How to Develop a Risk-Based Internal Audit Plan
An internal audit plan should not begin with a list of audits.
It should begin with risk.
A risk-based internal audit plan identifies the areas where independent assurance can provide the greatest value to the organization. It connects organizational objectives, significant risks, the audit universe, available assurance, and internal audit resources into a defensible program of audit work.
That distinction is important.
An organization can complete every audit on its annual schedule and still have an ineffective internal audit function if the plan fails to address the risks that matter most.
The objective is not simply to determine what internal audit will audit.
The objective is to determine:
Where does the organization most need independent assurance?
1. Start With Organizational Objectives
Risk cannot be evaluated in isolation.
A risk exists because something could interfere with the achievement of an objective.
Internal audit should therefore begin the planning process by understanding the organization's objectives, strategies, major initiatives, and commitments.
These might include:
Revenue and profitability objectives
Cost-reduction initiatives
Regulatory requirements
Major capital projects
Acquisitions
New products
Geographic expansion
Digital transformation
Cybersecurity objectives
Artificial intelligence initiatives
Enterprise resource planning implementations
Customer service objectives
Workforce initiatives
Supply-chain objectives
This establishes the context for the risk assessment.
Internal audit should understand where the organization is trying to go before determining what could prevent it from getting there.
2. Understand the Organization's Risk Profile
The next step is developing an enterprise-level view of risk.
Internal audit should consider risks such as:
Strategic risk
Financial risk
Operational risk
Compliance risk
Cybersecurity risk
Information technology risk
Fraud risk
Third-party risk
Supply-chain risk
Human capital risk
Legal risk
Reputation risk
Data privacy risk
Business continuity risk
Artificial intelligence risk
Emerging risk
Internal audit should review the organization's existing enterprise risk assessment when one exists.
But the internal audit risk assessment should not simply duplicate management's enterprise risk management process.
Management owns risk.
Internal audit independently considers risk for the purpose of determining where assurance should be provided.
3. Build or Update the Audit Universe
The audit universe represents the population of potential areas that internal audit could examine.
Depending upon the organization, the audit universe may include:
Business Processes
Procure-to-pay
Order-to-cash
Payroll
Treasury
Financial reporting
Inventory
Capital expenditures
Revenue
Accounts payable
Accounts receivable
Organizational Units
Divisions
Departments
Subsidiaries
Branches
Geographic locations
Shared-service centers
Information Technology
Cybersecurity
Identity and access management
Cloud environments
Change management
IT operations
Data governance
Artificial intelligence
Business continuity
Disaster recovery
Compliance and Governance
Regulatory compliance
Ethics
Fraud risk management
Third-party management
Corporate governance
Enterprise risk management
Records management
Privacy
Strategic Activities
Acquisitions
Major projects
New systems
New products
Restructuring
Outsourcing
Transformation programs
The audit universe should not be static.
Organizations change. Risks change. Technology changes. Regulations change.
The audit universe must change with them.
4. Gather Information From Multiple Sources
Risk-based planning should never depend upon a single source of information.
Internal audit should consider information from across the organization.
Sources may include:
Strategic plans
Enterprise risk assessments
Budgets
Financial statements
Board materials
Audit committee discussions
Prior internal audit reports
External audit findings
Regulatory examination reports
Compliance reports
Cybersecurity assessments
Litigation
Whistleblower reports
Fraud investigations
Key performance indicators
Management dashboards
Customer complaints
Insurance claims
Loss events
System implementation plans
Major contracts
External developments should also be considered.
Changes in regulation, technology, economic conditions, cyber threats, industry practices, and business models may create risks that are not yet visible in internal reporting.
5. Interview Senior Management and the Board
Documents tell only part of the story.
Internal audit should speak with the people responsible for running and governing the organization.
Interviews may include:
Chief executive officer
Chief financial officer
Chief operating officer
Chief information officer
Chief information security officer
General counsel
Chief compliance officer
Chief risk officer
Human resources leadership
Business-unit executives
External auditors
Audit committee members
Useful questions include:
What could prevent us from achieving our objectives?
