,

How to Build an Internal Audit Plan (Worked Example + Memo)

An internal audit plan is a list of engagements with hours against them, and the list is the least important thing about it. What the audit committee is actually approving when it approves the plan is a set of judgments: which risks the function will look at this year, which it will not and why, how much assurance each engagement is meant to deliver, and whether the people and hours behind the list can deliver it. A plan that arrives as twelve engagement titles and a total hours figure asks the committee to take all of that on trust, and committees have learned to ask the question that exposes it: “what did you leave out?” The plans that survive that question are built from a documented risk assessment, sized from a capacity model, sequenced against the business calendar, and explicit about the gap between what the risk assessment says needs covering and what the budget covers.

This guide is the build sequence for that kind of plan, from the audit universe to the approval memo, under the Global Internal Audit Standards’ requirements for planning. It contains the ten-step sequence with the output of each step, an inputs table showing where the risk assessment’s information comes from, a scoring model, a coverage-cycle table that turns scores into frequencies, a capacity model with the arithmetic for a six-person function, the complete FY27 plan for MidState Beverage as a worked example with hours, sourcing, and the risk each engagement addresses, an uncovered-areas table, the approval memo as model language, a maintenance cadence for the year, and the mistakes that produce plans committees do not believe. It was rewritten in September 2026 to reflect the Global Internal Audit Standards, which made the risk-based plan a stated requirement with specific content. The two artifacts it depends on have their own guides: the internal audit risk assessment, which produces the scores, and the internal audit plan template, which is the document the sequence below fills in.

In this guide

What the Standards require of the plan

Standard 9.4 of the Global Internal Audit Standards requires the chief audit executive to develop an internal audit plan based on a documented assessment of the organization’s strategies, objectives, and risks, considering input from the board and senior management, and to present the plan to the board for approval. The plan must cover the engagements needed to deliver the function’s mandate, and Standard 9.4 specifically requires that the chief audit executive identify and communicate the effect of resource limitations, and that the plan be reviewed and updated as risks change rather than fixed once a year. Standard 9.2 requires a strategy for the function that the plan serves; 9.3 the methodologies the engagements will follow; 9.5 the resources, which the chief audit executive must assess as sufficient and, where they are not, report to the board. Standard 8.1 puts the obligation on the board to approve the plan and the budget and to receive the communications the plan produces. Read together, the Standards describe a plan with five properties: risk-based and documented as such, informed by the board and management, explicit about coverage and its limits, resourced or declared under-resourced, and dynamic.

Two shifts from the pre-2025 Standards matter in practice. The old requirement to “consider” risk became a requirement to base the plan on a documented risk assessment, so a plan file with no assessment behind it is now a nonconformance an external assessor will write up. And the requirement to communicate resource limitations means the uncovered-areas list is not optional: a plan that silently drops the fifth-ranked risk because the hours ran out fails 9.4 even if every engagement in it is well chosen. The GIAS Domain IV guide covers the whole of Standard 9 and the evidence an assessor will look for; the Domain III guide covers the board’s side.

The ten steps from universe to approval

The sequence below is the one most functions follow whether they name it or not; naming it makes the file an assessor can trace. The elapsed time for a mid-sized function is eight to twelve weeks, with most of it in steps 2 and 3, and the sequence runs in the third quarter so that the plan reaches the committee’s fourth-quarter meeting.

