Skip to main content
Category: Internal Audit

Risk-Based Audit Planning

Also known as: Risk-Based Audit Plan, Risk-Based Auditing
Simply put

Risk-based audit planning is an approach that focuses an internal audit function's limited time and resources on the areas, processes, or assets that pose the greatest risk to an organization. Rather than reviewing everything equally, it uses an assessment of risk to decide what to audit, and in what depth. This helps ensure that assurance and advisory efforts are directed where they matter most to the organization's objectives.

Formal definition

Risk-based audit planning is the process by which an internal audit activity aligns its audit universe, scope, and resource allocation to the organization's risk profile, typically by combining business knowledge, risk assessment, and strategic prioritization before deploying audit resources. In many frameworks it involves identifying auditable areas, evaluating their relative risk, and constructing an audit plan that focuses assurance and advisory work on higher-risk domains. This is a management-supported assurance planning activity carried out by an independent internal audit function; it is distinct from the operational controls being audited and from management's own risk management processes. This entry does not cover specific risk-scoring methodologies, tooling, or the detailed execution of individual audit engagements, which vary by organization, jurisdiction, and sector.

Why it matters

Internal audit functions operate with finite time, staff, and budget, yet the range of processes, systems, and risks they could examine is typically far larger than any team can cover exhaustively. Risk-based audit planning matters because it provides a defensible basis for choosing what to audit and in what depth, directing assurance and advisory effort toward the areas that pose the greatest risk to the organization's objectives rather than spreading resources evenly across areas of unequal importance.

This approach also strengthens the value of internal audit as an independent assurance function. By combining business knowledge, risk assessment, and strategic prioritization before deploying resources, an audit activity can produce more insightful and forward-looking work and demonstrate to the board, audit committee, and senior management that its coverage is aligned to the organization's actual risk profile. It is important to keep the independence distinction clear: risk-based audit planning is an assurance planning activity, separate from management's own risk management processes and from the operational controls being audited.

The effectiveness of risk-based audit planning depends on the quality of the underlying risk assessment and business understanding, and it does not guarantee that every material issue will be identified. Specific risk-scoring methodologies, tooling, and engagement execution vary by organization, jurisdiction, and sector, and no single approach is universally mandated.

Who it's relevant to

Chief Audit Executives and Internal Auditors
Those responsible for the internal audit activity use risk-based audit planning to define the audit universe, prioritize higher-risk areas, and allocate limited resources across the annual or periodic audit plan. It provides a structured, defensible rationale for coverage decisions.
Audit Committees and Boards
Boards and audit committees that oversee internal audit rely on risk-based planning to gain confidence that assurance efforts are aligned to the organization's risk profile and objectives, and to challenge whether coverage is appropriately focused.
Senior Management and Risk Managers
Management supports the planning activity and provides business context and risk information that inform it. While management's own risk management processes remain distinct from audit's planning, the two intersect where risk assessments feed into audit prioritization.
Governance and Compliance Professionals
Those in governance and compliance roles benefit when audit coverage is directed toward areas of greatest risk, as it can help ensure that assurance over key control and compliance domains is proportionate to their significance to the organization.

Inside Risk-Based Audit Planning

Risk Assessment of the Audit Universe
The systematic identification and evaluation of auditable entities (processes, units, systems, or activities) against risk criteria so that audit effort can be directed toward areas of greater significance. This assessment typically considers factors such as inherent risk, the strength of the control environment, and prior audit findings, though the specific criteria vary by organization and sector.
Prioritization and Ranking
The ordering of auditable entities by their assessed risk to inform the allocation of limited audit resources. Higher-risk areas are commonly scheduled for more frequent or more in-depth coverage, while lower-risk areas may be reviewed less often, subject to professional judgment and any mandatory coverage requirements.
Alignment with Organizational Objectives and Risk Appetite
The linkage of audit priorities to the organization's strategic objectives and, where articulated, its risk appetite. This helps focus assurance on risks most relevant to achieving objectives, though the internal audit function retains independence in reaching its own view rather than simply adopting management's assessment.
Coverage Cycle and Frequency
The planned rotation over which auditable areas receive attention, often expressed across an annual or multi-year horizon. Frequency is typically calibrated to assessed risk, but may also reflect regulatory expectations, board or audit committee direction, and resource constraints.
Resource and Competency Considerations
The matching of available audit hours, budget, and specialist skills to the planned engagements. Risk-based planning accounts for whether the function has the capacity and competencies to address the higher-priority risks it has identified.
Periodic Review and Revision
The updating of the plan as risks change, so that the plan remains responsive to emerging issues, organizational changes, and new information rather than remaining static for the full period.

