{"description":"Runs the chief audit executive's annual internal audit planning cycle on a per-cycle Audit item created for the year (audit_type=internal, e.g. \"Annual IA Planning Cycle FY20XX\", status PLANNED→COMPLETE, period_start/period_end = the plan year) — the anchor the workflow instance and every cycle document and link hang off, since no native plan/cycle type exists. It consumes the standing (prior-year) audit universe carried in as Process items plus the prior cycle's archived instance and universe memo, and enriches rather than recreates it: it refreshes the audit universe and the documented understanding of governance, risk, and control processes, ranks the universe by residual risk, develops the internal audit strategy and the risk-based audit plan, resources it with a budget, staffing, and technology plan, tests resource sufficiency, obtains board approval, and reassesses the plan and resources on the quarterly refresh. In scope is the enterprise-level planning cycle from audit-universe refresh through board approval, plus the quarterly plan-and-resource reassessment; delivering the individual engagements is out of scope — the approved engagement list (the created engagement Audit items) hands off to each engagement's own audit engagement planning workflow.","edges":[{"id":"e-develop-audit-strategy-assess-resource-sufficiency","source":"develop-audit-strategy","target":"assess-resource-sufficiency"},{"id":"e-assess-resource-sufficiency-reconcile-constraints-and-coverage","label":"Constrained - resource shortfall limits coverage","source":"assess-resource-sufficiency","target":"reconcile-constraints-and-coverage","whenValue":"constrained"},{"id":"e-assess-resource-sufficiency-obtain-board-approval","label":"Sufficient - resources deliver the plan","source":"assess-resource-sufficiency","target":"obtain-board-approval","whenValue":"sufficient"},{"id":"e-reconcile-constraints-and-coverage-obtain-board-approval","source":"reconcile-constraints-and-coverage","target":"obtain-board-approval"},{"id":"e-obtain-board-approval-establish-quarterly-refresh","source":"obtain-board-approval","target":"establish-quarterly-refresh"},{"id":"e-establish-quarterly-refresh-log-plan-adjustment","label":"Adjustment required","source":"establish-quarterly-refresh","target":"log-plan-adjustment","whenValue":"adjustment_required"},{"id":"e-establish-quarterly-refresh-close-and-archive","label":"On track - no adjustment needed","source":"establish-quarterly-refresh","target":"close-and-archive","whenValue":"plan_on_track"},{"id":"e-log-plan-adjustment-close-and-archive","source":"log-plan-adjustment","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-AUDIT-09","UC-AUDIT-10"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-annual-internal-audit-planning-resource-management","contentDigest":"sha256:2e25e6b33c874dbffd18cd204117039793dba7390af3d1956eb91cbbd82141f7","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:2e25e6b33c874dbffd18cd204117039793dba7390af3d1956eb91cbbd82141f7","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-annual-internal-audit-planning-resource-management"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"audit-annual-internal-audit-planning-resource-management","source":"coworkcanvas-gallery","standards":["iia-2024"],"teams":["internal-audit"]},"name":"Annual Internal Audit Planning & Resource Management","nodes":[{"data":{"description":"Approve the auditable universe, resolve protected-score drift and choose the risk-based strategy, capacity mix and engagement priorities.","instructions":"**Objective** — Approve the auditable universe, resolve protected-score drift and choose the risk-based strategy, capacity mix and engagement priorities.\n\n**Inputs**\nThe standing (prior-year) audit universe carried in as the cycle's baseline — the Process items (the auditable-area inventory, each with `process_type` and `process_owner`), plus the prior cycle's archived workflow instance and its universe memo.\n- Source inventories uploaded at this step (CSV/XLSX extracts — there is no native entity/application/vendor-register type): the legal-entity register, the organization chart and business-unit structure, the process taxonomy, the application inventory or CMDB, and the vendor or third-party register.\n- Management's documentation uploaded at this step: governance charters and committee structures, the risk management framework, policies and process narratives — and the enterprise risk assessment, which is the Risk items already in the register (`inherent_rating`, `residual_rating`, `risk_owner`).\n- Prior engagement history per area, read from the prior Audit items (`rating`, `opinion`, `report_date`/`fieldwork_end` = last-audited date) and their linked Issue items (`severity`, `issue_type`, `identified_date`); the Audit↔Process links give per-area history.\n\nThe approved refreshed universe with the per-area understanding of governance, risk, and control processes.\n- Per entity: attributes (revenue or asset exposure, jurisdictions, process and system counts, change activity) and the historical baseline — the prior-year inherent score and the year-over-year delta.\n- Linked controls with effectiveness status and last-tested dates; key-risk-indicator status against the risk appetite; time since last audited and the scope actually covered.\n- External intelligence: recent regulatory enforcement and fraud cases in the organization's domains.\n- The organization's factor-weighting configuration where one exists; the changing risk landscape — emerging and top-of-house risks, regulatory developments, management and board areas of concern.\n\nThe stakeholder expectations: board or audit committee, executive management, primary regulators.\n- The organization's strategic plan and objectives and the enterprise risk assessment.\n- The approved risk-ranked universe with the per-area understanding; the internal audit charter and mandate.\n- The prior strategy and how it performed — where it over-promised or under-covered.\n\nThe approved prioritized universe: residual scores, tiers, coverage rhythm, and the areas marked as shifted.\n- Per entity: time since last audited and the scope covered; the target coverage cycle for its tier.\n- The approved strategy: assurance-and-advisory balance, coverage horizon, reliance intentions.