OSB Group plc · Internal Audit

Audit software built for the career you've already earned.

AuditPilot replaces the spreadsheet, the email chain and the risk register nobody's opened since 2019 with one system: documentation, plan oversight, audit universe and risk, issues and actions. Built so the hours you'd spend chasing evidence go back to the judgement calls only you're qualified to make — not the way an enterprise vendor imagined it in 2004.

AUD-2026-0142 Third-party payment risk review
Planning
Fieldwork
Review
Finalised
Risk: High Owner: P. Raghavan 2 steps · 1 open action
14:02D. Cheung marked step 3.2 Prepared
14:11T. Whitfield requested changes — step 3.2
14:19P. Raghavan finalised Fieldwork
14:24Reviewer queue: 1 waiting

What changes

What you inherit, and what you get instead.

What you inherit
What you get
A risk register that's a file called FINAL_v3(2).xlsx
One audit universe, scored and revisited on a real cadence
Chasing an action owner over email until someone remembers
One owner, one due date, per action — visible to them too
Reviewing your own work because nobody's watching
The system refuses a self-review. Every time.
Finding out who approved what by asking around
An append-only log of who did what, when — no hallway archaeology

The scope, as named on the call

Four things it actually runs.

CAP.01

Audit documentation

Steps, evidence and sign-off in one workflow — prepared, reviewed, finalised. Not a version-numbered Word document passed round by email.

CAP.02

Plan oversight

The annual plan as a live object you open and close cycles against, not a slide that's already wrong by February.

CAP.03

Audit universe & risk assessment

Every auditable entity scored and ranked, revisited on a schedule instead of rediscovered once a year under deadline.

CAP.04

Issue & action management

Ratings, owners, due dates. An action that goes quiet gets flagged overdue automatically — not three months later, in the next audit.

Built around how the team already works

Your queue. Your team. Your evidence — not spread across five inboxes.

D. CheungUSR-014
Preparer

Owns the fieldwork on step 3.2, evidence attached and versioned — nothing chasing him by email a week later.

T. WhitfieldUSR-009
Reviewer

Sign-off with a real queue: exactly what's waiting on him, nothing buried in an inbox.

P. RaghavanUSR-002
Plan & universe owner

Opens cycles, closes cycles, imports data — runs the plan instead of reporting on it after the fact.

N. PetrovaEXT-031
Action owner (external)

Sees her one action in a portal built for her — not IA's internal system with her name in a spreadsheet.

Why it holds up

Nothing happens off the record.

✓

Real password authentication, not a shared login — accounts lock for 15 minutes after five failed attempts.

✓

Every create, edit and decision writes to the same append-only log the rest of the app reads from — "who signed this off" is a query, not a Slack thread.

✓

Admin-managed accounts with forced password changes on first sign-in — no standing passwordless shortcuts.

EVENT LOG audit.db
09:41Admin reset password for USR-014
09:44USR-014 signed in, forced change
11:02USR-002 opened cycle FY26-Q3
11:15Action AP-114 flagged overdue
11:19USR-009 declined step 3.2

Ready when you are

Built for the internal audit function as it actually runs today — not the one a vendor imagined.

Sign in with your OSB Group credentials, or read the help guide first if you're new to the system.