assess.one – AI-powered business operations platform

Workflow Template

Internal Audit Workflow

Plans, executes, and closes internal audits: lead auditor defines scope and schedule, auditor performs fieldwork and records findings, the audited area supplies management responses and corrective actions, the report is approved, corrective actions are followed up and verified, and stakeholders are notified on closure.

Internal audit functions in larger organisations must demonstrate a defensible, repeatable process from audit planning through to closure, with clear evidence of management engagement and corrective action verification. The Internal Audit Management Workflow governs the full audit lifecycle in assess.one, coordinating lead auditors, fieldwork auditors, the audited business area, report approvers, and corrective action owners within a single controlled process. Every stage, from scope and scheduling through fieldwork, management response, approval, follow-up verification, and stakeholder notification, is captured with role-based accountability and a timestamped record suitable for audit committee and regulatory review.

Business Outcomes

  • Reduce average audit cycle time from planning to closure through structured, automated handoffs
  • Achieve 100% traceability of findings, management responses, and corrective actions in a single audit record
  • Eliminate unapproved audit report distribution through mandatory approval gating
  • Improve corrective action closure rates via automated follow-up and verification cycles
  • Provide audit committees with a consistent, exportable evidence trail for every audit

Workflow Steps

Steps

  1. 1
    Create Audit Recordcreate record

    Registers the new internal audit using the scope, criteria, business area and schedule provided by the lead auditor.

  2. 2
    Set Status: Plannedupdate record

    Sets the audit status to Planned once scope and schedule are captured.

  3. 3
    Set Audit Due Dateset due date

    Sets the record due date based on the planned audit duration for SLA tracking.

  4. 4
    Assign Auditor for Fieldworkassign user

    Assigns an auditor to perform fieldwork for this audit.

  5. 5
    Perform Fieldwork and Record Findingscreate task

    Auditor conducts fieldwork against the scope and criteria and records findings and severity.

  6. 6
    Set Status: Awaiting Management Responseupdate record

    Updates audit status once fieldwork and findings are recorded.

  7. 7
    Request Management Responserequest external input

    Sends the audited area a link to submit their management response and corrective action plan.

  8. 8
    Persist Management Responseupdate record

    Saves the audited area's management response and corrective action plan to the record.

  9. 9
    Request Audit Report Approvalrequest approvalrequires approval

    Sends the completed audit report — findings, management response and corrective actions — for approval.

  10. 10
    Route on Report Approval Outcome

    Branches based on whether the audit report is approved or sent back for rework.

    approval_status: "approved"Assign Corrective Action Follow-up
    approval_status: "rejected"Restart Fieldwork for Revision
    DefaultEnd
  11. 11
    Restart Fieldwork for Revisionrestart from step

    Report was rejected — restarts the workflow from fieldwork so findings/report can be revised and resubmitted.

  12. 12
    Assign Corrective Action Follow-upassign user

    Assigns an auditor to follow up and verify implementation of corrective actions after the due date.

  13. 13
    Set Status: Corrective Action Follow-upupdate record

    Updates audit status while corrective actions are being followed up and verified.

  14. 14
    Follow Up and Verify Corrective Actionscreate task

    Auditor follows up with the audited area and verifies whether corrective actions were implemented effectively.

  15. 15
    Persist Verification Outcomeupdate record

    Saves the corrective action verification outcome and notes to the record.

  16. 16
    Route on Verification Outcome

    Branches depending on whether corrective actions were effectively implemented or require further follow-up.

    verification_outcome: "Verified Effective"Set Status: Closed
    verification_outcome: "Partially Implemented"Restart Follow-up for Further Verification
    verification_outcome: "Not Implemented"Restart Follow-up for Further Verification
    DefaultEnd
  17. 17
    Restart Follow-up for Further Verificationrestart from step

    Corrective actions were not fully implemented — restarts the follow-up cycle for further verification.

  18. 18
    Set Status: Closedupdate record

    Sets the audit status to Closed once corrective actions are verified as effective.

