Discover powerful Dolibarr extensions designed to automate your business processes

Audit & Control Management is a premium Dolibarr module that transforms Dolibarr into a complete ERP platform dedicated to audit management and management control. It is designed for audit firms, consulting firms, finance departments, management-control departments, statutory auditors, internal-audit services and any organisation that needs to run 100% of its audit and controlling activity inside Dolibarr — without any additional software.
The module covers the full audit lifecycle (planning, execution, findings, recommendations, action plans, follow-up, reporting) as well as the management-control cycle (cost centers, budgets, variance analysis, KPIs, forecasts and financial analyses), all connected to native Dolibarr objects.
· Internal audit
· External audit
· Financial audit
· Accounting audit
· Operational audit
· Organisational audit
· Quality audit
· Risk audit
· IT audit
· Compliance audit
· Internal control, budget control and management control
· Audit firms and consulting firms
· Finance and management-control departments
· Statutory auditors and internal-audit services
· Any company running audits, risk mapping or budget control
The module follows the standard Dolibarr MVC architecture (CommonObject business classes, generic list/card engine, triggers, cron jobs, permissions and multi-entity support) to guarantee compatibility with future Dolibarr versions. It is built around 22 business objects grouped in six hubs (audited client, audit plan, audit mission, checklist, action plan and budget) with automatically discovered bidirectional links.
Rather than duplicating existing functionality, the module enriches native Dolibarr. Every audit mission and record can be linked to native objects:
· Third parties, contacts and users
· Projects and tasks
· Quotes, orders and invoices (customer & supplier)
· Accounting and banking
· Document management (ECM/GED)
· Agenda, categories and the REST API
· Multi-company / multi-entity setups
All objects share a common structure (reference, status, creation/modification tracking, multi-entity) and are driven by a generic engine providing lists with multi-criteria filters, column show/hide, sortable columns, and cards with a KPI cockpit plus linked-record panels for one-click connected data entry.
|
Object |
Kind |
Key attributes |
|
Audited clients |
Hub |
Company profile, sector, headcount, revenue, sites, account manager |
|
Audit plans |
Hub |
Annual / multi-year plans, priority, budget, progress |
|
Audit missions |
Core hub |
10 audit types, lifecycle stage, budget, planned/spent time |
|
Auditors |
Object |
Grade, specialty, certifications, availability, daily rate |
|
Audit team |
Line |
Auditor assignment, role, allocated days |
|
Audit programs |
Object |
Procedure, control objective, test type, sampling, result |
|
Checklists |
Hub |
Category, template flag, compliance counters |
|
Checklist items |
Line |
Question, answer (compliant / non-compliant), comment |
|
Findings |
Object |
Severity, criticity, cause, consequence, evidence |
|
Recommendations |
Object |
Priority, responsible, deadline, cost, impact, progress |
|
Action plans |
Hub |
Deadline, budget, progress |
|
Actions |
Line |
Responsible, deadline, done date, progress |
|
Risks |
Object |
Category, probability, impact, criticity, mastery level |
|
Documents |
Object |
Type, version, validation (GED) |
|
Audit reports |
Object |
Report type, issue date, audit opinion, conclusion |
|
Cost centers |
Object |
Cost/profit center, analytic axis, planned/actual |
|
Budgets |
Hub |
Type, fiscal year, planned/actual, variance |
|
Budget lines |
Line |
Period, planned/actual amount |
|
KPIs |
Object |
Family, unit, target/actual value, trend |
|
Forecasts |
Object |
Scenario, forecast/actual amount |
|
Financial analyses |
Object |
Analysis type, indicator, ratio value, benchmark |
|
Timesheets |
Object |
Mission, auditor, hours, billable flag |
The module ships a brand-new decision cockpit, inspired by BI tools (Power BI, Tableau, SAP Analytics) and completely different from the classic Dolibarr dashboard. It uses a professional palette (dark blue, petrol blue, green, orange, light grey and white) with interactive KPI cards and modern charts.
· Missions in progress, completed and late
· Consumed budget, remaining budget and budget variance
· Time spent vs planned
· Number of recommendations and implementation rate
· Critical risks and total risks
· Available vs busy auditors
· Firm revenue and mission profitability
· Missions by audit type
· Findings by severity
· Missions by lifecycle stage
· Budget planned vs actual
· Probability / impact risk heat matrix
Advanced management of audited entities: companies, groups, subsidiaries, administrations, associations, cooperatives and public authorities. Each client carries a full profile (sector, activity, headcount, annual revenue, number of sites, account manager) and links to a native third party, with a full history of missions and financial analyses.
