Resume examples

Auditor Resume Example

A full, ATS-ready sample resume for an Auditor — with the quantified findings, SOX and risk-assessment experience, and exact keywords hiring managers screen for. Use it as a model, then build yours free.

By Diane Pruett, Lead Career Strategist · Updated June 27, 2026 · ~9 min read

Short version: A strong Auditor resume proves three things fast — that you can assess risk and test controls (risk-based planning, walkthroughs, SOX controls testing under COSO), document and defend a conclusion (clean workpapers, sampling, audit evidence that ties out), and turn findings into change (issues written clearly, remediation tracked, management on board). Lead with a finding or efficiency result, keep it to one page, name your credential, and mirror the exact terms from the posting. Below is a complete example you can model line for line, then build yours free.

What an auditor actually does

An auditor independently examines whether an organization's financial records, controls, and processes are accurate, compliant, and free of material misstatement or undue risk. The U.S. Bureau of Labor Statistics groups the role with accountants and auditors, but the work is distinct from accounting in one decisive way: an accountant prepares the numbers, while an auditor provides assurance over them. The role splits into two big tracks. External auditors (typically in public accounting) issue an opinion on a client's financial statements under GAAS. Internal auditors sit inside a company and give the audit committee and management independent assurance over financial, operational, IT, and compliance risk. The throughline across both is evidence-based skepticism: you don't take a control on faith, you test it and document why you concluded what you concluded.

On a typical engagement or audit cycle, an auditor will:

  • Plan against risk — performing a risk assessment, scoping the audit to the accounts and processes that matter most, and setting materiality so effort lands where misstatement or failure is most likely.
  • Run walkthroughs and document processes — meeting process owners, tracing a transaction end to end, and mapping the control environment against a framework such as COSO.
  • Test controls and balances — designing and executing tests of design and operating effectiveness, plus substantive procedures, using sampling, recalculation, confirmation, and inspection of audit evidence.
  • Document workpapers — preparing clear, review-ready workpapers in which every conclusion is supported by referenced evidence, so a reviewer (or a regulator) can follow the logic.
  • Identify and write up findings — distinguishing a deficiency from a significant deficiency or material weakness, quantifying exposure, and writing the condition, criteria, cause, effect, and recommendation.
  • Use data analytics — running full-population tests over journal entries, AP, or access logs in tools such as ACL/Galvanize, IDEA, Alteryx, SQL, or Power BI rather than testing a 25-item sample by hand.
  • Drive remediation and report — agreeing action plans with management, tracking issues to closure, and presenting results to senior leadership and the audit committee.

What gets auditors promoted is rarely the volume of tickmarks; it is judgment and influence — the finding nobody else caught, the test that scoped a 40-item sample down to a clean analytic, and the ability to deliver a hard issue so the process owner fixes it instead of fighting it. That is exactly what your resume has to demonstrate — not that you are "detail-oriented," but that you found something material and got it remediated.

What hiring managers & ATS look for

Two readers screen your resume, and they want different things. The applicant tracking system (ATS) and the recruiter doing keyword searches want literal terms — SOX, internal controls, risk assessment, walkthroughs, controls testing, COSO, GAAS, ACL — matched to the posting. The hiring manager — usually an audit manager, internal audit director, or engagement partner — wants evidence you can be trusted with independence and judgment: clean workpapers, defensible conclusions, findings that mattered, and the diplomacy to get them fixed.

Across hundreds of auditor postings, the signals that move a resume to the "yes" pile are consistent:

