Risk Based Audit Planning
Most internal audit plans are last year plan with the dates changed. That is comfortable and it audits yesterday risk. A defensible plan starts from a risk assessment the business participated in, translates it into a scored audit universe, and produces coverage the audit committee approves rather than merely receives.
1
Universe
Define what is auditable
2
Assess
Facilitated risk workshops
3
Score
Rank by risk and coverage
4
Plan
Three year rolling
5
Approve
Committee adoption
How We Build the Plan
01
Defining the Audit Universe
The universe is everything that could be audited, expressed at a level that produces sensible engagements. Too granular and the plan becomes unmanageable; too broad and an engagement covers so much it tests nothing properly.
- Auditable areas defined by process, entity and system
- Alignment to the organisational structure and strategy
- Coverage of governance, risk and compliance obligations
- Level of granularity agreed with the audit committee
02
Facilitated Risk Assessment
We run the assessment with management rather than for them. An imposed risk score gets argued with during fieldwork; a score management helped set gets accepted, which matters more than the precision of the number.
- Workshops with process and executive owners
- Inherent and residual risk assessed per area
- Control environment maturity considered
- Alignment to the organisational risk register
03
Scoring and Prioritisation
Areas are scored on a defined basis so the ranking is repeatable and defensible. Time since last audit, prior findings and management change all raise priority independently of inherent risk.
- Scoring model agreed and applied consistently
- Time since last coverage factored in
- Prior findings and repeat issues weighted
- Known change, such as a new system or leadership
04
Building the Rolling Plan
A three year rolling plan with the current year in detail. High risk areas recur annually, moderate areas across the cycle, and low risk areas may legitimately go uncovered provided that decision is explicit.
- Three year rolling coverage with annual detail
- Resource and budget estimate per engagement
- Areas deliberately not covered, with rationale
- Contingency reserved for unplanned requests
05
Committee Approval and Revision
The plan is presented for approval, not information, with the rationale visible so the committee can genuinely challenge it. It is then revisited quarterly rather than left to age for twelve months.
- Approval pack with coverage rationale
- Formal adoption recorded in the minutes
- Quarterly reprioritisation against emerging risk
- Change control on plan amendments
What You Receive
- Defined and documented audit universe
- Facilitated risk assessment results by area
- Scoring model with rationale per ranking
- Three year rolling plan with annual detail
- Resource and budget estimate per engagement
- Committee approval pack and quarterly revision process
Indicative Timeline
Building a plan from scratch takes three to five weeks and is normally timed to precede the financial year. Annual refreshes are faster because the universe and scoring model already exist.
- Audit universe definition: one week
- Risk workshops with management: one to two weeks
- Scoring, plan build and costing: one week
- Committee presentation: next available cycle
What Drives the Plan
Coverage is driven by risk and by obligation, and both need to be visible to the committee approving it.
Inherent Risk
What could go wrong in each area before considering whether any control exists.
Control Maturity
Whether the control environment is strong enough to justify reduced coverage this cycle.
Time Since Coverage
An area untouched for three years attracts attention regardless of its risk score.
Prior Findings
Repeat findings signal an unresolved cause and pull an area up the ranking.
Statutory Obligation
PFMA, MFMA and Treasury requirements that mandate coverage regardless of risk scoring.
Management Request
Reserved capacity for areas the committee or executive asks to be examined during the year.
Frequently Asked Questions
How much coverage is enough?
There is no fixed percentage. The test is whether the committee can explain why the areas covered were chosen and why the uncovered ones were accepted. A defensible rationale matters more than a coverage ratio.
Should the plan follow the risk register?
It should align to it without being bound by it. Risk registers are self reported and frequently understate areas management is closest to. We use the register as an input and challenge it during the workshops.
Who approves the plan?
The audit committee. Management is consulted and contributes to the risk assessment, but a plan approved only by the people being audited is not an independent plan.
What if something urgent comes up mid year?
Contingency is built into the plan for exactly that. Where an unplanned request exceeds it, something planned is deferred, and that trade off goes to the committee rather than being absorbed silently.
How does ICT fit into the plan?
As auditable areas in their own right. ICT is frequently under covered because generalist internal audit teams lack the skills, which is a common reason for co-sourcing that specific coverage.
Do we need a three year plan or just annual?
The IIA standards expect a plan aligned to the organisation objectives, and a rolling multi year view shows the committee how the whole universe gets covered over time rather than only what happens next year.
Related Services
This sits inside our Internal Audit practice. Related work: Outsourced Internal Audit where the whole function is provided, and IT General Controls Reviews for ICT coverage within the plan.
