Products / Internal Audit Management
Available

Internal Audit Management

The full engagement lifecycle, from plan to closure.

An internal-audit engagement register covering Draft → Planning → Fieldwork → Review → Report Issued → Follow-Up → Closed, each engagement carrying a risk rating, scope memo and team assignment.

What you get

  • Engagement register
  • Linked evidence
  • AC reporting

Why it matters

Independent assurance, only if the engagement lifecycle holds.

Internal audit is the public sector's third line of defence — the independent function that gives the Accounting Officer and Audit Committee assurance that controls actually work, that public money is spent as appropriated, and that risk is being managed before it crystallises into loss. Under the PFMA and MFMA it is not optional: every department, municipality and public entity must operate an internal-audit unit reporting functionally to the Audit Committee, working to a plan the committee approves.

The discipline lives or dies on the engagement lifecycle. An audit that drifts from Planning to Fieldwork to Report without a controlled scope, dated working papers and a clear team mandate cannot withstand AGSA reliance testing or an IIA external quality assessment. When that lifecycle is managed on spreadsheets and email, scope creeps, evidence goes missing, reports issue late, and the committee loses the line of sight it is legally accountable for — the precise conditions that produce repeat findings year after year.

Done well, internal audit is the early-warning system that keeps an entity out of qualification. Each engagement carries its risk rating, its scope memo and its team, and its findings flow straight into remediation and follow-up. The result is a defensible, tamper-evident record that the function did its job — and the assurance leadership needs to sign the annual report with confidence.

Capabilities

What Internal Audit Management does.

Engagement register

Every engagement tracked across its lifecycle with risk rating, scope and team.

Linked evidence

Working papers, findings and follow-ups linked to each engagement.

AC reporting

Engagement status rolls straight into Audit Committee reporting.

Outcomes

What changes for your team.

Tangible improvements an entity sees once Internal Audit Management replaces the spreadsheet.

Run every engagement through a controlled Draft-to-Closed lifecycle with no off-system gaps
Tie working papers, findings and follow-ups to each engagement for instant AGSA reliance evidence
Roll live engagement status straight into Audit Committee reporting, no manual collation
Cut report turnaround by initiating directly from the approved annual plan
Demonstrate IIA-conformant practice for the mandatory external quality assessment
Keep a tamper-evident audit trail of scope, team and risk rating on every engagement

How it works

From data to defensible signal.

01
Plan
Initiate from the approved annual audit plan with scope and timeline.
02
Execute
Capture fieldwork, working papers and findings against the engagement.
03
Close
Issue the report, track follow-ups and close with full audit trail.

Want to see Internal Audit Managementrunning on your entity's own data?

Enquire now

Who it's for

  • Chief Audit Executive
  • Lead Auditors and Audit Seniors
  • Audit Committee
  • Auditees and process owners
  • Accounting Officer relying on internal assurance

Legislative basis

  • PFMA s.38(1)(a)(ii) & Treasury Regulation 3.2 — internal-audit function and work programme
  • MFMA s.165 — municipal internal-audit unit reporting to the Audit Committee
  • IIA International Professional Practices Framework (Standards 1000–2600) — conformant practice
  • Public Sector Internal Audit Standard — public-sector audit conduct

FAQ

Questions teams ask before they sign up.

How does this help with our AGSA audit?

AGSA tests whether they can rely on internal audit's work. Because every engagement carries dated working papers, a controlled scope and linked findings, you hand the engagement team a complete, traceable evidence file rather than reconstructing it under pressure.

Does our data leave our environment?

No. Every engagement, working paper and finding stays inside your tenant boundary. Nothing is sent to a third party or used to train any external model.

Is it conformant with IIA Standards for our external quality assessment?

Yes. The lifecycle, supervisory review and linked evidence are built around the IIA Standards (1000–2600) and the Public Sector Internal Audit Standard, so the EQA reviewer finds the conformance evidence already structured.

Want to know more about Internal Audit Management?

Tell us about your entity and we'll be in touch with a walkthrough, pricing and next steps — everything you see is traceable to source.