The Biggest Mistakes CAEs Make During Internal Audit Planning

Every internal audit function develops an audit plan. The problem is that many planning processes still reflect how internal audit teams operated years ago rather than how leading organizations operate today. Those standouts recognize that risks change and intensify too fast to do audit planning the old way. Yet even experienced chief audit executives and internal audit leaders can fall into planning habits that result in an audit plan that looks comprehensive but fails to focus on what matters most.

Some internal audit functions develop an annual plan and stick to it for the full year, as if it were cast in stone. A growing majority, however, now allow for changes to be made to the annual plan as the year progresses. Those internal audit teams recognize that they may need to pivot when either risks change or the organization’s goals or priorities change.

Still, following a rigid and unwavering audit plan even as the risk landscape is changing under their feet isn’t the only planning blunder that internal audit leaders make. Here we’ll look at some of the biggest mistakes internal audit functions make when it comes to audit planning. Note that it is hardly a comprehensive list, but includes the crucial planning missteps I have seen (and maybe even have made myself) along the way.

Mistake 1: Treating the Annual Audit Plan as if It Is Cast in Stone

Before anyone raises objections to this, let me acknowledge that in highly regulated industries, there are some audit projects that are non-negotiable and must be done, sometimes annually. And some audit committees may set expectations around certain audit projects that, regardless of what a risk assessment concludes, are simply better done than argued about.

It’s also true that the annual audit plan can be a valuable tool to help justify your staffing and financial budgets, which are also annual exercises. Setting all that aside, though, organizations are dynamic and fluid and your well-crafted annual audit plan should be too. Audit Committees should be comfortable, if they are not already, with the fact that you will need to make changes to your annual audit plan, as the environment changes. Some progressive internal audit functions are now doing rolling quarterly audit plans or even continuous planning, recognizing the need for flexibility. If you are setting the audit plan annually, and not deviating from it as the year goes on, you are not being appropriately responsive to a changing risk environment.

Mistake 2: Relying on Flawed Risk Assessments

Garbage in, garbage out, right?

Here is what some internal audit functions are still doing (and it’s not a good process). There is a universe of extensively developed auditable activities from which all potential audit projects are listed. These projects are risk scored considering both objective and subjective factors, including things like last time audited, staff turnover in the function or department, leadership changes, stability, and other factors. The internal audit team conducts interviews across the organization to gather risk information, and then applies a scoring algorithm. The riskier an area is perceived to be, the more likely it will be on the upcoming year’s audit plan. It looks thorough and well thought out. Yet, it likely misses the mark.

Consider that this is not how executives and boards view risk. They view risk through the lens of: what can derail the achievement of strategic and key operational objectives? That should be what drives your audit plan, not some comprehensive risk assessment methodology against an auditable activities universe. Produce your plan based on the risk to achievement of objectives, add to that some regulatory expectations and hot button compliance issues, toss in other high-risk issues, save room for currently unidentified advisory projects, and there is your audit plan.

Mistake 3: Developing the Audit Plan in a Vacuum

The longer we are employed by an organization, the more likely it is that we think we know all there is to know about it. Yes, we may go through some key person interviews to build an understanding going into our annual audit planning exercise, but we may also begin to over rely on our own knowledge and judgment.

As much as that seems to be quite expedient, it is also rife with the introduction of bias. Our own biases about what is a priority, what is important, what we think is, or is not, risky can skew our thinking. I know, we all like to think that we are objective and can set aside our biases and, maybe those conscious biases can be compartmentalized and set aside, but we are human, and we all have unconscious biases.

Try to avoid these traps as much as possible. Speak with key colleagues in the organization as you work to build your audit plan. Objectively challenge your assumptions. Do not create a plan in a vacuum. The question is not: “What keeps you up at night?” The question should be: “What will get in the way of the organization achieving its key objectives?”