What has changed significantly during the past year?
Where are we taking more risk than before?
Which controls concern you?
Where are we most dependent upon a few individuals, systems, or vendors?
What keeps you awake at night?
Where would independent assurance be most valuable?
Internal audit should listen carefully for risks that do not appear in formal risk registers.
6. Identify Emerging and Changing Risks
One weakness of traditional annual audit planning is that it can become backward-looking.
Last year's problems become this year's audits.
A risk-based approach should also look forward.
Internal audit should consider developments such as:
Artificial intelligence
Cyber threats
Cloud migration
New regulatory requirements
Economic changes
Geopolitical events
Supply-chain disruption
New competitors
Workforce changes
Acquisitions
Major system implementations
New business models
Increasing dependence on third parties
An area that was low risk two years ago may now be one of the organization's most important exposures.
7. Develop Risk Factors
Internal audit needs a disciplined way to compare auditable areas.
Common risk factors include:
Financial exposure
Strategic importance
Regulatory exposure
Fraud susceptibility
Cybersecurity exposure
Complexity
Transaction volume
Rate of change
Management turnover
Reliance on technology
Third-party dependence
Prior audit results
Time since last audit
Quality of internal controls
Reputation exposure
Business continuity impact
Not every organization should use the same factors.
A financial institution, manufacturer, governmental entity, technology company, healthcare organization, and retailer will have different risk profiles.
Risk factors should reflect the organization.
8. Score Risks—But Do Not Let the Spreadsheet Make the Decision
Many internal audit departments assign numerical values to risk factors.
For example:
1 = Low Risk
2 = Moderate Risk
3 = High Risk
Other organizations use five-point or more sophisticated weighted models.
Risk scoring can provide structure and consistency.
It can also create false precision.
An audit area receiving a risk score of 87 is not necessarily materially riskier than an area scoring 84.
Risk assessment requires professional judgment.
The scoring model should support the auditor's thinking—not replace it.
A useful principle is: Risk scoring informs the audit plan. Professional judgment determines the audit plan.
9. Evaluate Inherent and Residual Risk
Internal audit should distinguish between inherent risk and residual risk.
Inherent risk is the level of risk before considering controls or risk responses.
Residual risk is the risk remaining after management's controls and responses are considered.
Consider cybersecurity.
The inherent risk may be extremely high because of the organization's dependence on technology and the potential consequences of a cyberattack.
If the organization has mature security controls, monitoring, incident response, penetration testing, and independent security assessments, residual risk may be lower.
However, high inherent risk may still justify periodic internal audit attention because the potential consequences of control failure are significant.
10. Consider the Strength of Internal Controls
Risk alone does not determine audit priority.
Internal audit should also consider control maturity.
Ask:
Are controls formally documented?
Are responsibilities clearly assigned?
Are key controls automated or manual?
Is management monitoring control performance?
Have significant control failures occurred?
Have prior findings been corrected?
Has the process recently changed?
Is management experienced?
Are systems stable?
Is reliable performance data available?
A high-risk process with weak controls is an obvious candidate for internal audit attention.
11. Consider Other Sources of Assurance
Internal audit is rarely the only group examining risk.
Other assurance providers may include:
External auditors
Compliance
Risk management
Information security
Quality assurance
Safety
Legal
Regulatory examiners
Insurance reviewers
Independent consultants
Internal audit should understand the assurance already being provided.
This can be documented through an assurance map.
For each major risk, determine:
Who owns the risk?
Who monitors it?
Who provides independent assurance?
How frequently is it reviewed?
How reliable is that assurance?
This can reveal both duplication and assurance gaps.
12. Determine the Audit Priority
Once risks, controls, and existing assurance have been evaluated, internal audit can establish priorities.
A simplified approach might categorize auditable areas as:
High Priority — significant risk and strong need for independent assurance.
