Governance, risk and compliance

SmartSuite for the Internal Auditor

The Internal Auditor executes testing procedures, gathers evidence, documents findings and supports fieldwork. They validate that controls operate, log observations with root causes, link findings to risks and process owners, and verify that corrective actions are implemented.

Internal Auditor

Reports to:

What you own

  • Execute test procedures and gather evidence in fieldwork
  • Document workpapers and address review notes
  • Validate control execution and supporting evidence
  • Log observations, root causes and severity assessments
  • Link findings to related risks, controls and process owners
  • Verify that corrective actions are implemented and effective

Where the role sits

Each name opens that role's page.

Reports to

Audit Manager

Audit Manager

See the role

Direct reports

Works closely with

Control Owner

Control Owner

See the role
Compliance Analyst

Compliance Analyst

See the role
Risk Analyst

Risk Analyst

See the role
Controls Testing Lead

Controls Testing Lead

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

Touches

contributes or approves

audit, compliance, issues-actions

Depends on

consumes its output

risk, policy

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use SmartSuite

Fieldwork management

Conducts control testing and captures results directly within SmartSuite.

‍

Evidence tracking

Links findings to uploaded documentation and testing steps for traceability.

‍

‍

Remediation verification

Reviews and validates that corrective actions are implemented and effective.

‍

How they use the Internal Audit Management suite

Workpaper management

Documents procedures, attaches evidence, and addresses review notes.

Linked records

Connects findings to related risks, controls, and process owners.

Issue documentation

Logs observations, captures root causes, and routes findings for management review.

How they use SmartSuite

Test validation‍

Reviews control execution and supporting evidence

‍

Issue identification‍

Documents deficiencies and severity assessments

‍

Assurance reporting

Produces audit-ready summaries and findings

‍

How they use the SOX Management suite

Test validation

Reviews control execution and supporting evidence.

Issue identification

Documents deficiencies and severity assessments.

Assurance reporting

Produces audit-ready summaries and findings.

How they use SmartSuite

Suites that serve this role

How SmartSuite supports this role

Internal audit. Manages workpapers with evidence attached, review notes and sign-offs, and links findings to related risks, controls and process owners.

Compliance management. Reviews control execution and supporting evidence with full testing history for SOX and compliance testing.

Issues and actions. Logs observations with root causes and routes findings for management response and remediation verification.

Reporting. Produces audit-ready summaries and findings from the testing records.

Industry reference

The IIA's Global Internal Audit Standards (2024) and the CIA body of knowledge define the work: sufficient, reliable evidence; documented workpapers; findings with criteria, condition, cause and effect; and follow-up of management actions. Independence and objectivity requirements apply to every engagement.

What is tested depends on sector: FFIEC-based control areas in banks, HIPAA and billing controls in healthcare, Yellow Book compliance audits in government, and IT general controls and SOC 2 criteria in technology. In each case the auditor's workpapers may be reviewed by regulators or external auditors placing reliance on them.

In their words

Related roles

Audit Manager

Audit Manager

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.