An internal audit plan should be able to answer a simple question:
Why are we auditing these areas, and why now?
If the answer is simply “because they were on last year’s plan”, “because every department gets audited every three years” or “because management asked us to”, the plan may be organised, but it is not necessarily risk-based.
A well-structured audit universe gives internal audit a clearer starting point. It creates a view of the areas that could require assurance, connects them with the organisation’s objectives and risks, and helps auditors decide where limited time and resources will provide the greatest value.
But an audit universe should not become another static spreadsheet.
The purpose is not to create the longest possible list of auditable areas. It is to create enough structure to make better audit planning decisions.
What is an audit universe?
An audit universe is a structured view of the areas within an organisation that could potentially be subject to internal audit activity.
Depending on the organisation, those auditable areas might include:
- business units
- operational processes
- systems and applications
- programmes and projects
- legal entities
- locations
- regulatory obligations
- strategic initiatives
- significant third parties
- cross-functional activities such as cybersecurity, procurement or data governance
The Institute of Internal Auditors describes an audit universe as one approach to organising potentially auditable units so risks can be identified and assessed more systematically. It notes that the universe is most useful when it reflects the organisation’s objectives and strategic initiatives and aligns with its structure or risk framework.
That last point matters.
An audit universe is not simply an organisational chart converted into a spreadsheet.
It should help internal audit understand where important objectives, risks, controls and assurance needs sit across the organisation.
Is an audit universe required by the IIA Standards?
Not specifically.
Under Standard 9.4: Internal Audit Plan of the Global Internal Audit Standards, the chief audit executive must create an internal audit plan that supports the achievement of the organisation’s objectives.
The plan must be based on a documented assessment of the organisation’s strategies, objectives and risks. That assessment must be performed at least annually and informed by input from the board and senior management, together with internal audit’s understanding of governance, risk management and control processes. The plan should also remain dynamic as the organisation and its risks change.
An audit universe is therefore a planning tool, rather than the objective itself.
Used properly, it can provide the structure needed to demonstrate how internal audit moved from:
Objectives → Risks → Auditable areas → Priorities → Audit plan
That is much more useful than maintaining a list simply to show that every department eventually receives an audit.
Audit universe vs internal audit plan: what is the difference?
The terms are related, but they are not interchangeable.
The audit universe represents what could be considered for audit.
The internal audit plan represents what internal audit has decided to address during a particular period.
For example, an audit universe might contain 80 auditable areas. Internal audit may only have the capacity to perform 15 engagements during the year.
The important question is therefore not:
“Have we audited everything?”
It is:
“Have we directed our available assurance resources towards the areas that matter most?”
That is where risk-based audit planning begins.
Step 1: Start with organisational objectives
A common mistake is to begin by listing departments.
Finance. HR. IT. Operations. Procurement.
That creates an organisational inventory, but it does not automatically create a useful audit universe.
Start instead with what the organisation is trying to achieve.
Review:
- strategic objectives
- business plans
- major transformation programmes
- regulatory commitments
- key products and services
- critical operational processes
- significant technology
- major dependencies and third parties
Then consider what could prevent those objectives from being achieved.
The IIA’s latest guidance on risk-based internal audit planning emphasises the need to align internal audit priorities with organisational strategies, objectives and significant risks.
This changes the planning conversation.
Instead of asking:
“Which department has not been audited recently?”
internal audit can ask:
“Where could failure have the greatest effect on what the organisation is trying to achieve?”
That is a much stronger basis for assurance.
Step 2: Define auditable units at a useful level
Once the organisation is understood, determine what should actually appear in the audit universe.
An auditable unit needs to be specific enough to assess, but not so detailed that the universe becomes impossible to maintain.
For example, “Technology” may be too broad.
But creating a separate auditable unit for every individual server, application and technical control may be too granular.
A more useful structure might include:
| Auditable area | Possible scope |
|---|---|
| Identity and access management | User access, privileged access, joiners/movers/leavers |
| Cybersecurity | Security governance, threat management, incident response |
| Business continuity | BCP governance, testing, recovery capability |
| Third-party management | Due diligence, onboarding, monitoring and termination |
| Payroll | Payroll processing, access, approvals and reconciliations |
| Data protection | Governance, processing activities, DPIAs and data rights |
| Major transformation programme | Governance, delivery risk, benefits and change control |
The right level will depend on the organisation.
A smaller organisation may only need a relatively compact universe. A complex multinational or public-sector body may need multiple levels of hierarchy.
What matters is whether the structure helps internal audit understand and prioritise assurance needs.
Step 3: Capture enough information to make each entry useful
A list of names is not yet a risk-based audit universe.
Each auditable area needs enough context to help internal audit make a planning decision.
