Most internal audit functions cannot audit everything every year. They simply do not have the people, time, or budget. A risk-based internal audit plan solves this by directing scarce audit resources at the areas where risk is highest, rather than working through a fixed rotation. This guide explains what a risk-based plan is, how it differs from cyclical auditing, and how to build one from your audit universe and risk assessment.
What You'll Learn
By the end of this article you will understand the difference between risk-based and cyclical auditing, how to derive an annual plan from your audit universe and a risk assessment, how to prioritise and resource engagements, and how to get the plan approved by the board or audit committee. A worked example plan table is included.
What Is a Risk-Based Internal Audit Plan?
A risk-based internal audit plan is a forward-looking schedule of audit engagements that allocates audit effort in proportion to risk. Instead of asking "what is next on the rotation?", it asks "where is the organisation most exposed, and where can independent assurance add the most value?"
The plan is the output of a structured process. You define everything that could be audited (the audit universe), assess the risk of each auditable area, rank those areas, and then select the highest-priority engagements that fit within your available resources. The result is a documented, defensible answer to the perennial question: "Why are you auditing that, and not this?"
A good plan typically covers a defined period, most commonly twelve months, and specifies, for each engagement, the area to be audited, the rationale, the scope, the estimated effort, and the planned timing. It is approved by the audit committee and reviewed periodically so it stays relevant as risks shift.
Risk-Based vs Cyclical Auditing
The traditional approach is cyclical (or rotational) auditing. Every auditable unit is reviewed on a fixed cycle, say every three or five years, regardless of how its risk profile has changed. The appeal is fairness and simplicity. The weakness is that it spends the same effort on a low-risk, stable function as it does on a volatile, high-risk one.
| Dimension | Cyclical Auditing | Risk-Based Auditing |
|---|---|---|
| Driver | Fixed rotation / calendar | Assessed level of risk |
| Coverage | Everything, eventually | Highest risks first; some low-risk areas rarely |
| Effort allocation | Roughly equal per unit | Weighted toward high-risk units |
| Responsiveness | Slow, locked to the cycle | High; the plan flexes as risks emerge |
| Stakeholder value | Predictable but may miss the big issues | Focused on what matters most to objectives |
The two are not mutually exclusive. Many mature functions run a primarily risk-based plan but apply a "minimum coverage" rule, so that even low-risk areas are looked at occasionally, often every four or five years, to avoid blind spots. The professional standards published by the Institute of Internal Auditors (IIA) expect the plan to be risk-based, and most regulators and audit committees now treat a risk-based plan as the baseline expectation.
Important
"Risk-based" does not mean "only audit the red items." A function that never visits low-risk areas eventually loses sight of them, and low-risk areas drift into high-risk ones unnoticed. Build a minimum-coverage floor into your methodology so nothing is ignored indefinitely.
Building From the Audit Universe
The plan starts with the audit universe, the complete inventory of everything that could be audited. Each item is an "auditable unit": it might be a business process (procurement, payroll), a system (the ERP, the access-management platform), an entity (a subsidiary or branch), a key control area, or a strategic objective.
To build the universe, work top-down from the organisation's structure, objectives, and risk register, and bottom-up from processes and systems. Aim for units that are roughly comparable in size. If one unit is "the entire finance function" and another is "petty cash," your risk ranking will be distorted. A typical mid-size organisation ends up with somewhere between 40 and 150 auditable units.
Your enterprise risk register is a primary input here. The risks recorded there map onto auditable units and tell you where the organisation already believes its exposure lies. For the relationship between the two, see how risk registers support internal audit and our guide on preparing an audit risk register.
Want the full framework with worked examples?
Assessing and Scoring Risk
Once the universe is defined, score each auditable unit so you can rank it. Use a consistent set of risk factors and weight them. Common factors include:
- Inherent risk: the magnitude of risk in the area before controls are considered, covering materiality, complexity, volume, and regulatory exposure.
