A poorly constructed plan wastes limited audit resource on low-priority areas, leaves significant risks without coverage, and produces a programme of work that the board finds increasingly difficult to connect to what actually concerns them. A well-constructed plan is the foundation on which a strategically relevant internal audit function is built.
The IIA's Global Internal Audit Standards require that the chief audit executive develops a risk-based plan that takes into account the organisation's strategy, key business objectives, and associated risks, and that the plan is reviewed and approved by the board. This is a foundational requirement, not an optional refinement.
The audit universe is the complete inventory of everything that could potentially be audited: every significant business process, function, system, entity, and third-party relationship across the organisation. It is the population from which the annual plan is drawn, and its completeness determines the ceiling on the quality of the planning exercise.
A common mistake is constructing the audit universe primarily around financial processes and formal business functions while leaving out areas that carry significant risk but are less visible to a traditional audit perspective.
A comprehensive audit universe includes:
Core business processes (revenue generation, procurement, payroll, financial close, treasury). Operational functions (customer service, supply chain, facilities). Technology and information security (core systems, IT infrastructure, cybersecurity controls, data management). Compliance obligations (regulatory requirements relevant to the organisation's sector). Third-party relationships (critical suppliers, outsourced functions, key partnerships). Strategic and emerging areas (AI governance, new market entry, significant change programmes). Governance and conduct (tone at the top, conflicts of interest, whistleblowing processes).
An audit universe documented once and not revisited becomes outdated in proportion to the pace at which the organisation changes. New systems, acquisitions, regulatory changes, and strategic pivots all affect what the universe should contain. The IIA's practice guide on developing a risk-based internal audit plan recommends reviewing and updating the audit universe at least annually, and more frequently in organisations undergoing significant change.
The audit plan must flow from a documented risk assessment. The IIA's 2024 standards are explicit: the CAE must establish a risk-based plan based on the results of a risk assessment conducted at least annually.
The risk assessment evaluates each item in the audit universe against a consistent set of criteria that reflect its risk significance. The output is a risk-prioritised view of the universe that becomes the basis for plan construction.
The criteria used to assess each universe item should be defined in advance and applied consistently. Common criteria include:
Inherent risk: the significance of the risks present in the area, considering financial materiality, operational criticality, regulatory exposure, and reputational sensitivity.
Control environment maturity: how well developed and consistently applied the controls in the area are. An area with a demonstrably strong, independently verified control environment is lower priority than one with untested or recently changed controls.
Time since last audit: an area not reviewed for several years accumulates a higher priority weighting than one recently examined, all else being equal.
Rate of change: areas undergoing significant change, whether through system implementations, organisational restructuring, new products, or regulatory change, typically warrant more frequent attention.
Management and stakeholder concerns: what senior management, the board, and external regulators have raised as areas of concern.
The risk assessment should not be constructed by the internal audit function in isolation. The IIA's standards require the CAE to take into account input from senior management and the board. In practice this means consulting the second-line risk and compliance functions, reviewing the enterprise risk register, speaking with business unit leaders about what concerns them, and understanding the regulator's current areas of focus.
Risk and compliance functions typically have significant knowledge about where risk is concentrating that does not always make it into the audit planning process. Coordination avoids duplication and ensures that the audit plan and the second-line risk programme are complementary rather than overlapping.
The risk assessment produces a ranking. The audit plan translates that ranking into a programme of work that fits within the available resource.
Internal audit resource is finite, and the plan must be realistic about what can be achieved in the year. The practical steps are: calculate total available audit days after accounting for leave, training, quality management, and administrative overhead; estimate the time required for each planned engagement based on scope and complexity; and ensure the total does not exceed capacity.
A common planning failure is adding engagements to address board priorities without removing lower-priority ones. The result is a plan that is theoretically comprehensive but practically undeliverable, which means something will be dropped during the year, usually without explicit governance visibility of what has been deprioritised and why.
Another genuine planning trade-off is between coverage and depth. More engagements covering a broader range of areas produces wider coverage but shallower individual examinations. Fewer engagements with greater depth produces more thorough assurance in the areas selected but less coverage of the broader universe.
The right balance depends on the organisation's risk profile, the maturity of its control environment, and what the board most needs. An organisation with significant concentration of risk in a small number of areas may be better served by deep examination of those areas than by broad but superficial coverage across many.
A risk-based plan should match the type of engagement to the risk profile of the area. Full assurance engagements with extensive testing are appropriate for high-risk areas. Advisory engagements or control self-assessment facilitation may be appropriate for lower-risk areas or those where the primary value is capability building rather than independent assurance. Data analytics reviews can provide broad coverage of high-volume transaction areas at lower cost than traditional fieldwork. Matching engagement type to purpose is itself part of good plan design.
The board's approval of the audit plan should reflect genuine engagement, not a formal rubber-stamp of a document assembled without their input.
The audit committee's perspective on the organisation's most significant risks and governance concerns is a critical input to a credible audit plan. Board members often have visibility of strategic risks and external environment concerns that are not yet fully reflected in management's risk register. An audit committee chair who is asked "what keeps you awake at night?" and whose answer is not reflected anywhere in the audit plan has not been genuinely consulted.
The IIA's standards require the CAE to communicate the audit plan and resource requirements to senior management and the board for review and approval. The intent is substantive engagement, not a presentation to which the board assents without discussion.
When presenting the plan, the CAE should be able to explain the rationale for every inclusion and, just as importantly, every exclusion. Areas that fall within the universe but are not in the plan this year should be explained: what is the risk assessment basis for the lower priority, and when are they expected to receive coverage?
The board should also understand the resource assumptions underlying the plan. If the plan is built on assumptions about headcount that are not being met, or training needs that will reduce productive audit days, the board should know this before approving a plan that cannot be delivered as presented.
A plan approved in January should not be treated as immutable for the remaining eleven months. The risk environment changes, incidents occur, significant projects are launched, and regulators express concerns that were not anticipated at planning time.
A credible audit plan includes contingency, a defined proportion of available resource not committed to specific engagements, that can be allocated to unplanned work as it arises during the year. This is not waste. It is the mechanism through which internal audit can respond to significant developments without either abandoning planned engagements or becoming unable to address emerging priorities.
The IIA's practice guidance is clear that the CAE should monitor changes in business risks and adjust the plan accordingly, with significant changes communicated to and approved by the board.
Reporting progress against the plan to the audit committee on a quarterly basis, including any variations from the original plan and the reasons for them, maintains board visibility of how the programme is developing and ensures that any significant departures from the planned coverage are explicitly approved rather than happening by default.
Several patterns consistently produce audit plans that fail to deliver the assurance the board needs.
Building the plan around what was done last year. A plan shaped primarily by previous cycles is likely to reflect a risk environment that no longer fully applies, and to perpetuate coverage of areas that have reduced in significance while missing areas where risk has grown.
Producing the plan without genuine stakeholder consultation. An audit plan produced without meaningful input from management, the board, and the second-line functions may be technically sound but will be seen as disconnected from organisational priorities and will generate less board engagement with its conclusions.
Failing to acknowledge resource constraints honestly. An overambitious plan that is routinely under-delivered is worse than a more modest plan that is consistently completed, because it creates a false impression of coverage that the board may rely upon.
Never revisiting the plan during the year. An unresponsive plan that ignores significant developments sends a message about internal audit's relevance that is difficult to reverse.