Moderate Priority — meaningful risk but potentially lower urgency or existing assurance coverage.
Lower Priority — lower residual risk, strong controls, or substantial independent assurance already available.
Priority does not necessarily determine audit frequency automatically.
Professional judgment remains necessary.
13. Determine the Available Audit Resources
The audit plan must be achievable.
Start with total available staff hours and deduct time required for activities such as:
Holidays
Vacation
Training
Administration
Department meetings
Quality assurance
Audit planning
Audit committee meetings
Follow-up
Management activities
The remaining hours represent potential engagement capacity.
Then consider whether the department has the required expertise.
An audit department may have 10,000 available audit hours but still lack the specialized skills required to perform a sophisticated cybersecurity audit.
Capacity and capability are different issues.
14. Identify Where Co-Sourcing Is Necessary
Internal audit does not need every technical capability permanently on staff.
Specialists may be appropriate for areas such as:
Cybersecurity
Penetration testing
Cloud computing
Artificial intelligence
Complex tax matters
Environmental compliance
Construction
Healthcare regulation
Specialized financial instruments
The planning process should identify these needs early enough to obtain appropriate resources.
15. Reserve Hours for the Unexpected
A common planning mistake is allocating virtually every available audit hour before the year begins.
Organizations rarely operate according to the internal audit calendar.
Unexpected events may include:
Fraud allegations
Cyber incidents
Acquisitions
Regulatory inquiries
Control failures
Executive requests
Major projects
Litigation
New systems
Whistleblower allegations
Internal audit should maintain sufficient flexibility to respond.
A risk-based audit plan should be a management tool—not a straitjacket.
16. Build a Multi-Year Audit Perspective
Not every auditable area needs to be examined annually.
Internal audit can develop a multi-year planning horizon showing how the audit universe will be covered over time.
For example:
Highest-risk areas may receive annual or frequent attention.
Moderate-risk areas may rotate over several years.
Lower-risk areas may receive less frequent coverage.
Emerging risks may be added as circumstances change.
But a rigid three-year or five-year rotation should not override current risk.
The statement “We audit this every three years” is not, by itself, a risk-based justification.
17. Translate Risks Into Audit Engagements
Once priorities have been established, internal audit must translate broad risks into specific engagements.
For example: Risk: Cybersecurity
Possible engagements:
Identity and access management
Incident response
Vulnerability management
Cloud security
Third-party cybersecurity
Security governance
Risk: Procurement fraud
Possible engagements:
Vendor master controls
Conflicts of interest
Competitive bidding
Purchase cards
Duplicate payments
Vendor data analytics
The audit title should identify an auditable subject with meaningful objectives and scope.
18. Define Preliminary Objectives for Each Planned Audit
A plan is more useful when it explains why each engagement is being proposed.
Instead of listing:
Vendor Management Audit: consider describing the objective:
Evaluate whether significant third-party relationships are subject to appropriate due diligence, contracting, risk classification, ongoing monitoring, cybersecurity review, and performance oversight.
This gives management and the audit committee much more information about the intended assurance.
19. Present the Audit Plan to the Audit Committee
The audit committee should understand more than the names of proposed audits.
A strong audit-plan presentation should communicate:
Significant organizational risks
Risk-assessment methodology
Proposed audits
Relationship between major risks and planned engagements
Areas not receiving audit coverage
Other assurance being relied upon
Available internal audit resources
Resource limitations
Required specialized expertise
Planned contingency capacity
Significant changes from the prior plan
One particularly useful question for the audit committee is:
Which significant risks will not receive internal audit coverage under this plan?
That discussion can be more valuable than reviewing the list of audits that are included.
20. Obtain Audit Committee Approval
The audit committee should review and approve the risk-based internal audit plan.
Approval is important because the plan represents a governance decision concerning where internal audit resources will be concentrated.
If available resources are insufficient to provide appropriate coverage of significant risks, the chief audit executive should communicate that limitation clearly.
