Global Audit Intelligence HubAudit Intelligence & Professional Reference Portal
Source-referenced • 50 audit disciplines • v1.1 foundation
Find the audit insight you need.
Start with a risk, audit topic, framework or practical question. GAIH connects audit risks, control objectives, criteria, evidence, testing, red flags, related disciplines and official source references in one guided information portal.
⌕
Audit disciplines50
Framework / source records0
Risk intelligence themes8
Primary useReference & planning
Start with your question
What do you need help with?
The portal is organised around auditor questions rather than the type of content stored in the system.
📚
Explore an audit
Understand the purpose, risks, scope, control objectives, audit questions, evidence, tests, red flags and related audits.
🧭
Identify relevant audits
Start from an emerging risk, incident, organisational concern or sector and see which audit disciplines may be relevant.
🗂️
Find a framework
Understand what recognised frameworks support, how they can inform audit criteria and where applicability must be verified.
Translate AI, cyber, fraud, supplier, resilience, regulatory, ESG and transformation risks into assurance implications.
📰
See current audit & risk updates
Review fresh source-linked developments and see why they may matter to auditors and which GAIH topics they connect to.
🎓
Understand an audit concept
Use contextual explanations of criteria, control objectives, design effectiveness, evidence, findings and validated closure.
Connected logic
How audit information connects
Professional-use boundary
This pilot is an information and planning reference. Suggested audit questions and control objectives are derived from the scope, testing and framework content in the source taxonomy and should be tailored to the organisation, approved methodology, jurisdiction and engagement criteria.
Planning Intelligence
From risk universe to the right assurance response
Use this section to understand what can be audited, how to prioritise it, what assurance already exists, and which audit lens best fits the question.
What belongs in the audit universe?
Entities, business units and locations
Processes, products and services
Systems, applications and data assets
Projects, programmes and transformations
Vendors and outsourced services
Regulatory obligations, models and major risk themes
What should drive priority?
Impact and strategic importance
Regulatory or legal exposure
Control weakness and prior findings
Change velocity and transformation
Management / board concern
Time since last assurance review
Planning guardrails
The audit universe is wider than the annual plan.
Do not audit every unit every year.
Consider existing assurance before adding new work.
Escalate high-risk areas with little or stale assurance.
Refresh after major incidents, restructuring, new systems or regulation.
Assurance Intelligence
Which assurance approach fits the question?
Different audit disciplines answer different assurance questions. Use this map to avoid selecting a familiar audit label when another lens is more appropriate.
Audit Topics
Browse all audit disciplines
Each topic includes scope, control objectives, audit questions, evidence, testing methods, red flags and related frameworks.
Audit Practice
From mandate to evidence-based closure
Use this page for practical methodology, evidence quality, testing methods, finding development and contextual learning.
Audit planning questions
What objective or risk is the engagement intended to address?
What is in scope, out of scope and the period under review?
Which criteria will be used to evaluate the subject matter?
What populations, systems, locations and third parties are relevant?
What evidence is realistically available and how reliable is it?
What assurance has already been performed by other providers?
Common methodology mistakes
Scope is broader than the objective and available resources.
Evidence is collected without linking it to a control objective or criterion.
Inquiry is treated as sufficient evidence for important conclusions.
Findings describe the condition but do not explain root cause or consequence.
Management statements are accepted as proof of closure without validation.
Framework references are treated as mandatory without checking applicability.
Evidence
What counts as stronger audit evidence?
Evidence should be sufficient, reliable, relevant, traceable, current, complete enough for the purpose and corroborated where important.
Area
Weak evidence
Stronger evidence
Testing
Common audit testing methods
Findings
Build a defensible finding
Condition
What the evidence shows or what was observed.
Criteria
What should have happened based on policy, standard, regulation, contract or approved requirement.
Cause
The underlying reason the condition occurred or persisted.
Consequence
The actual or potential impact on objectives, stakeholders, compliance, operations or resources.
Action / recommendation
A response that addresses the root cause and risk rather than only the visible symptom.
Validated closure
Independent confirmation that implementation evidence addresses the original issue and the control operates as intended.
Learning
Audit glossary
Risk Intelligence
Start from an emerging risk or business situation
Each theme highlights warning signals and links directly to audit disciplines that may provide relevant assurance.
Sector pathways
Common audit priorities by organisational context
These are starting points for discussion, not prescribed annual audit plans. Risk assessment and local obligations should drive final selection.
Scenario horizons
When the trigger is an event
0–72 hours — contain & preserve
Clarify governance, protect people and critical services, preserve logs and records, identify affected systems or processes, and establish facts without compromising investigations.
3–30 days — stabilise & assess
Confirm control failures, assess exposure and dependencies, validate management actions, reconcile key records and determine whether an urgent audit or advisory review is needed.
30–90+ days — remediate & assure
Address root causes, strengthen control design, test implementation, monitor recurrence and provide independent assurance over sustained remediation.
Framework Library
Use frameworks as contextual audit criteria
Frameworks can inform objectives, control expectations, audit questions and evidence requirements. They do not automatically establish legal compliance, certification or a formal assurance conclusion.
Live Intelligence
Audit & Risk Intelligence Feed
A focused feed of source-linked developments relevant to audit, assurance, cyber, AI, compliance, financial crime, sustainability, resilience and standards. The feed is refreshed by GitHub Actions and stored as a static JSON file for GitHub Pages.
How to use this feed
News items are signals for professional review—not automatic audit criteria. Open the original source, confirm applicability and effective dates, then decide whether the development changes the audit universe, risk assessment, engagement criteria or evidence expectations.
Feed statusLoading feed…
Loading audit & risk intelligence…
Feed Governance
Source and update model
The updater prioritises official feeds and skips a source if it is temporarily unavailable. Failed sources do not prevent the remaining feed from publishing.
For a public GitHub repository, scheduled workflows run on the default branch. GitHub may disable scheduled workflows after prolonged repository inactivity, so check the Actions tab if the feed stops refreshing.
Sources & Validity
Know what supports the portal
The source taxonomy prioritises official standards, regulators, professional bodies and recognised framework publishers. Always verify the latest applicable version before formal reliance.
Authority model
Tier 1: legislation, regulation and official government/regulator requirements.
Tier 2: recognised international/professional standards and standard setters.
Tier 3: recognised frameworks, industry bodies and professional guidance.
Tier 4: internal policy, interpretation, commentary and contextual reference.
Validity controls
Review named frameworks and fast-changing topics at least semi-annually.
Refresh immediately after material regulatory, standard, technology or threat changes.
Confirm jurisdiction and sector applicability before treating a reference as criteria.
Do not state that the portal itself establishes compliance or certification.
Validity statement
This Global Audit Intelligence Hub is a general reference and learning artefact intended to support audit planning, assurance mapping and governance discussion. It is not an audit opinion, legal advice, certification or compliance determination. Users should verify jurisdiction-specific rules, sector requirements and the latest version of each named standard before formal reliance.