An internal audit plan is a list of engagements with hours against them, and the list is the least important thing about it. What the audit committee is actually approving when it approves the plan is a set of judgments: which risks the function will look at this year, which it will not and why, how much assurance each engagement is meant to deliver, and whether the people and hours behind the list can deliver it. A plan that arrives as twelve engagement titles and a total hours figure asks the committee to take all of that on trust, and committees have learned to ask the question that exposes it: “what did you leave out?” The plans that survive that question are built from a documented risk assessment, sized from a capacity model, sequenced against the business calendar, and explicit about the gap between what the risk assessment says needs covering and what the budget covers.
This guide is the build sequence for that kind of plan, from the audit universe to the approval memo, under the Global Internal Audit Standards’ requirements for planning. It contains the ten-step sequence with the output of each step, an inputs table showing where the risk assessment’s information comes from, a scoring model, a coverage-cycle table that turns scores into frequencies, a capacity model with the arithmetic for a six-person function, the complete FY27 plan for MidState Beverage as a worked example with hours, sourcing, and the risk each engagement addresses, an uncovered-areas table, the approval memo as model language, a maintenance cadence for the year, and the mistakes that produce plans committees do not believe. It was rewritten in September 2026 to reflect the Global Internal Audit Standards, which made the risk-based plan a stated requirement with specific content. The two artifacts it depends on have their own guides: the internal audit risk assessment, which produces the scores, and the internal audit plan template, which is the document the sequence below fills in.
In this guide
- What the Standards require of the plan
- The ten steps from universe to approval
- Inputs: where the risk assessment’s information comes from
- Scoring the universe and turning scores into coverage
- The capacity model: how many hours you actually have
- Worked example: MidState Beverage’s FY27 plan
- Saying what is not covered
- Sequencing the year
- The approval memo
- Maintaining the plan through the year
- Common planning mistakes
What the Standards require of the plan
Standard 9.4 of the Global Internal Audit Standards requires the chief audit executive to develop an internal audit plan based on a documented assessment of the organization’s strategies, objectives, and risks, considering input from the board and senior management, and to present the plan to the board for approval. The plan must cover the engagements needed to deliver the function’s mandate, and Standard 9.4 specifically requires that the chief audit executive identify and communicate the effect of resource limitations, and that the plan be reviewed and updated as risks change rather than fixed once a year. Standard 9.2 requires a strategy for the function that the plan serves; 9.3 the methodologies the engagements will follow; 9.5 the resources, which the chief audit executive must assess as sufficient and, where they are not, report to the board. Standard 8.1 puts the obligation on the board to approve the plan and the budget and to receive the communications the plan produces. Read together, the Standards describe a plan with five properties: risk-based and documented as such, informed by the board and management, explicit about coverage and its limits, resourced or declared under-resourced, and dynamic.
Two shifts from the pre-2025 Standards matter in practice. The old requirement to “consider” risk became a requirement to base the plan on a documented risk assessment, so a plan file with no assessment behind it is now a nonconformance an external assessor will write up. And the requirement to communicate resource limitations means the uncovered-areas list is not optional: a plan that silently drops the fifth-ranked risk because the hours ran out fails 9.4 even if every engagement in it is well chosen. The GIAS Domain IV guide covers the whole of Standard 9 and the evidence an assessor will look for; the Domain III guide covers the board’s side.
The ten steps from universe to approval
The sequence below is the one most functions follow whether they name it or not; naming it makes the file an assessor can trace. The elapsed time for a mid-sized function is eight to twelve weeks, with most of it in steps 2 and 3, and the sequence runs in the third quarter so that the plan reaches the committee’s fourth-quarter meeting.
