Appearance
Audit Sign-off
Sign-off is where an engagement becomes a formal audit conclusion.
The opinion
An engagement carries an opinion, issued by a person, with a rationale.
| Opinion | Typical use |
|---|---|
unqualified | No material exceptions |
qualified | Material exceptions in a specific area |
adverse | Pervasive material exceptions |
disclaimer | Insufficient evidence to form an opinion |
generally_satisfactory | Rating-scale equivalent of a positive opinion |
needs_improvement | Rating-scale equivalent of a qualified opinion |
unsatisfactory | Rating-scale equivalent of an adverse opinion |
Both an assurance-opinion vocabulary and a rating-scale vocabulary are available, because internal audit functions differ in which they use. Pick one convention and apply it consistently.
An opinion is issued by a person, never calculated
Evidence, indicators, control test results and AI assistance inform the opinion. Nothing in OrviQ computes one.
An opinion is a professional judgement that carries the auditor's name. A platform that generated it would be issuing an opinion nobody signed.
The opinion records its rationale, who issued it and when.
Governed sign-off
Sign-off consumes the organisational workflow layer:
Fieldwork and draft report, then independent audit review, optionally escalating to executive or CAE sign-off, then signed off or rejected.
| Sign-off status | Meaning |
|---|---|
draft | Not yet submitted |
in_review | Under independent quality review |
approved | Signed off |
rejected | Returned with comments |
Segregation of duties: the preparer or lead auditor cannot approve their own sign-off. Intermediate stages cannot finalise the audit.
Requires audit.engagement_signoff.
Finalisation and the report freeze
Once sign-off is approved, a person issues the formal opinion and finalises the engagement.
Finalisation writes an immutable report snapshot capturing:
- The engagement scope, including every linked object
- Every procedure, its test result and conclusion
- Every workpaper and its review record
- Every finding raised
- The opinion and its rationale
- The sign-off record
Why the freeze matters
The live control environment changes continuously. Controls are retired, mappings are adjusted, evidence goes stale, scope membership moves.
Without a freeze, opening a completed audit report a year later would show today's control environment against last year's conclusions — and the report would appear to say something its authors never said.
After finalisation the engagement is a historical record. Later changes to controls, mappings or evidence never rewrite it.
What finalisation does not do
Finalisation closes the engagement. It does not close the findings the engagement raised.
Those follow their own governed lifecycle, and closure requires auditor retest validation. A finalised engagement with eleven open findings is a normal and correct state.
Permissions
| Action | Permission |
|---|---|
| View engagements and reports | audit.engagement_read |
| Review workpapers and procedures | audit.engagement_review |
| Sign off reports and issue opinions | audit.engagement_signoff |
| Validate finding closure by retest | audit.finding_validate |
All require the audit_management entitlement.
Example
Engagement AUD-2026-0003 — Privileged Access Management Review.
| Element | Value |
|---|---|
| Procedures | 11 |
| Results | 7 satisfactory, 3 exceptions_noted, 1 unsatisfactory |
| Findings raised | 4 — one High, two Medium, one Low |
| Opinion | needs_improvement |
Opinion rationale: "Privileged access controls are appropriately designed and operate effectively for the majority of in-scope systems. Recertification was performed for all systems, although one quarter was completed late. Two access exceptions were not removed, and the emergency access process lacks documented authorisation. Overall the control environment requires improvement in exception follow-through and emergency access governance, but does not exhibit pervasive weakness."
Sign-off: submitted by the Lead Auditor, reviewed and approved by the Chief Audit Executive.
Finalisation: the report snapshot freezes all 11 procedures, 14 workpapers, 4 findings and the opinion.
Six months later: the control environment has moved on. CTL-2026-0067 has been amended, two mappings retired, and a new indicator added. The finalised report is unchanged — it still shows the environment as it was at the time of the audit, which is what makes it readable.
Of the four findings, three are validated_closed and one is still pending_validation awaiting the next retest window.
Troubleshooting
"I cannot sign off an engagement I led." Segregation of duties. Independent sign-off is required.
"A finalized report shows outdated control names." That is the freeze working. The report shows the environment as it was.
"Finalisation did not close the findings." Correct. Findings have their own closure requiring auditor retest.
"I need to correct a finalized report." Finalised reports are immutable by design. A correction is issued as a new communication, referencing the original — the same discipline as reissuing any formal report.