Global Audit Intelligence HubAudit Intelligence & Professional Reference Portal
Source-referenced • 50 audit disciplines • pilot edition

Find the audit insight you need.

Start with a risk, audit topic, framework or practical question. GIAH connects audit risks, control objectives, criteria, evidence, testing, red flags, related disciplines and official source references in one guided information portal.

Audit disciplines50
Framework / source records0
Risk intelligence themes8
Primary useReference & planning
Start with your question

What do you need help with?

The portal is organised around auditor questions rather than the type of content stored in the system.

📚

Explore an audit

Understand the purpose, risks, scope, control objectives, audit questions, evidence, tests, red flags and related audits.

🧭

Identify relevant audits

Start from an emerging risk, incident, organisational concern or sector and see which audit disciplines may be relevant.

🗂️

Find a framework

Understand what recognised frameworks support, how they can inform audit criteria and where applicability must be verified.

🧪

Prepare for an audit

Review methodology, evidence quality, testing techniques, workpaper expectations and finding construction.

⚠️

Explore emerging risks

Translate AI, cyber, fraud, supplier, resilience, regulatory, ESG and transformation risks into assurance implications.

📰

See current audit & risk updates

Review fresh source-linked developments and see why they may matter to auditors and which GIAH topics they connect to.

🎓

Understand an audit concept

Use contextual explanations of criteria, control objectives, design effectiveness, evidence, findings and validated closure.

Connected logic

How audit information connects

01Risk / concern
02Audit topic
03Control objective
04Criteria
05Evidence & testing
06Conclusion / insight
Professional-use boundary

This pilot is an information and planning reference. Suggested audit questions and control objectives are derived from the scope, testing and framework content in the source taxonomy and should be tailored to the organisation, approved methodology, jurisdiction and engagement criteria.

Planning Intelligence

From risk universe to the right assurance response

Use this section to understand what can be audited, how to prioritise it, what assurance already exists, and which audit lens best fits the question.

01Organisation context
02Risk universe
03Audit universe
04Prioritise
05Assurance coverage
06Audit plan

What belongs in the audit universe?

  • Entities, business units and locations
  • Processes, products and services
  • Systems, applications and data assets
  • Projects, programmes and transformations
  • Vendors and outsourced services
  • Regulatory obligations, models and major risk themes

What should drive priority?

  • Impact and strategic importance
  • Regulatory or legal exposure
  • Control weakness and prior findings
  • Change velocity and transformation
  • Management / board concern
  • Time since last assurance review

Planning guardrails

  • The audit universe is wider than the annual plan.
  • Do not audit every unit every year.
  • Consider existing assurance before adding new work.
  • Escalate high-risk areas with little or stale assurance.
  • Refresh after major incidents, restructuring, new systems or regulation.
Assurance Intelligence

Which assurance approach fits the question?

Different audit disciplines answer different assurance questions. Use this map to avoid selecting a familiar audit label when another lens is more appropriate.

Planning questions

Questions before an audit enters the plan

Risk

  • What could materially prevent objectives?
  • How quickly could the exposure change?
  • What incidents or near misses have occurred?

Assurance

  • Who already reviews this area?
  • How recent and independent is that assurance?
  • Where are the gaps or duplication?

Change

  • What systems, vendors, AI or operating-model changes are underway?
  • Has control design kept pace?

Practicality

  • Is evidence available?
  • Do we have the skills and mandate?
  • What decision will the audit support?
Audit Topics

Explore 50 connected audit disciplines

Search by audit name, risk, scope, evidence, framework, procedure or red flag. Open a topic to see the complete audit-intelligence profile.

Audit Practice

From mandate to evidence-based closure

Use this page for practical methodology, evidence quality, testing methods, finding development and contextual learning.

01Mandate & independence
02Risk-based planning
03Engagement design
04Fieldwork
05Reporting
06Follow-up & quality

Audit planning questions

  • What objective or risk is the engagement intended to address?
  • What is in scope, out of scope and the period under review?
  • Which criteria will be used to evaluate the subject matter?
  • What populations, systems, locations and third parties are relevant?
  • What evidence is realistically available and how reliable is it?
  • What assurance has already been performed by other providers?