| Step | What you do | Output | Typical elapsed time |
|---|---|---|---|
| 1. Refresh the audit universe | List every auditable entity: legal entities, business units, processes, systems, projects, regulations, and third parties; add what changed (acquisitions, new systems, new products) and retire what is gone | Universe listing with owner, last audit date, and last result for each entity | 1 week |
| 2. Gather inputs | Strategy documents, the enterprise risk register, prior audit results and open issues, incident and loss data, regulator and external auditor points, management interviews, board and committee requests | Inputs file with source, date, and the risks each source raised | 3 to 4 weeks, interviews being the constraint |
| 3. Score the universe | Apply the scoring model (impact, likelihood, and modifying factors) to every entity, with the evidence for each score | Scored universe, ranked | 2 weeks |
| 4. Set coverage | Translate scores into audit frequency; add mandatory coverage (regulatory, ICFR, validation of prior findings); identify what analytics can cover continuously | Coverage requirement in hours by entity | 1 week |
| 5. Model capacity | Available engagement hours by person and skill after leave, training, administration, and committee reporting; co-source budget converted to hours | Capacity figure and skills profile | 2 days |
| 6. Fit and cut | Rank the coverage requirement against capacity; select engagements; size each; record every entity the risk assessment says needs coverage that the plan does not provide | Draft plan and uncovered-areas list | 1 week |
| 7. Sequence | Place engagements in the calendar against close periods, peak seasons, system go-lives, external audit timing, and staff availability; add validation windows and the reserve | Calendared plan | 2 days |
| 8. Consult | Walk the draft with the CEO, CFO, and key executives for factual challenge; incorporate what changes the risk picture, not what removes scrutiny | Revised draft with a note of what changed and why | 1 to 2 weeks |
| 9. Present and approve | Plan document plus approval memo to the audit committee; private session with the chair on independence and resourcing | Approved plan, minuted | Committee cycle |
| 10. Maintain | Quarterly refresh of the scores for entities where risk changed; additions, deferrals, and their approval recorded; reserve drawn down with a reason | Plan status table in every quarterly pack | Continuous |
Step 6 is where plans fail quietly. The coverage requirement from step 4 almost always exceeds capacity, often by a factor of two, and the temptation is to shrink engagements until everything fits, which produces a plan in which every audit is too small to reach a conclusion. The disciplined alternative is to size each engagement to the audit risk its conclusion requires, keep the ones that fit, and write down the ones that do not, which is what step 6’s second output is for. The audit risk guide explains how the required hours follow from residual risk; the point here is that the plan should show the committee the choice rather than hide it in undersized engagements.
Inputs: where the risk assessment’s information comes from
A risk assessment is only as good as what goes into it, and the Standards’ requirement to consider input from the board and senior management is the minimum, not the list. The table gives the sources a mature function draws on, what each contributes, and the trap in each. The interviews are the most valuable and the most abused input: valuable because executives know where the bodies are, abused because a plan built only on what executives worry about audits their anxieties and not their blind spots.
| Input | What it contributes | How to use it | Trap |
|---|---|---|---|
| Strategy and business plan | Where the organization is going: new markets, acquisitions, systems, products; the objectives risks are measured against | Map each strategic initiative to the universe entities it touches; new initiatives get a change factor | Auditing last year’s business; a plan with no engagement touching the company’s biggest initiative |
| Enterprise risk register | Management’s own view of the top risks and their owners | Reconcile the register to the universe; every top-ten risk maps to at least one entity and a coverage decision | Adopting management’s scores as the audit scores; the register reflects appetite and politics |
| Prior audit results and the issue log | Where controls were weak; repeat findings; overdue actions | Entities with open High findings score up; validation hours are planned, not squeezed in | Re-auditing what was audited because the file is convenient |
| Incident, loss, and complaint data | Where things actually went wrong: fraud cases, operational losses, customer complaints, near misses | A loss in an entity raises its likelihood score; patterns across entities point to systemic causes | Chasing last year’s incident while the next one builds elsewhere |
| Regulators and external auditors | Examination findings, management letter points, new rules, areas of regulatory focus | Mandatory coverage items; new rules become universe entities with a change factor | Letting the external auditor’s SOX needs consume the plan |
| Management interviews (CEO, CFO, COO, CIO, general counsel, business unit heads) | What keeps them awake; what changed; where they lack visibility; what they would want audited if it were free | A structured 45-minute interview with the same questions for everyone; record the answers against universe entities | Executives steering the plan away from their own areas; treat requests for scrutiny of others’ areas with the same skepticism as requests to avoid it |
