Skip to content

Preparing your first audit cycle in Nextera Trace

Internal audit implementations succeed or fail on two things decided up front: whether the audit universe is granular enough to prioritise, and whether the rating scales are defined well enough to survive their first disagreement with management.

This page is written for a Head of Internal Audit or an audit methodology lead.

  1. Audit universe structure and granularity. What is an auditable unit — an entity, a process, a system, a location, or a risk theme? Pick a level and hold it. A universe mixing “the Surabaya branch” with “the entire finance function” cannot be prioritised, because the units are not comparable.
  2. Risk-scoring criteria. The factors that drive prioritisation — materiality, complexity, change, regulatory exposure, fraud susceptibility, control maturity, time since last audit — and how they combine. Write it down; an unwritten model becomes a negotiation.
  3. Finding rating scale, defined. Not the labels — the definitions, calibrated against impact and likelihood, published in your methodology.
  4. Engagement opinion scale, which is a separate scale. Several low findings can still support an adverse overall opinion, and conflating the two produces conclusions nobody trusts.
  5. Working paper standard. What must be recorded, and the review requirement. The professional test is that a competent reviewer with no prior connection to the engagement can read the papers and understand what was tested, what was found and why the conclusion follows.
  6. Independence boundaries in the system. What can an auditee see, and what can they change? Management may respond to a finding; management may not amend a finding, its rating or its evidence. Decide this before configuration, because it is a charter question, not a permissions question.
  7. Follow-up policy. Verification standard, how overdue actions escalate, and — explicitly — how risk acceptance is recorded and at what level of authority. Without that, accepted risks become permanently overdue actions and the overdue report loses meaning.
Input Typical owner Why it is needed
Existing audit universe, however informal Internal audit Starting population
Entity, process and system inventories Finance, IT, operations Building a complete universe
Enterprise risk register Risk management Risk-scoring input and assurance mapping
Prior audit history — what was audited when, and found what Internal audit Coverage and planning
Open findings and agreed actions with owners and dates Internal audit Migrating follow-up without losing anything
Audit charter and methodology Internal audit Configuration derives from it
Auditor resource and skills Internal audit The plan is constrained by auditor days
Other assurance providers and their coverage Risk / compliance Assurance mapping, so audit does not duplicate

The open-findings row is the one to be strict about. Migrating engagements without their open actions is the fastest way to lose the credibility the follow-up module exists to protect.

  • The Head of Internal Audit, who owns methodology, scales and independence positions.
  • An audit methodology or quality lead if the function has one.
  • Audit managers who will validate that the universe and the working paper structure match how the team actually works.
  • A risk management contact for the risk register and assurance mapping.
  • The audit committee chair, at least for the reporting format. The committee pack is a deliverable, and finding out in month six that it is the wrong shape is avoidable.

Your first cycle is complete when:

  1. The audit universe is loaded at a consistent granularity, with risk attributes and last- audited history.
  2. An annual plan has been built from it, prioritised by risk, constrained by available auditor days, and approved.
  3. Coverage can be answered from the system: what proportion of the universe, weighted by risk, has been audited within the cycle.
  4. An engagement has been run end to end — terms of reference, programme, fieldwork, working papers, review sign-off — inside the product.
  5. Findings carry all five elements, with cause genuinely completed rather than restated condition.
  6. Management responses are recorded with an agreed action, a named owner and a due date, and risk acceptances are recorded as such.
  7. Follow-up can be reported across all engagements at once — overdue actions by rating, owner and age — which is the question the committee actually asks.
  8. A committee pack is generated from the same data as the engagement records.

Point 7 is the real test, and it is the one a spreadsheet-based function cannot pass.

See Getting access to Nextera products. Nextera Trace normally runs at trace.nextera.id.