Assessment
The Modern Auditing Maturity Model
Six dimensions, five levels, no gate and no email address. Score your function honestly and you will get a level, a weakest link, and the one move that actually raises it.
Maturity models are usually sold to you at the point where the answer is "buy the thing". This one is built so the levels are checkable: each cell describes an observable fact about how your team works, not an aspiration. If you cannot point at the evidence for a level, you are not at it.
The five levels
| Level | Name | In one line |
|---|---|---|
| 1 | Manual | Email and spreadsheets. The audit is a person's calendar. |
| 2 | Digitised | The filing cabinet moved into software. The work did not change. |
| 3 | Integrated | Systems are reachable. Evidence is pulled, not requested. |
| 4 | Continuous | Tests are definitions that re-run. Cadence is a policy choice. |
| 5 | Agent-native | Agents execute, humans approve, and the approval is recorded. |
Most functions that describe themselves as modernised sit at level 2. Level 2 is the trap: the money has been spent, the software is installed, and none of the five shifts has happened. The gap between 2 and 3 is the only one that requires giving auditors real access to systems, which is why so few functions cross it.
Score your function
For each dimension, pick the highest level you could defend with evidence today — not the one you are working towards.
The full model
The whole grid, for the version you paste into a committee deck.
| Dimension | L1 · Manual | L2 · Digitised | L3 · Integrated | L4 · Continuous | L5 · Agent-native |
|---|---|---|---|---|---|
| Evidence | A PBC list goes out by email. Chasing it is a named person's job. | A portal collects the same attachments. The chasing is now automated email. | Auditors hold read access to the systems of record and pull evidence directly. | Evidence is captured on a schedule against the full population, without a request. | An agent retrieves, ties out and attaches evidence to the test it supports; the auditor reviews the exceptions. |
| Testing | A judgmental sample, tested by hand, sized by how long it takes. | A sample tracked in software, still tested by hand. | Full populations extracted, then analysed with scripts or query tools by a specialist. | Population testing runs automatically on a defined cadence; exceptions are queued. | Agents execute the test definition end-to-end and present exceptions with their evidence; the auditor rules on them. |
| Workpapers | A spreadsheet or document on a shared drive. | The same document, uploaded to an audit tool with a review sign-off. | A structured record: control, assertion, population, exceptions, conclusion, approver. | Structured and re-runnable — last period's test executes again without being rebuilt. | Machine-readable end to end, so an agent can read prior-period work as context and a human can audit the agent's trail. |
| Cadence | Annually, and late. | Annually, on time. | Quarterly for the controls that matter most. | Continuously for automated controls; periodically for the rest. | Continuously, with the reporting interval set by risk appetite rather than by team capacity. |
| Risk assessment | Last year's plan, adjusted. Interviews and instinct. | A risk register maintained in a tool, refreshed annually. | Register linked to controls and frameworks, so coverage gaps are visible. | Plan responds to signals from the business's own systems during the year. | Coverage is computed against a control-and-risk graph; the plan is a decision made against evidence, and revisited continuously. |
| Supervision | Not applicable — nothing is machine-performed. | Spreadsheet macros and scripts nobody has reviewed or inventoried. | Analytics are documented and re-performed by a second person. | Automated tests are version-controlled, with defined owners and change control. | Every agent action is scoped, logged and gated: a named human approves before a conclusion stands, and the approval is part of the record. |
In practice
Levels 4 and 5 describe a shape most audit tooling cannot hold: tests as re-runnable definitions, workpapers as structured records, and every agent action gated behind a named human approval that becomes part of the audit trail. That last requirement is the one that rules out bolting a chatbot onto an existing GRC suite, and it is whatCoworkCanvas was built to do.