Skip to content

Audit & Oversight

This domain covers two distinct forms of independent scrutiny: internal audit, which you conduct on yourself, and regulatory inspection, which a supervisory authority conducts on you.

In the application it spans the Audit & Inspection navigation domain: Audit Management (/audit) and Regulatory Inspections (/inspections).


Why they are separate

A regulatory examination is not an internal audit engagement with a different label.

Internal AuditRegulatory Inspection
Conducted byYour third lineAn external supervisory authority
Governed byYour audit charter and planThe authority's statutory powers
Working papersYours, internalNot applicable — you do not paper their work
OutputAn audit opinion you issueObservations the authority issues to you
ResponseManagement response to your own auditorsA formal, approved regulatory response
TimingYour annual planWhen the authority decides

Modelling an inspection as an audit engagement would force you to invent an audit plan for something a regulator scheduled, and would put the authority's observations into a workpaper structure they never produced.

They do, however, share the same canonical downstream objects — findings, actions, controls, requirements, evidence — so remediation is tracked identically regardless of who raised the issue.


Internal Audit

ArticleWhat it covers
Audit PlanningAnnual and periodic plans, the audit universe, plan approval
Audit EngagementsThe engagement lifecycle, scope, team and status
Audit FieldworkProcedures, test results and workpapers
Audit FindingsFindings, management response, and governed retest validation
Audit Sign-offOpinions, independent review, and the immutable report freeze

Regulatory Inspections

ArticleWhat it covers
Regulatory InspectionsThe inspection container, types, lifecycle and correspondence
Inspection ItemsCandidate extraction, confirmation, and canonicalisation into GRC records
Inspection ResponsesResponse packages, governed sign-off and immutable submission snapshots

Principles common to both

Conclusions stay human. Evidence, indicators, risk signals, control test results and AI assistance inform the auditor or the coordinator. None of them calculates an opinion, closes a finding, approves a plan or signs off a response.

Canonical reuse, zero duplication. Both domains consume the same requirements, controls, risks, findings, action plans, evidence, workflow, workbench, notifications and calendar as the rest of the platform. Neither builds a parallel register.

Immutable historical freeze. Finalising an engagement or submitting a regulatory response freezes a snapshot, so later changes to the live environment never rewrite a conclusion that was reached at the time.

Completion is not closure. Remediation action completion does not close an audit finding. Closure requires auditor retest validation.


Entitlements

CapabilityEntitlement
Audit managementaudit_management
Regulatory inspectionsregulatory_inspections
AI assistance in eitherai_risk_intelligence

Who works in this domain

RoleTypical work
Internal AuditorPlanning, fieldwork, workpapers, findings, retest
Chief Audit ExecutivePlan approval, engagement sign-off, opinions
Compliance ManagerAuditee response, inspection coordination, response review
Business ownerProviding evidence, responding to observations, remediating
External Auditor or RegulatorReading exported evidence packages and reconstructions

OrviQ Enterprise Governance, Risk & Compliance Platform