Audit and Assurance
Plan, execute and track audit work in one connected record.
Build a risk-based audit plan, run engagements, document working papers and control tests, and track findings through to verified follow-up.
Overview
Audit planning draws on the same risk register and control library used across the rest of the platform, so engagements are prioritised by actual risk exposure and findings connect directly back to the control or risk that produced them.
The business problem
- Audit evidence is assembled reactively, under deadline pressure, from disconnected sources.
- Findings and their follow-up are tracked separately from the audit and control that raised them.
- Audit planning isn't informed by the organisation's actual, current risk register.
Key capabilities
Planning and engagements
- Audit universe and risk-based planning
- Audit plan and individual engagements
- Working papers and sampling
Testing, findings and follow-up
- Control testing linked directly to the control library
- Findings with severity, root cause, and recommendations
- Follow-up tracked to verified closure
- Reports for management and the audit committee
How it works
- 1An audit plan is built from the risk register, prioritising the highest-exposure areas.
- 2An engagement is scoped, with working papers and a sample selected.
- 3Control tests are run and results recorded against the control library.
- 4Exceptions are logged as findings with severity and a recommendation.
- 5Remediation is tracked and the finding is verified closed before it's removed from the open list.
See it in the platform
Product screenshots for Audit and Assurance are available in a live walkthrough with a specialist.
View Product Demo →Dashboards and reports
Audit plan status
Engagement progress
Open findings by severity
Overdue follow-up
Audit committee report
Typical users
Head of Internal AuditInternal AuditorAudit CommitteeRisk/Control Owner
Business outcomes
- Audit plans prioritised by real, current risk exposure
- Findings connected directly to the control or risk that produced them
- Follow-up tracked to verified closure, not left open indefinitely
Frequently asked questions
- Does audit planning use the same risk register as the Risk module?
- Yes — audit planning is risk-based against the organisation's actual, current risk register rather than a separate audit-only risk list.
Part of the connected GRC platform