Information for internal audit

Trace the evidence you need for your audit.

Internal audit needs insight into the functions actually used, responsibilities and documented activities. T-NEX presents information about the relevant application in a traceable way. Your independent audit remains your responsibility.

From information to decisions
DataContextResponsibility
  1. 01Preserve independence during implementation
  2. 02Assess function, configuration and operation separately
  3. 03Read access for internal audit

Assessment and responsibility remain with your team.

In daily work

Preserve independence during implementation

For heads of internal audit, internal auditors and IT audit functions in banks.

Section 25a KWG establishes independent internal audit. An implementation project therefore records who owns business decisions, who implements them and who subsequently provides independent assurance. Auditability requirements can be described early without assigning operational approvals to internal audit.

FunctionProject taskSubject of review
Business teamOwn requirements and business acceptanceDefined target state and documented acceptance
IT and operationsImplement configuration, access and changesOperating scope, permissions and changes
Internal auditDetermine audit scope and independent assessmentAdequacy and effectiveness of the processes reviewed
Overview

Assess function, configuration and operation separately

An audit considers the version actually in use, enabled modules, roles and project-specific extensions. These are compared with the agreed functions and required evidence.

The technical overview supports your review with functions from Controlling, Compliance, PPM and Fraud Detection. Contract scope and operational services are tied to the specific engagement.

Overview

Read access for internal audit

Fraud Detection provides read access for internal audit: dashboards, case lists and case files including triage, evidence and the audit trail. Editing, rule maintenance and administration have separate permissions.

Action, time, user and reason provide concrete points to check in the log. Acceptance testing checks effective permissions, log protection and access paths in your installation.

Overview

Trace a sample through the complete process

A case containing at least one change and one business decision is useful for a functional review. The following points suggest how to prepare a sample; they are not a regulatory audit standard.

  • Identify input data, the business requirement and the version used.
  • Compare participating roles with their effective permissions.
  • Trace a change, approval or case decision to its supporting evidence.
  • For AI support, consider input scope, suggestion, human decision and reasons for any deviation.
  • Test read access and required exports against the intended audit scope.
Overview

Interpret project information by what it demonstrates

The PPM documentation describes planning states, resource requests and status reports. Such information can be relevant to an implementation audit. The documents needed depend on the audit objective and the institution’s project records.

A status report or planning baseline evidences a particular matter. It does not establish the completeness of all project evidence or regulatory compliance.

FAQ

Frequently asked questions

Does a product manual establish that a control is effective?

It describes functions at a particular version. Control effectiveness must be assessed against the design, actual application and selected audit scope.

Does read access work identically in every application?

No. This example applies to Fraud Detection. Effective permissions are configured and checked for each application, installation and role.

Does a demonstration replace reviewing the deployed installation?

A demonstration can explain a workflow. The deployed version and its supporting evidence are what matter for the audit.

Must a PPM system be introduced for internal audit?

The functions described here do not imply a requirement to purchase PPM software. Internal audit determines the project information needed for its engagement.

Related options

You may also be interested in these.

T-NEX Fraud Detection: Filter the overview

Fraud Detection

Review transactions, group alerts and investigate cases. T-NEX Fraud Detection connects rules, AI triage, supporting transactions and a traceable audit trail.

Learn more
A5Hub · project reference: Review the portfolio

Project portfolio management

PPM for financial institutions: connect projects, line capacity, resource approvals and baselines, with traceable changes and AI proposals for work breakdown structures.

Learn more