Internal audit software · Free Excel workbook
The internal audit software requirements matrix.
156 requirements for buying audit management software, weighted for the size of your function and scored for up to five vendors, with the 25-scenario demo scorecard, the reference-call questions and a response form to send with the RFP. It is the ready-to-fill version of the method in selecting an audit management system.
- Free, no sign-up
- 156 requirements in 10 areas
- Scores up to 5 vendors
- Must-have knock-outs
- Mapped to the Global Internal Audit Standards
An Excel file built on formulas only: no macros, no add-ins, no email address asked for. Version 1.1, September 2026. No software vendor has paid for, seen or approved it.
What is in the workbook
Six working sheets and a start page.
The start page explains the method on one page. Everything you fill in is yellow, and everything else calculates or explains, so the workbook runs without a vendor or a consultant.
Setup
Name the function, pick the team size and name up to five vendors. The area weights fill in for your size and can be moved, with a column for the reason behind each move.
Requirements
The 156 lines, each with a suggested priority, the scorecard area it evidences, the standards it supports, the demo scenario that tests it and how to verify the answer. Twenty blank rows take your own.
Summary
Score by area and by vendor: the weighted score out of 100, must-haves not met, must-haves met only through paid customization, lines still unanswered, the could-have tie-breaker, the demo score, a status and a rank.
Demo scorecard
The 25 scenarios from the demo script, scored 0 to 3 with a weight you set before the first demo, rolled up into the twelve scorecard areas.
Reference calls
Nine questions to ask in order, what a good answer sounds like and what to probe when it does not, with space for each vendor’s notes.
Response form
The vendor-facing sheet: one row per requirement and one column per response code, with a Code column that pastes back into the Requirements sheet row for row.
The ten areas and their starting weights
Weights decide more than the list does.
Every system on the market claims every capability on a requirements list, so products separate on the weights. The eight core areas carry the starting weights from the RFP method for three sizes of function; each column adds to 100. The two optional areas start at zero: give them points only if SOX testing or AI capability is part of the decision, and take the points from another row. The RFP method scores AI through the data-use and roadmap lines, which is why that area starts at zero.
| Area | Lines | Must | Should | Could | 1 to 5 auditors | 6 to 25 auditors | More than 25 |
|---|---|---|---|---|---|---|---|
| Universe, risk assessment and planning | 19 | 4 | 8 | 7 | 15 | 15 | 12 |
| Engagement workflow and workpapers | 25 | 8 | 13 | 4 | 25 | 22 | 18 |
| Issue and action tracking | 18 | 6 | 8 | 4 | 25 | 20 | 15 |
| Reporting and dashboards | 15 | 2 | 9 | 4 | 15 | 12 | 12 |
| Analytics, integration and data | 16 | 2 | 8 | 6 | 5 | 10 | 15 |
| Security and administration | 18 | 6 | 10 | 2 | 8 | 10 | 13 |
| Usability and adoption | 10 | 0 | 6 | 4 | 5 | 6 | 5 |
| Vendor viability and service | 13 | 4 | 6 | 3 | 2 | 5 | 10 |
| SOX and controls testing (optional) | 12 | 3 | 7 | 2 | 0 | 0 | 0 |
| AI features (optional) | 10 | 2 | 5 | 3 | 0 | 0 | 0 |
Must, should and could are the site’s suggested priorities; you set your own in the workbook. 34 of the lines (A1 to A6, B1 to B7, C1 to C6, D1 to D4, E1 to E5 and F1 to F6) are the requirements template published in the RFP method, word for word.
How the scoring works
Codes, not prose. Formulas, not feelings.
Vendors answer each line with one of five codes rather than a paragraph, because prose answers are where “yes” turns into “yes, with services”. The codes are also the scoring key.
- Five response codesStandard scores 1.00 (available now, in the base product, shown in the demo). Configuration 0.75 (an administrator can do it without the vendor). Customization 0.25 (vendor development or paid services). Roadmap and Not available score zero.
- Three prioritiesM for must: a product that cannot meet it is out, whatever its score. S for should: it scores. C for could: it breaks ties. Out takes a line off the list without deleting it.
