Annual Audit Plan
Plan & archive, by year
Annual Audit Plan
Quarterly calendar — parent departments expand to show sub-units
مرتفع جداً
مرتفع
متوسط
منخفض
| Quarter | Code | Parent department | Sub-unit | Risk classification | Duration (W) | Team in-charge | Status |
|---|
—
Click a row for the audit program · Click a status badge to advance
Audit Universe
The master list of every auditable entity (Department → Sub-Department → Process). The Risk Register & Annual Plan templates read their dropdowns from here.
✦
Knowledge Center
Ask a question — or search your standards & documents
Cited answers grounded in your standards, methodology & prior findings — plus a free search of the library.
AI answers are turned off in Settings ▸ AI usage — showing free library matches only.
Library registry
Manage indexed standards · upload missing PDFs
CAE-only. Each standard is a separate corpus indexed into ChromaDB.
Audit Assistant
Ask anything — grounded in your standards, methodology & prior findings
Loading knowledge base…
The Audit Assistant is turned off in Settings ▸ AI usage. Ask the CAE to enable it.
Knowledge base
Your private corpus — methodology & precedent
Stays local. Indexing runs offline; only a question sends short retrieved passages to the model.
Loading…
Search in:
Inbox
Auditee submissions awaiting your review
Reminder engine
Deadline emails fire at 14 days before · 3 days before · on the due date · 3 days overdue · 14 days overdue — sent to the assignee on each tracker row
Aging · days past due
By rating × status
| Tracker ID | Engagement | Title | Rating | Owner | Status | Due | Actions |
|---|
—
Click a row to view finding details →
Annual Planner · Risk-Assessment Hub
Build or import your annual audit plan
Two ways in — both with no AI. Build a plan from your risk register (the deterministic engine computes man-days, frequency, team mix and plan-year from your saved logic settings), or import an annual plan you already have — captured exactly as you entered it, no re-scoring.
Risk-assessment interviews
Pick an existing run to continue, or start a fresh session against a planned engagement.
Loading sessions…
Existing session
Or new session
"Plan session" runs the Session Planner: builds a tailored questionnaire for the engagement (must-ask + conditional + open-floor + strategy-derived), then you can start a run against it.
Voice mode is on. Press Play to hear the question, then the mic button to answer.
Submit with Ctrl+↵
Interview complete.
Run synthesis to generate the structured transcript and the risk register from the auditee's answers.
Path A — Use the Audics Audit-Planning Template
Download the template (EN or AR), fill in your audit universe, risks, and engagement
assessment, then upload it here. Sheet names, columns, and formulas are fixed —
the engine reads it deterministically so your outputs match your manual numbers
exactly. Auto-computed cells are locked; only input cells (white) are editable.
Audics Audit-Planning Template
7 sheets · dropdowns · auto-formulas · color-coded bands · sample row · locked computed cells
Drag & drop your filled-in Audics template, or click below to browse
Only Audics templates are accepted · max 25 MB
Import your existing Annual Plan
For clients who already have an approved annual plan. The template has two sheets:
fill the Audit Universe sheet (departments, sub-departments,
processes), then on the Annual Plan sheet pick each engagement's
Department / Process from dropdowns that read the Universe sheet. On import, your
Audit Universe module is built and each row becomes a scheduled
engagement in the Annual Plan & Engagements
— captured as-is, with no AI and no re-scoring. Blank fields show as "Not rated".
Before you start: add your audit team in Settings → Audit Team. The template's Team in Charge columns (Manager/Lead + up to 3 members) are dropdowns of that team, and everyone you pick is auto-assigned as the engagement's Team In-Charge on import.
Step 1 · Annual-Plan import template
Two sheets — Audit Universe (Department / Sub-Department / Process) + Annual Plan (Risk Rating, Priority, Complexity, Frequency, Quarter, Status) · dropdown-validated · locked
Step 2 · Upload your filled Annual-Plan template to preview the engagements before importing
Only Audics Annual-Plan templates are accepted · max 25 MB
Path B — Hybrid: list risks, let AI propose scores
Add the processes/risks you know about. Click "AI propose scores" to fill in residual/priority/complexity/volume. Every score comes with a verbatim citation you can verify.
| Process / activity | Department | Subsidiary | Narrative (optional) | Resid. | Prior. | Cmplx. | Vol. | AI citation |
|---|
Plan Results
Tabs control everything below — KPIs, manpower, and engagement list all switch to the selected year.
