Risk, controls, and findings — one audit trail your team can defend

A single Odoo-native system for the full internal-audit lifecycle: risk register, control library, control testing, findings, remediation, and compliance frameworks — with a guided, role-based workflow a non-specialist can run from day one.

The problem

Audit programs get stitched together from spreadsheets, email threads, and shared drives. Risk registers, control-test evidence, and findings trackers live in separate files with no connection to the ERP where the business actually happens. When an auditor or regulator asks how a control was tested and what was done about the exception, the team spends days reassembling a trail that should already exist.

The solution

Internal Audit Controls puts the entire lifecycle — risk, control, test, finding, remediation, evidence — inside Odoo as one connected system. Every control links to the risk it mitigates, every test feeds a live effectiveness score, and every failed test automatically raises a tracked finding with an owner and a due date, so the record builds itself as the work happens.

Capabilities

Everything an audit program needs, connected

Every capability below is implemented in the module.

01

Scored Risk Register

Score every risk by likelihood and impact on a 5x5 scale, with inherent and residual ratings that recalculate automatically as controls are added and tested.

02

Risk-Linked Control Library

Build a library of preventive, detective, and corrective controls, each tied to the risk it mitigates and assigned to an accountable owner and department.

03

Evidence-Based Control Testing

Record sample size, exception count, and evidence for every test. Pass, partial, and fail results are derived automatically from the exception ratio.

04

Automatic Findings from Failed Tests

A failed control test raises a finding on the spot, with severity, owner, and a 30-day due date already set — no manual re-entry.

05

Segregation of Duties & Locked Results

A control test's reviewer can never be the same person as its tester, and a validated test's results are locked from further edits, preserving a defensible record.

06

Findings & Remediation Lifecycle

Track findings from draft through resolution with management sign-off, overdue escalation, and a full status history for every case.

07

Audit Engagements with a Report-Readiness Gate

Scope engagements to specific risks and controls, then close them only after a guided wizard confirms nothing required is missing from the report.

08

Compliance Framework Tracking

Map controls to requirements from ISO 27001, ISO 9001, GDPR, SOX-lite, NIS2, and DORA, with a live compliance rate calculated per framework.

09

Role-Based Security & Dashboards

User, Auditor, and Manager roles enforce segregation of duties out of the box, backed by dashboards that roll up risk, testing, and findings in one view.

Workflow

How it works

1

Log the risk

Register a risk, score its likelihood and impact, and assign an owning department.

2

Attach controls

Link preventive, detective, or corrective controls to the risk and assign an owner.

3

Test and record

Test each control on schedule, log sample size and exceptions, and validate the result.

4

Close the loop

Failed tests raise findings automatically; track remediation through to sign-off and closure.

Questions

Frequently asked

No sales fog. If your question isn't here, email us and we'll answer it the same way.

Internal Audit Controls is available for Odoo 19, 18, and 17 Community and Enterprise.

Get the app

Buy it on the Odoo App Store

Purchase, download and install directly from the official Odoo Apps Store — you'll always get the latest supported build.

Internal Audit Controls

A scored risk register, risk-linked controls, evidence-based testing that raises findings automatically, remediation tracking and compliance frameworks — with segregation of duties and locked results.

Buy on Odoo App Store