All cases Consulting

From audit methodology to a scalable product

Global consulting company

Over 15 deployments
within major national organisations
Full audit workflow
from risk assessment to corrective action
No coding needed
to configure workflows and deploy for another client

Our client is a global consulting company that establishes internal audit departments in large corporations: introducing a methodology, recruiting and training people, and organising their work. We built its audit software and trained its implementation specialists. Alongside its methodology, the company can now offer a tool for everyday audit work, from deciding what to inspect to checking that problems are resolved. The system has been deployed in more than 15 legal entities within major national organisations.

There is never enough time to audit everything

Internal audit teams have limited time and people. They need to decide which areas carry the highest risks and how to cover the most important ones with the team available. Then come the documents, reports and follow-up work. Every hour spent organising this is an hour unavailable for auditing.

The initial request was for task tracking, and we considered adapting Jira. Detailed discussions showed how closely the stages depended on each other: risk assessment feeds a schedule, the schedule leads to audits with their own task structures, and findings become reports and instructions to other departments. We needed to build a system from scratch to connect that work properly.

Design and specification alone took seven months. That is a long time, but it involved understanding the methodology, talking to future users, and testing how they navigated clickable prototypes. A feature list would not explain what an auditor needed to see together or how the different parts should connect in daily use. We worked through those questions before development.

Who goes where, and for how long?

Planning starts with the areas to be audited. Risks are calculated semi-automatically using the client’s methodology, helping the team choose its priorities. The result is a calendar with named auditors, assignments and effort estimates in hours.

Teams can plan one or several years ahead, discuss and approve the schedule, then adjust it while retaining earlier versions. Managers can see what the team has capacity to cover and how a proposed change affects the workload.

Each audit is a project with a tree of tasks. The auditor chooses a template for the type of area being inspected and gets a work plan with deadlines, priorities and owners. The methodology is already built into the template; the auditor can adapt it without recreating every procedure.

Findings are recorded as separate items in a shared register. Their life extends well beyond the task that uncovered them: a finding goes into a report, leads to a corrective action plan, receives an owner and may need to be tracked for years.

Variables and loops inside Word

Audit reports have prescribed formats. In this project, they also had to be printed, signed and stored on paper for years. Preparing them manually would be particularly wasteful when the system already held the audit details and every finding.

We built a generator for Word and Excel reports using templates that users can edit themselves. In a Word file, they insert variables and even loops: a block describing a finding, for example, repeats for every finding in the audit. The system fills the template and produces the finished document.

When a report format changes, the user edits the template and uploads it again. The consulting company can meet different clients’ reporting requirements without asking developers to create another form.

The report is signed. The work continues

Once an audit is complete, the responsible departments must address its findings. For those employees, the system becomes a corrective action tracker. They see their assigned issues, submit action plans, record progress and attach evidence. The auditors’ internal sections remain inaccessible to them.

Some issues can be fixed quickly; others take years. The system tracks progress, sends reminders and produces status reports, saving auditors from repeatedly asking departments what is happening. Management gets an overall view, and findings remain visible after the report is signed.

Corrective work can continue for years after an audit report is signed. The findings remain tracked throughout.

Configuration the client can handle independently

Different corporations have different roles, permissions and processes, so the workflow itself is configurable. An administrator defines statuses and allowed transitions: who can take which action, in which role and at which stage. Together with audit and document templates, these settings let the consulting team adapt the product to another client without changing the code.

The system runs on-premises, integrates with Active Directory and supports digital-signature authentication. The setup is adapted to each organisation’s infrastructure.

Development took about a year to the first deployment, followed by roughly another year of support and improvements. We trained the client’s team to install the system, configure it and support users. They needed a sound understanding of the methodology and product; a full development team was unnecessary because configuration covered the required changes.

The client has independently completed more than 15 deployments. For each new customer, it already has a working product and its own specialists who know how to put it into use.