,

The Annotated Internal Audit Plan Template

The annual audit plan is the most consequential document an internal audit function produces — the one the audit committee formally approves, the one management uses to brace itself, the one the team lives inside for twelve months — and at most functions it is a spreadsheet with a cover memo stapled to the front. That works right up until someone asks the questions the spreadsheet cannot answer: why these audits and not those? what are we deliberately not covering? what happens when the world changes in March? A plan document answers them in advance, which is why the Standards now expect one that is risk-based, explains its own coverage choices, and can flex on evidence.

This is that document, in full: eight sections, each with model language you can lift (in the shaded blocks), drafting guidance on what the section must accomplish and where it usually fails, and — threaded through the whole Templates Suite — a worked example for one illustrative company, MidState Beverage, a three-state drinks distributor whose plan you’ll see here, whose route-cash audit gets its planning memo next, and whose engagement runs through the walkthrough, report, and issue log templates. One company, one cycle, five artifacts that actually connect.

In this guide

What the plan document has to do — for three different readers

Three audiences read the plan, and they want different things from the same pages. The audit committee wants to approve something defensible: that coverage follows risk, that the biggest exposures are watched, that what is not covered was a choice rather than an accident — they are exercising the oversight duty our Domain III guide describes, and they need a document built to be approved. Management wants to know what is coming, when, and why — a plan that reads as arbitrary breeds resistance; one that ties every engagement to a named risk breeds cooperation. The audit team needs the operational truth: hours, sequencing, skills, and the reserve that keeps a surprise from wrecking the year. The template below serves all three by separating the layers — basis and risk story up front for the committee, the plan listing with rationale for everyone, resourcing and mechanics at the back for the team — so each reader finds their section without wading through the others’. A plan document is the function’s Standard 9.4 artifact; built this way, it is also the function’s best annual argument for its own existence.

The template, annotated: eight sections

Shaded blocks are model language — bracketed text is what you replace. The guidance under each block is what a strong reviewer would tell you before the committee does.

Section 1 — Purpose and basis

1. Purpose and basis. This document presents the internal audit plan for [fiscal year], prepared under the authority of the Internal Audit Charter approved by the Audit Committee on [date] and in conformance with the Global Internal Audit Standards. The plan is risk-based: engagements were selected from the audit universe using the risk assessment summarized in Section 2, updated as of [date]. The plan is presented for the Committee’s approval and will be revisited at each quarterly meeting; material changes will be brought to the Committee for re-approval under the process in Section 5.

Drafting guidance. Short, formal, and load-bearing: this paragraph establishes authority (the charter), method (risk-based, from a dated assessment), and governance (approval and the change mechanism). Cite the charter’s approval date — committees notice when it’s stale — and reference the Standards by name; a plan that cites the 2017 framework in 2026 tells an assessor your methodology hasn’t been updated either. Resist the urge to add a mission statement here; the committee has read it.

Section 2 — Risk assessment summary

2. Risk assessment summary. The audit universe comprises [N] auditable entities across [business units / processes / systems / projects], refreshed in [month] for [acquisitions, reorganizations, new systems]. Each entity was assessed for inherent risk across [impact dimensions], for control environment maturity, and for change and prior-audit factors, using the methodology at Appendix A. Input was obtained from [executive interviews, ERM, external audit, compliance, prior results]. The assessment identified the following top risk themes for [year]: [1] [theme and driver]; [2] …; [3] …. Risk scores by entity appear in Appendix B; the [top-quartile] entities are addressed in this plan or covered by other assurance providers as noted in Section 7.

Drafting guidance. This section is the plan’s argument — everything in Section 3 has to trace back here. Three disciplines: name the universe and its refresh (the committee should see that acquisitions and new systems entered the universe before they entered the plan); state the method at summary level and push the scoring model to an appendix (the full method belongs in the methodology, not the plan); and lead with themes in business language, because “cash-intensive route sales in a thin-controls environment” is what a committee member remembers, not a score of 4.2. Say who was consulted — it signals the assessment wasn’t performed from inside the audit department.

Section 3 — The plan listing, with rationale

3. Planned engagements. The plan comprises [N] engagements totaling [H] hours, listed below with the risk each addresses. Engagement type: A = assurance, C = advisory/consulting, S = SOX/ICFR support, F = follow-up/validation.

#EngagementObjective (one sentence)Risk addressed (Section 2 ref.)TypeQuarterHours
[1][Name][Assess whether…][Theme #, entity score][A][Q1][400]
[2][Name][…][…][…][…][…]

Drafting guidance. The objective column is the discipline that separates real plans from lists: a one-sentence objective per engagement forces you to know what question the audit answers before the year starts, and it becomes the planning memo’s opening line later. The risk-reference column is the traceability the committee approves on — an engagement that cannot cite a Section 2 theme or a top-quartile entity is either mis-scoped or political. Group the listing by quarter, show hours honestly (including reporting and follow-up time, which plans chronically omit), and keep the SOX support and follow-up work visible as their own types, because both consume capacity and both get forgotten when someone asks why the plan “only” has twelve audits.