StepWhat you doOutputTypical elapsed time
1. Refresh the audit universeList every auditable entity: legal entities, business units, processes, systems, projects, regulations, and third parties; add what changed (acquisitions, new systems, new products) and retire what is goneUniverse listing with owner, last audit date, and last result for each entity1 week
2. Gather inputsStrategy documents, the enterprise risk register, prior audit results and open issues, incident and loss data, regulator and external auditor points, management interviews, board and committee requestsInputs file with source, date, and the risks each source raised3 to 4 weeks, interviews being the constraint
3. Score the universeApply the scoring model (impact, likelihood, and modifying factors) to every entity, with the evidence for each scoreScored universe, ranked2 weeks
4. Set coverageTranslate scores into audit frequency; add mandatory coverage (regulatory, ICFR, validation of prior findings); identify what analytics can cover continuouslyCoverage requirement in hours by entity1 week
5. Model capacityAvailable engagement hours by person and skill after leave, training, administration, and committee reporting; co-source budget converted to hoursCapacity figure and skills profile2 days
6. Fit and cutRank the coverage requirement against capacity; select engagements; size each; record every entity the risk assessment says needs coverage that the plan does not provideDraft plan and uncovered-areas list1 week
7. SequencePlace engagements in the calendar against close periods, peak seasons, system go-lives, external audit timing, and staff availability; add validation windows and the reserveCalendared plan2 days
8. ConsultWalk the draft with the CEO, CFO, and key executives for factual challenge; incorporate what changes the risk picture, not what removes scrutinyRevised draft with a note of what changed and why1 to 2 weeks
9. Present and approvePlan document plus approval memo to the audit committee; private session with the chair on independence and resourcingApproved plan, minutedCommittee cycle
10. MaintainQuarterly refresh of the scores for entities where risk changed; additions, deferrals, and their approval recorded; reserve drawn down with a reasonPlan status table in every quarterly packContinuous

Step 6 is where plans fail quietly. The coverage requirement from step 4 almost always exceeds capacity, often by a factor of two, and the temptation is to shrink engagements until everything fits, which produces a plan in which every audit is too small to reach a conclusion. The disciplined alternative is to size each engagement to the audit risk its conclusion requires, keep the ones that fit, and write down the ones that do not, which is what step 6’s second output is for. The audit risk guide explains how the required hours follow from residual risk; the point here is that the plan should show the committee the choice rather than hide it in undersized engagements.

Inputs: where the risk assessment’s information comes from

A risk assessment is only as good as what goes into it, and the Standards’ requirement to consider input from the board and senior management is the minimum, not the list. The table gives the sources a mature function draws on, what each contributes, and the trap in each. The interviews are the most valuable and the most abused input: valuable because executives know where the bodies are, abused because a plan built only on what executives worry about audits their anxieties and not their blind spots.

InputWhat it contributesHow to use itTrap
Strategy and business planWhere the organization is going: new markets, acquisitions, systems, products; the objectives risks are measured againstMap each strategic initiative to the universe entities it touches; new initiatives get a change factorAuditing last year’s business; a plan with no engagement touching the company’s biggest initiative
Enterprise risk registerManagement’s own view of the top risks and their ownersReconcile the register to the universe; every top-ten risk maps to at least one entity and a coverage decisionAdopting management’s scores as the audit scores; the register reflects appetite and politics
Prior audit results and the issue logWhere controls were weak; repeat findings; overdue actionsEntities with open High findings score up; validation hours are planned, not squeezed inRe-auditing what was audited because the file is convenient
Incident, loss, and complaint dataWhere things actually went wrong: fraud cases, operational losses, customer complaints, near missesA loss in an entity raises its likelihood score; patterns across entities point to systemic causesChasing last year’s incident while the next one builds elsewhere
Regulators and external auditorsExamination findings, management letter points, new rules, areas of regulatory focusMandatory coverage items; new rules become universe entities with a change factorLetting the external auditor’s SOX needs consume the plan
Management interviews (CEO, CFO, COO, CIO, general counsel, business unit heads)What keeps them awake; what changed; where they lack visibility; what they would want audited if it were freeA structured 45-minute interview with the same questions for everyone; record the answers against universe entitiesExecutives steering the plan away from their own areas; treat requests for scrutiny of others’ areas with the same skepticism as requests to avoid it
Board and audit committeeTheir concerns, their view of the risk appetite, requestsThe chair’s input is sought before the draft, not afterA committee request treated as a mandate that displaces higher-ranked risks without discussion
Data: volumes, values, headcount, transactions, system countsThe objective impact factors: how much money and how many transactions flow through each entityPulled from the ERP and HR systems into the universe as impact inputsImpact scored by impression rather than by the numbers
Second line functions (risk, compliance, security)Their assessments, testing results, and monitoring coverageWhere a second line function tests reliably, the plan may reduce coverage and say soReliance on second-line work that has never been evaluated
External environmentIndustry events, peer failures, economic conditions, technology shiftsAn emerging-risk section of the assessment, revisited quarterlyA slide of headlines with no link to the universe

Two inputs deserve a note. The interviews should include people below the executive layer, because a depot manager, a payroll supervisor, and a plant controller know things a CFO does not, and a function that only interviews the top table plans for the top table’s view. And the function’s own knowledge counts as an input and should be recorded as one: an auditor who spent four months in a process last year has a better-informed view of its risk than any interview, and that view belongs in the file with the same evidence standard as everything else.

