Risk-based audit plan
The annually refreshed audit plan based on a documented risk assessment of the organisation. The plan must originate from an identified risk universe, include a risk maturity assessment and ensure coordination with the second line and external assurance providers to prevent coverage gaps.
Source: IIA GIAS 2024, Standards 9.4 en 9.5
A risk-based audit plan is the annually refreshed audit plan that determines audit topics on the basis of a documented risk assessment of the organisation. The scarce audit capacity thus lands where the organisation's most significant risks lie. The plan originates from an identified risk universe, includes an assessment of risk maturity and coordinates with the second line and external assurance providers to prevent coverage gaps.
For the board, the supervisory board and the audit committee, the risk-based audit plan is where the priorities of internal audit become visible. It shows that the audit function directs its work towards what genuinely matters and that it deploys its resources responsibly. The plan is therefore an important topic of conversation between the Chief Audit Executive (CAE) and the audit committee: are the right risks covered, does the plan align with strategy and is there enough room for unforeseen topics.
In practice the plan starts with a risk universe: a structured overview of the organisational units, processes and risks relevant to audit. These are then weighed on impact, likelihood and risk maturity, and translated into a substantiated selection of engagements. The Global Internal Audit Standards 2024 address the risk-based audit plan in Standard 9.4 and coordination with other assurance providers in Standard 9.5. Such coordination prevents duplicated work and blind spots, and the plan is refreshed at least annually because the risk profile changes.
ONE Risk Advisory draws up risk-based audit plans that align with the organisation's strategy and risk profile. We make sure the plan meets the Standards, is practical to execute and is recognisable to the board and the audit committee. In this way, the audit plan becomes a management tool rather than a mandatory annual document.
Last updated:
Related service Internal Audit Support
Frequently asked questions
Why is an audit plan risk-based rather than routine?
Because audit capacity is scarce and should land where the most significant risks lie. A risk-based plan directs effort towards what genuinely matters, instead of visiting every unit at a fixed cadence regardless of risk.
What is a risk universe?
A risk universe is the structured overview of all organisational units, processes and risks relevant to internal audit. It is the starting point of the risk-based audit plan and ensures no important area is left out of view.
How often is the audit plan refreshed?
At least annually, and in the interim whenever the risk profile changes. A risk-based plan is by definition a living document, because the risks on which it rests are themselves in motion.
Why coordinate with other assurance providers?
To prevent duplicated work and blind spots. By aligning with the second line and external assurance providers, internal audit knows which risks are already covered elsewhere and where its own effort adds the most value.