Preparing your first audit cycle in Nextera Trace
Internal audit implementations succeed or fail on two things decided up front: whether the audit universe is granular enough to prioritise, and whether the rating scales are defined well enough to survive their first disagreement with management.
This page is written for a Head of Internal Audit or an audit methodology lead.
Before you start
Section titled “Before you start”Decisions your organisation must make
Section titled “Decisions your organisation must make”- Audit universe structure and granularity. What is an auditable unit — an entity, a process, a system, a location, or a risk theme? Pick a level and hold it. A universe mixing “the Surabaya branch” with “the entire finance function” cannot be prioritised, because the units are not comparable.
- Risk-scoring criteria. The factors that drive prioritisation — materiality, complexity, change, regulatory exposure, fraud susceptibility, control maturity, time since last audit — and how they combine. Write it down; an unwritten model becomes a negotiation.
- Finding rating scale, defined. Not the labels — the definitions, calibrated against impact and likelihood, published in your methodology.
- Engagement opinion scale, which is a separate scale. Several low findings can still support an adverse overall opinion, and conflating the two produces conclusions nobody trusts.
- Working paper standard. What must be recorded, and the review requirement. The professional test is that a competent reviewer with no prior connection to the engagement can read the papers and understand what was tested, what was found and why the conclusion follows.
- Independence boundaries in the system. Management may respond to a finding; management may not amend a finding, its rating or its evidence. In Trace the product has already drawn that boundary bluntly — there is no auditee login, and every account belongs to the audit function. What is left for you to decide is what leaves the system: who receives an export, in what form, and at what stage.
- Follow-up policy. Verification standard, how overdue actions escalate, and — explicitly — how risk acceptance is recorded and at what level of authority. This remains your own function’s process: Trace has no action register spanning engagements. Without that policy, accepted risks turn into permanently overdue actions.
Decisions 3, 4 and 5 have one concrete landing place inside the product: Templates. Your scales and mandatory entries are expressed as sections and fields on a working paper template, not as settings of their own. See step 3 below.
Data you must gather
Section titled “Data you must gather”| Input | Typical owner | Why it is needed |
|---|---|---|
| Existing audit universe, however informal | Internal audit | Starting population |
| Entity, process and system inventories | Finance, IT, operations | Building a complete universe |
| Enterprise risk register | Risk management | Risk-scoring input and assurance mapping |
| Prior audit history — what was audited when, and found what | Internal audit | Coverage and planning |
| Open findings and agreed actions with owners and dates | Internal audit | Migrating follow-up without losing anything |
| Audit charter and methodology | Internal audit | Configuration derives from it |
| Auditor resource and skills | Internal audit | The plan is constrained by auditor days |
| Other assurance providers and their coverage | Risk / compliance | Assurance mapping, so audit does not duplicate |
The open-findings row is the one to be strict about. Migrating engagements without their open actions is the fastest way to lose the credibility your follow-up process exists to protect.
People you need available
Section titled “People you need available”- The Head of Internal Audit, who owns methodology, rating scales and independence positions.
- An audit methodology or quality lead if the function has one.
- Audit managers who will validate that the working paper structure matches how the team actually works day to day.
- A risk management contact for the risk register and assurance mapping.
- The audit committee chair, at least to agree the reporting format. What comes out of Trace is an export, and finding out in month six that it is the wrong shape is avoidable.
Technical requirements
Section titled “Technical requirements”Nextera Trace is a web application. Each user needs only a modern browser — a current version of Google Chrome, Microsoft Edge or Mozilla Firefox — an internet connection, and an account created by your organisation’s administrator. The recommended minimum screen resolution is 1366×768.
Working through it in the product
Section titled “Working through it in the product”The sequence below follows Trace’s real flow. Work through it in order; each step rests on the one before.
1. Sign in and find your way around
Section titled “1. Sign in and find your way around”Open your application address and fill in Email Address and Password on the Sign In page. Once you are through, you land on the Dashboard. There is no onboarding wizard — the Dashboard shows Active Engagements, Papers Assigned, Pending Reviews, Completion Rate and Recent Activity straight away.
The sidebar on the left carries Dashboard, Engagements, My Tasks, Templates, Analytics, Reports, Team, Activity, with Integrations, Settings and Help at the bottom. The header above holds a Search box, the notification bell and the profile menu.
2. Build the team
Section titled “2. Build the team”Go to Team → Invite member and fill in Email, Full name, Initials, Role, and Phone where you need it. The organisation roles available are Partner, Manager, Supervisor, Senior, Junior.
Do this before creating an engagement, because an engagement needs preparers and reviewers who already exist in the system. Remember too that only Partner, Manager and Senior can pick up a submitted working paper for review — make sure your team composition includes them.
3. Settle the templates first
Section titled “3. Settle the templates first”Open Templates. You will see the built-in working paper library, grouped by category and searchable by name or code: the A110–A170 series for engagement acceptance and set-up, B100–B280 for procedures and testing, C100–C400 for completion and reporting. Each template shows a Form preview and its Standard references to Standar Audit (SA).
Click a template, then Edit template to add or adjust sections and fields to suit your methodology — including the scales and wording you settled in the previous section. The result is saved as your organisation’s own version, with a version history you can roll back to; the built-in template is left unchanged.
Do this before the first engagement runs. Changing the shape of a working paper in the middle of fieldwork is the most expensive way to discover that your methodology was not finished.
4. Create the first engagement
Section titled “4. Create the first engagement”Engagements → New Engagement. Fill in Client Name (the entity or area being audited), Industry, Client Address, then Engagement Type, Accounting Standard, Fiscal Year Start and End, Deadline, and Additional Notes. An engagement is born in Draft; the other statuses available are Active, Review, Completed and Archived.
Open that engagement’s Details page, go to the Team tab, then Add Member: search for a name, choose an Engagement role — Engagement Partner, Engagement Manager, Supervisor, Senior Auditor or Junior Auditor — and save. An engagement role is not an organisation role: one sets the part somebody plays on this engagement, the other their standing in the audit function.
The Working Papers tab shows the engagement’s papers, grouped into the A1 Pre-Engagement, A2 Planning, B Execution and C Completion categories, each with its own completion count.
5. Work the papers
Section titled “5. Work the papers”Click a working paper to open its editor. The title is the template’s code and name, for example A150 Pernyataan Independensi or B210 Pengujian Pengendalian.
- Entries save themselves as you type — watch for the Saving… then Saved indicator; a Save now button is there if you want to force it.
- The Completion bar shows what percentage of the required fields is filled in.
- The Comments panel holds review questions and can be attached to a particular field; the History panel records what happened to this paper, and who did it.
- When several people open the same paper, their presence shows live as avatars and cursors.
For engagements that lean on accounting data, Integrations connects Trace to Accurate Online, Jurnal.id, Zahir or QuickBooks through OAuth authorisation and data mapping; an Import from Excel path is available for loading working paper, engagement or user data by mapping the columns and reviewing the validation results before it runs.
6. Run the review
Section titled “6. Run the review”The transition button sits at the top right of the editor, and offers only the step you are allowed to take.
- The preparer submits the paper: In Progress → Submitted. The form locks read-only immediately.
- A reviewer holding the Partner, Manager or Senior role picks it up: Submitted → In Review.
- The assigned reviewer approves it to Completed, or returns it to Rework — and a return must carry a reason.
- From Rework, the preparer fixes it and submits again.
Completed is a final status. Every transition is recorded in that paper’s History, and appears in the organisation-level Activity as well.
Throughout all of this, My Tasks is each auditor’s daily view: every paper assigned to them across engagements, with counts for Total Tasks, In Progress, In Review and Needs Rework.
7. Issue and monitor
Section titled “7. Issue and monitor”Reports opens the Reports & Exports page. Exports come as PDF, Word or Excel, for a single working paper or as a bundle for one engagement — with options for a cover page, table of contents, signatures, history and comments. An export runs as a background job; the Download button appears as soon as its status is Completed.
Analytics watches delivery: KPI cards, Working Paper Status, Completion Trend, Engagement Progress and Team Workload, over the From–To range you choose. Activity provides the organisation-wide trail, filtered by Action, User, From and To.
What “done” looks like
Section titled “What “done” looks like”Your first cycle is complete when:
- The templates have been adjusted to your methodology and agreed, rather than taken as they come and patched halfway through.
- The team exists in Team with the right roles, including enough people at Partner, Manager or Senior to carry the review.
- One engagement has been run end to end inside the product — Engagement created, engagement team set, papers filled in, submitted, reviewed.
- At least one working paper has been through Rework, and the reason for the return is readable in History. An audit function that has never sent work back has not really tested its review control.
- The engagement conclusion is recorded — including C300 Ringkasan Audit with its main findings and its Jenis Opini — and does not live only in the engagement manager’s head.
- One export bundle has been produced and read by the people who will receive it, so the shape of the reporting is known early rather than in month six.
- Analytics shows numbers the team recognises as correct. Where it does not, it is rarely Analytics that is wrong — it is paper statuses that have not been kept up to date.
Outside the product it must still be clear who maintains the audit universe, how the annual plan is built, and where agreed actions are tracked to closure. Trace makes engagement execution and its evidence of review tidy; it does not replace those three — see Internal audit concepts.
Getting access
Section titled “Getting access”Nextera Trace normally runs at trace.nextera.id. Accounts are provided by the product
administrator in your organisation. The address above is the production address; if your
organisation uses a dedicated environment, use the address in your onboarding pack.