Internal audit engagements, evidence and findings follow-up, in your own Microsoft 365.
AuditEDMS runs each internal audit engagement through its stages, sends document request lists to auditees who upload without an account, keeps every piece of evidence in your SharePoint with who sent it and when, and follows every finding from recommendation to verified implementation.
Where internal audit loses time
- Requests by email
The request for audit information goes out as a Word document, the replies come back to three inboxes, and the monitoring checklist is a spreadsheet someone updates on Fridays.
- Evidence scattered across drives
When the audit committee, an external assessor or the auditor-general asks for the evidence behind a report, it has to be gathered again.
- Stages without a record
Entrance meetings, exit meetings, draft reports and management responses happen, but the dates and who signed off live in minutes nobody can find.
- Action plans that go quiet
Management agrees an action and a date in the report, and nobody checks again until next year's audit, or until the audit committee asks what is still open.
What AuditEDMS does for an internal audit function
Engagement stages with gates
An internal audit engagement template is ready to use, and adjusted to your methodology at implementation. It runs through ten stages: audit notification, planning memorandum, entrance meeting, request for audit information, fieldwork, exit meeting, draft report, management responses, final report and archiving. A stage that depends on a document, such as the notification, the meeting minutes or the report, cannot be completed until the document is filed against it, and stages complete in order. Issuing the final report starts the file-assembly clock. Internal audit records time; it does not bill.
Document request lists that auditees answer online
Each engagement has its request list, starting from a nine-item template that includes the status of prior audit recommendations: what was asked for, from whom, by when, what arrived and what is outstanding. The auditee's contact gets an expiring upload link, confirms their email with a one-time code and uploads against the list. Late items are chased by a daily sweep, sent from the mailbox you connect. The list is your information request monitoring checklist, kept for you.
Findings and follow-up
Each finding is recorded against the engagement with its severity, the recommendation and management's response, then the agreed action plan with its owner and due date. The action moves through agreed, in progress, implemented and verified, and the person who records an action as implemented cannot also verify it. If management accepts the risk instead, the acceptance needs a note. Every follow-up is logged with its date. A follow-up register shows open actions across engagements, with a filter for the overdue ones, so your report to the audit committee on outstanding recommendations starts from a list rather than a trawl through last year's reports. Action owners are recorded by name; nothing is emailed to them automatically.
Evidence custody in your SharePoint
Every document is filed to your SharePoint by auditee, engagement and document type, recording who sent it, when and how. Files are versioned and checksummed, retention dates follow your policy by document type, and legal hold keeps a file past its date.
Time against each engagement
Auditors record time against engagement and stage and submit weekly; the head of internal audit or a manager approves. Planned hours are set when staff are allocated, so time against plan is visible per engagement and per person.
Sign-offs and an audit trail
Stage completions record who completed each stage, when and with what evidence. Approvals record who approved and whether on someone else's behalf. Every action is written to an audit trail, and the engagement prints as a record of every stage and its evidence.
How it maps to the Global Internal Audit Standards
The IIA's Global Internal Audit Standards took effect on 9 January 2025. This table shows honestly where AuditEDMS supports a standard today and where it does not.
5.2 Protection of Information
Custody, retention and disposal of engagement records
Partly: SharePoint custody, retention dates, legal hold, permissions; disposal stays your decision, as AuditEDMS deletes nothing when a period ends
9.3 Methodologies
Documented methodology for engagements
Supported: your methodology as engagement stages and gates
12.2 Performance Measurement
Measures of the function's performance
Partly: time against plan, stage dates, dashboards
12.3 Oversee and Improve Engagement Performance
Evidence of supervision documented and retained
Supported: stage sign-offs, approvals, audit trail
13.1 Engagement Communication
Notifying and meeting with the auditee
Supported: notification and entrance meeting stages
14.1 Gathering Information
Information for analyses and evaluation
Supported: document request lists, auditee uploads, chasers
14.6 Engagement Documentation
Documentation reviewed, approved by the CAE and retained
Supported: filed evidence, sign-offs, retention, archive stage
14.2, 14.3 and 14.5 Findings, their evaluation and engagement conclusions
Analysing information, rating findings and concluding
Partly: findings are recorded with their severity, and the evidence is filed against the engagement; the analysis, the evaluation and the conclusions remain the auditor's judgement
14.4 Recommendations and Action Plans
Recommendations, and management's action plans with owners and dates
Supported: each finding carries the recommendation, management's response and the agreed action with its owner and due date
15.1 Final Engagement Communication
The final report
Supported as stages and documents: draft report, management responses, final report
15.2 Confirming Implementation
Following up recommendations and action plans
Supported: the follow-up register of open and overdue actions, verification by someone other than the person who recorded the action implemented, and a dated follow-up log
9.4 Internal Audit Plan
A risk-based internal audit plan
Not yet
AuditEDMS has no audit universe or risk-based annual plan, and it does not hold working papers or run a quality assessment programme. If a risk-based plan is a must-have for you today, tell us: it shapes the roadmap, and we will say plainly when it ships.
For the public sector and for regulated enterprises
- Ministries, counties and local governments, and state corporations, where internal audit units report to an accounting officer and an audit committee under public finance law, and national internal audit manuals set the engagement cycle. The request list, stages and evidence record follow the manual's templates.
- Banks, insurers, SACCOs and microfinance institutions, whose regulators require an internal audit function reporting to a board audit committee.
- Listed companies and groups, whose corporate governance codes require internal audit and an audit committee.
Each country page sets out that country's internal audit mandates: Kenya, Uganda, Tanzania, Rwanda, Zambia, Nigeria, Ghana, South Africa and the UAE.
Frequently asked questions.
Does AuditEDMS track audit findings and management action plans?
Yes. Each finding is recorded with its severity, the recommendation, management's response and the agreed action plan with its owner and due date. The action is followed through agreed, in progress, implemented and verified, and someone other than the person who recorded it implemented must verify it; accepting the risk instead needs a note. A dated follow-up log keeps the history, and a follow-up register shows open and overdue actions across engagements. Owners are not emailed automatically: your team follows up from the register.
Does it hold working papers?
No. AuditEDMS holds the engagement record, the evidence received, the requests and the time. Working papers stay in the tool or templates your team uses.
Do auditees need an account?
No. They receive an expiring upload link, confirm their email address with a one-time code and upload against the request list.
Where is our data?
In your own Azure subscription, in the region you choose, with documents in your own SharePoint. Creodata operates the deployment through managed-application access recorded in your Azure activity log.
Can one internal audit function serve several subsidiaries or entities?
Yes. Each entity you audit is set up as an auditee with its own contacts and folder, and engagements, requests and documents are kept against it.