Internal Audit Team Workflows

Open-source workflows owned by or involving Internal Audit. Review the steps, responsibilities and evidence, then download templates for your AssureSwarm instance.

All workflows 212 IT 92 HR 11 Finance 27 Internal Audit 45 Risk Management 32 Compliance & Legal 32 Privacy 11 Procurement 15 Executive 20 AI Governance 11 Facilities 7 Business Operations 9
  • Annual Internal Audit Planning & Resource Management — Internal Audit · 7 steps
    Run the chief audit executive's annual internal audit planning cycle: refresh the audit universe and the documented understanding of governance, risk, and control processes, develop the risk-based strategy and plan, secure the budget, staffing, and technology to deliver it, obtain board approval, and reassess the plan and resource sufficiency each quarter as the risk landscape changes.
  • Audit Engagement Planning — Internal Audit · 8 steps
    Establish the scope, engagement risk assessment, control population, and sampling plan for an already-opened audit engagement — together the engagement Risk & Control Matrix (RCM) — culminating in an approved planning memo and an enriched audit record handed to fieldwork.
  • Audit Fieldwork, Findings & Reporting — Internal Audit · 3 steps
    Execute approved audit procedures, evaluate and clear observations, issue a supported report, and close the engagement record with tracked actions.
  • Audit Planning and Scoping — Internal Audit · 2 steps
    Define engagement objectives, boundaries, independence, program, resources and approval before fieldwork.
  • Audit Report Drafting — Internal Audit · 10 steps
    Compile fieldwork findings into a formal audit report, from issue drafting and executive summary through management responses and final issuance.
  • Combined Assurance Mapping — Internal Audit; with Risk Management · 7 steps
    Map effective assurance across the Three Lines, resolve self-review safeguards, assess independent reliance and agree coverage commitments; govern remaining gaps and deliver the map and evidence to audit-committee reporting.
  • Continuous Monitoring & Agent Evaluation — Internal Audit · 2 steps
    Run the standing continuous auditing program: define KRI thresholds and queries, build and approve the monitoring dashboard, run the recurring monitoring cycle and triage breaches, then sample and grade agent-drafted suggestions and step results from across the course against the agent-draft rubric and raise every agent-quality finding as an owned issue.
  • Control Design Assessment — Internal Audit · 1 steps
    Judge whether the control's precision, evidence, ownership, frequency and segregation address its stated risk.
  • Control Exception Evaluation and Remediation — Internal Audit; with Risk Management · 2 steps
    Evaluate exception scope, impact, severity and compensating controls, then obtain management-owned remediation and authorized escalation.
  • Control Interim Testing Record — Internal Audit · 2 steps
    Test a defined interim-period population using a documented sampling and attribute plan, then record exceptions and a bounded conclusion.
  • Control Remediation Retest and Closure — Internal Audit · 2 steps
    Independently retest failed attributes on post-remediation evidence, assess recurrence and authorize finding closure.
  • Control Walkthrough — Internal Audit · 1 steps
    Trace an actual occurrence from input through operator action and retained evidence, challenging differences between procedure and practice.
  • Cybersecurity Assurance Review — Internal Audit; with IT · 8 steps
    Run a CAE-owned cybersecurity assurance review on the existing IT-audit engagement item — IIA Topical Requirement coverage tested against NIST 800-53 — producing a four-Cs findings register and a Standard 14.5 posture conclusion for report drafting.
  • Finding Remediation & Action-Plan Monitoring — Internal Audit · 7 steps
    Track audit findings and agreed actions from registration through evidence validation, escalation, risk acceptance, and committee reporting.
  • Fraud & Forensic Investigation Engagement — Internal Audit; with Compliance & Legal · 13 steps
    Run a predication-gated fraud and forensic investigation from allegation intake through evidence preservation, forensic procedures, interviews, loss quantification, audit-committee reporting, and referral and remediation handoffs.
  • Fraud Risk Assessment & JE Testing — Internal Audit · 2 steps
    Assess fraud risks across the fraud triangle and management override, map anti-fraud controls, profile and flag the journal-entry population, draw a reproducible random sample from the unflagged remainder, test every selected entry for support, and raise unsupported anomalies as issues.
  • Interim Operating Effectiveness Testing — Internal Audit; with Finance · 2 steps
    Review program coverage and aggregate interim exceptions from approved Control tests, then agree auditor reliance and management actions.
  • Internal Audit Charter, Independence & Board Governance Cycle — Internal Audit; with Executive · 8 steps
    Run the internal audit function's board-governance cycle: deliver the CAE's functional reporting and executive sessions to the audit committee, secure committee action on the CAE's appointment, evaluation, remuneration, and the audit plan and budget, and reaffirm the function's organizational independence in writing. Lead the periodic board review and reapproval of the audit mandate and charter with its unrestricted-access provisions, execute the stakeholder communication plan across the board, management, regulators, and external auditors, and retain the governance evidence.
  • Internal Audit Engagement Lifecycle — Internal Audit · 7 steps
    Run an IIA-aligned engagement on the existing Audit item — from evidence requests and fieldwork through an evaluated findings register (Issue items), conclusions per objective, a report-ready handoff package, and registered action plans.
  • Internal Audit Ethics, Objectivity & Competency Program — Internal Audit · 6 steps
    Run the internal audit function's annual professional-practice cycle: every auditor and assisting party attests to the ethics and professional-courage expectations with deviations documented and resolved, signs conflict-of-interest declarations backed by per-engagement conflict screening, assignment rotation, and recusal, and completes confidentiality acknowledgments while access to audit files is reviewed and restricted; the cycle closes with competency assessment against role requirements and approved, tracked continuing-professional-development plans for each auditor.