Common methodology mistakes

  • Scope is broader than the objective and available resources.
  • Evidence is collected without linking it to a control objective or criterion.
  • Inquiry is treated as sufficient evidence for important conclusions.
  • Findings describe the condition but do not explain root cause or consequence.
  • Management statements are accepted as proof of closure without validation.
  • Framework references are treated as mandatory without checking applicability.
Evidence

What counts as stronger audit evidence?

Evidence should be sufficient, reliable, relevant, traceable, current, complete enough for the purpose and corroborated where important.

AreaWeak evidenceStronger evidence
Testing

Common audit testing methods

Findings

Build a defensible finding

Condition

What the evidence shows or what was observed.

Criteria

What should have happened based on policy, standard, regulation, contract or approved requirement.

Cause

The underlying reason the condition occurred or persisted.

Consequence

The actual or potential impact on objectives, stakeholders, compliance, operations or resources.

Action / recommendation

A response that addresses the root cause and risk rather than only the visible symptom.

Validated closure

Independent confirmation that implementation evidence addresses the original issue and the control operates as intended.

Learning

Audit glossary

Risk Intelligence

Start from an emerging risk or business situation

Each theme highlights warning signals and links directly to audit disciplines that may provide relevant assurance.

Sector pathways

Common audit priorities by organisational context

These are starting points for discussion, not prescribed annual audit plans. Risk assessment and local obligations should drive final selection.

Scenario horizons

When the trigger is an event

0–72 hours — contain & preserve

Clarify governance, protect people and critical services, preserve logs and records, identify affected systems or processes, and establish facts without compromising investigations.

3–30 days — stabilise & assess

Confirm control failures, assess exposure and dependencies, validate management actions, reconcile key records and determine whether an urgent audit or advisory review is needed.

30–90+ days — remediate & assure

Address root causes, strengthen control design, test implementation, monitor recurrence and provide independent assurance over sustained remediation.

Framework Library

Use frameworks as contextual audit criteria

Frameworks can inform objectives, control expectations, audit questions and evidence requirements. They do not automatically establish legal compliance, certification or a formal assurance conclusion.

Live Intelligence

Audit & Risk Intelligence Feed

A focused feed of source-linked developments relevant to audit, assurance, cyber, AI, compliance, financial crime, sustainability, resilience and standards. The feed is refreshed by GitHub Actions and stored as a static JSON file for GitHub Pages.

How to use this feed

News items are signals for professional review—not automatic audit criteria. Open the original source, confirm applicability and effective dates, then decide whether the development changes the audit universe, risk assessment, engagement criteria or evidence expectations.

Feed statusLoading feed…
Loading audit & risk intelligence…
Feed Governance

Source and update model

The updater prioritises official feeds and skips a source if it is temporarily unavailable. Failed sources do not prevent the remaining feed from publishing.

For a public GitHub repository, scheduled workflows run on the default branch. GitHub may disable scheduled workflows after prolonged repository inactivity, so check the Actions tab if the feed stops refreshing.

Sources & Validity

Know what supports the portal

The source taxonomy prioritises official standards, regulators, professional bodies and recognised framework publishers. Always verify the latest applicable version before formal reliance.

Authority model

  • Tier 1: legislation, regulation and official government/regulator requirements.
  • Tier 2: recognised international/professional standards and standard setters.
  • Tier 3: recognised frameworks, industry bodies and professional guidance.
  • Tier 4: internal policy, interpretation, commentary and contextual reference.

Validity controls

  • Review named frameworks and fast-changing topics at least semi-annually.
  • Refresh immediately after material regulatory, standard, technology or threat changes.
  • Confirm jurisdiction and sector applicability before treating a reference as criteria.
  • Do not state that the portal itself establishes compliance or certification.
Validity statement

This Global Audit Intelligence Hub is a general reference and learning artefact intended to support audit planning, assurance mapping and governance discussion. It is not an audit opinion, legal advice, certification or compliance determination. Users should verify jurisdiction-specific rules, sector requirements and the latest version of each named standard before formal reliance.

0 selected