KITE 2025 New Product Award — Local IT | SACEEC

What Is a Risk-Based Internal Audit Plan? Definition, Method and Example

Stop auditing on a fixed rotation and start directing audit effort where risk actually lives. This guide shows you how to build a risk-based internal audit plan.

Free PDF GuideDownload this guide as a PDF

Most internal audit functions cannot audit everything every year. They simply do not have the people, time, or budget. A risk-based internal audit plan solves this by directing scarce audit resources at the areas where risk is highest, rather than working through a fixed rotation. This guide explains what a risk-based plan is, how it differs from cyclical auditing, and how to build one from your audit universe and risk assessment.

Watch: What is a risk-based internal audit plan Watch: Building a risk-based audit plan (short tutorial)
i

What You'll Learn

By the end of this article you will understand the difference between risk-based and cyclical auditing, how to derive an annual plan from your audit universe and a risk assessment, how to prioritise and resource engagements, and how to get the plan approved by the board or audit committee. A worked example plan table is included.

What Is a Risk-Based Internal Audit Plan?

A risk-based internal audit plan is a forward-looking schedule of audit engagements that allocates audit effort in proportion to risk. Instead of asking "what is next on the rotation?", it asks "where is the organisation most exposed, and where can independent assurance add the most value?"

The plan is the output of a structured process. You define everything that could be audited (the audit universe), assess the risk of each auditable area, rank those areas, and then select the highest-priority engagements that fit within your available resources. The result is a documented, defensible answer to the perennial question: "Why are you auditing that, and not this?"

A good plan typically covers a defined period, most commonly twelve months, and specifies, for each engagement, the area to be audited, the rationale, the scope, the estimated effort, and the planned timing. It is approved by the audit committee and reviewed periodically so it stays relevant as risks shift.

Risk-Based vs Cyclical Auditing

The traditional approach is cyclical (or rotational) auditing. Every auditable unit is reviewed on a fixed cycle, say every three or five years, regardless of how its risk profile has changed. The appeal is fairness and simplicity. The weakness is that it spends the same effort on a low-risk, stable function as it does on a volatile, high-risk one.

Dimension Cyclical Auditing Risk-Based Auditing
Driver Fixed rotation / calendar Assessed level of risk
Coverage Everything, eventually Highest risks first; some low-risk areas rarely
Effort allocation Roughly equal per unit Weighted toward high-risk units
Responsiveness Slow, locked to the cycle High; the plan flexes as risks emerge
Stakeholder value Predictable but may miss the big issues Focused on what matters most to objectives

The two are not mutually exclusive. Many mature functions run a primarily risk-based plan but apply a "minimum coverage" rule, so that even low-risk areas are looked at occasionally, often every four or five years, to avoid blind spots. The professional standards published by the Institute of Internal Auditors (IIA) expect the plan to be risk-based, and most regulators and audit committees now treat a risk-based plan as the baseline expectation.

!

Important

"Risk-based" does not mean "only audit the red items." A function that never visits low-risk areas eventually loses sight of them, and low-risk areas drift into high-risk ones unnoticed. Build a minimum-coverage floor into your methodology so nothing is ignored indefinitely.

Building From the Audit Universe

The plan starts with the audit universe, the complete inventory of everything that could be audited. Each item is an "auditable unit": it might be a business process (procurement, payroll), a system (the ERP, the access-management platform), an entity (a subsidiary or branch), a key control area, or a strategic objective.

To build the universe, work top-down from the organisation's structure, objectives, and risk register, and bottom-up from processes and systems. Aim for units that are roughly comparable in size. If one unit is "the entire finance function" and another is "petty cash," your risk ranking will be distorted. A typical mid-size organisation ends up with somewhere between 40 and 150 auditable units.

Your enterprise risk register is a primary input here. The risks recorded there map onto auditable units and tell you where the organisation already believes its exposure lies. For the relationship between the two, see how risk registers support internal audit and our guide on preparing an audit risk register.

