CIA-3 - Internal Audit Plan - Section B.2

Describe the processes to develop a risk-based audit plan, including risk assessment methodology, alignment with organizational and internal audit strategy, and triggers for timely updates.

Describe the risk assessment methodology and risk prioritisation approach used to build a risk-based audit plan, and explain the process for keeping the plan aligned with the organisation's strategy, the internal audit strategy, and stakeholder expectations. Recognise the circumstances, such as a new significant risk or organisational change, that trigger the need for timely updates to keep the audit plan dynamic rather than static.

Risk-based audit planRisk prioritisationDynamic audit plan

Practice question for this objective

Free sampleInternal Audit Planmedium

At Kingsford Logistics the chief audit executive is building next year's audit plan and has ranked the audit universe using a risk model weighted for likelihood and impact. A senior manager lobbies for the loyalty-rewards system to be audited first because a colleague in another company had a problem there, although Kingsford's own model scores that system as low risk. What should the chief audit executive do?

  • AMove the loyalty-rewards system to the top of the plan, since a peer organisation's incident is direct evidence that the residual risk score understates the true exposure.
  • BDrop the loyalty-rewards system from the plan entirely, because the risk model already scored it low and management pressure should not influence audit coverage.
  • CAssess whether the peer incident reflects a risk factor present at Kingsford, update the risk inputs if it does, and let the revised scoring determine the engagement's position. Correct
  • DAdd the engagement at its current low-risk position but expand its scope so that the concern raised by the senior manager is covered without disturbing the plan.
New risk information changes the audit plan only after it is tested against the organisation's own risk factors and fed through the risk assessment methodology. A risk-based plan is ordered by the organisation's own risk assessment, so external signals are inputs to be evaluated against local risk factors, not reasons to override the methodology on demand.

Why A is wrong: This is tempting because peer incidents can be a useful input, but a single anecdote from a different company is not evidence about Kingsford's own controls, and reordering the plan on it abandons the risk methodology.

Why B is wrong: This over-corrects: refusing even to consider new information is as unsound as caving to pressure, and the point of a risk assessment is to be revisited when relevant inputs appear, not frozen.

Why C is correct: Correct: the methodology drives prioritisation, so the CAE tests the new information against Kingsford's own risk factors and lets the updated assessment, not lobbying, set the ranking.

Why D is wrong: This looks like a compromise, but padding the scope of a low-priority engagement misallocates resources and does not address whether the risk score itself should change.

See more CIA-3 practice questions, answers explained.

More in this domain

Back to all Internal Audit Plan objectives, or the CIA-3 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.