Scoring the universe and turning scores into coverage

The scoring model does not need to be sophisticated; it needs to be consistent, evidenced, and explainable to a committee member in two minutes. The model below scores impact and likelihood on 1 to 5 scales from stated factors, multiplies them, and then applies modifying factors that move the result up or down a band. The evidence column is the discipline: a score is not a number, it is a number with a fact behind it.

ElementFactorsScaleEvidence recorded
ImpactFinancial magnitude (revenue, cost, assets, cash flowing through the entity); regulatory and legal consequence of failure; operational and customer consequence; reputational exposure1 (immaterial) to 5 (threatens objectives or the entity)The dollar figures and the specific regulation or contract
LikelihoodComplexity; degree of manual processing; rate of change (people, systems, structure); control history (prior findings, incidents); management competence and attention; fraud susceptibility1 (remote) to 5 (expected within the year)Incident counts, turnover data, prior ratings, change log
Base scoreImpact x likelihood1 to 25Computed
ModifiersTime since last audit (up one band if over three years or never); board or regulator interest (up one band); reliable second-line testing in the period (down one band); entity being retired within the year (down one band)Move to the adjacent bandThe specific reason for each modifier applied
Final bandHigh (base 15 to 25 after modifiers); Medium (8 to 14); Low (1 to 7)Three bands

Bands become coverage through a cycle policy the function sets once and the committee approves: how often each band is audited and what “audited” means for it. The cycle is the plan’s most consequential policy decision, because it fixes the coverage requirement in hours before any engagement is chosen, and it is what makes the uncovered-areas list computable rather than rhetorical.

BandCoverage policyForm of coverageTypical hours per entity
HighEvery yearFull engagement with design and operating-effectiveness testing, sized to low detection risk; continuous analytics where the data supports it350 to 600
MediumEvery two years, or annually by analytics with a full engagement every third yearFocused engagement on the key risks; analytics in the off year150 to 300
LowEvery three to four years, or on trigger (change, incident, request)Limited review or reliance on management’s self-assessment with spot verification40 to 120
Mandatory regardless of bandAs requiredICFR and regulatory coverage; validation of open findings; investigations; committee requestsSet by the requirement
ContinuousMonthly or quarterlyAnalytics programs on high-volume processes (payments, payroll, journal entries, route cash)300 to 600 a year for the program across processes

The cycle policy exposes under-resourcing honestly. A universe of 60 entities with 12 High, 24 Medium, and 24 Low, at the midpoints of the hours above, requires roughly 12 x 475 plus 12 x 225 (half the Mediums each year) plus 6 x 80 (a quarter of the Lows): about 8,900 hours before mandatory coverage, continuous analytics, validation, and reserve are added, which is a seven- or eight-person function. A four-person function facing that universe cannot meet its own cycle policy, and the plan should say so in those terms, with the committee choosing between more resource, a longer cycle, or accepted gaps. The site’s risk appetite guide is useful for that conversation, because a board that has articulated its appetite can decide what it is willing not to audit.

The capacity model: how many hours you actually have

Plans overrun because capacity is estimated from headcount rather than computed from hours, and headcount lies. A six-person function does not have 6 x 2,080 hours; it has what is left after leave, training, administration, committee reporting, quality work, and the chief audit executive’s management time, and what is left varies by role. The model below is MidState Beverage’s for FY27, and the discipline is that every deduction is a number the committee can see. The co-source line converts a budget into hours at the blended rate, which is what makes it comparable with the internal capacity.

