Home

Robert Mathison

rapidoAudit: a tool for help internal auditors to do their job

Mission Statement

To provide an specific tool for the internal auditors colective and auditors in general, focused in three main aspects:

  • Flexible: the tool will adapt to the way of working of the auditors
  • Thought for workteam from its beginning
  • With facilities for the follow up of the auditory findings

What is rapidoAudit?

rapidoAudit is an application to help internal auditors to do their job better. Nowadays, in a highly computerized environment it is suprising to see auditors keeping track of their job in office documents who share among his supervisor or collaborators by email.

This email-based working, although simple, has many disadvantages:

  • The register of the audit documents, and substantive proofs is made in archives, many times with few control over the confidentiality and the security
  • The difussion of the partial results and the coordination between the team members is made by emails, dificulting the coordination among the members of the team
  • The sending of the reports is made also with emails, with the problems that carries the control of the reception and the reading, wich is scattered among the email clients of the audit team instead of staying in a centralized repository
  • The follow-up of the findings becomes too complex: track in the same document findings that must be shared among many members of the company, get his responses and evidences, add them to another word document, create a summary for the management...

Me, as a computer worker in a big financial company based in United Kingdom, I had the opportunity to knew the internal auditors and realize how rudimentary his work were: they carry the work in Word documents, and write the final report in Word documents also. Keeping track of versions and changes were a nightmare. Keep track of reports sent also. And the follow-up of findings were nearly impossible.

rapidoAudit comes with some simple ideas in mind:

  1. All the audit work must be kept in a central database: this ease the the security measures to be taken to guarantee the security of those valuable assets
  2. The audit application must allow to work different auditors in a the same audit at the same time: some of them reviewing the work done, others making some work
  3. Web application for allow access enterprise-wide or --if needed-- world-wide
  4. A system to deliver reports safer than just email (by downloading the reports from the application, you can keep track of readings and can assure that the download is made in a safe manner)
  5. A system to keep track of the findings: have the accounting department fixed the issue found in my report of the last year??? With rapidoAudit, each finding is identified as this, and allow you to track if it is solved and query for additional information about the current state of this issue
  6. Fully customizable: every audit work is based on a template that can be easily changed: in this way, rapidoAudit can accomodate to your way of working instead of the opposite!!!

This is only an idea under development

Yes, by the moment this is only an idea under development. My plan is the following:

  • I am doing right now the most basic features of the application, without implementing security to allow the creation of a testable application
  • The second step will be implement a security model. My idea is not be tied to any particular system, but to allow the use of a directory service (LDAP, Active Directory) to implement permissions and authorization

This is a document under development

I am planning to use sourcerforge as the main website for this project and update this wiki with the technical features and description of the working of the application.

Resources

By the moment, we are only keeping the following resources online:

More things

Ideas about the design of the application

Key concepts about the Architecture

Enroll in the project

Drop me a line to the list!!!

https://lists.sourceforge.net/lists/listinfo/rapidoaudit-main

I'll be glad to hear that someone has targeted the same needs I've detected and if you share your vision about the applications to help auditors with me, I will glad also to read them!!!

Moreover, if you want to enroll to the project I'll be glad to hear from you. rapidoAudit is a start-up project and there are many things to do until the first release.


MongoDB Logo MongoDB