- Control environment: the strength and maturity of existing controls, and whether control effectiveness has been independently confirmed.
- Change: recent reorganisation, new systems, new leadership, or new products. Change is a reliable predictor of emerging risk.
- Time since last audit: the longer the gap, the higher the assurance risk.
- Management and audit-committee concern: areas flagged by leadership or where prior findings remain open.
Combine these into a single composite score per unit. Likelihood-and-impact thinking carries over directly from enterprise risk work; if you need a refresher, see likelihood and impact scoring.
| Risk Factor | Weight | Score (1 to 5) | Weighted |
|---|---|---|---|
| Inherent risk / materiality | 30% | 4 | 1.20 |
| Control environment | 25% | 5 | 1.25 |
| Recent change | 20% | 4 | 0.80 |
| Time since last audit | 15% | 3 | 0.45 |
| Management concern | 10% | 2 | 0.20 |
| Composite | 100% | 3.90 (High) |
Pro Tip
Score a higher control-environment number for a weaker control environment, so that weak controls push the composite risk up. Document the direction of each factor in your methodology so the scoring is repeatable across years and assessors.
Prioritising Audits by Risk
Sort the universe by composite score, descending. Group the units into bands (Critical, High, Medium, Low) and decide a coverage rule for each band:
- Critical: audit every year, or even more than once.
- High: audit every one to two years.
- Medium: audit every two to three years.
- Low: audit every four to five years (minimum coverage floor).
The ranking is the starting point, not the final answer. Apply judgement: a unit just below the line may rise above it because of a regulatory deadline, a fraud concern, or a request from the audit committee. Document every override and its rationale. That transparency is what makes the plan defensible.
From ranking to selection
Riverside Manufacturing has 60 auditable units. The risk assessment yields 6 Critical, 14 High, 22 Medium, and 18 Low units. With 720 available audit days for the year, the Chief Audit Executive selects all 6 Critical units, 9 of the 14 High units (the rest deferred to next year), 4 Medium units that are overdue, and 3 Low units to satisfy the minimum-coverage floor.
One Medium unit, export logistics, is promoted into the plan despite its score because a new customs system went live and a whistleblower complaint is open. The promotion is logged with its rationale so the audit committee can see exactly why effort was redirected.
Annual Plan vs Rolling Plan
There are two common formats. An annual plan fixes the engagements for the coming twelve months and is approved once. A rolling plan looks further ahead, often three years, and is refreshed every quarter, dropping completed engagements and pulling new ones forward as risks change.
Rolling plans are increasingly favoured because risk environments move faster than a year. The IIA's standards encourage a dynamic plan that is updated in response to changes in the organisation's strategy, operations, and risks. In practice many functions present an annual plan to the committee but treat it internally as a living document, formally revising it mid-year if material risks emerge.
Resourcing the Plan
A plan you cannot staff is a wish list. For each selected engagement, estimate the audit days required, then total them and compare against your available capacity. That capacity is the number of auditors multiplied by their productive days, minus leave, training, administration, and a contingency reserve (typically 10 to 15%) for unplanned work and investigations.
If demand exceeds capacity, you have three levers: defer lower-priority engagements, narrow scopes, or add resource through co-sourcing or guest auditors with specialist skills (for example, IT or data analytics). The gap between the ideal plan and the resourced plan is itself a message to the committee. It quantifies the assurance the organisation is choosing not to buy.
Important
Always present both the risk-prioritised wish list and the resourced plan. If the committee sees only what fits in the budget, it cannot make an informed decision about whether to fund more assurance. Surfacing the gap is part of the Chief Audit Executive's responsibility.
Board and Audit-Committee Approval
The audit plan should be formally reviewed and approved by the audit committee (or the board where there is no separate committee). This approval is what gives internal audit its mandate to enter, examine, and report on the selected areas, and it is documented in the audit charter.
