Governance, risk and compliance

SmartSuite for the Audit Manager

The Audit Manager leads individual engagements: scoping, planning, oversight of fieldwork, review of workpapers and timely reporting. They define objectives, risks and controls with standard templates, track testing completion and sign-offs, and coordinate with process owners on findings.

Audit Manager

Reports to:

What you own

  • Scope and plan engagements with objectives, risks and controls
  • Supervise fieldwork and review workpapers
  • Manage engagement schedules, assignments and review notes
  • Draft audit reports and agree findings with management
  • Follow up management actions to closure
  • Coach auditors and maintain engagement quality

Where the role sits

Each name opens that role's page.

Reports to

Audit Director

Audit Director

See the role

Direct reports

Internal Auditor

Internal Auditor

See the role

Works closely with

Control Owner

Control Owner

See the role
Risk Manager

Risk Manager

See the role
Compliance Manager

Compliance Manager

See the role
Audit Quality Assurance Reviewer

Audit Quality Assurance Reviewer

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

audit

Touches

contributes or approves

issues-actions, risk, reporting

Depends on

consumes its output

compliance

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use the Enterprise Risk Management suite

Control testing

Reviews and tests controls linked to enterprise risks.

Findings documentation

Records audit observations tied to specific risks.

Assurance coordination

Aligns audit results with ERM reporting and remediation efforts.

How they use the Internal Audit Management suite

Planning & scoping

Defines objectives, risks, and controls using standardized templates.

Workflow automation

Automates task assignments, review reminders, and follow-up requests.

Progress monitoring

Tracks testing completion, review notes, and sign-offs in real time.

How they use SmartSuite

Suites that serve this role

How SmartSuite supports this role

Internal audit. Defines objectives, risks and controls with standardised planning templates and tracks testing completion, review notes and sign-offs in real time.

Risk management. Reviews and tests controls linked to enterprise risks and records observations tied to specific risks.

Issues and actions. Automates task assignments, review reminders and follow-up requests to management.

Reporting. Produces engagement reports and status views from the workpapers.

Industry reference

The IIA's Global Internal Audit Standards (2024) set engagement requirements: objectives and scope tied to risk, a work programme, supervised fieldwork, evidenced conclusions and findings agreed with management. Workpapers must support every conclusion and be reviewed before the report is issued.

Sector regimes shape the engagements. Bank audits are read by examiners under FFIEC and Basel expectations; healthcare audits cover billing, HIPAA and clinical compliance; government audits may need to meet GAO's Yellow Book; technology audits often test the ITGCs and SOC 2 controls that external assessors rely on.

In their words

Related roles

Audit Director

Audit Director

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.