\n- Capacity data: total audit hours available for the period and the prior year's actual hours for comparable engagements.\n- The mandatory and regulator-expected coverage list.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Audit Executive owns the stated judgments and authorizations.*\n\n*Refresh the audit universe.* Produce a complete, current audit universe with a documented understanding of the organization's governance, risk management, and control processes for every auditable area (IIA Standard 9.1), so the risk assessment scores real entities instead of last year's list.\n\n1. Rebuild bottom-up from the inventories rather than editing last year's list: every business unit, legal entity, significant process, application, and key vendor that could be the subject of an engagement gets an entry. Size auditable units so one engagement can cover one unit within a normal hours budget — units too coarse hide risk inside the aggregate; units too fine explode the universe beyond what the function can assess.\n2. Test completeness with coverage arithmetic: map entities to revenue, assets, or headcount and confirm the mapped total materially covers the organization; reconcile the process list against the finance and operations taxonomies; confirm every major application and vendor appears. An inventory row with no universe entity is a gap to resolve, not an implicit exclusion.\n3. Refresh the documented understanding per area — the governance structures that oversee it, the risk-framework coverage it receives, and its control environment — from management's documentation, corrected by what prior engagements actually found. Mark understanding that is asserted but unevidenced; those areas carry extra uncertainty into scoring.\n4. Diff against the baseline universe: new auditable entities (acquisitions, new products, new systems), retired areas, and areas whose governance, risk, or control profile has materially changed since the last cycle. Every add, retirement, and profile change carries the reason it moved.\n5. Draft the audit-universe memo: the refreshed universe, the per-area understanding, and the change list with rationale. Route to the chief audit executive to resolve any area whose inclusion or profile is ambiguous and approve the universe as the risk-assessment basis — an area wrongly excluded here is invisible to every later step.\n\n*Assess risk and prioritize the universe.* Score every universe entity through the two-pass inherent-then-residual risk assessment and rank the universe into coverage tiers, so engagement selection traces to a factor-level risk picture the chief audit executive owns and can defend to the audit committee.\n\n6. Inherent pass — score each auditable area on a 1-to-5 scale, one proposed score per audit-universe entity, decomposed into six factors with each factor written to its own field: size (revenue or asset exposure); regulatory exposure (regulated industry, jurisdiction count, recent enforcement); operational complexity (process, system, and integration count); change frequency (org churn, system changes, M&A activity); inherent fraud susceptibility (cash-heavy, manual-process, weak segregation of duties); and historical issue volume (findings over the past two years).\n7. Pull each entity's attributes and its historical baseline (the prior-year inherent score and the year-over-year delta) and apply the customer-specific factor weighting where the organization has configured one. Present every score as a proposal with its factor breakdown and citations — never as a verdict: different audit functions weight factors differently, and the chief audit executive owns the final number.\n8. Never overwrite a manually-set inherent score. Where the freshly proposed score differs from the current one, surface the drift for the human to resolve — a suggested change carrying the factor evidence — rather than silently replacing it.\n9. Residual pass — residual equals inherent minus control coverage minus active monitoring plus external red flags. Adjust down for control coverage: count the linked controls that are effective versus partial versus ineffective, giving more credit to controls tested recently. Adjust down for active monitoring: key-risk-indicator status against the risk appetite, plus audit coverage measured by time since last audited and the scope actually covered. Adjust up for external red flags: recent regulatory enforcement or fraud cases in the same domain. For a brand-new entity with no historical data and no linked controls, set residual equal to inherent and flag it \"needs baseline\" instead of inventing an adjustment.\n10. Write the inherent and residual scores back to each area's paired Risk item (mapped onto Risk's four-level `inherent_rating`/`residual_rating`), keeping the 1-to-5 scores and the full six-factor breakdown in the prioritization memo — Risk carries no native numeric or factor fields.\n11. Rank the universe into risk tiers from the residual scores and derive the proposed coverage rhythm: which areas warrant annual coverage, which fit a multi-year rotation, and which are candidates for reliance on other assurance providers (IIA Standard 9.5). Incorporate the changing risk landscape — emerging and top-of-house risks, regulatory developments, and management and board areas of concern — and mark every area where the risk picture has shifted since the prior plan.\n12. Build the risk-ranked universe view and draft the prioritization memo: the inherent and residual scores, the factor breakdowns, the tiering, the proposed coverage rhythm, and the rationale for the highest-priority areas.\n13. Chief audit executive review — the owner of the ranking confirms it is defensible: the factor scoring reflects the real risk picture; the residual adjustments for controls, monitoring, and external red flags are sound; the emerging risks are captured; the coverage rhythm follows the tiers. The CAE resolves every drift between a proposed score and a manually-set score, adjusts any ranking that misreads the risk, and approves the prioritized universe as the input to the strategy and plan.\n\n*Develop the internal audit strategy.* Produce the internal audit strategy — vision, mandate, and multi-year assurance objectives — aligned to organizational objectives and stakeholder expectations and grounded in the documented understanding of governance, risk, and control processes (IIA Standard 9.2), as the frame every plan decision must fit.