  • ISMS Internal Audit & Management Review — Internal Audit; with IT, Executive · 6 steps
    Run the ISMS clause 9.2 internal audit and clause 9.3 management review: findings, corrective actions, review inputs, decisions, and follow-up.
  • ISO 27001 Certification Readiness — Internal Audit · 2 steps
    Assess ISO/IEC 27001 certification readiness across ISMS scope, clauses, risk treatment, Annex A applicability, internal assurance, gaps, and audit-entry governance.
  • ISO 27001 Stage 1 ISMS Documentation Review — Internal Audit · 1 steps
    Review ISMS clauses 4–10 documentation, record findings, and conclude readiness for Stage 2 planning.
  • ISO 27001 Stage 2 Annex A Controls Audit — Internal Audit · 5 steps
    Audit the organizational, people, physical and technological Annex A controls in the approved Statement of Applicability, with specialist assessments and an independent conclusion.
  • ISO/IEC 42001 AI Management System Internal Audit — Internal Audit; with AI Governance · 2 steps
    Plan and perform an independent internal audit of an AI management system against ISO/IEC 42001, using AIUC-1 crosswalk evidence where it helps test AI-specific safeguards; document findings, management actions, and an independent conclusion without presenting the work as certification.
  • ITGC Change & Provisioning Testing — Internal Audit · 2 steps
    Test the design and operating effectiveness of change-management and access-provisioning controls for one in-scope system: validate the populations, draw the samples, test each ticket against the control's attributes, conclude, and raise exceptions.
  • Period-End Roll-Forward / Rollover Testing — Internal Audit · 2 steps
    Bridge an approved interim control test through period end by assessing change, remaining occurrences, incremental evidence, and unresolved exceptions.
  • Period-End Roll-Forward Testing — Internal Audit; with Finance · 3 steps
    Bridge interim testing to period end using the remaining population, control changes, additional evidence and a bounded combined conclusion.
  • Process Narrative & Walkthrough — Internal Audit · 1 steps
    Document an end-to-end process, corroborate the narrative through a representative walkthrough, and approve a traceable current-state record.
  • Process Walkthrough & Design Assessment — Internal Audit · 2 steps
    Perform a SOX process walkthrough, update the ICFR narrative and control mapping, and document design observations for management follow-up.
  • Quality Assurance & Improvement Program Cycle — Internal Audit · 10 steps
    Operate the QAIP cycle on a per-cycle Audit item — ongoing-monitoring evidence, periodic self-assessment, external quality assessment support, improvement planning, and board reporting — producing the per-standard conformance ratings matrix, below-GC finding Issues, and the QAIP results report handed to board reporting.
  • Quarterly Board & Audit-Committee GRC Reporting — Risk Management; with Internal Audit, Executive · 6 steps
    Compile the quarterly GRC board pack across risk profile, audit, SOX, regulatory deadlines, control health, incidents, issues, and decisions.
  • SOC 2 Availability Assessment — Internal Audit · 1 steps
    Assess design readiness for Availability with documented evidence, findings and reviewer conclusions.
  • SOC 2 Confidentiality Assessment — Internal Audit · 1 steps
    Assess design readiness for Confidentiality with documented evidence, findings and reviewer conclusions.
  • SOC 2 Privacy Criteria Assessment — Internal Audit · 1 steps
    Assess design readiness for Privacy with documented evidence, findings and reviewer conclusions.
  • SOC 2 Processing Integrity Assessment — Internal Audit · 1 steps
    Assess design readiness for Processing Integrity with documented evidence, findings and reviewer conclusions.
  • SOC 2 Trust Services Readiness — Internal Audit · 3 steps
    Assess SOC 2 CC1–CC9 design readiness, reconcile scoped category assessments, and approve a criterion-level readiness disposition with evidence, findings and owned actions.
  • SOC 2 Type II Interim Testing — Internal Audit · 2 steps
    Perform SOC 2 Type II interim walkthroughs and control testing, then triage exceptions for remediation and retest.
  • SOX Control Testing — Internal Audit · 2 steps
    Native SAMPLE approves history, attributes and reproducible selection; TEST independently approves evidence, exceptions and the published SOX result for the fiscal year.
  • SOX IPE Validation — Internal Audit; with Finance · 7 steps
    Validate an Information Produced by the Entity (IPE) report for completeness and accuracy, then decide whether it is reliable control evidence or a deficiency.
  • SOX ITGC Testing — Internal Audit; with IT, Finance · 8 steps
    Scope and test SOX-relevant ITGCs by referencing the controls-owned 800-53 catalog and test scripts rather than rebuilding procedures.
  • SOX Key Control TOD/TOE Test — Internal Audit; with Finance · 10 steps
    Test key controls for design and operating effectiveness, including walkthrough, sampling, IPE linkage, exception handling, and reviewer sign-off.
  • SOX Process Walkthrough — Finance; with Internal Audit · 7 steps
    Capture an end-to-end process walkthrough and identify the key controls inside it, producing a walkthrough memo and draft control records.
  • Substantive Testing & Data Analytics — Internal Audit · 2 steps
    Validates a test population, draws a reproducible sample sized to risk, runs whole-population analytics (duplicates, gaps, three-way match) alongside it, evaluates and projects exceptions, and concludes on the tested FSLI assertion(s).
  • Third-Party Vendor Assurance Engagement — Internal Audit; with Procurement · 8 steps
    Run an IA-led third-party assurance engagement covering governance, risk tiering, control environment, monitoring, exclusions, and reporting.
Privacy Terms