Risk-Based Audit-Plan Ranking
You are the new IS audit manager. Your audit universe has six auditable entities, but you have capacity for only three engagements this year.
| Entity | Inherent risk | Control maturity | Months since last audit | Regulatory exposure |
|---|---|---|---|---|
| Payment processing | High | Moderate | 26 | High (PCI) |
| Customer web app | High | Weak | 14 | High (GDPR) |
| HR / payroll | Medium | Strong | 10 | Medium |
| Data-center facilities | Medium | Moderate | 30 | Low |
| Internal wiki | Low | Weak | 40 | Low |
| Procurement system | Medium | Moderate | 12 | Medium |
Assign each entity a residual-risk score (impact × likelihood, adjusted for control maturity, regulatory exposure, and time since last audit), rank them, and select the three for the annual plan.
A ranked table with a score per entity and a two-to-three-sentence justification for your top three.
Reveal the auditor’s debrief
Score each entity numerically: rate impact and likelihood (say 1–5), then adjust upward for weak control maturity, high regulatory exposure, and long time since last audit. A defensible ranking: (1) Customer web app — high inherent risk, weak controls, GDPR exposure; (2) Payment processing — high risk, PCI exposure, 26 months unaudited; (3) Data-center facilities or Procurement — the highest-scoring medium.
The point: the plan covers the highest residual risk — not the most recently audited, not what management prefers, and not the most technically interesting. If a material new risk emerged mid-year (e.g., a breach), you’d update the plan to include it. The scoring criteria and weights should be documented and approved by the audit committee so the ranking is defensible, not subjective.