\n\n14. Draft the strategy's core: the function's vision, mandate, and multi-year assurance objectives. Build the alignment mapping as you write, not after: each assurance objective traces to a named organizational objective or stakeholder expectation from those inputs. An objective that traces to nothing is padding; a stakeholder expectation with no supporting objective is an alignment gap to close or explicitly decline.\n15. Ground the strategy in the documented understanding and the risk-ranked universe so the assurance objectives track the organization's actual risk profile rather than a generic template — the highest residual tiers and the areas marked as shifted should be visible in the strategy's priorities. A strategy that would read the same for any organization fails Standard 9.2's alignment requirement.\n16. Set the operating parameters: the assurance-and-advisory balance (state the intended split of capacity); the coverage horizon (a three-year rolling view is typical); the methodologies and quality expectations the function commits to (Standard 9.3); and the intended use of other assurance providers (Standard 9.5) — name which universe areas the strategy expects to cover through reliance rather than direct engagement.\n17. State how the strategy flexes as the risk landscape changes: the quarterly refresh later in this cycle adjusts the plan; define what magnitude of change reopens the strategy itself — a changed mandate, a transformed business, a new regulatory regime — versus only the plan.\n18. Compile the draft with the alignment mapping and the assumptions it depends on — budget envelope, headcount, technology availability — flagged explicitly, because the resource steps that follow will test them.\n19. Route to the chief audit executive: confirm the strategy is aligned to organizational objectives and stakeholder expectations and grounded in the documented understanding; adjust the mandate, horizon, or assurance balance; approve the strategy as the frame for the plan.\n20. Document the assurance/advisory/administrative capacity mix and calibrate it against the four approved groups: (a) ERM maturity and ERM resourcing; (b) strategic change and current risk environment; (c) strength and reliability of other assurance providers; and (d) board direction and stakeholder expectations. Show the independent-assurance coverage impact of the selected mix.\n\n*Build the risk-based audit plan.* Convert the risk-ranked universe and the strategy into the period's risk-based audit plan (IIA Standard 9.4): a ranked, hour-budgeted, quarter-sequenced engagement schedule in which every inclusion — and every deferral — traces to residual risk and coverage-cycle position.\n\n21. Rank every auditable area for coverage this period with a coverage-priority score combining three signals: the area's residual risk score, the time since it was last audited, and the target coverage cycle — the interval within which an area of its risk tier must be audited at least once, for example a high-risk area every one to two years and a lower-risk area every three or more. Areas whose residual risk is high and whose time since last audit is approaching or past their coverage-cycle interval rank to the top; a useful ordering is residual risk multiplied by time-since-last-audit, weighed against the coverage-cycle target.\n22. Select the period's engagements from that ranking, covering the highest-risk and most-overdue areas first and honoring the coverage rhythm. Record for each: the objective, the auditable area, and the risk basis for its inclusion — its residual score and its time since last audit.\n23. Fit the selection within the total audit hours available: budget each engagement's hours from the size of its auditable area, its residual risk, and the prior year's actual hours for comparable work; sequence the engagements across the quarters to balance team loading rather than clustering effort.\n24. Create one engagement Audit item per selected engagement, linked to its auditable area and its risk ranking, with a proposed quarter, indicative scope, and the estimated hours. Assemble the plan record itself as the plan document backed by the anchor cycle Audit item — there is no native plan type — capturing on it: the period it covers, the total capacity hours, the target coverage cycle in years, the ordered list of planned engagements each carrying its own inclusion rationale, and the board-approval status (approver and approval date, filled once the board signs).\n25. For a multi-year plan, produce a rolling plan: commit the first year firmly and carry the out-years directionally, so the audit committee approves year one firmly and the later years as direction, and the plan re-rolls each cycle.\n26. Confirm the plan covers the audit universe appropriately: no high-risk area is unaddressed across the coverage horizon; every area is scheduled within its coverage cycle; mandatory and regulator-expected coverage is included; and capacity is reserved for advisory work and for unplanned and emerging-risk requests — functions typically hold 10–20 percent of hours unallocated for this.\n27. Draft the plan document: the engagement schedule, the coverage map against the universe, the reserved capacity, and the risk rationale for the selected and the deferred areas — deferrals need documented rationale as much as selections, because they are what the audit committee will probe.\n28. Chief audit executive review: the draft is genuinely risk-based — the ranking reflects residual risk and how overdue each area is against its coverage cycle — covers the universe over the horizon, and leaves room for emerging work. The CAE adjusts the engagement selection and the hour budgets and approves the draft plan to be resourced. Any change to an approved plan is later made as a tracked, rationaled revision, so the plan's change history is preserved.\n\n**Record in AssureSwarm**\nEnrich one Process item per auditable area (create only the genuinely new entities): `process_owner`, `process_type`, and `description` = the governance-risk-control understanding summary carrying its source-inventory reference. Legal entities, applications, and vendors with no process representation have no native universe type — they stay in the uploaded inventory extracts attached to this step.