Did You Know?
Version 11.6.1 introduces audit findings in the BarnOwl web app. An Auditee can now review and comment on his / her findings directly in BarnOwl web, utilising BarnOwl’s open / free license.
In addition version 11.6.1 allows the Auditee to continue tracking his / her open findings in the BarnOwl web portal and update action plan/s associated with the finding.
In previous versions of BarnOwl, audit findings had to be exported by the Auditor to Excel, sent to the Auditee to complete his / her management comments in Excel and then re-imported into the system.
The following is a high level overview of the Finding/s review process:
- Step 1: Auditor raises a Finding/s and assigns Auditee/s to the Finding (BarnOwl desktop)
- Step 2: Auditor sets the Referred Status to ‘Opened for Comment’ (BarnOwl desktop)
- Step 3: Auditee completes management comment/s online (automated email notification with a link directly to the Finding on the BarnOwl web portal)
- Step 4: Auditor reviews management comments (BarnOwl desktop)
- Step 5: Auditor closes and finalises management comments in preparation for reporting (BarnOwl desktop)
- Step 6: Auditor raises Action Plan/s against the Finding (BarnOwl desktop)
- Step 7: Auditee responds to Action Plan/s (BarnOwl web portal)
- Step 8: Auditor follows up and closes the Finding when resolved (BarnOwl desktop)
Step 1: Auditor raises and assigns Auditee/s to the Finding
BarnOwl facilitates the full audit lifecycle from planning and execution to reporting and monitoring. BarnOwl supports risk and control-based auditing, aligning with the latest Global Internal Audit Standards (2024). Findings can be raised against the following objects in an audit project:
- Controls (automated findings can be configured based on audit procedure sampling)
- Audit steps
- Incident (forensics)
Fig 1.1: Auditor raises and assigns Auditee/s to the Finding
- The finding owner/s (auditee/s) default from the linked object (e.g. the control owners), however owners can also be captured by the auditor directly in the finding.
Step 2: Auditor sets the Referred Status to ‘Opened for Comment’
Fig 2.1: Auditor sets the Referred Status to ‘Opened for Comment’
- When a finding is first created, the Referred Status is ‘Closed for Comment’.
- When the Auditor is ready, they can set the Referred Status to ‘Opened for Comment’ to allow feedback on the finding.
- The system will send out an automated email to the Auditee/s with a link to the finding on the BarnOwl web portal for the Auditee/s to review the finding and capture management comments. See step 3 below.
Step 3: Findings referred to Auditee for management comment
Fig 3.1: Findings referred to Auditee for management comment
- The Auditee/s receive an email notification with a link to their Finding on the BarnOwl web portal (free / open license).
- The Auditee can access ‘My Findings’ at any time and toggle between ‘Showing Referred’ and ‘All Findings’.
- Only an Auditee assigned to the Finding can view and comment on the Finding.
- Multiple Auditees can be assigned as Owners of a Finding, allowing each to review and comment on it at their convenience.
- Auditors assigned as resources on an audit project can access the findings raised within that project.
Fig 3.2: Auditee management comments #1
- ‘Auditee U1’ comments on the Finding and ticks the ‘Is Completed’ when complete with the management comments. The ‘Complete and Save’ menu option also sets the ‘Is Complete’ flag automatically. The Auditee can however just ‘Save’ the comments and set the ‘Is Completed’ at a later stage.
Fig 3.3: Auditee management comments #2
- ‘Auditee U2’ comments on the Finding and ticks the ‘Is Completed’ when complete with the management comments.
Step 4: Auditor reviews management comments
Fig 4.1: Auditor reviews management comments
- The Auditor can track whether the Auditee(s) have completed their review and provided comments.
- The Auditor reviews the Auditee/s management comments.
Fig 4.2: Auditor sets Referred Status to ‘Closed for Comment’
- The Auditor sets the Referred Status to ‘Closed for Comment’ when all management comments have been received and completed.
- The Auditee can still view the Finding/s on the web portal but won’t be able to add any further comments and / or change their comments. The finding is ‘Closed for Comment’.
Step 5: Auditor finalises comments in preparation for reporting
Fig 5.1 Auditor finalises comments in preparation for reporting
- The Auditor ‘wordsmiths’ the management comments in preparation for the final audit report.
Fig 5.2: Audit trail on Findings (Desktop and Web)
- Comprehensive audit trails display the finding history, tracking the progression of management comments up to the final version.
- In figure #1 above, the Auditor can see the current and previous management comments. (BarnOwl desktop app)
- In figure #2 above, the Auditee can see the current and previous management comments. (BarnOwl web app)
Step 6: Auditor raises Action Plan/s against the Finding
Fig 6.1 Auditor raises Action Plan/s against the Finding
- Action Plans are generally raised after a close-out meeting with management (i.e. the Auditee/s)
- Action Plan email notifications, reminders and escalation are sent to the relevant Action Plan Owners (i.e. the Auditee/s)
Step 7: Auditee responds to Action Plan/s (free / open license)
Fig 7.1 Auditee responds to Action Plan/s (free / open license)
- The Auditee (Action Plan Owner) can view a list of all action plans where he / she is assigned.
- The Auditee (Action Plan Owner) can respond to his / her action plan and update progress.
- In addition, the Auditee can open the attached finding to review the finding details.
- BarnOwl sends out automated action plan notifications, reminders and escalation based on approaching due dates. Alternatively, BarnOwl enables a consolidated email to be sent out once a month only (for example) to the Owners with all of their outstanding action plans.
- The Auditee can access the BarnOwl portal at any time to quickly view their to-do list, including:
- My Action Plans (free / open license)
- My Findings (free / open license)
- My Key Indicators input values (free / open license)
- My Votes (surveys, Risk & Control self-assessments (RCSAs), questionnaires) (free / open license)
- My Risk Re-assessments (paid-for BarnOwl web license)
Fig 7.2: Auditee views the Finding linked to Action Plan
- View the Finding linked to the Action Plan
Fig 7.3: Auditee can view the Finding detail linked to Action Plan
- Including drill down into ‘Audit Procedure Tests’ to see which tests and samples failed.
Step 8: Auditor follows up and closes the Finding when resolved
Fig 8.1: Auditor follows up and closes the Finding when resolved
- The Auditor can close the Finding when satisfied that the Finding has been addressed adequately.
- The Auditee can view all ‘My Findings’ that are / were assigned to him / her.
- The Auditor can view all findings (open and closed) where he / she is a resource on the Audit Project, in either the BarnOwl desktop app and / or the BarnOwl web portal.
Conclusion
BarnOwl’s web-based findings streamline the review process which assists with management’s (the Auditee) buy-in for the finding.
Real time action plans linked to the finding/s drive ownership and accountability for resolving and closing finding/s.
BarnOwl’s web based portal helps embed enterprise risk management, assurance and good corporate governance throughout the organisation:
- My Action Plans (free / open license)
- My Findings (free / open license)
- My Key Indicators input values (free / open license)
- My Votes (surveys, Risk & Control self-assessments (RCSAs), questionnaires) (free / open license)
- My Risk Re-assessments (paid-for BarnOwl web license)
Useful links
https://barnowl.co.za/solutions/internal-audit-software
The new Global Internal Audit Standards (2024) focus on Risk Management
https://barnowl.co.za/barnowl-knowledge-base
About BarnOwl
BarnOwl is a fully integrated governance, risk management, compliance and audit software solution used by over 150 blue-chip organisations. BarnOwl is a locally developed software solution and is the preferred risk management solution for the South African public sector supporting the National Treasury risk framework.
Please see www.barnowl.co.za for more information.