RolePaid hoursLeave and holidaysTraining (CPE and methodology)Administration, reporting, QAIP, and managementEngagement hours available
Chief audit executive2,080240601,080 (committee packs, plan, budget, stakeholder management, review of all reports, QAIP)700
Audit manager2,08024060480 (supervision, review, issue log, scheduling)1,300
Senior auditor (2)4,160480120560 (methodology, tools, analytics maintenance, mentoring)3,000
Staff auditor2,080240802601,500
IT auditor2,080240802601,500
Internal total12,4801,4404002,6408,000
Co-source: ERP security specialist ($28,000 at $200 an hour blended)140
Total engagement capacity8,140
Reserve (12 percent of internal capacity, for investigations, requests, and overruns)(960)
Plannable hours7,180

Three features of the model are deliberate. The chief audit executive’s engagement hours are real but small, and functions that plan the CAE at 1,500 engagement hours have planned for the CAE to stop running the function. The reserve is taken off the top before engagements are placed, because a reserve that exists only as the gap between plan and capacity is spent by the first overrun; MidState’s reserve at 12 percent reflects a year with two unintegrated acquisitions and a live fraud history, and a stable function might hold 8 to 10. And the co-source hours are bought for a skill the function lacks (ERP security configuration), not for volume; buying volume through co-source is a legitimate model but it is a different decision, covered in the site’s co-sourcing guide. Skills matter as much as hours: 7,180 plannable hours with no one who can read an ERP role design will not deliver a user access engagement, and the model should carry a skills column in practice.

Worked example: MidState Beverage’s FY27 plan

MidState Beverage is a three-state drinks distributor with twelve depots, 300 delivery routes, about 4,200 smaller customers who pay drivers in cash and checks (roughly $31 million a year, 14 percent of revenue), a 2013 route-accounting module bolted to the ERP, two recently acquired distributors not yet on the ERP, a lean finance team, and a six-person internal audit function. Its FY26 year included a Dayton driver’s diversion of $18,400 over five months, found through a customer complaint, and it ended with fourteen open findings. The FY27 plan below is the output of the ten steps: eight engagements, two standing programs, validation, and the reserve, against the 7,180 plannable hours from the capacity model, with the risk each engagement addresses and the assurance it is sized to deliver.

#EngagementRisk assessment basis (band and evidence)Objective and assurance levelQuarterHoursSourcing
1Route cash handling, all twelve depotsHigh (25): $31M in driver-collected cash; FY26 Dayton diversion; 9 of 12 depots with no independent settlement reconciliation per the FY26 planning walkthroughs; self-approved variance overridesConclude on whether settlement, deposit, and customer statement controls prevent and detect diversion; low detection risk; full-population analytics plus site workQ1520In-house
2Acquisition integration: the two acquired distributorsHigh (20): legacy purchasing and payroll systems; no prior audit; control environment unknown; change factor at maximumBaseline the control environment; identify gaps before ERP migration; moderate detection risk with a full walkthrough programQ1 to Q2750In-house
3ERP user access and segregation of dutiesHigh (20): roles unchanged since the 2013 module implementation; 38 users with administrative rights per the IT inventory; SoD conflicts suspected in depot rolesConclude on access provisioning, removal, review, and role design; low detection risk on full-population role analysisQ2550 plus 140 co-sourceIn-house plus ERP security specialist
4Warehouse inventory at the three largest depotsHigh (16): $410,000 FY26 shrink write-off; cycle counts unreconciled for two quarters at one depotConclude on count, adjustment, and custody controls; moderate detection riskQ2 to Q3650In-house
5Financial close under finance team turnoverHigh (16): controller and two of five accountants replaced in FY26; close extended to 12 days; three late adjustments over $100,000Conclude on close checklist, journal entry, and reconciliation controls; moderate detection riskQ3550In-house
6ICFR support: key control documentation and testing for the lender covenant package and the planned FY28 external assuranceMandatory: lender requirement; board decision to prepare for external assurance over internal controlsDocument and test the key controls over financial reporting in the covenant package; advisory-to-assurance boundary stated in the charterQ1 to Q4900In-house
7Validation of the fourteen open FY26 findingsMandatory: open High and Medium actions due through FY27; three already extended onceConfirm each closed action operates; two validation windowsQ2 and Q4450In-house
8Fleet and DOT compliance advisoryMedium (12), management request: 300 routes; a near-miss regulatory inspection in FY26; no prior coverageAdvisory: assess the compliance program’s design and recommend; no assurance conclusionQ4300In-house
Continuous analytics program: payments, payroll, journal entries, route cash exceptionsCovers Medium-band high-volume processes in their off year; feeds engagements 1 and 5Monthly exception reporting to process owners; quarterly summary to the committeeAll year600In-house (senior auditor plus IT auditor)
Depot rotational reviews: five depots not visited in engagement 1Medium-band coverage of remaining depots on a three-year rotationLimited review against the route cash control set after remediationQ3 to Q41,000In-house
Committee requests, investigations, and overrun reserve12 percent of internal capacityDrawn down with a documented reason; unspent reserve released to deferred engagements in Q4960
Total6,410 planned against 7,180 plannable, plus the 960 reserve; 770 hours held for Q4 additions from the uncovered list

Several things about the plan are worth pointing out because committees ask about them. Engagement 1 is sized at 520 hours because its conclusion has to be able to say whether diversion is occurring, not merely whether controls are designed, and the audit risk that conclusion carries requires analytics over 37,400 settlements and re-performance at every depot; the plan says that in the objective column so that the hours are understood before they are spent. Engagement 6, at 900 hours, is the largest line and is not risk-based in the ordinary sense; it is a board decision to prepare for external assurance, and the plan labels it mandatory rather than pretending it emerged from the scoring. The advisory engagement is marked as advisory in the objective column, with no assurance conclusion, which is the boundary the Standards require to be clear. And the plan leaves 770 hours unallocated on purpose, to be assigned in Q4 from the uncovered list once the reserve’s fate is known, which is how a dynamic plan is built into a static document. The actual FY27-01 route cash report, rated Unsatisfactory with five findings and eleven actions, ran 548 hours against the 520 planned; the overrun came from the reserve with a one-line note.

Saying what is not covered

The uncovered-areas table is the part of the plan that Standard 9.4’s resource-limitation requirement makes mandatory and that most committees find the most useful, because it is the only place they can see the risk they are accepting by approving this budget. It lists every entity the cycle policy says should be covered this year that the plan does not cover, with its band, the reason, the mitigation, and the year it is expected to be reached. MidState’s FY27 list is below. Note the last column: an uncovered area with no expected year is a permanent gap, and the committee should be asked whether it accepts it as such.

EntityBandCycle policy saysWhy not covered in FY27Mitigation in the meantimeExpected coverage
Sales tax and excise reportingMedium (12)Analytics this year, full engagement FY28Analytics capacity consumed by route cash exception reportingSecond-line tax review by the external tax adviser, quarterly, which the function has not evaluatedFY28 full engagement; Q4 FY27 if the held hours allow
Treasury and banking arrangementsMedium (10)Every two years; last audited FY25Ranked below the FY27 selections; stable process, no incidentsDual authorization on all bank platforms confirmed at FY25; CFO monthly bank reviewFY28
Sales commission schemeMedium (12)Every two years; never auditedRanked below the FY27 selections; management redesigning the scheme in FY27Audit the redesigned scheme rather than the retiring oneFY28, after redesign
Fleet maintenance and vehicle asset managementMedium (9)Every two years; never auditedPartially covered by the DOT compliance advisory; asset side deferredFixed asset controls tested in FY24FY29
Marketing and trade promotion spend ($4.1M)Medium (10)Every two years; never auditedNo capacity; no incident historyBudget-versus-actual review by the CFO; promotion approvals by the sales VPFY28 if the held hours allow; otherwise FY29
Depots 6 to 12 site visits beyond the rotationHigh (route cash) covered by analytics; site risk MediumEvery depot every three years on siteEngagement 1 visits four depots and the rotation five; three depots have no site visit in FY27Route cash analytics cover all twelve depots monthlyFY28 rotation
Human resources: hiring, compensation changes, and terminationsMedium (10)Every two years; last audited FY25Ranked below the FY27 selectionsPayroll analytics cover pay-change and duplicate-account risks monthlyFY28

The list does two things for the function. It converts an abstract resource argument into specific risks the committee can weigh, which is how audit budgets get increased when they need to be. And it protects the function later: when the sales commission scheme produces a problem in FY28, the committee minutes show that the risk was assessed, deferred with a reason, and mitigated in the interim, which is a different conversation from the one that follows a plan that never mentioned it. Functions that cannot bring themselves to show the committee a gap should reread Standard 9.4, which does not make the disclosure optional.

