Internal audit source data readiness is the evidence gate before analytics, sampling, monitoring rules or dashboards. The audit team should be able to reproduce the report, reconcile it to a control total, test mandatory fields and prove that the population used for testing is complete.
Download the Excel/PDF pack for source report inventory, extraction evidence, control-total reconciliation, field dictionary, join-key quality, exception taxonomy and monitoring readiness.
Name the system, report, query, API, table or export used. A screenshot or forwarded spreadsheet is not enough.
Record entity, location, date range, status filters, document types, exclusions and currency so the population can be reproduced.
Tie the report to GL, sub-ledger, statutory return, bank statement, payroll register or independent system total before testing.
Capture row count, run date/time, preparer, reviewer and file hash/version so later changes are visible.
Check transaction date, document number, party, amount, tax fields, approver, user ID, status and source reference.
Validate vendor ID, customer ID, employee ID, item code, GL code, PO, GRN, invoice, payment and journal keys before analytics joins.
Separate extraction defects, master-data gaps, process exceptions, control failures and reviewer-cleared false positives.
Only convert a test into continuous monitoring when fields, thresholds, owner, cadence and false-positive handling are stable.
Vendor master, PR/PO register, GRN, invoice register, payment run, MSME ageing, GST/TDS fields and user-access report.
Customer master, credit limit changes, sales orders, dispatch, invoice register, collections, credit notes and receivables ageing.
Trial balance, GL dump, journal register, close calendar, reconciliation tracker, provisions, intercompany and user-access report.
Employee master, attendance, payroll register, statutory returns, deductions, increments, exits, full-and-final and HRMS access.
Item master, GRN, issues, transfers, stock ledger, count results, ageing, write-offs, scrap and costing reports.
Bank master, mandates, bank statements, BRS, borrowings, covenant tracker, investments, BG/LC and forex exposure reports.
GST returns, e-invoice/e-way bill data, TDS/TCS returns, challans, ROC forms, notices, licences and portal access logs.
User listing, privileged users, SoD conflicts, change tickets, backup logs, interface jobs, audit logs and report catalogue.
Does the extracted population include the full period, all entities, all document types and all statuses relevant to the audit objective?
Do key values agree to source totals, sub-ledger balances, statutory returns or independently generated control reports?
Are dates, document numbers, master codes, amounts, tax fields, approval IDs and status values in expected formats and ranges?
Are voucher numbers, invoice IDs, employee IDs, item codes or transaction IDs duplicated where they should be unique?
Was the report extracted after the cut-off event, month close, payroll lock, GST filing or management review being tested?
Can the auditor trace the field from source system to export, transformation, workbook, exception and final observation?
The file may be useful for discussion, but it is weak evidence unless period, filters, source and preparer are retained.
The report could exclude cancelled, open, archived, branch, tax or foreign-currency transactions. Reconcile before sampling.
Vendor, customer, employee or item fields are incomplete and nobody is accountable for correction.
False exceptions multiply when IDs are reused, missing, manually edited or inconsistent across reports.
A KPI may look clean while its formula, refresh timing, source fields or exception logic are not audit-ready.
Recurring reports become noise unless exceptions have owner, due date, false-positive route and closure evidence.
This public resource can become specification input for the separate Internal Audit product build: data intake, PBC workflow, report reliability, field dictionary, quality engine, monitoring readiness and dashboard lineage.
Data intake: System, report name, owner, extraction method, cadence, field list, control total and reliability rating.
PBC workflow: Run date/time, filters, row count, preparer, reviewer, file version, hash and storage link.
Data model: Canonical field, source field, data type, mandatory flag, join key, validation rule and transformation note.
Quality engine: Source total, independent total, variance, reason, owner, reviewer and sign-off.
Issue workflow: Data defect, process exception, control failure, false positive, accepted risk and remediation route.
Continuous audit: Rule ID, stable fields, threshold, owner, cadence, false-positive rate, closure evidence and dashboard flag.
Source data readiness means the audit team has confirmed the source report, period, filters, row count, control-total reconciliation, mandatory fields and join keys before relying on the data for testing, analytics or reporting.
No. An ERP export still needs report parameters, extraction evidence, row count, control-total reconciliation, access/change context and reviewer acceptance before internal audit relies on it.
A sample is only meaningful if the population is complete. If the source report excludes branches, cancelled items, open transactions, old periods or specific document types, the sample conclusion can be misleading.
A report is ready for monitoring when the field definitions, extraction cadence, thresholds, owner, exception taxonomy, false-positive route and closure evidence are stable enough to run repeatedly.