Understanding what risk-based auditing genuinely involves, how it differs from alternative approaches, and what distinguishes a mature risk-based programme from one that has adopted the terminology without the substance, is the purpose of this article.
Risk-based internal auditing directs audit resource toward the areas of greatest risk to the organisation's objectives, rather than rotating through a fixed schedule of audit areas regardless of how their risk profile has changed. The fundamental principle is straightforward: where risk is highest, assurance is most needed, and audit resource should follow risk.
This requires two things to be true simultaneously. First, the internal audit function must have a credible, documented understanding of where risk is greatest across the organisation. Second, it must be willing to make genuine trade-off decisions, spending more time and effort on high-risk areas and less on low-risk ones, even if that means some areas receive infrequent or no direct audit coverage.
Neither of these is as straightforward as it sounds.
The contrast with cyclical auditing helps clarify what risk-based means in practice.
Cyclical auditing works through a fixed rotation. A schedule is set, typically covering a two or three-year period, in which every significant audit area is examined once. The schedule advances regardless of changes in risk significance. An area audited recently may receive a clean opinion but still appear on next year's schedule. An area where risk has materially increased since its last review may not be examined for another eighteen months because it is not yet "due."
The appeal of cyclical auditing is predictability. Business units know when they will be audited. The audit committee can see that coverage is comprehensive over the cycle. The function's work can be planned far in advance. These are genuine advantages for a function operating in a stable environment.
The weakness is that it treats all areas as equally deserving of audit attention regardless of their actual risk profile. A well-controlled, low-risk function and a poorly controlled, high-risk process receive the same frequency of coverage. In an environment where risk changes and audit resource is limited, this is an inefficient allocation.
Risk-based auditing replaces the fixed rotation with a dynamic assessment. At least annually, and often more frequently for volatile risk environments, the audit function reassesses where risk is concentrated across the organisation and constructs the audit plan to reflect those conclusions.
An area that has remained stable, with well-evidenced controls and no significant changes, may reasonably receive attention every three or four years. An area where risk has increased significantly, whether through process change, system implementation, personnel change, or external developments, moves up the priority list regardless of when it was last audited.
This requires genuine willingness to deprioritise areas. A function that claims to be risk-based but whose plan always includes every area on a roughly equal rotation has not actually made the shift. Risk-based auditing produces unequal coverage by design.
The quality of risk-based auditing depends entirely on the quality of the risk assessment that drives it. A risk assessment that is superficial, poorly evidenced, or shaped by the preferences of those being audited rather than by objective analysis produces a plan that looks risk-based but is not.
The IIA's practice guidance on risk-based audit planning describes the risk assessment as a process that identifies and evaluates risks that could prevent the organisation from achieving its objectives, and uses those findings to determine the areas that need internal audit attention.
A credible risk assessment draws on multiple sources. The enterprise risk register, reviewed with an understanding of how current and well-evidenced the ratings are. Input from senior management and the board, including their perspectives on emerging risks and areas of concern. Second-line risk and compliance function data. External sources including regulatory guidance, sector risk outlooks, and the experience of peer organisations. And internal audit's own knowledge of the organisation accumulated from previous engagements.
The risk assessment for audit planning purposes should be focused on residual risk rather than inherent risk alone. Areas with high inherent risk but strong, well-evidenced controls operating effectively may warrant less frequent audit attention than areas where inherent risk is moderate but control effectiveness is uncertain. The question for audit planning is not "how risky could this be?" but "how well protected is the organisation against this risk right now?"
This distinction matters because it prevents the risk assessment from defaulting to coverage of the organisation's most inherently risky areas regardless of control quality. A mature risk-based programme uses audit resource to examine the areas where the combination of risk and control uncertainty is greatest.
A risk-based programme does not apply the same type of engagement to every area. The engagement type should be matched to what is most needed given the area's risk profile and what the board needs to know.
Full assurance engagements, involving scoping, fieldwork, testing, finding identification, and formal reporting, are appropriate for the highest-risk areas or those where the board requires positive assurance that controls are operating effectively. These engagements carry the most resource cost and should be reserved for areas that genuinely warrant that investment.
