unified

UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan

The chief audit executive develops an internal audit strategy aligned with organizational objectives and stakeholder expectations, grounded in a documented understanding of the organization's governance, risk management, and control processes. The strategy includes a documented assurance, advisory, and administrative capacity mix calibrated against ERM maturity and resourcing; strategic change and the current risk environment; the strength and reliability of other assurance providers; and board direction and stakeholder expectations. A risk-based internal audit plan covering the audit universe is created at least annually, approved by the board, and adjusted as the risk landscape changes. The capacity mix is reconsidered whenever the plan is refreshed, and material changes are communicated to senior management and the board with their coverage impact. The strategy, plan, capacity mix, board approvals, refresh decisions, and communications are retained.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Compliance, Audit & Assurance
type
preventive
category
administrative

Details

unified_id
UC-AUDIT-09
title
Develop a risk-based internal audit strategy and plan
statement
The chief audit executive develops an internal audit strategy aligned with organizational objectives and stakeholder expectations, grounded in a documented understanding of the organization's governance, risk management, and control processes. The strategy includes a documented assurance, advisory, and administrative capacity mix calibrated against ERM maturity and resourcing; strategic change and the current risk environment; the strength and reliability of other assurance providers; and board direction and stakeholder expectations. A risk-based internal audit plan covering the audit universe is created at least annually, approved by the board, and adjusted as the risk landscape changes. The capacity mix is reconsidered whenever the plan is refreshed, and material changes are communicated to senior management and the board with their coverage impact. The strategy, plan, capacity mix, board approvals, refresh decisions, and communications are retained.
domain
Compliance, Audit & Assurance
control_type
preventive
control_category
administrative
members
  • framework
    iia-2024
    control_id
    Principle 9
    coverage
    partial
    delta
    Principle 9 also spans methodologies (9.3) and assurance coordination/reliance (9.5)
    relationship
    intersects_with
  • framework
    iia-2024
    control_id
    Std 9.1
    coverage
    full
    relationship
    superset_of
  • framework
    iia-2024
    control_id
    Std 9.2
    coverage
    full
    relationship
    superset_of
  • framework
    iia-2024
    control_id
    Std 9.4
    coverage
    full
    relationship
    superset_of
guidance
  • source
    iia-pos-2026-erm
    sourceTitle
    The Role of the Internal Audit Function in Enterprise Risk Management
    propositionId
    IIA-POS-ERM-04
    propositionTitle
    Assurance and Advisory Portfolio Calibration
    sourcePages
    ERM p. 14

Source

No record-specific source URL is provided.

Connections