| Board and audit committee | Their concerns, their view of the risk appetite, requests | The chair’s input is sought before the draft, not after | A committee request treated as a mandate that displaces higher-ranked risks without discussion |
| Data: volumes, values, headcount, transactions, system counts | The objective impact factors: how much money and how many transactions flow through each entity | Pulled from the ERP and HR systems into the universe as impact inputs | Impact scored by impression rather than by the numbers |
| Second line functions (risk, compliance, security) | Their assessments, testing results, and monitoring coverage | Where a second line function tests reliably, the plan may reduce coverage and say so | Reliance on second-line work that has never been evaluated |
| External environment | Industry events, peer failures, economic conditions, technology shifts | An emerging-risk section of the assessment, revisited quarterly | A slide of headlines with no link to the universe |
Two inputs deserve a note. The interviews should include people below the executive layer, because a depot manager, a payroll supervisor, and a plant controller know things a CFO does not, and a function that only interviews the top table plans for the top table’s view. And the function’s own knowledge counts as an input and should be recorded as one: an auditor who spent four months in a process last year has a better-informed view of its risk than any interview, and that view belongs in the file with the same evidence standard as everything else.
Scoring the universe and turning scores into coverage
The scoring model does not need to be sophisticated; it needs to be consistent, evidenced, and explainable to a committee member in two minutes. The model below scores impact and likelihood on 1 to 5 scales from stated factors, multiplies them, and then applies modifying factors that move the result up or down a band. The evidence column is the discipline: a score is not a number, it is a number with a fact behind it.
| Element | Factors | Scale | Evidence recorded |
|---|---|---|---|
| Impact | Financial magnitude (revenue, cost, assets, cash flowing through the entity); regulatory and legal consequence of failure; operational and customer consequence; reputational exposure | 1 (immaterial) to 5 (threatens objectives or the entity) | The dollar figures and the specific regulation or contract |
| Likelihood | Complexity; degree of manual processing; rate of change (people, systems, structure); control history (prior findings, incidents); management competence and attention; fraud susceptibility | 1 (remote) to 5 (expected within the year) | Incident counts, turnover data, prior ratings, change log |
| Base score | Impact x likelihood | 1 to 25 | Computed |
| Modifiers | Time since last audit (up one band if over three years or never); board or regulator interest (up one band); reliable second-line testing in the period (down one band); entity being retired within the year (down one band) | Move to the adjacent band | The specific reason for each modifier applied |
| Final band | High (base 15 to 25 after modifiers); Medium (8 to 14); Low (1 to 7) | Three bands | — |
Bands become coverage through a cycle policy the function sets once and the committee approves: how often each band is audited and what “audited” means for it. The cycle is the plan’s most consequential policy decision, because it fixes the coverage requirement in hours before any engagement is chosen, and it is what makes the uncovered-areas list computable rather than rhetorical.
| Band | Coverage policy | Form of coverage | Typical hours per entity |
|---|---|---|---|
| High | Every year | Full engagement with design and operating-effectiveness testing, sized to low detection risk; continuous analytics where the data supports it | 350 to 600 |
| Medium | Every two years, or annually by analytics with a full engagement every third year | Focused engagement on the key risks; analytics in the off year | 150 to 300 |
| Low | Every three to four years, or on trigger (change, incident, request) | Limited review or reliance on management’s self-assessment with spot verification | 40 to 120 |
| Mandatory regardless of band | As required | ICFR and regulatory coverage; validation of open findings; investigations; committee requests | Set by the requirement |
| Continuous | Monthly or quarterly | Analytics programs on high-volume processes (payments, payroll, journal entries, route cash) | 300 to 600 a year for the program across processes |
The cycle policy exposes under-resourcing honestly. A universe of 60 entities with 12 High, 24 Medium, and 24 Low, at the midpoints of the hours above, requires roughly 12 x 475 plus 12 x 225 (half the Mediums each year) plus 6 x 80 (a quarter of the Lows): about 8,900 hours before mandatory coverage, continuous analytics, validation, and reserve are added, which is a seven- or eight-person function. A four-person function facing that universe cannot meet its own cycle policy, and the plan should say so in those terms, with the committee choosing between more resource, a longer cycle, or accepted gaps. The site’s risk appetite guide is useful for that conversation, because a board that has articulated its appetite can decide what it is willing not to audit.