  • Risk-based methodology, named and proven. "Risk assessment," "internal controls," and "SOX" appear in the large majority of audit job descriptions. A skills line isn't enough — show it inside a bullet ("scoped a risk-based SOX plan covering 120+ key controls across 4 cycles").
  • The full audit lifecycle. Planning, walkthroughs, testing, workpapers, findings, and reporting — demonstrating you've owned an audit end to end, not just executed someone else's test steps.
  • Findings with impact. Number and severity of issues raised, dollars of exposure or recovery quantified, control gaps closed. This separates a tester from an auditor with judgment.
  • Data analytics. Naming ACL/Galvanize, IDEA, Alteryx, SQL, or Power BI — and showing you tested a full population, not a hand sample — is one of the highest-value differentiators in 2026 audit hiring.
  • Frameworks and standards. COSO, the IIA's IPPF standards, GAAS, GAAP, PCAOB, and SOX 404 — naming the framework signals you operate to a professional standard, not improvisation.
  • Credentials. CPA, CIA, CISA, or candidacy. Even "CIA Part 1 complete" or "CPA candidate, passed AUD" is worth stating plainly.
The single biggest lever: rewrite each procedure as a finding or an improvement. "Tested internal controls" is a task. "Tested 120 SOX key controls, identified 3 access-segregation gaps, and worked with IT to remediate all 3 before year-end" is a hire.

Full auditor resume example

Here is a complete, realistic one-page example for a mid-level (senior) auditor with a mix of external and internal experience. Every bullet follows the same shape — action verb, what you tested or found, the framework or tool, and the quantified result. Treat it as a model, not a fill-in-the-blank; your numbers must be your own.

Miles Anand
Senior Auditor — Internal Audit & SOX
Charlotte, NC · priya.anand@email.com · (704) 555-0148 · linkedin.com/in/priyaanand-cia

Professional Summary

Senior Auditor and CIA with 6 years across external (public accounting) and internal audit, owning risk-based audit plans, SOX 404 controls testing, and operational audits under COSO and the IIA standards. Strong in walkthroughs, sampling, and review-ready workpapers, with a data-analytics edge using ACL and SQL to test full populations. Known for finding issues that stick and driving them to remediation with management buy-in.

Core Skills

Audit lifecycle: Risk assessment, audit planning & scoping, walkthroughs, tests of design & operating effectiveness, substantive testing, workpaper documentation, findings & reporting
Compliance & frameworks: SOX 404, internal controls, COSO, GAAS, GAAP, PCAOB standards, IIA IPPF, ITGCs, segregation of duties
Data analytics & systems: ACL/Galvanize, IDEA, SQL, Alteryx, Power BI, Excel (PivotTables, Power Query), SAP, Workiva, AuditBoard
Audit types: Financial-statement, SOX, operational, compliance, and IT general controls audits; remediation tracking; audit-committee reporting
Credentials: CIA (active), CPA candidate (passed AUD & FAR), B.S. Accounting

Professional Experience

Senior Internal Auditor — Meridian Financial Group (~$3.4B assets)Charlotte, NC · 2023–PresentLeads SOX and operational audits; reports findings to the VP of Internal Audit and audit committee.
  • Built and led the risk-based SOX 404 plan covering 120+ key controls across 4 financial cycles, completing testing two weeks ahead of the year-end deadline.
  • Identified 3 segregation-of-duties gaps in the procure-to-pay ITGCs and partnered with IT to remediate all 3 before management's assessment, avoiding a potential significant deficiency.
  • Replaced a 40-item manual AP sample with a full-population ACL analytic over 180K invoices, surfacing $260K in duplicate and out-of-policy payments recovered by the business.
  • Wrote 11 audit findings using condition–criteria–cause–effect–recommendation and drove 100% to remediation closure within the committed timeline.
  • Led walkthroughs with 9 process owners and rationalized the controls matrix, retiring 14 redundant controls and cutting annual testing hours by ~18%.
Audit Associate / Senior — Calderwood & Pratt LLP (public accounting)Charlotte, NC · 2020–2023Executed financial-statement and SOX engagements for middle-market and pre-IPO clients.
  • Executed substantive and controls testing across revenue, cash, and inventory for a portfolio of 8 clients under GAAS, consistently delivering workpapers with zero reviewer reopen notes.
  • Performed tests of operating effectiveness over 60+ SOX key controls and documented results in Workiva, supporting two clean, on-time external audit opinions.
  • Used IDEA to recalculate and reperform revenue cut-off across 100% of year-end transactions, catching a $190K early-recognition error before the opinion was issued.
  • Mentored 2 first-year associates on sampling, tickmark discipline, and audit evidence standards, raising first-pass workpaper quality on the engagement.

