من أنا
المقالات
الوظائف
التواصل معي

The risk-based annual plan

Audit cannot examine everything every year. So how does it choose? Not by rotation and not by mood, but by ranking areas according to their risk.

Chapter 1 · Lesson 2 of 59 min readBeginner level

A risk-based plan simply means: spend audit time where the likelihood and impact of error are greatest.

1 The audit universe

The audit universe is a list of everything that could be audited in the organisation: processes, departments, systems, projects, branches and subsidiaries. It is the foundation the plan is built on.

1
Cycles

Procurement · sales · inventory · payroll

2
Functions

Finance · HR · IT

3
Governance

Risk · compliance · policies

4
Projects

Major initiatives and new systems

Each of these components becomes an “auditable unit” with a risk score

2 Ranking the units by risk

Each unit is scored using declared factors, among them:

  • Financial impact and the size of the amounts flowing through it.
  • Complexity and the number of manual exceptions.
  • Regulatory impact and the likelihood of breach.
  • Previous audit results and the number of open findings.
  • Recent change: a new system, new leadership, or a restructuring.
  • Time since the last audit of this unit.
UnitImpactLikelihoodScoreSuggested frequency
Procurement and contracts5420Annually
Payroll and benefits4312Every one to two years
Inventory and warehouses4416Annually
System access rights5315Annually
Petty cash expenses236Every 3 years

Sources that feed the ranking

The organisation’s risk register · interviews with executive management and the board · the external auditor’s findings · whistleblowing reports · performance indicators and exceptions.

3 From a ranking to a plan

After the ranking, the resources are calculated: how many auditors do we have? How many days does each engagement need? The engagements are then spread across the quarters, with a reserve left for urgent work the board requests or events force — and that reserve is the difference between a realistic plan and one that collapses at the first surprise.

A simplified annual plan
QuarterEngagementDays
Q1The procurement and contracts cycle20
Q2Inventory and warehouses15
Q3System access rights12
Q4Payroll and benefits12
SpreadFollow-up on previous findings10
SpreadReserve for urgent engagements15

The plan is then put to the audit committee for approval, where coverage and resources are discussed.

4 Approving and updating the plan

  • Approval by the audit committee, not by executive management alone.
  • Disclosing the gaps: if resources are insufficient to cover a high-risk area, that is stated explicitly in the plan.
  • Declared flexibility: the plan is updated on any material change, with the amendments put to the committee.
  • Independence in selection: management may suggest; audit decides its own scope on the basis of risk.

A common mistake

A plan built on “what we can get done” rather than “what must be audited”. It should be built on risk first, and then the resource shortfall disclosed so the board can decide: add resources, or accept the risk?

Lesson summary

  • The audit universe is a list of everything that could be audited in the organisation.
  • Units are ranked using declared factors: impact, complexity, regulation, history and change.
  • The plan allocates resources across the quarters and leaves a reserve for contingencies.
  • It is approved by the audit committee, and coverage gaps are disclosed.
  • The plan is built on risk, not on available capacity.

5 Test your understanding

Three quick questions

Pick the answer you believe is correct and you will see the result immediately.

1. Who approves the annual audit plan?

2. Resources are not enough to audit a high-risk area. What is the right course?

3. Why leave a reserve of days in the plan?

Sources and review: the risk-based planning methodology per the professional framework for internal auditing. The figures and tables are illustrative examples, to be calibrated to the size of the organisation. Last reviewed: September 2026.