Section 4 — Coverage analysis against the universe

4. Coverage analysis. The plan addresses [X] of the [N] universe entities directly and [Y] through reliance on other assurance providers (Section 7). Of the [Z] entities rated high-risk, [all / all but the following] are covered in [year] or were audited within the prior [12–24] months. Entities not covered in this cycle, with the last audit date and the basis for deferral, are listed in Appendix C. The Committee’s attention is drawn to the following deliberate coverage gaps: [entity] — [reason, e.g., system replacement in progress; will be audited post-go-live]; [entity] — [reason].

Drafting guidance. This is the section most plans skip and the one committees value most, because it answers the question they are legally there to ask: what are we not looking at? Present it as a rotation view — every universe entity with its last-audited date and next-planned date — and then name the deliberate gaps in the body text, with reasons. A gap with a stated reason is governance; a gap discovered by the committee is a credibility event. If a high-risk entity is deferred, say so in this paragraph, not in an appendix footnote: you want the committee to accept the deferral explicitly, because that acceptance is what protects the function when the deferred area produces the year’s surprise.

Section 5 — Reserve capacity and the change mechanism

5. Reserve capacity and plan changes. [X]% of available hours ([H] hours) is held unallocated for management requests, investigations, and emerging risks. Requests against the reserve are approved by the Chief Audit Executive and reported to the Committee quarterly. The plan will be re-evaluated on the following triggers: [a significant acquisition or divestiture; a major system implementation; a control failure or fraud; a regulatory development; a material change in the risk assessment]. Engagements added, deferred, or removed will be presented for the Committee’s approval at the next scheduled meeting, with the risk consequence of each change stated.

Drafting guidance. A plan with no reserve is a forecast of its own failure — something always arrives. Ten to fifteen percent is the practical range; state the number and the approval rule so drawing on the reserve is governance, not improvisation. The trigger list matters more than it looks: it pre-authorizes the conversation, so when the acquisition lands in May, re-planning is a scheduled act rather than an admission. And write the last sentence exactly as shown — changes go to the committee with their risk consequence, which is what stops plans from shrinking quietly, the failure mode the resource-escalation standard exists to prevent.

Section 6 — Resources

6. Resources. Available capacity for [year] is [H] productive hours from [N] staff after training, administration, and leave ([assumptions]). Planned engagements require [H] hours; the reserve requires [H]; the total is [within / exceeds] capacity by [H] hours. Skills required by the plan that are not held in-house — [e.g., ERP security, actuarial, data science] — will be sourced through [co-source arrangement / guest auditors] at an estimated cost of [$], within the approved budget. [If applicable:] The plan as presented exceeds available capacity by [H] hours; absent additional resources, the engagements marked † in Section 3 would be deferred, with the coverage consequences described in Section 4.

Drafting guidance. Show the capacity arithmetic — productive hours, not headcount — and let it be visibly honest about training and leave; committees respect a plan that admits people are not machines. The skills paragraph is the 10.2 obligation in one sentence. And use the bracketed last sentence when it is true: putting the shortfall and the deferral list in the plan is the single strongest move a CAE can make, because it converts a budget constraint into a coverage decision the committee owns — the same logic the plan-defense simulation rewards in interviews, applied for real.

Section 7 — Coordination and reliance

7. Coordination with other assurance providers. Internal audit’s coverage was planned in coordination with [external audit, compliance, risk management, information security, quality assurance]. The following universe entities are covered in [year] by other providers rather than by this plan: [entity] — [provider, nature of work, basis for reliance]; [entity] — […]. Reliance was evaluated against [the provider’s independence, competence, and the scope and evidence of their work] and will be reconfirmed at [mid-year]. External audit’s planned reliance on internal audit’s work is [described / not applicable].

Drafting guidance. This section is where duplicated coverage gets eliminated and phantom coverage gets caught — the entity both you and compliance assumed the other had. Name the provider and the basis for reliance per entity; “we rely on second line” without a basis is exactly what Standard 9.5 now forbids. Keep the assurance map itself as an appendix and summarize here.

Section 8 — Approval page

8. Approval. The Audit Committee reviewed the [year] internal audit plan at its meeting on [date], including the risk assessment on which it is based, the engagements planned, the coverage analysis and deliberate coverage gaps in Section 4, the reserve and change mechanism in Section 5, and the resource position in Section 6. The Committee [approves the plan as presented / approves the plan subject to the following modifications: …] and accepts the coverage gaps identified. Committee Chair: [name, signature, date]. Chief Audit Executive: [name, signature, date]. Appendices: A — risk assessment methodology; B — entity risk scores; C — universe rotation and deferrals; D — assurance map.

Drafting guidance. Make the committee approve the gaps, not just the plan — the resolution language above does that explicitly, and that sentence is the one you will be grateful for in a bad year. A signature page also converts the plan from a management document into a governance record, which is what quality assessors and regulators go looking for.

Worked example: MidState Beverage, FY27

MidState Beverage: a three-state drinks distributor, twelve warehouses, 300 delivery routes with drivers collecting cash from smaller customers, a 2013-vintage ERP, two small acquisitions last year still on their own systems, and a lean finance team with recent turnover. A six-person audit function. The plan’s Section 2 themes, as MidState’s CAE wrote them: (1) cash custody at the route level — 300 daily points of custody with reconciliation dependent on driver honesty and depot discipline; (2) unintegrated acquisitions — two entities consolidating from unassessed systems through spreadsheets; (3) ERP access and change debt — thirteen years of role accretion under an ITGC program last refreshed in 2021; (4) close capacity — review controls thinning under turnover. Section 3, abbreviated:

#EngagementObjectiveRisk ref.TypeQtrHours
1Route cash handling and collectionsAssess whether cash collected on routes is completely deposited, timely reconciled, and monitored for skimming and lappingTheme 1; Routes 4.6AQ1520
2Acquisition integration controlsAssess whether the two acquired entities’ financial data reaches consolidation completely and accurately, and which controls exist at the entitiesTheme 2; Acq. 4.4AQ1–Q2440
3ERP user access managementConclude whether access is provisioned, adjusted, and removed timely and reviewed effectivelyTheme 3; ERP 4.3AQ2360
4Warehouse inventory — two largest sitesAssess count integrity, shrinkage monitoring, and adjustment controlsTheme 1 (custody); Inv. 3.9AQ3380
5Financial close under turnoverAssess whether key close controls operate at required precision given staffing changesTheme 4; Close 4.1AQ3300
6ICFR support — key control testingTest management’s key controls per the SOX planAll themesSQ2–Q4900
7Issue validationValidate remediation of the 14 open FY26 findingsFQ1–Q4240
8Fleet and DOT compliance (advisory)Advise on the compliance monitoring design ahead of the FY28 auditFleet 3.4CQ4160

Section 4, in MidState’s words: “The Committee’s attention is drawn to two deliberate gaps. Procurement (score 3.7) is deferred to FY28 following its FY25 audit and satisfactory follow-up. Fleet safety (3.4) receives advisory work only in FY27; the acquisitions’ fleet operations will be included in the FY28 assurance scope once integrated.” Section 5: 12% reserve (600 hours) with the standard triggers, plus one MidState-specific trigger — any further acquisition. Section 6: 6,300 productive hours available against 6,180 planned; ERP security skills co-sourced for engagement 3 at an estimated $28,000 within budget. The route-cash engagement, #1, is the one that continues through the rest of the Templates Suite — its planning memo is next.

The four ways plan documents fail

FailureHow it looksThe fix in the template
The inherited planLast year’s list with the dates changed; the risk assessment written afterward to justify itSection 2 first, Section 3 traced to it — the risk-reference column makes inheritance visible
The silent gapHigh-risk entities uncovered for years and nobody decided thatSection 4’s named gaps and the approval language that makes the committee own them
The fantasy budgetHours that omit reporting, follow-up, SOX support, and training; a plan that is 30% over capacity by MarchSection 6’s productive-hours arithmetic and the † deferral list
The frozen planNo reserve, no triggers; the year’s surprise either gets ignored or cannibalizes an audit without anyone decidingSection 5’s reserve, triggers, and re-approval mechanism

Formats, cadence, and Standards alignment

The template is format-agnostic — a document for most functions, a deck for committees that prefer slides (sections become slides; the plan listing and coverage rotation become the two exhibits everyone photographs), and a workbook behind either for the scoring and hours. Whatever the format, keep the eight sections in order, because the order is the argument: basis → risk → plan → coverage → flexibility → resources → reliance → approval. Cadence: full re-issue annually; a one-page change memo per quarter under Section 5 (added, deferred, removed, with risk consequence); a mid-year universe refresh if the trigger list fires. On the Standards: this structure satisfies 9.4 (the plan), evidences 9.1 (the understanding behind it) and 9.5 (coordination) at summary level, and gives the committee what 8.1 and 8.2 ask of it — which means the plan document doubles as an artifact for the Domain IV evidence checklist. One last discipline: date every version, because the plan you present in January and the plan you deliver in December should differ, visibly, for reasons written down.

Final thoughts

A plan document is the function’s annual argument — for its coverage, its resources, and its judgment about what matters. Eight sections, each doing one job, each answering a question before it’s asked: that structure is what turns the committee’s approval from a formality into an informed decision, and turns the year’s inevitable surprise from a crisis into a scheduled conversation. Build it once from this template; after that, it mostly maintains itself.

The Templates Suite — one company, one cycle: the engagement planning memo · the walkthrough document · the audit report set · the finding and issue log. The method behind Section 2 lives in our risk assessment guide.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading