Skip to main content

Audit settings

Internal Audit → Settings

Set-once configuration for the audit function. These are deliberately kept off the main audit rail — you touch them when the cycle starts or the methodology changes, not during fieldwork.

Everything here is per organisation, and every change is written to the audit trail with who made it.

Schedule

The annual audit Gantt. Lay planned engagements across the cycle and set their planned start and end by dragging.

The by-resource view shows each auditor's allocation against their capacity, so you can see who is over-committed before the cycle starts rather than in month seven.

Capacity planning

Internal Audit → Capacity

Works out how many man-days the function actually has, then feeds that into the annual plan so the plan is balanced against reality.

SettingDefaultWhat it does
Hours per day8Converts man-days to man-hours in the calculator.
Public holidays12 days/auditorDeducted from every auditor's working year.
Ad-hoc reserve15%Held back from the team total for unplanned work.

The calculation is shown on the page as you change the inputs:

net days per auditor = (working − public holidays − leave − training − admin)
× availability %

available man-days = (team net man-days) − ad-hoc reserve %
available man-hours = available man-days × hours per day

Apply pushes the result into the cycle's annual plan as its engagement allotment.

The ad-hoc reserve is the setting people regret skipping

Set it to zero and the plan consumes 100% of capacity, so the first investigation or regulator request in the year puts you behind. 15% is a starting point, not a rule — tune it from last year's actuals.

Risk factors

Configures how the audit universe is risk-ranked and therefore what enters the plan. Documented separately in Risk scoring and factors.

Regulatory regimes

The list of regulations and standards an engagement's regulatory scope can be chosen from — KSA PDPL, NCA ECC, SAMA CSF, Qatar NIA, ISO 27001, IIA GIAS and others. Seeded with a GCC and international set.

Add your own, and disable the ones you do not use so they stop cluttering the picker.

Disabling is not deleting

A disabled regime stays on engagements already tagged with it. Historic engagements keep their scope exactly as it was assured — disabling only removes it from future choices.

Engagement quality criteria

The checklist a quality reviewer grades each engagement against: objective and scope, supervision, evidence sufficiency, report quality, timeliness and so on.

Seeded with the IIA 12.3 default set. Add, rename, reorder or disable criteria to match your own methodology.

These feed the Quality tab on each engagement and the QAIP reporting.

Survey templates

Reusable stakeholder-survey question sets — post-engagement satisfaction, periodic board or management surveys. Edit the questions and their types here.

Surveys snapshot their template

When a survey is created it takes a copy of the template. Editing a template afterwards never alters surveys already issued or responses already collected — so past results stay comparable and cannot be retro-edited. To change what is asked, edit the template and issue a new survey.

Remediation reminders

Configured inline at the bottom of the settings page. This drives the daily job that chases action owners.

SettingDefaultRangeWhat it does
Lead days30–90How many days before an action is due to start reminding.
Reminder cadence31–90Minimum days between repeat reminders for the same action.
Escalate after71–365Days overdue before the action escalates to the CAE.
Escalation to CAEOnWhen off, overdue actions still remind the owner but never escalate.

Values outside the ranges are clamped rather than rejected, so a typo cannot switch reminders off by accident or set a cadence of zero and spam owners daily.

Cadence is a floor, not a schedule

Setting cadence to 3 does not promise a reminder every third day — it prevents one being sent sooner than that. Owners with several overdue actions still receive one message per action.

Work program library

Internal Audit → Program Library

Reusable audit programs (RACM). Save a good engagement's program into the library, or upload one, then apply it to future engagements instead of rebuilding the procedures each time.

Applying a template copies its procedures into the engagement. From that point the engagement owns them — editing them does not change the library, and updating the library does not reach back into engagements already running.