Build annual and multi-year audit plans with priorities, calendar, budget and resource allocation. Each plan tracks progress and groups the related missions, giving a consolidated view of the audit schedule.
The audit mission is the core object. It records the audit type (internal, external, financial, accounting, operational, organisational, quality, risk, IT, compliance), the responsible lead, the audit team, the client, the period, the budget, planned and consumed time, objectives, scope and deliverables. The complete lifecycle is managed: preparation → planning → execution → validation → reporting → follow-up → closing.
For each auditor: profile, competencies, certifications, grade, availability, daily rate and workload. Missions are staffed with an audit team (role and allocated days), and workload is tracked through timesheets.
Structured audit programs covering procedures, objectives, domains, controls, tests, criteria and sampling, with the test result recorded per program line.
Dynamic checklists (financial, accounting, legal, HR, IT, quality, production, stocks, security) with reusable templates. Each control point records a compliant / non-compliant answer and a comment, and the compliance rate is computed automatically.
Each finding captures its severity, criticity, domain, description, cause, consequence, evidence and responsible auditor, and is attached to its mission.
Recommendations are formalised with priority, responsible, deadline, estimated cost, impact and implementation progress, linked to the originating finding, with automatic follow-up.
Recommendations are turned into operational action plans: actions, tasks, responsibles, deadlines, validation and follow-up, with automatic reminders on overdue items.
A complete risk map covering strategic, financial, operational, legal, tax, IT, HR and cybersecurity risks. Each risk is scored by probability and impact; criticity is computed automatically, together with the mastery level. The risk map page renders an interactive probability / impact matrix (5×5 heat grid) with clickable cells.
A document library (GED) manages reports, evidence, supporting documents, contracts, procedures, policies and organisation charts with versioning and validation. Audit reports record the report type, issue date, audit opinion, signatory and conclusion.
Manage cost centers and profit centers along analytic axes, with planned and actual amounts and a responsible manager.
Manage annual, monthly, project and service budgets with detailed budget lines per period. The dedicated budget-control page tracks planned vs actual and performs automatic variance analysis (value and percentage), flagging overruns.
Define KPI indicators (financial, operational, HR, commercial, quality, production, logistics) with target and actual values and trends. Build forecasts (optimistic / realistic / pessimistic scenarios) and financial analyses (intermediate balances, ratios, profitability, liquidity, solvency, treasury, margins) connected to the audited client.
Record time spent by auditor and mission, with a billable flag, feeding profitability and workload reporting.
An extensive reporting menu provides 12 ready-to-use reports: missions, audit summary, findings, recommendations, risks, KPI indicators, budgets, financial analyses, mission profitability, collaborator workload, client portfolio and expenses/time. Every report can be exported to CSV, Excel and PDF, or printed.
Records follow a status workflow (draft → in progress → closed / cancelled) with validation, and a daily alert engine (cron job) scans for overdue recommendations, action plans and missions. Business triggers keep objects coherent — for example risk criticity is recomputed automatically on create/update.
Granular permissions are provided per functional domain, following Dolibarr standards (SQL injection protection, CSRF and XSS protection). Read and write are granted by default so the module is usable immediately after activation.
|
Permission group |
Actions |
|
Audited clients |
Read / write / delete |
|
Audit plans |
Read / write / delete |
|
Missions, team, programs, time |
Read / write / delete |
|
Auditors |
Read / write / delete |
|
Checklists |
Read / write / delete |
|
Findings, recommendations, actions |
Read / write / delete |
|
Risks |
Read / write / delete |
|
Documents & reports |
Read / write / delete |
|
Management control (budgets, KPI, analyses) |
Read / write / delete |
|
Reporting |
Read |
|
Module administration |
Admin |
From the configuration page, two buttons let administrators generate and remove a full demonstration dataset (audited clients, missions, auditors, plans, teams, programs, checklists, findings, recommendations, action plans, risks, documents, reports, cost centers, budgets, KPIs, forecasts, analyses and timesheets, plus native third parties). The purge removes only the data generated by the module.
The module is fully translated into French, English, Spanish, Italian and German. All translations are stored in the standard Dolibarr language files.
· Architecture: Dolibarr MVC, CommonObject classes, generic list/card engine
· Compatibility: Dolibarr 16 → 22+, PHP 7.1+ / 8.x, MariaDB / MySQL
· Security: SQL injection, CSRF and XSS protection, granular permissions
· Extensibility: Hooks, triggers, cron jobs, REST API, multi-entity
· Editor: DoliResources — www.doliresources.com
· Licence: GPL v3+
· Copyright: © 2026 DoliResources – All rights reserved