3.3 Strategy, Risk Management, and Performance of the Activity Under Review
Key Takeaways
- CIA Part 2 A3b is about the strategic objectives of the activity under review — not the chief audit executive's annual internal audit plan
- You cannot plan key-risk coverage if you do not understand what the activity is trying to achieve, which KPIs it uses, and how it manages risk to those objectives
- Strategy, risk management, business performance measures, and performance management techniques must be read together; incentive scorecards show where people will trade control for a target
- Efficiency KPIs such as invoice cycle time can conflict with control objectives such as three-way match completeness, duplicate-payment prevention, and vendor-master segregation of duties
- Plan procedures against the controls the activity's strategy is likely to stress, and use the activity's own KRIs and residual-risk limits as candidate evaluation criteria after they pass the Section 3.1 tests
3.3 Strategy, Risk Management, and Performance of the Activity Under Review
Quick Answer: You cannot plan key-risk coverage if you do not understand what the activity under review is trying to achieve, which KPIs it uses, and how it manages risk to those objectives. CIA Part 2 A3b is an engagement-planning skill. It is not the annual internal audit plan, not the CAE's board dashboard, and not a license to redesign corporate strategy.
Section A3 of the 2025 syllabus tells you to plan the engagement so you can assess key risks and controls. Bullet A3b is specific: when planning, recognize the strategic objectives of the activity under review and their integration with risk management, business performance measures, and performance management techniques. “Integration” is the exam word. Strategy without KPIs is a poster. KPIs without risk limits are a speedometer with no brakes. Risk registers that never mention the activity's actual targets are theatre.
Three questions that unlock the work program
Before you choose samples, answer three questions in the planning file:
- What is this activity trying to achieve this year? Not the enterprise mission statement. The activity's own objectives — cycle-time reduction, cost-per-unit, fill rate, licensing turnaround, claims accuracy, uptime, enrollment yield.
- How is success measured and steered? Business performance measures (KPIs, SLAs, balanced-scorecard cells) plus performance management techniques (OKRs, Lean/Six Sigma throughput goals, operating reviews, incentive compensation).
- How does the activity manage risk to those objectives? Risk appetite and tolerance, key risk indicators, compensating controls, accepted residual risk, and escalation when a KRI is breached.
If you cannot answer those three, you do not yet know where the activity will cut corners. You therefore cannot claim you planned coverage of key risks. You can only claim you planned coverage of last year's work program.
Stay inside the engagement. How the CAE selected this activity for the annual plan, how many hours finance receives this year, and how the CAE reports internal audit's own KPIs to the board are CIA Part 3 topics (GIAS Domain IV). Using them as distractors is a common 2019-syllabus leftover.
How the four pieces integrate
| Piece | What you collect in planning | Why it changes procedures |
|---|---|---|
| Strategic objectives of the activity | Approved local strategy, shared-service mandate, transformation business case | Tells you which outcomes management will defend even if controls slow them down |
| Risk management | Activity-level risks on the ERM register, residual-risk ratings, appetite/tolerance, incident history | Tells you which failures management already accepted — and which it claims it did not |
| Business performance measures | KPI dictionary, SLA clauses, dashboard definitions, clock-start rules | Candidate evaluation criteria (after the Section 3.1 tests) and a map of measurement bias |
| Performance management techniques | Scorecards, OKRs, stretch targets, bonus weightings, quality gates, daily huddles | Tells you where people are paid or praised to hit a number |
The integration test on the exam looks like this: given an activity objective, a KPI, and a risk limit, which engagement procedures address the tension among them? The wrong answers isolate one piece (“cycle time is improving, so risk is low”) or jump to the CAE's annual plan.
Performance management techniques deserve a hard look because they are how strategy becomes daily behavior:
- Balanced scorecard / weighted bonus scorecard — If 80% of the bonus is cycle time and 20% is accuracy, planning should expect accuracy controls to be under pressure.
- OKRs — A stretch “key result” of three-day invoice cycle time is a design choice, not a law of nature. Ask what was de-scoped to make the stretch possible.
- SLAs and operating-level agreements — These are often the most relevant criteria for the activity (Section 3.1). Confirm the definition matches the dashboard, or your comparisons will not be reliable.
