Skip to main content
Category: Internal Audit and Assurance

Audit Plan

Also known as: Annual Audit Plan, Risk-Based Audit Plan, Internal Audit Plan
Simply put

An audit plan is a structured schedule that sets out which areas of an organization will be examined, when, and with what resources. It is typically shaped by risk, so that areas judged to carry greater risk generally receive more audit attention. The plan helps an audit function use its limited time and people where they are most likely to add value.

Formal definition

An audit plan is the systematic articulation of an audit function's intended scope, approach, timing, and resource allocation over a defined period, commonly developed on an annual basis. Under a risk-based approach, prioritization and scheduling are typically driven by factors such as the risk classification of each auditable area and the date of the last audit, drawing on a defined audit universe to align assurance resources with the entity's most significant risks. Ownership of the plan generally rests with the internal audit function (for example, under a chief audit executive), and specific methodologies, cycles, and governance for approval vary by organization and mandate.

Why it matters

An audit function almost never has the resources to examine everything an organization does in a given period. The audit plan is the mechanism that forces disciplined choices about where limited assurance capacity should go. By tying scheduling to risk, typically using factors such as the risk classification of each area and the date it was last audited, the plan aims to direct attention toward the areas most likely to matter to the organization, rather than spreading effort evenly or defaulting to habit. Without a structured plan, audit coverage can drift toward familiar or convenient topics while significant risks go unexamined.

A well-constructed, risk-based plan also supports the credibility and independence of the internal audit function. Because it is grounded in a defined audit universe and a transparent prioritization logic, it gives the board, its audit committee, and management a basis for understanding what will and will not be covered, and why. This makes it easier to have an informed conversation about assurance gaps and to hold the function accountable for delivering against a stated schedule.

At the same time, an audit plan is only as good as the risk assessment behind it and the willingness to revisit it as conditions change. Risk classifications can become stale, and an emerging issue may not fit neatly into a schedule set months earlier. The plan should therefore be understood as a living instrument that guides, but does not rigidly constrain, how assurance resources are deployed.

Who it's relevant to

Chief audit executives and internal audit teams
The internal audit function typically owns the plan and is accountable for developing it, aligning resources to the audit universe, and delivering against the agreed schedule. Audit leaders use the plan to justify how limited people and time are deployed and to keep coverage focused on the most significant risks.
Audit committees and boards
Those charged with oversight generally rely on the audit plan to understand the intended scope and coverage of assurance activity for the period. In many organizations the audit committee reviews or approves the plan, using it as a basis to probe whether coverage matches the organization's risk profile and to identify potential assurance gaps.
Management
Management of the areas within the audit universe is affected by the plan's prioritization, since risk classification and timing determine when and how intensively their functions are examined. The plan helps management anticipate audit activity, though the accountability for the plan itself sits with the audit function rather than with management.
Risk and compliance functions
Risk and compliance professionals may inform the risk assessment that shapes the plan, and the plan's coverage decisions can affect where independent assurance complements their own monitoring. Coordinating on where audit attention is directed helps reduce duplication and gaps across assurance activities, though ownership of the audit plan remains with internal audit.

Inside Audit Plan

Audit Universe and Risk Assessment
A catalogue of the entity's auditable areas, processes, and entities, prioritized through a risk assessment that considers factors such as inherent risk, prior audit results, and changes in the business or regulatory environment. This typically forms the analytical basis for deciding what internal audit examines and when.
Planned Engagements and Scope
The specific audits or reviews scheduled over the plan period, generally with an indication of objectives and scope for each, so that coverage aligns with the areas of greatest risk rather than being distributed evenly across the organization.
Timing and Resource Allocation
The proposed schedule and the staffing, budget, and skills required to deliver the plan. This often includes an assessment of whether internal resources are sufficient or whether co-sourcing or specialist expertise is needed for certain topics.
Coverage Cycle and Flexibility
An indication of how frequently areas are revisited and typically an allowance for reserve capacity or unplanned work, reflecting that plans are generally revisited periodically as risks evolve rather than fixed for the entire period.
Approval and Reporting Lines
Documentation of how the plan is reviewed and approved, commonly by the audit committee, and how results are reported. This reinforces the independence of the internal audit function within the assurance model.

Common questions

Answers to the questions practitioners most commonly ask about Audit Plan.

