Skip to content

Journey: Audit

An internal audit engagement, from the annual plan to a validated finding closure eleven months later.

Fictional example.


The plan

The Chief Audit Executive prepares the FY2026 audit plan: 14 engagements.

The advisory audit universe surfaces attention signals:

SignalEffect on the plan
Payments platform: critical tier, last audited three years agoEngagement added, Q2
RSK-2026-0014 Critical inherent, degrading control assurancePrivileged access engagement added, Q1
Material outsourcing engagement, reassessment overdueFolded into the outsourcing engagement scope
Two business services with no BIAReferred to the resilience engagement rather than a separate audit

The universe is advisory

It surfaces where attention may be warranted, with reasoning visible. It does not generate the plan.

The last row is the CAE exercising judgement: two missing BIAs did not warrant a dedicated engagement. Audit independence means the plan is the auditor's to set.

Approval: submitted by the CAE, approved by the Audit Committee Chair. The preparer could not approve their own plan.


Q1 — Engagement setup

Engagement AUD-2026-0003 — Privileged Access Management Review.

FieldValue
Typeinternal
Lead auditorSenior IT Auditor
TeamTwo auditors
AuditeeHead of IT Security
DurationSix weeks

Scope, linked to canonical objects rather than described in prose:

ObjectRecords
Business serviceCore Banking
Assets38 systems in SCP-2026-0004
ControlsCTL-2026-0041, CTL-2026-0044, CTL-2026-0067
RequirementsThree obligations
RiskRSK-2026-0014

Linked scope is queryable scope

Because scope is linked rather than described, "which engagements have covered this business service?" is answerable — including when next year's plan is being set.

Status moves draftplanningscheduledfieldwork.


Fieldwork — 11 procedures

Procedure 4 is representative:

FieldValue
ObjectiveDetermine whether privileged access is recertified quarterly across in-scope systems
Linked controlCTL-2026-0067
SamplingJudgemental, all 38 systems
AssignedIT Auditor

Test steps: obtain recertification records for four quarters; confirm each system has a record per quarter; for a sample of 10, confirm reviewer independence; for any exception identified, confirm the access was removed.

Result: exceptions_noted.

Conclusion: "Recertification performed for 38 of 38 systems in Q1 and Q2. In Q3, 5 systems were not recertified within the quarter; completion was 22 days late. Reviewer independence confirmed in all 10 sampled. Of 14 exceptions identified across the year, 12 were removed within 5 working days; 2 remained active at the time of testing."

exceptions_noted is not a soft unsatisfactory

The control operated. It operated imperfectly. Keeping the two results distinct is what lets a reader tell a control with a tolerable error rate from a control that failed.

Workpapers link to the same canonical evidence and assertions that continuous assurance evaluates — not a separate copy uploaded into an audit silo.

Maker-checker: each procedure and workpaper is prepared by one auditor and reviewed by another. Preparers cannot review their own work.

Overall results across 11 procedures: 7 satisfactory, 3 exceptions_noted, 1 unsatisfactory.


Findings

Four findings are raised as canonical findings in the shared register:

FindingSeveritySubject
FND-2026-0119HighTwo privileged access exceptions not removed
FND-2026-0120MediumQ3 recertification completed 22 days late
FND-2026-0121MediumEmergency access process lacks documented authorisation
FND-2026-0122LowAccess review evidence not consistently dated

Canonical, not audit-only

These sit alongside compliance, RCSA and third-party findings. The Head of IT Security sees one list of what they owe, not four.

Management response to FND-2026-0119: accepted, with a commitment and an owner. It becomes action plan ACT-2026-0211.


Opinion and sign-off

Opinion: needs_improvement.

"Privileged access controls are appropriately designed and operate effectively for the majority of in-scope systems. Recertification was performed for all systems, although one quarter was completed late. Two access exceptions were not removed, and the emergency access process lacks documented authorisation. Overall the control environment requires improvement in exception follow-through and emergency access governance, but does not exhibit pervasive weakness."

The opinion is issued by a person, never calculated

Evidence, indicators, test results and AI assistance inform it. Nothing computes it.

An opinion carries the auditor's name. A platform that generated it would be issuing an opinion nobody signed.

Sign-off: submitted by the Lead Auditor, reviewed and approved by the CAE. The lead auditor could not sign off their own engagement.

Finalisation freezes an immutable report snapshot: scope, all 11 procedures, 14 workpapers, 4 findings, the opinion and the sign-off record.


Month 4 — Remediation and the first retest

ACT-2026-0211 completes on day 9 and is verified on day 12 by its verifier — the two accounts are confirmed removed.

Day 21 — auditor retest. The auditor confirms the accounts are removed. Reviewing the amended decommissioning procedure, they find it addresses application decommissioning but not infrastructure decommissioning — which was the origin of one of the two accounts.

Result: reopened_failed_retest.

"Account removal confirmed. However the procedural remediation does not address infrastructure decommissioning, which was the origin of one of the two exceptions. The recurrence risk is not addressed."

Why retest is separate from action plan verification

The action plan verifier correctly confirmed the two accounts were removed. That was the plan, and it was done.

The auditor asked a different question: will this happen again? Only the second question closes an audit finding.

A second action plan is raised. The finding closes at retest three weeks later as validated_closed.


Month 11 — The position

FindingState
FND-2026-0119validated_closed
FND-2026-0120validated_closed
FND-2026-0121validated_closed
FND-2026-0122pending_validation — awaiting the next retest window

The engagement has been finalized since Q1 and is unchanged.

Meanwhile the live control environment has moved: CTL-2026-0067 has been amended, two mappings retired, and a new indicator added.

The finalised report still shows the environment as it was at the time of the audit.

Without the freeze, the report would appear to say something its authors never said

Opening a completed audit report a year later against today's control environment would misrepresent the auditors' conclusions. The snapshot is what makes a historical report readable.


What the journey demonstrates

PrincipleWhere
The audit universe is advisoryPlanning — the CAE folded two items into an existing scope
Scope is linked, not describedSetup — queryable coverage
Preparers cannot review their own workFieldwork
exceptions_noted is distinct from unsatisfactoryProcedure 4
Findings are canonical, not audit-onlyFour findings in the shared register
Opinions are issued, never calculatedSign-off
Preparers cannot sign off their own engagementSign-off
Finalisation freezes an immutable snapshotMonth 11
Action completion is not finding closureMonth 4 — the retest reopened it
Finalisation does not close findingsMonth 11 — one still pending

OrviQ Enterprise Governance, Risk & Compliance Platform