Internal Audit Checklist for Saudi Arabia (Free Template)
A free internal audit checklist for Saudi functions — charter, universe, annual plan, engagement, reporting, QAIP, and the SAMA and NCA review obligations.
Most internal audit checklists you can download are engagement checklists — how to run one audit. That is the easy part. What Saudi Heads of Internal Audit actually get caught by is function-level completeness: the charter that was never re-approved, the QAIP external assessment that is now in year six, and the NCA review obligation with a three-year clock that nobody was counting.
This checklist works at the function level. It covers the IPPF requirements and the specific review obligations SAMA and the NCA impose, which generic IIA checklists omit entirely. A downloadable working copy is available at the end.
How to use this checklist
- Mark the current state — in place, partial, or absent.
- Name the owner. For the independence items, name the reporting line as well.
- Note the evidence reference and where it lives.
- Record the date last reviewed — most failures here are staleness, not absence.
- Identify the gap and the action to close it.
1 — Charter and mandate
1.1 Audit charter documented, defining purpose, authority and responsibility.
1.2 Charter approved by the audit committee or board, with the approval evidenced and dated.
1.3 Charter reviewed on a defined cadence — annually is the common standard.
1.4 Right of access to records, personnel and premises stated explicitly.
1.5 Scope covers the whole organisation, including subsidiaries — and, where ECC scope reaches them, affiliated entities outside the Kingdom.
2 — Independence and objectivity
2.1 Reporting line. The Head of Internal Audit reports functionally to the audit committee and administratively to the CEO — not to the CFO or CIO.
2.2 Direct committee access without management present, evidenced at least annually.
2.3 Annual independence confirmation from the Head of Internal Audit to the committee.
2.4 Conflict-of-interest declarations from all audit staff, refreshed annually.
2.5 Safeguards where audit has non-assurance roles. Where internal audit advises on control design, the safeguard preventing self-review is documented.
3 — Audit universe
3.1 A documented universe covering business processes, systems, legal entities, third parties and regulatory obligations.
3.2 Systems classified critical under the CSCC identified within it as distinct auditable units.
3.3 Third parties and material outsourcing present as auditable units, not folded into the owning business process.
3.4 Regulatory obligations as auditable units — SAMA CSF domains, NCA ECC subdomains, PDPL duties.
3.5 Risk rating per unit combining inherent risk, control environment and regulatory exposure.
3.6 Refreshed at least annually and on material business change.
4 — Annual planning
4.1 Plan derived from the universe, with the derivation shown — not a rotation schedule.
4.2 Fixed-frequency regulatory items committed first (see section 7) before discretionary capacity is allocated.
4.3 Resourcing and capacity modelled against the plan, with gaps flagged to the committee rather than absorbed silently.
4.4 Plan approved by the audit committee, with changes during the year re-approved and the reason recorded.
4.5 Coverage reported — what percentage of high-risk universe units the plan touches, and what it deliberately does not.
5 — Engagement execution
5.1 Engagement planning memo per audit, with objectives, scope and criteria.
5.2 Audit programme derived from the applicable control set where the engagement is a compliance audit.
5.3 Working papers supporting every conclusion, reviewed and signed off by someone other than the preparer.
5.4 Findings rated on a documented, consistently applied scale.
5.5 Management responses obtained, with an owner and a target date per recommendation.
5.6 Report issued within a defined turnaround from fieldwork close.
6 — Follow-up and reporting
6.1 Recommendation tracking with owner, due date and current status.
6.2 Ageing on overdue items, with automatic escalation past a defined threshold.
6.3 Closure evidenced — verified by audit, not asserted by management.
6.4 Audit committee reporting on a defined cadence, covering plan progress, findings by rating, and overdue recommendations.
6.5 Reporting generated from live data rather than assembled manually each quarter.
6.6 Arabic reporting available where the committee reads in Arabic.
7 — Regulated review obligations
The section generic checklists omit. Each of these has a fixed frequency and a named owner requirement.
| Ref | Obligation | Frequency |
|---|---|---|
| CSCC 1-4-1 | Review of CSCC implementation by the cybersecurity function | At least annually |
| CSCC 1-4-2 | Review of CSCC implementation by independent parties outside the cybersecurity function | At least every 3 years |
| ECC 1-8 | Periodical cybersecurity review and audit | Per the entity's defined cadence |
| SAMA CSF | Internal audit of the cyber security function, findings tracked to closure and reported to the audit committee | Defined cadence, evidenced |
| DCC 1-1 | Periodical review and audit of data cybersecurity controls | Varies by data classification level |
| OTCC 1-6 | Periodical cybersecurity review and audit for OT environments | Per assigned facility level |
| IPPF | External quality assessment of the internal audit function | At least every 5 years |
7.1 Each obligation above has a named owner and a next-due date recorded somewhere other than one person's calendar.
7.2 The three-year and five-year clocks are tracked from the date of the last completed review, with the evidence retained.
7.3 Where the entity is subject to both SAMA and NCA regimes, the reviews are planned as one exercise producing evidence for both — not run twice.
8 — Quality assurance and improvement
8.1 A documented QAIP covering internal monitoring, periodic internal assessment and external assessment.
8.2 Ongoing monitoring embedded in engagement supervision and review.
8.3 Periodic internal self-assessment against the IPPF.
8.4 External quality assessment at least every five years, by a qualified, independent assessor — with the next date known.
8.5 QAIP results reported to the audit committee, including any statement of non-conformance.
8.6 Improvement actions tracked to closure like any other finding.
9 — People and capability
9.1 Skills matrix against the plan, identifying where the function lacks the technical capability to audit what it has committed to.
9.2 Cybersecurity audit capability specifically — the regulated obligations in section 7 are technical engagements.
9.3 Continuing professional development tracked per auditor.
9.4 Use of external specialists where capability is absent, with the sourcing route agreed in advance rather than negotiated mid-plan.
Get the downloadable checklist
The full checklist — a working spreadsheet with state, owner, evidence reference, last-reviewed date and next-due columns, plus the regulated frequencies in section 7 pre-loaded as a tracker — is available on request. Contact us to receive a copy.
For the wider discipline, read the internal audit in Saudi Arabia guide. For the planning cycle, see risk-based internal audit and the audit universe template. For running a framework engagement, see the compliance audit playbook.
To run this checklist as a live programme — universe, plan, engagements, recommendations and committee reporting connected rather than spread across spreadsheets — see GRC Vantage's audit module.
Book a demo with the GRC Vantage team in Riyadh or Dammam.
See Audit Management →
The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.
Related articles
How to choose internal audit management software in Saudi Arabia — the selection criteria that decide it, IIA/IPPF alignment, and a capability scorecard.
A practical playbook for compliance audit in Saudi Arabia — scoping, evidence, fieldwork and reporting against SAMA CSF, NCA ECC, PDPL and ISO 27001 in 2026.
A free IIA-aligned internal audit universe template for Saudi internal audit functions — auditable units, risk rating, planning columns, downloadable Excel.