Audit observations in Audit Workspace
Summarize
Summary of Audit observations in Audit Workspace
Audit observations are critical results derived from audit activities such as reviews, analysis, interviews, and discussions. They highlight significant issues identified during an audit and are essential components of the audit report. These observations document how operations, like those of a bank, perform against established audit criteria.
Show less
Observations are created during control testing, interviews, and walkthroughs, and can be added from audit engagements or audit tasks, provided the engagement is not in the Follow Up or Closed state. These observations help auditors summarize problems, discoveries, and recommendations for audit supervisors and determine whether they represent reportable issues, recommendations, or best practices.
Creating and Managing Audit Observations
Users with the snaudit.user role can create observations within the Audit Workspace by navigating through engagements and filling out the observation form. When creating an observation, respondents (entity owners and control owners) and peer reviewers (auditors and audit leads) are assigned.
The observation lifecycle includes the following states: Draft, Review, Respond, Finalize, and Closed. Key processes include:
- Peer Review: The observation creator can request a peer review, which notifies the peer reviewer and changes the observation substate to "Peer review requested" while keeping the state as Draft. Peer reviewers access their tasks via the workspace or homepage.
- Review: Reviewers (audit supervisors or leads) receive notifications and can request revisions, request responses from respondents, or provide feedback via the Results section.
- Response: Respondents reply to observations in the Audit Workspace under "My Pending Response."
Once responses and reviews are complete, the observation moves to the Finalize state and eventually closes, often resulting in the creation of an issue for further tracking.
Practical Benefits for ServiceNow Customers
- Enables structured documentation and tracking of audit findings within engagements.
- Facilitates collaboration among auditors, respondents, and supervisors through assigned roles and notification workflows.
- Supports governance by guiding observations through a defined lifecycle, ensuring thorough review and response before closure.
- Integrates audit results with issue management by converting finalized observations into actionable issues.
Audit observations are the results of an audit. As an important part of the audit report, audit observations represent the results of reviews, analysis, interviews, and discussions.
Overview of an audit observation
Audit observations are used to bring significant issues to the attention of audit supervisors. Observations are logged in the system. For example, if a bank's operations are being audited, then the audit observations are based on evidence about how the bank's operations perform against the audit criteria. During control testing, interviews, and walkthroughs, audit observations are recorded. An audit user can create an observation from an engagement if the engagement is not in the Follow Up or Closed states. An observation can also be created from all types of audit tasks.
After the auditor completes the audit, the auditor then presents the audit observations to the audit supervisors. By using the audit observations, the auditor can present a summary of problems, discoveries, and recommendations. The audit team reviews the observations to determine if the observation is a reportable issue. The audit team can also determine if the observation can be tracked as a recommendation, an observation, or a best practice.
- Draft
- Review
- Respond
- Finalize
- Closed
Status workflow of an audit observation in workspace
- An audit user with the role sn_audit.user creates an observation. See Create an observation for an
engagement.
- To create an observation, navigate to .
- Click the lists icon (
).
- Click All engagements or My engagements in the Execution list.
- Click the link to the engagement record in the Name column.
- Click the Observations tab.
- Click New.
- On the Create New Observation form, fill in the fields.
- The observation creator assigns respondents and peer reviewers to the observation. The respondents are the entity owners and control owners. The peer reviewers are the auditors and audit leads of the engagement.
- The observation creator can request a peer review of the observation. In that case, the
following happens:
- The peer reviewer gets a notification to perform the peer review. The peer reviewer can view the task under by clicking the tasks icon (
) in the workspace.
Note:The peer reviewer can also navigate to in the Home page of the workspace. - The peer reviewer completes the review.
Note:When a peer review is requested, the state remains as Draft but the substate changes to Peer review requested. - The peer reviewer gets a notification to perform the peer review. The peer reviewer can view the task under by clicking the tasks icon (
- The observation creator can also request a review. The reviewer can be an audit supervisor
or the audit lead.
- The reviewer gets a notification to perform the review. The reviewer can view the task by navigating to .
- The reviewer can either request a revision of the observation or request a response from the respondent. The reviewer can also provide feedback in the Results section by selecting the appropriate option.
- If the reviewer requested a response from the respondent, then the respondent responds to the observation by navigating to .
- The observation moves to the Finalize state.
- The observation is closed and an issue is created.