The capacity model: how many hours you actually have
Plans overrun because capacity is estimated from headcount rather than computed from hours, and headcount lies. A six-person function does not have 6 x 2,080 hours; it has what is left after leave, training, administration, committee reporting, quality work, and the chief audit executive’s management time, and what is left varies by role. The model below is MidState Beverage’s for FY27, and the discipline is that every deduction is a number the committee can see. The co-source line converts a budget into hours at the blended rate, which is what makes it comparable with the internal capacity.
| Role | Paid hours | Leave and holidays | Training (CPE and methodology) | Administration, reporting, QAIP, and management | Engagement hours available |
|---|---|---|---|---|---|
| Chief audit executive | 2,080 | 240 | 60 | 1,080 (committee packs, plan, budget, stakeholder management, review of all reports, QAIP) | 700 |
| Audit manager | 2,080 | 240 | 60 | 480 (supervision, review, issue log, scheduling) | 1,300 |
| Senior auditor (2) | 4,160 | 480 | 120 | 560 (methodology, tools, analytics maintenance, mentoring) | 3,000 |
| Staff auditor | 2,080 | 240 | 80 | 260 | 1,500 |
| IT auditor | 2,080 | 240 | 80 | 260 | 1,500 |
| Internal total | 12,480 | 1,440 | 400 | 2,640 | 8,000 |
| Co-source: ERP security specialist ($28,000 at $200 an hour blended) | — | — | — | — | 140 |
| Total engagement capacity | — | — | — | — | 8,140 |
| Reserve (12 percent of internal capacity, for investigations, requests, and overruns) | — | — | — | — | (960) |
| Plannable hours | — | — | — | — | 7,180 |
Three features of the model are deliberate. The chief audit executive’s engagement hours are real but small, and functions that plan the CAE at 1,500 engagement hours have planned for the CAE to stop running the function. The reserve is taken off the top before engagements are placed, because a reserve that exists only as the gap between plan and capacity is spent by the first overrun; MidState’s reserve at 12 percent reflects a year with two unintegrated acquisitions and a live fraud history, and a stable function might hold 8 to 10. And the co-source hours are bought for a skill the function lacks (ERP security configuration), not for volume; buying volume through co-source is a legitimate model but it is a different decision, covered in the site’s co-sourcing guide. Skills matter as much as hours: 7,180 plannable hours with no one who can read an ERP role design will not deliver a user access engagement, and the model should carry a skills column in practice.
Worked example: MidState Beverage’s FY27 plan
MidState Beverage is a three-state drinks distributor with twelve depots, 300 delivery routes, about 4,200 smaller customers who pay drivers in cash and checks (roughly $31 million a year, 14 percent of revenue), a 2013 route-accounting module bolted to the ERP, two recently acquired distributors not yet on the ERP, a lean finance team, and a six-person internal audit function. Its FY26 year included a Dayton driver’s diversion of $18,400 over five months, found through a customer complaint, and it ended with fourteen open findings. The FY27 plan below is the output of the ten steps: eight engagements, two standing programs, validation, and the reserve, against the 7,180 plannable hours from the capacity model, with the risk each engagement addresses and the assurance it is sized to deliver.