\n- Link each Process to the anchor cycle Audit item (Process ↔ Audit); link the prior Audit items whose history informs the understanding (Process ↔ Audit).\n- Attach the audit-universe memo with the change list as a step document (DOCX); record the CAE approval in the memo — there is no native approval field on the cycle Audit item.\n\nPair each auditable area (its Process item) with a Risk item and update the Risk: `inherent_rating` and `residual_rating` (the four-level scale the two-pass score maps onto), `likelihood`, `impact`, `category`, and `risk_owner` = the CAE. The 1-to-5 scores and the six-factor breakdown have no native numeric fields — they live in the prioritization memo (below); raise proposed-versus-manual drift as suggested changes, never as overwrites.\n- Link each Risk to its area and to the controls the residual adjustments credit (Risk ↔ Process, Risk ↔ Control); last-tested credit reads from the linked Control-hosted SOX testing workflows (cycle from `Workflow.customFields.sox.fiscalYear`; effectiveness from the Test-step conclusion).\n- Attach the prioritization memo with the factor breakdowns and tiering as a step document (XLSX/DOCX); build the risk-ranked universe dashboard; link both to the anchor cycle Audit item.\n\nUpload the strategy as a step document (DOCX/PDF) versioned against the cycle; link it to the anchor cycle Audit item and to the risk-ranked Process/Risk items it draws on.\n- Capture the alignment mapping — each assurance objective against its organizational objective or stakeholder expectation — and the stated assumptions within the strategy document; there is no native strategy or alignment field.\n- Record the assurance/advisory/administrative capacity mix calibrated against (a) ERM maturity and ERM resourcing; (b) strategic change and current risk environment; (c) strength and reliability of other assurance providers; and (d) board direction and stakeholder expectations, together with the independent-assurance coverage impact, in the approved strategy.\n\nCreate one Audit item per selected engagement (status PLANNED, `audit_type` per engagement, `scope` = objective + indicative scope + risk basis, `period_start`/`period_end` = the planned quarter, `lead_auditor`); link each to its area, its risk ranking, and the anchor cycle (engagement Audit ↔ Process, ↔ Risk, ↔ cycle Audit). These engagement Audit items ARE the plan and the downstream handoff.\n- There is no native plan-record type: capture the plan-level fields (period covered, total capacity hours, target coverage-cycle years, ordered engagement list with inclusion rationale, board-approval status) in the plan document, with the eventual approval date approximated by the cycle Audit's `report_date`.\n- Attach the plan document with the engagement schedule, the coverage map, the reserved capacity, and the deferred-area rationale as a step document (XLSX/DOCX).\n\n**Exit criteria**\nEvery source-inventory row maps to a universe entity or a documented exclusion; each entity carries an owner and a current documented understanding; the change list is complete with reasons; the CAE approval is recorded.\n\nEvery entity carries both scores with the six-factor breakdown, or an explicit \"needs baseline\" flag; no manually-set score was overwritten and every drift is resolved by the CAE; tiers and coverage rhythm approved; the memo and dashboard exist and are linked to the cycle.\n\nThe assurance/advisory/administrative capacity mix is explicitly calibrated against (a) ERM maturity and ERM resourcing; (b) strategic change and current risk environment; (c) strength and reliability of other assurance providers; and (d) board direction and stakeholder expectations, and its independent-assurance coverage impact is explicit. — Strategy approved by the CAE; every assurance objective traces in the mapping and every stakeholder expectation is addressed or explicitly declined; operating parameters and assumptions stated; the document is linked to the cycle.\n\nEvery selected engagement carries objective, quarter, estimated hours, and its risk basis; total budgeted hours fit capacity with the emerging-work reserve held; the coverage confirmation is documented — no uncovered high-risk area, cycles honored, mandatory coverage included; deferrals are rationaled; CAE approval to resource is recorded.","label":"Develop the internal audit strategy","performedBy":{"agent":"audit-artist","note":"Two-pass inherent-then-residual risk scoring Build risk-based audit plan","primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload","coach-dashboard-create","coach-item-update"]},"roleIntegrity":{"decisionOwner":"Chief Audit Executive","ermPhase":"manage","independenceRequired":false,"lineRole":"third","serviceMode":"advisory"}},"id":"develop-audit-strategy"},{"data":{"decisionField":"resource_sufficiency","description":"Agent builds the budget, staffing, and audit-technology plan and reconciles it against the plan demand; the chief audit executive decides whether resources are sufficient or the plan is constrained","formData":{"fields":[{"key":"resource_sufficiency","label":"Assess resource sufficiency against the plan","options":[{"label":"Sufficient - resources deliver the plan","value":"sufficient"},{"label":"Constrained - resource shortfall limits coverage","value":"constrained"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Build the budget, staffing, and audit-technology plan that can actually deliver the risk-based plan (IIA Standards 10.1–10.3) and put the chief audit executive's call on whether those resources are sufficient — the gate on which IIA Standards 9.4 and 10.1 hang the duty to communicate the effect of resource limitations to the board and senior management.\n\n**Inputs**\n- The draft plan: the engagement list with estimated hours, indicative scope, and quarters.\n- The staffing roster and skills inventory, utilization history, attrition, and open requisitions.\n- The current budget baseline, co-source rate cards, and existing specialist arrangements.\n- The audit technology inventory — data-analytics, working-paper, and other tooling — with renewal dates and costs.