Education & Certifications

B.S., Accounting — University of North Carolina at Charlotte · 2020
Certified Internal Auditor (CIA) · 2023 · CPA candidate (passed AUD & FAR)

Build a resume like this — free.

Start from this exact structure in the free Marqee Resume Builder. ATS-ready formatting, role-specific prompts, and an instant keyword check.

Build yours free →Browse templates

Key skills & ATS keywords for auditors

Pull the eight to twelve terms the posting names, confirm you genuinely have them, and place each into a real finding or testing bullet or your skills line. These are the keywords that show up most across auditor job descriptions — match the ones that are true for you, in the posting's exact phrasing. A common trap is writing "compliance testing" when the posting says "SOX controls testing" and names COSO; mirror the posting, and never list a framework or tool you can't speak to in an interview.

risk assessmentinternal controlsSOXSOX 404controls testingwalkthroughsaudit planningfieldworksubstantive testingsamplingworkpapersaudit findingsCOSOGAASGAAPPCAOBIIA standardsITGCssegregation of dutiesdata analyticsACLIDEASQLremediationCPACIACISA
Hard skills (must show)Soft skills (must signal)
Risk assessment & risk-based audit planningProfessional skepticism — never take a control on faith
Internal controls & SOX 404 testing under COSOObjectivity & independence — the core trust signal
Walkthroughs, sampling & substantive testingEvidence discipline — every conclusion supported
Workpaper documentation & review-ready referencingClear writing — a finding a non-auditor can act on
Findings, reporting & remediation trackingDiplomacy — deliver a hard issue and keep cooperation
Data analytics — ACL, IDEA, SQL, Alteryx, Power BIDeadline discipline — busy season and year-end never slip

For a deeper method on weaving these in without keyword-stuffing, see how to choose resume keywords and how to quantify resume bullets.

A realistic salary range

Compensation for auditors varies widely by metro, industry, credentials, and track, but the bands are well established. In the United States, most auditors earn roughly $60,000 to $110,000, with a national median near $79,000–$81,000 (consistent with BLS figures for accountants and auditors). Entry-level staff auditors commonly start in the high $50,000s to mid $60,000s. Senior auditors, CPAs and CIAs, and IT auditors frequently reach $90,000 to $120,000+, and audit managers, IT-audit leads, and directors move well above that — particularly in financial services and high-cost metros.

  • What pushes you up the band: a CPA, CIA, or CISA; SOX and IT-audit (ITGC) experience; data-analytics skills (ACL, IDEA, SQL, Alteryx); public-accounting or Big-firm pedigree; and a record of findings that drove real recoveries or remediation.
  • What anchors the number: location, industry (financial services, technology, and public accounting pay above nonprofit and small private firms), and whether you own audits end to end or mostly execute assigned test steps.
On the resume: you don't list salary, but you earn the top of your band by quantifying impact — controls tested, findings raised, dollars recovered or exposure avoided, testing hours saved. When an offer comes, our Salary Analyzer shows where it sits in the market, and our guide to total compensation helps you weigh bonus and benefits.

Common auditor resume mistakes

Listing procedures instead of findings. "Responsible for SOX testing" tells an audit manager nothing. "Tested 120 key controls, found 3 SODs gaps, and remediated all before year-end" gets the interview. Aim for a number — controls, findings, or dollars — in roughly half your bullets.
Naming no framework or tool. Reviewers search by COSO, SOX, ACL, IDEA, and SQL. If the posting names a framework or analytic tool and your resume only says "audit software," you're invisible. Name every standard and tool you've actually used, in the posting's phrasing.
Hiding the credential (or its status). If you hold a CPA, CIA, or CISA, put it after your name and in your summary. If you're in progress, say "CIA Part 2 complete" or "CPA candidate, passed AUD." Don't make a reviewer guess.
No severity or scale. "Identified control issues" could mean a typo or a material weakness. Name how many findings, their severity (deficiency, significant deficiency, material weakness), and the exposure or recovery in dollars.
A two-column, icon-heavy layout. Many ATS parsers scramble multi-column resumes and ignore skill icons. Use a single-column, reverse-chronological format with standard headings. See ATS resume formatting.
Ignoring data analytics. Full-population testing with ACL, IDEA, or SQL is now a core differentiator. If you've done it, give it its own bullet; if you haven't, it's the highest-ROI skill to build. More fixes in common resume mistakes.