| # | Engagement | Risk assessment basis (band and evidence) | Objective and assurance level | Quarter | Hours | Sourcing |
|---|---|---|---|---|---|---|
| 1 | Route cash handling, all twelve depots | High (25): $31M in driver-collected cash; FY26 Dayton diversion; 9 of 12 depots with no independent settlement reconciliation per the FY26 planning walkthroughs; self-approved variance overrides | Conclude on whether settlement, deposit, and customer statement controls prevent and detect diversion; low detection risk; full-population analytics plus site work | Q1 | 520 | In-house |
| 2 | Acquisition integration: the two acquired distributors | High (20): legacy purchasing and payroll systems; no prior audit; control environment unknown; change factor at maximum | Baseline the control environment; identify gaps before ERP migration; moderate detection risk with a full walkthrough program | Q1 to Q2 | 750 | In-house |
| 3 | ERP user access and segregation of duties | High (20): roles unchanged since the 2013 module implementation; 38 users with administrative rights per the IT inventory; SoD conflicts suspected in depot roles | Conclude on access provisioning, removal, review, and role design; low detection risk on full-population role analysis | Q2 | 550 plus 140 co-source | In-house plus ERP security specialist |
| 4 | Warehouse inventory at the three largest depots | High (16): $410,000 FY26 shrink write-off; cycle counts unreconciled for two quarters at one depot | Conclude on count, adjustment, and custody controls; moderate detection risk | Q2 to Q3 | 650 | In-house |
| 5 | Financial close under finance team turnover | High (16): controller and two of five accountants replaced in FY26; close extended to 12 days; three late adjustments over $100,000 | Conclude on close checklist, journal entry, and reconciliation controls; moderate detection risk | Q3 | 550 | In-house |
| 6 | ICFR support: key control documentation and testing for the lender covenant package and the planned FY28 external assurance | Mandatory: lender requirement; board decision to prepare for external assurance over internal controls | Document and test the key controls over financial reporting in the covenant package; advisory-to-assurance boundary stated in the charter | Q1 to Q4 | 900 | In-house |
| 7 | Validation of the fourteen open FY26 findings | Mandatory: open High and Medium actions due through FY27; three already extended once | Confirm each closed action operates; two validation windows | Q2 and Q4 | 450 | In-house |
| 8 | Fleet and DOT compliance advisory | Medium (12), management request: 300 routes; a near-miss regulatory inspection in FY26; no prior coverage | Advisory: assess the compliance program’s design and recommend; no assurance conclusion | Q4 | 300 | In-house |
| — | Continuous analytics program: payments, payroll, journal entries, route cash exceptions | Covers Medium-band high-volume processes in their off year; feeds engagements 1 and 5 | Monthly exception reporting to process owners; quarterly summary to the committee | All year | 600 | In-house (senior auditor plus IT auditor) |
| — | Depot rotational reviews: five depots not visited in engagement 1 | Medium-band coverage of remaining depots on a three-year rotation | Limited review against the route cash control set after remediation | Q3 to Q4 | 1,000 | In-house |
| — | Committee requests, investigations, and overrun reserve | 12 percent of internal capacity | Drawn down with a documented reason; unspent reserve released to deferred engagements in Q4 | — | 960 | — |
| Total | — | — | — | — | 6,410 planned against 7,180 plannable, plus the 960 reserve; 770 hours held for Q4 additions from the uncovered list | — |
Several things about the plan are worth pointing out because committees ask about them. Engagement 1 is sized at 520 hours because its conclusion has to be able to say whether diversion is occurring, not merely whether controls are designed, and the audit risk that conclusion carries requires analytics over 37,400 settlements and re-performance at every depot; the plan says that in the objective column so that the hours are understood before they are spent. Engagement 6, at 900 hours, is the largest line and is not risk-based in the ordinary sense; it is a board decision to prepare for external assurance, and the plan labels it mandatory rather than pretending it emerged from the scoring. The advisory engagement is marked as advisory in the objective column, with no assurance conclusion, which is the boundary the Standards require to be clear. And the plan leaves 770 hours unallocated on purpose, to be assigned in Q4 from the uncovered list once the reserve’s fate is known, which is how a dynamic plan is built into a static document. The actual FY27-01 route cash report, rated Unsatisfactory with five findings and eleven actions, ran 548 hours against the 520 planned; the overrun came from the reserve with a one-line note.