For areas where the primary value of internal audit involvement is helping management improve rather than providing independent assurance, an advisory or consulting engagement may be more appropriate. Being involved in a significant change programme at the design stage, facilitating a control self-assessment workshop, or reviewing a draft policy for risk and control implications, these advisory activities can deliver significant value without the overhead of a full assurance engagement.
The IIA's standards permit advisory work subject to independence considerations: where advisory involvement creates a threat to the objectivity needed for subsequent assurance work over the same area, that threat must be managed.
Data analytics applied to complete transaction populations allows internal audit to monitor control effectiveness across high-volume areas on a continuous or frequent basis, rather than examining a sample during a periodic engagement. Payment anomaly detection, access control monitoring, and exception identification across large data sets can all be conducted analytically.
The IIA's guidance on data analytics notes that analytics can expand coverage significantly and identify issues that sample-based testing would not reliably detect. For many organisations, integrating data analytics into the risk-based programme substantially increases the breadth of coverage achievable within existing resource constraints.
Within each engagement, risk-based thinking applies at the individual audit level as well as the planning level. A risk-based engagement focuses fieldwork on the specific risks identified in planning and the specific controls designed to manage those risks, rather than attempting comprehensive coverage of everything in the audit area.
Engagement planning begins with a clear definition of the audit objectives: what specific risks or control questions is this engagement designed to answer? The engagement scope should then be limited to what is necessary to answer those questions. Scope creep, expanding the engagement beyond what is needed to address the identified risks, dilutes resource and often produces findings that are interesting but peripheral to what the board needs to know.
The Chartered Institute of Internal Auditors emphasises that engagement planning should include an explicit assessment of the risks relevant to the area and the controls in place, which then drives the selection of audit tests. Testing that is not clearly connected to a specific risk or control objective is difficult to justify in a resource-constrained function.
Internal audit uses a range of fieldwork techniques, and selecting the right method for each control or risk being tested is itself a form of risk-based thinking.
Inquiry involves asking control owners and staff how processes work and how controls are applied. It is an essential source of understanding but is not on its own sufficient evidence of control effectiveness. What people say they do may differ from what they demonstrably did.
Observation involves watching a control or process being performed. It is direct evidence of how things work in practice but only captures a single point in time and may be affected by awareness that an audit is underway.
Inspection involves reviewing documents, records, and systems to obtain evidence of how controls operated during the audit period. It is typically the most substantive form of evidence for controls that leave a documentary trail.
Re-performance involves the auditor independently repeating a control procedure and comparing the result to the actual outcome. It is particularly useful for calculation-based controls.
Data analytics involves applying analytical techniques to data to identify patterns, anomalies, and exceptions that provide evidence about control effectiveness or risk exposure across a population.
Where it is not feasible to test the entire population of control instances, sampling is used to draw conclusions about the population. The IIA's guidance on sampling provides direction on sample sizes and selection methods. Key principles are that samples should be large enough to support the conclusions drawn, selection should be genuinely random unless there is a specific reason for judgmental selection, and the conclusions drawn from the sample should be appropriately qualified to reflect the sampling approach used.
Risk-based findings reporting should connect findings explicitly to the risks they relate to. A finding that describes what went wrong without connecting it to the risk that the failed control was designed to address does not give the board the information it needs to assess the significance of the finding.
Findings should be prioritised by risk significance, with the most material issues receiving the most prominent treatment. A risk-based report that buries a significant control failure among numerous lower-priority observations is not serving the board well.
Follow-up is where the value of audit work is often lost or realised. The IIA's standards require the CAE to establish a process for monitoring whether management actions on audit findings have been implemented effectively. A finding that has been reported and acknowledged but where management's remediation action has not been implemented, or has been implemented ineffectively, requires escalation to the audit committee. The board accepted risk based on the assumption that identified weaknesses would be addressed.
Several characteristics distinguish a genuinely mature risk-based programme from one that has adopted the language without the substance.
The plan contains areas that receive high coverage because risk is high, and areas that receive little or no coverage because risk is genuinely low. The differential in coverage is documented and explainable. The risk assessment draws explicitly on multiple sources of evidence and is updated when significant changes occur. Engagement types are varied and matched to the purpose of each engagement. Findings are connected clearly to risks. Follow-up is systematic, and the audit committee is informed where management action is insufficient. And the whole programme is reviewed periodically against the IIA's standards through a quality assurance process.