Blog

Risk-Based Internal Audit Plans That Hold Up: A Guide for Internal Audit Leaders

Subscribe now to join the Risk Register community:

Plenty of audit plans call themselves risk-based. A lot of them are rotation schedules with a heat map stapled to the front.

‍

You can usually spot the difference in about ten seconds. Look for the travel and expense audit that comes back every three years because it came back three years ago, clean every time. Then look for the AI tools your finance team adopted last spring, which appear nowhere in the plan at all.

‍

A risk-based internal audit plan isn't a formatting choice. It's the mechanism that decides where a stretched function spends its hours, and in a year of flat or shrinking budgets, that decision is the job.

‍

This post is about how to build that plan. We've already written about what belongs on your 2026 audit plan. This one is about the construction work underneath it, and that starts with strategy.

‍

A Risk-Based Internal Audit Plan Starts With Strategy, Not the Audit Universe

‍

The instinct is to open last year's audit universe and start scoring. That's how you end up with an inventory of audit areas instead of a strategic document.

‍

A strategic plan starts with the organization's documented priorities and the risks the board is actually worried about, then works backward to the auditable units. An inventory starts with what you've always audited and adds new items as they come up. The first one gets funded. The second one gets cut.

‍

That isn't a hunch. In the Internal Audit Foundation's 2026 North American Pulse, funding sufficiency was 30 percentage points higher for functions fully or almost fully aligned with strategy (59%) than for those only somewhat aligned (29%). We unpacked the rest of that data in our breakdown of the 2026 Pulse.

‍

Alignment is not an aspiration. It is a funding mechanism.

‍

So before you score a single risk, ask yourself this. Could a board member read your plan and find their own concerns in it?

‍

The Standards Set the Floor for Risk-Based Planning, Not the Method

‍

Under the Global Internal Audit Standards, which became effective on January 9, 2025, the plan lives in Standard 9.4. It requires the chief audit executive to base the plan on a documented assessment of the organization's strategies, objectives, and risks. That assessment must draw on input from the board and senior management, and it must happen at least annually.

‍

The Standard also asks the plan to consider coverage of IT governance, fraud risk, and compliance and ethics programs. It has to identify the resources needed to deliver it. And it has to be dynamic, updated as the business, its systems, and its culture change.

‍

What the Standard doesn't do is hand you a scoring model. The IIA's practice guide on developing a risk-based internal audit plan, now in its second edition, fills in the process. The judgment calls are still yours.

‍

That's where most plans quietly go wrong, which brings us to the risk assessment itself.

‍

Your Internal Audit Risk Assessment Needs More Than Management's Risk Register

‍

Management's risk register is a useful input. It is not your risk assessment.

‍

The Standards are direct about this. Internal audit should independently validate the key risks management has identified, and should only rely on management's view of risk if it has concluded the risk management process is effective. If your enterprise risk management program is still maturing, copying its register into your plan just imports its blind spots.

‍

When we build a risk assessment at Cherry Hill, we pull from several sources on purpose: internal interviews, surveys, past audit results, the IIA's Risk in Focus research, and industry benchmarking. We also use AI to comb through large volumes of public-facing information as a completeness check. The AI doesn't replace those sources. It expands them, and now and then it surfaces something the interviews missed.

‍

Think of the conversation with the one operations director who always says "nothing's changed." Something has almost always changed. The job of the assessment is to find it before it finds you. 

‍

The next question is how fast it could reach you.

‍

Velocity Belongs Next to Impact and Likelihood in Every Risk Score

‍

Most internal audit risk assessments score two things: impact and likelihood. That framework worked when risk moved at the speed governance could match. It doesn't work now.

‍

Regulations can go from finalized to operational in a matter of months. A vendor can switch on an AI feature inside a tool you approved two years ago. Impact and likelihood alone won't tell you whether your controls can respond before you feel the effect.

‍

Risk velocity fills that gap. It measures how fast a risk materializes and how quickly the organization feels it. Adding it doesn't require a new framework, just two extra questions in every risk discussion: how fast can this happen to us, and at what point will we feel it? Score velocity on a 1-to-5 scale alongside the other two dimensions, and revisit it quarterly.

‍

The Standards already leave room for this. Their implementation guidance notes that a dynamic environment may need plan updates every six months, quarterly, or even monthly. Risk doesn't stay still, and technology doesn't wait for your audit plan.

‍

Retiring Low-Risk Rotations Is How the Plan Pays for Itself

‍

The uncomfortable part of a risk-based approach is simple. It asks you to stop doing some audits.

‍

Areas with low residual risk and stable control environments don't need a fixed rotation. That clean travel and expense audit, the third one in a row, is capacity you could spend somewhere the organization is actually exposed. A risk-based audit plan is not just a methodology preference. It is how you reclaim capacity without adding headcount.

‍

This is also where the Standards help you. Resource limits can make it impossible to assess every area in the audit universe each year. In that case the guidance points you toward other risk information: management's own assessments, conversations with the board, and results from previous engagements.

‍

The objection you'll hear is that someone always audited that area. Fair enough. The better question is what you would find there this year that you didn't find last time.

‍

A Realistic Capacity Model Beats an Aspirational One

‍

Most audit plans are built on aspirational capacity. That's what the function could cover if nobody took training, nobody got pulled into an investigation, and the CFO never called with a special request.

‍

A realistic capacity model starts with the hours you actually have after training, administration, and unplanned work. Then it maps those hours against the risk-ranked list. Standard 9.4's implementation guidance points the same way, asking the proposed plan to show available hours against administrative and non-audit time.

‍

The gap between aspirational and realistic is where the honest planning conversation begins. In most functions, it's bigger than anyone has said out loud.

‍

The Coverage You Can't Deliver Belongs in Front of the Audit Committee

‍

Broad scope with constrained resources creates one specific risk: a function that is a mile wide and an inch deep.

‍

The Standards don't let you hide that. Standard 9.4 requires the chief audit executive to communicate the impact of resource limitations on coverage, and the rationale for leaving any high-risk area out of the plan. The plan and significant changes to it must be approved by the board.

‍

That conversation feels risky. Avoiding it is riskier. When you tell the audit committee what the function can cover with rigor and what it can't, you also get to show them the options for the rest.

‍

Some of those options are internal: training, sequencing, a narrower scope. Some aren't. For specialist areas like cybersecurity, AI governance, or data analytics, internal audit co-sourcing is a capability decision rather than a headcount one. You rent the expertise for the engagement that needs it and keep your fixed cost base lean, while your team stays in the center of the work and owns the findings.

‍

The coverage map is also your early warning system for new obligations. If you haven't mapped your plan against the IIA's Topical Requirements yet, our Topical Requirements screener is a quick place to start.

‍

The Next Plan Will Be Tested Faster Than the Last One

‍

The risk profile your plan was built on will look different by the time your next audit committee meeting comes around. That isn't a reason for alarm. It's a reason to build a plan designed to move.

‍

Start from strategy, validate the risks yourself, score velocity, retire the rotations that no longer earn their slot, and be honest about capacity. A plan built that way will hold up when the audit committee asks why something is on it, and it will hold up just as well when they ask why something isn't.

‍

The next disruption is coming, whether it's a regulation, a vendor's AI rollout, or something none of us has named yet. The functions that come through it well will be the ones whose plans were already built to adjust.

‍

If you want to see how those choices play out in practice, our look at the biggest internal audit risks for 2026 is a good next read. And if your plan has a gap you can't staff, our co-sourcing team would be glad to talk it through with you.

‍

Until next time.

Subscribe now to join the Risk Register community: