High-performing internal audit teams do not need another static format. They need a controlled path from audit universe to final follow-up: planning, scope, evidence, RCM, testing, monitoring, reporting and action tracking. CORAA keeps those objects connected, so a dashboard number can be traced back to the source test, evidence request, exception and reviewer conclusion behind it.
Every engagement is built on the same structure SIA 220 and SIA 310 already expect: a process cycle breaks into sub-processes, each sub-process carries a rated risk, each risk is met by a control with a named objective, each control has a test, each test has a result, and a failed result can become an observation that flows into the report. CORAA seeds this from a pack library at engagement creation — the auditor’s confirm-or-edit is what makes a row authoritative, not the seed.
Internal audit dashboards fail when they become presentation layers disconnected from evidence. CORAA’s command-centre view is built from the same RCM rows, monitoring results, fieldwork status, observations and ATR records used in the audit file. Where Intelligence Studio is connected, reviewers can move from a high-risk KPI into money-flow, Business DNA and voucher-level context before deciding whether the signal is a control exception, a monitoring item or a false positive.
Nine generic monitorable process cycles ship as standard. The cadences below are illustrative starting references, not fixed rules — the actual review frequency for each cycle is calibrated with the internal audit team during onboarding, the same way SIA 310 expects planning to be tailored to the entity rather than templated.
Internal audit teams usually start with practical cycle questions: P2P checklists, R2R controls, O2C testing, payroll, cash-bank, treasury, inventory and statutory compliance RCM formats. These guides turn the product model into fieldwork content an auditor can inspect, download and reuse before moving the same structure into a live workflow.
Buyers do not need a demo to understand the file structure. The public repository exposes the same sequence the module operationalises: score the audit universe, convert it into an annual plan, scope the engagement, build the RCM, run monitoring rules, write observations and track management action. Each tool is downloadable so an auditor can test the workflow on one client before deciding what to automate.
The free public resources are useful starting points; inside CORAA, the same structure becomes a managed repository. The risk scorer ranks the audit universe, the annual plan sets quarter and reviewer coverage, the SOW starts the engagement, the control repository seeds each cycle RCM, checklist rows become assigned tests, monitoring rules run on refreshed data, observations flow into reports and action-taken tracking, and the dashboard pack gives the audit committee status without losing the underlying evidence trail. The auditor confirms or edits every row before it becomes part of the engagement record.
An entity’s internal audit plan can run either engagement type, or both together — a fieldwork engagement for the dated report a board or audit committee expects, and continuous process monitors for the cycles that benefit from being watched every week instead of every quarter.
A control test concludes on the same four-point scale the Guidance Note on Audit of Internal Financial Controls uses, so a rating means the same thing whether an audit committee or a statutory auditor is reading it.
Condition — what was actually found, with the count or sample size. Criteria — the policy, standard or law the condition falls short of. Cause — the root cause, not just “control failed.” Effect — what could go wrong because of it. Recommendation— the specific fix, addressed to a role. From a failed test, CORAA can draft this structure — condition carries the real counts from the test, the rest is a starting point the auditor edits before creating it. Management response, response owner and agreed action date fields keep the observation ready for SIA 390 follow-up and export; closure evidence still needs the firm's follow-up workflow: High → re-audit procedures, Medium → documentary evidence, Low → written management confirmation.
Every figure in the report — controls tested, observations by rating and status, RCM summary by cycle — is a direct count over the engagement’s own RCM rows and observations, not a document assembled separately at the end. A draft view is available at any point; a final report is gated until a draft has actually been issued to the auditee, the way SIA 370 (3.3) expects. An optional AI-drafted narrative can add an executive-summary reading of those same numbers — it’s marked as a draft the auditor reviews before it goes into the issued report, and flagged stale the moment the underlying RCM or observations change.
Internal audit under Section 138 of the Companies Act 2013 is mandatory for a defined set of companies (by paid-up capital, turnover, borrowings, or public deposits — check applicability for the entity in question). Separately, Section 143(3)(i) requires the statutory auditor to opine on the adequacy and operating effectiveness of internal financial controls. A control tested for the Section 138 function can support management readiness and statutory-auditor coordination, but the statutory auditor’s Section 143(3)(i) conclusion still depends on independent evaluation and procedures. CORAA’s RCM engine can carry the additional Guidance Note fields (assertions, key-control flag, IPE reference, test-of-design and test-of-effectiveness results) on the same control row, instead of a second team re-documenting the same control from scratch.