Appearance
Journey: Audit
An internal audit engagement, from the annual plan to a validated finding closure eleven months later.
Fictional example.
The plan
The Chief Audit Executive prepares the FY2026 audit plan: 14 engagements.
The advisory audit universe surfaces attention signals:
| Signal | Effect on the plan |
|---|---|
| Payments platform: critical tier, last audited three years ago | Engagement added, Q2 |
RSK-2026-0014 Critical inherent, degrading control assurance | Privileged access engagement added, Q1 |
| Material outsourcing engagement, reassessment overdue | Folded into the outsourcing engagement scope |
| Two business services with no BIA | Referred to the resilience engagement rather than a separate audit |
The universe is advisory
It surfaces where attention may be warranted, with reasoning visible. It does not generate the plan.
The last row is the CAE exercising judgement: two missing BIAs did not warrant a dedicated engagement. Audit independence means the plan is the auditor's to set.
Approval: submitted by the CAE, approved by the Audit Committee Chair. The preparer could not approve their own plan.
Q1 — Engagement setup
Engagement AUD-2026-0003 — Privileged Access Management Review.
| Field | Value |
|---|---|
| Type | internal |
| Lead auditor | Senior IT Auditor |
| Team | Two auditors |
| Auditee | Head of IT Security |
| Duration | Six weeks |
Scope, linked to canonical objects rather than described in prose:
| Object | Records |
|---|---|
| Business service | Core Banking |
| Assets | 38 systems in SCP-2026-0004 |
| Controls | CTL-2026-0041, CTL-2026-0044, CTL-2026-0067 |
| Requirements | Three obligations |
| Risk | RSK-2026-0014 |
Linked scope is queryable scope
Because scope is linked rather than described, "which engagements have covered this business service?" is answerable — including when next year's plan is being set.
Status moves draft → planning → scheduled → fieldwork.
Fieldwork — 11 procedures
Procedure 4 is representative:
| Field | Value |
|---|---|
| Objective | Determine whether privileged access is recertified quarterly across in-scope systems |
| Linked control | CTL-2026-0067 |
| Sampling | Judgemental, all 38 systems |
| Assigned | IT Auditor |
Test steps: obtain recertification records for four quarters; confirm each system has a record per quarter; for a sample of 10, confirm reviewer independence; for any exception identified, confirm the access was removed.
Result: exceptions_noted.
Conclusion: "Recertification performed for 38 of 38 systems in Q1 and Q2. In Q3, 5 systems were not recertified within the quarter; completion was 22 days late. Reviewer independence confirmed in all 10 sampled. Of 14 exceptions identified across the year, 12 were removed within 5 working days; 2 remained active at the time of testing."
exceptions_noted is not a soft unsatisfactory
The control operated. It operated imperfectly. Keeping the two results distinct is what lets a reader tell a control with a tolerable error rate from a control that failed.
Workpapers link to the same canonical evidence and assertions that continuous assurance evaluates — not a separate copy uploaded into an audit silo.
Maker-checker: each procedure and workpaper is prepared by one auditor and reviewed by another. Preparers cannot review their own work.
Overall results across 11 procedures: 7 satisfactory, 3 exceptions_noted, 1 unsatisfactory.
Findings
Four findings are raised as canonical findings in the shared register:
| Finding | Severity | Subject |
|---|---|---|
FND-2026-0119 | High | Two privileged access exceptions not removed |
FND-2026-0120 | Medium | Q3 recertification completed 22 days late |
FND-2026-0121 | Medium | Emergency access process lacks documented authorisation |
FND-2026-0122 | Low | Access review evidence not consistently dated |
Canonical, not audit-only
These sit alongside compliance, RCSA and third-party findings. The Head of IT Security sees one list of what they owe, not four.
Management response to FND-2026-0119: accepted, with a commitment and an owner. It becomes action plan ACT-2026-0211.
Opinion and sign-off
Opinion: needs_improvement.
"Privileged access controls are appropriately designed and operate effectively for the majority of in-scope systems. Recertification was performed for all systems, although one quarter was completed late. Two access exceptions were not removed, and the emergency access process lacks documented authorisation. Overall the control environment requires improvement in exception follow-through and emergency access governance, but does not exhibit pervasive weakness."
The opinion is issued by a person, never calculated
Evidence, indicators, test results and AI assistance inform it. Nothing computes it.
An opinion carries the auditor's name. A platform that generated it would be issuing an opinion nobody signed.
Sign-off: submitted by the Lead Auditor, reviewed and approved by the CAE. The lead auditor could not sign off their own engagement.
Finalisation freezes an immutable report snapshot: scope, all 11 procedures, 14 workpapers, 4 findings, the opinion and the sign-off record.
Month 4 — Remediation and the first retest
ACT-2026-0211 completes on day 9 and is verified on day 12 by its verifier — the two accounts are confirmed removed.
Day 21 — auditor retest. The auditor confirms the accounts are removed. Reviewing the amended decommissioning procedure, they find it addresses application decommissioning but not infrastructure decommissioning — which was the origin of one of the two accounts.
Result: reopened_failed_retest.
"Account removal confirmed. However the procedural remediation does not address infrastructure decommissioning, which was the origin of one of the two exceptions. The recurrence risk is not addressed."
Why retest is separate from action plan verification
The action plan verifier correctly confirmed the two accounts were removed. That was the plan, and it was done.
The auditor asked a different question: will this happen again? Only the second question closes an audit finding.
A second action plan is raised. The finding closes at retest three weeks later as validated_closed.
Month 11 — The position
| Finding | State |
|---|---|
FND-2026-0119 | validated_closed |
FND-2026-0120 | validated_closed |
FND-2026-0121 | validated_closed |
FND-2026-0122 | pending_validation — awaiting the next retest window |
The engagement has been finalized since Q1 and is unchanged.
Meanwhile the live control environment has moved: CTL-2026-0067 has been amended, two mappings retired, and a new indicator added.
The finalised report still shows the environment as it was at the time of the audit.
Without the freeze, the report would appear to say something its authors never said
Opening a completed audit report a year later against today's control environment would misrepresent the auditors' conclusions. The snapshot is what makes a historical report readable.
What the journey demonstrates
| Principle | Where |
|---|---|
| The audit universe is advisory | Planning — the CAE folded two items into an existing scope |
| Scope is linked, not described | Setup — queryable coverage |
| Preparers cannot review their own work | Fieldwork |
exceptions_noted is distinct from unsatisfactory | Procedure 4 |
| Findings are canonical, not audit-only | Four findings in the shared register |
| Opinions are issued, never calculated | Sign-off |
| Preparers cannot sign off their own engagement | Sign-off |
| Finalisation freezes an immutable snapshot | Month 11 |
| Action completion is not finding closure | Month 4 — the retest reopened it |
| Finalisation does not close findings | Month 11 — one still pending |