The Internal Audit Request for Information: Template, Monitoring Checklist and Auditee Uploads
A request for audit information template, an information request monitoring checklist, how both tie to IIA Standards 13.1 and 14.1, and how to stop chasing auditees by email.

Short answer: A request for audit information lists every document the internal audit team needs, who in the auditee must provide it, for which period, in what format and by when. A monitoring checklist records when each item arrived, who received it and who was chased. Together they are the evidence that information was gathered properly, which the IIA's Standard 14.1 expects you to be able to show.
This guide is for heads of internal audit, audit managers and lead auditors in ministries, county governments, state corporations, banks, insurers, SACCOs and groups who still send the request as a Word document and track replies in a spreadsheet. It gives you a template you can copy, a monitoring checklist, and the points where the standards and Kenya's public-sector templates expect a record.
Creodata sells audit management software, including internal audit management software, so we say plainly where it fits near the end. The template and checklist work with or without any software. This is practical guidance, not professional advice: your internal audit charter, methodology and the rules of your sector decide what applies to you.
What a request for audit information is
The request for audit information (often shortened to RFI, and called a document request list or an information request in many functions) is the formal list of what the audit team needs from the auditee to plan and perform the engagement. It usually travels with, or just after, the audit notification.
A good request does three jobs:
- It lets fieldwork start at the desk. If documents arrive before the team goes on site, the desk review is done and the time on site is spent on walkthroughs and testing, not on waiting for files.
- It fixes accountability. Each item has a named owner in the auditee and a due date, so a late item is a fact, not an impression.
- It becomes evidence. The request, and the record of what came back, show what information the conclusions rest on and where it came from.
How the request ties to the Global Internal Audit Standards
The IIA's Global Internal Audit Standards took effect on 9 January 2025. Two standards frame the request.
Standard 13.1, Engagement Communication. Internal auditors must communicate the engagement's objectives, scope and timing to management. The implementation guidance lists requesting the information and resources the engagement needs among the ongoing communications, and suggests that the advance notice of an engagement should also ask for the documents needed to assess risks and start the work programme. The examples of evidence include documentation, such as emails, minutes or memos, showing the communications took place.
Standard 14.1, Gathering Information for Analyses and Evaluation. Information must be relevant, reliable and sufficient. The standard's own examples of evidence of conformance include a description of the information gathered: its source, the date it was gathered and the period it relates to. That is almost exactly what a well-kept monitoring checklist records.
Two further standards reach the request indirectly. Standard 14.6, Engagement Documentation, requires engagement documentation to be reviewed, approved by the chief audit executive and retained under law, regulation and policy. Standard 5.2, Protection of Information, names custody, retention and disposal of engagement records among its considerations. Documents an auditee sends are engagement records, so where they land matters.
For a wider view of which standards software can help evidence, see our guide to the Global Internal Audit Standards 2024, standard by standard.
Kenya's public-sector templates
In Kenya, the Public Sector Accounting Standards Board (PSASB) publishes the 2025 Model Public Sector Internal Audit Manual Templates on its internal audit templates page. The page says PSASB prescribed the IIA's International Professional Practices Framework for public-sector internal auditors through Gazette Notice No. 11033 of 30 August 2024, and that the templates are being updated in line with the Global Internal Audit Standards.
The engagement planning group includes four templates that belong together:
| PSASB 2025 template | What it is for |
|---|---|
| Audit Notification Template | The memo from the head of internal audit announcing the review, its period and objectives, and proposing an opening meeting |
| Internal Audit Planning Memorandum Template | The plan for the engagement |
| Request for Audit Information Template | A covering memo and a document request form: each document, who it is requested from, expected delivery and return dates, and remarks |
| Information Request Monitoring Checklist Template | A log of each request: date requested, from whom, date received and by whom, date returned and by whom, and remarks |
The fieldwork group adds Entrance Meeting and Exit Meeting agenda and minutes templates. The monitoring checklist's note asks for remarks on days delayed, reminders and escalation, which is the chasing record most functions keep only in email.
The request template's covering memo cites section 162 of the PFM regulations. Regulation 162(3) of the Public Finance Management (National Government) Regulations, 2015 gives the internal auditor "unrestricted, direct and prompt access to all records". A public-sector auditee that is slow to respond is therefore not only delaying the audit; the delay is itself worth recording.
Outside the public sector, and outside Kenya, the same structure works. Use your own manual's templates if it has them. Our guide to Kenya's public sector internal audit manual and the 2025 PSASB templates covers the rest of the engagement cycle.
A request for audit information template
Copy this table into your own request form. The example rows are for an illustrative procurement audit; replace them with your engagement's items.
| Ref | Document or information requested | Period covered | Format | Requested from | Due by | Original to be returned? | Notes for the auditee |
|---|---|---|---|---|---|---|---|
| RFI-01 | Procurement policy and procedures manual in force during the period | Current version and any version in force during the period | Head of Procurement | 5 working days after issue | No | Include the approval date of each version | |
| RFI-02 | Organisation chart of the procurement function, with names and roles | As at the start of the audit | Head of Procurement | 5 working days | No | ||
| RFI-03 | Listing of all purchase orders raised | Full audit period | Excel, exported from the system | Head of Procurement | 5 working days | No | Include PO number, date, supplier, value and approver |
| RFI-04 | Supplier master file listing | As at period end | Excel | Head of Finance | 5 working days | No | Include date created and date last changed for each supplier |
| RFI-05 | Tender committee minutes | Full audit period | Secretary, Tender Committee | 10 working days | Yes, if only in hard copy | Signed copies | |
| RFI-06 | Contracts register | Full audit period | Excel | Legal Officer | 10 working days | No | |
| RFI-07 | Prior internal and external audit reports on procurement, with management responses | Last two years | Head of Procurement | 5 working days | No |
Put these points on the covering memo, as the PSASB template does:
- the engagement name and reference, and a reference to the audit notification;
- why the items are needed now (desk review before fieldwork);
- the single due date, or a note that each row has its own;
- what to do if an item cannot be provided electronically; and
- the lead auditor's name and contact for questions.
