A chief audit executive builds the annual plan from last year's plan, adds two engagements the chief financial officer requested, and presents it to the board in November. Nine months later a new payments platform goes live, a data-privacy regulator opens an inquiry, and neither appears anywhere in the plan. The defect is not effort. It is the absence of a documented risk assessment methodology and of the circumstances that trigger timely updates.
A risk-based audit plan allocates limited audit hours to the auditable areas where risk to objectives is greatest. The chief audit executive (CAE) owns the plan and the methodology behind it. The board approves it. The sequence runs: understand strategy and objectives, build the audit universe, assess risk, prioritize, match to resources, then obtain approval.
The audit universe is the inventory of everything that could be audited: business units, processes, systems, legal entities, geographies, third parties, and major projects. Each item is an auditable entity, the unit the risk assessment methodology scores and prioritization then ranks.
Common mistakes
- Ranking on inherent risk only. Entity A at 4.1 inherent looks riskier than Entity B at 4.0, but B's residual 3.60 beats A's 2.46. Prioritize on what controls leave exposed.
- Letting stakeholders author the plan. Requests are input. A plan built from the chief financial officer's two asks plus last year's schedule has no documented risk basis and fails the alignment test in both directions.
- Omitting uncovered risks from the board submission. The plan must name the significant risks it does not address. Presenting only what will be audited hides the resource decision the board is supposed to make.
Bottom line
- Sequence: understand strategy, build the audit universe, assess risk on each auditable entity, prioritize, match resources, obtain board approval.
- Methodology choice: weighted scoring for defensible fine-grained ranking, likelihood-by-impact mapping for board presentation.
- Rank on residual risk (inherent reduced for control effectiveness), never inherent alone.
- Inputs: management risk register, board minutes, strategy documents, prior results, regulator correspondence, incident data, interviews; internal audit forms its own conclusion.
Exam shortcut
When a stem gives you both inherent and residual scores, the answer ranks on residual. If the stem gives only volume and dollar size with no control information, it is testing inherent scoring and the trap answer over-audits payroll.
The full lesson (about 2,314 words, 15 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 2
Browse all free CIA Part 3 lessons or jump into free CIA Part 3 practice questions.