Internal audit · Method · Prioritisation
The risk-based approach: auditing where the real stakes lie
You can't audit everything, all the time. The risk-based approach responds to this reality: focusing internal audit resources where the stakes are highest for the organisation. A simple principle, with very practical implications for the board and management.
Why not audit everything in the same way
Audit resources are limited; risks are not all equal. Giving the same attention to a low-stakes process as to a risk capable of threatening the business is a waste of scarce effort — and, often, leaves the most critical areas under-covered. The risk-based approach starts from a commonsense observation: it is better to thoroughly address the few subjects that truly matter than to skim over the whole lot.
How does it actually work
The approach follows a clear logic. Risks are identified and assessed — by cross-referencing their probability and potential impact. They are prioritised. An audit plan is built that primarily targets the most significant ones. Then, this plan is adjusted as soon as the landscape changes.
Corporate risks, not just isolated processes
The modern approach goes further than a simple list of services to be reviewed in turn. It starts from the most significant risks for the company as a whole — including emerging and cross-functional risks that do not correspond to any particular department: a cyberattack, a dependency on a critical supplier, a transformation project. It is often these risks, which cut across the organisation, that deserve the most attention.
The role of the board: challenging the plan
This is where the board or the audit committee steps in. The risk-based audit plan is submitted to it for validation — and this is not just a formality. Two questions are often enough to test its robustness: are our most significant risks properly covered? And is the plan readjusted when these risks evolve? A plan that never changes in a fast-moving environment should ring alarm bells.
ARCAD helps you map your risks and draw up a targeted and scalable audit plan.
References & further reading
- Global Internal Audit Standards, Institute of Internal Auditors (IIA), 2024 — risk-based internal audit plan.
- Report Risk in Focus 2026, European Confederation of Institutes of Internal Auditing (ECIIA).