Skip to content

Preparing your first audit cycle in Nextera Trace

Internal audit implementations succeed or fail on two things decided up front: whether the audit universe is granular enough to prioritise, and whether the rating scales are defined well enough to survive their first disagreement with management.

This page is written for a Head of Internal Audit or an audit methodology lead.

  1. Audit universe structure and granularity. What is an auditable unit — an entity, a process, a system, a location, or a risk theme? Pick a level and hold it. A universe mixing “the Surabaya branch” with “the entire finance function” cannot be prioritised, because the units are not comparable.
  2. Risk-scoring criteria. The factors that drive prioritisation — materiality, complexity, change, regulatory exposure, fraud susceptibility, control maturity, time since last audit — and how they combine. Write it down; an unwritten model becomes a negotiation.
  3. Finding rating scale, defined. Not the labels — the definitions, calibrated against impact and likelihood, published in your methodology.
  4. Engagement opinion scale, which is a separate scale. Several low findings can still support an adverse overall opinion, and conflating the two produces conclusions nobody trusts.
  5. Working paper standard. What must be recorded, and the review requirement. The professional test is that a competent reviewer with no prior connection to the engagement can read the papers and understand what was tested, what was found and why the conclusion follows.
  6. Independence boundaries in the system. Management may respond to a finding; management may not amend a finding, its rating or its evidence. In Trace the product has already drawn that boundary bluntly — there is no auditee login, and every account belongs to the audit function. What is left for you to decide is what leaves the system: who receives an export, in what form, and at what stage.
  7. Follow-up policy. Verification standard, how overdue actions escalate, and — explicitly — how risk acceptance is recorded and at what level of authority. This remains your own function’s process: Trace has no action register spanning engagements. Without that policy, accepted risks turn into permanently overdue actions.

Decisions 3, 4 and 5 have one concrete landing place inside the product: Templates. Your scales and mandatory entries are expressed as sections and fields on a working paper template, not as settings of their own. See step 3 below.

Input Typical owner Why it is needed
Existing audit universe, however informal Internal audit Starting population
Entity, process and system inventories Finance, IT, operations Building a complete universe
Enterprise risk register Risk management Risk-scoring input and assurance mapping
Prior audit history — what was audited when, and found what Internal audit Coverage and planning
Open findings and agreed actions with owners and dates Internal audit Migrating follow-up without losing anything
Audit charter and methodology Internal audit Configuration derives from it
Auditor resource and skills Internal audit The plan is constrained by auditor days
Other assurance providers and their coverage Risk / compliance Assurance mapping, so audit does not duplicate

The open-findings row is the one to be strict about. Migrating engagements without their open actions is the fastest way to lose the credibility your follow-up process exists to protect.

  • The Head of Internal Audit, who owns methodology, rating scales and independence positions.
  • An audit methodology or quality lead if the function has one.
  • Audit managers who will validate that the working paper structure matches how the team actually works day to day.
  • A risk management contact for the risk register and assurance mapping.
  • The audit committee chair, at least to agree the reporting format. What comes out of Trace is an export, and finding out in month six that it is the wrong shape is avoidable.

Nextera Trace is a web application. Each user needs only a modern browser — a current version of Google Chrome, Microsoft Edge or Mozilla Firefox — an internet connection, and an account created by your organisation’s administrator. The recommended minimum screen resolution is 1366×768.

The sequence below follows Trace’s real flow. Work through it in order; each step rests on the one before.

Open your application address and fill in Email Address and Password on the Sign In page. Once you are through, you land on the Dashboard. There is no onboarding wizard — the Dashboard shows Active Engagements, Papers Assigned, Pending Reviews, Completion Rate and Recent Activity straight away.

The sidebar on the left carries Dashboard, Engagements, My Tasks, Templates, Analytics, Reports, Team, Activity, with Integrations, Settings and Help at the bottom. The header above holds a Search box, the notification bell and the profile menu.

Go to Team → Invite member and fill in Email, Full name, Initials, Role, and Phone where you need it. The organisation roles available are Partner, Manager, Supervisor, Senior, Junior.

Do this before creating an engagement, because an engagement needs preparers and reviewers who already exist in the system. Remember too that only Partner, Manager and Senior can pick up a submitted working paper for review — make sure your team composition includes them.

Open Templates. You will see the built-in working paper library, grouped by category and searchable by name or code: the A110–A170 series for engagement acceptance and set-up, B100–B280 for procedures and testing, C100–C400 for completion and reporting. Each template shows a Form preview and its Standard references to Standar Audit (SA).

