CORAA
Resources · Audit Data Quality

Source data ready.

Internal audit source data readiness is the evidence gate before analytics, sampling, monitoring rules or dashboards. The audit team should be able to reproduce the report, reconcile it to a control total, test mandatory fields and prove that the population used for testing is complete.

Build PBC listOpen analytics guide
Downloads

Source data readiness workbook workbook

Download the Excel/PDF pack for source report inventory, extraction evidence, control-total reconciliation, field dictionary, join-key quality, exception taxonomy and monitoring readiness.

Readiness gates

What must be proved before testing prove

Source report identified

Name the system, report, query, API, table or export used. A screenshot or forwarded spreadsheet is not enough.

Period and filters locked

Record entity, location, date range, status filters, document types, exclusions and currency so the population can be reproduced.

Control total reconciled

Tie the report to GL, sub-ledger, statutory return, bank statement, payroll register or independent system total before testing.

Row count retained

Capture row count, run date/time, preparer, reviewer and file hash/version so later changes are visible.

Mandatory fields complete

Check transaction date, document number, party, amount, tax fields, approver, user ID, status and source reference.

Join keys tested

Validate vendor ID, customer ID, employee ID, item code, GL code, PO, GRN, invoice, payment and journal keys before analytics joins.

Exception taxonomy agreed

Separate extraction defects, master-data gaps, process exceptions, control failures and reviewer-cleared false positives.

Monitoring readiness decided

Only convert a test into continuous monitoring when fields, thresholds, owner, cadence and false-positive handling are stable.

Source reports

Cycle-wise reports to validate request

P2P

Vendor master, PR/PO register, GRN, invoice register, payment run, MSME ageing, GST/TDS fields and user-access report.

O2C

Customer master, credit limit changes, sales orders, dispatch, invoice register, collections, credit notes and receivables ageing.

R2R

Trial balance, GL dump, journal register, close calendar, reconciliation tracker, provisions, intercompany and user-access report.

H2R

Employee master, attendance, payroll register, statutory returns, deductions, increments, exits, full-and-final and HRMS access.

Inventory

Item master, GRN, issues, transfers, stock ledger, count results, ageing, write-offs, scrap and costing reports.

Treasury

Bank master, mandates, bank statements, BRS, borrowings, covenant tracker, investments, BG/LC and forex exposure reports.

Compliance

GST returns, e-invoice/e-way bill data, TDS/TCS returns, challans, ROC forms, notices, licences and portal access logs.

ITGC

User listing, privileged users, SoD conflicts, change tickets, backup logs, interface jobs, audit logs and report catalogue.

Data tests

Minimum data quality checks quality

Completeness

Does the extracted population include the full period, all entities, all document types and all statuses relevant to the audit objective?

Accuracy

Do key values agree to source totals, sub-ledger balances, statutory returns or independently generated control reports?

Validity

Are dates, document numbers, master codes, amounts, tax fields, approval IDs and status values in expected formats and ranges?

Uniqueness

Are voucher numbers, invoice IDs, employee IDs, item codes or transaction IDs duplicated where they should be unique?

Timeliness

Was the report extracted after the cut-off event, month close, payroll lock, GST filing or management review being tested?

Lineage

Can the auditor trace the field from source system to export, transformation, workbook, exception and final observation?

Failure modes

Common ways audit data breaks avoid

Spreadsheet sent without parameters

The file may be useful for discussion, but it is weak evidence unless period, filters, source and preparer are retained.

ERP report does not tie to GL

The report could exclude cancelled, open, archived, branch, tax or foreign-currency transactions. Reconcile before sampling.

Master data has no owner

Vendor, customer, employee or item fields are incomplete and nobody is accountable for correction.

Analytics run before join keys are tested

False exceptions multiply when IDs are reused, missing, manually edited or inconsistent across reports.

Dashboards use unreviewed metrics

A KPI may look clean while its formula, refresh timing, source fields or exception logic are not audit-ready.

Monitoring rules lack closure logic

Recurring reports become noise unless exceptions have owner, due date, false-positive route and closure evidence.

Authority anchors

Sources to verify before relying on source data cite

IIA Global Internal Audit Standards

Use the Standards as the quality anchor for sufficient, reliable, relevant and useful information, documented work and board communication.

IIA GTAG Understanding and Auditing Big Data

Use the IIA GTAG when big-data risks, source data quality, analytics, automation and dashboards become part of internal audit methodology.

ICAI SIA 320, 330, 350 and 520

For Indian files, connect source-data readiness to internal audit evidence, internal control evaluation, review and supervision, and IT-environment work.

Companies Act Section 138 and Rule 13

For covered Indian companies, source-data readiness supports the approved internal audit scope, functioning, periodicity and methodology.

Product reuse

Website resource now, product data model later later

This public resource can become specification input for the separate Internal Audit product build: data intake, PBC workflow, report reliability, field dictionary, quality engine, monitoring readiness and dashboard lineage.

Source report catalogue

Data intake: System, report name, owner, extraction method, cadence, field list, control total and reliability rating.

Extraction evidence

PBC workflow: Run date/time, filters, row count, preparer, reviewer, file version, hash and storage link.

Field dictionary

Data model: Canonical field, source field, data type, mandatory flag, join key, validation rule and transformation note.

Reconciliation log

Quality engine: Source total, independent total, variance, reason, owner, reviewer and sign-off.

Exception taxonomy

Issue workflow: Data defect, process exception, control failure, false positive, accepted risk and remediation route.

Monitoring readiness

Continuous audit: Rule ID, stable fields, threshold, owner, cadence, false-positive rate, closure evidence and dashboard flag.

Related resources

Use source readiness before fieldwork and monitoring next

Internal Audit Data Request List

Request the source reports, owners, due dates and purpose before readiness testing starts.

Internal Audit Process Mining & Analytics

Use readiness tests before relying on event logs, process variants or exception analytics.

Continuous Monitoring Rules Repository

Convert stable source reports into recurring monitoring rules only after readiness gates pass.

Internal Audit Sampling Plan Generator

Lock population completeness before selecting samples or concluding on deviations.

Internal Audit Fieldwork Testing Tracker

Track testing status, evidence blockers, exceptions and reviewer sign-off after source data is accepted.

Internal Audit Dashboard KPIs

Route reliable source fields into dashboard metrics, committee packs and monitoring dashboards.

FAQs

Source data readiness questions answered

What is source data readiness in internal audit?

Source data readiness means the audit team has confirmed the source report, period, filters, row count, control-total reconciliation, mandatory fields and join keys before relying on the data for testing, analytics or reporting.

Is an ERP export automatically reliable audit evidence?

No. An ERP export still needs report parameters, extraction evidence, row count, control-total reconciliation, access/change context and reviewer acceptance before internal audit relies on it.

Why does population completeness matter before sampling?

A sample is only meaningful if the population is complete. If the source report excludes branches, cancelled items, open transactions, old periods or specific document types, the sample conclusion can be misleading.

When is a source report ready for continuous monitoring?

A report is ready for monitoring when the field definitions, extraction cadence, thresholds, owner, exception taxonomy, false-positive route and closure evidence are stable enough to run repeatedly.