Risk-Based Audit Planning: A Practical Guide
How to turn a ranked audit universe into a resourced, defensible annual audit plan — methodology, common pitfalls, and how to keep the plan alive through the year.
How to turn a ranked audit universe into a resourced, defensible annual audit plan — methodology, common pitfalls, and how to keep the plan alive through the year.
An annual audit plan built on gut feel eventually gets challenged — by a committee member, a regulator, or a finding nobody saw coming in an area that “everyone knew” was low risk. Risk-based audit planning exists to replace that gut feel with a documented, repeatable methodology that can withstand scrutiny and still flex as the year unfolds.
This guide walks through the mechanics of risk-based planning: scoring, resourcing, sequencing, and — just as important — keeping the plan honest once it’s approved.
Risk-based planning only works if it starts from a complete audit universe — every auditable entity, process and system your function is responsible for, independent of whether you’ve ever audited it before. If you start planning from last year’s calendar instead (“we did IT security last year, treasury the year before, so payroll must be next”), you’re not doing risk-based planning — you’re doing rotation, and rotation quietly ignores risk.
Once the universe is in place, each entry gets scored against a consistent set of risk factors. Common factors include:
Score each factor on a consistent scale (1–5 is common), apply agreed weightings, and combine into an overall inherent risk score — the risk before considering existing controls. Where you have visibility into control design and operating effectiveness, layer in a residual risk score that reflects risk after controls. The gap between the two tells you where controls are doing real work and where they might be assumed rather than tested.
Whatever methodology you choose, the critical requirement is consistency — the same scales, the same weightings, applied the same way across the whole universe, so a 4 in finance means the same thing as a 4 in IT. Inconsistent scoring is the fastest way to have your risk ranking dismissed as subjective.
A ranked universe is not yet a plan — it’s an input. Building the plan means layering resourcing reality on top of the ranking:
1. Rank, then triage. Sort by overall risk score, but don’t treat the ranking as gospel — apply judgement for mandatory coverage (regulatory-mandated audits, board requests) and minimum-frequency rules (nothing goes more than N years without a look, regardless of score).
2. Match to capacity. Estimate hours per engagement against actual team capacity for the period, accounting for leave, training, and unplanned advisory or investigation work that inevitably eats into the plan. A plan that assumes 100% utilisation is a plan that will slip in month two.
3. Sequence deliberately. Some engagements depend on system changes landing first, others cluster around year-end financial close, others need to avoid a business unit’s peak season. Sequencing is where a theoretically sound risk ranking meets the calendar.
4. Document the “why.” For every entry that ranks high but doesn’t make the plan, and every entry that ranks lower but does, record the reasoning. This is what makes the plan defensible in front of an audit committee, rather than merely presentable.
Committees don’t want a spreadsheet of scores — they want a narrative: what’s covered, what’s deliberately deferred and why, what’s mandatory, and how the plan connects to the organisation’s top risks. A visual heat-map of the universe, with the planned engagements highlighted against it, does more to build confidence than a table of numbers ever will.
The plan you approve in January will not survive December unchanged, and that’s fine — a static plan in a dynamic risk environment is actually a red flag. Build in a formal revision process: a new regulation lands, a fraud incident occurs, a major system goes live — any of these can justify pulling an engagement forward or adding one that wasn’t originally scoped. What matters is that revisions are tracked with context, not silently edited, so the plan’s history tells a coherent story of how audit judgement responded to a changing risk landscape.
This is also where coverage reporting earns its keep: a simple, current view of planned-vs-completed-vs-in-progress that you can hand to the audit committee without rebuilding it from scratch each meeting.
Once engagements move from the plan into fieldwork, the next discipline that matters is documentation — see our guide to internal audit working papers best practices for how to keep evidence, testing and review trails clean and defensible.
Verity Audit’s audit planning tools connect directly to your risk-scored universe, so resourcing, sequencing and plan revisions stay linked to the risk data that justified them — with full history on every change, ready for the next committee pack.