See Audithink's Latest Events →

Internal Audit Application for GCG: Implementation Guide for State-Owned Enterprises and Government Agencies

internal audit application for gcg

Topic Recommendations

Share Article

Ready To Improve Your Internal Audit Process?

Discover Audithink's full features and choose a pricing plan that works for your audit team. Start audit transformation now!

Table Of Contents

The internal audit application for GCG is a digital system that manages the entire internal audit cycle — from risk-based planning, implementation, working paper documentation, to follow-up monitoring — so that the internal audit function can produce documented, traceable, and audit-ready evidence of governance compliance.

For state-owned enterprises (BUMN), regionally-owned enterprises (BUMD), and government agencies, implementing good corporate governance is no longer merely a formality. Minister of State-Owned Enterprises Regulation No. PER-2/MBU/03/2023 emphasizes that SOEs are required to implement the principles of transparency, accountability, responsibility, independence, and fairness, and must have Internal Control System (ISC) and information disclosure policies. Consequently, the Internal Audit Unit is required to provide a reliable audit trail at all times—something that is difficult to achieve with spreadsheet-based management and scattered documents.

This article discusses the relationship between internal audit and GCG, mandatory features of GCG internal audit software, selection criteria, and implementation steps in public sector organizations and regulated corporations.

The Relationship Between Internal Audit and GCG Implementation

Internal audit is one of the main pillars in the governance structure. Within the framework three lines model Promoted by The Institute of Internal Auditors (IIA), internal audit occupies the third line: providing independent assurance on the effectiveness of internal control and risk management to the Board of Commissioners and the Audit Committee.

The contribution of internal audit to the five GCG principles can be mapped as follows:

GCG PrinciplesContribution of Internal Audit Function
TransparencyProvide audit results reports that are documented and can be traced back to the source of evidence.
AccountabilityEnsure each finding has a risk owner (risk owner) and clear follow-up PIC
AccountabilityTesting business process compliance with regulations and internal policies
IndependencyMaintaining separation of assurance functions from the operational functions being audited
FairnessEnsuring equal treatment between stakeholders through control testing

The problem is, without system support, these contributions are often inadequately substantiated. Audit findings recorded in separate documents, working papers disconnected from supporting evidence, and follow-up status updates only prior to Audit Committee meetings are commonplace—and actually pose weaknesses when assessing an organization's governance maturity.

Why Organizations Need Internal Audit Applications for GCG

1. The Need for a Traceable Audit Trail

GCG maturity assessment requires evidence, not statements. Internal audit application record every activity — who created the working paper, who reviewed it, when the findings were approved, and how they were changed — in audit log which cannot be modified. This track record is the basis for proving accountability.

2. Consistency of Risk-Based Audit Methodology

Risk-Based Internal Audit (RBIA) requires that the preparation of the Annual Supervisory Work Program (PKPT) be based on the organization's risk map, not on previous years' practices. A good system links the risk register to the audit object, so that the allocation of supervisory resources can be methodologically justified.

3. Acceleration of Follow-up Monitoring

The completion rate of audit recommendations is an indicator frequently highlighted by the Audit Committee and external auditors. GCG internal audit software allows for accurate monitoring of follow-up status. operated, complete with automatic notification to the PIC and escalation of recommendations that pass the deadline.

4. Reports Ready to be Presented to the Board of Commissioners

Manually preparing monitoring reports takes up auditor time that could be used for substantive testing. A centralized dashboard allows for a direct presentation of the findings profile, risk distribution, and follow-up progress, eliminating the need for repetitive recapitulation processes.

Mandatory Features in GCG Internal Audit Software

The following features need to be available in an internal audit application to adequately support the implementation of GCG:

  1. Risk management and preparation of risk-based PKPT — mapping organizational risks to determine audit object priorities in a measurable manner.
  2. Audit assignment management — team formation, allocation of working hours, and monitoring progress per assignment stage.
  3. Audit papers digital (electronic working paper) — preparation of structured working papers with direct linking of audit evidence.
  4. Multi-level review flow — approval mechanism from team leader, technical controller, to quality controller according to professional standards.
  5. Management of findings and follow-up — recording findings, recommendations, PIC, deadlines, and completion status.
  6. Centralized audit evidence repository — storage of supporting documents with version control and access rights.
  7. Executive dashboard and reporting — visualization of supervisory performance for the needs of the Board of Directors, Audit Committee, and Board of Commissioners.
  8. Role-based access control (RBAC) — access restrictions according to authority to maintain the independence and confidentiality of audit data.
  9. Audit trail system — recording all user activity as proof of data integrity.
  10. Whistleblowing system integration — linking violation reports with special audit processes, in line with the obligation to implement WBS in BUMN.

