Cowork Canvas
Workflows Mapping Book a Walkthrough
Book a Walkthrough

Internal Audit Workflows

Free, open-source internal audit workflow templates — engagement planning, control testing, walkthroughs and more. Preview the steps, then import them directly into your CoworkCanvas instance.

All Internal Audit SOX Regulatory Controls
  • Annual Internal Audit Planning & Resource Management — Internal Audit · 11 steps
    Run the chief audit executive's annual internal audit planning cycle: refresh the audit universe and the documented understanding of governance, risk, and control processes, develop the risk-based strategy and plan, secure the budget, staffing, and technology to deliver it, obtain board approval, and reassess the plan and resource sufficiency each quarter as the risk landscape changes.
  • Audit Engagement Planning — Internal Audit · 17 steps
    Establish the scope, engagement risk assessment, control population, and sampling plan for an already-opened audit engagement — together the engagement Risk & Control Matrix (RCM) — culminating in an approved planning memo and an enriched audit record handed to fieldwork.
  • Audit Report Drafting — Internal Audit · 15 steps
    Compile fieldwork findings into a formal audit report, from issue drafting and executive summary through management responses and final issuance.
  • Cybersecurity Assurance Review — Internal Audit · 16 steps
    Run a CAE-owned cybersecurity assurance review on the existing IT-audit engagement item — IIA Topical Requirement coverage tested against NIST 800-53 — producing a four-Cs findings register and a Standard 14.5 posture conclusion for report drafting.
  • Finding Remediation & Action-Plan Monitoring — Internal Audit · 12 steps
    Track audit findings and agreed actions from registration through evidence validation, escalation, risk acceptance, and committee reporting.
  • Fraud & Forensic Investigation Engagement — Internal Audit · 18 steps
    Run a predication-gated fraud and forensic investigation from allegation intake through evidence preservation, forensic procedures, interviews, loss quantification, audit-committee reporting, and referral and remediation handoffs.
  • Internal Audit Charter, Independence & Board Governance Cycle — Internal Audit · 10 steps
    Run the internal audit function's board-governance cycle: deliver the CAE's functional reporting and executive sessions to the audit committee, secure committee action on the CAE's appointment, evaluation, remuneration, and the audit plan and budget, and reaffirm the function's organizational independence in writing. Lead the periodic board review and reapproval of the audit mandate and charter with its unrestricted-access provisions, execute the stakeholder communication plan across the board, management, regulators, and external auditors, and retain the governance evidence.
  • Internal Audit Engagement Lifecycle — Internal Audit · 13 steps
    Run an IIA-aligned engagement on the existing Audit item — from evidence requests and fieldwork through an evaluated findings register (Issue items), conclusions per objective, a report-ready handoff package, and registered action plans.
  • Internal Audit Ethics, Objectivity & Competency Program — Internal Audit · 10 steps
    Run the internal audit function's annual professional-practice cycle: every auditor and assisting party attests to the ethics and professional-courage expectations with deviations documented and resolved, signs conflict-of-interest declarations backed by per-engagement conflict screening, assignment rotation, and recusal, and completes confidentiality acknowledgments while access to audit files is reviewed and restricted; the cycle closes with competency assessment against role requirements and approved, tracked continuing-professional-development plans for each auditor.
  • Quality Assurance & Improvement Program Cycle — Internal Audit · 18 steps
    Operate the QAIP cycle on a per-cycle Audit item — ongoing-monitoring evidence, periodic self-assessment, external quality assessment support, improvement planning, and board reporting — producing the per-standard conformance ratings matrix, below-GC finding Issues, and the QAIP results report handed to board reporting.
  • Third-Party Vendor Assurance Engagement — Internal Audit · 16 steps
    Run an IA-led third-party assurance engagement covering governance, risk tiering, control environment, monitoring, exclusions, and reporting.
© 2026 CoworkCanvas. All rights reserved. CoworkCanvas Privacy Terms