- Lean / Six Sigma cycle-time projects — Throughput projects often remove “non-value-added” checks. Your job is to see whether a control was reclassified as waste.
- Quality gates versus skip rules — Match waivers, auto-approval thresholds, and “touchless” invoice processing are performance techniques with control consequences.
Scenario: shared-service accounts payable chasing cycle time
A global manufacturer moved AP into a shared-service center. The center's strategy for this fiscal year is to cut average invoice cycle time from 8 days to 3 days. The business case promised working-capital improvement and a lower cost per invoice. The center's performance measures are average days to pay, invoices per FTE, and cost per invoice. Its monthly scorecard weights cycle time at 70%, cost at 20%, and “quality” at 10%. Quality is defined as the percentage of invoices paid without a vendor query — not as match completeness.
Risk management tells a different story. Duplicate payments are rated residual “low” if they stay under 0.15% of spend. Three-way match may be waived under $5,000 with a single approver “to protect cycle time.” Vendor-master changes are processed by the same team that can add invoices to the payment run on overtime weekends. Incentive pay for team leads is tied to the cycle-time cell of the scorecard.
If you plan only to test whether cycle time is 3 days, you will likely conclude the function is succeeding. That is the trap. Efficiency KPIs can conflict with control. The strategy predicts where control will break:
| Control likely stressed by the 3-day strategy | Why cycle time puts it under pressure | Planning implication |
|---|---|---|
| Three-way match | Waivers and skip rules shorten the path from invoice to payment | Sample waiver volume, threshold breaches, and approver SOD |
| Duplicate-payment prevention | Faster processing reduces time to notice a second invoice | Plan analytics on invoice number, amount, and vendor variants |
| Vendor-master integrity | New vendors and bank-detail changes can be rushed to “unblock” invoices | Test change logs versus payment-run access |
| Segregation of duties | Overtime and cross-training to hit the KPI can combine incompatible duties | Re-perform SOD in the live system, not the policy narrative |
| Hold-and-query discipline | “Paid without query” as a quality metric punishes legitimate holds | Recast quality using criteria that include valid holds |
Those procedures are still engagement planning for this activity. They are not a supply-chain process chapter (Chapter 5) and not a finance-concepts chapter (Chapter 4). You are learning to read strategy as a risk signal.
Turning the scenario into criteria and coverage
Apply Section 3.1 to this activity:
- Cycle-time SLA (if signed and measurable) is a relevant, specific criterion for the efficiency objective — use it, do not replace it with an unagreed four-hour target.
- Duplicate-payment residual-risk limit of 0.15% of spend is a management-established performance measure that can serve as a criterion for the accuracy objective if it is specific, practical, and aligned with risk appetite. If it is a slogan with no data definition, it fails the tests and you discuss a replacement.
- Match-waiver policy is an internal-policy criterion. Planning should include the population of waivers, not only happy-path matched invoices — otherwise your comparisons are not reliable.
Do not let the activity's favorite KPI monopolize the engagement. A3b requires you to see the system: objective, measures, techniques, and risk management. Key-risk coverage means the work program spends time on the controls the strategy is currently asking people to weaken.
Exam traps for A3b
- Treating improving KPIs as low inherent risk. Cycle time falling from 8 days to 2.1 days is a performance result. It can increase control risk.
- Using only enterprise strategy. “The company wants to be a low-cost producer” is not a substitute for the AP center's three-day objective and waiver rule.
- Drifting into the annual audit plan. Hours allocated to finance, rotational coverage of AP versus payroll, and CAE utilization are the wrong layer.
- Ignoring incentive design. If you never ask how people are paid, you will miss why match waivers spiked in the last quarter of the bonus year.
Planning is complete for A3b when the work program can point to each key risk and say: this risk exists because of what the activity is trying to achieve, how it measures itself, and how it has chosen to manage (or accept) the related risk.
A shared-service AP function's stated strategy is reducing invoice cycle time from eight days to three. Its bonus scorecard weights cycle time at 80% and payment accuracy at 20%. What is the most important planning implication?
Why must engagement planning include the activity's performance management techniques such as scorecards, OKRs, SLAs, and incentive pay?
Which pairing best shows strategy, risk management, and performance measures integrated for an accounts-payable engagement?