Preparing your first audit cycle in Nextera Trace
Internal audit implementations succeed or fail on two things decided up front: whether the audit universe is granular enough to prioritise, and whether the rating scales are defined well enough to survive their first disagreement with management.
This page is written for a Head of Internal Audit or an audit methodology lead.
Before you start
Section titled “Before you start”Decisions your organisation must make
Section titled “Decisions your organisation must make”- Audit universe structure and granularity. What is an auditable unit — an entity, a process, a system, a location, or a risk theme? Pick a level and hold it. A universe mixing “the Surabaya branch” with “the entire finance function” cannot be prioritised, because the units are not comparable.
- Risk-scoring criteria. The factors that drive prioritisation — materiality, complexity, change, regulatory exposure, fraud susceptibility, control maturity, time since last audit — and how they combine. Write it down; an unwritten model becomes a negotiation.
- Finding rating scale, defined. Not the labels — the definitions, calibrated against impact and likelihood, published in your methodology.
- Engagement opinion scale, which is a separate scale. Several low findings can still support an adverse overall opinion, and conflating the two produces conclusions nobody trusts.
- Working paper standard. What must be recorded, and the review requirement. The professional test is that a competent reviewer with no prior connection to the engagement can read the papers and understand what was tested, what was found and why the conclusion follows.
- Independence boundaries in the system. What can an auditee see, and what can they change? Management may respond to a finding; management may not amend a finding, its rating or its evidence. Decide this before configuration, because it is a charter question, not a permissions question.
- Follow-up policy. Verification standard, how overdue actions escalate, and — explicitly — how risk acceptance is recorded and at what level of authority. Without that, accepted risks become permanently overdue actions and the overdue report loses meaning.
Data you must gather
Section titled “Data you must gather”| Input | Typical owner | Why it is needed |
|---|---|---|
| Existing audit universe, however informal | Internal audit | Starting population |
| Entity, process and system inventories | Finance, IT, operations | Building a complete universe |
| Enterprise risk register | Risk management | Risk-scoring input and assurance mapping |
| Prior audit history — what was audited when, and found what | Internal audit | Coverage and planning |
| Open findings and agreed actions with owners and dates | Internal audit | Migrating follow-up without losing anything |
| Audit charter and methodology | Internal audit | Configuration derives from it |
| Auditor resource and skills | Internal audit | The plan is constrained by auditor days |
| Other assurance providers and their coverage | Risk / compliance | Assurance mapping, so audit does not duplicate |
The open-findings row is the one to be strict about. Migrating engagements without their open actions is the fastest way to lose the credibility the follow-up module exists to protect.
People you need available
Section titled “People you need available”- The Head of Internal Audit, who owns methodology, scales and independence positions.
- An audit methodology or quality lead if the function has one.
- Audit managers who will validate that the universe and the working paper structure match how the team actually works.
- A risk management contact for the risk register and assurance mapping.
- The audit committee chair, at least for the reporting format. The committee pack is a deliverable, and finding out in month six that it is the wrong shape is avoidable.
What “done” looks like
Section titled “What “done” looks like”Your first cycle is complete when:
- The audit universe is loaded at a consistent granularity, with risk attributes and last- audited history.
- An annual plan has been built from it, prioritised by risk, constrained by available auditor days, and approved.
- Coverage can be answered from the system: what proportion of the universe, weighted by risk, has been audited within the cycle.
- An engagement has been run end to end — terms of reference, programme, fieldwork, working papers, review sign-off — inside the product.
- Findings carry all five elements, with cause genuinely completed rather than restated condition.
- Management responses are recorded with an agreed action, a named owner and a due date, and risk acceptances are recorded as such.
- Follow-up can be reported across all engagements at once — overdue actions by rating, owner and age — which is the question the committee actually asks.
- A committee pack is generated from the same data as the engagement records.
Point 7 is the real test, and it is the one a spreadsheet-based function cannot pass.
Working through it in the product
Section titled “Working through it in the product”Getting access
Section titled “Getting access”See Getting access to Nextera products. Nextera Trace normally runs
at trace.nextera.id.