The Internal Audit Request for Information: Template, Monitoring Checklist and Auditee Uploads

A request for audit information template, an information request monitoring checklist, how both tie to IIA Standards 13.1 and 14.1, and how to stop chasing auditees by email.

CS
Creodata Solutions Team
The Internal Audit Request for Information: Template, Monitoring Checklist and Auditee Uploads

Short answer: A request for audit information lists every document the internal audit team needs, who in the auditee must provide it, for which period, in what format and by when. A monitoring checklist records when each item arrived, who received it and who was chased. Together they are the evidence that information was gathered properly, which the IIA's Standard 14.1 expects you to be able to show.

This guide is for heads of internal audit, audit managers and lead auditors in ministries, county governments, state corporations, banks, insurers, SACCOs and groups who still send the request as a Word document and track replies in a spreadsheet. It gives you a template you can copy, a monitoring checklist, and the points where the standards and Kenya's public-sector templates expect a record.

Creodata sells audit management software, including internal audit management software, so we say plainly where it fits near the end. The template and checklist work with or without any software. This is practical guidance, not professional advice: your internal audit charter, methodology and the rules of your sector decide what applies to you.

What a request for audit information is

The request for audit information (often shortened to RFI, and called a document request list or an information request in many functions) is the formal list of what the audit team needs from the auditee to plan and perform the engagement. It usually travels with, or just after, the audit notification.

A good request does three jobs:

  • It lets fieldwork start at the desk. If documents arrive before the team goes on site, the desk review is done and the time on site is spent on walkthroughs and testing, not on waiting for files.
  • It fixes accountability. Each item has a named owner in the auditee and a due date, so a late item is a fact, not an impression.
  • It becomes evidence. The request, and the record of what came back, show what information the conclusions rest on and where it came from.

How the request ties to the Global Internal Audit Standards

The IIA's Global Internal Audit Standards took effect on 9 January 2025. Two standards frame the request.

Standard 13.1, Engagement Communication. Internal auditors must communicate the engagement's objectives, scope and timing to management. The implementation guidance lists requesting the information and resources the engagement needs among the ongoing communications, and suggests that the advance notice of an engagement should also ask for the documents needed to assess risks and start the work programme. The examples of evidence include documentation, such as emails, minutes or memos, showing the communications took place.

Standard 14.1, Gathering Information for Analyses and Evaluation. Information must be relevant, reliable and sufficient. The standard's own examples of evidence of conformance include a description of the information gathered: its source, the date it was gathered and the period it relates to. That is almost exactly what a well-kept monitoring checklist records.

Two further standards reach the request indirectly. Standard 14.6, Engagement Documentation, requires engagement documentation to be reviewed, approved by the chief audit executive and retained under law, regulation and policy. Standard 5.2, Protection of Information, names custody, retention and disposal of engagement records among its considerations. Documents an auditee sends are engagement records, so where they land matters.

For a wider view of which standards software can help evidence, see our guide to the Global Internal Audit Standards 2024, standard by standard.

Kenya's public-sector templates

In Kenya, the Public Sector Accounting Standards Board (PSASB) publishes the 2025 Model Public Sector Internal Audit Manual Templates on its internal audit templates page. The page says PSASB prescribed the IIA's International Professional Practices Framework for public-sector internal auditors through Gazette Notice No. 11033 of 30 August 2024, and that the templates are being updated in line with the Global Internal Audit Standards.

The engagement planning group includes four templates that belong together:

PSASB 2025 templateWhat it is for
Audit Notification TemplateThe memo from the head of internal audit announcing the review, its period and objectives, and proposing an opening meeting
Internal Audit Planning Memorandum TemplateThe plan for the engagement
Request for Audit Information TemplateA covering memo and a document request form: each document, who it is requested from, expected delivery and return dates, and remarks
Information Request Monitoring Checklist TemplateA log of each request: date requested, from whom, date received and by whom, date returned and by whom, and remarks

The fieldwork group adds Entrance Meeting and Exit Meeting agenda and minutes templates. The monitoring checklist's note asks for remarks on days delayed, reminders and escalation, which is the chasing record most functions keep only in email.

The request template's covering memo cites section 162 of the PFM regulations. Regulation 162(3) of the Public Finance Management (National Government) Regulations, 2015 gives the internal auditor "unrestricted, direct and prompt access to all records". A public-sector auditee that is slow to respond is therefore not only delaying the audit; the delay is itself worth recording.

Outside the public sector, and outside Kenya, the same structure works. Use your own manual's templates if it has them. Our guide to Kenya's public sector internal audit manual and the 2025 PSASB templates covers the rest of the engagement cycle.

A request for audit information template

Copy this table into your own request form. The example rows are for an illustrative procurement audit; replace them with your engagement's items.

RefDocument or information requestedPeriod coveredFormatRequested fromDue byOriginal to be returned?Notes for the auditee
RFI-01Procurement policy and procedures manual in force during the periodCurrent version and any version in force during the periodPDFHead of Procurement5 working days after issueNoInclude the approval date of each version
RFI-02Organisation chart of the procurement function, with names and rolesAs at the start of the auditPDFHead of Procurement5 working daysNo
RFI-03Listing of all purchase orders raisedFull audit periodExcel, exported from the systemHead of Procurement5 working daysNoInclude PO number, date, supplier, value and approver
RFI-04Supplier master file listingAs at period endExcelHead of Finance5 working daysNoInclude date created and date last changed for each supplier
RFI-05Tender committee minutesFull audit periodPDFSecretary, Tender Committee10 working daysYes, if only in hard copySigned copies
RFI-06Contracts registerFull audit periodExcelLegal Officer10 working daysNo
RFI-07Prior internal and external audit reports on procurement, with management responsesLast two yearsPDFHead of Procurement5 working daysNo

Put these points on the covering memo, as the PSASB template does:

  • the engagement name and reference, and a reference to the audit notification;
  • why the items are needed now (desk review before fieldwork);
  • the single due date, or a note that each row has its own;
  • what to do if an item cannot be provided electronically; and
  • the lead auditor's name and contact for questions.

An information request monitoring checklist

The checklist has two parts: a log per item, and a set of control points the audit manager checks.

The log, per request item

FieldWhy it matters
Ref and itemTies the log to the request and to the working papers
Requested from, and date requestedFixes who owes the item and from when
Due dateThe basis for "late"
Date received, and received byThe source and date Standard 14.1's evidence examples describe
Version or file name receivedShows exactly what the conclusions rest on
Days lateA fact for the exit meeting and the report
Reminders sent (dates) and escalation (to whom, when)The chasing record the PSASB checklist asks for in its remarks
Date returned and returned byFor originals and hard-copy files
StatusOutstanding, partly received, received, not available

The control points

WhenCheckEvidence to keep
Before issueEach item links to an engagement objective or planned test; no "everything you have" requestsThe planning memorandum and the request, reviewed by the audit manager
On issueThe request went to named owners with dates; the notification and request are filed against the engagementThe sent request and its date
Each weekOutstanding items are chased; items past due are escalated under your charterReminder dates and escalations on the log
At the entrance meetingOutstanding items and owners are confirmed with managementEntrance meeting minutes
Before fieldwork closesEvery item is received, marked not available, or recorded as a limitationThe completed log
At the exit meetingFor items never received, you have decided whether to report a finding, as Standard 14.1 requires, or to record a scope limitationExit meeting minutes
At archivingThe request, the log and every document received are retained with the engagement fileThe archived engagement record

Where requests by email break down

The template is rarely the problem. The trouble starts when the replies come back.

  • Documents arrive in several inboxes. The lead auditor, the manager and a team member each receive part of the response, and nobody sees the whole picture.
  • The log lags behind reality. Someone updates the spreadsheet on Fridays, so on Wednesday nobody knows what is outstanding.
  • The source is lost. A forwarded attachment no longer shows who in the auditee sent it, or when.
  • Large files do not travel. System extracts bounce off mailbox limits and end up on flash drives.
  • Evidence ends up on personal drives. When the audit committee or an external assessor asks for it, it has to be gathered again.

Where Creodata fits

AuditEDMS, our audit management software, keeps the request list and the monitoring log as one record against each engagement. Each engagement carries its request list: what was asked for, from whom, by when, what has arrived and what is outstanding, with chasers for late items. The auditee's contact receives an expiring upload link, confirms their email address with a one-time code and uploads against the list, with no account to create. Each upload is receipted and filed to your own SharePoint by auditee, engagement and document type, recording who sent it, when and how it arrived. Files are versioned and checksummed, never silently overwritten, with retention dates by document type and legal hold.

The engagement itself runs as stages with evidence gates. The internal audit template is ready to use, and adjusted to your methodology at implementation: audit notification, planning memorandum, entrance meeting, request for audit information, fieldwork, exit meeting, draft report, management responses, final report and archiving. It comes with a nine-item starting request list, from the organisation chart and policies in force to the status of prior audit recommendations, and a stage that depends on a document cannot be completed until it is filed. Auditors record time against engagement and stage, and every action is written to an audit trail. It runs in your own Azure subscription, with documents in your SharePoint; Creodata operates it through standing management access recorded in your Azure activity log.

When an item never arrives and you decide it is a finding, the findings register holds it: severity, recommendation, management's response and the agreed action with owner and due date, followed to implementation and confirmed, with a follow-up register of open and overdue actions across engagements. It is not working-paper software, and it has no audit universe or risk-based annual plan. Pilots are by invitation, and pricing is on request.

Frequently asked questions

Is a request for audit information the same as a PBC list?

They do the same job. "Prepared by client" (PBC) lists belong to external audit, where the client prepares schedules for the auditor. Internal audit usually speaks of a request for audit information or a document request list, sent to the auditee. For the external audit version, see our PBC list template.

When should the request go out?

With or soon after the audit notification, early enough for the desk review. Standard 13.1's implementation guidance suggests that the advance notice of an engagement should also ask for the information needed to assess risks and begin developing the work programme. Set a lead time in your methodology and apply it consistently.

What if the auditee never provides an item?

Record it. Standard 14.1 requires internal auditors to decide whether to gather more information when evidence falls short, and, if relevant evidence cannot be obtained, whether to report that as a finding. The monitoring log, with its reminder and escalation dates, is the support for either decision.

Do we need software to monitor information requests?

No. A disciplined spreadsheet can carry a small function. Software helps once several engagements run at once, when auditees send large files, or when you need to show an assessor where each document came from and when.


See how AuditEDMS internal audit management software keeps the request list, auditee uploads and chasers on one record: request a pilot.

See Audit Management Software in action.