How to Build a Risk-Based Internal Audit Plan (Step by Step)

An annual audit plan is a resourcing decision disguised as a document. Done well, it tells the audit committee why each engagement earned its place — and why everything else did not. This is the sequence that produces a plan you can defend.

1. Define the audit universe before you score anything

The audit universe is the complete list of things that could be audited: functions, processes, branches, systems, and third parties. Build it from the organisation chart, the process inventory, the risk register, and the systems list — then reconcile the four. Gaps between them are usually the first finding of the planning cycle.

Keep units at a consistent altitude. A universe mixing "Finance" with "Petty cash reconciliation" produces scores that cannot be compared, because the two are not the same size of thing.

2. Choose weighted drivers, and write down what each one means

Scoring collapses if two people interpret a driver differently. Define each driver, its scale, and what each score means in a sentence. A common weighting is: management's own risk assessment (30%), impact on strategy (20%), time since last audit (15%), regulatory exposure (15%), prior audit issues (10%), and industry or global risk (10%).

The weights matter less than their consistency. What the audit committee will challenge is not whether regulatory exposure is 15% or 20% — it is whether you applied it the same way to every unit.

3. Score the universe, then look at the outliers first

Score every unit, then sort. Before trusting the ranking, examine the extremes: the highest-scoring unit you were not planning to audit, and the lowest-scoring one you assumed you would. One of those two will reveal a driver that is mis-weighted or a unit defined at the wrong altitude.

4. Convert capacity into coverage honestly

Convert available auditor-days into engagements, and stop at the line where capacity runs out. The units below that line are not "not risky" — they are unaudited, and saying so explicitly is what makes the plan credible. Many functions present this as a coverage gap slide alongside the plan.

5. Get approval, then let the plan create the work

Once the audit committee approves the plan, each approved line should become an engagement with its scope, methodology phases, and auditable area already attached. Re-keying approved plan lines into a separate engagement tracker is where most audit functions lose the link between risk and work performed.

Reviewing the plan during the year

A plan fixed in January is stale by June. Re-score units when something material changes — a system migration, a regulatory action, a restructure — and take material plan changes back to the committee rather than absorbing them silently.

Keep reading

More internal audit guides