  19. 19
    Notify Stakeholders of Closuresend email

    Notifies stakeholders and the audited area that the internal audit has been closed.

  20. 20
    Set Status: Fieldwork In Progressupdate record

    Sets the audit status to Fieldwork In Progress as fieldwork begins.

Fields

  • Audit Title*
  • Business Area / Department*
  • Audit Scope*
  • Audit Criteria / Standards*
  • Planned Start Date*
  • Planned End Date*
  • +12 more fields

Forms

Internal Audit Planning Form

10 fields

Data Views

Active Internal Audits

audit_title, business_area, audit_status, findings_severity +1 more

Corrective Action Follow-up

audit_title, business_area, corrective_action_due_date, verification_outcome

Dashboard Widgets

Audit Pipeline OverviewFindings by SeverityAudit Progress Funnel

Recommended integrations

Setup the following integrations to extend workflow capability.

  • Send email in the workflow

    AWS SES logoAWS SES
internal auditaudit workflowcompliance auditaudit managementaudit findings

Similar Workflows

Similar Categories

FAQs

How is this audit workflow audited internally?

Every action within the workflow, including status changes, fieldwork findings, management responses, approval decisions, and verification outcomes, is timestamped and attributed to the responsible user in assess.one. This creates a complete, immutable audit trail for each audit record that can be reviewed by internal audit leadership, compliance, or external assessors without reconstructing activity from email or spreadsheets.

Who has access to audit findings and management responses within the platform?

Access is governed by role-based permissions configured directly in assess.one, so lead auditors, fieldwork auditors, the audited business area, and approvers only see the information and steps relevant to their role. Sensitive findings and draft management responses remain restricted until the appropriate stage in the workflow releases them, supporting confidentiality requirements common in audit functions.

How does this workflow integrate with existing enterprise systems?

Notifications and status updates can be configured inside assess.one to route through email, Slack, or other connected channels, keeping stakeholders informed without leaving their existing tools. All integration configuration happens natively within the platform, so there is no separate development project required to connect notification channels.

Can the audit approval and escalation logic be customised?

Yes. The report approval step, escalation routing on rejection, and corrective action follow-up cycles can all be adjusted directly within assess.one to reflect your organisation's audit charter and approval hierarchy. Teams can add additional approvers, change notification triggers, or extend verification cycles without any coding or vendor engagement.

What happens if the audit report is not approved?

The Route on Report Approval Outcome step automatically directs the audit record back to the Restart Fieldwork for Revision step, ensuring rejected reports are revised rather than left unresolved. This closed-loop mechanism ensures no audit report progresses to closure without a formally recorded approval decision.

How are corrective actions tracked and verified before closure?

Once management responses are recorded, a corrective action owner is assigned and the audit moves into the Corrective Action Follow-up status, where progress is followed up and verification outcomes are formally persisted. If verification fails, the workflow automatically restarts follow-up for further verification, preventing premature closure of unresolved issues.

Who needs access to this workflow, and how are roles assigned?

Typical participants include the lead auditor, fieldwork auditor, representatives from the audited business area, report approvers, and corrective action owners, all of whom are assigned within assess.one at the relevant workflow step. Access can be scoped narrowly so each participant only interacts with the steps and information required for their role, supporting segregation of duties.

How long does it take to implement this audit management workflow?

The template is ready to use and can be published in minutes, with no lengthy implementation project required. Once published, your audit team can immediately begin creating audit records and running live audits, while step names, roles, and notification logic can be refined in the platform as your process matures.

What compliance considerations does this workflow support?

The structured sequence of scoping, fieldwork, management response, approval, and verified corrective action closure aligns with common internal audit standards such as those referenced by IIA guidance and SOX-related audit programmes. Because every step and decision is logged with role attribution and timestamps, the workflow supports evidentiary requirements for internal control assessments and external quality reviews.

Ready to use this workflow?

Create a free account and customise this workflow for your business.

Internal Audit Management Workflow | assess.one