KITE 2025 New Product Award โ€” Local IT | SACEEC
Internal audit

An audit plan your risks drove

Good practice expects the risk register to direct where internal audit spends its time. Dimeri holds that link directly, so the reconciliation your audit committee asks for is a report rather than a project.

Annual audit planRisk based

A risk based annual plan

Why findings keep coming back

The plan cannot be traced to risk

The audit plan and the risk register are separate documents, so when an auditor asks which risks drove which engagements there is no answer on paper.

Agreed actions quietly lapse

Management agrees a remediation date, the engagement closes, and follow up falls away. The finding reappears next cycle as a repeat.

Follow up depends on one person

Tracking lives in a spreadsheet owned by the audit manager, so follow up stops when they are on leave or move on.

Assurance overlaps and gaps

Three providers test the same well controlled process while a material risk goes untested for years, because the full picture is split across documents.

Run internal audit the steady way with Dimeri

The plan derived from the register

Each engagement is tied to the risks that justify it, so the rolling three year plan and the annual plan both reconcile to exposure on demand.

One combined assurance map

Management assurance, internal audit and external providers on one grid against the significant risks, with duplication and gaps both visible.

Findings owned in the business

Every finding is an action with a named owner, a due date and escalation, carried forward automatically until it is closed with evidence.

A position that stays current

Engagement status, findings and follow up update as the work happens, so the committee pack reflects today rather than the last reporting date.

A clear path to risk based assurance

Four steps from an audit plan built on habit to one built on exposure.

Book a demo

The significant risks are ranked and the engagements that would give assurance over them are identified. Where a high risk is deliberately not audited, the reason is recorded rather than left implicit.

Built for clarity, designed for control

The plan, the engagement, the finding and the committee pack are one record seen from different angles.

Annual audit planRisk based

Annual audit plan

Engagements with their phase, resourcing and progress, each traceable back to the risks that justified it.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Coverage against exposure

Every significant risk on one axis and planned assurance on the other, so uncovered cells are obvious.

Treatment planQ3
2 of 4 closed1 overdue
โœ“Dual supplier for critical sparesClosedT. Mokoena ยท 12 Aug20 โ†’ 9
โœ“Quarterly access recertificationClosedN. Adeyemi ยท 29 Aug16 โ†’ 8
Contractor induction refreshOn trackS. Naidoo ยท 04 Sep12 โ†’ 12
Pipeline integrity inspectionOverdueL. Dlamini ยท 22 Jul15 โ†’ 15

Findings and follow up

Actions with owners, due dates and status, carried across cycles until closed with evidence.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Control testing

Preventive, detective and corrective controls with test results feeding straight back into control effectiveness.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Audit committee pack

Generated from live engagement and finding data, so the pack and the platform cannot disagree.

When internal audit becomes a business advantage

The reconciliation is a report

When the committee or the Auditor-General asks which risks drove the plan, the answer is a view rather than a week of reconstruction.

Repeat findings drop

Findings stay open with an owner and escalation until evidence closes them, which removes the most common and most expensive audit outcome.

Assurance effort goes where it counts

The combined assurance map reallocates testing from well controlled processes to the exposures that have gone untested.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.

FAQ

Frequently Asked Questions

What is internal audit management software?
Internal audit management software is a platform that helps audit teams plan engagements, execute fieldwork, track findings, and generate reports in one place. Instead of managing audit plans in spreadsheets and findings in email threads, teams use a centralised system with workflows, evidence management, and real-time status tracking. Dimeri is internal audit software built for African organisations.
Who needs internal audit software?
Any organisation with an internal audit function benefits from dedicated software. This includes listed companies, public sector entities, financial institutions, SOEs, and any business with an audit committee or regulatory oversight. If your audit team manages more than a handful of engagements per year, software replaces manual tracking with structured, repeatable processes.
What audit standards does Dimeri support?
Dimeri aligns to the IIA International Standards for the Professional Practice of Internal Auditing, King IV requirements for internal audit, and PFMA requirements for public sector entities. The platform accommodates risk-based audit planning, engagement workflows, and reporting structures aligned to these standards.
How does Dimeri connect audit findings to risks and controls?
Every audit finding in Dimeri can be linked to risks in your risk register and controls in your controls library. When a finding identifies a control weakness, that link updates the control effectiveness score automatically. This gives your audit committee a direct line of sight from audit results to risk exposure.
Is Dimeri free to use for internal audit?
Yes. Dimeri offers a free workspace that includes audit planning, engagement management, findings tracking, and up to three users. You can upgrade when you need more users, additional modules like workpaper management or automated reporting, or premium integrations. No credit card is required to start.

Still have questions? Talk to our team โ†’