Implementierung
20 Min. Lesezeit

How Employee Interviews Drive Reliable Audit Evidence

support@ismscalculator.com|

Hands arranging interview notes on desk

Employee interviews convert organizational practice into audit evidence by revealing how controls actually operate in daily work, exposing gaps between written policy and real behavior, and surfacing risk signals that documents alone cannot show. That is the core role of employee interviews in audits, and every phase of your engagement should reflect it.

Three things interviews do that nothing else can:

  • Reveal actual process. Employees describe what they do, not what the procedure manual says they should do. That gap is often where findings live.
  • Surface risk signals and intent. Tone, hesitation, and inconsistency are data. Automated analytics cannot read a pause.
  • Corroborate or challenge documentary evidence. A signed access-control log means little if the person who signed it cannot explain the process behind it.

When interviews are essential: control walkthroughs, fraud inquiries, IT control assessments, ISO 27001 readiness reviews, and any audit where process documentation is sparse or outdated.

When interviews are optional but still valuable: routine compliance checks with strong transactional evidence, low-risk process reviews, or follow-up audits where prior findings are already well-documented.

Pro Tip: Before your next engagement, write a single sentence stating what the interview must confirm or rule out. If you cannot write that sentence, the interview is not ready to schedule.


Key Takeaways

Employee interviews are most reliable when they are structured, documented, and triangulated against at least two other evidence types before a finding is concluded.

Point Details
Structure improves reliability Structured interviews produce higher validity than unstructured ones; use a written question guide for every interview.
Three-phase model Pre-interview planning, structured conduct, and post-interview evaluation within 48 hours produce consistent, defensible evidence.
Triangulate before concluding Match each significant interview claim against documents, system logs, or a second independent interview before treating it as evidence.
Red flags require immediate action Behavioral inconsistencies and undocumented workarounds should be documented verbatim and escalated before the next interview.
Ismscalculator for ISO 27001 scoping The free readiness check and full assessment help audit teams prioritize interview targets by domain risk before fieldwork begins.

Table of Contents

How employee interviews shape audit planning and evidence gathering

Effective pre-interview planning is the difference between a conversation that generates usable evidence and one that generates meeting notes. According to IIA guidance on interview preparation, thorough background research and purpose definition materially improve the quality of information auditors obtain and the working relationship with the interviewee.

Map the objective first. Each interview should tie directly to a specific audit objective: verifying operating effectiveness of a control, understanding process flow, or identifying exceptions. An interview designed to verify operating effectiveness asks different questions than one designed to map a process. Conflating the two produces answers that fit neither purpose.

Background documents to gather before scheduling:

  • Process maps and standard operating procedures for the area under review
  • Recent management reports, KPIs, or dashboards related to the process
  • Prior audit findings and management action plans
  • Organizational charts showing reporting lines and role responsibilities
  • Relevant policies, access control matrices, and system configuration records

Selecting and sequencing interviewees. Choose by function, not just title. A process owner and a frontline operator will describe the same control differently, and both perspectives matter. Sequence interviews from general to specific: start with process owners to understand the intended design, then move to operators to test whether that design runs as described. Avoid interviewing subordinates before their managers when the topic is sensitive, since managers can inadvertently prime responses.

Scheduling and logistics checklist:

  1. Send a brief agenda at least 48 hours in advance, stating the audit objective and approximate duration.
  2. Confirm the interviewee’s role and the specific processes they own or operate.
  3. Book a private room or secure video call, not an open floor plan.
  4. Allocate 30–60 minutes per interview; complex control areas may need 90 minutes.
  5. Assign a note taker separate from the lead interviewer before the meeting, not during it.

A step-by-step audit interview model you can follow on every engagement

A reproducible three-phase model gives you consistent, defensible outputs regardless of who on the team conducts the interview. The ECA audit interview guideline defines three core interview purposes: orientation, examination, and confirmation. Your phase model should map to all three.

Phase 1: Pre-interview

  1. Finalize the interview objective and link it to the audit program step it supports.
  2. Review background documents and draft a structured question guide (not a rigid script).
  3. Assign team roles: lead interviewer, note taker, and, for complex interviews, an observer who monitors body language and flags follow-up questions silently.
  4. Agree on team signals: a note taker who needs clarification can write “PROBE?” on a shared pad rather than interrupting.
  5. Confirm logistics, send the agenda, and verify the interviewee understands the scope.

