Platform
Audit & Controls

Audit Management

Plan, conduct and track audits with findings driven to closure

Run the whole internal-audit lifecycle — risk-based planning, fieldwork, findings and follow-up — on one platform where audits draw on the same risks and controls the rest of the organisation manages, and every finding is tracked to closure rather than filed in a report. Internal audit is the third line of defence, but too often it runs on standalone spreadsheets disconnected from the risk and control universe it is meant to assure. OnyxOne Audit Management gives audit a home that is wired into the enterprise: plans built from real risk, fieldwork evidenced as it happens, findings linked to the controls they concern, and remediation followed through with the same rigour the audit demanded.

At a glance

How it works, visually

Controls, policies & risksSchematic
POLICIESAML policyData protectionSanctions policyCode of conductCONTROLSKYC checksScreeningAccess controlTransaction monitoringApprovalsRISKSFinancial crimeRegulatory breachData lossReputational harmPolicies map to controls; controls mitigate risks — traceable both ways for audit.

How policies map to controls and controls mitigate risks — traceable both ways for audit.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Audit runs on standalone spreadsheets

Plans, workpapers, findings and tracking live in disconnected files and inboxes. There is no single system of record, version control is manual, and knowledge walks out the door with whoever owned the spreadsheet. The function that assures everyone else is the least systematised in the building.

The plan is disconnected from real risk

The annual audit plan is built from last year's plan and professional judgement, with no live link to the enterprise risk register or control universe. Audit effort is not demonstrably steered by where risk actually concentrates, and coverage gaps are hard to see until they matter.

Findings die in the report

An audit produces findings and recommendations, the report is issued, and then follow-up depends on whoever remembers to chase. Management agrees actions that are never delivered, the same issue recurs next cycle, and audit spends its time re-finding problems it already raised.

The same issue is worked in three places

An audit finding, a risk-register entry and a control weakness often describe the same underlying problem, but they sit in separate systems with no link. The organisation works the issue three times, and the true exposure is understated because nobody connects them.

Evidence is rebuilt at review time

When audit quality is reviewed — internally or by an external assessor — the evidence of how conclusions were reached has to be reassembled from scattered workpapers. The trail exists, but not as a single, timestamped record of who did what and when.

The approach

How OnyxOne addresses it

One system of record for the audit lifecycle

Planning, fieldwork, findings and follow-up run on one platform with versioned workpapers, defined workflow and clear ownership. Audit stops depending on personal spreadsheets and gains a durable record of every engagement that survives staff turnover and stands up to quality review.

Risk-based planning wired to the enterprise

The audit universe and plan draw on the same risks and controls the organisation already manages, so effort is demonstrably steered by where risk concentrates. Coverage across the universe is visible, gaps are surfaced, and the plan can be defended as genuinely risk-based rather than habitual.

Findings linked to risks and controls

Every finding is linked to the control it concerns and the risk it affects, so an issue is worked once and its true impact is visible. Audit, risk and controls describe the same weakness in one connected picture rather than three disconnected ones.

Findings driven to closure, not filed

Agreed management actions are owned, dated and tracked through a defined follow-up workflow with reminders and escalation. Audit can see at any moment what is open, overdue and closed, so recommendations translate into change instead of dissolving after the report is issued.

Evidence captured as the work is done

Workpapers, testing and conclusions are captured against the engagement as fieldwork happens, on an immutable trail. Quality review and external assessment become a matter of retrieving the record rather than reconstructing how the audit reached its opinion.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Audit universe & risk-based planning

Maintain the auditable universe and build the plan from the enterprise risks and controls, with coverage visible across it.

Engagement management

Run each audit end to end — scope, schedule, resourcing, fieldwork and reporting — on a defined workflow.

Working papers

Capture testing, evidence and conclusions in versioned workpapers linked to the engagement and its scope.

Findings & recommendations

Raise findings with rating, root cause and recommendation, linked to the controls and risks they concern.

Management-action tracking

Assign agreed actions to owners with due dates and drive them to closure through follow-up workflow.

Follow-up & re-testing

Verify that remediation actually worked through structured follow-up and re-testing before closing a finding.