The answer should not be to quietly reduce audit coverage while allowing the board to assume that significant risks are adequately covered.
21. Make the Audit Plan Dynamic
The risk assessment should not disappear into a file after the annual planning process.
Internal audit should periodically reconsider:
What has changed?
Have new risks emerged?
Have existing risks increased?
Have risks declined?
Have major projects been delayed?
Have control failures occurred?
Has management changed?
Have regulatory requirements changed?
Has a cyber incident occurred?
Has the organization entered a new market?
The audit plan should change when the organization's risk profile changes.
For many organizations, quarterly reassessment may be appropriate.
For rapidly changing organizations, risk assessment may need to be continuous.
A Practical Risk-Based Planning Model
A useful way to visualize the process is:
Organizational Objectives
↓
Identify Risks
↓
Develop the Audit Universe
↓
Assess Inherent Risk
↓
Evaluate Controls
↓
Determine Residual Risk
↓
Consider Other Assurance
↓
Prioritize Audit Areas
↓
Evaluate Resources and Skills
↓
Develop Proposed Engagements
↓
Audit Committee Review and Approval
↓
Execute the Plan
↓
Monitor Changes in Risk
↓
Update the Plan
This creates a direct connection between the organization's objectives and the work performed by internal audit.
Questions the Chief Audit Executive Should Be Able to Answer
Before presenting the plan to the audit committee, the chief audit executive should be able to answer several fundamental questions:
What are the organization's most significant risks?
How did internal audit identify them?
Which risks will internal audit address?
Which risks will not receive internal audit coverage?
Why were the proposed audits selected?
What assurance is being provided by others?
Does internal audit have sufficient resources?
Does internal audit have the required expertise?
What capacity has been reserved for unexpected events?
What has changed since last year's plan?
How will the plan change if organizational risks change?
If these questions cannot be answered clearly, the planning process may not yet be complete.
Common Mistakes in Internal Audit Planning
Several practices can undermine a risk-based approach.
Repeating last year's audit plan.Prior plans can provide useful information, but they should not determine current priorities.
Auditing based primarily on elapsed time.“We haven't audited this area in three years” is not a complete risk assessment.
Allowing management requests to dominate the plan.Management input is important, but internal audit must maintain an independent view of risk.
Relying entirely on a numerical risk model.Mathematical models cannot replace professional judgment.
Ignoring emerging risks.Historical audit results may provide little information about new technologies, business models, or threats.
Ignoring available resources.An audit plan that cannot realistically be completed provides little value.
Committing every available hour.Internal audit needs capacity to respond to unexpected risk.
Failing to explain what is not being audited.The audit committee should understand significant gaps in assurance.
From an Audit Calendar to a Risk-Based Audit Plan
There is an important difference between an audit calendar and a risk-based internal audit plan.
An audit calendar says:These are the audits we intend to perform this year.
A risk-based plan explains:These are the organization's significant risks, this is the assurance currently available, these are the areas where internal audit can provide meaningful independent assurance, and this is how we propose using our limited resources.
That is a fundamentally different approach.
The Bottom Line
A risk-based internal audit plan should provide a logical and defensible connection between:
Organizational Objectives → Risks → Controls → Residual Risk → Existing Assurance → Audit Priorities → Internal Audit Resources → Audit Engagements
The process should also work in reverse.
For every engagement appearing on the internal audit plan, the chief audit executive should be able to answer:
Why are we auditing this?
And the answer should ultimately connect to a meaningful organizational risk.
The objective is not to complete the greatest possible number of audits.
It is to deploy limited internal audit resources where independent assurance matters most.
That is what turns an annual list of audits into a genuinely risk-based internal audit plan.
Corporate Compliance Seminars (CCS) provides continuing professional education for internal auditors, external auditors, compliance professionals, accounting professionals, and information technology professionals. CCS training addresses internal auditing, risk assessment, internal controls, corporate governance, fraud, cybersecurity, information technology auditing, and other areas important to today's assurance professionals.

Comments