Want the full framework with worked examples?

Assessing and Scoring Risk

Once the universe is defined, score each auditable unit so you can rank it. Use a consistent set of risk factors and weight them. Common factors include:

  • Inherent risk: the magnitude of risk in the area before controls are considered, covering materiality, complexity, volume, and regulatory exposure.
  • Control environment: the strength and maturity of existing controls, and whether control effectiveness has been independently confirmed.
  • Change: recent reorganisation, new systems, new leadership, or new products. Change is a reliable predictor of emerging risk.
  • Time since last audit: the longer the gap, the higher the assurance risk.
  • Management and audit-committee concern: areas flagged by leadership or where prior findings remain open.

Combine these into a single composite score per unit. Likelihood-and-impact thinking carries over directly from enterprise risk work; if you need a refresher, see likelihood and impact scoring.

Risk Factor Weight Score (1 to 5) Weighted
Inherent risk / materiality 30% 4 1.20
Control environment 25% 5 1.25
Recent change 20% 4 0.80
Time since last audit 15% 3 0.45
Management concern 10% 2 0.20
Composite 100% 3.90 (High)
i

Pro Tip

Score a higher control-environment number for a weaker control environment, so that weak controls push the composite risk up. Document the direction of each factor in your methodology so the scoring is repeatable across years and assessors.

Prioritising Audits by Risk

Sort the universe by composite score, descending. Group the units into bands (Critical, High, Medium, Low) and decide a coverage rule for each band:

  • Critical: audit every year, or even more than once.
  • High: audit every one to two years.
  • Medium: audit every two to three years.
  • Low: audit every four to five years (minimum coverage floor).

The ranking is the starting point, not the final answer. Apply judgement: a unit just below the line may rise above it because of a regulatory deadline, a fraud concern, or a request from the audit committee. Document every override and its rationale. That transparency is what makes the plan defensible.

Example

From ranking to selection

Riverside Manufacturing has 60 auditable units. The risk assessment yields 6 Critical, 14 High, 22 Medium, and 18 Low units. With 720 available audit days for the year, the Chief Audit Executive selects all 6 Critical units, 9 of the 14 High units (the rest deferred to next year), 4 Medium units that are overdue, and 3 Low units to satisfy the minimum-coverage floor.

One Medium unit, export logistics, is promoted into the plan despite its score because a new customs system went live and a whistleblower complaint is open. The promotion is logged with its rationale so the audit committee can see exactly why effort was redirected.

Annual Plan vs Rolling Plan

There are two common formats. An annual plan fixes the engagements for the coming twelve months and is approved once. A rolling plan looks further ahead, often three years, and is refreshed every quarter, dropping completed engagements and pulling new ones forward as risks change.

Rolling plans are increasingly favoured because risk environments move faster than a year. The IIA's standards encourage a dynamic plan that is updated in response to changes in the organisation's strategy, operations, and risks. In practice many functions present an annual plan to the committee but treat it internally as a living document, formally revising it mid-year if material risks emerge.

Resourcing the Plan

A plan you cannot staff is a wish list. For each selected engagement, estimate the audit days required, then total them and compare against your available capacity. That capacity is the number of auditors multiplied by their productive days, minus leave, training, administration, and a contingency reserve (typically 10 to 15%) for unplanned work and investigations.

If demand exceeds capacity, you have three levers: defer lower-priority engagements, narrow scopes, or add resource through co-sourcing or guest auditors with specialist skills (for example, IT or data analytics). The gap between the ideal plan and the resourced plan is itself a message to the committee. It quantifies the assurance the organisation is choosing not to buy.

!

Important

Always present both the risk-prioritised wish list and the resourced plan. If the committee sees only what fits in the budget, it cannot make an informed decision about whether to fund more assurance. Surfacing the gap is part of the Chief Audit Executive's responsibility.

