Internal audit cannot review everything every year. To decide where to look first, you need a complete map of everything that could be audited, plus a consistent way to rank those things by risk. That map is the audit universe. This guide explains what it is, how to build one, how to keep it current, and how it feeds your annual audit plan.
What You'll Learn
By the end of this article you will understand what an audit universe is, how to identify and structure every auditable entity, how to score those entities by risk, how the universe drives your audit plan, and how to keep it current. A worked example universe table is included.
What Is an Audit Universe?
An audit universe is the complete inventory of all the areas, units, processes, systems, and entities within an organization that internal audit could potentially review. It is the full population of auditable entities, the universe from which the annual and multi-year audit plans are drawn.
Think of it as the map before the journey. Just as a risk register is the inventory of risks an organization faces, the audit universe is the inventory of things the audit function could examine to provide assurance over those risks. Each entry in the universe is a candidate for auditing. The audit plan decides which candidates actually get audited, and when.
A well-constructed audit universe answers three questions for the Chief Audit Executive (CAE) and the audit committee:
- Coverage: What is the full set of things we are responsible for providing assurance over?
- Prioritization: Which of those things carry the most risk and therefore deserve attention first?
- Cycle: How often should each area be audited, so that nothing material goes unexamined for too long?
Without a defined universe, audit planning comes down to habit, gut feel, or whoever shouts loudest. With one, planning becomes a defensible, risk-based exercise that you can explain to the board and to external auditors.
Auditable Entities: Units, Processes and Systems
The building block of the audit universe is the auditable entity, a discrete area that can be scoped, examined, and reported on as a self-contained engagement. The art of building a good universe lies in choosing the right level of granularity. Too coarse ("Finance") and you cannot meaningfully scope or score it. Too fine ("the petty cash float in the Durban branch") and your universe balloons into thousands of unmanageable line items.
Most audit functions define their universe along one or more of these dimensions:
| Lens | What It Groups By | Example Auditable Entities |
|---|---|---|
| Organizational | Business units, divisions, branches, legal entities | Retail Division, Treasury, Eastern Cape Branch Network |
| Process / Cycle | End-to-end business processes | Procure-to-Pay, Order-to-Cash, Payroll, Customer Onboarding |
| System / Technology | Applications and infrastructure | ERP General Ledger, Identity & Access Management, Cloud Hosting |
| Risk / Theme | Cross-cutting risk domains | Cybersecurity, POPIA Data Privacy, Third-Party Risk, Fraud |
| Regulatory | Compliance obligations | Anti-Money-Laundering, Health & Safety, Tax Compliance |
Many functions blend lenses. A primarily process-based universe might have a handful of thematic entities (cyber, fraud, privacy) layered on top to ensure cross-cutting risks are not lost between process silos.
How to Identify Your Auditable Entities
Build the inventory from multiple sources so nothing is missed:
- Organizational chart and legal structure: every division, function, subsidiary, and branch.
- Process maps and the value chain: the end-to-end processes that run the business.
- Application and asset registers: the systems that support those processes.
- The enterprise risk register: a strong universe maps directly onto the organization's risks. See how risk registers support internal audit.
- Regulatory and compliance obligations: the laws and standards you must demonstrably meet.
- The strategy and major change initiatives: new products, acquisitions, and transformation programs are auditable too.
Pro Tip
Aim for an audit universe of roughly 40 to 150 entities for a mid-sized organization. If you have thousands, your granularity is too fine. If you have a dozen, it is too coarse to plan against. The right number is the one where each entity could realistically become a single, scopeable engagement.
Want the full framework with worked examples?
Scoring Auditable Entities by Risk
Listing entities is only half the job. To turn the universe into a plan, you score each entity for risk so that high-risk areas rise to the top. This is what makes the resulting plan risk-based rather than arbitrary. The scoring should align with the same risk language the rest of the organization uses. See our guide to likelihood and impact scoring.
A practical approach is to score each entity against a small set of weighted risk factors, then combine them into a single composite score that drives prioritization and audit frequency.
| Risk Factor | What It Measures | Typical Weight |
|---|---|---|
| Inherent risk | Materiality, complexity, and exposure before controls | 25% |
| Control environment | Maturity and reliability of existing controls | 20% |
| Financial significance | Value of transactions, assets, or revenue involved | 15% |
| Regulatory exposure | Severity of consequences for non-compliance | 15% |
| Change & volatility | Recent reorganizations, system changes, or new leadership | 15% |
| Time since last audit | How long the area has gone unexamined | 10% |
Each factor is rated on a consistent scale (for example 1 to 5), multiplied by its weight, and summed. The result is a composite risk rating, commonly banded into High, Medium, and Low, that determines both priority and how often the entity should appear in the plan.
Composite Risk Score
Note the role of the control environment factor. Inherent risk tells you how exposed an area is before controls. The control factor adjusts for how well that exposure is currently managed. The combination is effectively a residual-risk view. See inherent vs residual risk for the underlying concept and control effectiveness for how the control rating is judged.
Important
Do not let scoring become a false-precision exercise. The factors and weights are a structured way to apply judgement, not a black box that produces "the answer." The CAE should always be able to override a score with documented rationale, for example to schedule an audit a regulator has specifically requested.
How the Universe Feeds the Audit Plan
Once every entity is scored, the universe becomes the engine of the annual and multi-year audit plan. The mechanics are straightforward:
- Rank entities by composite score. The highest-risk entities are the priority candidates.
- Assign audit cycles. High-risk entities might be audited annually, medium-risk every two to three years, and low-risk on a longer rotation or via continuous monitoring.
- Fit to capacity. Compare the demanded coverage against available audit days and budget. The plan is where ambition meets reality.
- Balance the portfolio. Ensure coverage across risk themes, business units, and assurance types, not just a stack of finance audits.
- Document what is excluded. Everything in the universe that is not in this year's plan is a deliberate, documented choice, your coverage gap analysis.
This is the bridge from universe to plan. For the full method of turning these inputs into an approved annual plan, see what is a risk-based internal audit plan.
A Simplified Audit Universe Extract
A mid-sized financial services firm scores its universe on a 1 to 5 scale across the weighted factors above. An extract of the resulting universe table:
| Auditable Entity | Type | Composite Score | Rating | Cycle | Last Audited |
|---|---|---|---|---|---|
| Cybersecurity & Access Management | System / Theme | 4.6 | High | Annual | 2025 |
| Anti-Money-Laundering Compliance | Regulatory | 4.4 | High | Annual | 2024 |
| Procure-to-Pay | Process | 3.5 | Medium | 2 years | 2023 |
| Payroll | Process | 2.8 | Medium | 3 years | 2024 |
| Facilities & Fleet | Org Unit | 1.9 | Low | 4 years | 2021 |
From this extract, the planner would slot the two High-rated entities into the current year, schedule Procure-to-Pay (due based on cycle), and note that Facilities & Fleet has not been touched since 2021 despite its low score, so it warrants a refresh.
Keeping the Universe Current
An audit universe is not a one-time artefact. Organizations restructure, launch products, adopt new systems, and face new regulations, and a stale universe quietly produces blind spots. The universe should be reviewed and refreshed on a defined rhythm.
- Annual full refresh: revisit every entity, re-score against current risk, and reconcile against the latest org chart and risk register as part of annual planning.
- Trigger-based updates: add or rescore entities when major events occur, such as an acquisition, a new ERP, a new regulation, a significant incident, or a leadership change.
- Continuous risk inputs: feed in signals from the enterprise risk function, management self-assessments, prior audit findings, and external events.
- Version control: keep a documented history of changes so the board can see how coverage decisions evolved.
Pro Tip
Link the audit universe directly to the enterprise risk register so that when a new risk is logged, the corresponding auditable entity is prompted for review. A connected platform keeps the two in sync automatically instead of relying on a once-a-year reconciliation in a spreadsheet.
Common Mistakes to Avoid
1. Building It Once and Letting It Rot
A universe that is never refreshed becomes a record of the organization that existed three years ago. Schedule reviews and tie updates to organizational change.
2. Wrong Granularity
Too coarse and entities cannot be scored or scoped. Too fine and the universe is unmanageable. Calibrate so each entity is a realistic single engagement.
3. Scoring Without Consistent Criteria
If different team members interpret the risk factors differently, the rankings are meaningless. Define each factor and rating level explicitly, and calibrate as a team.
4. Ignoring Cross-Cutting Risks
A purely process- or unit-based universe can let themes like cyber, fraud, and data privacy fall between the cracks. Add thematic entities deliberately.
5. Confusing the Universe With the Plan
The universe is everything you could audit. The plan is what you will audit this year. Keeping them distinct is what makes your coverage gaps visible and defensible.
Summary
- The audit universe is the complete inventory of everything internal audit could examine
- Build it from org structure, process maps, systems, the risk register, and regulatory obligations
- Choose a granularity where each entity is a realistic single engagement (often 40 to 150 entities)
- Score each entity against weighted risk factors to produce a composite, risk-based ranking
- The scored universe drives audit cycles, priorities, and documented coverage gaps in the plan
- Refresh annually and on major change so the universe never produces blind spots
Frequently Asked Questions
What is the difference between an audit universe and an audit plan?
The audit universe is the full population of everything internal audit could review. The audit plan is the selected subset that audit will review in a given period, chosen by ranking the universe by risk and fitting it to available capacity. The universe feeds the plan.
How many entities should an audit universe contain?
There is no fixed number, but a mid-sized organization typically lands somewhere between 40 and 150 auditable entities. The right granularity is the level at which each entity could become a single, scopeable engagement, neither so broad it cannot be planned against nor so narrow that the list becomes unmanageable.
How is the audit universe related to the risk register?
They are complementary. The risk register records the risks the organization faces. The audit universe records the areas audit could examine to provide assurance over those risks. A strong universe maps directly onto the register, and many functions use the register as a primary input when building and refreshing the universe. See risk registers and internal audit for the connection.
How often should the audit universe be updated?
At minimum, perform a full refresh annually as part of audit planning. In addition, update it on a trigger basis whenever a major event occurs, such as an acquisition, a new core system, a significant new regulation, a major incident, or a leadership change, so the universe never lags behind the real organization.
Who owns the audit universe?
The Chief Audit Executive owns the audit universe and the risk-based plan derived from it. The audit committee typically reviews and approves the resulting plan. While the CAE owns it, building and refreshing the universe is a collaborative exercise that draws on the enterprise risk function, management, and prior audit results.
Can a small audit team still benefit from an audit universe?
Absolutely, and arguably more so. The smaller the team, the more important it is to spend limited days on the highest-risk areas. Even a one-page universe of 30 entities with simple high/medium/low ratings gives a small function a defensible, risk-based basis for its plan and a clear story to tell the audit committee.
Save this guide for later
Download the PDF version to read offline or share with your team.

