We are in the currently in the process of completing a formal assessment by an external person. He is using the OCC Internal Control Questionnaire and Verification Procedures with management to conduct their portion of the assessment. We have not started the departmental observation yet.
Also each time I perform a specific audit, I try to conduct a "small" risk assessment for that specific area, service, product, etc.
Hope this helps.
Opinions are mine not my employer