Kenya's Public Sector Internal Audit Manual and the 2025 PSASB Templates: Running the Cycle in a System
The legal base for internal audit in Kenya's national and county entities, the engagement cycle in the PSASB manual and its 32 templates, and which parts a system can hold today.

Short answer: The PFM Act requires internal audit and an audit committee in every national and county government entity, and the 2015 regulations set the clocks: an annual plan by 15 February, written findings within seven days, an action plan within fourteen. PSASB's model manual and 32 templates describe each engagement. A system can hold the stages, evidence, findings and action-plan follow-up; the risk-based plan and workpapers stay outside.
This guide is for heads of internal audit and internal auditors in ministries, departments and agencies, county executives and assemblies, and state corporations. It sets out the legal base, the engagement cycle as PSASB's manual and 2025 templates frame it, and which parts a system can hold.
Creodata sells audit software for Kenya's internal audit teams, so we say plainly where it fits and where it does not; the mapping works for any tool. This is practical guidance, not legal advice.
The legal base
Internal audit in Kenya's public sector rests on the Public Finance Management Act, 2012 and its two sets of 2015 regulations: the National Government Regulations (Legal Notice 34 of 2015) and the County Governments Regulations (Legal Notice 35 of 2015).
| Provision | What it requires |
|---|---|
| PFM Act s.73 | Every national government entity must have internal audit following international best practice, and an audit committee. The Internal Auditor-General's Department sets its scope: governance, risk-based, value-for-money and systems audits, asset verification, policy compliance and management information |
| PFM Act s.155 | The same duty for every county government entity, with its own audit committee |
| National regs 161 and 162 | Internal auditors comply with the IIA's International Professional Practices Framework; the head of internal audit reports administratively to the Accounting Officer and functionally to the audit committee |
| National reg 166; county reg 159 | Annual self-assessment and audit committee review; an external assessment by a recognised body every three to five years |
| National reg 170; county reg 163 | A three-year risk-based strategic plan, and an annual plan submitted to the audit committee by 15 February |
| National reg 171; county reg 164 | Findings reported promptly to the Accounting Officer; an oral preliminary report confirmed in writing within seven days |
| National reg 172; county reg 165 | The Accounting Officer's response and action plan to the audit committee chair within fourteen days |
| National reg 173; county reg 166 | Quarterly internal audit reports within 14 days of the end of each quarter |
| County reg 167 | County audit committees of three to five members, with an independent chair |
Three more rules raise the stakes on the records internal audit keeps:
- The Auditor-General reads them. Section 33 of the Public Audit Act gives the Auditor-General unhindered access to all internal audit reports of state organs and public entities.
- Follow-up now carries a penalty. Under the PFM (Amendment) Act, 2026, in force from 25 September 2026, an accounting officer who fails to implement recommendations of a National Assembly committee report on the Auditor-General's findings is liable to the section 199 penalty (s.68(4A); s.149(3A) for counties). That concerns external audit, but it sharpens every audit committee's question: which recommendations are still open?
- Government-owned enterprises have their own audit committees. The Government Owned Enterprises Act, 2025 requires every board to establish an audit committee overseeing internal audit, with a majority of independent directors, including the chair.
PSASB is the body that prescribes internal audit procedures for public entities (PFM Act s.194(1)(c)). It publishes the Global Internal Audit Standards and a compliance monitoring tool for public sector internal audit, alongside the manuals and templates.
The manuals and the 2025 templates
Two PSASB manuals rank for the searches internal auditors run:
- The Public Sector Entities Model Internal Audit Manual (August 2025), for internal audit functions across the public sector, aligned with the IIA's framework. Entities may customise it, and it is reviewed every three years.
- The County Government Internal Audit Manual (October 2021), for county executives and assemblies, developed by PSASB with the Internal Auditor-General's Department.