Mistake 4: Ignoring Changing Risk Dynamics

For many internal audit functions, the annual plan is developed from an exercise done, well, annually. Risk assessments cannot be a “once a year and, wash your hands, call it a done” activity. Because risk is dynamic—and becoming even more so over time—the organization’s risk profile changes continually. Before you start thinking about making or proposing changes to that well-crafted, audit committee-approved, annual audit plan, you must have a basis for which you want to make or recommend changes.

That comes from having some form of continuous risk assessment taking place in the background as audit projects are being completed. This process will benefit from being as formalized as possible, but it does not need to be overly complex. Even if it simply involves the CAE regularly meeting with key internal audit staff members to discuss changing organizational dynamics and consider whether adjustments to the audit plan are needed, that may be sufficient. The key is to stay ahead of evolving risk dynamics and establish processes that ensure internal audit remains aligned with the organization’s changing risk profile.

Mistake 5: Taking a Cyclical Approach to Audit Project Prioritization

Sure, the last time an area was audited should factor into the audit planning processes if that area, subject, or process has responsibility for managing the risks that could impede the organization from realizing its key strategic and operational objectives. But the old days of doing audits on a cyclical basis should now be long gone. Other than a pesky regulator holding your feet to the fire to audit certain areas on a cyclical basis, doing the same audit once a year, once every two years, every three years, or even every five years is not a justification to audit something again. Approaching things with that mentality is not a risk-based audit plan.

Mistake 6: Developing the Plan from an Extensive Auditable Activity Universe

Ordering up your audit plan is not like deciding what you want to eat from an extensive menu at a restaurant. If you have a comprehensive auditable activities universe that you consult from time to time to assess whether you may be missing something after you’ve done your risk assessment, then that’s not a bad idea. But it is not the place to start. Auditable activities typically reflect how the organization is organized along the lines of who is responsible for what, and are more of a vertical view of the organization. But risk can cut across the organization and is more of a horizontal view of the organization. Start with risk and use your extensive auditable activities universe as a gut check on the plan you are considering … not the other way around.

Mistake 7: Failing to Carve out Sufficient Time for Advisory Projects

Some internal audit functions—sometimes driven by audit committee or executive expectations—allocate all available audit hours to assurance work. The goal is often to maximize the number of projects completed on the annual audit plan and achieve what appears to be 100% utilization. That approach may work if the organization has no expectation that internal audit will provide advisory support (which itself may signal a larger problem), or if leadership understands that any unplanned advisory work will necessarily reduce the number of assurance projects completed. Otherwise, internal audit risks creating a plan at the beginning of the year that it knows it cannot realistically achieve.

Leading internal audit functions set aside some time, usually as a percent of available audit hours, for unscheduled advisory work. What percentage you use reflects how much your organization expects, and has confidence in your team’s ability to perform advisory work that crops up during the year. The typical amount may be 20 to 30 percent, but that can vary. If you do not set aside time for unplanned advisory work, you are setting yourself up for failure and establishing an assurance audit plan that will never get completed.

Audit Planning Creates a Roadmap

Annual audit planning provides many benefits. It helps justify resources, identify where co-sourcing may be needed, and develop a training plan to ensure the internal audit function has the capabilities required to achieve its objectives. But even the best-laid plans will not always align with reality as the year unfolds—especially in organizations facing constantly changing risk dynamics, as most do.

Creating an audit plan and then following it in a rigid, unchanging manner is a recipe for becoming less relevant to the organization and the audit committee. The most effective internal audit functions recognize that the plan is a roadmap, not a contract. Avoiding these seven mistakes will enhance your relevance, strengthen your value proposition, and position your internal audit function to make a meaningful difference in the organization. And ultimately, isn’t that why we’re here?  Internal audit end slug


Hal Garyn is Contributing Editor at Internal Audit 360°, and Managing Director and Owner of Audit Executive Advisory Services, LLC based in FL.

Leave a Reply

Your email address will not be published. Required fields are marked *