Saying what is not covered
The uncovered-areas table is the part of the plan that Standard 9.4’s resource-limitation requirement makes mandatory and that most committees find the most useful, because it is the only place they can see the risk they are accepting by approving this budget. It lists every entity the cycle policy says should be covered this year that the plan does not cover, with its band, the reason, the mitigation, and the year it is expected to be reached. MidState’s FY27 list is below. Note the last column: an uncovered area with no expected year is a permanent gap, and the committee should be asked whether it accepts it as such.
| Entity | Band | Cycle policy says | Why not covered in FY27 | Mitigation in the meantime | Expected coverage |
|---|---|---|---|---|---|
| Sales tax and excise reporting | Medium (12) | Analytics this year, full engagement FY28 | Analytics capacity consumed by route cash exception reporting | Second-line tax review by the external tax adviser, quarterly, which the function has not evaluated | FY28 full engagement; Q4 FY27 if the held hours allow |
| Treasury and banking arrangements | Medium (10) | Every two years; last audited FY25 | Ranked below the FY27 selections; stable process, no incidents | Dual authorization on all bank platforms confirmed at FY25; CFO monthly bank review | FY28 |
| Sales commission scheme | Medium (12) | Every two years; never audited | Ranked below the FY27 selections; management redesigning the scheme in FY27 | Audit the redesigned scheme rather than the retiring one | FY28, after redesign |
| Fleet maintenance and vehicle asset management | Medium (9) | Every two years; never audited | Partially covered by the DOT compliance advisory; asset side deferred | Fixed asset controls tested in FY24 | FY29 |
| Marketing and trade promotion spend ($4.1M) | Medium (10) | Every two years; never audited | No capacity; no incident history | Budget-versus-actual review by the CFO; promotion approvals by the sales VP | FY28 if the held hours allow; otherwise FY29 |
| Depots 6 to 12 site visits beyond the rotation | High (route cash) covered by analytics; site risk Medium | Every depot every three years on site | Engagement 1 visits four depots and the rotation five; three depots have no site visit in FY27 | Route cash analytics cover all twelve depots monthly | FY28 rotation |
| Human resources: hiring, compensation changes, and terminations | Medium (10) | Every two years; last audited FY25 | Ranked below the FY27 selections | Payroll analytics cover pay-change and duplicate-account risks monthly | FY28 |
The list does two things for the function. It converts an abstract resource argument into specific risks the committee can weigh, which is how audit budgets get increased when they need to be. And it protects the function later: when the sales commission scheme produces a problem in FY28, the committee minutes show that the risk was assessed, deferred with a reason, and mitigated in the interim, which is a different conversation from the one that follows a plan that never mentioned it. Functions that cannot bring themselves to show the committee a gap should reread Standard 9.4, which does not make the disclosure optional.
Sequencing the year
An engagement scheduled in the wrong month costs more and finds less. Finance cannot support a close audit during the close; a warehouse cannot host a count during peak shipping; an acquisition audit before the integration decision produces findings about a system that is about to be replaced. The sequencing pass places each engagement against the business calendar and the function’s own constraints, and the table shows the rules MidState applied and the result.
