Days 1–30: read the paper trail, not the org chart
The temptation in week one is a tour of introductions. Resist it long enough to read four things closely first, because they will make every subsequent meeting sharper. Read the last two years of audit reports — not the summaries, the reports — and note which functions have never been visited. Read the audit committee minutes for the same period and mark where the committee pushed back, and where it merely received. Read the risk register against the audit plan and list every risk with no corresponding assurance. And read the open-findings ledger with one question in mind: what is the age of the oldest critical action, and who has accepted living with it?
This reading yields the map you actually need: not what the function says it covers, but what it demonstrably has and has not looked at. In most airline audit functions the pattern is visible within days — strong recurring coverage of finance, procurement and stations; thin or absent coverage of revenue management, network planning, fuel, maintenance contracts and the commercial deals that move the largest sums.
Days 31–60: meet the business where the money moves
The second month is for conversations — but structured ones, held after the reading, so you can ask about specifics rather than collect assurances. Beyond the obvious meetings with the CFO, audit committee chair and external auditors, prioritise the executives whose functions the paper trail showed to be under-assured: the head of revenue management, the head of network planning, the head of fuel, the head of engineering and maintenance, the head of cargo. Ask each the same three questions. What could go materially wrong in your area that nobody outside it would see quickly? When were you last audited, and was it useful? Where do you rely on a spreadsheet you wish you did not?
The answers matter less individually than in pattern. Executives who answer the first question fluently have thought about their risk; those who answer it with "our processes are robust" have not been asked recently — usually because no one from audit has been in the room for years.
The most dangerous areas in an airline are rarely the ones with the worst audit findings. They are the ones with no findings because there has been no audit.
The early signals that assurance is thin
Across these first two months, a handful of signals reliably indicate where the function you have inherited needs rebuilding:
- The audit universe reads like a generic corporate template — finance-heavy, station-light, with no entries for revenue management, slot portfolio, hedging execution or wet-lease oversight.
- Critical actions are routinely re-dated rather than escalated, and the committee pack presents ageing without ownership.
- The analytics capability is one person with database access rather than a tested, repeatable set of full-population routines.
- Audit reports describe control weaknesses without ever quantifying exposure — a sign the function lacks the data access or commercial confidence to size what it finds.
- The team's aviation depth sits in one or two veterans near retirement, with no plan to transfer what they know.
Days 61–100: size two risks and show the method
By day sixty you will have a list of under-assured areas far longer than any plan can absorb. Do not present the list; present evidence. Choose two risks — one revenue-side, one cost-side — where data exists and exposure is plausibly material, and run rapid sizing reviews: full-population analytics where possible, a tightly scoped fieldwork sprint where not. The purpose is threefold. It gives the audit committee a concrete, quantified reason to support the plan changes you are about to propose. It shows the team the working method you expect. And it tests, cheaply, whether the function's data access and analytical muscle are what they claimed to be.
Close the hundred days with a short memo to the committee: what the function has covered and not covered, what the two sizing reviews found, the three-year direction for the plan and the capability gaps — people, data access, analytics — that need investment. Ask explicitly for the committee's position on the risks you propose to leave uncovered. Making non-coverage a documented committee decision, rather than a silent default, is perhaps the most important governance shift a new CAE can make.
What not to do
Three failure patterns recur in new-CAE transitions. Do not reorganise the team before you understand the work — structure follows plan, not the reverse. Do not announce a transformation of the function in month one and spend the year on methodology documents while audits stall; credibility comes from findings, not frameworks. And do not quietly accept the inherited plan for a full cycle "to learn the business" — the committee hired a fresh pair of eyes, and a year of continuity is a year of the same blind spots with a new signature on them.
Where to start
If you are in the role now, start with the open-findings ledger and the audit-universe-versus-risk-register comparison — both are available this week and neither requires anyone's permission. If you chair the committee that has just appointed a CAE, ask for the hundred-day memo described above and put it on the agenda before the appointment is three months old. Either way, the first hundred days set the terms for the next three years; they are worth planning with the same rigour you would demand of an audit.