Both manuals say their templates are published separately on PSASB's website. The current set is the 2025 Model Public Sector Internal Audit Manual Templates: 32 templates in six groups. PSASB says it is progressively updating the templates in line with the Global Internal Audit Standards, which took effect on 9 January 2025.
| Group | Templates |
|---|---|
| 1. Governance and charter documents | Model Audit Committee Charter; Model Internal Audit Charter |
| 2. Strategic and annual planning | Internal Audit Strategic Plan; Internal Audit Plan |
| 3. Engagement planning | Ethics and Professionalism Acknowledgement Form; Coordination and Reliance Framework; Audit Notification; Engagement Plan; Internal Audit Planning Memorandum; Request for Audit Information; Information Request Monitoring Checklist; Business Process Analysis Form; Sample Engagement Audit Program |
| 4. Fieldwork and documentation | Entrance Meeting Agenda; Entrance Meeting Minutes; Exit Meeting Agenda; Exit Meeting Minutes; Workpaper; Draft Finding Sheet; Findings Database; Workpaper File Checklist; Review Notes |
| 5. Reporting | Internal Audit Final Report; Action Plan Reporting; Internal Audit Quarterly Report; Internal Audit Annual Report |
| 6. Quality assurance and performance measurement | Audit Client Satisfaction Survey; Periodic Audit Committee Survey; Periodic Senior Management Survey; Periodic Internal Audit Staff Survey; Performance Measurement Matrix; External Assessors TOR |
The engagement cycle as the manual frames it
Chapter 3 of the 2025 model manual, "Performing internal audit services", runs each engagement in three parts: engagement planning, conducting the engagement work, and communicating results and monitoring action plans. Read with the templates and the regulations, an engagement moves through these steps:
- Notification of objectives, scope and timing (Audit Notification).
- Planning: confirm the engagement is in the approved plan, understand the process, assess risks, set the programme (Engagement Plan, Business Process Analysis Form, Planning Memorandum, Sample Engagement Audit Program).
- Entrance meeting with management (Entrance Meeting Agenda and Minutes).
- Request for audit information: what is needed, from whom, by when, and what has arrived (Request for Audit Information; Information Request Monitoring Checklist).
- Fieldwork: tests documented, findings drafted and reviewed (Workpaper, Draft Finding Sheet, Review Notes, Workpaper File Checklist).
- Exit meeting to discuss significant observations and proposed recommendations before the report (Exit Meeting Agenda and Minutes).
- Draft report and written confirmation. Preliminary findings reported orally are confirmed in writing within seven days.
- Management responses and action plan. The Accounting Officer's response and action plan go to the audit committee chair within fourteen days (Action Plan Reporting).
- Final report. The head of internal audit reviews and approves the final engagement communication (Internal Audit Final Report).
- Follow-up and reporting. Findings and agreed actions are logged, followed up and rolled into the quarterly and annual reports (Findings Database, Quarterly and Annual Reports).
- Archive. The engagement file is closed and kept.
The manual also asks the head of internal audit to maintain a database of significant findings, recommendations and management action plans, which feeds the quarterly and annual reports and the follow-up.
Mapping the templates to a system
The question is which templates should become records in a system and which can stay as documents. This table maps each part of the cycle to what a system can hold, and says honestly what AuditEDMS holds today.