Common questions

Answers to the questions practitioners most commonly ask about Risk-Based Audit Planning.

Does risk-based audit planning mean the internal audit function only reviews the areas that management has already flagged as high risk?
No. Risk-based audit planning uses risk as a lens for prioritizing and allocating audit resources, but the internal audit function typically forms its own independent view of the risk universe rather than simply adopting management's risk assessments. Relying solely on management's flagged areas would compromise the objectivity that distinguishes an assurance activity from a management activity. In many frameworks, internal audit corroborates, challenges, and supplements management's risk information, and may plan coverage of areas management considers lower risk to validate that assessment or to maintain periodic baseline coverage.
Does concentrating audit effort on the highest-rated risks guarantee that significant issues will not be missed?
No. Prioritizing by risk improves the allocation of limited resources, but it does not guarantee outcomes. Risk assessments are estimates based on available information and judgment, and emerging or misclassified risks can fall outside the areas prioritized. Areas rated lower may still harbor significant control failures. For this reason, risk-based planning is commonly supplemented with periodic baseline coverage, mechanisms to respond to emerging risks, and ongoing reassessment. The approach optimizes coverage against constraints; it does not provide assurance over everything.
How is the audit universe typically defined as an input to risk-based planning?
The audit universe is commonly defined as the set of auditable entities within an organization, which may include business units, processes, systems, locations, legal entities, or specific risk themes. The way it is structured varies by organization size, sector, and how the business is organized. Defining it involves cataloging these entities so that risk can be assessed consistently across them. This entry does not prescribe a single structure or provide tooling guidance; the appropriate granularity depends on organizational context.
What factors are commonly used to assess and rank auditable entities by risk?
Assessment factors vary by organization but commonly include the significance of the underlying risks to objectives, the strength or maturity of the associated control environment, regulatory or compliance exposure, financial materiality, complexity, the pace of change, and the time elapsed since the last audit. Some functions weight these factors and combine them into a composite score. The specific factors, weightings, and scoring approach are matters of professional judgment and organizational context rather than a universal formula.
How often is a risk-based audit plan typically reviewed or refreshed?
Many internal audit functions prepare an annual plan while treating it as a dynamic document subject to periodic reassessment during the year. The cadence varies by organization and by how quickly its risk profile changes. In more volatile environments, functions may revisit the plan on a more frequent basis, such as quarterly, to reflect emerging risks, organizational changes, or completed work. The appropriate frequency depends on context, and this entry does not specify a mandatory interval.
How does risk-based audit planning relate to the organization's enterprise risk management outputs?
Enterprise risk management outputs, such as risk registers and risk assessments produced by management or the second line, can serve as valuable inputs to audit planning. However, internal audit typically maintains an independent perspective and does not simply inherit those outputs, since ERM is a management activity while audit planning supports an independent assurance function. Coordinating with ERM can help avoid duplication and identify coverage gaps, but the independence and objectivity of the audit function are generally preserved by forming a separate risk view.

Common misconceptions

Risk-based audit planning means the internal audit function simply adopts management's risk assessment or the organization's risk register.
While internal audit commonly draws on management's risk information as an input, the function is expected to form its own independent view. Uncritically inheriting management's assessment would undermine the objectivity that distinguishes an assurance activity from a management activity.
Areas assessed as low risk can be excluded from audit coverage indefinitely.
Lower-risk areas are typically reviewed less frequently rather than never. Risk assessments can change, and some coverage may be expected regardless of assessed risk, so periodic reconsideration is generally appropriate. A low ranking is not a permanent exemption.
A risk-based plan, once approved, remains fixed for the whole planning period.
The plan is commonly treated as dynamic and subject to periodic review and revision as risks emerge or shift. Treating it as static can leave assurance effort directed at outdated priorities.

Best practices

Base prioritization on documented, consistent risk criteria so that the ranking of auditable entities can be explained and challenged rather than resting on undocumented judgment.
Draw on management's risk information as an input while independently validating and, where warranted, differing from it, preserving the objectivity of the assurance function.
Reassess and revise the plan periodically and in response to significant changes, treating it as a living document rather than a fixed annual schedule.
Align planned coverage with the organization's objectives and articulated risk appetite while retaining sufficient flexibility for emerging and unforeseen risks.
Match planned engagements to available audit hours, budget, and the specialist competencies required, and flag any gaps between higher-priority risks and the capacity to address them.
Communicate the plan, its risk basis, and subsequent revisions to the board or audit committee, and document any mandatory or regulator-driven coverage that applies regardless of assessed risk.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps