Skip to content

Internal and Forensic Audit · Internal Audit Engagements and Planning

Risk Based Internal Audit Planning: Steps and Method

Updated 11 October 2026 · Fact-checked

Risk based internal audit planning means building the audit plan around risk. You list the areas to audit, score each for risk, rank them, and give the most time and the most experienced people to the high-risk areas. Low-risk areas get lighter or less frequent coverage. You then review the plan as risks change.

Understand Risk-Based Internal Audit Planning

Every entity has more areas to audit than the internal audit team has time for. Risk based planning solves this. Instead of covering every area equally or in a fixed rotation, you decide where a failure would hurt most and look there first.

Start with the audit universe, the full list of auditable units: processes, functions, locations and systems. For each unit you assess inherent risk (how likely and how serious a problem is before controls) and then how well controls work. Units with high risk and weak controls rise to the top.

The ranking drives three decisions: which areas are audited this year, how often each is revisited, and how much effort each gets. This matches the logic in SA 300, which says the overall audit strategy helps decide the resources for specific audit areas, such as using appropriately experienced team members for high-risk areas, allocating audit budget in hours to high-risk areas, and when and how resources are deployed and supervised. SA 300 is an external audit standard, but the same thinking applies to an internal audit plan.

A traditional audit is usually cyclical or transaction-heavy. It covers everything on a fixed schedule, often focusing on compliance with past procedures. A risk based audit is forward-looking. It starts from business objectives and what could stop them, and it adjusts coverage as risks change.

Planning is not a one-time event. SA 300 describes planning as a continual and iterative process. Your annual plan should be reviewed when the business changes, such as a new acquisition, a system change, a change in key management, or a new regulation. Also talk to management and the audit committee, so the plan reflects their concerns.

Key rules to remember

Risk score (common scoring approach)
Risk score = Likelihood score × Impact score
This is a common practice, not a prescribed formula. Use the scale your entity uses, for example 1 to 5 each. Say so in your answer.
Control-adjusted risk (common approach)
Residual risk rating = Inherent risk rating adjusted for the strength of controls
Strong controls lower the rating, weak controls keep it high. Explain this in words; do not present it as a fixed arithmetic rule.
Audit strategy vs audit plan (SA 300)
Overall audit strategy = scope, timing, direction and resources; Audit plan = more detailed nature, timing and extent of procedures
SA 300 (A13) says the audit plan is more detailed than the overall audit strategy.
Planning activities in strategy (SA 300, para 7)
Identify scope characteristics; ascertain reporting objectives and timing; consider significant factors directing the team; consider preliminary activities; ascertain resources
Use as a checklist of what the plan must cover.

How to solve Risk-Based Internal Audit Planning questions

For any question on risk based planning, follow this order. It gives you provision, analysis and conclusion in a form examiners like.

  1. 1Define the audit universe from the facts: list the functions, processes, locations and systems mentioned.
  2. 2Identify risks for each area, using business objectives, past findings, volume of transactions, changes in systems or management, and regulatory changes.
  3. 3Score or rate each area for likelihood and impact, and consider the strength of existing controls.
  4. 4Rank the areas and group them as high, medium and low risk.
  5. 5Allocate resources: put experienced staff and more hours on high-risk areas, and decide frequency of coverage and timing, such as interim visits or cut-off dates.
  6. 6Get the plan approved by the audit committee or management and set how work will be supervised and reviewed.
  7. 7Provide for review and updating when risks or the business change, and state the conclusion for the facts given.

Quickest way: Rank, allocate, review

When to use it: Use when time is short or the question asks you to briefly explain how to prepare an annual plan.

  1. Write one line defining risk based planning.
  2. List the facts-based risk areas in a short ranked list.
  3. Say what each tier gets: people, hours, timing and frequency.
  4. Add that the plan is approved and revisited when risks change.
  5. Close with a one-line conclusion for the entity in the question.

Common mistakes in Risk-Based Internal Audit Planning

  • Treating risk based planning as auditing only high-risk areas and ignoring the rest.

    Students read 'prioritise' as 'exclude'.

    Fix: Say low-risk areas get lighter or less frequent coverage, not none. Every area stays in the universe.

  • Presenting a risk score formula as a legal or standard-prescribed rule.