An information request monitoring checklist
The checklist has two parts: a log per item, and a set of control points the audit manager checks.
The log, per request item
| Field | Why it matters |
|---|---|
| Ref and item | Ties the log to the request and to the working papers |
| Requested from, and date requested | Fixes who owes the item and from when |
| Due date | The basis for "late" |
| Date received, and received by | The source and date Standard 14.1's evidence examples describe |
| Version or file name received | Shows exactly what the conclusions rest on |
| Days late | A fact for the exit meeting and the report |
| Reminders sent (dates) and escalation (to whom, when) | The chasing record the PSASB checklist asks for in its remarks |
| Date returned and returned by | For originals and hard-copy files |
| Status | Outstanding, partly received, received, not available |
The control points
| When | Check | Evidence to keep |
|---|---|---|
| Before issue | Each item links to an engagement objective or planned test; no "everything you have" requests | The planning memorandum and the request, reviewed by the audit manager |
| On issue | The request went to named owners with dates; the notification and request are filed against the engagement | The sent request and its date |
| Each week | Outstanding items are chased; items past due are escalated under your charter | Reminder dates and escalations on the log |
| At the entrance meeting | Outstanding items and owners are confirmed with management | Entrance meeting minutes |
| Before fieldwork closes | Every item is received, marked not available, or recorded as a limitation | The completed log |
| At the exit meeting | For items never received, you have decided whether to report a finding, as Standard 14.1 requires, or to record a scope limitation | Exit meeting minutes |
| At archiving | The request, the log and every document received are retained with the engagement file | The archived engagement record |
Where requests by email break down
The template is rarely the problem. The trouble starts when the replies come back.
- Documents arrive in several inboxes. The lead auditor, the manager and a team member each receive part of the response, and nobody sees the whole picture.
- The log lags behind reality. Someone updates the spreadsheet on Fridays, so on Wednesday nobody knows what is outstanding.
- The source is lost. A forwarded attachment no longer shows who in the auditee sent it, or when.
- Large files do not travel. System extracts bounce off mailbox limits and end up on flash drives.
- Evidence ends up on personal drives. When the audit committee or an external assessor asks for it, it has to be gathered again.
Where Creodata fits
AuditEDMS, our audit management software, keeps the request list and the monitoring log as one record against each engagement. Each engagement carries its request list: what was asked for, from whom, by when, what has arrived and what is outstanding, with chasers for late items. The auditee's contact receives an expiring upload link, confirms their email address with a one-time code and uploads against the list, with no account to create. Each upload is receipted and filed to your own SharePoint by auditee, engagement and document type, recording who sent it, when and how it arrived. Files are versioned and checksummed, never silently overwritten, with retention dates by document type and legal hold.
The engagement itself runs as stages with evidence gates. The internal audit template is ready to use, and adjusted to your methodology at implementation: audit notification, planning memorandum, entrance meeting, request for audit information, fieldwork, exit meeting, draft report, management responses, final report and archiving. It comes with a nine-item starting request list, from the organisation chart and policies in force to the status of prior audit recommendations, and a stage that depends on a document cannot be completed until it is filed. Auditors record time against engagement and stage, and every action is written to an audit trail. It runs in your own Azure subscription, with documents in your SharePoint; Creodata operates it through standing management access recorded in your Azure activity log.
When an item never arrives and you decide it is a finding, the findings register holds it: severity, recommendation, management's response and the agreed action with owner and due date, followed to implementation and confirmed, with a follow-up register of open and overdue actions across engagements. It is not working-paper software, and it has no audit universe or risk-based annual plan. Pilots are by invitation, and pricing is on request.
Frequently asked questions
Is a request for audit information the same as a PBC list?
They do the same job. "Prepared by client" (PBC) lists belong to external audit, where the client prepares schedules for the auditor. Internal audit usually speaks of a request for audit information or a document request list, sent to the auditee. For the external audit version, see our PBC list template.
When should the request go out?
With or soon after the audit notification, early enough for the desk review. Standard 13.1's implementation guidance suggests that the advance notice of an engagement should also ask for the information needed to assess risks and begin developing the work programme. Set a lead time in your methodology and apply it consistently.
What if the auditee never provides an item?
Record it. Standard 14.1 requires internal auditors to decide whether to gather more information when evidence falls short, and, if relevant evidence cannot be obtained, whether to report that as a finding. The monitoring log, with its reminder and escalation dates, is the support for either decision.
Do we need software to monitor information requests?
No. A disciplined spreadsheet can carry a small function. Software helps once several engagements run at once, when auditees send large files, or when you need to show an assessor where each document came from and when.
See how AuditEDMS internal audit management software keeps the request list, auditee uploads and chasers on one record: request a pilot.