Board and Audit-Committee Approval

The audit plan should be formally reviewed and approved by the audit committee (or the board where there is no separate committee). This approval is what gives internal audit its mandate to enter, examine, and report on the selected areas, and it is documented in the audit charter.

When you present the plan, include the methodology used, the audit universe and how it was scored, the selected engagements with rationale, the resource analysis, the coverage achieved versus the universe, and any significant areas not being audited and why. The committee's role is to challenge the priorities, confirm the plan aligns with the organisation's risks, and ensure internal audit has the resources to deliver it. Once approved, the plan and any subsequent material changes are minuted.

Example Annual Plan Table

A finished plan is usually a single page the committee can absorb at a glance:

Engagement Risk Band Quarter Est. Days Rationale
Cyber access management Critical Q1 40 New IAM platform; high inherent risk
Revenue and billing Critical Q1 35 Material; prior findings open
Procurement & vendor onboarding High Q2 30 Fraud exposure; 2 years since last audit
Export logistics (customs) Medium, promoted Q2 25 New customs system; open complaint
Payroll High Q3 20 Annual; regulatory reporting
Facilities & petty cash Low Q4 10 Minimum coverage floor (5-year)
Contingency / advisory Reserve Rolling 90 Reserve for emerging risk and requests

Common Mistakes to Avoid

1. Treating the plan as a calendar, not a risk tool

If the plan never changes once approved, it is cyclical auditing wearing a risk-based label. Revisit it when the risk picture shifts.

2. An audit universe that is wrong or stale

If the universe omits new systems, entities, or processes, those areas will never be ranked, and never audited. Refresh the universe before each planning cycle.

3. Scoring inconsistently

If risk factors are interpreted differently year to year, the ranking is not comparable. Lock down definitions and weights in a documented methodology.

4. Ignoring resource reality

A plan that needs 900 days against 700 days of capacity will fail silently mid-year. Resource it honestly and show the committee the gap.

5. No minimum coverage

Auditing only the red items means low-risk areas are never tested, and they silently drift upward. Build a coverage floor.

6. Approving without documenting rationale

If you cannot explain why an area is in or out of the plan, you cannot defend the plan to regulators or the board.

Key Takeaways

Summary

  • A risk-based audit plan allocates effort in proportion to risk, not to a fixed rotation
  • It is built from the audit universe and a consistent, weighted risk assessment
  • Prioritise into bands, then select engagements that fit your resourced capacity
  • Rolling plans flex with changing risk; annual plans are simpler but slower
  • Always show the committee both the ideal plan and the resourced plan
  • The audit committee approves the plan; document every selection and override

Frequently Asked Questions

How long should an internal audit plan cover?

Most plans cover twelve months and are formally approved annually. Many functions also maintain a three-year rolling view that is refreshed quarterly, so the plan can respond to emerging risks rather than staying frozen for a year.

Does a risk-based plan mean low-risk areas are never audited?

No. Good practice is to set a minimum-coverage floor, for example auditing every low-risk area at least once every four or five years, so nothing is ignored indefinitely and areas that silently drift into higher risk are caught.

Who approves the internal audit plan?

The audit committee (or the board where there is no committee) reviews and approves the plan. This approval, together with the audit charter, gives internal audit the mandate to carry out the engagements.

What is the audit universe?

The audit universe is the complete inventory of everything that could be audited: processes, systems, entities, and control areas. The plan is built by scoring each unit in the universe for risk and selecting the highest-priority ones.

Can the plan change after it is approved?

Yes, and it should, when risks change materially. A new system failure, a fraud allegation, or a major reorganisation may justify pulling an engagement forward or adding one. Material changes are taken back to the audit committee and minuted.

How do I resource a plan that is bigger than my team?

Defer lower-priority engagements, narrow scopes, or co-source specialist work. Crucially, present the gap between the ideal plan and the resourced plan to the committee so leadership can decide whether to fund additional assurance.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.