Internal Audit Workflows

Free, open-source internal audit workflow templates — engagement planning, control testing, walkthroughs and more. Preview the steps, then import them directly into your AssureSwarm instance.

All workflows 212 IT 92 HR 11 Finance 27 Internal Audit 45 Risk Management 32 Compliance & Legal 32 Privacy 11 Procurement 15 Executive 20 AI Governance 11 Facilities 7 Business Operations 9
  • Annual Internal Audit Planning & Resource Management — Internal Audit · 7 steps
    Run the chief audit executive's annual internal audit planning cycle: refresh the audit universe and the documented understanding of governance, risk, and control processes, develop the risk-based strategy and plan, secure the budget, staffing, and technology to deliver it, obtain board approval, and reassess the plan and resource sufficiency each quarter as the risk landscape changes.
  • Audit Engagement Planning — Internal Audit · 8 steps
    Establish the scope, engagement risk assessment, control population, and sampling plan for an already-opened audit engagement — together the engagement Risk & Control Matrix (RCM) — culminating in an approved planning memo and an enriched audit record handed to fieldwork.
  • Audit Fieldwork, Findings & Reporting — Internal Audit · 3 steps
    Execute approved audit procedures, evaluate and clear observations, issue a supported report, and close the engagement record with tracked actions.
  • Audit Planning and Scoping — Internal Audit · 2 steps
    Define engagement objectives, boundaries, independence, program, resources and approval before fieldwork.
  • Audit Report Drafting — Internal Audit · 10 steps
    Compile fieldwork findings into a formal audit report, from issue drafting and executive summary through management responses and final issuance.
  • Continuous Monitoring & Agent Evaluation — Internal Audit · 2 steps
    Run the standing continuous auditing program: define KRI thresholds and queries, build and approve the monitoring dashboard, run the recurring monitoring cycle and triage breaches, then sample and grade agent-drafted suggestions and step results from across the course against the agent-draft rubric and raise every agent-quality finding as an owned issue.
  • Control Design Assessment — Internal Audit · 1 steps
    Judge whether the control's precision, evidence, ownership, frequency and segregation address its stated risk.
  • Control Exception Evaluation and Remediation — Internal Audit; with Risk Management · 2 steps
    Evaluate exception scope, impact, severity and compensating controls, then obtain management-owned remediation and authorized escalation.
  • Control Remediation Retest and Closure — Internal Audit · 2 steps
    Independently retest failed attributes on post-remediation evidence, assess recurrence and authorize finding closure.
  • Control Walkthrough — Internal Audit · 1 steps
    Trace an actual occurrence from input through operator action and retained evidence, challenging differences between procedure and practice.
  • Cybersecurity Assurance Review — Internal Audit; with IT · 8 steps
    Run a CAE-owned cybersecurity assurance review on the existing IT-audit engagement item — IIA Topical Requirement coverage tested against NIST 800-53 — producing a four-Cs findings register and a Standard 14.5 posture conclusion for report drafting.
  • Finding Remediation & Action-Plan Monitoring — Internal Audit · 7 steps
    Track audit findings and agreed actions from registration through evidence validation, escalation, risk acceptance, and committee reporting.
  • Fraud & Forensic Investigation Engagement — Internal Audit; with Compliance & Legal · 13 steps
    Run a predication-gated fraud and forensic investigation from allegation intake through evidence preservation, forensic procedures, interviews, loss quantification, audit-committee reporting, and referral and remediation handoffs.
  • Fraud Risk Assessment & JE Testing — Internal Audit · 2 steps
    Assess fraud risks across the fraud triangle and management override, map anti-fraud controls, profile and flag the journal-entry population, draw a reproducible random sample from the unflagged remainder, test every selected entry for support, and raise unsupported anomalies as issues.
  • Internal Audit Charter, Independence & Board Governance Cycle — Internal Audit; with Executive · 8 steps
    Run the internal audit function's board-governance cycle: deliver the CAE's functional reporting and executive sessions to the audit committee, secure committee action on the CAE's appointment, evaluation, remuneration, and the audit plan and budget, and reaffirm the function's organizational independence in writing. Lead the periodic board review and reapproval of the audit mandate and charter with its unrestricted-access provisions, execute the stakeholder communication plan across the board, management, regulators, and external auditors, and retain the governance evidence.
