Naitra Services · Internal Audit and Assurance

Co-sourced internal audit

An assurance service

Naitra works inside your audit plan as an extension of your team for a defined period, rather than delivering a single engagement. Your chief audit executive directs the work, supervises it, and owns every conclusion. Naitra supplies capacity and specialist skills in information technology and cybersecurity audit.

How the engagement runs

  1. Coverage discussion. Which engagements on your plan Naitra takes, which your team takes, and where the two overlap.
  2. Working agreement. Supervision and review points, your methodology or Naitra's, your workpaper system, and how evidence is exchanged and retained.
  3. Delivery. Naitra executes assigned engagements to your methodology, at your reporting cadence. Applicable Topical Requirements are assessed and documented during planning on each engagement.
  4. Review. Your chief audit executive or designate reviews and signs off in your system of record.
  5. Standing check-in. A recurring session on progress, obstacles, and plan changes.

What you receive

  • Completed engagements delivered to your methodology and templates
  • Workpapers filed in your system of record, not in a system you cannot access later
  • Documented supervision and review trail
  • A reliance pack covering Naitra's role and scope, the methodology applied, the competency of the people who performed the work, the objectivity position including any disclosed threats, the due professional care exercised, and the results

Independence and objectivity

Naitra does not accept management responsibilities and does not make control decisions. Your function owns the audit plan, the conclusions, and the report.

Where Naitra has previously performed advisory or engineering work in an area, the potential self-review threat is assessed and disclosed in writing at scoping. Naitra performs assurance work only where objectivity can be appropriately safeguarded. Where it cannot, that scope is excluded or the engagement is declined.

Where Naitra built, configured, or operated a specific control or system, that control or system is excluded from Naitra's assurance scope. The exclusion is on the control or system itself, not on the wider area around it.

How the software relationship is handled is set out on the services overview.

Also in Internal Audit and Assurance: Audit as a service Audit readiness AI and automation for internal audit

Start with a conversation

Scope, timing, and fee are set one company at a time. Send a note describing the work you are considering and you will get a direct reply.

Talk to Naitra