Sequencing the year

An engagement scheduled in the wrong month costs more and finds less. Finance cannot support a close audit during the close; a warehouse cannot host a count during peak shipping; an acquisition audit before the integration decision produces findings about a system that is about to be replaced. The sequencing pass places each engagement against the business calendar and the function’s own constraints, and the table shows the rules MidState applied and the result.

ConstraintRule appliedEffect on the FY27 calendar
Fraud history and open High riskThe highest-risk engagement starts in Q1 regardless of convenienceRoute cash fieldwork in January to March, including unannounced depot visits in February
Peak seasonNo depot or warehouse fieldwork in the eight summer weeks when volumes peakWarehouse inventory finished by mid-June; depot rotations resume in September
Financial close and year endNo finance-team engagement in the first ten business days of any month or in the year-end close monthFinancial close engagement fieldwork in the middle weeks of July to September, testing the prior three closes
System changesAudit before a decision that the results can inform, not after a migration has fixed the populationAcquisition integration engagement completed before the Q3 ERP migration decision
External assurance timingICFR documentation and testing sequenced to the covenant reporting dates and the FY28 external assurance planICFR work runs all year with quarterly deliverables aligned to covenant certifications
Validation windowsTwo fixed windows so management knows when closure evidence is dueQ2 (April to May) and Q4 (October to November)
Staff availability and skillsThe IT auditor cannot be on two engagements at once; co-source booked at planningERP access in Q2 with the specialist booked in January; analytics program staffed at 25 percent of two people all year
Committee cycleAt least one report issued before each quarterly meetingRoute cash report for the Q1 meeting; acquisition and access reports for Q2; inventory and close for Q3; advisory and validation summary for Q4

The approval memo

The plan document carries the tables; the approval memo carries the argument, in two pages, and it is the part the committee reads. The model below is MidState’s FY27 memo, compressed. Each paragraph corresponds to a requirement of Standard 9.4 or 9.5, which is deliberate: a memo structured this way is its own conformance evidence.

Purpose. This memo presents the FY27 internal audit plan for the Audit Committee’s approval, together with the risk assessment on which it is based, the resources required to deliver it, and the areas the risk assessment identifies that the plan does not cover.

Basis. The plan is based on a documented assessment of 58 auditable entities, scored for impact and likelihood using the methodology approved by the Committee in FY25, informed by the FY27 business plan, the enterprise risk register, FY26 audit results and the fourteen open findings, incident and loss data including the Dayton cash diversion, the external auditor’s FY26 management letter, and interviews with eleven executives and depot managers. Twelve entities scored High, twenty-two Medium, and twenty-four Low. The scored universe is at Appendix A.

Plan. The plan comprises eight engagements, a continuous analytics program, depot rotational reviews, and two validation windows, totaling 6,410 hours, with a reserve of 960 hours for investigations, Committee requests, and overruns. Seven of the eight engagements address High-band entities or mandatory requirements; the eighth is an advisory engagement requested by management on fleet and DOT compliance. Each engagement’s objective and the level of assurance it is designed to provide are stated in Appendix B.

Resources. The plan is deliverable within the function’s six positions and the approved co-source budget of $28,000 for ERP security expertise, on the capacity model at Appendix C. I assess the resources as sufficient for the plan as presented. They are not sufficient to meet the coverage cycle policy in full.

Areas not covered. Seven entities that the cycle policy indicates should be covered in FY27 are not covered, listed with the reason, the interim mitigation, and the expected year of coverage at Appendix D. The most significant is sales tax and excise reporting, a Medium-band entity whose accuracy depends on the settlement data that engagement 1 will test; I propose to cover it in the fourth quarter if the held hours allow. I ask the Committee to note these areas and to confirm whether it accepts the deferrals.

Independence and changes. No impairments to independence arose during planning. The plan will be refreshed quarterly; additions, deferrals, and reserve usage will be reported in each quarterly pack and material changes brought for approval.

