Every engagement is built on the same structure SIA 220 and SIA 310 already expect: a process cycle breaks into sub-processes, each sub-process carries a rated risk, each risk is met by a control with a named objective, each control has a test, each test has a result, and a failed result can become an observation that flows into the report. CORAA seeds this from a pack library at engagement creation — the auditor’s confirm-or-edit is what makes a row authoritative, not the seed.
Eight process cycles ship as standard. The cadences below are illustrative starting references, not fixed rules — the actual review frequency for each cycle is calibrated with the internal audit team during onboarding, the same way SIA 310 expects planning to be tailored to the entity rather than templated.
An entity’s internal audit plan can run either engagement type, or both together — a fieldwork engagement for the dated report a board or audit committee expects, and continuous process monitors for the cycles that benefit from being watched every week instead of every quarter.
A control test concludes on the same four-point scale the Guidance Note on Audit of Internal Financial Controls uses, so a rating means the same thing whether an audit committee or a statutory auditor is reading it.
Condition — what was actually found, with the count or sample size. Criteria — the policy, standard or law the condition falls short of. Cause — the root cause, not just “control failed.” Effect — what could go wrong because of it. Recommendation— the specific fix, addressed to a role. From a failed test, CORAA can draft this structure — condition carries the real counts from the test, the rest is a starting point the auditor edits before creating it. A management response, response owner and agreed action date then carry the observation into the SIA 390 follow-up register, where closure evidence is risk-tiered: High → re-audit procedures, Medium → documentary evidence, Low → written management confirmation.
Every figure in the report — controls tested, observations by rating and status, RCM summary by cycle — is a direct count over the engagement’s own RCM rows and observations, not a document assembled separately at the end. A draft view is available at any point; a final report is gated until a draft has actually been issued to the auditee, the way SIA 370 (3.3) expects. An optional AI-drafted narrative can add an executive-summary reading of those same numbers — it’s marked as a draft the auditor reviews before it goes into the issued report, and flagged stale the moment the underlying RCM or observations change.
Internal audit under Section 138 of the Companies Act 2013 is mandatory for a defined set of companies (by paid-up capital, turnover, borrowings, or public deposits — check applicability for the entity in question). Separately, Section 143(3)(i) requires the statutory auditor to opine on the adequacy and operating effectiveness of internal financial controls. A control tested for the Section 138 function — its design, its test result, its rating — is the same evidence a statutory auditor needs for the Section 143(3)(i) opinion. CORAA’s RCM engine can carry the additional Guidance Note fields (assertions, key-control flag, IPE reference, test-of-design and test-of-effectiveness results) a statutory ICFR conclusion needs on the same control row, instead of a second team re-documenting it from scratch.