Audit

How to Plan an Internal Audit: Risk-Based Scope, Audit Universe and Work Programme

A practical guide to planning an internal audit, from understanding the business and building an audit universe to defining objectives, scope, resources and a usable audit programme.

How to Plan an Internal Audit: Risk-Based Scope, Audit Universe and Work Programme

Internal audit planning is the stage where a broad mandate such as ‘review procurement’ or ‘audit inventory’ becomes a disciplined engagement. A useful plan does more than list processes to test: it explains why the area matters, what risks are being addressed, what is inside and outside scope, what evidence will be needed and how limited audit time will be allocated.

ICAI’s material on planning an internal audit identifies core planning elements including obtaining knowledge of the business, establishing the audit universe, setting engagement objectives and scope, deciding resource allocation and preparing the audit programme. ICAI also publishes a current Internal Audit Standards Board publications page, including its Compendium of Standards on Internal Audit.

1. Start with the business, not the checklist

Before selecting samples or requesting documents, understand how the process actually works. Identify the business model, locations, systems, transaction volumes, key people, outsourced activities, regulatory dependencies and major changes since the previous review. A process narrative or walkthrough is often more useful at this stage than a long document request.

The reason is simple: the same process can carry very different risks in different organisations. Procurement risk in a centralised manufacturing company may concentrate around vendor onboarding, purchase-price changes and goods receipt. In a decentralised services business, the larger risks may be delegated approvals, duplicate vendors, contract leakage or purchases outside the approved system.

2. Build or refresh the audit universe

The audit universe is the structured population of auditable areas from which internal-audit coverage is planned. It can include business processes, legal entities, branches, plants, functions, technology systems, projects and major compliance areas. ICAI’s planning guidance expressly identifies establishing the audit universe as part of the planning process; see its official planning guidance page.

Do not treat the audit universe as a static spreadsheet. Refresh it when the organisation acquires a business, implements a new ERP, enters a new geography, launches a major product, changes its operating model or faces a material control incident.

3. Rank risks before deciding scope

A risk-based plan directs attention toward areas where failure would matter most. For each auditable area, consider financial exposure, regulatory impact, fraud susceptibility, operational disruption, data sensitivity, management concern, pace of change, prior findings and time since the last audit. The scoring model does not need false precision; its purpose is to make prioritisation transparent.

For example, assume a company has recently centralised vendor payments into a new ERP workflow. Even if accounts payable was audited last year, the system change may justify fresh coverage because access rights, approval routing, master-data migration and automated controls have changed.

4. Convert risks into clear engagement objectives

An objective should state what the audit is trying to determine. ‘Audit procurement’ is too broad. A stronger objective could be: assess whether vendor onboarding, purchasing approvals, receipt recording and payment controls are designed and operating to reduce unauthorised purchasing, duplicate payments and conflicts of interest.

Clear objectives prevent the audit from becoming an open-ended search for errors. They also make the final report easier to evaluate because each observation can be linked back to a defined risk or objective.

5. Define scope and exclusions explicitly

Scope should identify the entities, locations, processes, systems and period covered. It should also record important exclusions. If procurement is in scope but tendering for capital projects is excluded because another review covers it, say so. Silent exclusions create expectation gaps between the auditor and management.

A practical scope note can specify: process stages covered; review period; locations; systems; major data sets; relevant policies; interfaces with other functions; and exclusions. Scope should be wide enough to answer the objective but narrow enough to be completed with appropriate depth.

6. Match resources to the risk

Planning includes deciding resource allocation. Consider the number of audit days, seniority and specialist skills required. An ERP access-control review may need technology-audit expertise; a treasury review may need knowledge of banking products; a multi-location inventory audit may require physical visits. Assigning only generalist resources to a specialist risk can weaken an otherwise sound plan.

7. Turn the scope into an audit programme

The audit programme translates objectives into procedures. Each procedure should connect to a risk and identify the evidence expected. Procedures may include walkthroughs, inspection of approvals, data analysis, reconciliations, observation, reperformance, confirmations and sample testing.

A procurement programme, for example, might test whether new vendors were independently approved, bank-detail changes were authenticated, purchase orders followed delegated authority, goods receipts supported invoices, and duplicate-payment controls operated. The programme should remain adaptable: if early testing reveals a new material risk, the auditor should reassess the planned work rather than mechanically complete the original checklist.

8. Document the planning file

A strong planning file normally contains enough evidence for another experienced auditor to understand why the engagement was designed as it was. Useful records include the process understanding, risk assessment, audit universe reference, objectives, scope and exclusions, resource plan, timelines, data requirements, key contacts and approved audit programme.

Common planning mistakes

  • Reusing last year’s programme unchanged: it can miss new systems, products, regulations or fraud patterns.
  • Starting with samples before understanding the process: testing can become disconnected from the real risks.
  • Making the scope too broad: superficial coverage of ten processes is often less useful than disciplined testing of the risks that matter.
  • Ignoring exclusions: stakeholders may assume an area was reviewed when it was not.
  • Failing to connect procedures to risks: a large checklist is not automatically a risk-based audit.

A compact planning checklist

  1. Understand the business and process changes.
  2. Refresh the relevant audit universe.
  3. Identify and prioritise material risks.
  4. Write specific engagement objectives.
  5. Define scope, period, locations, systems and exclusions.
  6. Allocate people, specialist skills and time.
  7. Design procedures that respond to identified risks.
  8. Agree logistics and information requirements.
  9. Document and approve the plan.
  10. Reassess the plan if new risks emerge during fieldwork.

Practical takeaway

Good internal audit planning is a chain of reasoning: understand the business, identify the auditable universe, prioritise risks, set objectives, define scope, allocate resources and design procedures that produce relevant evidence. ICAI’s internal-audit publications directory is a useful first-party reference for the current professional framework. The plan should guide the engagement without becoming so rigid that the team ignores important risks discovered during fieldwork.

Related Articles

Subscribe To Our Newsletter

Subscribe us to get updates on latest Jobs Openings, News, Articles, Notices/ Circulars

Submit

© 2026 CA Samaaj. All rights reserved.

Join Whatsapp Group of CA Samaaj