CIA Risk-Based Audit Planning
A risk-based internal audit plan prioritizes assurance work using a documented view of organizational objectives, risks, changes, governance concerns, prior results, other assurance coverage, and available resources.
- It should be updated when material risks change, and significant plan changes or limitations should be communicated to governance.
On this page13 sections
- Start with the organization and its objectives
- Assess and prioritize risk
- Map assurance coverage
- Translate risk into engagements
- Resources and feasibility
- Make the plan dynamic
- Worked example: risk universe update
- Plan monitoring and performance
- Common planning mistakes
- Study application
- Different views of risk and audit coverage
- Plan prioritization example
- Governance communication of constraints
Start with the organization and its objectives
An audit plan is a portfolio of engagements designed to provide assurance and advice on matters that could affect organizational objectives. Begin with an understanding of strategy, operations, governance, risk appetite, regulatory obligations, major change, and stakeholder concerns. A list of departments alone is not a risk assessment.
The risk universe can include business processes, entities, programs, systems, third parties, major projects, regulatory obligations, strategic objectives, and cross-functional themes. Structure it so risks can be assessed and mapped to potential audit coverage. The universe should reflect how the organization works, not only its organization chart.
Internal audit retains independent judgment when considering inputs. Board and senior-management views, enterprise risk management, incidents, external audit, compliance, security, and prior engagement results are useful sources, but none automatically determines the audit plan.
Assess and prioritize risk
A documented risk assessment considers likelihood and impact as well as velocity, complexity, change, control reliance, known incidents, regulatory exposure, fraud susceptibility, third-party dependence, and reputation. The method should be understandable and consistently applied, but scoring should not replace judgment.
Inherent risk is the exposure before considering controls; residual risk is what remains after management responses. A high inherent risk may have strong safeguards, while a moderate inherent risk may be elevated by weak controls or rapid change. Consider both and explain the priority.
Risk scores help compare items, but qualitative factors can matter. A low-volume process that supports critical patient care may deserve attention despite limited financial size. A fast-changing cloud platform may merit review before the next ordinary cycle because the risk is emerging.
Map assurance coverage
The chief audit executive identifies existing assurance from internal audit, compliance, risk management, security, quality, external audit, regulators, and other providers. A coverage map can show where work overlaps and where material risks have no independent assurance.
Before relying on a provider’s work, assess objectivity, competence, scope, methodology, evidence, reporting, and limitations. A provider’s report may cover one control or period but omit another. Document the specific reliance decision and any additional procedures.
Coordination is not the same as surrendering the plan. The internal audit function retains accountability for its own conclusions and should not let a provider’s calendar or management preference eliminate independent coverage of a significant risk.
Translate risk into engagements
An engagement plan should state objectives, potential scope, timing, and resource needs at a level that lets governance understand expected coverage. Prioritization should explain why some work proceeds sooner, why other work is deferred, and what risk remains uncovered.
For a high-risk system implementation, an engagement could assess governance, access, change management, data migration, and post-launch monitoring. The scope should be proportionate; a short pre-implementation advisory review may not provide assurance over post-launch operation.
The plan should account for assurance and advisory work. Advisory engagements can help management improve risk and control processes, but should not make internal audit responsible for design or operation. Preserve capacity for independent assurance on significant risks.
Resources and feasibility
A risk-based plan must be feasible. Consider staff skills, available days, budget, technology, geographic scope, language, specialists, and quality review. If a critical risk needs expertise the function does not have, options include recruiting, training, co-sourcing, or changing scope and timing while communicating the limitation.
A plan that assumes unlimited resources can create false assurance. The chief audit executive should identify unaddressed risks and explain the effect to senior management and the board. Management can provide resources or accept a prioritization trade-off, but internal audit should not conceal the gap.
Resource changes can also affect quality. A smaller team may deliver fewer engagements, but the function should preserve adequate supervision, documentation, and evidence standards for the work it does accept.
Make the plan dynamic
Risk changes during the year. A merger, system failure, major fraud allegation, new regulation, strategy shift, or significant control breakdown can warrant timely reassessment. The chief audit executive compares the new risk with existing priorities, resources, and assurance coverage, then determines whether to add, defer, rescope, or accelerate engagements.
Document why the plan changed and what remains uncovered. Communicate material changes and resource constraints to the appropriate governance recipients. Annual approval does not require the function to ignore a major change; it creates a basis for explaining departures and obtaining governance direction.
Example: a company announces an acquisition after plan approval. Internal audit assesses integration, financial reporting, access, third-party, and compliance risks; considers due diligence and other assurance work; and decides whether focused coverage is needed before close. It estimates specialist capacity and brings material scope or resource changes to governance.
Worked example: risk universe update
A logistics company relies on a third-party route-planning platform. The provider suffers a ransomware incident, and dispatch delays affect several regions. The risk universe already lists technology resilience but has not ranked the vendor relationship highly because past uptime was strong.
The chief audit executive updates the assessment using incident impact, recovery capability, data access, business continuity, contract rights, and assurance-provider information. The function checks whether security or compliance teams already cover specific controls and evaluates whether their work is reliable.
The audit plan adds a focused review of resilience and vendor oversight, shifts a lower-priority engagement, and requests a technology specialist. The chief audit executive communicates the material change, resource impact, and residual coverage gap. Engagement results later inform a broader plan review.
Plan monitoring and performance
Monitor whether planned engagements begin and finish, but interpret completion alongside risk coverage, quality, budget, stakeholder needs, emerging issues, and action follow-up. A high completion rate may conceal deferred high-risk work; a lower rate may reflect justified reprioritization after an incident.
Useful measures can include percentage of high-risk universe covered, significant risks deferred, days from event to plan reassessment, specialist capacity, review findings, and stakeholder feedback. Quantitative indicators should be combined with qualitative explanation. Avoid using one metric to reward volume or discourage necessary plan changes.
Review plan execution with the board or appropriate committee at an interval suitable to the governance framework. Communicate changes, reasons, resource constraints, and unaddressed risk. A plan is a management tool for independent assurance, not a static calendar.
Common planning mistakes
Do not equate enterprise risk scores with internal audit priorities. Risk management’s assessment is an input; internal audit uses its own objective assessment. Do not rely on a provider without evaluating competence and scope. Do not ignore emerging risks because the approved plan is old.
Do not put every risk on the plan without prioritizing, and do not promise coverage the function lacks resources to perform. Do not measure effectiveness only by engagement count or plan completion.
A sound answer links objective, risk, assurance coverage, resources, engagement timing, governance communication, and follow-up.
Study application
For any plan scenario, identify the risk change, available assurance, resource need, materiality of the coverage gap, and decision authority. Decide whether to add, defer, rescope, or coordinate work, then determine who should receive the information.
The current Part 3 Internal Audit Plan domain is 15%. Its ideas also appear in Operations and Results because resources constrain coverage and prior findings inform future risk assessments. Practice the full cycle, not isolated risk-score formulas.
Different views of risk and audit coverage
Enterprise risk management helps describe the organization’s risk assessment, but internal audit must retain an independent view of risk and coverage. A high score from management is a useful input, not an instruction to audit. Internal audit may identify an unrecognized risk or question whether a mitigation is operating.
Assurance mapping shows what work providers perform, but coverage may be partial. A compliance review may test regulatory adherence while internal audit tests governance and control operation. A financial statement audit may rely on materiality thresholds that do not address operational resilience. Map purpose and limits, not provider labels alone.
Plan prioritization example
A university has three proposed audits: student-record access, a low-risk travel reimbursement process, and a new online learning platform. The risk assessment considers data sensitivity, regulatory exposure, user access, change, third-party hosting, prior incidents, and other assurance. The platform and student records may rank above travel reimbursement even if the reimbursement process has more transactions.
The function checks whether the information-security team already tested platform access and whether that work is competent and sufficiently broad. It then identifies the remaining gaps, estimates specialist time, and chooses a focused engagement. A lower-priority engagement may be deferred with its residual risk documented and communicated.
Governance communication of constraints
A plan can contain more high-priority work than the function can staff. The chief audit executive should explain which risks will receive less coverage, why, and what options exist: added resources, co-sourcing, scope changes, or accepted deferral. Governance can decide on resources and receive risk information, but the audit function must not imply that omitted work received assurance.
If the function later obtains a specialist, update coverage and milestones. Document the change and review whether the plan still addresses current objectives. This closes the loop between risk assessment and operation.
A plan should also preserve capacity for unplanned work such as investigations, urgent advisory requests, or rapid response to a significant incident. The function can define a reasonable reserve using past demand and current risk. If unplanned work consumes the reserve, reassess priorities and communicate the resulting coverage changes rather than quietly reducing planned testing.