Recommendation. That the Committee approve the FY27 internal audit plan and budget as presented.

Maintaining the plan through the year

A plan approved in December describes a company that will not exist by June. Standard 9.4’s requirement to review and update the plan as risks change turns the plan into a living document, and the practical mechanism is a quarterly refresh with a fixed agenda, reported in the committee pack in a fixed format. The cadence below is the minimum.

WhenWhat is reviewedPossible outcomesApproval and reporting
Quarterly, before the committee packScores for entities where anything material changed (incident, reorganization, system change, new regulation, executive request); reserve usage; hours against budget; engagements at risk of slippingAdd an engagement from the uncovered list or a new risk; defer or descope an engagement; re-sequence; draw the reserveAdditions and deferrals that change coverage of a High-band entity go to the committee for approval; others are reported
On triggerInvestigation request, significant incident, acquisition announcement, regulator inquiryReserve drawn; an engagement deferred with the chair’s agreement if the reserve is insufficientChair informed at once; committee at the next meeting
Mid-yearFull re-run of the scoring for the top twenty entities; capacity re-forecastSecond-half plan confirmed or revisedRevised plan to the committee if changes are material
Q4Held hours allocated from the uncovered list; unspent reserve released; next year’s universe refresh beginsLate-year engagements started; plan completion reportedPlan completion percentage with deferrals named, in the year-end pack

The reporting format matters as much as the review. Every quarterly pack should carry the same plan status table (planned, in progress, reported, deferred, added), the reserve position, and the uncovered-areas list with any changes, so that the committee can see the plan move rather than being told about it. The issue log template covers the validation side of that pack, and the small-company function guide shows the same cadence run by a one-person function.

Common planning mistakes

FailureWhat it looks likeWhy it mattersFix
Plan without a documented assessmentEngagement list built from last year’s list and executive requests; no scored universe in the fileNonconformance with Standard 9.4; the committee cannot see why these engagements and not othersScore the universe first, with evidence per score, and file it as Appendix A
Capacity from headcountSix auditors planned at 2,000 hours eachOverruns from month one; the reserve is gone by Q2; the plan loses credibilityCompute engagement hours by role after every deduction; take the reserve off the top
Everything shrunk to fitFourteen engagements of 200 hours each in a function whose risks need six of 500No engagement reaches a conclusion the committee can rely onSize to audit risk; cut the count, not the depth; list what was cut
No uncovered-areas listThe plan presents only what will be doneFails the resource-limitation disclosure; the committee unknowingly accepts riskAppendix D, every year, with expected coverage dates
Management steeringEngagements removed or added after executive review without a change in the risk pictureIndependence impaired; the plan audits what management wants auditedConsult for facts; record what changed and why; report steering attempts to the chair
The unlabeled advisoryA management request planned as an “audit” with no assurance objectiveBlurs the boundary; the committee thinks it received assuranceMark advisory engagements as such, with no assurance conclusion
Mandatory work disguised as risk-basedICFR or regulatory work listed as if the scoring produced itMisrepresents the assessment; hides the true cost of the mandateLabel mandatory items and show their hours separately
Sequencing by convenienceThe highest-risk engagement placed in Q4 because Q1 was busyA known High risk runs unexamined for a year; if it fails, the plan is the exhibitHighest risk first; peak-season and close constraints applied to the rest
Static planNo changes between December approval and the following DecemberFails the update requirement; audits a company that changedQuarterly refresh with a fixed agenda and reporting format
No validation hoursFollow-up done “when we can”Closed actions never verified; repeat findings; the issue log becomes fictionFixed validation windows with hours in the plan

A plan is a promise to the committee about what it will know by year end, and the discipline in this guide is what makes the promise keepable: a risk assessment that can be traced, a capacity figure that is real, engagements sized to the assurance they claim, and an honest list of what was left out. The plan template is the document; the planning memo template takes each engagement from the plan into its own scope; and the risk assessment guide covers the scoring in the depth the assessor will expect.

Related guides

Comments

One response to “How to Build an Internal Audit Plan (Worked Example + Memo)”

  1. […] oversight. This requires forging relationships with business unit leaders and ensuring the annual plan devotes adequate time to strategic or operational audits, not just […]

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading