SmartSuite for the Internal Auditor
The Internal Auditor executes testing procedures, gathers evidence, documents findings and supports fieldwork. They validate that controls operate, log observations with root causes, link findings to risks and process owners, and verify that corrective actions are implemented.
What you own
- Execute test procedures and gather evidence in fieldwork
- Document workpapers and address review notes
- Validate control execution and supporting evidence
- Log observations, root causes and severity assessments
- Link findings to related risks, controls and process owners
- Verify that corrective actions are implemented and effective
Where the role sits
Each name opens that role's page.
Reports to
Direct reports
Works closely with
GRC processes
The shared GRC process map, highlighted for this role.
Owns
accountable for the process
Touches
contributes or approves
Depends on
consumes its output
How SmartSuite helps, suite by suite
Each card is the persona record from that suite's Users tab.
How they use SmartSuite
Fieldwork management
Conducts control testing and captures results directly within SmartSuite.
Evidence tracking
Links findings to uploaded documentation and testing steps for traceability.
Remediation verification
Reviews and validates that corrective actions are implemented and effective.
How they use the Internal Audit Management suite
Workpaper management
Documents procedures, attaches evidence, and addresses review notes.
Linked records
Connects findings to related risks, controls, and process owners.
Issue documentation
Logs observations, captures root causes, and routes findings for management review.
How they use SmartSuite
Test validation
Reviews control execution and supporting evidence
Issue identification
Documents deficiencies and severity assessments
Assurance reporting
Produces audit-ready summaries and findings
How they use the SOX Management suite
Test validation
Reviews control execution and supporting evidence.
Issue identification
Documents deficiencies and severity assessments.
Assurance reporting
Produces audit-ready summaries and findings.
How they use SmartSuite
Suites that serve this role
Products this role uses most
How SmartSuite supports this role
Internal audit. Manages workpapers with evidence attached, review notes and sign-offs, and links findings to related risks, controls and process owners.
Compliance management. Reviews control execution and supporting evidence with full testing history for SOX and compliance testing.
Issues and actions. Logs observations with root causes and routes findings for management response and remediation verification.
Reporting. Produces audit-ready summaries and findings from the testing records.
Industry reference
The IIA's Global Internal Audit Standards (2024) and the CIA body of knowledge define the work: sufficient, reliable evidence; documented workpapers; findings with criteria, condition, cause and effect; and follow-up of management actions. Independence and objectivity requirements apply to every engagement.
What is tested depends on sector: FFIEC-based control areas in banks, HIPAA and billing controls in healthcare, Yellow Book compliance audits in government, and IT general controls and SOC 2 criteria in technology. In each case the auditor's workpapers may be reviewed by regulators or external auditors placing reliance on them.
In their words
Related roles
See SmartSuite for your role
Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.




