Skip to main content
Version: 1.0.0-beta

Audit Universe & Library

The Audit Universe is the foundational building block of your audit program. It provides a centralized, governed registry of every auditable entity in your organization—business units, processes, applications, and regulatory domains—along with their associated risks and controls.

Audit Universe list view

What Is the Audit Universe?

The Audit Universe is the master catalog of everything your internal audit function can—or should—audit. Each item in the universe represents an auditable entity with associated risk ratings, control mappings, last audit dates, and coverage metrics.

The Library complements the universe by providing reusable building blocks:

  • Risks — categorized risk statements with inherent/residual ratings
  • Controls — control activities mapped to risks with effectiveness ratings
  • Risk-Control Mappings — the linkages between risks and their mitigating controls

Together, these components form a complete risk-and-control framework that drives risk-based audit planning.

Key Capabilities

CapabilityDescription
Entity RegistryCatalog all auditable entities with structured metadata
Risk AssessmentAttach quantified risk ratings (likelihood × impact) to entities
Control MappingLink controls to risks with many-to-many relationships
Coverage TrackingAutomatically track when each entity was last audited
Hierarchy SupportNest entities under parent business units or processes
Bulk ImportUpload entities, risks, and controls via CSV/Excel
AI-AssistedAI suggests risk ratings based on historical data and industry benchmarks
Search & FilterFull-text search with faceted filtering by type, risk level, owner, and status

How It Connects to Other Modules

  • Annual Planning pulls universe items to build risk-based audit plans
  • Engagements link to universe items for scope definition
  • Compliance maps framework controls to library controls
  • Monitoring uses universe items as KRI data sources
  • Fieldwork uses library test procedures for workpaper execution
  • Findings reference library controls when documenting exceptions

Entity Types

The universe supports the following entity categories:

TypeExamplesIcon
Business UnitFinance, HR, IT, Operations🏢
ProcessProcure-to-Pay, Hire-to-Retire, Order-to-Cash⚙️
ApplicationSAP, Oracle HCM, Salesforce💻
Regulatory DomainNCA ECC, PDPL, SOX, GDPR📋
ProjectDigital Transformation, ERP Migration📁
LocationRiyadh HQ, Jeddah Branch, Remote📍

Risk Rating Methodology

AIIA uses a 5×5 risk matrix by default (configurable per organization):

Impact 1Impact 2Impact 3Impact 4Impact 5
Likelihood 5🟡 Medium🟠 High🔴 Critical🔴 Critical🔴 Critical
Likelihood 4🟡 Medium🟡 Medium🟠 High🔴 Critical🔴 Critical
Likelihood 3🟢 Low🟡 Medium🟡 Medium🟠 High🔴 Critical
Likelihood 2🟢 Low🟢 Low🟡 Medium🟡 Medium🟠 High
Likelihood 1🟢 Low🟢 Low🟢 Low🟡 Medium🟡 Medium

The resulting risk score (1–25) determines the entity's priority for audit coverage.

User Interface Overview

Universe List View

The universe list displays all auditable entities with:

  • Search bar — full-text search across name, description, and tags
  • Filter panel — filter by entity type, risk level, owner, last audit date
  • Sort options — sort by name, risk score, last audit date
  • Bulk actions — select multiple items for bulk operations
  • Quick actions — edit, archive, or view details from the list

Entity Detail View

Clicking an entity opens the detail panel with tabs:

TabContent
OverviewEntity metadata, description, owner, dates
RisksAssociated risk statements with ratings
ControlsMapped controls with effectiveness status
Audit HistoryPast engagements that covered this entity
DocumentsAttached reference documents
ActivityAudit log of all changes to this entity

AI Integration

The AI companion assists with the Audit Universe in several ways:

FeatureHow It Helps
Risk Suggestion"Suggest risks for this business unit based on industry standards"
Coverage Analysis"Which universe items haven't been audited in 18 months?"
Duplicate DetectionAI flags potential duplicate entries when creating new items
Description EnhancementAI helps refine entity descriptions for clarity
AI Governance

All AI suggestions in the Audit Universe require human review and explicit "Apply" action before changes are committed. Every AI interaction is logged in the audit trail.

Getting Started

  1. Create Universe Items → — Add your first auditable entities
  2. Manage Risks → — Attach risk assessments to entities
  3. Map Controls → — Link controls to risks
  4. Field Reference → — Complete field-by-field documentation
  5. Permissions → — Who can do what in this module