A risk-based plan simply means: spend audit time where the likelihood and impact of error are greatest.
1 The audit universe
The audit universe is a list of everything that could be audited in the organisation: processes, departments, systems, projects, branches and subsidiaries. It is the foundation the plan is built on.
Cycles
Procurement · sales · inventory · payroll
Functions
Finance · HR · IT
Governance
Risk · compliance · policies
Projects
Major initiatives and new systems
Each of these components becomes an “auditable unit” with a risk score
2 Ranking the units by risk
Each unit is scored using declared factors, among them:
- Financial impact and the size of the amounts flowing through it.
- Complexity and the number of manual exceptions.
- Regulatory impact and the likelihood of breach.
- Previous audit results and the number of open findings.
- Recent change: a new system, new leadership, or a restructuring.
- Time since the last audit of this unit.
| Unit | Impact | Likelihood | Score | Suggested frequency |
|---|---|---|---|---|
| Procurement and contracts | 5 | 4 | 20 | Annually |
| Payroll and benefits | 4 | 3 | 12 | Every one to two years |
| Inventory and warehouses | 4 | 4 | 16 | Annually |
| System access rights | 5 | 3 | 15 | Annually |
| Petty cash expenses | 2 | 3 | 6 | Every 3 years |
Sources that feed the ranking
The organisation’s risk register · interviews with executive management and the board · the external auditor’s findings · whistleblowing reports · performance indicators and exceptions.
3 From a ranking to a plan
After the ranking, the resources are calculated: how many auditors do we have? How many days does each engagement need? The engagements are then spread across the quarters, with a reserve left for urgent work the board requests or events force — and that reserve is the difference between a realistic plan and one that collapses at the first surprise.
| Quarter | Engagement | Days |
|---|---|---|
| Q1 | The procurement and contracts cycle | 20 |
| Q2 | Inventory and warehouses | 15 |
| Q3 | System access rights | 12 |
| Q4 | Payroll and benefits | 12 |
| Spread | Follow-up on previous findings | 10 |
| Spread | Reserve for urgent engagements | 15 |
The plan is then put to the audit committee for approval, where coverage and resources are discussed.
4 Approving and updating the plan
- Approval by the audit committee, not by executive management alone.
- Disclosing the gaps: if resources are insufficient to cover a high-risk area, that is stated explicitly in the plan.
- Declared flexibility: the plan is updated on any material change, with the amendments put to the committee.
- Independence in selection: management may suggest; audit decides its own scope on the basis of risk.
A common mistake
A plan built on “what we can get done” rather than “what must be audited”. It should be built on risk first, and then the resource shortfall disclosed so the board can decide: add resources, or accept the risk?
Lesson summary
- The audit universe is a list of everything that could be audited in the organisation.
- Units are ranked using declared factors: impact, complexity, regulation, history and change.
- The plan allocates resources across the quarters and leaves a reserve for contingencies.
- It is approved by the audit committee, and coverage gaps are disclosed.
- The plan is built on risk, not on available capacity.
5 Test your understanding
Three quick questions
Pick the answer you believe is correct and you will see the result immediately.
1. Who approves the annual audit plan?
Committee approval protects the plan from being tailored to suit whoever is about to be audited.
2. Resources are not enough to audit a high-risk area. What is the right course?
Disclosure moves the decision to whoever owns it: either add resources, or accept the risk knowingly.
3. Why leave a reserve of days in the plan?
Without a reserve, the first urgent engagement displaces a planned one and breaks the approved coverage.