Technical evidence
Functions, manual versions and assessment cases for T-NEX Controlling, Compliance, PPM and Fraud Detection, with an editable procurement overview.
Learn moreInternal audit needs insight into the functions actually used, responsibilities and documented activities. T-NEX presents information about the relevant application in a traceable way. Your independent audit remains your responsibility.
Assessment and responsibility remain with your team.
For heads of internal audit, internal auditors and IT audit functions in banks.
Section 25a KWG establishes independent internal audit. An implementation project therefore records who owns business decisions, who implements them and who subsequently provides independent assurance. Auditability requirements can be described early without assigning operational approvals to internal audit.
| Function | Project task | Subject of review |
|---|---|---|
| Business team | Own requirements and business acceptance | Defined target state and documented acceptance |
| IT and operations | Implement configuration, access and changes | Operating scope, permissions and changes |
| Internal audit | Determine audit scope and independent assessment | Adequacy and effectiveness of the processes reviewed |
An audit considers the version actually in use, enabled modules, roles and project-specific extensions. These are compared with the agreed functions and required evidence.
The technical overview supports your review with functions from Controlling, Compliance, PPM and Fraud Detection. Contract scope and operational services are tied to the specific engagement.
Fraud Detection provides read access for internal audit: dashboards, case lists and case files including triage, evidence and the audit trail. Editing, rule maintenance and administration have separate permissions.
Action, time, user and reason provide concrete points to check in the log. Acceptance testing checks effective permissions, log protection and access paths in your installation.
A case containing at least one change and one business decision is useful for a functional review. The following points suggest how to prepare a sample; they are not a regulatory audit standard.
The PPM documentation describes planning states, resource requests and status reports. Such information can be relevant to an implementation audit. The documents needed depend on the audit objective and the institution’s project records.
A status report or planning baseline evidences a particular matter. It does not establish the completeness of all project evidence or regulatory compliance.
It describes functions at a particular version. Control effectiveness must be assessed against the design, actual application and selected audit scope.
No. This example applies to Fraud Detection. Effective permissions are configured and checked for each application, installation and role.
A demonstration can explain a workflow. The deployed version and its supporting evidence are what matter for the audit.
The functions described here do not imply a requirement to purchase PPM software. Internal audit determines the project information needed for its engagement.
Functions, manual versions and assessment cases for T-NEX Controlling, Compliance, PPM and Fraud Detection, with an editable procurement overview.
Learn moreEntities, international team locations, data access and operational responsibilities: concrete topics for assessing a proposed engagement with T-NEX.
Learn more
Review transactions, group alerts and investigate cases. T-NEX Fraud Detection connects rules, AI triage, supporting transactions and a traceable audit trail.
Learn more
PPM for financial institutions: connect projects, line capacity, resource approvals and baselines, with traceable changes and AI proposals for work breakdown structures.
Learn more