Turning a Flat Schedule into a Board-Ready Audit Plan

Overview
Internal audit teams plan their entire year of work inside a single timeline, the Audit Plan. It's the artifact a Head of Audit uses to show an audit committee what's covered, what's at risk, and when.
But the existing timeline could only do one thing: show when audits happened. It couldn't show whether the plan actually covered the risks that mattered.
I led the end-to-end design of Swimlanes and Milestones: a structural rework of the audit plan timeline that turned a flat scheduling list into a strategic, board-ready coverage view. I owned the work from early concept validation through final visual design, a cross-team design system fix, and post-launch dev support.
The problem
The problem source
Target personas
Who This Was For
-Head of Audit (primary/strategic): owns the plan at a governance level. Needs to communicate coverage and risk exposure to the audit committee without manual rework.
-Audit Managers & Senior Auditors (operational): run the timeline day-to-day. Need to understand how audits move through phases and where work overlaps.
Designing for both meant the timeline had to work as a reporting surface and a working tool — at the same time, without becoming cluttered.

The process
Fast Exploration, Then Deliberate Design
Starting with AI, deliberately
I picked this up during an internal AI Building Day with PM and engineering. The scope was well-suited to it, the user need was already validated, and the interaction model was contained enough to explore quickly.
AI got us from zero to a first UI direction fast, and it did real work: it helped the team align on the job-to-be-done before a single Figma file existed.

AI output in the beggining
The Solution
The rebuilt timeline replaced a flat audit list with two additions that changed what the plan could communicate:
-Swimlanes : group audits by risk domain, business unit, audit type, or assurance provider, so coverage (and coverage gaps) are visible at a glance.
-Milestones : visible markers for the dates that actually drive audit work: committee meetings, regulatory deadlines, phase gates, remediation due dates.
The interaction model was intentionally manual-first: users create, edit, reorder, and assign everything themselves. This made the feature immediately useful on day one, and established the structural foundation for what came next.
Designing for What Comes Next
The manual-first approach wasn't just a scoping decision for launch, it was a deliberate architectural choice. I designed the swimlane and milestone structure to be scalable and flexible enough to support AI-assisted planning later, without requiring a rebuild.
Structured, addressable data model, swimlane categories and milestones are explicit objects, not just visual groupings, so an AI system can reason about them, suggest them, or auto-populate them later
A clear manual baseline: because users can fully control the structure by hand today, any future AI suggestion is additive, not a replacement they have to blindly trust
First iteration: manual category creation, with an "AI suggestion" entry point built in.
AI analyzing historical audit data to identify category patterns.
Result: AI-suggested categories with reasoning, user reviews and confirms.







