Audit Management Implementation Flashcards
Audit admin (sn_audit.admin)
Set up the Audit Management application
Coordinate and facilitate configuration requests
Delete engagements, audit tasks, test templates, and test plans
Audit manager (sn_audit.manager)
Create audit plans and engagements, including records necessary to conduct the audit, such as milestones, tasks, and evidence requests
Approve audit tasks, workpapers, and engagements
Track and monitor audit findings
Audit user (sn_audit.user)
Perform fieldwork (walkthroughs, interviews, control testing, etc.)
Document the work and findings
Resolve and/or follow up with audit findings
Create test templates and test plans
Read-only access to Policy and Compliance and Risk Management applications
Engagement project manager (sn_audit_advanced.engagement_project_manager)
Complete advanced planning with audit plans and engagements
Create resource and costs plans and approve time cards
External auditor (sn_audit.external_auditor)
Assigned as auditor for an engagement and audit tasks
Perform audit against specific regulation
View closed engagements and tasks
View published policies, controls, and risks in the Monitor state
GRC business user (sn_grc.business_user)
Leveraged across GRC applications. Audit-specific activities include:
Partner with the auditor on the action plan
Respond to observations and evidence requests
Resolve issues converted from the observation
What is an audit plan?
An audit plan helps to manage different types of audits in a periodic manner and group engagements in a logical manner.
What is an audit engagement?
An audit engagement is an audit project that may include audit tasks that accomplish a set of objectives or goals.
Audit engagements are scoped with auditable units or entities
An entity type called ‘auditable units’ is created for auditable units.
What are the 4 audit tasks?
An engagement’s four types of tasks are: control tests, interviews, walkthroughs, and/or activities
How are audit issues created?
Automatically, if the indicator result is failed or not passed.
Automatically, if the attestation result is not implemented.
Automatically, if the control test effectiveness is Ineffective and the state of the test is closed complete.
Manually to document audit observations, the intention of remediations, or to accept any problems.
Do you recall the conditions which move the audit engagement into the Closed state?
The engagement is closed as incomplete during the Scope, Validate, or Fieldwork states.
Incorrectly unchecked
There are no open audit tasks, observations, or issues after the engagement is approved. In this case, the engagement automatically moves from Awaiting Approval to the Closed state.
Incorrectly unchecked
All of the follow up tasks, observations and issues are closed. In this case, the engagement automatically moves from the Follow Up state to the Closed state.