Governs the Internal Audit process, according to the ISO 19011 Standard and in compliance with the Global Internal Audit Standards (Section V).
Supports the entire Internal Audit cycle: from the creation of the Audit Universe and the annual risk-based program, to operational planning, audit execution, reporting, operational and participatory management of action plans, and communication of results to stakeholders.

 

CONTEXT

It allows you to define the organizational, regulatory, and control framework within which to base audit activities. It supports process mapping for Legal Entities, both through direct entry and continuous import from corporate systems. It enables repository management of various types of controls, including 262, 231, privacy, entity-level control, IT general controls, and corporate controls. It allows you to associate responsibility, scope, methods, type, frequency, and test plan with each control, ensuring an integrated information base for building the Audit Universe. It allows you to configure checklists for each process, for use during audits. It also supports management of the internal and external auditor structure, highlighting the requirements and qualifications needed to perform the activities.

UNIVERSE AUDIT DEFINITION

It allows for the definition of priority criteria (for each Auditable Unit based on the assessment of the Company Complexity Coefficient and the Process Risk Coefficient derived from ERM) and the definition of the annual Audit Program based on the defined Priority level, in order to assess the effective coverage of the Audit Universe. As part of the audit program definition, it allows for the interactive management of follow-up audits. It enables the activation of approval workflows to validate the annual program and consolidate a plan consistent with the organization's control and oversight needs.

INTERNAL AUDIT PLANS MANAGEMENT

It enables you to transform the annual program into operational, structured, and monitorable audit plans. It supports the generation of individual plans, the definition of the activity agenda, and the identification of controls to be investigated during audits. It enables graphical planning and plan updates via Gantt charts, facilitating the management of time, responsibilities, and progress. It allows you to assign tasks, auditors, and contact persons, keeping the planning aligned with supporting documentation and any changes to the scope of intervention.

 

 

 

 

 

 

 

 

CONDUCTING INTERNAL AUDITS

It allows you to perform scheduled checks and collect objective evidence in a structured manner. It supports the collection of information through appropriate checklists, promoting methodological consistency and completeness in data collection. It enables the collection and uploading of supporting documents and images, including through the use of tablets, making the evidence collected in the field immediately available.

INTERNAL AUDIT REPORT

It enables the automatic generation of the Audit Report, which provides detailed documentation of general audit information, the audit team, the findings, and the related findings. It allows process managers to define specific action plans for these findings. It enables the generation of reports, following audits, at different organizational levels, activating escalation processes based on management's definition of rules and assessments, before the final closure of the audit report.

ACTION PLANS MANAGEMENT

It allows for the management of the corrective action plan based on findings raised during the audit, incorporating proposals from both the audited departments and those formulated by internal and external auditors, linking actions to the findings, nonconformities, and observations raised. It enables active and participatory management at all levels of the organization, by defining those responsible for implementing individual actions and establishing a system of notifications and deadlines. This allows for the improvement process to be tracked and its consistency with the commitments made.

COMMUNICATION AND REPORTING

It enables the communication of results to the users involved. It provides process owners with reports and indicators for controlling and monitoring activities. It supports the production of management and operational reports at different organizational levels, facilitating the sharing of evidence and decisions. It integrates with the ERM model (if actively managed on the platform), sending control assessments to the dedicated structure for possible updating of the risk assessment itself.

 

It integrates with the ERM risk model and the operational controls flow.
 

 

 

 

 

 

 

 

 

 


Modules