I’ve seen small-town mayors use it to track missing public funds, without calling it an audit.
You don’t need a badge or a certification to use these pillars.
If you run a small business, you’re already doing audit work. You’re just calling it “double-checking,” or “making sure the books add up.”
If you’ve ever asked “Where’s the bottleneck?” or “Who dropped the ball?” you’re Zooming Out and Tracking the Trail.
The difference is: the Five Pillars give you a language and a structure. So you’re not starting from scratch every time a problem shows up. As an example, a field medic I once worked with used Track the Trail to monitor missing oxygen tanks.
The point is ACCESSIBILITY. The more people who can spot issues clearly and calmly, the fewer blind spots we’ll have.
Let’s talk about it, because I use AI tools too, and they help me flag anomalies, scan documents, and pull patterns. I’m all for it.
But AI can’t yet do this:
Catch the difference between “We always do that” and “We’re supposed to do that.”
Hear hesitation in someone’s voice.
Notice when a signature looks hurried or oddly identical to another one.
That’s nuance. That’s human. That’s audit thinking. And we can’t lose it.
I’ve had some inquiries as to how the Five Pillars align with the big-name frameworks: COSO, COBIT, ISO 31000, and The IIA’s Global Internal Audit Standards.
So here’s the plan:
In an upcoming post, I’ll break it down, pillar by pillar, side by side. Not as a formal mapping, but as a field-friendly comparison: How I see the connections, where the language gets tangled, and how I translate it for people who don’t speak “audit.”
It’ll include:
A plain-language reference grid (Pillars ↔ COSO/COBIT/IIA/ISO)
Practical prompts you can actually use in the field
Tips for teaching non-auditors how to spot the same gaps
It’ll be free, no logins, no gated PDFs. Just another article you can read, share, or build on. Because at the end of the day, I just want more people using Audit Thinking.
If you’re subscribed here, you’ll get it first. And when the book drops, you’ll already know where the pillars stand.
I didn’t create the Five Pillars to be clever. I built them because most frameworks don’t fit the field realities I face. And truthfully? Sometimes they’re too heavy for the people I serve.
The work still matters. The risks are still real. But the guidance has to be portable.
That’s what this is: a compass, not a command.
The Five Pillars won’t tell you what to think. But they’ll remind you HOW to think, especially when thing start falling apart. Take what’s useful. Leave the rest. See you in the field.
What’s a framework you’ve used that worked beautifully on paper, but completely broke down in practice?
Have you ever “audited” something without realizing that’s what you were doing? What tipped you off that something wasn’t right?
Which of the Five Pillars do you find yourself using even outside of audit work?
Have you ever been in a room where someone spoke “audit” and no one else understood a word of it? What got lost in translation?
If AI can’t hear tone or hesitation, how are we training humans to keep that skill sharp?
When you Zoom Out in your own work, what do you suddenly see that others don’t?
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.