A&A-01 Audit and Assurance Policy and Procedures
Maintain approved audit and assurance policies, procedures and standards that are documented, communicated to the staff they bind, applied in practice, and reassessed at least once a year.
4
artefacts
0
held by a system
1
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- The annual review record with reviewer, date and outcome · Document repository
governing documentDocuments that govern the control
- The signed audit and assurance policy showing an approval authority and an effective date · Policy repository / GRC workspace
- Distribution or acknowledgement evidence showing the policy reached audit and assurance staff · HR system / LMS
- The audit standards the organisation has adopted, named in the policy · Policy repository / GRC workspace
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Policy exists but has not been reviewed inside the last twelve months
- Approval is undated or by someone without the authority to approve it
- No evidence the policy was ever communicated beyond the team that wrote it
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet