Risk Based Audit Planning

Most internal audit plans are last year plan with the dates changed. That is comfortable and it audits yesterday risk. A defensible plan starts from a risk assessment the business participated in, translates it into a scored audit universe, and produces coverage the audit committee approves rather than merely receives.

1

Universe

Define what is auditable

2

Assess

Facilitated risk workshops

3

Score

Rank by risk and coverage

4

Plan

Three year rolling

5

Approve

Committee adoption

How We Build the Plan

01

Defining the Audit Universe

The universe is everything that could be audited, expressed at a level that produces sensible engagements. Too granular and the plan becomes unmanageable; too broad and an engagement covers so much it tests nothing properly.

02

Facilitated Risk Assessment

We run the assessment with management rather than for them. An imposed risk score gets argued with during fieldwork; a score management helped set gets accepted, which matters more than the precision of the number.

03

Scoring and Prioritisation

Areas are scored on a defined basis so the ranking is repeatable and defensible. Time since last audit, prior findings and management change all raise priority independently of inherent risk.

04

Building the Rolling Plan

A three year rolling plan with the current year in detail. High risk areas recur annually, moderate areas across the cycle, and low risk areas may legitimately go uncovered provided that decision is explicit.

05

Committee Approval and Revision

The plan is presented for approval, not information, with the rationale visible so the committee can genuinely challenge it. It is then revisited quarterly rather than left to age for twelve months.

What You Receive

Indicative Timeline

Building a plan from scratch takes three to five weeks and is normally timed to precede the financial year. Annual refreshes are faster because the universe and scoring model already exist.

What Drives the Plan

Coverage is driven by risk and by obligation, and both need to be visible to the committee approving it.

Inherent Risk

What could go wrong in each area before considering whether any control exists.

Control Maturity

Whether the control environment is strong enough to justify reduced coverage this cycle.

Time Since Coverage

An area untouched for three years attracts attention regardless of its risk score.

Prior Findings

Repeat findings signal an unresolved cause and pull an area up the ranking.

Statutory Obligation

PFMA, MFMA and Treasury requirements that mandate coverage regardless of risk scoring.

Management Request

Reserved capacity for areas the committee or executive asks to be examined during the year.

Frequently Asked Questions

There is no fixed percentage. The test is whether the committee can explain why the areas covered were chosen and why the uncovered ones were accepted. A defensible rationale matters more than a coverage ratio.

It should align to it without being bound by it. Risk registers are self reported and frequently understate areas management is closest to. We use the register as an input and challenge it during the workshops.

The audit committee. Management is consulted and contributes to the risk assessment, but a plan approved only by the people being audited is not an independent plan.

Contingency is built into the plan for exactly that. Where an unplanned request exceeds it, something planned is deferred, and that trade off goes to the committee rather than being absorbed silently.

As auditable areas in their own right. ICT is frequently under covered because generalist internal audit teams lack the skills, which is a common reason for co-sourcing that specific coverage.

The IIA standards expect a plan aligned to the organisation objectives, and a rolling multi year view shows the committee how the whole universe gets covered over time rather than only what happens next year.

Related Services

This sits inside our Internal Audit practice. Related work: Outsourced Internal Audit where the whole function is provided, and IT General Controls Reviews for ICT coverage within the plan.

Discuss your audit plan