Risk & control linkage

Connect engagements and findings to the enterprise risk register and control framework so issues are worked once.

Quality assurance

Support review sign-off, workpaper review and quality-assessment evidence for the audit function itself.

Audit committee reporting

Assemble committee packs — plan progress, findings and action status — from live engagement data.

Immutable audit trail

Every plan change, workpaper, finding, action and sign-off is written to an append-only record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Plan & coverage view

The audit plan against the auditable universe, showing coverage, progress and gaps across the year at a glance.

Engagement tracker

Every live audit by stage, owner and status, with milestones and slippage surfaced for the head of audit.

Findings register

All findings by rating, theme and root cause, with linkage to the controls and risks they concern.

Action-status board

Agreed management actions by owner and due date — open, overdue and closed — driven to closure with follow-up.

Committee dashboard

Plan progress, findings and action status assembled from live data, ready for the audit committee.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Plan-to-universe coverage checks

Coverage of the auditable universe is calculated from the plan automatically, so gaps and over-audited areas are surfaced without manual tallying.

Action reminders & escalation

Agreed management actions are reminded before they fall due and escalated when they slip past their target date.

Re-test scheduling

Closing a finding schedules the follow-up or re-test needed to verify remediation, so closure is evidenced rather than asserted.

Control-failure to audit signal

A control that repeatedly fails testing can automatically flag the related area for consideration in the audit plan.

Committee-pack assembly

Plan progress, findings and action status are compiled from live engagement data on a schedule ready for committee review.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Risk-based scoping assistance

Suggests areas and controls to include in an engagement's scope from linked risk and prior findings, which the auditor reviews and decides.

Finding drafting

Drafts a finding's condition, cause and recommendation from captured workpaper evidence, leaving the auditor to challenge, edit and own it.

Thematic analysis

Highlights recurring themes and root causes across findings that may point to a systemic issue, prompting the auditor to investigate rather than concluding alone.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Plan on riskThe audit universe and annual plan are built from the enterprise risks and controls,so effort is directed where risk concentrates and coverage is visible.02Scope the engagementEach audit is scoped, scheduled and resourced, with objectives and the controls inscope defined up front.03Perform fieldworkTesting is carried out and evidence and conclusions are captured in versionedworkpapers against the engagement.04Raise findingsFindings are recorded with rating, root cause and recommendation, linked to thecontrols and risks they concern, and agreed with management.05Track to closureAgreed management actions are owned, dated and tracked, with follow-up andre-testing to verify remediation before a finding is closed.06Report & assurePlan progress, findings and action status are reported to the audit committee fromlive data, with a full trail behind every conclusion.

Every result, decision and override is captured against the record it belongs to.

01

Plan on risk

The audit universe and annual plan are built from the enterprise risks and controls, so effort is directed where risk concentrates and coverage is visible.

02

Scope the engagement

Each audit is scoped, scheduled and resourced, with objectives and the controls in scope defined up front.

03

Perform fieldwork

Testing is carried out and evidence and conclusions are captured in versioned workpapers against the engagement.

04

Raise findings

Findings are recorded with rating, root cause and recommendation, linked to the controls and risks they concern, and agreed with management.

05

Track to closure

Agreed management actions are owned, dated and tracked, with follow-up and re-testing to verify remediation before a finding is closed.

06

Report & assure

Plan progress, findings and action status are reported to the audit committee from live data, with a full trail behind every conclusion.

The value

What your team gains

Unified

Audit on one system of record

Planning, fieldwork, findings and follow-up on one platform replace standalone spreadsheets with a durable record that survives turnover and review.

Risk-based

A plan you can defend

Building the plan from the enterprise risk and control universe means audit effort is demonstrably steered by risk, with coverage and gaps visible.

Connected

One issue, worked once

Findings linked to risks and controls mean the same weakness is not managed three times, and its true impact is visible across the organisation.

Closed

Findings that lead to change

Owned, tracked actions with follow-up and re-testing turn recommendations into delivered remediation instead of items filed in a report.

Quality review without the scramble

Evidence captured as fieldwork happens means quality assessment and external review are retrieval, not reconstruction.

Committee reporting from live data

Plan progress and action status assembled from the live record give the audit committee a current, reconcilable picture rather than a stale slide.