| Constraint | Rule applied | Effect on the FY27 calendar |
|---|---|---|
| Fraud history and open High risk | The highest-risk engagement starts in Q1 regardless of convenience | Route cash fieldwork in January to March, including unannounced depot visits in February |
| Peak season | No depot or warehouse fieldwork in the eight summer weeks when volumes peak | Warehouse inventory finished by mid-June; depot rotations resume in September |
| Financial close and year end | No finance-team engagement in the first ten business days of any month or in the year-end close month | Financial close engagement fieldwork in the middle weeks of July to September, testing the prior three closes |
| System changes | Audit before a decision that the results can inform, not after a migration has fixed the population | Acquisition integration engagement completed before the Q3 ERP migration decision |
| External assurance timing | ICFR documentation and testing sequenced to the covenant reporting dates and the FY28 external assurance plan | ICFR work runs all year with quarterly deliverables aligned to covenant certifications |
| Validation windows | Two fixed windows so management knows when closure evidence is due | Q2 (April to May) and Q4 (October to November) |
| Staff availability and skills | The IT auditor cannot be on two engagements at once; co-source booked at planning | ERP access in Q2 with the specialist booked in January; analytics program staffed at 25 percent of two people all year |
| Committee cycle | At least one report issued before each quarterly meeting | Route cash report for the Q1 meeting; acquisition and access reports for Q2; inventory and close for Q3; advisory and validation summary for Q4 |
The approval memo
The plan document carries the tables; the approval memo carries the argument, in two pages, and it is the part the committee reads. The model below is MidState’s FY27 memo, compressed. Each paragraph corresponds to a requirement of Standard 9.4 or 9.5, which is deliberate: a memo structured this way is its own conformance evidence.
Purpose. This memo presents the FY27 internal audit plan for the Audit Committee’s approval, together with the risk assessment on which it is based, the resources required to deliver it, and the areas the risk assessment identifies that the plan does not cover.
Basis. The plan is based on a documented assessment of 58 auditable entities, scored for impact and likelihood using the methodology approved by the Committee in FY25, informed by the FY27 business plan, the enterprise risk register, FY26 audit results and the fourteen open findings, incident and loss data including the Dayton cash diversion, the external auditor’s FY26 management letter, and interviews with eleven executives and depot managers. Twelve entities scored High, twenty-two Medium, and twenty-four Low. The scored universe is at Appendix A.
Plan. The plan comprises eight engagements, a continuous analytics program, depot rotational reviews, and two validation windows, totaling 6,410 hours, with a reserve of 960 hours for investigations, Committee requests, and overruns. Seven of the eight engagements address High-band entities or mandatory requirements; the eighth is an advisory engagement requested by management on fleet and DOT compliance. Each engagement’s objective and the level of assurance it is designed to provide are stated in Appendix B.
Resources. The plan is deliverable within the function’s six positions and the approved co-source budget of $28,000 for ERP security expertise, on the capacity model at Appendix C. I assess the resources as sufficient for the plan as presented. They are not sufficient to meet the coverage cycle policy in full.
Areas not covered. Seven entities that the cycle policy indicates should be covered in FY27 are not covered, listed with the reason, the interim mitigation, and the expected year of coverage at Appendix D. The most significant is sales tax and excise reporting, a Medium-band entity whose accuracy depends on the settlement data that engagement 1 will test; I propose to cover it in the fourth quarter if the held hours allow. I ask the Committee to note these areas and to confirm whether it accepts the deferrals.
Independence and changes. No impairments to independence arose during planning. The plan will be refreshed quarterly; additions, deferrals, and reserve usage will be reported in each quarterly pack and material changes brought for approval.
Recommendation. That the Committee approve the FY27 internal audit plan and budget as presented.
Maintaining the plan through the year
A plan approved in December describes a company that will not exist by June. Standard 9.4’s requirement to review and update the plan as risks change turns the plan into a living document, and the practical mechanism is a quarterly refresh with a fixed agenda, reported in the committee pack in a fixed format. The cadence below is the minimum.