When you present the plan, include the methodology used, the audit universe and how it was scored, the selected engagements with rationale, the resource analysis, the coverage achieved versus the universe, and any significant areas not being audited and why. The committee's role is to challenge the priorities, confirm the plan aligns with the organisation's risks, and ensure internal audit has the resources to deliver it. Once approved, the plan and any subsequent material changes are minuted.
Example Annual Plan Table
A finished plan is usually a single page the committee can absorb at a glance:
| Engagement | Risk Band | Quarter | Est. Days | Rationale |
|---|---|---|---|---|
| Cyber access management | Critical | Q1 | 40 | New IAM platform; high inherent risk |
| Revenue and billing | Critical | Q1 | 35 | Material; prior findings open |
| Procurement & vendor onboarding | High | Q2 | 30 | Fraud exposure; 2 years since last audit |
| Export logistics (customs) | Medium, promoted | Q2 | 25 | New customs system; open complaint |
| Payroll | High | Q3 | 20 | Annual; regulatory reporting |
| Facilities & petty cash | Low | Q4 | 10 | Minimum coverage floor (5-year) |
| Contingency / advisory | Reserve | Rolling | 90 | Reserve for emerging risk and requests |
Common Mistakes to Avoid
1. Treating the plan as a calendar, not a risk tool
If the plan never changes once approved, it is cyclical auditing wearing a risk-based label. Revisit it when the risk picture shifts.
2. An audit universe that is wrong or stale
If the universe omits new systems, entities, or processes, those areas will never be ranked, and never audited. Refresh the universe before each planning cycle.
3. Scoring inconsistently
If risk factors are interpreted differently year to year, the ranking is not comparable. Lock down definitions and weights in a documented methodology.
4. Ignoring resource reality
A plan that needs 900 days against 700 days of capacity will fail silently mid-year. Resource it honestly and show the committee the gap.
5. No minimum coverage
Auditing only the red items means low-risk areas are never tested, and they silently drift upward. Build a coverage floor.
6. Approving without documenting rationale
If you cannot explain why an area is in or out of the plan, you cannot defend the plan to regulators or the board.
Summary
- A risk-based audit plan allocates effort in proportion to risk, not to a fixed rotation
- It is built from the audit universe and a consistent, weighted risk assessment
- Prioritise into bands, then select engagements that fit your resourced capacity
- Rolling plans flex with changing risk; annual plans are simpler but slower
- Always show the committee both the ideal plan and the resourced plan
- The audit committee approves the plan; document every selection and override
Frequently Asked Questions
How long should an internal audit plan cover?
Most plans cover twelve months and are formally approved annually. Many functions also maintain a three-year rolling view that is refreshed quarterly, so the plan can respond to emerging risks rather than staying frozen for a year.
Does a risk-based plan mean low-risk areas are never audited?
No. Good practice is to set a minimum-coverage floor, for example auditing every low-risk area at least once every four or five years, so nothing is ignored indefinitely and areas that silently drift into higher risk are caught.
Who approves the internal audit plan?
The audit committee (or the board where there is no committee) reviews and approves the plan. This approval, together with the audit charter, gives internal audit the mandate to carry out the engagements.
What is the audit universe?
The audit universe is the complete inventory of everything that could be audited: processes, systems, entities, and control areas. The plan is built by scoring each unit in the universe for risk and selecting the highest-priority ones.
Can the plan change after it is approved?
Yes, and it should, when risks change materially. A new system failure, a fraud allegation, or a major reorganisation may justify pulling an engagement forward or adding one. Material changes are taken back to the audit committee and minuted.
How do I resource a plan that is bigger than my team?
Defer lower-priority engagements, narrow scopes, or co-source specialist work. Crucially, present the gap between the ideal plan and the resourced plan to the committee so leadership can decide whether to fund additional assurance.
Save this guide for later
Download the PDF version to read offline or share with your team.

