Administration & governance

Audit that reads the records, not a reconstruction of them

Internal control framework, audit missions and findings, legal opinions, risk register and the follow-up that closes them.

Request a demo See how it works

Change log on a configuration record showing who changed what, when and why
Every change leaves a lineWho changed what, when, and against which finding.Configuration and case history, both auditable

Why it matters

Evidence that is already the record

Internal audit spends most of its effort collecting evidence that already exists somewhere in the administration. When control activities and audit missions run on the same platform as the operations, the evidence is the record — and a finding can be tracked until it is actually implemented.

Controls where the work happens

Control activities run on the operational platform, not beside it.

Missions on the same base

Audit works from the records rather than requesting them.

Findings tracked to implementation

A recommendation is followed until it is actually applied.

What it covers

Control, assurance and what follows a finding

The framework and the missions kept where the operations they examine already run.

Internal control

Control objectives, the activities that meet them and who performs each one.

Audit missions

Plan, scope, working papers, findings and the report, in one file.

Findings and actions

Each recommendation with an owner, a deadline and a verified implementation.

Risk register

Risks, their owners, their controls and their movement over time.

Legal opinions

Requested, given and recorded against the decisions that relied on them.

Compliance obligations

Data protection, transparency and reporting duties tracked to a date.

How it works

Planned, tested, raised, verified

A mission that starts from the records ends with findings someone has to close.

01

Plan on risk

The audit plan is built from the risk register and from what the operational records show, rather than from a fixed rotation.

02

Test against live records

Sampling and testing draw on the actual cases, contracts and payments, with the evidence linked rather than copied.

03

Raise findings with owners

A recommendation without an owner and a date is not a recommendation; the system will not accept one.

04

Verify implementation

Follow-up is scheduled from the deadline, and open findings stay visible to management until they close.

Outcomes

What changes

Assurance that costs less to produce and means more when it arrives.

Evidence already assembled

The mission draws on records rather than on requests to departments.

Findings that get implemented

Owners, deadlines and verification instead of an annual list.

Control that is demonstrable

Who performed which control activity, and when.

Configured per administration

What is configured

  • the internal control framework and its objectives
  • control activities, owners and frequency
  • the audit plan and mission methodology
  • working paper and report templates
  • finding severities and escalation
  • the risk register structure and review cycle
  • compliance obligations and their deadlines
  • what is reported to management and to oversight

Connected to

The rest of the platform

  • Every operational solution, as the source of evidence
  • The document registry and the audit trail
  • HR, for declarations, delegation and segregation of duties
  • Budget and procurement, the most audited processes

On your own control framework

See audit working on live records.

We take one control objective and one mission scope, draw the evidence from the operational records, and follow a finding to verified implementation.

Request a demo All administration & governance