Internal Audit Report
Detects internal audit reports containing control assessments and organisational vulnerability findings.
- Type
- regex
- Confidence
- medium
- Confidence justification
- Medium confidence: keyword-based detection requires corroborative evidence for accurate identification.
- Jurisdictions
- global
- Regulations
- IPA 2009 (Qld), Privacy Act 1988 (Cth), SOCI Act 2018 (Cth)
- Frameworks
- DISP, ISO 27001, NIST CSF
- Data categories
- audit, governance
- Scope
- narrow
- Risk rating
- 8
Should match
Internal audit report— Low-tier probe - report title without substantive audit contentInternal audit report: audit scope, audit objective, and audit opinion.— Medium-tier probe - substantive audit sections without a classified finding responseInternal audit report: high risk finding and audit exception; management response, corrective action, and target completion date.— High-tier probe - classified finding plus management response
Should not match
Tax audit by the ATO— External tax-audit siblingAudit the financial statements— Financial-audit instructionThe public annual report links to an internal audit report.— Public link mentions only the report titleTemplate example: internal audit report with high risk finding, audit exception, management response, and target completion date.— Template contains otherwise high-tier evidence
Known false positives
- External audit or financial audit references. Mitigation: Require internal audit specific terms like internal audit plan or management letter.