Phase 2: Conducting the interview

  1. Open with a clear statement of purpose, confidentiality expectations, and time frame.
  2. Move through the question guide using the cone technique: open questions first, probing follow-ups second, closed confirmation questions last.
  3. The lead interviewer focuses on listening and follow-up; the note taker captures verbatim quotes where possible, tagging each answer with the control or risk area it addresses.
  4. The observer notes hesitations, topic changes, or emotional shifts that warrant a follow-up probe.
  5. Close by summarizing key points and asking whether the interviewee wants to add anything.

Phase 3: Post-interview evaluation

  1. Debrief as a team within 30 minutes while memory is fresh. The observer’s notes are discussed first.
  2. Classify each answer: corroborates existing evidence, contradicts existing evidence, or introduces a new risk area requiring testing.
  3. Identify follow-up requests: documents, system screenshots, or a second interview.
  4. Draft the interview minutes and circulate for the interviewee’s review within 48 hours.

Pro Tip: Schedule your debrief before you leave the building or end the video call. A 15-minute debrief immediately after the interview captures nuance that disappears by the next morning.


Designing questions that produce reliable, verifiable answers

Question design is where most audit interviews fail. Vague questions produce vague answers; leading questions produce the answer you already expected. Neither is evidence.

Four question types and when to use them:

  • Structured questions: Predetermined, asked in the same order for every interviewee covering the same control. Use these when you need comparable responses across multiple interviews or when the finding must withstand scrutiny.
  • Behavioral questions: Ask what the person actually did in a past situation (“Walk me through the last time you processed an exception request”). Use these to test whether a control operates as described.
  • Situational questions: Present a hypothetical scenario (“If you received a request to grant temporary admin access outside normal hours, what would you do?”). Use these to assess understanding of policy and escalation paths.
  • Confirmation questions: Closed yes/no or specific-value questions used at the end of a topic to pin down a fact (“So the approval always goes to the IT security manager before access is granted — is that correct?”). Use these to lock in a specific claim before moving on.

The cone technique in practice. Open with a broad question to let the interviewee describe the process in their own words. Then probe: “You mentioned the request goes to your manager — who specifically, and how?” Then confirm: “So every access request, without exception, requires written approval from the IT security manager before provisioning?” Each layer narrows the answer and tests internal consistency.

Sample question templates auditors can adapt:

Control effectiveness: “Describe how you verify that [control X] was completed before [process Y] proceeds.”

Segregation of duties: “Who else in your team has the ability to both initiate and approve [transaction type]?”

Access management: “When an employee leaves your department, what steps do you take to remove their system access, and how quickly does that happen?”

Incident response: “Tell me about the last security incident you were aware of. What happened, and who did you notify?”

Questions to avoid:

  • Leading: “You do review the logs daily, right?” (signals the expected answer)
  • Double-barreled: “Do you review access logs and escalate anomalies?” (two questions in one)
  • Jargon-heavy: “Do you perform a reconciliation of the IAM provisioning workflow?” (use plain language first, then clarify)
  • Hypothetical without grounding: “What would you do in a perfect world?” (produces aspirational, not operational, answers)

Research-based principles for good interviewing emphasize avoiding poor question design and using structured probes to test consistency across answers, which is particularly important when multiple interviewees describe the same control.


How to run the interview: rapport, bias control, and evidence capture

The opening two minutes of an interview set the tone for everything that follows. State the audit’s purpose plainly, clarify that the interview is not a performance evaluation, and confirm roughly how long it will take. That framing reduces defensiveness and increases candor.

Rapport without coaching. Framing the interview as collaborative, where you are trying to understand how the process works rather than catch someone out, consistently produces better disclosures. IIA practitioner guidance notes that auditors who position themselves as problem-solving partners get higher cooperation and higher-quality information. That does not mean softening your questions. It means the interviewee understands you are there to understand, not to prosecute.

