3.1 Strategic & Annual Audit Planning
Key Takeaways
Strategic planning translates mandate and organisational objectives into a multi-year view of the auditable universe, risks, resources and intended assurance coverage.
Annual planning selects and sequences assignments using transparent risk criteria while preserving room for emerging risks and mandatory work.
A risk-based ranking supports judgment but does not replace it; legal obligations, prior findings, stakeholder significance, auditability and available skills can change priorities.
Each proposed assignment needs a preliminary objective, scope, timing, resource estimate and explanation of why it matters now.
Plans should be revisited when risk, resources or organisational objectives change, with decisions and deferred coverage documented.
3.1 Strategic & Annual Audit Planning
Audit planning begins before an individual engagement. Annex II expressly includes contributing to strategic and annual audit planning, including identifying, assessing and prioritising topics through risk analysis and organisational objectives. The aim is not to fill a calendar. It is to direct scarce assurance resources toward work that can reduce uncertainty, strengthen accountability or improve outcomes.
Strategic plan, annual plan and engagement plan
Keep three levels distinct:
- A strategic or multi-year plan describes the audit function's priorities, intended coverage, capabilities and broad resource choices over several years.
- An annual plan selects assignments and other work for the next cycle, estimates timing and resources, and preserves capacity for change.
- An engagement plan turns one selected topic into objectives, scope, criteria, risks, procedures, team roles and milestones.
Confusing these levels produces either a vague annual list or an engagement programme created before the topic has been justified.
Build the auditable universe
Start from mandate and organisational objectives. Catalogue entities, programmes, processes, funds, systems, projects, locations and cross-cutting themes that could be audited. Define units at a level that supports decisions: “IT” is usually too broad, while every application screen is too narrow. Record ownership, objectives, scale, dependencies and known oversight.
The universe is not static. New legislation, programmes, delivery partners, data systems and crises can create topics. Closed programmes may still need final-account or follow-up work. Map connections because a weakness may cross organisational boundaries—for example, procurement data quality can affect grant management, fraud prevention and financial reporting.
Identify and assess risk
Use evidence from management risk registers, financial exposure, performance data, prior audits, control self-assessments, complaints, incidents, external oversight and stakeholder concerns. Common dimensions include:
- Impact: financial, legal, operational, policy, safety, reputational or rights-related consequence.
- Likelihood or vulnerability: probability, complexity, change, decentralisation, discretion and control maturity.
- Strategic significance: relationship to core objectives or public commitments.
- Prior assurance: recency, quality and independence of earlier review.
- Auditability and value: available criteria, evidence, timing and realistic capacity to influence action.
A scoring model can make comparisons transparent, but numbers are decision aids. Avoid false precision: a score of 74 is not objectively “three points riskier” than 71 if inputs are ordinal judgments. Document definitions, evidence and overrides.
Prioritise topics
Rank the candidates, then apply professional judgment and constraints. Mandatory statutory work may proceed even when its residual risk score is lower. A rapidly emerging issue may outrank a large stable programme. Repeated control failure or overdue high-risk recommendations can increase priority. Conversely, a recent credible independent audit may justify deferral.
For every selected topic, prepare a short proposition stating the reason for selection, preliminary audit question, likely scope, expected users, indicative timing, required expertise and resource estimate. For a deferred high-risk topic, state the reason, compensating assurance and reconsideration date.
Balance coverage and capacity
Convert available staff time into realistic capacity after leave, training, administration, follow-up and quality review. Match skills as well as days: an IT-system audit may require specialists unavailable to a general team. Consider travel, language, data-access and procurement lead times.
Maintain a contingency reserve for urgent requests and emerging risks. Overcommitting 100% of theoretical capacity makes the plan brittle and encourages superficial work. If demand exceeds capacity, expose the gap to governance rather than disguising it through optimistic budgets.
Approve, communicate and refresh
The responsible authority reviews whether the plan supports mandate, independence and risk coverage. Internal-audit governance differs from external public audit, so do not assume identical approval arrangements. Once adopted, communicate objectives and timing without surrendering the audit function's independence to choose scope or conclusions.
Monitor delivery, emerging risk and resource changes throughout the year. A sound plan can change. Record additions, cancellations, scope changes, deferred topics and their effects on assurance coverage. At year-end, compare planned and delivered work, identify causes of variance and feed lessons into the next cycle.
Mini-case
Suppose the auditable universe contains a stable payroll process, a newly launched grant platform, a large mature procurement programme and overdue recommendations on access controls. The new platform and access-control follow-up may rank above payroll despite payroll's financial size: change and unresolved security exposure increase vulnerability, while recent reliable payroll assurance reduces the incremental value of another audit. The decision should show those reasons, the resources required and what coverage is deferred.
What is the principal purpose of an annual risk-based audit plan?
To direct available assurance resources to justified priority work while documenting coverage choices
To audit every unit every year
To eliminate the need for engagement planning
To reproduce management’s risk register without challenge
Why should a numerical topic score not be treated as an automatic decision?
Scores are prohibited in audit planning
Inputs often include ordinal judgments, while mandatory work, prior assurance, auditability and emerging risks also matter
Only financial value may be considered
The highest score always lacks evidence
Which item belongs in a concise proposal for a selected topic?
A final audit opinion
Completed test results
A preliminary objective, scope concept, timing, skills and resource estimate
A guarantee that no scope changes will occur
What is the best response when a major emerging risk appears after plan approval?
Ignore it until the next multi-year strategy
Add it without recording any effect
Cancel the lowest-cost audit automatically
Reassess priorities, document the change and explain the effect on resources and deferred coverage
Sections you finish are checked off in the contents.