Business management · Internal Audit and GRC

Governance, risk and compliance backed by evidence, not by a slide deck

The GRC layer on top of Compliance Control: an audit universe prioritized by risk, an annual plan approved by the committee, engagements with an audit program and reviewed working papers, findings with a management action plan and follow-up, three lines of defense declared, key risk indicators with risk appetite thresholds read from the real operating modules, and the ISO 27001, COSO and SOX libraries mapped onto the controls the company already has.

The problem and the fix

The problems Internal Audit and GRC solves every day

If any of these situations sounds familiar, it is because they happen in almost every graduation company, until the right system comes in.

The problem

Internal audit is a spreadsheet of loose findings, and nobody knows whether the annual plan was carried out.

With Partiu Formatura

An audit universe with risk by process, an annual plan that is versioned and approved, engagements with status and plan execution measured on the dashboard.

The problem

The finding is written down, the manager agrees in the meeting and six months later nothing has changed.

With Partiu Formatura

A finding with a recommendation, a management action plan, a deadline and an owner, turning into an action in the same remediation flow Compliance already uses, with automatic follow-up and overdue alerts.

The problem

The person testing the control belongs to the same area that performs the control.

With Partiu Formatura

Independence checked through the segregation of duties that already exists: an auditor does not run procedures over controls in their own area, and any exception has to be recorded.

The problem

The board asks for risk indicators and gets opinions painted in traffic-light colors.

With Partiu Formatura

Indicators calculated from named formulas in code, reading overdue receivables, chargebacks, serious incidents, turnover, accidents and critical nonconformities, with risk appetite and tolerance declared.

The problem

Certification asks for the Statement of Applicability, and it gets assembled by hand every time.

With Partiu Formatura

ISO 27001, COSO and SOX libraries loaded per company and mapped to the internal controls, with the statement generated from the matrix and an explicit exception for any item excluded without justification.

In practice

Real examples of Internal Audit and GRC working for you

Everyday situations at graduation companies, from the problem to the result, using the modules on this page.

01

A risk-based annual plan

The scenario

The company has to decide what to audit this year with the team it has.

With the system

The audit universe is scored for inherent risk by process and business unit. The plan is built from that prioritization, versioned and approved on the committee agenda.

The result

The choice of what to audit is documented, and plan execution becomes a metric for the period.

02

An audit engagement in accounts payable

The scenario

The auditor has to prove what was tested, with the sample and the evidence.

With the system

The engagement has an audit program with procedures, working papers with the sample, attached evidence, a conclusion and review by someone else. A finding becomes an action with an owner and a deadline.

The result

The report comes out with a complete trail, and follow-up chases on its own once the deadline passes.

03

A risk indicator breaching the appetite

The scenario

Overdue receivables go past the limit the board accepted.

With the system

The daily measurement compares the value against appetite and tolerance. Out of range, continuous monitoring raises an alert and the board dashboard shows the trend.

The result

The conversation in the meeting starts from the number and the time series, not from this month's impression.

How it works

How information flows through Internal Audit and GRC

Every step is a real module, and what comes out of one goes into the next without anyone typing it again.

  1. 1UniverseProcesses and business units are scored for risk, and the annual plan comes out of that prioritization.
  2. 2ApprovalThe committee approves the plan, and the approval is recorded on the agenda.
  3. 3ExecutionThe engagement runs with an audit program, working papers and independent review.
  4. 4RemediationThe finding becomes an action with an owner and a deadline, chased through follow-up.
  5. 5Financial reportingIndicators, plan execution and open findings go to the board dashboard.

Module by module

Everything included in Internal Audit and GRC

7 modules and 35 features on this page, all running on the same class, graduate and event records.

Audit Universe and Annual Plan

What can be audited, and what will be audited this year.

  • Processes and business units with inherent risk and last audit date
  • Risk-based prioritization feeding the annual plan
  • A plan that is versioned, approved and tracked by execution
  • Quality audits appearing in the universe, without being moved out of their module
  • An auditor register with home area and conflicts of interest

Engagements and Working Papers

The test that happened, with the proof that it happened.

  • Engagement with scope, period, team and status
  • An audit program with procedures by control objective
  • Working paper with sample, evidence, conclusion and reviewer
  • A reviewer different from the preparer, enforced by the system
  • Engagement closure blocked while a working paper is unreviewed or a finding has no action plan

Findings and Follow-up

What was found turns into change, with a deadline.

  • Finding with severity, recommendation and management action plan
  • Action created in the same Compliance remediation flow
  • Status read from the action itself, with no parallel tracking
  • Overdue finding alerts in continuous monitoring
  • Report and opinion going onto the committee agenda

Three Lines of Defense

Who performs, who monitors and who audits, declared.

  • Line of defense declared on the control, the risk and the test
  • The tester's area recorded on the effectiveness test
  • An auditor barred from testing a control in their own area
  • Exceptions allowed, but recorded with a justification
  • Independence visible in the report, without relying on trust

Key Risk Indicators

Risk measured with data from the system itself.

  • Named formulas in code, reading installments, chargebacks, incidents, HR, occupational health and safety and quality
  • Appetite and tolerance per indicator, set by the company
  • Daily measurement with a time series and a calculated trend
  • An automatic alert when the indicator moves out of range
  • A missing module returns an indicator with no basis, instead of a misleading zero

Frameworks and Statement of Applicability

The standard tied to the control you already have.

  • ISO 27001, COSO and SOX libraries loaded per company
  • Mapping of several requirements onto the same internal control
  • Coverage per framework calculated from the matrix
  • Statement of Applicability generated, flagging any exclusion made without justification
  • Lives alongside the existing libraries for LGPD (Brazilian data protection law), labor, occupational health and safety, tax and integrity

Board Dashboard

The snapshot that goes to the meeting, with its date and its source.

  • Residual risk heat map, showing the effect of the controls
  • Trend of the key risk indicators over the period
  • Audit plan execution and overdue findings
  • Business continuity maturity and the integrity program score
  • PDF export kept along with the period's snapshot

Find the right plan for Internal Audit and GRC

Compare the modules and choose the setup that fits your operation.