
How to Plan a Risk-Based Internal Audit
A six-step approach for moving from business objectives and risks to a focused, defensible audit plan — with clear objectives, scope, evidence and agreed boundaries.
PDF • 6 Pages • Free

Build a risk-based annual audit plan from the risk universe: risk scores and trends, last assurance coverage, proposed engagements with rationale, quarters and days, resource allocation and contingency.
An annual plan that simply rotates through the same audits each year rarely reflects real risk. This template helps you document the audit universe, risk priorities, coverage, timing and resources behind the plan.
Use it when building the annual plan and presenting it for approval. The header records plan year, preparer, approver, audit FTE, available days and approval date. Part 1 covers the risk universe, with business units or processes, risk score and trend, and last audit or assurance coverage, followed by plan selection: proposed engagements, rationale and strategic link, and quarter and estimated days. Part 2 covers capacity and governance: resource allocation, contingency and advisory capacity, and plan change and reporting rules. A working table lists each audit with its risk rationale, quarter, days and owner.
The worked example includes Procurement, Cyber/ITGC, Travel Expense, Vendor Master Data and Store Operations based on risk trend, change and time since last audit, and reserves 12% contingency. The completion page provides a final quality check and sign-off, so plan decisions and changes are documented for the audit committee.
© Salih Ahmed Islam

A six-step approach for moving from business objectives and risks to a focused, defensible audit plan — with clear objectives, scope, evidence and agreed boundaries.
PDF • 6 Pages • Free

Reduce a long risk list to the few risks that deserve audit attention, scoring impact, likelihood, velocity, control weakness and sensitivity.
PDF • 6 Pages • Free

Check that an engagement is ready for fieldwork: purpose linked to business risk, prior issues reviewed, risks and scope explicit, out-of-scope areas justified, and resources and timing realistic.
PDF • 6 Pages • Free

Turn an audit request into a focused, risk-based engagement plan, documenting purpose, objectives, in- and out-of-scope areas, walkthroughs, data needs and milestones in one reviewable record.
PDF • 6 Pages • Free