Year-by-year comparison
Engagements
Click any engagement row to expand its detail
| # | Engagement | Risk Classification | Team | Schedule (Year) |
|---|
Review the plan above, then choose:
Risk-Assessment Logic Settings
Loading…
Sector preset
Loads sensible defaults for the sector — you can still tweak below.
Annual man-days per auditor
Computed: — days/auditor/year
Composite-score weights (must sum to ≈ 1.00)
Team structure
Excel rule: 1 senior + 1 specialist (or 2 if band = Very High OR complexity = High) + 30% manager. No juniors.
Risk-band thresholds (residual score boundaries)
Audit frequency by band (months between audits)
Engagement duration mapping
Duration maps linearly to 2 → 8 weeks.
When the Active Cluster is set, composite range is 1.0 → 3.5.
When unset, the cluster contribution is dropped and weights renormalise to
0.625 / 0.375 — composite ceiling becomes 3.625.
عرض النص بالعربية
Download template
Choose how the logic settings should be baked into the template's formulas.
Module 3 · Root Cause Analysis
Find systemic issues hiding across engagements
The agent reads every finding produced this period, clusters them into themes, hypothesises root causes that span subsidiaries, and emits organisation-level recommendations the CAE takes to the Audit Committee.
Kingdom-wide observations 2025 · auto-classified · RCA
Loading…
Executive summary
Module 4 · Predictive Analytics
Forecast next-period risk areas
A transparent three-layer signal-fusion engine. It fuses Assurance, Operational and Environmental risk signals, scores each auditable entity for next-period risk, and proposes concrete plan changes — every output traceable to a real source record.
Data analytics & testing
AI‑driven data analytics on your audit data
Run AI testing on an approved RCM's control tests, or on any data/evidence outside the RCM. Upload Excel, Word, PDF or an image — the engine reads it and reports findings you can push back into the RCM.
Combined Assurance
Coverage of the audit universe across the three lines of defence
What the coverage levels mean & how Audics scores them — click to expand
Full Coverage
Design and operating effectiveness have been tested, the effectiveness test is still current, and it is documented. Strongest assurance.
Partial Coverage
Some assurance exists but not enough to be Full — e.g. design only (no effectiveness), the effectiveness test is overdue, or it is self-reported / estimated rather than documented.
Gap (No Coverage)
No provider tests this process to at least design depth, or a High / Very-High risk process has no effectiveness testing, or the most recent coverage is more than 3 years old. Escalate / add to the plan.
Duplication
Two or more providers test the same depth in the same year — an overlap that may let Internal Audit free up capacity. (External auditor + IA on the same financial controls is allowed.)
How the score is computed — what each field does
- Test depth. Effectiveness (sample-tested) outranks design (walkthrough) outranks existence (on paper). Only effectiveness can earn Full Coverage.
- Recency (Last test date). Very-High / High processes must be covered within 12 months, Medium within 24, Low within 36. A hard floor applies to all: anything older than 3 years counts as no coverage.
- Frequency. Coverage overdue versus its own stated cadence drops a tier — e.g. an annual control last tested 18 months ago is treated as overdue. Continuous / ad-hoc add no extra cadence penalty.
- Confidence. Only documented effectiveness can reach Full Coverage. Self-reported or estimated coverage caps the process at Partial.
- Scope summary. Describes what was tested — context for reviewers; it does not change the numeric verdict.
- No coverage (N/C). A provider can explicitly mark a process as does not cover (Test depth = "No coverage"); the other fields are then disabled. This is distinct from a blank cell, which just means "not recorded yet."
- Combined Assurance Score. The share of High & Very-High risk processes that have Full Coverage.
Audit Committee Pack
Generate the board-ready quarterly pack — DOCX + PPTX
One click pulls every section from the live data — engagements, findings, RCA themes, predictive flags, closure validations, top risks, KPIs.
Pick your reporting period and which sections to include, then generate.
1 · Reporting period
2 · Sections to include
·
Loading sections…
3 · Formats
4 · CAE narrative (optional)
Generated packs
Loading…