Frequently asked questions

Not always, but a credential is a strong differentiator. For external audit and public-accounting roles, the CPA is often expected or required. For internal audit, the CIA (Certified Internal Auditor) is the most recognized credential, and the CISA (Certified Information Systems Auditor) is valued for IT and SOX-ITGC work. Many staff and senior auditor jobs hire candidates who are exam-eligible or in progress, so state your status plainly — for example, "CPA candidate, passed AUD and FAR" or "CIA Part 1 complete." If you have no credential yet, lead with results: clean workpapers, findings that drove remediation, and audits delivered on schedule carry real weight.

One page for staff and most senior auditors with under roughly ten years of experience. Audit managers, IT-audit leads, and auditors with a long, varied record across industries can run to two pages. Reviewers skim the top third first, so put your strongest finding or efficiency result, your SOX and risk-assessment experience, and any credential where the eye lands.

Employers look for risk assessment, internal controls evaluation, SOX compliance, walkthroughs and controls testing, audit planning and fieldwork, and clear workpaper documentation, framed against GAAP, GAAS, COSO, and the IIA standards. Sampling, substantive testing, and writing findings and recommendations appear constantly. Data-analytics skills are increasingly required — naming tools such as ACL/Galvanize, IDEA, Alteryx, SQL, Power BI, or Excel. Soft skills matter as much: skepticism, objectivity, the discipline to support every conclusion with evidence, and the diplomacy to deliver a finding to a process owner without losing their cooperation.

Use a single-column, reverse-chronological layout with standard headings, and mirror the exact terms from the job description — write SOX, internal controls, risk assessment, walkthroughs, and the specific framework or tool the posting names such as COSO, ACL, or SQL. Keep a short skills line for keyword coverage but prove each skill inside a finding or testing bullet. Save as a text-based PDF unless the posting asks for .docx, and avoid tables, text boxes, and icons that parsers scramble.

In the United States most auditors earn roughly $60,000 to $110,000, with a national median near $79,000 to $81,000 based on BLS data for accountants and auditors. Entry-level staff auditors often start in the high $50,000s to mid $60,000s, while senior auditors, CPAs and CIAs, and IT auditors can reach $90,000 to $120,000 or more. Audit managers and directors, and roles in high-cost metros or financial-services and IT audit, run well above that. Certifications, public-accounting experience, and data-analytics skills push the range higher.

An external audit resume emphasizes the financial-statement opinion: GAAS, substantive and controls testing, sampling, audit evidence, and engagement work across a portfolio of clients under tight busy-season deadlines. An internal audit resume emphasizes risk and improvement: building the risk-based audit plan, evaluating controls against COSO, operational and compliance audits, writing findings and recommendations, and tracking remediation with management. If you are targeting internal audit, foreground risk assessment, findings that changed a process, and stakeholder management; for external audit, foreground GAAS, testing rigor, and engagement throughput.

Don't want to do this alone?

A great resume gets you parsed. It doesn't get you in front of the audit manager or internal audit director who owns the role — and for stable, in-demand audit jobs, especially around busy season and SOX cycles, the front door is crowded with qualified applicants. That's where Marqee comes in. We're a Career Concierge: a real person runs your job search, tailors your resume to each auditor posting, reaches the hiring manager directly, and finds a referral inside the firm or audit department so you skip the pile. You stop spending nights filling out forms and start showing up to interviews.

Free tools first — then put a human on it.

Grade and build your resume free, or let a dedicated strategist headline the marquee and run the whole search for you.

Build my resume free →See how Marqee works

Keep exploring