\n\n**Procedure**\n\n_Items 1–6 are agent-run (folded from the former \"Build budget, staffing, and technology plan\" step); the human moment is the sufficiency decision below._\n\n1. Estimate demand per engagement: hours by competency — core audit, IT audit, data analytics, fraud, and whatever specialist skills the scopes call for — then aggregate into the total budget, headcount, competency mix, and audit-technology needs of the plan.\n2. Convert headcount into real capacity: productive engagement hours per auditor net of administration, training, and leave. Plan at realistic utilization — roughly 70–80 percent of paid hours, on the order of 1,400–1,600 engagement hours per FTE-year — not the 2,080-hour fiction. Capacity overstated here resurfaces later as blown hour budgets and quietly cut scopes.\n3. Build the budget across its real lines (Standard 10.1): internal cost, co-source and external specialist spend, training, and technology. Build the staffing plan (Standard 10.2): recruitment, development, and deployment of qualified personnel against the competencies the plan demands, with lead times — a hire that lands after the engagement's quarter does not resource it.\n4. Build the audit-technology plan (Standard 10.3): the data-analytics, working-paper, and other tooling that supports the audit process, with the acquisition or renewal actions and their costs.\n5. Map available capacity against the plan's demand by quarter and by competency; flag every gap — hours, skills, or tooling — with the specific engagements it touches. Capture the budget, staffing, and technology needs as line items in the resource plan, each tied to the engagement Audit items they serve — there is no native resource item type (see Record in AssureSwarm).\n6. Assemble the resource plan and its reconciliation: the budget request, the staffing and recruitment plan, the technology plan, the demand-versus-capacity view with its stated utilization assumption, and the quantified shortfall list — total available and budgeted hours against required hours, the competency mix against the skills the engagements need, the technology in hand against what the plan assumes — plus the coverage model showing the coverage the resources can actually deliver against the coverage the risk-based plan calls for, marking the high-risk areas that would go uncovered if the shortfall stands.\n7. The chief audit executive tests that reconciliation and selects the branch below. Adjustments to the resource plan the CAE makes at this point are recorded here; the plan carries no separate confirmation step.\n\n**Decision criteria**\n\nGround the decision in the quantitative reconciliation above, and quantify every shortfall by the engagements it puts at risk — which cannot be delivered within budget, which competencies cannot be sourced in time, which technology gaps would limit coverage.\n\n- **Sufficient (`sufficient`)** — capacity meets or exceeds required hours with the emerging-work reserve intact; every demanded competency is on the roster or covered by a funded co-source or hire that lands before the engagement's quarter; the technology assumptions hold; and any residual gaps are minor and sourceable within existing authority without cutting or deferring high-risk coverage. Timing frictions that quarter re-sequencing absorbs do not make a plan constrained.\n- **Constrained (`constrained`)** — any shortfall that would force high-risk coverage to be cut, deferred past its coverage cycle, or materially descoped: an hours deficit beyond what re-sequencing absorbs, a competency the function lacks and cannot source in time, or a technology gap that limits planned coverage. Constrained routes the cycle through the reconciliation step, where the trade-offs are worked and the mandatory constraint communication is drafted. Do not soften a real shortfall into sufficient to avoid that conversation — an understated constraint silently transfers the risk of uncovered areas to the organization, which is exactly what the communication duty exists to prevent.\n\n**Record in AssureSwarm**\n- Submit the decision form: `resource_sufficiency` (the branch), the step result citing the demand-versus-capacity numbers and the specific coverage each shortfall would sacrifice, and the step's approver record — the chief audit executive.\n- There are no native budget, staffing, or technology item types: carry the budget lines, the staffing/recruitment plan, and the technology plan as line items inside the resource plan document, each referenced to the engagement Audit items they serve.\n- Attach as step documents: the resource plan (XLSX/DOCX) and the sufficiency assessment with the reconciliation, the shortfall list, and the coverage model (XLSX). Record the demand-versus-capacity view and the stated utilization assumption in the resource plan and summarize them on the anchor cycle Audit's `description` — there is no native resource-plan field.\n\n**Exit criteria** — Every engagement's hours-and-skills demand maps to named capacity or a flagged gap; the budget covers internal, co-source, training, and technology lines; the utilization assumption is stated; the form is submitted by the CAE with a quantified rationale; the resource plan and sufficiency assessment are attached; the branch not selected is prunable.","kind":"decision","label":"Assess resource sufficiency against the plan","performedBy":{"primitives":["coach-query-data","coach-dashboard-create","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"assess-resource-sufficiency"},{"data":{"description":"Agent works the resource shortfall into a revised coverage decision and drafts the constraint communication for senior management and the board; human approves the revised coverage and the communication","instructions":"**Objective** — Turn the resource shortfall into a deliberate, approved coverage position and the board-ready statement of what the constraints sacrifice — the communication of the effect of resource limitations that IIA Standards 9.4 and 10.1 make mandatory, not optional.\n\n**Inputs**\n- The sufficiency assessment: the quantified shortfalls and the engagements each puts at risk.\n- The draft plan and engagement items, the coverage map, and the risk ranking.\n- Option data: co-source rates and availability, recruiting lead times, technology quotes, and the limits of the CAE's budget authority.