Appearance
Audit & Oversight
This domain covers two distinct forms of independent scrutiny: internal audit, which you conduct on yourself, and regulatory inspection, which a supervisory authority conducts on you.
In the application it spans the Audit & Inspection navigation domain: Audit Management (/audit) and Regulatory Inspections (/inspections).
Why they are separate
A regulatory examination is not an internal audit engagement with a different label.
| Internal Audit | Regulatory Inspection | |
|---|---|---|
| Conducted by | Your third line | An external supervisory authority |
| Governed by | Your audit charter and plan | The authority's statutory powers |
| Working papers | Yours, internal | Not applicable — you do not paper their work |
| Output | An audit opinion you issue | Observations the authority issues to you |
| Response | Management response to your own auditors | A formal, approved regulatory response |
| Timing | Your annual plan | When the authority decides |
Modelling an inspection as an audit engagement would force you to invent an audit plan for something a regulator scheduled, and would put the authority's observations into a workpaper structure they never produced.
They do, however, share the same canonical downstream objects — findings, actions, controls, requirements, evidence — so remediation is tracked identically regardless of who raised the issue.
Internal Audit
| Article | What it covers |
|---|---|
| Audit Planning | Annual and periodic plans, the audit universe, plan approval |
| Audit Engagements | The engagement lifecycle, scope, team and status |
| Audit Fieldwork | Procedures, test results and workpapers |
| Audit Findings | Findings, management response, and governed retest validation |
| Audit Sign-off | Opinions, independent review, and the immutable report freeze |
Regulatory Inspections
| Article | What it covers |
|---|---|
| Regulatory Inspections | The inspection container, types, lifecycle and correspondence |
| Inspection Items | Candidate extraction, confirmation, and canonicalisation into GRC records |
| Inspection Responses | Response packages, governed sign-off and immutable submission snapshots |
Principles common to both
Conclusions stay human. Evidence, indicators, risk signals, control test results and AI assistance inform the auditor or the coordinator. None of them calculates an opinion, closes a finding, approves a plan or signs off a response.
Canonical reuse, zero duplication. Both domains consume the same requirements, controls, risks, findings, action plans, evidence, workflow, workbench, notifications and calendar as the rest of the platform. Neither builds a parallel register.
Immutable historical freeze. Finalising an engagement or submitting a regulatory response freezes a snapshot, so later changes to the live environment never rewrite a conclusion that was reached at the time.
Completion is not closure. Remediation action completion does not close an audit finding. Closure requires auditor retest validation.
Entitlements
| Capability | Entitlement |
|---|---|
| Audit management | audit_management |
| Regulatory inspections | regulatory_inspections |
| AI assistance in either | ai_risk_intelligence |
Who works in this domain
| Role | Typical work |
|---|---|
| Internal Auditor | Planning, fieldwork, workpapers, findings, retest |
| Chief Audit Executive | Plan approval, engagement sign-off, opinions |
| Compliance Manager | Auditee response, inspection coordination, response review |
| Business owner | Providing evidence, responding to observations, remediating |
| External Auditor or Regulator | Reading exported evidence packages and reconstructions |
Related domains
- Controls & Assurance — what audit tests
- Risk & Remediation — where findings and actions live
- Reporting — evidence packages and historical reconstruction