Plan progress
Owner: CAE / internal audit head
- Planned vs completed audits
- Quarter slippage
- Deferred reviews
- Budgeted vs actual hours
Decision: Does the audit committee need to approve scope changes, defer low-risk work or add coverage?
A good internal audit dashboard is a decision pack, not a chart gallery. It should tell the CAE, CFO and audit committee where the plan is slipping, which risks lack coverage, which observations matter, and which owners are not closing action items.
Download the Excel/PDF pack for dashboard metrics, committee packet structure, ATR ageing, monitoring exceptions, emerging-risk coverage and future product data-model fields.
Owner: CAE / internal audit head
Decision: Does the audit committee need to approve scope changes, defer low-risk work or add coverage?
Owner: Audit manager
Decision: Are the right risks being audited, or is the plan busy but not risk-aligned?
Owner: Engagement manager
Decision: Which themes need management escalation instead of item-level fixes?
Owner: Process owner / audit coordinator
Decision: Which owners need escalation because committed actions are not closing?
Owner: Fieldwork lead
Decision: Can the report be issued, or should scope limitation / evidence weakness be called out?
Owner: Analytics lead
Decision: Which monitoring rules are generating useful assurance, and which thresholds need recalibration?
Owner: Technology audit lead
Decision: Which emerging risks need assurance coverage outside the traditional finance cycles?
One-page summary of plan progress, high-risk observations, overdue ATR, emerging themes and decisions needed.
Status by P2P, O2C, R2R, cash/bank, H2R, inventory, fixed assets, treasury, compliance and ITGC.
High-rated observations with condition, impact, owner, due date, dependency and escalation status.
Open actions by owner, original due date, revised due date, ageing bucket, closure evidence and repeat flag.
Exception rule, source system, run date, population, exception count, false positives and validated issues.
Cyber, AI, third-party, geopolitical, resilience and data-governance coverage mapped to audit activities.
Cybersecurity remains the top-ranked risk and top internal audit priority globally; digital disruption including AI is the second-fastest climbing risk and reached No. 2 globally.
Chief audit executives are balancing AI growth with governance, integration, data-quality, cybersecurity, third-party and regulatory pressures.
The internal-audit file still needs SIA-linked evidence, documentation, review, reporting and prior-issue follow-up even when dashboarding and AI are used.
This is a public website resource. The reusable layer for the separate Internal Audit product build is the KPI dictionary, metric formula, source-system mapping, threshold logic, exception workflow and committee packet structure.
Product shape: Internal Audit command centre
Likely fields: Metric ID, formula, source system, owner, refresh cadence, threshold, committee display flag.
Product shape: Audit committee pack builder
Likely fields: Meeting date, period, summary narrative, decisions needed, high-risk issues, overdue actions.
Product shape: Continuous monitoring queue
Likely fields: Rule run, source extract, exception count, false positives, validated issues, owner, status.
Product shape: Audit universe planning
Likely fields: Risk theme, source signal, process owner, coverage status, planned review, dashboard note.
Generate an Excel/PDF committee dashboard pack from selected IA metrics.
Use the risk map before selecting dashboard themes.
Review the file before committee reporting.
Feed repeat exceptions into the monitoring dashboard.
Convert dashboard findings into observations and ATR follow-up.
Explain slippage and coverage gaps using hours and capacity.
An internal audit dashboard should show plan progress, risk coverage, high-risk observations, overdue management actions, evidence blockers, continuous monitoring exceptions and emerging risk coverage. It should support decisions, not only display counts.
The most useful audit committee KPIs are high-risk observations, overdue ATR ageing, repeat findings, plan slippage, critical scope gaps, evidence limitations and emerging risks such as cyber, AI, third-party risk and operational resilience.
Plan and issue dashboards should usually update monthly or before committee meetings. Continuous monitoring exception dashboards can update more frequently, but exceptions should be validated before they are treated as observations.
AI can draft dashboard commentary, but the file should preserve source metrics, thresholds, human edits and reviewer approval. Committee reporting should not rely on AI narrative without evidence and management validation.