Audit settings
Internal Audit → Settings
Set-once configuration for the audit function. These are deliberately kept off the main audit rail — you touch them when the cycle starts or the methodology changes, not during fieldwork.
Everything here is per organisation, and every change is written to the audit trail with who made it.
Schedule
The annual audit Gantt. Lay planned engagements across the cycle and set their planned start and end by dragging.
The by-resource view shows each auditor's allocation against their capacity, so you can see who is over-committed before the cycle starts rather than in month seven.
Capacity planning
Internal Audit → Capacity
Works out how many man-days the function actually has, then feeds that into the annual plan so the plan is balanced against reality.
| Setting | Default | What it does |
|---|---|---|
| Hours per day | 8 | Converts man-days to man-hours in the calculator. |
| Public holidays | 12 days/auditor | Deducted from every auditor's working year. |
| Ad-hoc reserve | 15% | Held back from the team total for unplanned work. |
The calculation is shown on the page as you change the inputs:
net days per auditor = (working − public holidays − leave − training − admin)
× availability %
available man-days = (team net man-days) − ad-hoc reserve %
available man-hours = available man-days × hours per day
Apply pushes the result into the cycle's annual plan as its engagement allotment.
Set it to zero and the plan consumes 100% of capacity, so the first investigation or regulator request in the year puts you behind. 15% is a starting point, not a rule — tune it from last year's actuals.
Risk factors
Configures how the audit universe is risk-ranked and therefore what enters the plan. Documented separately in Risk scoring and factors.
Regulatory regimes
The list of regulations and standards an engagement's regulatory scope can be chosen from — KSA PDPL, NCA ECC, SAMA CSF, Qatar NIA, ISO 27001, IIA GIAS and others. Seeded with a GCC and international set.
Add your own, and disable the ones you do not use so they stop cluttering the picker.
A disabled regime stays on engagements already tagged with it. Historic engagements keep their scope exactly as it was assured — disabling only removes it from future choices.
Engagement quality criteria
The checklist a quality reviewer grades each engagement against: objective and scope, supervision, evidence sufficiency, report quality, timeliness and so on.
Seeded with the IIA 12.3 default set. Add, rename, reorder or disable criteria to match your own methodology.
These feed the Quality tab on each engagement and the QAIP reporting.
Survey templates
Reusable stakeholder-survey question sets — post-engagement satisfaction, periodic board or management surveys. Edit the questions and their types here.
When a survey is created it takes a copy of the template. Editing a template afterwards never alters surveys already issued or responses already collected — so past results stay comparable and cannot be retro-edited. To change what is asked, edit the template and issue a new survey.
Remediation reminders
Configured inline at the bottom of the settings page. This drives the daily job that chases action owners.
| Setting | Default | Range | What it does |
|---|---|---|---|
| Lead days | 3 | 0–90 | How many days before an action is due to start reminding. |
| Reminder cadence | 3 | 1–90 | Minimum days between repeat reminders for the same action. |
| Escalate after | 7 | 1–365 | Days overdue before the action escalates to the CAE. |
| Escalation to CAE | On | — | When off, overdue actions still remind the owner but never escalate. |
Values outside the ranges are clamped rather than rejected, so a typo cannot switch reminders off by accident or set a cadence of zero and spam owners daily.
Setting cadence to 3 does not promise a reminder every third day — it prevents one being sent sooner than that. Owners with several overdue actions still receive one message per action.
Work program library
Internal Audit → Program Library
Reusable audit programs (RACM). Save a good engagement's program into the library, or upload one, then apply it to future engagements instead of rebuilding the procedures each time.
Applying a template copies its procedures into the engagement. From that point the engagement owns them — editing them does not change the library, and updating the library does not reach back into engagements already running.