Filled

Jump to a Section

Filled

SHARE THIS ARTICLE

Shape

Copy Link

Filled

Subscribe to CrossCheck

Get news from CrossCheck in your inbox.

Building a Risk-Based Audit Plan: Focusing Internal Audit Where It Matters Most

For financial institutions, there is rarely a shortage of areas that could be audited. The challenge is determining which areas should be audited, and how frequently.

A well-designed risk-based audit plan helps answer that question. Rather than treating the audit plan as a calendar of recurring reviews, a risk-based approach connects audit coverage to the institution’s current risk profile, strategic direction, control environment, and emerging concerns. The result should be a plan that directs limited audit resources toward the areas where independent assurance can provide the greatest value.

Federal banking regulators operate under risk-focused supervisory models and expect internal audit functions at financial institutions to do the same. The Consumer Financial Protection Bureau’s (CFPB) examination procedures for an institution’s compliance management system call for examiners to evaluate whether the audit plan coverage is commensurate with the institution’s size, complexity, and risk profile. Examiners will also assess the quality and depth of analysis used to develop the risk-based audit plan.

Start with the Audit Universe

Effective planning begins by understanding what can be audited. The audit universe should capture the institution’s significant businesses, products, processes, systems, legal entities, and risk management functions.

For a financial institution, that may include lending, deposits, operations, finance, information technology, cybersecurity, compliance, Bank Secrecy Act (BSA)/Anti-Money Laundering (AML)/Countering the Financing of Terrorism (CFT), third-party risk management, human resources, model risk, and other key areas.

The audit universe should evolve as the institution evolves. New products, acquisitions, system conversions, organizational changes, use of artificial intelligence, fintech relationships, changes in delivery channels, and significant regulatory developments can all introduce risks that may not have existed previously, or may not have been significant when the prior audit plan was developed.

This is why risk assessment should be more than an annual administrative exercise. Regulators, including the CFPB, expect risk assessments to be updated to reflect recent changes, such as those made to internal controls, work processes, and new lines of business.

Assess Risk

Once the audit universe is established, institutions typically assess the relative risk of each area. Factors may include regulatory requirements, financial exposure, transaction volume, complexity, degree of change, prior audit results, management concerns, and the length of time since the last audit. These factors can then be used to assess the inherent risk for each area, which is the risk faced prior to considering any established controls. The effectiveness of controls mitigating the inherent risks can then be assessed to help determine the overall level of residual risk faced from each area.  Many institutions translate these factors into a numerical score and classify areas as high, moderate, or low risk.

However, the numerical score should not be a replacement for sound auditor judgment. For example, it is possible for the score of an area to remain steady over time, when further auditor judgment could determine that the level of risk faced from the area has increased due to recent material changes to procedures, recent changes in key management, or recent internally detected control issues.

Look Forward, Not Just Backward

One of the most common weaknesses in audit planning is overreliance on historical information. Prior findings, loss history, examination results, and previous audit ratings are important, but they primarily tell you where risk has been. The audit plan also needs to consider where risk is going.

That means talking with senior management and business leaders about strategic initiatives, growth plans, technology changes, staffing challenges, new products, third-party relationships, regulatory developments, and areas where management itself may be concerned about controls.

Emerging risks should be considered to ensure that the risk assessment incorporates these risks as the financial institution and industry evolves.  Regulators expect that emerging risks are considered as part of maintaining the audit universe and developing the audit plan. More broadly, looking beyond historical results is simply sound risk management. Risk assessments should consider whether risks are stable, increasing, or decreasing.

Connect Risk to Audit Frequency and Scope

Once risks have been assessed, the institution can determine the appropriate audit response. Higher-risk areas generally warrant more frequent or more extensive coverage, while lower-risk areas may justify longer audit cycles or more targeted reviews.

But frequency is only one lever.

Risk should also influence scope, timing, sample sizes, expertise, and audit hours. An area undergoing substantial change may require a focused audit shortly after implementation rather than waiting for its normal audit cycle. A technically complex area may require specialized resources. An area with strong controls and consistently favorable results may warrant a narrower scope.

Regulatory guidance recognizes both multi-year planning and approaches that reassess risks annually (or more frequently if warranted), while emphasizing appropriate coverage based on the institution’s size and complexity.

Make the Audit Plan Dynamic

An annual audit plan should not become obsolete the moment the audit committee approves it.

Risk changes throughout the year. A significant acquisition, cybersecurity event, regulatory development, control failure, new product, system conversion, or unexpected management turnover may justify reconsidering planned coverage.

Internal audit should have a process for periodically evaluating whether the assumptions underlying the risk assessment remain valid. When risk changes materially, the audit plan may need to change with it.

From an Audit Schedule to a Risk Management Tool

The ultimate objective of risk-based audit planning is not to demonstrate that every area has been placed on a three-year cycle or that last year’s audits have simply been moved forward another year. It is to provide the board of directors and management with meaningful independent assurance over the risks that matter most.

The best audit plans therefore answer more than “What are we auditing this year?”

They also answer “Why are we auditing it now?”

Contact CrossCheck to assess whether your audit plan is appropriately aligned to your institution’s evolving risk profile, strategic priorities, and regulatory environment.

Authored by Jim Treacy

 

Learn More

About CrossCheck

CrossCheck is a consulting firm that empowers companies in the financial industry to solve their most pressing compliance, risk management, and internal audit challenges.

crosscheck logomark classic building with columns

Related Resources