Domain 1: The IS Audit Process9 min · 3 questions

Risk-Based Audit Planning

How the annual audit plan is built from a risk assessment rather than from last year's plan, and why coverage is not the objective.

What this makes you able to do

Develop a risk-based IS audit plan that allocates audit resources according to assessed risk.

By the end you can

  • Construct an audit universe and rank it by inherent and residual risk.
  • Explain why residual risk drives resource allocation while inherent risk drives the universe.
  • Determine the correct response when a significant risk emerges after the plan is approved.

Transcript

Risk-based audit planning. This lesson is about how the annual audit plan is actually built, which is from a risk assessment, not from last year plan, and why coverage is not the objective.

Start with the arithmetic. You have resource for eleven audits this year. The audit universe has sixty entries. Last year plan covered eleven different ones, and the year before that another eleven. At that rate every system is audited once every five years, which sounds like perfectly reasonable coverage.

And it is the wrong answer. Auditing everything on a cycle feels diligent, and on the exam, cycle-based planning is a distractor in almost every planning question. It allocates effort by elapsed time rather than by risk, which guarantees you spend resource on low-risk areas simply because their turn has come.

So step one is the audit universe. That is the complete set of auditable entities: systems, processes, business units, third parties, projects. And you build it from the organisation, not from the audit function history.

An entity belongs in the universe if it could, in the absence of any controls, cause harm significant to the organisation objectives. That is a statement about inherent risk, which is risk before controls are considered. Controls come next.

Once the universe exists, you assess each entity, and the exam expects you to know the components. Inherent risk is the risk in the absence of any controls. High-value data, regulatory exposure and financial materiality all raise it.

Control risk is the risk that controls fail to prevent or detect a problem in time. And residual risk is what remains after controls operate. Residual risk is the primary driver of where audit effort goes, because it reflects actual current exposure.

Then there is detection risk, and this one is different. Detection risk is the risk that your own procedures fail to detect a material issue. It is about the audit, not the auditee. It is the risk you control directly, by testing more, or differently.

Hold on to that difference, because it is heavily tested. You cannot change inherent risk or control risk. Those belong to management. The only risk the auditor moves is detection risk. So a question that asks what you should do about high control risk is asking about the audit response, which is more testing, not about fixing the control.

That gives you the rule the exam tests most. If control risk is assessed as high, the auditor reduces detection risk by performing more extensive substantive testing. High control risk means more testing, never less.

Now you build the plan against the ranked universe, and you adjust for a few things. Regulatory or statutory requirements that mandate certain audits regardless of ranking. Requests from the audit committee, considered but not determinative. And assurance already provided by others, so you do not duplicate a reliable external review. Time since last audited is a modifier, not a driver. A low-risk area does not become high-risk through neglect alone.

And the plan stays flexible. A significant change in the risk profile, an acquisition, a major new system, a serious incident, triggers a reassessment and re-approval. Not a rigid march through the approved list to the end of the year.

So carry two things away. Resist coverage, because a plan that visits everything on a cycle is not risk-based, however thorough it feels. And remember who owns the plan. Audit proposes it and the audit committee approves it. The moment management decides what audit will and will not examine, independence is gone.

Knowledge check
0 / 3
  1. 1.An IS auditor is preparing the annual audit plan. Which of the following should be the PRIMARY basis for deciding which areas to audit?

  2. 2.Which risk should an IS auditor consider when determining whether an area belongs in the audit universe at all?

  3. 3.Three months after the audit plan is approved, the organisation acquires a competitor with a substantially different technology estate. What should the IS auditor do?

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.