\n\n**Procedure**\n1. Work the options for each constraint: request additional budget or headcount; co-source or engage external specialists; acquire the missing technology; or re-scope and defer engagements. Estimate for each option the coverage it preserves, its cost, and its lead time — an option that lands after the affected engagement's quarter is not an option.\n2. Where the shortfall cannot be fully closed, decide the coverage trade-offs from the risk ranking: defer or descope lower-risk engagements so the highest-risk areas stay covered. Never thin a high-risk engagement's scope silently to make the numbers fit — a documented deferral of a low-risk area is defensible; an invisible haircut on a high-risk one is how coverage failures become surprises.\n3. Revise the plan and engagement items to fit the resource envelope: updated quarters, scopes, and hours, each change carrying its rationale.\n4. Draft the constraint communication for senior management and the board: the resources requested versus available, the specific coverage impact of the shortfall, the high-risk areas affected, and the chief audit executive's recommendation. It travels to the board with the plan — the board approves coverage knowing what it is not getting, rather than discovering it at year end.\n5. Update the plan, resource, and engagement items to the reconciled position; record the residual coverage gap and every resource request still awaiting a decision.\n6. Approval: the chief audit executive and senior management approve the reconciled coverage and the resource requests, confirm the coverage-impact communication fairly states what the constraints sacrifice, and clear it to go to the board with the plan.\n\n**Record in AssureSwarm**\n- Update the affected engagement Audit items to the reconciled position — `period_start`/`period_end` re-quartered, `scope` descoped/deferred with the rationale in the scope text; revise the plan and resource documents to match, since there are no native plan/resource items.\n- Upload the constraint communication as a step document (DOCX/PDF) and link it to the affected engagement Audit items.\n- Record the residual coverage gap and the pending resource requests on the anchor cycle Audit's `description` and in the reconciliation document.\n\n**Exit criteria** — The revised plan fits the resource envelope; every deferral and descope carries rationale tied to the risk ranking; the constraint communication is approved and linked to the engagements it affects; residual gaps and pending requests are explicit on the record.","label":"Reconcile constraints and coverage impact","performedBy":{"primitives":["coach-document-upload","coach-item-create","coach-items-link","coach-item-update"]}},"id":"reconcile-constraints-and-coverage"},{"data":{"description":"Agent packages the strategy, risk-based plan, resource plan, and any constraint communication for the board or audit committee and captures the approval; human records the board's approval","instructions":"**Objective** — Put the strategy, the risk-based plan, and the resource plan before the board or audit committee with an honest view of what the resources will and will not cover, and capture the approval as the cycle's authoritative, dated evidence — board approval of the plan and its resourcing is what gives the plan its mandate (IIA Standards 8.2 and 9.4).\n\n**Inputs**\n- The approved internal audit strategy; the risk-based plan with its coverage map; the budget, staffing, and technology plan; the resource-sufficiency assessment.\n- The constraint communication, where the constrained branch ran.\n- The board or audit-committee calendar and materials deadline; the prior-year approval record as precedent for format and depth.\n\n**Procedure**\n1. Assemble the approval pack: the strategy, the plan with its coverage map, the resource plan, the sufficiency assessment, and — where the plan is resource-constrained — the constraint communication. Lead with the risk basis: the highest tiers, what the plan covers, what it defers and why.\n2. Present the plan's risk basis and coverage, the resources required to deliver it, and the coverage impact of any resource limitation, so the board approves with a clear view of what the resources will and will not cover — an engagement list without the deferral story is approval theater. For a rolling plan, ask for firm approval of year one and directional endorsement of the out-years.\n3. Capture the board's decision precisely: approval of the strategy, the plan, and the budget, together with any conditions, requested changes, or additional coverage the board directs. Revise the plan and resource items to reflect exactly what was approved — an unrecorded verbal condition is a finding waiting for the next external quality assessment.\n4. Record the board-approval artifact — the minutes or approval memo, the approved plan version, and the date — and link it to the plan, the strategy, and the resource plan as the authoritative approval evidence. Record the approval date on the anchor cycle Audit's `report_date` and name the approver in the artifact, since there are no native approver/approval-date fields.\n5. The chief audit executive confirms the approval is complete before the cycle moves to the refresh cadence: strategy, plan, and resources approved; board-directed changes reflected; the approval captured as a dated, retained record.\n\n**Record in AssureSwarm**\n- Upload the board-approval artifact (minutes/memo plus the approved plan version) as a step document (PDF) and link it to the anchor cycle Audit item and to the strategy, plan, and resource-plan documents.\n- Record the approval date as the cycle Audit's `report_date` and name the approver in the artifact (no native approver/approval-date fields); apply board-directed changes to the plan document and the engagement Audit items as tracked revisions.\n\n**Exit criteria** — A dated board-approval artifact is linked to the approved plan version; every board condition or directed change is reflected in the items; the plan record shows approver and date; the approved plan is the version the refresh cadence will monitor.