Skip to main content
Internal audit software

Run the full assurance lifecycle of your internal audit function

A complete five-step assurance lifecycle — a risk-based annual plan, fieldwork with workpapers and review, findings tracked through to closure.

GIAS 2024ISO 19011Three lines of defence
Illustration of the product interface
What to know before you choose

Is this module right for your internal audit function?

What is RiskTech internal audit?

It is the module that runs the entire assurance lifecycle of the internal audit function: building the annual plan from the risk map, performing engagements with workpapers and review, recording findings, issuing signed-off reports, and tracking corrective actions through to closure.

Who is it for?

The chief audit executive tracks risk coverage and stalled engagements. Team leads open and close review notes. Auditors produce workpapers and run testing. The audit committee and board receive reports. Audited units submit documents through a dedicated portal.

What problems does it solve?

Audit files sit on a shared drive so nobody knows which workpapers have been reviewed; the annual plan is built on experience rather than risk; and recommendations after the report go untracked to closure.

Is it aligned to GIAS 2024?

The processes are built around the Global Internal Audit Standards 2024, including role separation, review before conclusions, and evidence trails for every finding. RiskTech supports the process; conformance with the standards remains the organisation's responsibility.

How is it rolled out?

The module runs on its own and builds its own risk map without the risk management module. Initial data covers the org structure, the business process catalogue and the current annual audit plan.

The business problem

When files are scattered, review becomes hard to control

01

The annual plan is not risk-based

The engagement list follows habit and available resources, which is hard to justify to the audit committee.

02

Nobody knows if workpapers were reviewed

Files sit on a shared drive. It is unclear which review notes are still open, who closed them and on what basis.

03

Recommendations go untracked

Once the report is issued, that is the end of it. The next cycle reveals the corrective action was never done.

04

Stalled engagements stay invisible

The chief audit executive only learns progress by asking each team lead, usually too late to intervene.

Photo of an internal audit team working on site — landscape
Assurance lifecycle
Reviewed audit files, traceable enough for the audit committee.
End-to-end process

Run an engagement from plan through to recommendation tracking

Input
Risk map, org structure, annual plan
Activity
Workpapers · control testing · evidence collection
Control and approval
Team lead reviews and signs off before conclusions
Output
Signed-off report, recommendations tracked to closure
Internal audit lifecyclefive steps, following the Global Standards 20245 steps
  1. 1Plan
    Risk-based annual plan, scope and programme for each engagement.
  2. 2Fieldwork
    Workpapers, design and operating effectiveness testing.
  3. 3Findings
    Record findings, rate severity, confirm with the unit.
  4. 4Report
    Issue a signed-off report with evidence sources attached.
  5. 5Follow up
    Close corrective actions by deadline and update risk levels.
Product screens

See the audit process working in practice

Two representative screens illustrating the product interface. The figures shown are sample data.

Chief audit executive dashboard

Screen 1

High-risk coverage, annual plan progress and the list of stalled engagements with the specific reason for each.

Workpapers and review notes

Screen 2

Team leads open review notes on each workpaper; an engagement cannot move to conclusion while any note is open.

Feature groups

Every role sees exactly the work in front of them

Annual audit plan

Chief audit executive
  • Prioritised against the risk map
  • Completion progress tracked against plan
  • High-risk coverage expressed as a percentage

Workpapers and review

Team leads, auditors
  • Workpapers following the audit programme
  • Review notes opened and closed, with named owners
  • No conclusion possible while review notes remain open

Control testing

Auditors
  • Design and operating effectiveness testing on one form
  • Sampling with results recorded per item
  • Data testing over the dataset submitted by the unit

Findings and remediation

All roles
  • Findings carry severity, unit, owner and deadline
  • Printable sheets with evidence sources and sign-off
  • Alerts for overdue actions

Executive dashboard

Chief audit executive, audit committee
  • Stalled engagements with the specific reason
  • Annual plan progress across three states
  • Reports exported straight from live data

Audited unit portal

Business units
  • Receive document requests with deadlines
  • Respond to findings and commit to actions
  • See only their own unit's workload
Who it fits

Who is it for and what do you need to prepare?

Portrait photo of an internal auditor
Who it fitsWhen to use itData to prepare
Internal audit functions of three people or moreWhen files need standardising before a quality assessmentThe current annual audit plan
Listed companies or organisations with an audit committeeWhen the committee requires periodic reports with consistent figuresOrg structure and process catalogue
Organisations adopting GIAS 2024When moving from paper files and shared drives to a systemThe list of identified controls and risks
Reference standards

Which standards is it built around?

RiskTech supports organisations operating to the standards below. This is not a certification claim for the software or for the organisations using it.

GIAS 2024
Global Internal Audit Standards
ISO 19011
Guidelines for auditing management systems
Three lines of defence
Responsibility model
Application scenario

Illustrative application scenario

This scenario explains how the product is used; it is not the result of a rollout at a specific client. Once we have a real client scenario with written consent to publish, this section will be updated.

Frequently asked questions

Internal audit

See how RiskTech supports your internal audit work

A 30-minute demo following the role you hold. No data preparation needed beforehand. We respond within one business day.

ceo-office@risktech.asia