top of page
Search

How to Develop a Risk-Based Internal Audit Plan

6 minutes ago
10 min read

An internal audit plan should not begin with a list of audits.


It should begin with risk.


A risk-based internal audit plan identifies the areas where independent assurance can provide the greatest value to the organization. It connects organizational objectives, significant risks, the audit universe, available assurance, and internal audit resources into a defensible program of audit work.


That distinction is important.


An organization can complete every audit on its annual schedule and still have an ineffective internal audit function if the plan fails to address the risks that matter most.


The objective is not simply to determine what internal audit will audit.


The objective is to determine:


Where does the organization most need independent assurance?


1. Start With Organizational Objectives

Risk cannot be evaluated in isolation.


A risk exists because something could interfere with the achievement of an objective.


Internal audit should therefore begin the planning process by understanding the organization's objectives, strategies, major initiatives, and commitments.


These might include:

  • Revenue and profitability objectives

  • Cost-reduction initiatives

  • Regulatory requirements

  • Major capital projects

  • Acquisitions

  • New products

  • Geographic expansion

  • Digital transformation

  • Cybersecurity objectives

  • Artificial intelligence initiatives

  • Enterprise resource planning implementations

  • Customer service objectives

  • Workforce initiatives

  • Supply-chain objectives


This establishes the context for the risk assessment.


Internal audit should understand where the organization is trying to go before determining what could prevent it from getting there.


2. Understand the Organization's Risk Profile

The next step is developing an enterprise-level view of risk.


Internal audit should consider risks such as:

  • Strategic risk

  • Financial risk

  • Operational risk

  • Compliance risk

  • Cybersecurity risk

  • Information technology risk

  • Fraud risk

  • Third-party risk

  • Supply-chain risk

  • Human capital risk

  • Legal risk

  • Reputation risk

  • Data privacy risk

  • Business continuity risk

  • Artificial intelligence risk

  • Emerging risk


Internal audit should review the organization's existing enterprise risk assessment when one exists.


But the internal audit risk assessment should not simply duplicate management's enterprise risk management process.


Management owns risk.


Internal audit independently considers risk for the purpose of determining where assurance should be provided.


3. Build or Update the Audit Universe

The audit universe represents the population of potential areas that internal audit could examine.


Depending upon the organization, the audit universe may include:


Business Processes

  • Procure-to-pay

  • Order-to-cash

  • Payroll

  • Treasury

  • Financial reporting

  • Inventory

  • Capital expenditures

  • Revenue

  • Accounts payable

  • Accounts receivable


Organizational Units

  • Divisions

  • Departments

  • Subsidiaries

  • Branches

  • Geographic locations

  • Shared-service centers


Information Technology

  • Cybersecurity

  • Identity and access management

  • Cloud environments

  • Change management

  • IT operations

  • Data governance

  • Artificial intelligence

  • Business continuity

  • Disaster recovery


Compliance and Governance

  • Regulatory compliance

  • Ethics

  • Fraud risk management

  • Third-party management

  • Corporate governance

  • Enterprise risk management

  • Records management

  • Privacy


Strategic Activities

  • Acquisitions

  • Major projects

  • New systems

  • New products

  • Restructuring

  • Outsourcing

  • Transformation programs


The audit universe should not be static.


Organizations change. Risks change. Technology changes. Regulations change.


The audit universe must change with them.


4. Gather Information From Multiple Sources

Risk-based planning should never depend upon a single source of information.


Internal audit should consider information from across the organization.


Sources may include:

  • Strategic plans

  • Enterprise risk assessments

  • Budgets

  • Financial statements

  • Board materials

  • Audit committee discussions

  • Prior internal audit reports

  • External audit findings

  • Regulatory examination reports

  • Compliance reports

  • Cybersecurity assessments

  • Litigation

  • Whistleblower reports

  • Fraud investigations

  • Key performance indicators

  • Management dashboards

  • Customer complaints

  • Insurance claims

  • Loss events

  • System implementation plans

  • Major contracts


External developments should also be considered.


Changes in regulation, technology, economic conditions, cyber threats, industry practices, and business models may create risks that are not yet visible in internal reporting.


5. Interview Senior Management and the Board

Documents tell only part of the story.


Internal audit should speak with the people responsible for running and governing the organization.


