Internal Audit

Risk-based audit plan

The annually refreshed audit plan based on a documented risk assessment of the organization. The plan must originate from an identified risk universe, include a risk maturity assessment and ensure coordination with second and third line assurance providers to prevent coverage gaps in the risk management landscape.

Source: IIA GIAS 2024, Standards 9.4-9.5

A risk-based audit plan is the annually refreshed audit plan that determines audit topics on the basis of a documented risk assessment of the organisation. Instead of spreading capacity evenly or by routine, the scarce audit capacity lands where the organisation's most significant risks lie. The plan originates from an identified risk universe, includes an assessment of risk maturity and coordinates with assurance providers in the second and third line to prevent coverage gaps.

For the board, the supervisory board and the audit committee, the risk-based audit plan is where the priorities of internal audit become visible. It shows that the audit function directs its work towards what genuinely matters and that it deploys its resources responsibly. The plan is therefore an important topic of conversation between the Chief Audit Executive (CAE) and the audit committee: are the right risks covered, does the plan align with strategy and is there enough room for unforeseen topics.

In practice the plan starts with a risk universe: a structured overview of the organisational units, processes and risks relevant to audit. These are then weighed on impact, likelihood and risk maturity, and translated into a substantiated selection of engagements. The Global Internal Audit Standards 2024 address the risk-based audit plan within the planning domain. Coordination with other assurance providers prevents duplicated work and blind spots, and the plan is refreshed at least annually because the risk profile changes.

ONE Risk Advisory draws up risk-based audit plans that align with the organisation's strategy and risk profile. We make sure the plan not only meets the Standards but is also practical to execute and recognisable to the board and the audit committee. In this way, the audit plan becomes a steering instrument rather than a mandatory annual document.

Last updated:

Related service Internal Audit Support

Frequently asked questions

Why is an audit plan risk-based rather than routine?

Because audit capacity is scarce and should land where the most significant risks lie. A risk-based plan directs effort towards what genuinely matters, instead of visiting every unit at a fixed cadence regardless of risk.

What is a risk universe?

A risk universe is the structured overview of all organisational units, processes and risks relevant to internal audit. It is the starting point of the risk-based audit plan and ensures no important area is left out of view.

How often is the audit plan refreshed?

At least annually, and in the interim whenever the risk profile changes. A risk-based plan is by definition a living document, because the risks on which it rests are themselves in motion.

Why coordinate with other assurance providers?

To prevent duplicated work and blind spots. By aligning with the second and third line, internal audit knows which risks are already covered elsewhere and where its own effort adds the most value.

← All terms