- Area scoresPoints earned on an area’s must and should lines, divided by the number of those lines. An unanswered line counts as zero and is counted separately, so gaps cannot hide.
- The weighted scoreEach area’s score times its weight, added up and scaled to 100. Could lines stay out of it and appear as a separate tie-breaker.
- Knock-outsRoadmap or Not available on a must line puts a vendor out. Customization on a must line keeps it in but is shown on its own row, because it means paying for services.
- The demo sits beside itThe demo score and the reference calls are reported next to the requirements score, not blended into it, so a strong demo cannot paper over a failed must-have.
Seven steps
From blank workbook to a defensible shortlist.
- Set up the function.Team size, vendor names and, if your function differs from the defaults, new weights with the reason written next to each move.
- Set the priorities before any vendor sees the list.Read every line and mark it must, should, could or out. A list with too many musts ranks nobody, because every product fails one of them.
- Send the response form with the RFP.Copy the form into a new workbook, paste columns A to C as values, keep every row (out lines stay struck through) and require one code per line. Give vendors two to three weeks.
- Paste the codes back.Each returned form has a Code column; paste it as values into that vendor’s column on the Requirements sheet, starting at row 6. The rows line up because none were deleted.
- Read the Summary, then chase the gaps.Unanswered lines and must-haves met only through customization are the follow-up questions for the next round.
- Run the demo script with the finalists.Score the 25 scenarios on your own data, with weights set before the first session.
- Make the reference calls.Ask the nine questions in order and write the answers up the same day. Score nothing: what you hear belongs in the contract.
Mapped to the Global Internal Audit Standards
Why each requirement matters to an audit function.
102 of the 156 lines carry a reference to the standard they help a function evidence, 37 different standards in all, from engagement documentation (14.6) and monitoring action plans (15.2) to the internal audit plan (9.4) and protection of information (5.2). A system does not make a function conform; it makes the evidence of conformance cheaper to produce and easier to show an external assessor. The standard behind the purchase itself is 10.3, Technological Resources. The guide to the Global Internal Audit Standards explains each one.
- 5.2 Protection of Information
- 14.6 Engagement Documentation
- 15.2 Confirming the Implementation of Recommendations or Action Plans
- 9.4 Internal Audit Plan
- 14.1 Gathering Information for Analyses and Evaluation
- 12.3 Oversee and Improve Engagement Performance
- 12.2 Performance Measurement
- 9.3 Methodologies
- 14.2 Analyses and Potential Engagement Findings
- 14.3 Evaluation of Findings
Standard numbers and names are from the IIA’s Global Internal Audit Standards, effective 9 January 2025. internalauditguide.com is not affiliated with or endorsed by The Institute of Internal Auditors. 70 lines also name the demo scenario that tests them.
Questions
About the requirements matrix.
Is the workbook free?
Yes. There is no sign-up and no email gate: the download button is a direct link to the file. It is free to use and adapt inside your organization.
Does it favor any product?
No. It ranks no product and scores nobody until you enter the answers; the only product names in it are examples of tools to integrate with, such as Microsoft Teams, Jira or Power BI. No vendor has paid for, seen or approved it, and this site takes no vendor money of any kind, as the review method explains.
We are a team of three buying our first system. Is this overkill?
Set the team size to 1 to 5 auditors, mark the lines you do not need as out, and keep the must list short. The weights for small functions put issue tracking and the engagement workflow first, which is where a first system earns its cost. The guide to audit software for small teams covers real prices.
Can we add our own requirements?
Yes. Twenty blank rows at the end of the Requirements sheet take your own lines; pick an area for each and they flow into the scoring, the must-have checks and the response form.
Why does one failed must-have knock a vendor out?
Because that is what must means. If a product can be forgiven a missing must, the line was a should. Customization on a must line is different: the product can do it for a price, so it stays in and the Summary shows the count.
How does it fit with the demo script and due diligence?
The matrix is the paper round, the demo script is the live round, and due diligence covers security, data, AI and ownership questions in depth. 70 lines in the matrix name the demo scenario that tests them.