Interviews may include:

  • Chief executive officer

  • Chief financial officer

  • Chief operating officer

  • Chief information officer

  • Chief information security officer

  • General counsel

  • Chief compliance officer

  • Chief risk officer

  • Human resources leadership

  • Business-unit executives

  • External auditors

  • Audit committee members


Useful questions include:


What could prevent us from achieving our objectives?


What has changed significantly during the past year?


Where are we taking more risk than before?


Which controls concern you?


Where are we most dependent upon a few individuals, systems, or vendors?


What keeps you awake at night?


Where would independent assurance be most valuable?


Internal audit should listen carefully for risks that do not appear in formal risk registers.


6. Identify Emerging and Changing Risks

One weakness of traditional annual audit planning is that it can become backward-looking.


Last year's problems become this year's audits.


A risk-based approach should also look forward.


Internal audit should consider developments such as:

  • Artificial intelligence

  • Cyber threats

  • Cloud migration

  • New regulatory requirements

  • Economic changes

  • Geopolitical events

  • Supply-chain disruption

  • New competitors

  • Workforce changes

  • Acquisitions

  • Major system implementations

  • New business models

  • Increasing dependence on third parties


An area that was low risk two years ago may now be one of the organization's most important exposures.


7. Develop Risk Factors

Internal audit needs a disciplined way to compare auditable areas.


Common risk factors include:

  • Financial exposure

  • Strategic importance

  • Regulatory exposure

  • Fraud susceptibility

  • Cybersecurity exposure

  • Complexity

  • Transaction volume

  • Rate of change

  • Management turnover

  • Reliance on technology

  • Third-party dependence

  • Prior audit results

  • Time since last audit

  • Quality of internal controls

  • Reputation exposure

  • Business continuity impact


Not every organization should use the same factors.


A financial institution, manufacturer, governmental entity, technology company, healthcare organization, and retailer will have different risk profiles.


Risk factors should reflect the organization.


8. Score Risks—But Do Not Let the Spreadsheet Make the Decision

Many internal audit departments assign numerical values to risk factors.


For example:

1 = Low Risk

2 = Moderate Risk

3 = High Risk


Other organizations use five-point or more sophisticated weighted models.


Risk scoring can provide structure and consistency.


It can also create false precision.


An audit area receiving a risk score of 87 is not necessarily materially riskier than an area scoring 84.


Risk assessment requires professional judgment.


The scoring model should support the auditor's thinking—not replace it.


A useful principle is: Risk scoring informs the audit plan. Professional judgment determines the audit plan.


9. Evaluate Inherent and Residual Risk

Internal audit should distinguish between inherent risk and residual risk.


Inherent risk is the level of risk before considering controls or risk responses.


Residual risk is the risk remaining after management's controls and responses are considered.


Consider cybersecurity.


The inherent risk may be extremely high because of the organization's dependence on technology and the potential consequences of a cyberattack.


If the organization has mature security controls, monitoring, incident response, penetration testing, and independent security assessments, residual risk may be lower.


However, high inherent risk may still justify periodic internal audit attention because the potential consequences of control failure are significant.


10. Consider the Strength of Internal Controls

Risk alone does not determine audit priority.


Internal audit should also consider control maturity.


Ask:

  • Are controls formally documented?

  • Are responsibilities clearly assigned?

  • Are key controls automated or manual?

  • Is management monitoring control performance?

  • Have significant control failures occurred?

  • Have prior findings been corrected?

  • Has the process recently changed?

  • Is management experienced?

  • Are systems stable?

  • Is reliable performance data available?


A high-risk process with weak controls is an obvious candidate for internal audit attention.


11. Consider Other Sources of Assurance

Internal audit is rarely the only group examining risk.


Other assurance providers may include:

  • External auditors

  • Compliance

  • Risk management

  • Information security

  • Quality assurance

  • Safety

  • Legal

  • Regulatory examiners

  • Insurance reviewers

  • Independent consultants


Internal audit should understand the assurance already being provided.


This can be documented through an assurance map.


For each major risk, determine:

  • Who owns the risk?

  • Who monitors it?

  • Who provides independent assurance?

  • How frequently is it reviewed?

  • How reliable is that assurance?


This can reveal both duplication and assurance gaps.


12. Determine the Audit Priority

Once risks, controls, and existing assurance have been evaluated, internal audit can establish priorities.


