Beyond the Annual Audit Plan

Building a Risk-Based Internal Audit Approach Aligned with Strategy

Reading Time: 4 Minutes
9/3/2026
web grc news 030926

The greatest risk in a risk-based internal audit plan may be treating the plan itself as fixed.

An audit plan approved today reflects today’s understanding of strategy, risk and organizational priorities. Yet cyber threats, regulatory developments, geopolitical events, artificial intelligence and transformation programmes do not operate according to the internal audit calendar.

When the risk landscape moves faster than the assurance plan, completing the annual plan can become a poor proxy for providing the right assurance.

This is changing the conversation around risk-based internal audit (RBIA). The challenge is no longer simply to select audits based on risk. It is to direct finite assurance capacity towards the risks most consequential to strategy and to adapt that allocation as priorities evolve.

For internal audit leaders and Audit Committees, this requires four important shifts.

1. From Risk Registers to Strategic Risk Intelligence

The enterprise risk register remains an important input into a risk-based internal audit plan, but it should not define it.

Even where risk registers are regularly refreshed, they represent management’s view of risk and may not fully capture emerging exposures, interconnected risks or vulnerabilities developing around strategic change.

Internal audit therefore needs a broader intelligence base.

Strategic plans, board and executive discussions, key performance indicators, regulatory developments, external risk intelligence, previous assurance findings and data analytics can provide signals that complement the enterprise risk register.

Importantly, internal audit should not simply inherit management’s assessment of risk. Its independent perspective allows it to challenge assumptions and consider where assurance may be needed even when an issue has not yet reached the top of the corporate risk register.

The question shifts from “What are our highest-rated risks?” to “What could most significantly affect the achievement of our strategy and where would independent assurance add the greatest value?”

2. From Audit Universes to Assurance Priorities

Traditional audit universes often organize potential engagements around entities, functions, systems and processes. While useful, this structure can reinforce historical audit cycles rather than future strategic priorities.

A strategy-aligned RBIA framework starts with organizational objectives.

Growth, digital transformation, market expansion, cost optimization and AI adoption each create assumptions, dependencies and exposures. Understanding these connections allows internal audit to establish a clearer line of sight:

Strategy → Objectives → Risks → Management Responses → Assurance Needs → Audit Priorities

This may mean prioritizing a new transformation programme over a process routinely audited every few years.

The objective is not maximum audit coverage. With finite capacity, the objective should be optimal assurance coverage, deploying internal audit resources where uncertainty could have the greatest impact on strategic outcomes.

web grc 030926

3. From Annual Plans to Dynamic Assurance Portfolios

Perhaps the most significant evolution is to stop viewing the annual internal audit plan as a fixed schedule of engagements.

Instead, it can be managed as a dynamic portfolio of assurance priorities.

Dynamic risk assessment, supported by periodic or continuous risk monitoring where appropriate, allows internal audit to test whether the assumptions underpinning its plan remain valid. Emerging risks can be elevated, planned reviews rescoped and lower-priority work deferred when the organization’s risk profile changes materially.

This does not weaken governance. It makes governance more important.

Material changes should be supported by clear prioritization criteria and transparent communication with senior management and the Audit Committee. The governance question therefore shifts from plan completion to assurance relevance: are internal audit resources still focused on the risks that matter most?

For Audit Committees, this means looking beyond percentage completion of the annual plan towards risk coverage, emerging assurance gaps, changes in priorities and the rationale for reallocating audit capacity.

4. From Long Audit Cycles to Risk-Appropriate Agility

Dynamic planning determines where assurance is most needed. A more agile delivery model can help determine how and when that assurance reaches decision-makers.

For fast-moving risks and transformation programmes, waiting months for a completed audit report can reduce the relevance of the insight. Short, focused agile audit sprints can enable teams to examine priority risks, engage stakeholders iteratively and communicate significant observations earlier.

But agility should not become an objective in itself.

Not every engagement requires a sprint-based approach. Regulatory, highly prescribed or narrowly defined audits may be better suited to more traditional delivery models. Equally, becoming more agile does not necessarily require adopting a formal Agile Internal Audit methodology.

The objective is responsiveness to risk, not adherence to a particular framework.

Whatever the delivery model, evidence, professional judgement, documentation, independence and quality remain non-negotiable. Agility should change the speed and rhythm of assurance, not its rigour.

Closing the Strategy-Risk-Assurance Loop

Together, these shifts move internal audit beyond periodic planning towards a continuous strategy-risk-assurance loop.

Strategy informs risk. Changes in risk reshape assurance priorities. Internal audit activity generates insight. That insight strengthens management and board understanding and informs future risk and assurance decisions.

This requires a corresponding shift in how internal audit effectiveness is considered.

For Chief Audit Executives and Audit Committees, the question should no longer only be:

“Did we complete the audit plan?”

It should increasingly be:

“Did we provide timely assurance over the risks that mattered most to achieving our strategy?”

That is the real evolution of risk-based internal audit. The strongest internal audit functions will not necessarily be those that follow their original plans most precisely. They will be those that recognize when the risk landscape has changed, understand what that means for strategy and can redirect assurance accordingly without compromising independence, rigour or governance.


The author is Partner – Internal Audit & Governance Risk Compliance at Crowe UAE and can be reached at +971 52 373 4662 or [email protected]

GRC Compass

GRC Compass is a curated weekly newsletter published every Thursday, delivering the most relevant insights and updates in Internal Audit, Governance, Risk & Compliance (GRC), Cyber Threat Management, Technology, and evolving training needs.

Designed for professionals navigating a dynamic business environment, GRC Compass helps you stay informed, prepared, and ahead of the curve.
Dawn Thomas
Dawn Thomas
Senior Partner - Governance Risk & Compliance
Ahmed Ali Bin Haider
Ahmed Ali Bin Haider
Partner - GRC Technology
Rajeev Nanda
Rajeev Nanda
Partner – Internal Audit & Governance Risk Compliance