Governance, risk and compliance

SmartSuite for the Audit Director

The Audit Director oversees annual audit planning, resource allocation, methodology and programme execution across multiple engagements. They build risk-based plans tied to enterprise risk, monitor fieldwork and quality checkpoints, and oversee open findings to effective remediation.

What you own

  • Build and maintain the risk-based audit plan and audit universe
  • Allocate audit resources and manage capacity across engagements
  • Maintain the audit methodology and quality checkpoints
  • Monitor fieldwork progress and review cycles
  • Oversee open findings, due dates and remediation effectiveness
  • Provide leadership with continuous assurance dashboards
  • Deputise for the Chief Audit Executive with committees

Where the role sits

Each name opens that role's page.

Reports to

Chief Audit Executive

Chief Audit Executive

See the role

Direct reports

Audit Manager

Audit Manager

See the role
Audit Analyst

Audit Analyst

See the role
Audit Quality Assurance Reviewer

Audit Quality Assurance Reviewer

See the role

Works closely with

Enterprise Risk Director

Enterprise Risk Director

See the role
Compliance Director

Compliance Director

See the role
Head of Internal Controls

Head of Internal Controls

See the role
External Auditor

External Auditor

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

audit

Touches

contributes or approves

issues-actions, reporting, risk

Depends on

consumes its output

compliance

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use SmartSuite

How they use SmartSuite

Audit universe management

Defines and maintains all auditable entities with risk and control relationships.

Issue tracking & remediation

Tracks open findings, action owners, and resolution deadlines.

‍

Continuous assurance

Provides leadership with dashboards highlighting audit progress and recurring issues.

‍

How they use the Internal Audit Management suite

Risk-based planning

Builds dynamic audit plans tied to enterprise risk assessments.

Engagement management

Monitors fieldwork progress, review cycles, and quality checkpoints.

Issue tracking

Oversees open findings, due dates, and remediation effectiveness.

Suites that serve this role

How SmartSuite supports this role

Internal audit. Builds dynamic risk-based audit plans tied to enterprise risk assessments, with an audit universe that holds every auditable entity and its risk and control relationships.

Risk management. Draws on the enterprise risk register for planning so coverage follows risk.

Issues and actions. Tracks open findings, action owners and resolution deadlines with escalation.

Reporting. Provides leadership with dashboards highlighting audit progress and recurring issues.

Industry reference

The IIA's Global Internal Audit Standards (2024) require a risk-based plan, documented methodology, supervision and a quality programme; the director operates those on the chief audit executive's behalf. NYSE rule 303A.07 requires an internal audit function at listed companies.

Sector expectations raise the bar: the Basel Committee's guidance on internal audit in banks and the OCC's heightened standards expect full coverage of material risks on a cycle; GAO's Yellow Book governs government audit functions; the OIG's compliance guidance shapes audit coverage in healthcare; technology companies align audit plans with SOC 2 and ISO 27001 cycles.

In their words

Related roles

Chief Audit Executive

Chief Audit Executive

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.