A simplified approach might categorize auditable areas as:

  • High Priority — significant risk and strong need for independent assurance.

  • Moderate Priority — meaningful risk but potentially lower urgency or existing assurance coverage.

  • Lower Priority — lower residual risk, strong controls, or substantial independent assurance already available.


Priority does not necessarily determine audit frequency automatically.


Professional judgment remains necessary.


13. Determine the Available Audit Resources

The audit plan must be achievable.


Start with total available staff hours and deduct time required for activities such as:

  • Holidays

  • Vacation

  • Training

  • Administration

  • Department meetings

  • Quality assurance

  • Audit planning

  • Audit committee meetings

  • Follow-up

  • Management activities


The remaining hours represent potential engagement capacity.


Then consider whether the department has the required expertise.


An audit department may have 10,000 available audit hours but still lack the specialized skills required to perform a sophisticated cybersecurity audit.


Capacity and capability are different issues.


14. Identify Where Co-Sourcing Is Necessary

Internal audit does not need every technical capability permanently on staff.


Specialists may be appropriate for areas such as:

  • Cybersecurity

  • Penetration testing

  • Cloud computing

  • Artificial intelligence

  • Complex tax matters

  • Environmental compliance

  • Construction

  • Healthcare regulation

  • Specialized financial instruments


The planning process should identify these needs early enough to obtain appropriate resources.


15. Reserve Hours for the Unexpected

A common planning mistake is allocating virtually every available audit hour before the year begins.


Organizations rarely operate according to the internal audit calendar.


Unexpected events may include:

  • Fraud allegations

  • Cyber incidents

  • Acquisitions

  • Regulatory inquiries

  • Control failures

  • Executive requests

  • Major projects

  • Litigation

  • New systems

  • Whistleblower allegations


Internal audit should maintain sufficient flexibility to respond.


A risk-based audit plan should be a management tool—not a straitjacket.


16. Build a Multi-Year Audit Perspective

Not every auditable area needs to be examined annually.


Internal audit can develop a multi-year planning horizon showing how the audit universe will be covered over time.


For example:

  • Highest-risk areas may receive annual or frequent attention.

  • Moderate-risk areas may rotate over several years.

  • Lower-risk areas may receive less frequent coverage.

  • Emerging risks may be added as circumstances change.


But a rigid three-year or five-year rotation should not override current risk.


The statement “We audit this every three years” is not, by itself, a risk-based justification.


17. Translate Risks Into Audit Engagements

Once priorities have been established, internal audit must translate broad risks into specific engagements.


For example: Risk: Cybersecurity


Possible engagements:

  • Identity and access management

  • Incident response

  • Vulnerability management

  • Cloud security

  • Third-party cybersecurity

  • Security governance


Risk: Procurement fraud


Possible engagements:

  • Vendor master controls

  • Conflicts of interest

  • Competitive bidding

  • Purchase cards

  • Duplicate payments

  • Vendor data analytics


The audit title should identify an auditable subject with meaningful objectives and scope.


18. Define Preliminary Objectives for Each Planned Audit

A plan is more useful when it explains why each engagement is being proposed.


Instead of listing:

  • Vendor Management Audit: consider describing the objective:

  • Evaluate whether significant third-party relationships are subject to appropriate due diligence, contracting, risk classification, ongoing monitoring, cybersecurity review, and performance oversight.


This gives management and the audit committee much more information about the intended assurance.


19. Present the Audit Plan to the Audit Committee

The audit committee should understand more than the names of proposed audits.


A strong audit-plan presentation should communicate:

  • Significant organizational risks

  • Risk-assessment methodology

  • Proposed audits

  • Relationship between major risks and planned engagements

  • Areas not receiving audit coverage

  • Other assurance being relied upon

  • Available internal audit resources

  • Resource limitations

  • Required specialized expertise

  • Planned contingency capacity

  • Significant changes from the prior plan


One particularly useful question for the audit committee is:


Which significant risks will not receive internal audit coverage under this plan?


That discussion can be more valuable than reviewing the list of audits that are included.


20. Obtain Audit Committee Approval

The audit committee should review and approve the risk-based internal audit plan.


Approval is important because the plan represents a governance decision concerning where internal audit resources will be concentrated.


If available resources are insufficient to provide appropriate coverage of significant risks, the chief audit executive should communicate that limitation clearly.