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles the board pack — strategy, plan with coverage map, resource plan, sufficiency assessment, and any constraint communication — from the linked cycle records into one presentable package.","label":"Obtain board approval","performedBy":{"primitives":["coach-document-upload","coach-items-link","coach-render-package"]}},"id":"obtain-board-approval"},{"data":{"decisionField":"refresh_outcome","description":"Agent monitors the risk landscape and resource sufficiency on the defined cadence; ERM maturity, provider reliability, expanded remit, or risk-context changes trigger a refresh that records the independent-assurance coverage impact before the CAE decides whether adjustment is warranted.","formData":{"fields":[{"key":"refresh_outcome","label":"Run the quarterly refresh checkpoint","options":[{"label":"On track - no adjustment needed","value":"plan_on_track"},{"label":"Adjustment required","value":"adjustment_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — The chief audit executive's quarterly call on whether the approved plan and its resourcing still fit the risk landscape — IIA Standard 9.4's requirement that the plan stay current, exercised on a defined cadence rather than when someone remembers.\n\n**Decision criteria**\n\nBase the call on the refresh scan this checkpoint runs on cadence: the status of the plan's engagements against schedule; the risk landscape re-pulled — new and escalating risks, regulatory developments, organizational changes, and board or management concerns since the plan was approved; and resource sufficiency against the remaining plan — actual hours and spend against budget, staffing and competency changes, attrition and recruitment progress, and whether the technology in place is still adequate. Compare the current picture against the approved plan and flag the drift: high-risk areas that have emerged or receded, engagements at risk of slipping, and resource shortfalls or surpluses that change what can be delivered.\n\n- **On track (`plan_on_track`)** — engagements are tracking schedule within normal tolerance; no new or escalated risk changes the tiering or demands coverage beyond what the emerging-work reserve absorbs; actual hours and spend are within tolerance of budget (a working threshold: within about 10 percent with no adverse trend); staffing changes and attrition are absorbed; the technology remains adequate. Record the affirmative evidence — \"nothing changed\" is a conclusion that needs support, not a default.\n- **Adjustment required (`adjustment_required`)** — any one of these suffices: a new or escalated risk with no planned coverage; a high-risk engagement slipping past its coverage-cycle interval; an hours or spend overrun that will force descoping; attrition or a competency loss that unfunds planned engagements; a regulatory development or a board or management concern demanding coverage this period; or a resource surplus large enough to pull deferred high-risk work forward. Name the specific drift — the adjustment step executes from that list.\n**Role-integrity triggers**\n- Trigger the refresh when ERM maturity, provider reliability, expanded remit, or risk-context changes alter the basis for coverage. For each trigger, record the independent-assurance coverage impact before selecting the branch.\n\n**Record in AssureSwarm**\n- Submit the decision form: `refresh_outcome` (the branch), the step result citing the specific drift or the affirmative on-track evidence, and the step's approver record — the chief audit executive.\n- Attach the quarterly refresh summary — the risk-landscape changes, the resource-sufficiency reassessment, and the recommendation — as a step document (DOCX) on this step.\n- Record the trigger factors and the independent-assurance coverage impact in the quarterly refresh summary.\n\n**Exit criteria** — The form is submitted on the quarter's cadence with the refresh summary attached; where adjustment is required, the drift items are named; the branch not selected is prunable; trigger factors and the independent-assurance coverage impact are recorded.","kind":"decision","label":"Run the quarterly refresh checkpoint","performedBy":{"primitives":["coach-query-data","coach-workflow-scan"]},"roleIntegrity":{"decisionOwner":"Chief Audit Executive","ermPhase":"monitor","independenceRequired":false,"lineRole":"third","serviceMode":"advisory"}},"id":"establish-quarterly-refresh"},{"data":{"description":"Agent revises the plan and resources for ERM maturity, provider reliability, expanded remit, or risk-context changes; it records the independent-assurance coverage impact and routes the adjustment for the required approval.","instructions":"**Objective** — Apply the quarter's plan and resource adjustment as a versioned, approved, and communicated change, so coverage tracks the current risk landscape without the plan losing its change history or skipping the coverage-impact communication.\n\n**Inputs**\n- The refresh summary and decision rationale: the specific drift driving the adjustment.\n- The approved plan version and its engagement items; the resource plan with remaining budget and capacity.\n- The plan's change-tolerance policy: what the chief audit executive may approve alone versus what is material enough for the board.\n\n**Procedure**\n1. Revise the risk-based plan for the change the refresh identified: add, reprioritize, defer, or drop engagements so coverage tracks the current risk landscape, and update the affected engagement items with the new priority and timing, each carrying the reason for the change.\n2. Reassess and adjust the resources to match: reallocate hours, redirect budget, adjust the co-source or recruitment plan, and record any technology change needed to deliver the revised plan. An adjustment that changes engagements but not their resourcing is only half done.\n3. Where the adjustment changes coverage or is driven by a resource constraint, draft the coverage-impact communication for senior management and the board on the required cadence: what changed, why, and what coverage is affected. Standard 9.4 treats significant plan changes and the effect of resource limitations as items to communicate, not internal notes.\n4. Capture the approval at the right level: the chief audit executive's authority within the plan's change tolerance; the board's approval where the change is material. A working materiality test: dropping or adding an engagement in a high-risk tier, moving a significant share of the period's hours, or exceeding the approved budget.