Naitra Services · Internal Audit and Assurance
Audit as a service
Naitra performs a discrete internal audit engagement end to end, from planning through the final report, under the direction of your chief audit executive. Your function keeps ownership of the audit plan, the conclusions, and the report. Naitra performs the work.
This suits a function that has more on its plan than it has hours to deliver, or that needs an area covered where it does not currently hold the skills, most often information technology, cybersecurity, or cloud.
How the engagement runs
- Scoping. Objectives, criteria, in-scope processes and systems, exclusions, timing, and the evidence you can provide. Agreed in writing before work starts.
- Planning. Engagement risk assessment, risk and control matrix, and a work program with test attributes stated per control. Applicable Topical Requirements issued by the Institute of Internal Auditors are assessed and documented during planning.
- Walkthroughs. Sessions with control owners to confirm the process as it actually operates rather than as documented.
- Fieldwork. Testing against the stated attributes, with sample basis and population source recorded for every test.
- Findings. Each finding documents the condition, the criteria, the root cause where it can be established, the potential effect, and the significance. Recommendations and management action plans are documented separately.
- Management response. Findings validated with the control owners, then responses and target dates collected.
- Reporting. Draft report to you, closing meeting, final report issued.
What you receive
- Engagement work program with test attributes
- Risk and control matrix
- Testing workpapers with an evidence index
- Findings register with significance ratings
- Draft and final report
- Management action plan tracker with target dates and owners
Why a chief audit executive uses this
The work is documented to support your function's conformance obligations and the basis for reliance a chief audit executive is required to record when relying on an external assurance provider. Scope, methodology, evidence, review, and conclusions stay visible in the engagement record rather than sitting with the provider.
Independence and objectivity
Naitra does not accept management responsibilities and does not make control decisions. Your function owns the audit plan, the conclusions, and the report.
Where Naitra has previously performed advisory or engineering work in an area, the potential self-review threat is assessed and disclosed in writing at scoping. Naitra performs assurance work only where objectivity can be appropriately safeguarded. Where it cannot, that scope is excluded or the engagement is declined.
Where Naitra built, configured, or operated a specific control or system, that control or system is excluded from Naitra's assurance scope. The exclusion is on the control or system itself, not on the wider area around it.
How the software relationship is handled is set out on the services overview.
Also in Internal Audit and Assurance: Co-sourced internal audit Audit readiness AI and automation for internal audit
Start with a conversation
Scope, timing, and fee are set one company at a time. Send a note describing the work you are considering and you will get a direct reply.
Talk to Naitra