1 · Assess
Start with the risk and audit plan
Define the entities, branches, systems and regulatory priorities that need assurance.
For SACCOs
Murikah supports regulated SACCOs with co-sourced internal audit, technology assurance and Assurance OS, so findings move from fieldwork to owned action and board follow-up in one evidence trail.
What matters
SASRA publishes corporate-governance and risk-management guidance for regulated SACCOs. The practical audit question is whether the board can see the evidence, the risk and the status of management action clearly.
1 · Assess
Define the entities, branches, systems and regulatory priorities that need assurance.
2 · Evidence
Keep work papers, review notes, findings, owners and due dates connected.
3 · Report
Report the same findings and actions management is already updating rather than recreating the pack.
Regulatory reference: SASRA corporate-governance guidance ↗ and SASRA risk-management guidance ↗.
For SACCO audit leaders
Bring the current plan, open findings and reporting pain points. We will identify the smallest useful starting scope.