8

A HOLISTIC APPROACH TO RISK-BASED AUDIT PLANNING

The audit work performed during the year should obtain sufficient information to enable an evaluation of the system of controls and the formulation of an opinion.

—IIA Practice Advisory 2120.A1-1

INTRODUCTION

This final chapter attempts to summarize and draw together all the material we have discussed in the previous chapters. In this way, we can formulate a holistic approach to risk-based audit planning and use this to feed into appendix A where we provide a best practice checklist. It is a good idea to repeat the definition of internal auditing before we draft the first stage of our final model:

Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.1

A risk-based approach to audit planning simply means that the audit resource is focused on those aspects of the business that are key to its success. This is a concept that is aimed at shifting the audit process onto the boardroom's agenda and so allows the auditors to audit new horizons.

HOLISTIC RISK-BASED AUDIT PLANNING MODEL: PHASE ONE

Our first model looks as in Figure 8.1.

Each aspect of the model is described in the following paragraphs.

Corporate Governance Arrangements

The organization's governance ...

Get Audit Planning: A Risk-Based Approach now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.