Does the audit plan cover every risk facing the organization?
Generally no. An audit plan is typically risk-based and prioritized, meaning it directs finite internal audit resources toward the areas judged to carry the greatest risk or assurance need over a given period. It is not intended to be an exhaustive inventory of every risk, nor does it guarantee that unexamined areas are risk-free. Risks falling below the prioritization threshold, or emerging after the plan is set, may not be addressed until a later cycle or through a plan revision. The plan reflects judgment about where assurance is most valuable, not a comprehensive audit of all activities.
Is the audit plan set by management, or is it management's responsibility to decide what gets audited?
Under commonly applied governance arrangements, the internal audit function proposes the audit plan, and it is typically the audit committee (or the board, depending on the structure) that reviews and approves it, reinforcing internal audit's independence. Management is consulted and provides valuable input on risks and operations, but management does not own the plan or dictate its scope; allowing the audited functions to control what is audited would undermine the objectivity that internal audit is meant to provide. The precise approval authority and reporting lines vary by jurisdiction, entity type, and the organization's own charter.
How often should the audit plan be reviewed or updated?
Many functions establish an annual plan while treating it as a living document subject to periodic reassessment, since the risk landscape can shift within a cycle. Some organizations revisit the plan quarterly or on a rolling basis to reflect emerging risks, changes in the business, regulatory developments, or resource constraints. The appropriate cadence depends on the volatility of the organization's risk profile, the length of the planning horizon adopted, and any requirements in the internal audit charter. Material changes are typically brought back to the audit committee for approval.
What inputs typically inform how the audit plan is built?
Common inputs include the organization's risk assessment and risk register, input from the board and management, prior audit findings, regulatory and industry developments, changes to the business or its systems, and the assessed maturity of controls. Some functions also coordinate with other assurance providers to reduce duplication and identify coverage gaps. How these inputs are weighted is a matter of professional judgment, and the resulting prioritization should be documented so the rationale behind coverage decisions is transparent to those approving the plan.
How should limited audit resources be allocated across the plan?
Allocation generally follows the risk-based prioritization: higher-risk areas typically receive more frequent or deeper coverage, while lower-risk areas may be reviewed on a longer cycle or through lighter procedures. Functions weigh available staff, specialist skills, budget, and time against the assessed assurance needs. Where resources are insufficient to cover all high-priority areas, this constraint is often disclosed to the audit committee so it can decide whether to accept the coverage gap, adjust priorities, or provide additional resources. The specific approach depends on the function's methodology and the organization's context.
How is progress against the audit plan tracked and reported?
Internal audit functions commonly monitor completion of planned engagements against the schedule and report status to the audit committee, including any deviations, deferrals, or additions. Reporting typically covers work completed, work in progress, significant findings, and the reasons for any changes to the approved plan. Where the plan cannot be delivered as approved, the shortfall and its potential implications for assurance coverage are generally communicated so those charged with oversight can respond. The format and frequency of this reporting vary by organization and by any provisions in the internal audit charter.

Common misconceptions

The audit plan is owned and set by management.
The internal audit plan is typically developed by the chief audit executive and, in many governance arrangements, reviewed and approved by the audit committee of the board. While management provides input on risks and operations, the plan should preserve internal audit's independence; management does not direct its priorities. Specific approval arrangements vary by jurisdiction, entity type, and applicable listing or regulatory requirements.
An audit plan must cover every process every year to be adequate.
Audit plans are generally risk-based, concentrating effort on areas of higher assessed risk rather than providing uniform annual coverage of all activities. Lower-risk areas may be reviewed on a longer cycle. Comprehensive annual coverage is neither typical nor necessarily a mark of quality.
Once approved, the audit plan is fixed for the period.
Plans are generally treated as dynamic and revisited periodically to reflect emerging risks, organizational change, or newly identified concerns. Many functions build in reserve capacity for unplanned work and update the plan with appropriate governance approval.

Best practices

Ground the plan in a documented, current risk assessment and refresh it periodically so that coverage tracks the organization's evolving risk profile rather than a static list.
Present the plan for review and, where the governance structure provides for it, approval by the audit committee, preserving internal audit's independence from management direction.
Align planned engagement objectives and scope with the areas of highest assessed risk, and be explicit about which areas are intentionally on a longer coverage cycle.
Assess whether the function has the resources, skills, and specialist expertise to deliver the plan, and identify co-sourcing needs where internal capabilities are insufficient.
Build in reserve capacity for unplanned or emerging work, and document a clear process for updating the plan with appropriate approval when priorities shift.
Coordinate with other assurance providers to understand coverage across the lines of defense and reduce unnecessary duplication, while keeping internal audit's role distinct from management's control activities.