# GeNext MedEd Foundation — Internal Audit Schedule & Register

**Document code:** GMEF-QA-002
**Version:** 1.0
**Status:** Controlled working register

| Audit ID | Domain / programme | Scope | Risk basis | Planned date | Reviewer | Evidence sampled | Findings | CAPA reference | Closure status |
|---|---|---|---|---|---|---|---|---|---|
| | | | Routine / Elevated / Triggered | | | | | | Planned / Open / Verified closed |

## Minimum audit cycle
At least annual review of core institutional domains, with more frequent review for active high-volume programmes, newly launched systems or elevated-risk areas.

## Triggered audit examples
Certificate discrepancy; serious participant complaint; privacy/data incident; research-governance concern; repeated assessment variance; host-centre change; material partner-role misrepresentation; resource-rights complaint; unresolved corrective action.

## Independence
Where practical, the reviewer should not be the sole owner of the process being audited. Conflicts are disclosed and recorded.

## Sampling
Audit may sample approvals, attendance, assessments, certificates, faculty records, site evidence, research records, library permissions, version history and archive bundles. Sampling does not replace mandatory review of a known serious concern.