Click a template, then Edit template to add or adjust sections and fields to suit your methodology — including the scales and wording you settled in the previous section. The result is saved as your organisation’s own version, with a version history you can roll back to; the built-in template is left unchanged.

Do this before the first engagement runs. Changing the shape of a working paper in the middle of fieldwork is the most expensive way to discover that your methodology was not finished.

Engagements → New Engagement. Fill in Client Name (the entity or area being audited), Industry, Client Address, then Engagement Type, Accounting Standard, Fiscal Year Start and End, Deadline, and Additional Notes. An engagement is born in Draft; the other statuses available are Active, Review, Completed and Archived.

Open that engagement’s Details page, go to the Team tab, then Add Member: search for a name, choose an Engagement role — Engagement Partner, Engagement Manager, Supervisor, Senior Auditor or Junior Auditor — and save. An engagement role is not an organisation role: one sets the part somebody plays on this engagement, the other their standing in the audit function.

The Working Papers tab shows the engagement’s papers, grouped into the A1 Pre-Engagement, A2 Planning, B Execution and C Completion categories, each with its own completion count.

Click a working paper to open its editor. The title is the template’s code and name, for example A150 Pernyataan Independensi or B210 Pengujian Pengendalian.

  • Entries save themselves as you type — watch for the Saving… then Saved indicator; a Save now button is there if you want to force it.
  • The Completion bar shows what percentage of the required fields is filled in.
  • The Comments panel holds review questions and can be attached to a particular field; the History panel records what happened to this paper, and who did it.
  • When several people open the same paper, their presence shows live as avatars and cursors.

For engagements that lean on accounting data, Integrations connects Trace to Accurate Online, Jurnal.id, Zahir or QuickBooks through OAuth authorisation and data mapping; an Import from Excel path is available for loading working paper, engagement or user data by mapping the columns and reviewing the validation results before it runs.

The transition button sits at the top right of the editor, and offers only the step you are allowed to take.

  1. The preparer submits the paper: In Progress → Submitted. The form locks read-only immediately.
  2. A reviewer holding the Partner, Manager or Senior role picks it up: Submitted → In Review.
  3. The assigned reviewer approves it to Completed, or returns it to Rework — and a return must carry a reason.
  4. From Rework, the preparer fixes it and submits again.

Completed is a final status. Every transition is recorded in that paper’s History, and appears in the organisation-level Activity as well.

Throughout all of this, My Tasks is each auditor’s daily view: every paper assigned to them across engagements, with counts for Total Tasks, In Progress, In Review and Needs Rework.

Reports opens the Reports & Exports page. Exports come as PDF, Word or Excel, for a single working paper or as a bundle for one engagement — with options for a cover page, table of contents, signatures, history and comments. An export runs as a background job; the Download button appears as soon as its status is Completed.

Analytics watches delivery: KPI cards, Working Paper Status, Completion Trend, Engagement Progress and Team Workload, over the From–To range you choose. Activity provides the organisation-wide trail, filtered by Action, User, From and To.

Your first cycle is complete when:

  1. The templates have been adjusted to your methodology and agreed, rather than taken as they come and patched halfway through.
  2. The team exists in Team with the right roles, including enough people at Partner, Manager or Senior to carry the review.
  3. One engagement has been run end to end inside the product — Engagement created, engagement team set, papers filled in, submitted, reviewed.
  4. At least one working paper has been through Rework, and the reason for the return is readable in History. An audit function that has never sent work back has not really tested its review control.
  5. The engagement conclusion is recorded — including C300 Ringkasan Audit with its main findings and its Jenis Opini — and does not live only in the engagement manager’s head.
  6. One export bundle has been produced and read by the people who will receive it, so the shape of the reporting is known early rather than in month six.
  7. Analytics shows numbers the team recognises as correct. Where it does not, it is rarely Analytics that is wrong — it is paper statuses that have not been kept up to date.

Outside the product it must still be clear who maintains the audit universe, how the annual plan is built, and where agreed actions are tracked to closure. Trace makes engagement execution and its evidence of review tidy; it does not replace those three — see Internal audit concepts.

Nextera Trace normally runs at trace.nextera.id. Accounts are provided by the product administrator in your organisation. The address above is the production address; if your organisation uses a dedicated environment, use the address in your onboarding pack.