Step 1 (program level): Utilize a data-driven approach to assessing team structures (e.g., # of reports completed per auditor, avg. audit duration, etc.)
Step 2 (engagement level): Conduct fieldwork in confined, risk-based sprints.
Reduce duplicate risk coverage (e.g., SOX Compliance, Lines of Defense).
Structures should support need for technical subject matter experts (e.g., analytics or data science, IT auditors) and non-auditor roles (e.g., transformation, metrics & reporting, operational support).
Consider cost vs. benefit of offshore or 3rd party staff augmentation or managed outcome support.