Useful fields might include:
- auditable area
- description and scope
- responsible business owner
- linked organisational objectives
- linked strategic or operational risks
- regulatory significance
- financial or operational materiality
- relevant systems
- critical third parties
- known control concerns
- recent incidents or losses
- significant organisational change
- date of last audit
- previous audit result
- outstanding audit actions
- other assurance providers
- current risk assessment
- proposed audit priority
Not every organisation will need every field.
The aim is to capture the information that explains why an area may or may not require internal audit attention.
Step 4: Connect the audit universe to risks
This is where the universe becomes much more powerful.
Each significant auditable area should be considered against the risks that could affect it — and the risks it could create for the organisation.
Suppose the organisation has a strategic objective to increase digital sales.
That objective may depend on:
Digital growth objective
↓
E-commerce platform
↓
Cybersecurity risk
↓
Customer-data risk
↓
Payment-processing risk
↓
Third-party hosting risk
↓
Business continuity risk
A traditional audit universe might list “E-commerce” or “IT”.
A connected audit universe shows why the area matters.
It also prevents audit planning from becoming too siloed.
One enterprise risk may cross several business areas, while one business process may contribute to several risks.
Internal audit needs to be able to see both.
Step 5: Assess risk — but do not let a score make the decision for you
A risk rating can help prioritise the audit universe, but it should not replace professional judgement.
A simple model might assess factors such as:
- impact
- likelihood
- regulatory exposure
- financial materiality
- pace of change
- control maturity
- fraud susceptibility
- previous audit findings
- management concern
- incident history
- time since previous assurance
- strategic importance
The resulting score can help highlight priorities.
But consider two areas:
Area A: High inherent risk, mature controls, independently reviewed recently and no significant changes.
Area B: Moderately high risk, rapidly changing technology, several unresolved incidents and no independent assurance for three years.
A simple risk score might put Area A first.
A stronger audit planning process might decide that Area B currently needs more attention.
This is why an audit universe should support judgement rather than automate it away.
Risk ratings help structure the discussion. They should not end it.
Step 6: Look at existing assurance before adding another audit
Risk is only one part of the planning decision.
Internal audit also needs to understand who else is already providing assurance.
That may include:
- compliance
- risk management
- information security
- quality teams
- health and safety
- external audit
- regulators
- specialist external assessors
- certification bodies
The IIA’s Standard 9.5: Coordination and Reliance requires the chief audit executive to coordinate with internal and external assurance providers and consider relying on their work. The purpose includes reducing unnecessary duplication and identifying gaps in coverage.
This can materially change the audit plan.
A high-risk area receiving strong, recent and reliable assurance elsewhere may require less immediate internal audit work than a slightly lower-risk area where no one is providing meaningful assurance.
ACCA’s guidance makes a similar practical point: the audit universe should be treated as an input to planning rather than the sole driver, alongside risks, objectives, emerging concerns and existing assurance.
A useful planning question is therefore:
“What assurance do we already have — and where are the gaps?”
Step 7: Turn priorities into a realistic internal audit plan
After assessing the universe, internal audit can begin translating priorities into actual engagements.
For each proposed audit, consider:
- Why is this engagement being selected?
- Which objective or risk does it support?
- What assurance already exists?
- What would the proposed scope cover?
- What skills will be required?
- How many audit days are available?
- Are specialist resources needed?
- What other major audits are competing for capacity?
- What happens if this work is deferred?
This is where prioritisation becomes real.
A risk-based plan is not the list of everything internal audit would like to examine.
It is the best use of the resources actually available.
That can also mean being explicit about what is not included.
If several significant risk areas cannot be covered because of resource constraints, that information is relevant to discussions with senior management and the board.
Step 8: Keep part of the plan flexible
A 12-month audit plan should not assume the organisation will remain unchanged for 12 months.
A new acquisition may occur.
A critical supplier may fail.
A significant cyber incident may expose weaknesses.
A regulatory requirement may change.
A major transformation programme may fall behind schedule.
An emerging technology may fundamentally alter a process that appeared low-risk six months earlier.
Standard 9.4 requires the internal audit plan to be dynamic and updated when changes in the organisation’s business, risks, operations, programmes, systems, controls or culture make that necessary.
That does not mean rebuilding the entire audit plan every month.
It does mean defining what should trigger reconsideration.
For example:
- significant new or emerging risk
- serious incident or control failure
- major organisational restructuring
- acquisition or disposal
- implementation of a critical system
- regulatory change
- repeated overdue remediation
- major change in risk assessment
- new concerns raised by the board or senior management
The audit universe should make those changes easier to identify.
If it cannot change when the organisation changes, it is a historical record rather than a planning tool.
A practical example: when the audit priority changes
Imagine supplier management appears in the audit universe.
At the beginning of the year, it receives a moderate risk assessment. Procurement controls are established, the supplier base is stable and a second-line compliance review was recently completed.
Internal audit decides not to include it in the immediate plan.
Six months later:
- the organisation outsources a critical service
- the new supplier processes sensitive customer information
- several existing suppliers have not completed scheduled reviews
- a supplier-related incident occurs
- management begins a rapid cost-reduction programme involving further outsourcing
The name of the auditable area has not changed.
Its risk context has.
A live audit universe should allow internal audit to see that change, reconsider its priority and determine whether the existing audit plan still provides appropriate coverage.
This is the difference between maintaining an audit list and performing risk-based audit planning.
Common audit universe mistakes
1. Copying the organisational chart
Departments can be useful auditable units, but significant risks frequently cross organisational boundaries.
Think in terms of processes, objectives, systems and dependencies as well as functions.
2. Making the universe too granular
More entries do not automatically mean better coverage.
If the universe contains hundreds of items that cannot realistically be assessed and maintained, important information can disappear into administrative detail.
3. Making it too broad
“Finance”, “Operations” or “IT” may be too large to produce a meaningful risk assessment.
An auditable unit should be defined at a level where a useful assurance engagement could realistically be considered.
4. Treating the highest score as the automatic audit priority
Risk scores are an input.
Recent assurance, major change, management concern, unresolved actions, incidents, regulatory requirements and resource availability may all affect the decision.
5. Ignoring assurance provided by others
Repeatedly auditing an area that already has strong independent assurance can consume resources while another significant risk receives little or no coverage.
6. Updating the universe once a year
An annual formal risk assessment may provide the foundation, but major changes should be reflected when they happen.
7. Disconnecting the universe from audit execution
The audit universe should not stop being useful when an engagement begins.
Ideally, an auditable area should connect through the audit lifecycle:
Auditable area → Risk → Planned audit → Working papers → Findings → Actions → Follow-up
That creates traceability between why an audit was selected, what was tested and what happened afterwards.
What should you be able to explain to the audit committee?
A strong audit universe should help internal audit answer questions such as:
- What areas could reasonably be subject to internal audit?
- Which organisational objectives and risks do those areas affect?
- Which areas currently carry the greatest assurance need?
- What assurance is already being provided elsewhere?
- When was each significant area last reviewed?
- Where do unresolved findings or actions remain?
- Why were this year’s audit engagements selected?
- Which significant areas are not covered by the plan?
- What would cause the plan to change?
- Can changes in organisational risk be reflected without rebuilding the planning process from scratch?
If those answers require combining several spreadsheets, searching previous audit reports and asking different teams for the latest risk information, the problem may not be the audit methodology.
It may be the way the information is connected.
From static audit universe to connected audit planning
Spreadsheets can be sufficient for a small and relatively stable audit universe.
The difficulty comes when the universe needs to be continually reconciled with changing risks, previous audits, findings, actions and assurance activity.
Symbiant’s Audit Universe Software provides a centralised environment for maintaining auditable entities and connecting them directly with the wider audit and risk process. It integrates with Symbiant’s Risk Register, Audit Working Papers, Audit Action Tracker and assessment capabilities, allowing teams to move from audit planning through execution and remediation without maintaining disconnected records.
That connection matters because risk-based planning should not end when the annual audit plan is approved.
When risks change, findings emerge or actions remain unresolved, internal audit needs to be able to see what those developments mean for future assurance.
Build an audit plan that can explain its priorities
An audit universe is not valuable because it gives internal audit a comprehensive spreadsheet.
It is valuable because it provides a structured way to understand what could be audited, why it matters, what assurance already exists and where internal audit can provide the greatest value.
Start with organisational objectives.
Define meaningful auditable areas.
Connect them to risks.
Understand existing assurance.
Prioritise using both evidence and professional judgement.
Then keep the information alive as the organisation changes.
That turns the audit universe from an inventory into something much more useful:
a defensible basis for risk-based audit planning.
Sources
The Institute of Internal Auditors (IIA), Global Internal Audit Standards (2024) — particularly Standard 9.4: Internal Audit Plan and Standard 9.5: Coordination and Reliance.
https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/The Institute of Internal Auditors (IIA), Developing a Risk-Based Internal Audit Plan, 2nd Edition (2025).
https://www.theiia.org/en/content/guidance/recommended/supplemental/practice-guides/developing-a-risk-based-internal-audit-plan/ACCA, Guidance on Internal Audit Planning and Strategy.
https://www.accaglobal.com/gb/en/member/sectors/internal-audit/learn/guidance-for-audit-planning-for-ia.html
Make risk-based audit planning easier to manage
Symbiant connects your Audit Universe with risks, working papers, findings and actions, helping internal audit teams maintain visibility from initial planning through to remediation.
Build a live view of your auditable areas, understand where risks and assurance activity intersect, and keep your audit plan connected to the information behind each decision.
Speak to our experts to see how Symbiant can support a more connected approach to internal audit planning and management.