Bias management. Three biases most commonly distort audit interviews:

  • Confirmation bias: You already suspect a control is weak and unconsciously weight answers that confirm it. Counter by asking the same question in two different framings and comparing responses.
  • Anchoring: The first answer you hear shapes how you interpret subsequent ones. Debrief as a team before drawing conclusions.
  • Early judgment: Deciding the interviewee is credible or not in the first five minutes. Credibility is assessed after corroboration, not during the conversation.

Note-taking and recording:

Practice Recommended approach
Verbatim quotes Capture exact wording for key claims; bracket paraphrases clearly
Answer tagging Tag each answer to the control, risk area, or audit objective it addresses
Nonverbal observations Note hesitations, topic deflections, or emotional shifts in a separate column
Audio/video recording Requires explicit consent; avoid unless legally necessary
Shared notes Lead interviewer reviews note taker’s draft before the debrief, not after

In IT audit contexts, interviews frequently surface control breakdowns that system logs and configuration reviews do not show, precisely because operators describe workarounds they consider routine but that represent undocumented exceptions to the control design.


Red flags and fraud indicators to watch for during interviews

Interviews are one of the few audit procedures that can surface intent, not just outcome. A transaction log shows what happened; an interview can reveal why, and whether the person describing it understood it was wrong.

Behavioral red flags to note:

  • Inconsistency between what the interviewee says now and what they said earlier in the same interview
  • Evasive answers: topic changes, excessive qualifications, or answering a different question than the one asked
  • Unusual process workarounds described as normal (“We always do it that way because the system doesn’t allow the proper route”)
  • Unexplained access changes or system overrides the interviewee cannot attribute to a specific business need
  • Reluctance to name specific approvers or document owners

Factual red flags:

  • Descriptions of processes that contradict documented controls
  • References to approvals that cannot be traced to a system record or signature
  • Timelines that do not align with transaction data you have already reviewed

Distinguishing perception from allegation. An interviewee saying “I think someone might be approving their own transactions” is a perception. An interviewee saying “I saw John approve his own expense report on March 14” is an allegation. Document both, but treat them differently. Perceptions direct your testing; allegations require immediate escalation and evidence preservation.

If fraud is suspected during an interview:

  1. Do not confront the interviewee or reveal what you suspect.
  2. Continue the interview normally and document responses verbatim.
  3. Immediately after the interview, notify your audit supervisor or chief audit executive.
  4. Preserve all notes, recordings (if any), and documents gathered to that point.
  5. Do not discuss the matter with other interviewees until you receive guidance.

Post-interview red-flag checklist for working papers:

  • Were any answers inconsistent with prior evidence? (Y/N, describe)
  • Did the interviewee describe any undocumented workarounds? (Y/N, describe)
  • Were any escalation or approval steps described that cannot be corroborated? (Y/N, describe)
  • Did behavioral indicators suggest evasion or discomfort on specific topics? (Y/N, describe)

Turning interview information into reliable audit evidence

An interview answer is not evidence by itself. It becomes evidence when it is corroborated, documented, and assessed for reliability. Audit guidance on interview evidence is clear that interviews are a major source for directing audit effort, but they are usually supplemented by other evidence before a finding is concluded.

Triangulation in practice. Match each significant interview claim against at least two other evidence types:

  • Documents: Does the process the interviewee described match the written procedure and the transaction records?
  • System logs: Does the access or approval sequence they described appear in the system audit trail?
  • Other interviews: Does a second interviewee, independently, describe the same control operating the same way?

Reliability factors to assess for each interview:

Factor Higher reliability Lower reliability
Independence Interviewee has no stake in the finding Interviewee is the control owner being tested
Direct observation Describes what they personally do Describes what they believe others do
Motive to misstate No apparent incentive Potential disciplinary or financial exposure
Contemporaneous records Answer aligns with dated records Answer relies entirely on memory

Documentation checklist for working papers:

  • Interview date, time, location, and participants
  • Stated purpose and audit objective the interview supports
  • Verbatim quotes for key claims, clearly labeled as quotes
  • Paraphrased responses, clearly labeled as paraphrases
  • Evidence links: documents, logs, or prior findings the answer corroborates or contradicts
  • Reliability assessment: one sentence per significant claim
  • Follow-up items: what still needs corroboration

For ISO 27001 audits, interviews are particularly valuable for assessing how controls operate across the 14 ISO domains, since many controls depend on human behavior that documentation alone cannot verify.


Post-interview: documentation, follow-up, and integrating results

The 48 hours after an interview are as important as the interview itself. Delayed documentation degrades accuracy; undocumented follow-up items disappear.

Producing consistent interview minutes:

  1. Draft minutes within 24 hours using the note taker’s verbatim captures as the base.
  2. Structure minutes as: purpose, participants, key topics covered, significant responses (quoted or paraphrased with clear labeling), follow-up items, and reliability notes.
  3. Circulate to the interviewee for factual review within 48 hours. Note that this is a factual accuracy check, not an opportunity to revise substantive disclosures.
  4. Obtain a signed confirmation or email acknowledgment before closing the working paper.
  5. File minutes with the evidence links attached, not in a separate folder.

Follow-up actions:

  • Send document requests within 24 hours of the interview, referencing the specific claim they support.
  • If a follow-up interview is needed, schedule it before leaving the fieldwork site.
  • Flag unresolved items in the audit risk register immediately, not at the end of fieldwork.

Mapping interview findings into the audit:

  • Each significant interview finding should map to a risk register entry, a test step, or a finding draft.
  • If an interview reveals a new risk not in the original scope, escalate to the audit manager before expanding testing independently.
  • Use interview outputs to adjust sample sizes: if multiple interviewees describe the same exception, increase your transaction sample for that control.

Working paper fields for traceability:

  • Quote or paraphrase → control or risk area → corroborating evidence reference → finding or test step number

Practical tools: question bank, checklists, and templates you can use now

One-page interview planning checklist:

  • [ ] Audit objective the interview supports: ___
  • [ ] Interview type (orientation / examination / confirmation): ___
  • [ ] Background documents reviewed: ___
  • [ ] Interviewee role and function confirmed: ___
  • [ ] Question guide drafted and reviewed by audit lead: ___
  • [ ] Team roles assigned (lead, note taker, observer): ___
  • [ ] Agenda sent at least 48 hours in advance: ___
  • [ ] Private room or secure call confirmed: ___
  • [ ] Recording decision made and consent obtained if applicable: ___

Sample question bank by objective:

  1. Control effectiveness: “Walk me through the last time you performed [control X]. What did you check, and what did you do if something was off?”
  2. Segregation of duties: “Is there anyone in your team who can both create and approve [transaction type] without a second sign-off?”
  3. Access management: “How does your team handle access removal when someone transfers departments or leaves the company?”
  4. Incident response: “Describe the last time you identified or reported a potential security issue. What steps did you follow?”
  5. Policy awareness: “Where would you go if you needed to check the current policy for [specific process]? When did you last look at it?”
  6. Exception handling: “What happens when a transaction or request falls outside the normal approval path? Can you give me a recent example?”
  7. Change management: “When a system or process change is implemented, how are you notified, and what training do you receive?”

Interview minutes template fields:

  • Date, time, location, duration
  • Audit engagement name and reference number
  • Participants (name, title, role in the process)
  • Stated purpose of the interview
  • Key responses (verbatim quotes in quotation marks; paraphrases labeled “P:”)
  • Follow-up items (item, responsible party, due date)
  • Reliability notes
  • Auditor signature and date

Remote vs. in-person adaptation. For remote interviews, confirm the interviewee is in a private space before beginning. Use screen-share to walk through documents together rather than emailing them in advance, which reduces the risk of coached responses. Note any technical disruptions in the minutes.

Pro Tip: Build your question bank in a shared document your team can update after each engagement. Questions that consistently produce useful answers are worth keeping; questions that consistently produce “I don’t know” or deflection are worth replacing.


Why structured interviews produce more reliable audit evidence

The case for structured interviews is not just practitioner preference. Meta-analytic research by McDaniel et al. shows that structured interviews generally produce higher validity than unstructured ones for assessment purposes, a finding that translates directly to audit contexts where reliability of evidence is the standard.

The FAINT-based structured interview approach (Forensic Assessment Interview Technique) demonstrates that a structured three-phase process increases the percentage of usable, reliable data in complex assessments. In fraud or high-risk interviews, FAINT’s emphasis on open narrative followed by targeted probes reduces the risk that the auditor’s framing contaminates the interviewee’s account.