| When | What is reviewed | Possible outcomes | Approval and reporting |
|---|---|---|---|
| Quarterly, before the committee pack | Scores for entities where anything material changed (incident, reorganization, system change, new regulation, executive request); reserve usage; hours against budget; engagements at risk of slipping | Add an engagement from the uncovered list or a new risk; defer or descope an engagement; re-sequence; draw the reserve | Additions and deferrals that change coverage of a High-band entity go to the committee for approval; others are reported |
| On trigger | Investigation request, significant incident, acquisition announcement, regulator inquiry | Reserve drawn; an engagement deferred with the chair’s agreement if the reserve is insufficient | Chair informed at once; committee at the next meeting |
| Mid-year | Full re-run of the scoring for the top twenty entities; capacity re-forecast | Second-half plan confirmed or revised | Revised plan to the committee if changes are material |
| Q4 | Held hours allocated from the uncovered list; unspent reserve released; next year’s universe refresh begins | Late-year engagements started; plan completion reported | Plan completion percentage with deferrals named, in the year-end pack |
The reporting format matters as much as the review. Every quarterly pack should carry the same plan status table (planned, in progress, reported, deferred, added), the reserve position, and the uncovered-areas list with any changes, so that the committee can see the plan move rather than being told about it. The issue log template covers the validation side of that pack, and the small-company function guide shows the same cadence run by a one-person function.
Common planning mistakes
| Failure | What it looks like | Why it matters | Fix |
|---|---|---|---|
| Plan without a documented assessment | Engagement list built from last year’s list and executive requests; no scored universe in the file | Nonconformance with Standard 9.4; the committee cannot see why these engagements and not others | Score the universe first, with evidence per score, and file it as Appendix A |
| Capacity from headcount | Six auditors planned at 2,000 hours each | Overruns from month one; the reserve is gone by Q2; the plan loses credibility | Compute engagement hours by role after every deduction; take the reserve off the top |
| Everything shrunk to fit | Fourteen engagements of 200 hours each in a function whose risks need six of 500 | No engagement reaches a conclusion the committee can rely on | Size to audit risk; cut the count, not the depth; list what was cut |
| No uncovered-areas list | The plan presents only what will be done | Fails the resource-limitation disclosure; the committee unknowingly accepts risk | Appendix D, every year, with expected coverage dates |
| Management steering | Engagements removed or added after executive review without a change in the risk picture | Independence impaired; the plan audits what management wants audited | Consult for facts; record what changed and why; report steering attempts to the chair |
| The unlabeled advisory | A management request planned as an “audit” with no assurance objective | Blurs the boundary; the committee thinks it received assurance | Mark advisory engagements as such, with no assurance conclusion |
| Mandatory work disguised as risk-based | ICFR or regulatory work listed as if the scoring produced it | Misrepresents the assessment; hides the true cost of the mandate | Label mandatory items and show their hours separately |
| Sequencing by convenience | The highest-risk engagement placed in Q4 because Q1 was busy | A known High risk runs unexamined for a year; if it fails, the plan is the exhibit | Highest risk first; peak-season and close constraints applied to the rest |
| Static plan | No changes between December approval and the following December | Fails the update requirement; audits a company that changed | Quarterly refresh with a fixed agenda and reporting format |
| No validation hours | Follow-up done “when we can” | Closed actions never verified; repeat findings; the issue log becomes fiction | Fixed validation windows with hours in the plan |
A plan is a promise to the committee about what it will know by year end, and the discipline in this guide is what makes the promise keepable: a risk assessment that can be traced, a capacity figure that is real, engagements sized to the assurance they claim, and an honest list of what was left out. The plan template is the document; the planning memo template takes each engagement from the plan into its own scope; and the risk assessment guide covers the scoring in the depth the assessor will expect.
Related guides
- Internal audit plan template — the annotated document this sequence fills in
- Internal audit risk assessment — building and scoring the universe
- Audit planning memo template — from plan line to engagement scope
- GIAS Domain IV: managing — Standards 9.1 to 9.5 in full
- GIAS Domain III: governing — the board’s approval duties
- Audit risk explained — why engagement hours follow residual risk
- Risk appetite statements — the board conversation behind the uncovered list
- Internal audit co-sourcing 101 — buying skills and capacity
- Audit issue log template — the validation windows’ other half
- Setting up a small-company internal audit function — the same plan at one-person scale
- All Guides — the full index
Leave a Reply