    Likelihood × impact appears in many books.

    Fix: Describe it as a common practice and say the entity may use its own scale.

  • Confusing the overall strategy with the detailed plan.

    Both words sound alike.

    Fix: Strategy sets scope, timing, direction and resources. The plan sets detailed nature, timing and extent of procedures.

  • Treating the plan as fixed for the whole year.

    Students think of the plan as a schedule.

    Fix: State that planning is continual and iterative and the plan changes with new risks, such as system changes or management changes.

  • Writing a generic answer without using the case facts.

    Students recall notes instead of analysing the scenario.

    Fix: Name the entity's actual areas, rank them, and justify each rank from the facts.

  • Skipping resource allocation.

    Focus stays on risk identification.

    Fix: Always mention who, how many hours, when and how supervised.

Worked examples

Example 1

Explain how the internal auditor of Sundaram Textiles Ltd should prepare a risk based annual internal audit plan. The company has five units: procurement, inventory, payroll, IT systems (recently migrated to a new ERP) and a small canteen.

Show the solution
  1. Audit universe: the five units are the auditable areas.
  2. Identify risks: procurement involves high-value purchases; inventory involves physical custody; payroll involves cash outflow and statutory dues; the ERP migration brings a change in information technology and processes; the canteen has low value.
  3. Assess likelihood, impact and control strength: the new ERP has untested controls, so it ranks high. Procurement and inventory are high or medium because of value and volume. Payroll is medium. The canteen is low.
  4. Allocate resources: assign the most experienced team members and more hours to the ERP, procurement and inventory, and visit at key dates such as the year-end stock count. Give payroll standard coverage. Cover the canteen less often.
  5. Approval and supervision: present the plan to the audit committee and set review points.
  6. Update: revise the plan if, for example, there are fraud indications or further business changes.

Answer: The plan ranks the ERP system, procurement and inventory highest and gives them most experience and hours. Payroll gets standard coverage and the canteen limited, less frequent coverage. The plan is approved and updated as risks change.

Example 2

Distinguish between traditional and risk based internal audit planning.

Show the solution
  1. Starting point: traditional planning starts from a fixed cycle or the books and transactions; risk based planning starts from business objectives and risks.
  2. Coverage: traditional covers areas in rotation, roughly equally; risk based covers high-risk areas first and most deeply.
  3. Resources: traditional spreads resources evenly; risk based assigns experienced people and more hours to high-risk areas, in line with the resource thinking in SA 300.
  4. Orientation: traditional is mostly backward-looking and compliance-focused; risk based is forward-looking and tries to prevent significant failures.
  5. Flexibility: traditional plans change rarely; risk based plans are updated when risks change.

Answer: Traditional planning is cyclical and evenly spread. Risk based planning ranks areas by risk, directs resources to the highest risks, and is reviewed as risks change.

Exam tips

  • Link your answer to the facts. Rank the areas in the case and justify each rank.
  • Always include resource allocation: people, hours, timing and supervision.
  • If asked to distinguish traditional and risk based audit, give four or five points in a comparison list with the starting point, coverage, resources and flexibility.
  • Cite SA 300 for strategy and resources, and SA 610 only where the question involves coordination with or reliance on internal audit by external auditors.
  • Mention that risk scoring methods are a matter of entity practice.

Practice questions from Internal Audit Engagements and Planning

Risk-Based Internal Audit Planning in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk-Based Internal Audit Planning: frequently asked questions

What are the steps in risk based internal audit planning?

Define the audit universe, identify and assess risks, rank the areas, allocate resources and timing, get approval, and review the plan as risks change. Keep the steps in this order in your answer.

How do I prepare an annual internal audit plan?

List all auditable areas, rate each for risk and control strength, and decide which areas to cover and how often. Assign people and hours, set timing, and obtain approval from the audit committee or management. Plan reviews during the year.

What is the difference between risk based audit and traditional audit?

A traditional audit follows a fixed cycle and spreads effort evenly, often checking compliance with set procedures. A risk based audit starts from risks to objectives and directs the most effort to high-risk areas. It is also updated as risks change.

Is the audit plan the same as the audit strategy?

No. Under SA 300, the overall audit strategy sets scope, timing, direction and resources. The audit plan is more detailed and covers the nature, timing and extent of procedures.