Skip to content

Audit Engagements

Where to find it: Audit & Inspection, then Audit Management (/audit).

An Audit Engagement (AUD-YYYY-NNNN) is a single piece of audit work: its scope, its team, its procedures, its findings and its opinion.


Engagement types

TypeMeaning
internalAn internal audit engagement under the audit plan
regulatoryAudit work responding to a regulatory driver
third_partyAudit of a third party or an outsourced arrangement
specialA special or unplanned engagement

Lifecycle

StatusMeaning
draftCreated, not yet scoped
planningScope being defined
scheduledResourced and timetabled
fieldworkProcedures being executed
reviewProcedures and workpapers under review
reportingDraft report and opinion being prepared
finalizedOpinion issued and report snapshot frozen
closedComplete

Scope

Engagement scope is defined by linking to canonical objects rather than by describing scope in prose alone.

LinkableExample
AssetsSpecific systems
Business servicesAn important business service
Departments and legal entitiesAn organisational boundary
Third parties and engagementsAn outsourced arrangement
RequirementsThe obligations being examined
ControlsThe controls being tested
RisksThe risks the engagement provides assurance over

Linking scope this way means the engagement's coverage can be queried later — "which engagements have covered this business service?" is answerable.


Team and dates

FieldPurpose
Lead auditorAccountable for the engagement
Audit teamAssigned auditors
Auditee owner and departmentWho the engagement is with
Planned start and endThe intended timetable
Actual start and endWhat happened
Report due dateWhen the report is committed

Report due dates project into the GRC Calendar.


Creating an engagement

  1. Create the engagement, optionally under an approved plan.
  2. Set its type, title and auditee.
  3. Move to planning and link its scope.
  4. Assign the lead auditor and team, and set dates.
  5. Move to scheduled, then fieldwork when work begins.

Requires audit.engagement_manage.


Permissions

ActionPermission
View engagements, workpapers, procedures and reportsaudit.engagement_read
Create, update and manage engagementsaudit.engagement_manage
Execute procedures and record test resultsaudit.engagement_execute
Review procedures and workpapersaudit.engagement_review
Sign off reports and issue opinionsaudit.engagement_signoff
Validate finding closure by retestaudit.finding_validate
Generate advisory AI suggestionsaudit.ai_assist

All require the audit_management entitlement.


Example

Engagement AUD-2026-0003 — Privileged Access Management Review.

FieldValue
Typeinternal
PlanFY2026 Internal Audit Plan
Lead auditorSenior IT Auditor
TeamTwo auditors
AuditeeHead of IT Security
PlannedQ1, six weeks
Report dueEnd of Q1

Scope links:

ObjectRecords
Business serviceCore Banking
Assets38 systems in SCP-2026-0004
ControlsCTL-2026-0041, CTL-2026-0044, CTL-2026-0067
RequirementsA.5.15, A.5.18, A.8.2
RiskRSK-2026-0014

Because scope is linked rather than described, the engagement's coverage is queryable — and when the same controls are considered for next year's plan, the platform can show they were audited in Q1 2026 and what the opinion was.


Troubleshooting

"I cannot move an engagement to finalized." Finalisation follows governed sign-off. See Audit Sign-off.

"A finalized engagement shows old control data." Correct. Finalisation freezes a report snapshot so later changes never rewrite the audit conclusion.

"I cannot create an engagement." Requires audit.engagement_manage and the audit_management entitlement.


OrviQ Enterprise Governance, Risk & Compliance Platform