GRC SaaS

Audit and Assurance

Plan, execute and track audit work in one connected record.

Build a risk-based audit plan, run engagements, document working papers and control tests, and track findings through to verified follow-up.

Overview

Audit planning draws on the same risk register and control library used across the rest of the platform, so engagements are prioritised by actual risk exposure and findings connect directly back to the control or risk that produced them.

The business problem

  • Audit evidence is assembled reactively, under deadline pressure, from disconnected sources.
  • Findings and their follow-up are tracked separately from the audit and control that raised them.
  • Audit planning isn't informed by the organisation's actual, current risk register.

Key capabilities

Planning and engagements

  • Audit universe and risk-based planning
  • Audit plan and individual engagements
  • Working papers and sampling

Testing, findings and follow-up

  • Control testing linked directly to the control library
  • Findings with severity, root cause, and recommendations
  • Follow-up tracked to verified closure
  • Reports for management and the audit committee

How it works

  1. 1An audit plan is built from the risk register, prioritising the highest-exposure areas.
  2. 2An engagement is scoped, with working papers and a sample selected.
  3. 3Control tests are run and results recorded against the control library.
  4. 4Exceptions are logged as findings with severity and a recommendation.
  5. 5Remediation is tracked and the finding is verified closed before it's removed from the open list.

See it in the platform

Product screenshots for Audit and Assurance are available in a live walkthrough with a specialist.

View Product Demo →

Dashboards and reports

Audit plan status
Engagement progress
Open findings by severity
Overdue follow-up
Audit committee report

Typical users

Head of Internal AuditInternal AuditorAudit CommitteeRisk/Control Owner

Business outcomes

  • Audit plans prioritised by real, current risk exposure
  • Findings connected directly to the control or risk that produced them
  • Follow-up tracked to verified closure, not left open indefinitely

Frequently asked questions

Does audit planning use the same risk register as the Risk module?
Yes — audit planning is risk-based against the organisation's actual, current risk register rather than a separate audit-only risk list.

Build a more connected audit and assurance programme.