modern auditing

Assessment

The Modern Auditing Maturity Model

Six dimensions, five levels, no gate and no email address. Score your function honestly and you will get a level, a weakest link, and the one move that actually raises it.

Maturity models are usually sold to you at the point where the answer is "buy the thing". This one is built so the levels are checkable: each cell describes an observable fact about how your team works, not an aspiration. If you cannot point at the evidence for a level, you are not at it.

Takes about four minutes. Nothing is transmitted — scoring runs entirely in your browser.

The five levels

LevelNameIn one line
1ManualEmail and spreadsheets. The audit is a person's calendar.
2DigitisedThe filing cabinet moved into software. The work did not change.
3IntegratedSystems are reachable. Evidence is pulled, not requested.
4ContinuousTests are definitions that re-run. Cadence is a policy choice.
5Agent-nativeAgents execute, humans approve, and the approval is recorded.

Most functions that describe themselves as modernised sit at level 2. Level 2 is the trap: the money has been spent, the software is installed, and none of the five shifts has happened. The gap between 2 and 3 is the only one that requires giving auditors real access to systems, which is why so few functions cross it.

Score your function

For each dimension, pick the highest level you could defend with evidence today — not the one you are working towards.

Evidence

How does evidence reach the auditor?

Testing

What gets tested, and by whom?

Workpapers

What is a workpaper, structurally?

Cadence

How often does assurance refresh?

Risk assessment

How is the plan set?

Supervision

How is machine-performed work governed?

The full model

The whole grid, for the version you paste into a committee deck.

DimensionL1 · ManualL2 · DigitisedL3 · IntegratedL4 · ContinuousL5 · Agent-native
EvidenceA PBC list goes out by email. Chasing it is a named person's job.A portal collects the same attachments. The chasing is now automated email.Auditors hold read access to the systems of record and pull evidence directly.Evidence is captured on a schedule against the full population, without a request.An agent retrieves, ties out and attaches evidence to the test it supports; the auditor reviews the exceptions.
TestingA judgmental sample, tested by hand, sized by how long it takes.A sample tracked in software, still tested by hand.Full populations extracted, then analysed with scripts or query tools by a specialist.Population testing runs automatically on a defined cadence; exceptions are queued.Agents execute the test definition end-to-end and present exceptions with their evidence; the auditor rules on them.
WorkpapersA spreadsheet or document on a shared drive.The same document, uploaded to an audit tool with a review sign-off.A structured record: control, assertion, population, exceptions, conclusion, approver.Structured and re-runnable — last period's test executes again without being rebuilt.Machine-readable end to end, so an agent can read prior-period work as context and a human can audit the agent's trail.
CadenceAnnually, and late.Annually, on time.Quarterly for the controls that matter most.Continuously for automated controls; periodically for the rest.Continuously, with the reporting interval set by risk appetite rather than by team capacity.
Risk assessmentLast year's plan, adjusted. Interviews and instinct.A risk register maintained in a tool, refreshed annually.Register linked to controls and frameworks, so coverage gaps are visible.Plan responds to signals from the business's own systems during the year.Coverage is computed against a control-and-risk graph; the plan is a decision made against evidence, and revisited continuously.
SupervisionNot applicable — nothing is machine-performed.Spreadsheet macros and scripts nobody has reviewed or inventoried.Analytics are documented and re-performed by a second person.Automated tests are version-controlled, with defined owners and change control.Every agent action is scoped, logged and gated: a named human approves before a conclusion stands, and the approval is part of the record.

The Modern Auditing Maturity Model · modernauditing.com/maturity · free to reuse with attribution.

In practice

Levels 4 and 5 describe a shape most audit tooling cannot hold: tests as re-runnable definitions, workpapers as structured records, and every agent action gated behind a named human approval that becomes part of the audit trail. That last requirement is the one that rules out bolting a chatbot onto an existing GRC suite, and it is whatCoworkCanvas was built to do.