{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-09","description":"The chief audit executive develops an internal audit strategy aligned with organizational objectives and stakeholder expectations, grounded in a documented understanding of the organization's governance, risk management, and control processes. The strategy includes a documented assurance, advisory, and administrative capacity mix calibrated against ERM maturity and resourcing; strategic change and the current risk environment; the strength and reliability of other assurance providers; and board direction and stakeholder expectations. A risk-based internal audit plan covering the audit universe is created at least annually, approved by the board, and adjusted as the risk landscape changes. The capacity mix is reconsidered whenever the plan is refreshed, and material changes are communicated to senior management and the board with their coverage impact. The strategy, plan, capacity mix, board approvals, refresh decisions, and communications are retained.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-ERM-04","propositionTitle":"Assurance and Advisory Portfolio Calibration","source":"iia-pos-2026-erm","sourcePages":"ERM p. 14","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"}],"members":[{"control_id":"Principle 9","coverage":"partial","delta":"Principle 9 also spans methodologies (9.3) and assurance coordination/reliance (9.5)","framework":"iia-2024","relationship":"intersects_with"},{"control_id":"Std 9.1","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 9.2","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 9.4","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"The chief audit executive develops an internal audit strategy aligned with organizational objectives and stakeholder expectations, grounded in a documented understanding of the organization's governance, risk management, and control processes. The strategy includes a documented assurance, advisory, and administrative capacity mix calibrated against ERM maturity and resourcing; strategic change and the current risk environment; the strength and reliability of other assurance providers; and board direction and stakeholder expectations. A risk-based internal audit plan covering the audit universe is created at least annually, approved by the board, and adjusted as the risk landscape changes. The capacity mix is reconsidered whenever the plan is refreshed, and material changes are communicated to senior management and the board with their coverage impact. The strategy, plan, capacity mix, board approvals, refresh decisions, and communications are retained.","title":"Develop a risk-based internal audit strategy and plan","unified_id":"UC-AUDIT-09"},"id":"uc:UC-AUDIT-09","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-09","sourceIds":["iia-2024","iia-pos-2026-erm"],"sourceUrl":null,"title":"UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0456f3c81c9ed5dc0e903c99a995812d5139e03c6c2157e2ccb916347824a01b","properties":{"control_id":"Std 9.4","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-9-4-ba0e83d3.json","targetId":"ctrl:iia-2024:Std 9.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0ab85b62605a0cc1d7fad0caaff344a503e50114cc7abbf9da035cb6d1000e78","properties":{},"sourceDetailPath":"/data/v1/records/wf-a5-cb7fa618.json","sourceId":"wf:A5","targetDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","targetId":"uc:UC-AUDIT-09","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:37b061e56d22142ddc51e3b30a6612e15b06727b53790c237c770be9ccebc719","properties":{"rationale":"A board-approved risk-based plan directs independent assurance to the key risks the board must oversee.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/risk-gov-oversight-failure-d98ffc12.json","targetId":"risk:gov-oversight-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3ae879825aa0923bdf383513123695da051588e837f4f6f10635b82f82e58d33","properties":{},"sourceDetailPath":"/data/v1/records/wf-a9-8040386c.json","sourceId":"wf:A9","targetDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","targetId":"uc:UC-AUDIT-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:75848d488894949daa1062fd17db2cd9d2f4800a73de6afd9fe6c8824c571caf","properties":{"control_id":"Std 9.2","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-9-2-5d85724b.json","targetId":"ctrl:iia-2024:Std 9.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8d541a5cf5c4693768950d074cf5285533f6708c692c8404b375d1e8a65d9b21","properties":{"control_id":"Principle 9","coverage":"partial","delta":"Principle 9 also spans methodologies (9.3) and assurance coordination/reliance (9.5)","framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-9-068ca212.json","targetId":"ctrl:iia-2024:Principle 9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:beddf33a2bdee63b7ae0cd3234a6b150c9b08bf30516bbf1632ec9b7b4aed435","properties":{"control_id":"Std 9.1","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-9-1-896fe078.json","targetId":"ctrl:iia-2024:Std 9.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dff5fbe626f856a99fa964c901dc3e7176cdc5bf15dd37141519715437b6a3e5","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/risk-ops-regulatory-reporting-failure-d1dbc50a.json","targetId":"risk:ops-regulatory-reporting-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f32821d0b84d82e1a105e55ab3563bf1af959c2a5f017cd896ba6e6c35dbd43e","properties":{"control_id":"IIA-POS-ERM-04","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM p. 14","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-04-592b59ae.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-04","type":"informed_by"}],"schemaVersion":1}
