CIA Part 3 · Internal Audit Plan · Free Lesson

Describe the process for developing a risk-based audit plan

Free IIA CIA Part 3 (Internal Audit Function) lesson in Internal Audit Plan. 15 min read, ~2,314 words.

A chief audit executive builds the annual plan from last year's plan, adds two engagements the chief financial officer requested, and presents it to the board in November. Nine months later a new payments platform goes live, a data-privacy regulator opens an inquiry, and neither appears anywhere in the plan. The defect is not effort. It is the absence of a documented risk assessment methodology and of the circumstances that trigger timely updates.

A risk-based audit plan allocates limited audit hours to the auditable areas where risk to objectives is greatest. The chief audit executive (CAE) owns the plan and the methodology behind it. The board approves it. The sequence runs: understand strategy and objectives, build the audit universe, assess risk, prioritize, match to resources, then obtain approval.

The audit universe is the inventory of everything that could be audited: business units, processes, systems, legal entities, geographies, third parties, and major projects. Each item is an auditable entity, the unit the risk assessment methodology scores and prioritization then ranks.

Read the full lesson, free →
Worked examples and practice. Free with a free account, no card.

Common mistakes

Bottom line

Exam shortcut

When a stem gives you both inherent and residual scores, the answer ranks on residual. If the stem gives only volume and dollar size with no control information, it is testing inherent scoring and the trap answer over-audits payroll.

The full lesson (about 2,314 words, 15 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.

Learning objectives

Browse all free CIA Part 3 lessons or jump into free CIA Part 3 practice questions.