U.S. Merit Systems Protection Board guidance recommends structured interviews for assessment functions because structure increases the likelihood of reliable, defensible decisions. The parallel for internal audit is direct: when interview evidence will support a finding or risk rating, the interview process must be structured enough to withstand challenge.

Practical implications for audit teams:

  • Use a written question guide for every interview, even informal walkthroughs.
  • Score or rate responses against predetermined criteria when comparing multiple interviewees on the same control.
  • Document the basis for reliability assessments, not just the conclusion.
  • Train newer auditors on the cone technique before they conduct interviews independently.

Key insight: Structured interviews do not make conversations rigid. They make the evidence defensible. An interviewee can still speak freely; the structure ensures you capture and assess what they say consistently.


Recording laws in the United States vary by state. Federal law and most states permit one-party consent recording, meaning only one participant needs to consent. However, a significant number of states, including California, Florida, and Illinois, require all-party consent. The practical guidance: unless you have confirmed the applicable state law and obtained explicit consent from all participants, do not record.

Key legal and ethical obligations:

  • Confidentiality: Inform interviewees at the outset what will be done with their responses, who will see the minutes, and how sensitive disclosures will be handled.
  • Whistleblower statements: If an interviewee makes a protected disclosure, document it accurately, escalate to legal counsel or the audit committee as appropriate, and take steps to protect the interviewee’s identity in working papers.
  • Sensitive personal information: Do not include personally identifiable information in working papers beyond what is necessary to support the finding.
  • Consent for recording: Obtain written or email confirmation of consent before recording any interview, regardless of state law, as a matter of professional practice.
  • Scope boundaries: Do not expand the interview into areas outside the stated audit scope without notifying the interviewee and obtaining authorization from the audit manager.
  • Regulatory note: In formal investigations or regulatory audits, interview evidence may be subject to discovery or subpoena. Treat all interview documentation as potentially reviewable by external parties.

What experienced auditors actually do with interviews across fieldwork

The sequence that consistently produces the best evidence is not complicated, but it requires discipline. Start fieldwork with orientation interviews: process owners, department heads, and control designers. Use those conversations to build your control map and identify where the documented design and the described reality diverge. That divergence tells you where to focus examination interviews.

Examination interviews go to the operators: the people who run the process daily. Ask behavioral questions. Ask for recent examples. When an answer contradicts the control map you built in the orientation phase, you have a potential finding. When it confirms it, you have corroboration.

Auditor inspecting physical security lock

Confirmation interviews come last. By that point, you have transaction evidence, system logs, and two layers of interview data. A short confirmation interview with the control owner, presenting what you found and asking them to explain it, either closes the finding or deepens it.

One habit that changes the quality of every interview: schedule a 15-minute pre-brief with your team the morning of a major interview. Review the background documents, confirm the question guide, and agree on what a satisfactory answer to each key question looks like. Auditors who do this consistently report fewer “we forgot to ask” moments in the debrief.

Interviews also serve a purpose beyond evidence. Auditors who use interviews to build relationships with process owners get better cooperation throughout the engagement, faster responses to document requests, and more candid disclosures when something is wrong. That is not a soft benefit. It is a material factor in audit quality.

Hands pouring coffee during professional conversation


Ismscalculator helps you scope ISO 27001 interview targets before fieldwork begins

Ismscalculator

When your audit covers ISO 27001 controls, knowing which domains carry the most implementation risk tells you exactly where to focus your interviews. Ismscalculator’s free 2-minute readiness check maps your organization’s current maturity across all 14 ISO 27001 domains in minutes, giving you a domain-by-domain risk profile you can use to prioritize interview targets and evidence collection before fieldwork starts.

The full readiness assessment goes further: it benchmarks your maturity against industry averages, flags the domains most likely to surface control gaps, and produces a report you can use as a planning input for your interview program. Treat the output as a scoping aid, not a substitute for the interviews themselves. The tool narrows your focus; your interviews produce the evidence.


Sources

Bereit, Ihre ISO 27001-Kosten zu schätzen?

Nutzen Sie unseren kostenlosen Rechner für eine maßgeschneiderte Kosten-, Aufwands- und Zeitplanschätzung basierend auf Ihrem Unternehmensprofil.

Zurück zu allen Artikeln