See also: 7 Best Internal Audit Software Recommendations for Businesses in 2026

Internal Audit Application Selection Criteria for GCG

Before making a choice, it is recommended to evaluate candidate systems based on the following criteria:

  • Compliance with Indonesian regulations — The system must accommodate the SPIP framework (PP No. 60 of 2008), AAIPI standards for APIP, and applicable BUMN Ministerial Regulations. Applications designed for foreign jurisdictions generally require significant adjustments.
  • RBIA methodology support — ensure the system links risks to audit objects, not just provides digital forms.
  • Workflow configuration capabilities — the tiered review structure differs between the BUMN SPI and the Regional Inspectorate; the system needs to be adaptable.
  • Data security and sovereignty — pay attention to the options for placing servers domestically, data encryption, and compliance with the Personal Data Protection Act.
  • Integration capabilities — connectivity with existing financial systems, ERP, or risk management applications.
  • Implementation support and mentoring — availability of assistance in developing methodologies, auditor training, and Indonesian-language technical support.
  • Scalability — the system's ability to serve additional work units, subsidiaries, or supervisory areas without reducing performance.

Steps for Implementing Internal Audit Applications in Organizations

  1. Initial condition mapping — inventory of the ongoing audit process, documents used, and major bottlenecks.
  2. Methodological coordination — ensure internal audit charters, audit guidelines, and risk frameworks are up to date before digitizing.
  3. System configuration — adjustment of the supervisory organizational structure, review flow, working paper format, and report templates.
  4. Historical data migration — transfer of open findings and unfinished recommendations for continuous monitoring.
  5. User training — provision of auditors, PIC of work units, and leaders according to their respective roles.
  6. Limited trial — implementation on one to two audit assignments as pilot project.
  7. Comprehensive implementation and periodic evaluation — expansion to all assignments accompanied by evaluation of effectiveness each period.

Digitizing the audit process should not precede methodological improvements. A good system will accelerate correct processes, but it will also accelerate the replication of incorrect ones.

Frequently Asked Questions

What is an internal audit application for GCG?

The internal audit application for GCG is a system that digitally manages the internal audit cycle — from risk-based planning, implementation, working papers, to follow-up monitoring — to produce traceable and accountable evidence of governance implementation to the Audit Committee and external auditors.

Are state-owned enterprises required to use internal audit software?

The regulation doesn't mandate the use of specific software. However, Ministerial Regulation of the State-Owned Enterprises No. PER-2/MBU/03/2023 requires SOEs to have an Internal Control System and implement a whistleblowing system, making system support a practical necessity to meet these documentation and reporting requirements.

What is the difference between an internal audit application and a GRC application?

Internal audit applications focus on the auditor's work cycle: assignments, workpapers, findings, and follow-up. GRC applications have a broader scope, encompassing governance, corporate risk management, and compliance. Some platforms, including those based on the RBIA methodology, combine the two in a single integrated system.

How long does an internal audit application implementation typically take?

The duration depends on the organization's complexity and methodology readiness. Implementation within a single internal audit unit typically takes several weeks to several months, including configuration, data migration, training, and limited testing.

Can the internal audit application be used by the Regional Inspectorate?

Yes, as long as the system accommodates the SPIP framework and government internal audit standards (AAIPI). The main adjustments typically lie in the PKPT structure, the Audit Result Report format, and the review process in accordance with APIP regulations.

Strengthening GCG Implementation with an Integrated Internal Audit System

The implementation of Good Corporate Governance requires documented evidence, not just written commitments. Audithink is present as an internal audit application based on the Risk-Based Internal Audit methodology designed for the needs of BUMN, BUMD, government agencies, and regulated industries in Indonesia — covering risk-based planning, digital work papers, findings management, and follow-up monitoring in one integrated platform.

Schedule a consultation with our team to discuss your organization's specific needs and see firsthand how Audithink supports strengthening governance in your workplace.

Find out how the implementation of the audit application can have a positive impact on the company on an ongoing basis.

Consultation on Your Needs

Related Articles

internal mining audit software recommendations
information system audit application
internal audit software for banks