Built for

Industries it serves

BankingFinancial ServicesInsuranceInvestment FirmsFintechHealthcareManufacturingPublic SectorRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Enterprise & operational risk
  • Builds the audit universe and plan from the enterprise and operational risk registers through the shared taxonomy
Internal controls
  • Links engagements and findings to the internal-controls framework so audit and control assurance describe one picture
Evidence & workpapers
  • Draws on the evidence-management module so testing evidence is captured once and reused across engagements
Issue & action tracking
  • Feeds agreed actions into the platform's action and remediation tracking so follow-up is enforced consistently
Collaboration & notification
  • Routes fieldwork tasks, action reminders and committee reporting through your existing email and messaging tools
Assurance

Security, compliance & reporting

Security & data handling

  • Audit plans, workpapers, findings and action records are encrypted in transit and at rest, with access governed by granular, role-based permissions.
  • Audit independence is protected — access to draft findings and workpapers can be restricted to the audit function until they are issued.
  • Segregation of duties keeps preparation and review separate, so a workpaper cannot be self-reviewed where policy requires independence.
  • Every plan change, workpaper, finding, action and sign-off is written to an append-only audit trail.
  • Data residency and retention for audit records are configurable to your regulatory and internal-policy obligations.

Compliance support

  • Supports an internal-audit function aligned to recognised professional standards such as the IIA International Professional Practices Framework
  • Underpins the third line within a three-lines-of-defence model
  • Provides risk-based planning, working-paper and follow-up evidence expected by audit committees and external assessors
  • Supports quality-assurance and improvement-programme evidence for the audit function itself
  • Supplies documented, dated engagement evidence for regulatory examination where internal audit is in scope
  • OnyxOne is a technology vendor — responsibility for audit conclusions and opinions remains with your audit function

Reports & exports

  • Annual audit plan and coverage-of-universe reports
  • Engagement status and progress reports
  • Findings register by rating, theme and root cause
  • Management-action status — open, overdue, closed — and ageing reports
  • Follow-up and re-testing outcome reports
  • Audit committee packs assembled from live engagement data
Best practice

How to get the most from it

Build the plan from live risk

Anchor the audit universe and plan to the enterprise risk and control registers rather than last year's plan. A plan that traces to real risk is both more useful and far easier to defend to the committee.

Link every finding to a control

Tie findings to the controls and risks they concern. It is what stops the same weakness being worked three times and makes the true impact of a finding visible.

Close the loop with re-testing

Do not close a finding on a management assertion alone — verify through follow-up and re-testing that the remediation actually worked. An action marked done is not the same as a risk resolved.

Capture evidence as you go

Record workpapers and conclusions as fieldwork happens, not at report-writing time. Contemporaneous evidence is stronger, and it turns quality review into retrieval rather than reconstruction.

FAQ

Questions, answered

Does OnyxOne support risk-based audit planning?

Yes. The audit universe and annual plan are built from the same enterprise and operational risks and controls the rest of the organisation manages, so audit effort is demonstrably directed to where risk concentrates, coverage across the universe is visible, and the plan can be defended as genuinely risk-based.

How are findings tracked to closure?

Each finding carries a rating, root cause and agreed management action with an owner and due date. Actions are driven through a follow-up workflow with reminders and escalation, and findings are closed only after follow-up or re-testing verifies the remediation worked — so recommendations lead to change rather than being filed.

How does audit connect to the rest of the platform?

Engagements and findings link to the enterprise risk register and the internal-controls framework, and agreed actions feed the platform's remediation tracking. The same weakness described by an audit finding, a risk entry and a control gap is connected into one picture and worked once.

Does OnyxOne protect audit independence?

Yes. Access to draft findings and workpapers can be restricted to the audit function until they are issued, and segregation of duties keeps preparation and review separate. The platform supports audit's independence rather than exposing work in progress to the areas being audited.

Does OnyxOne form the audit opinion?

No. OnyxOne is a technology vendor that gives the audit function its system of record and workflow. Auditors plan, test, conclude and sign off; responsibility for audit findings and opinions remains entirely with your audit function.

See Audit Management in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.