A chief audit executive opens the year with 47 auditable entities, three regulator mandates, a board request about a pending acquisition, and a business unit that just deployed generative artificial intelligence in customer service. The plan starts with knowing where all of that comes from.
The audit universe is the complete list of auditable entities the internal audit function could examine. An auditable entity is any unit of the organization that can be scoped, tested, and concluded on independently. The universe is an inventory, not a schedule. It answers "what exists," while the plan answers "what we will do this year."
Components the exam expects you to name:
- Organizational units: subsidiaries, divisions, branches, legal entities, and geographies.
- Business processes: procure-to-pay, order-to-cash, payroll, close and reporting, treasury.
- Systems and technology: applications, infrastructure, cloud environments, data flows, cybersecurity.
- Objectives and strategies: each strategic objective and the risks that threaten it.
- External relationships: third parties, vendors, joint ventures, outsourced service providers.
- Governance and compliance domains: ethics, regulatory obligations, board committees, culture.
Common mistakes
- Equating the audit universe with the plan. The universe lists everything auditable, often 47 entities. The plan is the risk-prioritized subset that fits the hours.
- Reading a topical requirement as an engagement trigger. It sets minimum coverage inside an engagement you already scoped; it does not by itself put the topic on the calendar.
- Accepting every board request as mandatory. Requests are evaluated for risk relevance and resource impact, and displacement of higher-risk work is discussed with the board.
Bottom line
- Audit universe: the full inventory of auditable entities (units, processes, systems, objectives, third parties, compliance domains), refreshed at least annually and on trigger events.
- Universe attributes drive prioritization: owner, risk rating, last-audited date, other assurance coverage, estimated hours.
- Topical requirements apply when the topic is relevant to the organization and the engagement covers it, including partial coverage; deviations are documented and communicated.
- Board and management requests are evaluated inputs, not orders; mandates from law and regulators are the least discretionary source and consume hours first.
Exam shortcut
Sort every stem into one of three buckets before reading the options: mandatory, risk-driven, or accommodation. Mandatory answers say "include in the plan and inform the board." Risk-driven answers say "prioritize against the universe." Accommodation answers say "only if capacity remains after mandates and high-risk coverage." When a stem says "topical requirement," look for the word "covers" in the scenario.
The full lesson (about 2,227 words, 15 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1
Browse all free CIA Part 3 lessons or jump into free CIA Part 3 practice questions.