Appearance
Audit Engagements
Where to find it: Audit & Inspection, then Audit Management (/audit).
An Audit Engagement (AUD-YYYY-NNNN) is a single piece of audit work: its scope, its team, its procedures, its findings and its opinion.
Engagement types
| Type | Meaning |
|---|---|
internal | An internal audit engagement under the audit plan |
regulatory | Audit work responding to a regulatory driver |
third_party | Audit of a third party or an outsourced arrangement |
special | A special or unplanned engagement |
Lifecycle
| Status | Meaning |
|---|---|
draft | Created, not yet scoped |
planning | Scope being defined |
scheduled | Resourced and timetabled |
fieldwork | Procedures being executed |
review | Procedures and workpapers under review |
reporting | Draft report and opinion being prepared |
finalized | Opinion issued and report snapshot frozen |
closed | Complete |
Scope
Engagement scope is defined by linking to canonical objects rather than by describing scope in prose alone.
| Linkable | Example |
|---|---|
| Assets | Specific systems |
| Business services | An important business service |
| Departments and legal entities | An organisational boundary |
| Third parties and engagements | An outsourced arrangement |
| Requirements | The obligations being examined |
| Controls | The controls being tested |
| Risks | The risks the engagement provides assurance over |
Linking scope this way means the engagement's coverage can be queried later — "which engagements have covered this business service?" is answerable.
Team and dates
| Field | Purpose |
|---|---|
| Lead auditor | Accountable for the engagement |
| Audit team | Assigned auditors |
| Auditee owner and department | Who the engagement is with |
| Planned start and end | The intended timetable |
| Actual start and end | What happened |
| Report due date | When the report is committed |
Report due dates project into the GRC Calendar.
Creating an engagement
- Create the engagement, optionally under an approved plan.
- Set its type, title and auditee.
- Move to
planningand link its scope. - Assign the lead auditor and team, and set dates.
- Move to
scheduled, thenfieldworkwhen work begins.
Requires audit.engagement_manage.
Permissions
| Action | Permission |
|---|---|
| View engagements, workpapers, procedures and reports | audit.engagement_read |
| Create, update and manage engagements | audit.engagement_manage |
| Execute procedures and record test results | audit.engagement_execute |
| Review procedures and workpapers | audit.engagement_review |
| Sign off reports and issue opinions | audit.engagement_signoff |
| Validate finding closure by retest | audit.finding_validate |
| Generate advisory AI suggestions | audit.ai_assist |
All require the audit_management entitlement.
Example
Engagement AUD-2026-0003 — Privileged Access Management Review.
| Field | Value |
|---|---|
| Type | internal |
| Plan | FY2026 Internal Audit Plan |
| Lead auditor | Senior IT Auditor |
| Team | Two auditors |
| Auditee | Head of IT Security |
| Planned | Q1, six weeks |
| Report due | End of Q1 |
Scope links:
| Object | Records |
|---|---|
| Business service | Core Banking |
| Assets | 38 systems in SCP-2026-0004 |
| Controls | CTL-2026-0041, CTL-2026-0044, CTL-2026-0067 |
| Requirements | A.5.15, A.5.18, A.8.2 |
| Risk | RSK-2026-0014 |
Because scope is linked rather than described, the engagement's coverage is queryable — and when the same controls are considered for next year's plan, the platform can show they were audited in Q1 2026 and what the opinion was.
Troubleshooting
"I cannot move an engagement to finalized." Finalisation follows governed sign-off. See Audit Sign-off.
"A finalized engagement shows old control data." Correct. Finalisation freezes a report snapshot so later changes never rewrite the audit conclusion.
"I cannot create an engagement." Requires audit.engagement_manage and the audit_management entitlement.