  • Internal Audit Engagement Lifecycle — Internal Audit · 7 steps
    Run an IIA-aligned engagement on the existing Audit item — from evidence requests and fieldwork through an evaluated findings register (Issue items), conclusions per objective, a report-ready handoff package, and registered action plans.
  • Internal Audit Ethics, Objectivity & Competency Program — Internal Audit · 6 steps
    Run the internal audit function's annual professional-practice cycle: every auditor and assisting party attests to the ethics and professional-courage expectations with deviations documented and resolved, signs conflict-of-interest declarations backed by per-engagement conflict screening, assignment rotation, and recusal, and completes confidentiality acknowledgments while access to audit files is reviewed and restricted; the cycle closes with competency assessment against role requirements and approved, tracked continuing-professional-development plans for each auditor.
  • ISO 27001 Certification Readiness — Internal Audit · 2 steps
    Assess ISO/IEC 27001 certification readiness across ISMS scope, clauses, risk treatment, Annex A applicability, internal assurance, gaps, and audit-entry governance.
  • ISO 27001 Stage 1 ISMS Documentation Review — Internal Audit · 1 steps
    Review ISMS clauses 4–10 documentation, record findings, and conclude readiness for Stage 2 planning.
  • ISO 27001 Stage 2 Annex A Controls Audit — Internal Audit · 5 steps
    Audit the organizational, people, physical and technological Annex A controls in the approved Statement of Applicability, with specialist assessments and an independent conclusion.
  • ISO/IEC 42001 AI Management System Internal Audit — Internal Audit; with AI Governance · 2 steps
    Plan and perform an independent internal audit of an AI management system against ISO/IEC 42001, using AIUC-1 crosswalk evidence where it helps test AI-specific safeguards; document findings, management actions, and an independent conclusion without presenting the work as certification.
  • ITGC Change & Provisioning Testing — Internal Audit · 2 steps
    Test the design and operating effectiveness of change-management and access-provisioning controls for one in-scope system: validate the populations, draw the samples, test each ticket against the control's attributes, conclude, and raise exceptions.
  • Process Narrative & Walkthrough — Internal Audit · 1 steps
    Document an end-to-end process, corroborate the narrative through a representative walkthrough, and approve a traceable current-state record.
  • Quality Assurance & Improvement Program Cycle — Internal Audit · 10 steps
    Operate the QAIP cycle on a per-cycle Audit item — ongoing-monitoring evidence, periodic self-assessment, external quality assessment support, improvement planning, and board reporting — producing the per-standard conformance ratings matrix, below-GC finding Issues, and the QAIP results report handed to board reporting.
  • SOC 2 Availability Assessment — Internal Audit · 1 steps
    Assess design readiness for Availability with documented evidence, findings and reviewer conclusions.
  • SOC 2 Confidentiality Assessment — Internal Audit · 1 steps
    Assess design readiness for Confidentiality with documented evidence, findings and reviewer conclusions.
  • SOC 2 Privacy Criteria Assessment — Internal Audit · 1 steps
    Assess design readiness for Privacy with documented evidence, findings and reviewer conclusions.
  • SOC 2 Processing Integrity Assessment — Internal Audit · 1 steps
    Assess design readiness for Processing Integrity with documented evidence, findings and reviewer conclusions.
  • SOC 2 Trust Services Readiness — Internal Audit · 3 steps
    Assess SOC 2 CC1–CC9 design readiness, reconcile scoped category assessments, and approve a criterion-level readiness disposition with evidence, findings and owned actions.
  • SOC 2 Type II Interim Testing — Internal Audit · 2 steps
    Perform SOC 2 Type II interim walkthroughs and control testing, then triage exceptions for remediation and retest.
  • Substantive Testing & Data Analytics — Internal Audit · 2 steps
    Validates a test population, draws a reproducible sample sized to risk, runs whole-population analytics (duplicates, gaps, three-way match) alongside it, evaluates and projects exceptions, and concludes on the tested FSLI assertion(s).
  • Third-Party Vendor Assurance Engagement — Internal Audit; with Procurement · 8 steps
    Run an IA-led third-party assurance engagement covering governance, risk tiering, control environment, monitoring, exclusions, and reporting.
Privacy Terms