Risk, controls, and findings — one audit trail your team can defend
A single Odoo-native system for the full internal-audit lifecycle: risk register, control library, control testing, findings, remediation, and compliance frameworks — with a guided, role-based workflow a non-specialist can run from day one.
The problem
Audit programs get stitched together from spreadsheets, email threads, and shared drives. Risk registers, control-test evidence, and findings trackers live in separate files with no connection to the ERP where the business actually happens. When an auditor or regulator asks how a control was tested and what was done about the exception, the team spends days reassembling a trail that should already exist.
The solution
Internal Audit Controls puts the entire lifecycle — risk, control, test, finding, remediation, evidence — inside Odoo as one connected system. Every control links to the risk it mitigates, every test feeds a live effectiveness score, and every failed test automatically raises a tracked finding with an owner and a due date, so the record builds itself as the work happens.
Everything an audit program needs, connected
Every capability below is implemented in the module.
Scored Risk Register
Score every risk by likelihood and impact on a 5x5 scale, with inherent and residual ratings that recalculate automatically as controls are added and tested.
Risk-Linked Control Library
Build a library of preventive, detective, and corrective controls, each tied to the risk it mitigates and assigned to an accountable owner and department.
Evidence-Based Control Testing
Record sample size, exception count, and evidence for every test. Pass, partial, and fail results are derived automatically from the exception ratio.
Automatic Findings from Failed Tests
A failed control test raises a finding on the spot, with severity, owner, and a 30-day due date already set — no manual re-entry.
Segregation of Duties & Locked Results
A control test's reviewer can never be the same person as its tester, and a validated test's results are locked from further edits, preserving a defensible record.
Findings & Remediation Lifecycle
Track findings from draft through resolution with management sign-off, overdue escalation, and a full status history for every case.
Audit Engagements with a Report-Readiness Gate
Scope engagements to specific risks and controls, then close them only after a guided wizard confirms nothing required is missing from the report.
Compliance Framework Tracking
Map controls to requirements from ISO 27001, ISO 9001, GDPR, SOX-lite, NIS2, and DORA, with a live compliance rate calculated per framework.
Role-Based Security & Dashboards
User, Auditor, and Manager roles enforce segregation of duties out of the box, backed by dashboards that roll up risk, testing, and findings in one view.
How it works
Log the risk
Register a risk, score its likelihood and impact, and assign an owning department.
Attach controls
Link preventive, detective, or corrective controls to the risk and assign an owner.
Test and record
Test each control on schedule, log sample size and exceptions, and validate the result.
Close the loop
Failed tests raise findings automatically; track remediation through to sign-off and closure.
Frequently asked
No sales fog. If your question isn't here, email us and we'll answer it the same way.
Internal Audit Controls is available for Odoo 19, 18, and 17 Community and Enterprise.
Buy it on the Odoo App Store
Purchase, download and install directly from the official Odoo Apps Store — you'll always get the latest supported build.
Internal Audit Controls
A scored risk register, risk-linked controls, evidence-based testing that raises findings automatically, remediation tracking and compliance frameworks — with segregation of duties and locked results.
Buy on Odoo App Store