A risk based internal audit plan is the schedule of engagements that internal audit commits to for the coming period, chosen because of where the organisation’s significant risks sit rather than because of habit, rotation or last year’s list. Under the Global Internal Audit Standards it is governed by Standard 9.4, which sets out what the plan rests on, what it must consider, what the board must be told, and who approves it.
This guide follows the plan from audit universe to board approval, and flags the communication duties that are easy to leave out.
What this guide covers
- What Standard 9.4 requires of a risk based internal audit plan
- Step 1: build the audit universe
- Step 2: run the annual risk assessment
- Mandatory coverage considerations in a risk based internal audit plan
- Step 3: resource the risk based internal audit plan
- What the board must be told about the risk based internal audit plan
- Approving and changing the risk based internal audit plan
- Frequently asked questions

What Standard 9.4 requires of a risk based internal audit plan
The chief audit executive (CAE) must produce a risk based internal audit plan that supports the organisation’s objectives. The core requirements are:
- A documented assessment underneath it. The plan rests on a written assessment of the organisation’s strategies, objectives and risks.
- Board and senior management input. That assessment has to draw on what the board and senior management tell you, together with the CAE’s understanding of governance, risk management and control processes (Standard 9.1).
- At least annually. The organisation-wide risk assessment is repeated at least once a year.
- Named coverage areas. The plan must consider IT governance, fraud risk and how well the compliance and ethics programs work, plus any further high-risk areas.
- Resources identified. The people, budget and technology needed to deliver the plan are spelled out.
- Kept current. The plan changes when the business, its risks, systems, controls or culture change.
- Board approval. The plan, and any significant changes to it, are approved by the board.
The risk based internal audit plan also has to reflect the mandate in the internal audit charter and the full range of services agreed there, so a charter that limits scope will limit the plan.
Step 1: build the audit universe
The audit universe is the list of everything internal audit could audit. Standard 9.4’s guidance describes it as a set of auditable units, such as business units, processes, programs and systems, organised around the organisation’s objectives and aligned to its structure or risk framework.
Three practical points make the universe usable for a risk based internal audit plan:
- Link units to risks. Each unit should point to the key risks that affect it, so the risk assessment scores something concrete.
- Validate, do not copy. The guidance expects internal audit to review the key risks in the organisation’s risk register independently, and to rely on management’s risk information only once it has concluded that risk management is effective.
- Capture cross-cutting risks. Ethics, fraud, IT, third-party and regulatory risks can span several units. Record them as themes so they are not diluted across rows.
Step 2: run the annual risk assessment
With the universe in place, score each unit. The assessment should consider strategy and objectives at organisation level and at unit level, and it should treat risk as opportunity as well as threat. Interviews with board members and senior managers are part of the evidence, as are results from recent engagements.
The Standards set an annual minimum, but the guidance says to stay current with risk information through the year and update the assessment as things change. In a fast-moving organisation that can mean revisiting the risk based internal audit plan every six months, quarterly or even monthly.
Scoring factors for a risk based internal audit plan
The Standards do not prescribe a scoring model. The factors below are drawn from what Standard 9.4’s guidance says should influence the plan; weight them to suit your organisation and agree the scale with the board.
| Factor | What it captures | Where the evidence comes from |
|---|---|---|
| Inherent impact | Financial, regulatory, operational and reputational consequence if the risk occurs | Risk register, board and management interviews |
| Likelihood | How plausible the risk is given the current environment | Incidents, loss data, prior findings |
| Known control effectiveness | What is already known about how well controls work | Past engagement results, open actions |
| Strategic importance | Whether the unit is critical to the mission or a strategic initiative | Strategy documents, board input |
| Legal or regulatory requirement | Whether an engagement is required by law or a regulator | Compliance obligations register |
| Other assurance coverage | Whether another provider already covers the risk adequately | Assurance map, reliance assessment (Standard 9.5) |
| Change and time since last audit | New systems, reorganisations, and how long since internal audit looked | Change log, engagement history |
| Topical Requirement flag | Whether cybersecurity, third-party, behaviour or resilience risk is significant | Applicability and exclusions record |
The last row matters because of the IIA Topical Requirements. Where a topic is significant and lands in the plan as an assurance engagement, the relevant requirement applies, and every item has to be assessed for applicability.
Mandatory coverage considerations in a risk based internal audit plan
Standard 9.4 names three areas the risk based internal audit plan must consider: IT governance, fraud risk and the effectiveness of compliance and ethics programs. “Consider” is the operative word. It does not require an engagement on each topic every year, but it does require a visible decision. The plan documentation should show that each area was assessed, what risk level it was given, and either the engagement that covers it or the reason none is planned this cycle.
If one of these areas is high risk and the plan does not include an assurance engagement on it, that omission is one of the matters the board must be told about, with the reason.
Step 3: resource the risk based internal audit plan
The risk based internal audit plan must identify the human, financial and technological resources it needs. Standard 8.2 then requires the CAE to judge whether the function’s resources are enough to deliver the mandate and the plan. If they are not, the CAE develops a strategy to close the gap and tells the board what the shortfall means and how it will be addressed. Under the Essential Conditions, the board discusses resource sufficiency with the CAE at least once a year.
The guidance suggests the proposed plan show:
- Hours available for engagements, set against administrative time, non-audit work and improvement initiatives.
- Each proposed engagement, marked as assurance or advisory, with its focus area and objective type.
- The reason each engagement was selected and its preliminary scope.
- A percentage of hours held back for contingencies and ad hoc requests.
- The engagements that would come next if more resources were available.
That last list earns its place in a resource conversation, because it turns “we need more staff” into specific risks left uncovered.
What the board must be told about the risk based internal audit plan
Standard 9.4 requires the CAE to review the risk based internal audit plan as needed and to tell the board and senior management promptly about four things:
| Matter | Example |
|---|---|
| How resource constraints reduce coverage | A vacancy means two high-risk engagements move to next year |
| Why a high-risk area has no assurance engagement | Fraud risk rated high, but no engagement planned this cycle, with the reason given |
| Competing demands from major stakeholders | Management asks to swap a planned assurance review for an advisory project |
| Limits on scope or access | An area restricts access to records needed for a planned engagement |
Each of these belongs in the plan paper or the periodic report, not in a conversation that leaves no record.
Approving and changing the risk based internal audit plan
The CAE must discuss the risk based internal audit plan with the board and senior management, including significant changes during the year. The board approves both the plan and any significant change.
The guidance recommends that the CAE, board and senior management agree in advance what counts as a significant change, and build that definition into the audit methodology. Cancelling or postponing an engagement tied to a significant risk or a critical strategic objective is the guidance’s own example. Where an urgent change cannot wait for the next meeting, the board is informed straight away and formal approval follows as soon as possible.
Keep a change log that records each change, the reason, whether it met the significance criteria, and the date of board approval. That log, the documented risk assessment and its inputs, and the minutes of the approval meeting are the evidence a quality assessor will look for.
Frequently asked questions
How often must the risk assessment behind a risk based internal audit plan be done?
At least annually under Standard 9.4. The guidance adds that the CAE should keep risk information current and update the assessment and plan more often where the environment changes quickly.
Does the plan have to include an IT, fraud and compliance audit every year?
No. The plan must consider coverage of those areas. If one is high risk and no assurance engagement is planned, the board must be told why.
Who approves the risk based internal audit plan?
The board, after the CAE has discussed it with the board and senior management. Significant interim changes also need board approval. The full text of Standard 9.4 is in the IIA’s free Global Internal Audit Standards publication.
Can we rely on management’s risk register?
Only to the extent internal audit has concluded that risk management is effective. Otherwise, validate the key risks independently before using them, as our overview of the Global Internal Audit Standards explains in the context of the wider 2024 changes.
When the plan includes an engagement on a Topical Requirement topic, the item-by-item testing is set out in our guides to the Cybersecurity Topical Requirement and the Third-Party Topical Requirement, and the results feed a consistent findings rating scale.
Our Internal Audit Toolkit provides 87 editable templates built on the Global Internal Audit Standards. For planning, it includes the Audit Universe, the Annual Risk Assessment Workbook, the Risk-Based Internal Audit Plan, the Internal Audit Plan Schedule and Change Log, the Assurance Map and the Resource Sufficiency Assessment, plus the Fraud Risk, IT Governance, and Compliance and Ethics Program Audit Programs for the three coverage areas Standard 9.4 names. It is $99.