| Stage or template | What a system can hold | AuditEDMS today |
|---|---|---|
| Internal Audit Strategic Plan; Internal Audit Plan | The risk-based plan, each engagement linked to it | Not held. The plan stays in the template or another tool |
| Audit Notification | A dated stage with the signed notification filed against it | Held as a stage and its document |
| Engagement Plan; Planning Memorandum; Audit Program | A planning stage that cannot close until the memorandum is filed | Held as a stage and its documents; the programme itself is a document you file |
| Entrance Meeting Agenda and Minutes | A stage with the agenda and minutes filed, dated and signed off | Held |
| Request for Audit Information | A request list per engagement: item, owner, due date | Held; auditees upload against it through an expiring link, with no account |
| Information Request Monitoring Checklist | What arrived, when, from whom, what is late, who was chased | Held: the request list records receipts and outstanding items, with chasers |
| Workpaper; Workpaper File Checklist; Review Notes | Working papers and review | Not held: AuditEDMS is not working-paper software. Evidence the auditee sends is held |
| Draft Finding Sheet; Findings Database | A findings register with ratings, owners and dates | Held: a findings register per engagement, each finding with severity, recommendation, management's response and the agreed action with owner and due date. Drafting the finding is still the auditor's work |
| Exit Meeting Agenda and Minutes | A stage with the minutes filed | Held |
| Draft report; seven-day written confirmation | A dated stage with the draft filed | Held as a stage and its document |
| Management responses; Action Plan Reporting | Responses filed; action plans tracked to closure | Held. Management responses are a stage with their document; each agreed action moves from agreed through in progress to implemented, is verified by someone other than the person who recorded it implemented, or is closed as risk accepted with a note, with a dated follow-up log. A follow-up register shows open and overdue actions across engagements. Action owners are not emailed by the system |
| Internal Audit Final Report | A stage with the approved report filed and signed off | Held |
| Quarterly and Annual Reports | Reports drawn from engagement and findings records | Partly: dashboards and the follow-up register of open and overdue actions help; the report itself is written outside |
| Surveys; Performance Measurement Matrix; External Assessors TOR | Quality programme records | Not held as structured records; completed documents can be filed |
| Archive | A closed file, retention dates and legal hold | Held: an archive stage, retention dates by document type and legal hold |
The engagement itself, from notification to archive, fits a system well, because each step is a dated event with a document behind it. So do the findings database and action-plan follow-up, which the manual asks the head of internal audit to maintain and which feed the audit committee's question of what is still open. The annual risk-based plan and workpapers are structured work of their own; with AuditEDMS they stay in PSASB's templates or another tool for now.
A note on where the data sits
Regulation 26 of the Data Protection (General) Regulations, 2021 requires processing in Kenya, or a serving copy kept in Kenya, for listed purposes including overseeing any system for administering public finances by a state organ. Azure has no region in East Africa today; its African regions are in South Africa. Before choosing any cloud system for internal audit records, ours included, ask your data protection officer and legal adviser whether reg 26 applies.
Where Creodata fits
AuditEDMS, our audit management software, holds the engagement cycle as stages with evidence. Its internal audit template, ready to use and adjusted to your methodology at implementation, follows the manual's cycle: notification, planning memorandum, entrance meeting, request for audit information, fieldwork, exit meeting, draft report, management responses, final report (which starts the file-assembly clock) and archiving. A stage cannot be completed until the document it depends on is filed, and stages complete in order, dated and signed off. The request list, answered by auditees online with chasers for late items, doubles as your information request monitoring checklist. Evidence is filed to your own SharePoint, versioned and checksummed, with retention dates and legal hold. Findings are recorded with severity, recommendation, management's response and the agreed action with owner and due date, and each action is followed to implementation and confirmed; the follow-up register shows what is open and overdue across engagements, ready for the quarterly report and the audit committee. Auditors record time against each engagement, and every action is written to an audit trail, with a printable compliance view per engagement.
It does not hold the annual risk-based plan or working papers; those stay in PSASB's templates or another tool for now. AuditEDMS runs in your own Azure subscription, in the region you choose, with documents in your own SharePoint, and Creodata operates the deployment through standing management access recorded in your Azure activity log. Pilots are by invitation, and pricing is on request. See audit software in Kenya, and our guide to the internal audit request for information.
Frequently asked questions
Where do I find the public sector internal audit manual for Kenya?
On PSASB's website. The Public Sector Entities Model Internal Audit Manual is dated August 2025, the County Government Internal Audit Manual October 2021, and the 2025 templates are listed on PSASB's internal audit templates page.
Do county governments follow the same cycle as national government?
Yes, in substance. PFM Act s.155 mirrors s.73, and the County Governments Regulations set the same plan date, seven-day confirmation, fourteen-day action plan and quarterly reporting (regs 163 to 166), with county audit committees under reg 167.
Can a system replace the findings database and action plan tracking?
Yes. In AuditEDMS each finding holds its recommendation, management's response and the agreed action with owner and due date, and the action is tracked to implementation and verified by someone other than the person who recorded it implemented. A follow-up register lists open and overdue actions across engagements. Chasing action owners is still done by your team: the system records owners by name and does not email them.
See how AuditEDMS for Kenya's internal audit teams runs an engagement from notification to final report, with the request list answered from the auditee's side and every agreed action followed to closure: request a pilot.