unified
UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan
The chief audit executive develops an internal audit strategy aligned with organizational objectives and stakeholder expectations, grounded in a documented understanding of the organization's governance, risk management, and control processes. The strategy includes a documented assurance, advisory, and administrative capacity mix calibrated against ERM maturity and resourcing; strategic change and the current risk environment; the strength and reliability of other assurance providers; and board direction and stakeholder expectations. A risk-based internal audit plan covering the audit universe is created at least annually, approved by the board, and adjusted as the risk landscape changes. The capacity mix is reconsidered whenever the plan is refreshed, and material changes are communicated to senior management and the board with their coverage impact. The strategy, plan, capacity mix, board approvals, refresh decisions, and communications are retained.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Compliance, Audit & Assurance
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-AUDIT-09
- title
- Develop a risk-based internal audit strategy and plan
- statement
- The chief audit executive develops an internal audit strategy aligned with organizational objectives and stakeholder expectations, grounded in a documented understanding of the organization's governance, risk management, and control processes. The strategy includes a documented assurance, advisory, and administrative capacity mix calibrated against ERM maturity and resourcing; strategic change and the current risk environment; the strength and reliability of other assurance providers; and board direction and stakeholder expectations. A risk-based internal audit plan covering the audit universe is created at least annually, approved by the board, and adjusted as the risk landscape changes. The capacity mix is reconsidered whenever the plan is refreshed, and material changes are communicated to senior management and the board with their coverage impact. The strategy, plan, capacity mix, board approvals, refresh decisions, and communications are retained.
- domain
- Compliance, Audit & Assurance
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iia-2024
- control_id
- Principle 9
- coverage
- partial
- delta
- Principle 9 also spans methodologies (9.3) and assurance coordination/reliance (9.5)
- relationship
- intersects_with
- framework
- iia-2024
- control_id
- Std 9.1
- coverage
- full
- relationship
- superset_of
- framework
- iia-2024
- control_id
- Std 9.2
- coverage
- full
- relationship
- superset_of
- framework
- iia-2024
- control_id
- Std 9.4
- coverage
- full
- relationship
- superset_of
- guidance
- source
- iia-pos-2026-erm
- sourceTitle
- The Role of the Internal Audit Function in Enterprise Risk Management
- propositionId
- IIA-POS-ERM-04
- propositionTitle
- Assurance and Advisory Portfolio Calibration
- sourcePages
- ERM p. 14
Source
No record-specific source URL is provided.
Connections
- UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan maps_to Std 9.4 — Internal Audit Plan
- framework
- iia-2024
- control_id
- Std 9.4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2024 edition
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Quality Assurance & Improvement Program Cycle tests UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan
- UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan mitigates Inadequate board and management oversight of risk and control
- strength
- related
- rationale
- A board-approved risk-based plan directs independent assurance to the key risks the board must oversee.
- Annual Internal Audit Planning & Resource Management operates UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan
- UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan maps_to Std 9.2 — Internal Audit Strategy
- framework
- iia-2024
- control_id
- Std 9.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2024 edition
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan maps_to Principle 9 — Plan Strategically
- framework
- iia-2024
- control_id
- Principle 9
- coverage
- partial
- delta
- Principle 9 also spans methodologies (9.3) and assurance coordination/reliance (9.5)
- relationship
- intersects_with
- source_version
- 2024 edition
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan maps_to Std 9.1 — Understanding Governance, Risk Management, and Control Processes
- framework
- iia-2024
- control_id
- Std 9.1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2024 edition
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan mitigates Failed or inaccurate mandatory regulatory reporting
- strength
- related
- rationale
- UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan informed_by IIA-POS-ERM-04 — Assurance and Advisory Portfolio Calibration
- framework
- iia-pos-2026-erm
- control_id
- IIA-POS-ERM-04
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- ERM p. 14