Could your audit function evidence
every review it owes?
Answer 15 questions across four domains. Get an instant maturity score against the IIA IPPF and the review obligations SAMA and the NCA impose — including the CSCC independent review on a three-year clock that most functions are not counting.
How ready is your internal audit function?
15 questions across 4 control domains. One at a time. Keyboard-driven. You'll get an instant maturity score and a prioritised remediation roadmap in under five minutes.
What happens when you finish
Your full results are instant — score, domain breakdown and priority gaps, no email required. Optionally enter your email on the results screen to receive the report in your inbox.
See your overall readiness percentage and where the function sits — Initial, Developing, Defined or Managed.
Understand whether independence, planning, engagement quality or the regulated reviews is your weakest link.
Walk away with your top 3 gaps ranked, including any fixed-frequency obligation that has slipped its window.
Run the audit function on connected data
Universe, annual plan, engagements, working papers, recommendations and committee reporting in one place — with the SAMA and NCA control libraries already mapped, so a compliance audit draws on evidence you have already collected.
Universe to committee pack
One connected chain — auditable unit, risk rating, plan, engagement, finding, recommendation, committee report.
Regulated review tracker
The fixed-frequency obligations held with owners and next-due dates, counted from the last completion rather than intent.
Evidence collected once
Working papers captured against control references, so an audit of SAMA CSF and one of NCA ECC share the same evidence store.
Frequently asked questions
- What is the Internal Audit Readiness Assessment?
- A free, interactive self-assessment that measures an internal audit function's maturity against the IIA International Professional Practices Framework (IPPF) and the specific review obligations SAMA and the NCA impose on Saudi entities. It covers 4 domains — Charter and Independence, Audit Universe and Planning, Engagement and Reporting, and Regulated Reviews and QAIP — and returns your full results instantly — with an optional email report.
- Which regulator obligations does the assessment cover?
- NCA CSCC control 1-4-1, which requires the cybersecurity function to review CSCC implementation at least annually, and control 1-4-2, which requires a review by parties independent of that function at least every three years. It also covers NCA ECC subdomain 1-8 on periodical cybersecurity review and audit, DCC 1-1, OTCC 1-6, the SAMA CSF internal audit requirement, and the IPPF external quality assessment due at least every five years.
- Who is the assessment for?
- Heads of Internal Audit and audit managers at Saudi organisations — banks and insurers supervised by SAMA, government entities and critical national infrastructure operators regulated by the NCA, and large private enterprises running an internal audit function against the IPPF.
- Why does the reporting line matter to the score?
- Independence is both an IPPF requirement and a precondition for satisfying NCA CSCC control 1-4-2, which requires reviewers independent of the cybersecurity function. An internal audit function reporting through IT or through the CISO cannot satisfy that control regardless of the quality of its work, so the assessment weights the reporting line heavily.
- How long does the assessment take?
- The assessment has 15 questions and takes approximately 4 to 5 minutes to complete. Your full results appear instantly with no signup; you can optionally enter your email to receive the report in your inbox.
Run another readiness assessment
Score your maturity against the other Saudi frameworks — same conversational format, same instant results.
NCA ECC Readiness
Score your cybersecurity maturity across the four NCA ECC-2:2024 domains.
Start AssessmentNCA CSCC Readiness
Score your critical-systems protection against the NCA CSCC overlay.
Start AssessmentSAMA CSF Readiness
Score your cybersecurity maturity against the Saudi Central Bank Cyber Security Framework.
Start AssessmentSAMA IT Governance
Score your IT governance maturity against the SAMA IT Governance Framework.
Start AssessmentSAMA Third-Party Risk
Score your outsourcing maturity against the SAMA Outsourcing Regulations.
Start AssessmentBCM Readiness
Score your business continuity maturity against ISO 22301 and the SAMA BCM Framework.
StartStart your internal audit assessment — it takes under 5 minutes.
Free. Instant results. No commitment. Built for Heads of Internal Audit at Saudi organisations.
Take the assessment