Workflow Template
Internal Audit Workflow
Plans, executes, and closes internal audits: lead auditor defines scope and schedule, auditor performs fieldwork and records findings, the audited area supplies management responses and corrective actions, the report is approved, corrective actions are followed up and verified, and stakeholders are notified on closure.
Internal audit functions in larger organisations must demonstrate a defensible, repeatable process from audit planning through to closure, with clear evidence of management engagement and corrective action verification. The Internal Audit Management Workflow governs the full audit lifecycle in assess.one, coordinating lead auditors, fieldwork auditors, the audited business area, report approvers, and corrective action owners within a single controlled process. Every stage, from scope and scheduling through fieldwork, management response, approval, follow-up verification, and stakeholder notification, is captured with role-based accountability and a timestamped record suitable for audit committee and regulatory review.
Business Outcomes
- Reduce average audit cycle time from planning to closure through structured, automated handoffs
- Achieve 100% traceability of findings, management responses, and corrective actions in a single audit record
- Eliminate unapproved audit report distribution through mandatory approval gating
- Improve corrective action closure rates via automated follow-up and verification cycles
- Provide audit committees with a consistent, exportable evidence trail for every audit
Workflow Steps
Steps
- 1Create Audit Recordcreate record
Registers the new internal audit using the scope, criteria, business area and schedule provided by the lead auditor.
- 2Set Status: Plannedupdate record
Sets the audit status to Planned once scope and schedule are captured.
- 3Set Audit Due Dateset due date
Sets the record due date based on the planned audit duration for SLA tracking.
- 4Assign Auditor for Fieldworkassign user
Assigns an auditor to perform fieldwork for this audit.
- 5Perform Fieldwork and Record Findingscreate task
Auditor conducts fieldwork against the scope and criteria and records findings and severity.
- 6Set Status: Awaiting Management Responseupdate record
Updates audit status once fieldwork and findings are recorded.
- 7Request Management Responserequest external input
Sends the audited area a link to submit their management response and corrective action plan.
- 8Persist Management Responseupdate record
Saves the audited area's management response and corrective action plan to the record.
- 9Request Audit Report Approvalrequest approvalrequires approval
Sends the completed audit report — findings, management response and corrective actions — for approval.
- 10Route on Report Approval Outcome
Branches based on whether the audit report is approved or sent back for rework.
approval_status: "approved"→Assign Corrective Action Follow-upapproval_status: "rejected"→Restart Fieldwork for RevisionDefault→End - 11Restart Fieldwork for Revisionrestart from step
Report was rejected — restarts the workflow from fieldwork so findings/report can be revised and resubmitted.
- 12Assign Corrective Action Follow-upassign user
Assigns an auditor to follow up and verify implementation of corrective actions after the due date.
- 13Set Status: Corrective Action Follow-upupdate record
Updates audit status while corrective actions are being followed up and verified.
- 14Follow Up and Verify Corrective Actionscreate task
Auditor follows up with the audited area and verifies whether corrective actions were implemented effectively.
- 15Persist Verification Outcomeupdate record
Saves the corrective action verification outcome and notes to the record.
- 16Route on Verification Outcome
Branches depending on whether corrective actions were effectively implemented or require further follow-up.
verification_outcome: "Verified Effective"→Set Status: Closedverification_outcome: "Partially Implemented"→Restart Follow-up for Further Verificationverification_outcome: "Not Implemented"→Restart Follow-up for Further VerificationDefault→End - 17Restart Follow-up for Further Verificationrestart from step
Corrective actions were not fully implemented — restarts the follow-up cycle for further verification.
- 18Set Status: Closedupdate record
Sets the audit status to Closed once corrective actions are verified as effective.
- 19Notify Stakeholders of Closuresend email
Notifies stakeholders and the audited area that the internal audit has been closed.
- 20Set Status: Fieldwork In Progressupdate record
Sets the audit status to Fieldwork In Progress as fieldwork begins.
Fields
- Audit Title*
- Business Area / Department*
- Audit Scope*
- Audit Criteria / Standards*
- Planned Start Date*
- Planned End Date*
- +12 more fields
Forms
Internal Audit Planning Form
10 fields
Data Views
Active Internal Audits
audit_title, business_area, audit_status, findings_severity +1 more
Corrective Action Follow-up
audit_title, business_area, corrective_action_due_date, verification_outcome
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Workflows
Similar Categories
FAQs
How is this audit workflow audited internally?
Every action within the workflow, including status changes, fieldwork findings, management responses, approval decisions, and verification outcomes, is timestamped and attributed to the responsible user in assess.one. This creates a complete, immutable audit trail for each audit record that can be reviewed by internal audit leadership, compliance, or external assessors without reconstructing activity from email or spreadsheets.
Who has access to audit findings and management responses within the platform?
Access is governed by role-based permissions configured directly in assess.one, so lead auditors, fieldwork auditors, the audited business area, and approvers only see the information and steps relevant to their role. Sensitive findings and draft management responses remain restricted until the appropriate stage in the workflow releases them, supporting confidentiality requirements common in audit functions.
How does this workflow integrate with existing enterprise systems?
Notifications and status updates can be configured inside assess.one to route through email, Slack, or other connected channels, keeping stakeholders informed without leaving their existing tools. All integration configuration happens natively within the platform, so there is no separate development project required to connect notification channels.
Can the audit approval and escalation logic be customised?
Yes. The report approval step, escalation routing on rejection, and corrective action follow-up cycles can all be adjusted directly within assess.one to reflect your organisation's audit charter and approval hierarchy. Teams can add additional approvers, change notification triggers, or extend verification cycles without any coding or vendor engagement.
What happens if the audit report is not approved?
The Route on Report Approval Outcome step automatically directs the audit record back to the Restart Fieldwork for Revision step, ensuring rejected reports are revised rather than left unresolved. This closed-loop mechanism ensures no audit report progresses to closure without a formally recorded approval decision.
How are corrective actions tracked and verified before closure?
Once management responses are recorded, a corrective action owner is assigned and the audit moves into the Corrective Action Follow-up status, where progress is followed up and verification outcomes are formally persisted. If verification fails, the workflow automatically restarts follow-up for further verification, preventing premature closure of unresolved issues.
Who needs access to this workflow, and how are roles assigned?
Typical participants include the lead auditor, fieldwork auditor, representatives from the audited business area, report approvers, and corrective action owners, all of whom are assigned within assess.one at the relevant workflow step. Access can be scoped narrowly so each participant only interacts with the steps and information required for their role, supporting segregation of duties.
How long does it take to implement this audit management workflow?
The template is ready to use and can be published in minutes, with no lengthy implementation project required. Once published, your audit team can immediately begin creating audit records and running live audits, while step names, roles, and notification logic can be refined in the platform as your process matures.
What compliance considerations does this workflow support?
The structured sequence of scoping, fieldwork, management response, approval, and verified corrective action closure aligns with common internal audit standards such as those referenced by IIA guidance and SOX-related audit programmes. Because every step and decision is logged with role attribution and timestamps, the workflow supports evidentiary requirements for internal control assessments and external quality reviews.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
