Lewati ke konten

Nextera Trace modules

Konten ini belum tersedia dalam bahasa Anda.

Nextera Trace has six modules, and they map cleanly onto the internal audit cycle. The audit universe is the foundation; everything else runs on an annual rhythm above it.

If any term here is unfamiliar, read Internal audit concepts first — this page assumes it.

Maintain the full universe of auditable entities and processes that planning draws from.

Purpose. The complete population of what could be audited — entities, processes, systems, geographies, third parties — each with risk attributes, an owner, and when it was last audited with what result.

Depends on. Nothing — it is the foundation.

Watch for. Two properties make it useful rather than decorative. It must be maintained rather than rebuilt each year, or the history the plan most needs is lost. And its granularity must be consistent: a universe mixing “the Surabaya branch” with “the entire finance function” cannot be prioritised, because the units are not comparable.

Build the annual audit plan from the audit universe, prioritised by risk.

Purpose. Turning the universe into an approved annual plan: which engagements, in what order, with what resource, justified by risk.

Depends on. Audit universe; Follow-up tracking, for what previous audits found.

Watch for. The plan is constrained by auditor days, and a plan that ignores that fails in Q3. Plans also change — what matters is that changes are visible and approved, not that January’s version was perfect. Coverage is the question this module exists to answer: what proportion of the universe, weighted by risk, has been audited within the cycle?

Run each engagement — scope, fieldwork and working papers — in one place.

Purpose. The engagement itself: terms of reference, the audit programme, fieldwork, and the working papers that record what was done.

Depends on. Audit planning for the mandate.

Watch for. Working papers carry a specific professional standard: a competent reviewer with no prior connection to the engagement should be able to read them and understand what was tested, what was found, and why the conclusion follows. Review — by someone more senior, evidenced — is the corresponding control, and it should be visible in the record.

Record findings, rate them and agree recommendations with management.

Purpose. Findings with all five elements — criteria, condition, cause, effect, recommendation — rated consistently and agreed with management, each with an action, an owner and a due date.

Depends on. Audit execution for the evidence.

Watch for. Cause is the element most often skipped and the one that determines whether remediation works. A finding without a cause produces a management action that fixes the symptom and recurs next year. Note also that finding rating and engagement opinion are two different scales: several low findings can still support an adverse overall opinion.

Track agreed actions to closure, with status visible in real time.

Purpose. Every agreed action across every engagement, with owner, due date, status and verification.

Depends on. Findings & recommendations.

Watch for. This is where most audit functions lose value, for a structural reason: findings are raised in engagement-shaped batches but come due continuously, long after the engagement closed. If actions live in the engagement file, nobody can answer the committee’s actual question — how many high-rated actions are overdue across everything. Also, where management accepts a risk rather than acting, record it explicitly as risk acceptance at an appropriate level of authority; do not let it become a permanently overdue action.

Produce engagement and committee reporting from the same underlying data.

Purpose. Engagement reports for management, and committee reporting: plan progress, universe coverage, findings by rating and theme, overdue actions with ageing.

Depends on. Everything above.

Watch for. The value of generating this from the same records is that the numbers cannot drift between the engagement file and the committee pack — which is precisely the failure mode of a spreadsheet-based audit function.