\n5. Version the plan so the change history is preserved: the approved baseline stays retrievable next to the revision, the adjustment record links to the affected engagements, and the change is a tracked, rationaled revision — never an in-place overwrite.\n6. The chief audit executive approves the plan and resource adjustment, confirms the coverage-impact communication is accurate and issued on cadence, and confirms the change is recorded against the approved plan before the cycle closes.\n7. Trigger and document the adjustment when ERM maturity, provider reliability, expanded remit, or risk-context changes alter planned coverage; state the independent-assurance coverage impact before approval.\n\n**Record in AssureSwarm**\n- Update the affected engagement Audit items with the new timing (`period_start`/`period_end`) and the reason in the `scope` text; capture the adjustment record as a step document (DOCX/XLSX) and link it to those engagement Audit items.\n- Upload the coverage-impact communication as a step document (DOCX); record the new plan version and its approval (CAE or board) in the adjustment/plan documents — the baseline plan document on the earlier steps stays retrievable, since there is no native plan-version field.\n- Record the trigger factors and the independent-assurance coverage impact in the adjustment record and coverage communication.\n\n**Exit criteria** — The plan is re-versioned with the approved baseline preserved; every changed engagement carries its rationale; approval is captured at the level the change tolerance requires; the communication is issued where coverage changed or a constraint drove the change; trigger factors and the independent-assurance coverage impact are recorded.","label":"Log the plan and resource adjustment","performedBy":{"primitives":["coach-item-create","coach-document-upload","coach-items-link","coach-item-update"]},"roleIntegrity":{"decisionOwner":"Chief Audit Executive","ermPhase":"manage","independenceRequired":false,"lineRole":"third","serviceMode":"advisory"}},"id":"log-plan-adjustment"},{"data":{"description":"Automatically retain the approved planning record, carry forward unresolved items and distribute the authorized plan.","instructions":"**Objective** — Close the planning cycle with a self-contained archive that evidences every planning and resourcing decision — strategy, plan, approvals — and a clean carry-forward, so the next cycle starts with explicit inputs and the record outlives staff turnover.\n\n**Inputs**\n- The full cycle trail: the cycle record and its scope; the refreshed audit universe with its documented understanding; the risk assessment and prioritization; the internal audit strategy; the risk-based plan with its coverage map; the budget, staffing, and technology plan; the resource-sufficiency assessment; the constraint communication where the constrained branch ran; the board-approval artifact; and the quarterly refresh summaries with any adjustment records.\n- The records-retention schedule for audit planning records.\n- The next cycle's intake in the audit planning register.\n\n**Procedure**\n1. Verify completeness against that checklist: every artifact present, linked, and final-versioned. The working test: could an external quality assessor reconstruct from the archive alone why each engagement was or was not planned, and what the board approved — without oral explanation?\n2. Retain the strategy, the plan, and the board approvals as the authoritative record; archive the full cycle file to the audit records repository; set the retention period the planning-records schedule requires (seven years is a common floor; longer where a regulator says so) so the strategy, plan, and approvals stay retrievable as evidence. Verify retrievability by opening the archived copy, not by trusting the upload confirmation.\n3. Carry forward into the next cycle's intake, each item with its owner and due date intact: deferred and descoped engagements — next cycle's coverage-priority inputs; unresolved resource requests and recruitment actions; technology acquisitions in flight; and the scheduled quarterly refresh checkpoints.\n4. Mark the cycle closed in the audit planning register with the archive references and the closure timestamp. Notify the board or audit committee, executive management, and the audit team of the approved plan and the resource commitments — the approved engagement list is what triggers each engagement's own planning workflow, and a plan nobody was told about steers nothing.\n5. After the preceding authorized decision, check the archive and carry-forward against the approved package and record completion automatically. Escalate a missing artifact to its existing owner without adding a separate closure approval.\n\n**Record in AssureSwarm**\n- Export the complete cycle workflow instance and attach it with the archive references (workflow export plus document upload) as the self-contained cycle file.\n- Carry forward the deferred/descoped engagements as their Audit items left in PLANNED for the next cycle, plus a carry-forward note document capturing unresolved resource requests, recruitment actions, and technology-in-flight with owners and due dates; mark the anchor cycle Audit item closed (status COMPLETE) with the closure timestamp.\n- Log the approved-plan notification to the board, executive management, and the audit team as a step document; the approved engagement Audit items are the handoff that triggers each engagement's own audit engagement planning workflow.\n\n**Exit criteria** — The completeness checklist passes; the archive is stored, retrievable, and under retention; every open thread exists as a carry-forward item with owner and due date; the cycle is marked closed with the archive reference; the notification is issued.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-export` exports the full planning-cycle record — every step, decision, and attachment — as the self-contained archive file; `/coach-notify` distributes the approved plan and resource commitments to the board, management, and the audit team with a logged trail.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-document-upload","coach-notify"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:audit-annual-internal-audit-planning-resource-management"}
