INTERNAL AUDIT · PRACTICAL GUIDE
Internal audit planning checklist for a risk-based review
A useful plan connects the company’s risks to the processes reviewed, the evidence required and the people responsible for acting on findings. Use this checklist to prepare an initial scope discussion.
1. Establish the mandate and reporting line
Record why the review is being commissioned, which entities and locations it covers, who approves the plan and who receives the report. Clarify access to records, escalation arrangements and the responsibilities of management and the reviewer before fieldwork.
For a listed or large private company, agree how the work supports the board, audit committee or other designated governance body. Confirm applicable requirements for the particular company rather than assuming that one checklist covers every entity.
Assess independence, conflicts and permitted scope at the outset. Avoid arrangements in which the reviewer takes responsibility for operating a control and then assesses the same work. Internal audit and statutory audit have different objectives; an internal-audit report does not replace the statutory audit opinion.
2. Map the audit universe and the business risks
List the processes that could affect financial reliability, operations, compliance or the protection of assets. Discuss the map with process owners and compare it with current organisation charts, system access, prior findings and significant changes in the business.
- Order to cash: customer approval, pricing, billing completeness, collections, credit notes and receivables.
- Procure to pay: vendor creation, purchasing approval, receipt of goods or services, invoices and payments.
- Finance and close: reconciliations, journals, estimates, reporting, related-party balances and approval of adjustments.
- Payroll, inventory and assets: access to employee or asset records, authorised changes, physical checks and exceptions.
- Systems and governance: user access, change approvals, audit logs, delegated authority and follow-up of earlier findings.
This is an illustrative universe. Add industry-specific areas and outsourced processes where relevant. Record the risk, possible consequence and existing control for each area; a list of departments alone is not an assessment.
3. Prioritise using evidence and judgement
Consider the significance of the potential impact, likelihood, transaction volume, process complexity, recent system changes, known control gaps and overdue findings. Agree a consistent rating method and document why an area has been selected or deferred.
Use the assessment to set the review sequence, frequency, resources and time available. A high score is a prioritisation aid, not proof that a loss or breach has occurred. Avoid promising to review every transaction or discover every possible fraud.
Define the period, locations, systems, process boundaries and exclusions for each assignment. Specify the objective in observable terms: for example, whether changes to vendor bank details require independent verification and recorded approval before payment. Obtain approval of the plan and revisit it when material risks change.
4. Turn the scope into a control and test matrix
For each risk, identify the control owner, how often the control operates, what evidence it creates and how the reviewer will assess it. Distinguish whether the control is suitably designed from whether it actually operated during the review period.
| Risk | A payment is directed to unauthorised bank details. |
|---|---|
| Expected control | An authorised person independently verifies and approves the change before it is used. |
| Evidence | Change request, verification record, approval, system log and related payment record. |
| Review procedure | Trace selected changes to verification and approval; compare timestamps and check segregation of access. |
| Limit | Selection and testing are determined by the scope and risk assessment; the example is not an assurance conclusion. |
Record the selection method, period covered, source population and limitations. Use appropriately controlled document-sharing arrangements. Preserve enough evidence for another qualified reviewer to understand the observation and the basis for it.
5. Report clearly and follow through
A useful finding states the condition observed, the expected control or criterion, the risk or consequence and the evidence supporting the observation. Discuss facts with the responsible team and distinguish confirmed issues from missing information.
Agree a management response, action owner, target date and priority. Report material issues through the agreed governance route. Keep a follow-up register with overdue actions, revised dates, evidence of implementation and the reviewer’s closure assessment.
Marking an action “done” is not the same as establishing that the revised control operates. Define how closure will be tested. Periodically review recurring issues and whether the underlying cause has been addressed.
Download the illustrative planning matrix
Use the CSV as a starting point for a scope discussion. It contains example risks, controls, evidence and review procedures for purchasing, collections, close, inventory, payroll and systems. Assign the actual owners, dates and priorities for your business.
Download the planning matrix (CSV) ↗A template is not an approved audit plan or a substitute for professional judgement. None of its example entries represents a finding about a client.
Standards and engagement boundaries
For current professional standards, refer to ICAI’s compendium of Standards on Internal Audit. This page is an original practical planning aid; it does not reproduce the standards or certify compliance.
Applicability, legal obligations, independence and the permitted engagement scope must be assessed on the company’s facts. Discuss the proposed internal-audit scope with the firm.