
How to Plan a Risk-Based Internal Audit
A six-step approach for moving from business objectives and risks to a focused, defensible audit plan — with clear objectives, scope, evidence and agreed boundaries.
PDF • 6 Pages • Free

Check that an engagement is ready for fieldwork: purpose linked to business risk, prior issues reviewed, risks and scope explicit, out-of-scope areas justified, and resources and timing realistic.
Many engagement problems start before fieldwork: an audit purpose not linked to a business risk, scope boundaries that were never written down, or data access that is requested too late. This pre-engagement checklist helps you build a focused, risk-based audit before testing begins.
Use it at planning stage, while preparing interviews and drafting objectives. Business context checks confirm the audit purpose is linked to an objective or risk, that recent organizational, system, regulatory or process changes are understood, that prior audits, incidents, complaints and open actions have been reviewed, and that stakeholders, process owners and relevant documents are identified. Risk and scope checks confirm key inherent risks are documented before tests are defined, objectives address the highest-priority risks, entities, locations, systems and period are explicit, out-of-scope areas are justified, and reliance on other assurance providers is considered. Resources and approach checks cover required skills, early data requirements, realistic fieldwork timing, testing proportionate to risk, and agreed milestones, review points and reporting dates.
Mark each point Done, Review or N/A and record the supporting evidence. The risk prompts help you think about what could fail even if procedures look adequate, and the completion page gives you a signed-off planning conclusion for the audit file.
© Salih Ahmed Islam

A six-step approach for moving from business objectives and risks to a focused, defensible audit plan — with clear objectives, scope, evidence and agreed boundaries.
PDF • 6 Pages • Free

Turn a broad request such as “audit procurement” into a clear, risk-based scope linking objectives, risks, processes, locations, systems and exclusions.
PDF • 6 Pages • Free

Turn an audit request into a focused, risk-based engagement plan, documenting purpose, objectives, in- and out-of-scope areas, walkthroughs, data needs and milestones in one reviewable record.
PDF • 6 Pages • Free

Define exactly what the audit will cover and what it will not, recording included processes, locations and systems, documented exclusions with reasons, and how scope changes are approved.
PDF • 6 Pages • Free