The answer should not be to quietly reduce audit coverage while allowing the board to assume that significant risks are adequately covered.


21. Make the Audit Plan Dynamic

The risk assessment should not disappear into a file after the annual planning process.


Internal audit should periodically reconsider:

  • What has changed?

  • Have new risks emerged?

  • Have existing risks increased?

  • Have risks declined?

  • Have major projects been delayed?

  • Have control failures occurred?

  • Has management changed?

  • Have regulatory requirements changed?

  • Has a cyber incident occurred?

  • Has the organization entered a new market?


The audit plan should change when the organization's risk profile changes.


For many organizations, quarterly reassessment may be appropriate.


For rapidly changing organizations, risk assessment may need to be continuous.


A Practical Risk-Based Planning Model

A useful way to visualize the process is:

Organizational Objectives

↓

Identify Risks

↓

Develop the Audit Universe

↓

Assess Inherent Risk

↓

Evaluate Controls

↓

Determine Residual Risk

↓

Consider Other Assurance

↓

Prioritize Audit Areas

↓

Evaluate Resources and Skills

↓

Develop Proposed Engagements

↓

Audit Committee Review and Approval

↓

Execute the Plan

↓

Monitor Changes in Risk

↓

Update the Plan


This creates a direct connection between the organization's objectives and the work performed by internal audit.


Questions the Chief Audit Executive Should Be Able to Answer

Before presenting the plan to the audit committee, the chief audit executive should be able to answer several fundamental questions:

  • What are the organization's most significant risks?

  • How did internal audit identify them?

  • Which risks will internal audit address?

  • Which risks will not receive internal audit coverage?

  • Why were the proposed audits selected?

  • What assurance is being provided by others?

  • Does internal audit have sufficient resources?

  • Does internal audit have the required expertise?

  • What capacity has been reserved for unexpected events?

  • What has changed since last year's plan?

  • How will the plan change if organizational risks change?


If these questions cannot be answered clearly, the planning process may not yet be complete.


Common Mistakes in Internal Audit Planning

Several practices can undermine a risk-based approach.


Repeating last year's audit plan.Prior plans can provide useful information, but they should not determine current priorities.


Auditing based primarily on elapsed time.“We haven't audited this area in three years” is not a complete risk assessment.


Allowing management requests to dominate the plan.Management input is important, but internal audit must maintain an independent view of risk.


Relying entirely on a numerical risk model.Mathematical models cannot replace professional judgment.


Ignoring emerging risks.Historical audit results may provide little information about new technologies, business models, or threats.


Ignoring available resources.An audit plan that cannot realistically be completed provides little value.


Committing every available hour.Internal audit needs capacity to respond to unexpected risk.


Failing to explain what is not being audited.The audit committee should understand significant gaps in assurance.


From an Audit Calendar to a Risk-Based Audit Plan

There is an important difference between an audit calendar and a risk-based internal audit plan.


An audit calendar says:These are the audits we intend to perform this year.


A risk-based plan explains:These are the organization's significant risks, this is the assurance currently available, these are the areas where internal audit can provide meaningful independent assurance, and this is how we propose using our limited resources.


That is a fundamentally different approach.


The Bottom Line

A risk-based internal audit plan should provide a logical and defensible connection between:


Organizational Objectives → Risks → Controls → Residual Risk → Existing Assurance → Audit Priorities → Internal Audit Resources → Audit Engagements


The process should also work in reverse.


For every engagement appearing on the internal audit plan, the chief audit executive should be able to answer:

  • Why are we auditing this?


And the answer should ultimately connect to a meaningful organizational risk.


The objective is not to complete the greatest possible number of audits.


It is to deploy limited internal audit resources where independent assurance matters most.


That is what turns an annual list of audits into a genuinely risk-based internal audit plan.

Corporate Compliance Seminars (CCS) provides continuing professional education for internal auditors, external auditors, compliance professionals, accounting professionals, and information technology professionals. CCS training addresses internal auditing, risk assessment, internal controls, corporate governance, fraud, cybersecurity, information technology auditing, and other areas important to today's assurance professionals.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

​

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

​

National Registry of CPE Sponsors ID #108983

​

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366; davem@cseminars.com) and/ or John Blackshire (479-200-4373; johnb@cseminars.com)

 

​

bottom of page