Audit Planning Cheat Sheet: 7 Steps to Increasing Audit Impact in 2027

Internal Audit teams are starting to plan for 2027. Our audit planning “cheat sheet” is here to help.
Take these seven steps to ensure that your 2027 audit plan is as impactful as possible.
Step 1: Do a Quick Reconciliation Against Your 2026 Plan
What was on last year’s audit plan? How does it compare to what other teams were doing?
The Internal Audit Collective’s 2025–2026 audit plan benchmarking survey offers a snapshot of what was on members’ audit plans in 2026 and 2025, including:
- Top 20 audit areas for 2026, including the top eight of cybersecurity, fraud, ERM, general control reviews, procurement/vendor management, identity and access management, external auditor assistance, and corporate compliance
- A comparative two-year view on audit coverage (to account for rotating audits)
- Top 10 audit topics for teams planning 20+ audit projects
- Top 10 audit topics for teams of different sizes
Are there any big-ticket items you missed in 2026? Add them to 2027’s plan.
Interested in 2026 audit plan benchmarking? Participate in the CAE Leadership Forum’s audit plan benchmarking survey; watch for an announcement soon. As always, anyone who participates will receive the anonymous raw survey results.
Step 2: Self-Diagnose the Health of Your Audit Planning Approach
How are you identifying audit areas? What’s your risk assessment or audit planning process?
Is it more process-focused (i.e., auditing a certain process)? Or does every audit tie to specific risks?
Is it focused on solving specific business problems business leaders care about?
While a 100% risk-based audit approach is unrealistic for most teams due to compliance requirements, management requests, and advisory work, every team benefits from trying to move closer to the mark.
These actionable recommendations from fellow Internal Audit leaders can help you combat the persistent pain points of risk-based auditing.
Which ring true for you? How can you improve planning to get closer to a truly risk-based plan in 2027?
Step 3: Audit Against Top Business Leader and Board Priorities
If you ask your C-Suite and board what your top risks and priorities are, what would they say?
How well did your 2026 audit plan cover those topics?
According to our audit plan benchmarking survey and similar benchmarking (e.g., The IIA Pulse, Optro’s Focus on the Future, Protiviti’s Executive Perspectives on Top Risks), most audit plans still miss the mark on auditing many of the topics business leaders and boards care about.
We need to do better. This article takes an honest look at the incongruence and highlights specific audit topics to consider in response (e.g., product development, pricing, brand usage, talent onboarding).
What 2027 audit projects will you add to better address what your business leaders really care about?
Step 4: Strategize to Increase Stakeholder Conversation Quality/Quantity
So you’ve benchmarked against peers (step 1), self-diagnosed audit planning process health (step 2), and audited your plan against what your business leader and board priorities (step 3).
Step 4 is about making simple changes that help you get a better pulse on what actually matters to the business — and be a better leader to the business.
The Internal Audit Collective’s CAE leadership survey found that top-tier CAEs do two specific things more often than their peers:
- They have more conversations about the business with the business (e.g., risks, trends, operational effectiveness) — and fewer conversations about Internal Audit (e.g., findings, remediation status, upcoming audits).
- They require their direct reports to formally maintain more business relationships. More people = more meetings and more information about the business.
By improving stakeholder conversation quality/quantity, you’ll improve stakeholder relationships, increase business knowledge, uncover business problems worth solving, and make progress toward trusted-advisor status in your organization.
You’ll move from auditing processes to solving problems. Learn how four CAEs are doing it.
How will you level up your stakeholder meeting approach to uncover more problems worth solving?
Step 5: Assess Fit: Is a Traditional Audit Project the Right Tool to Use?
Are you using all the tools in your audit toolkit? Once you’re talking more about the business and its risks and problems (versus its processes), a traditional audit project may no longer fit.
For many years, Internal Audit teams had one tool: The traditional audit project, which focuses on providing the business with backward-looking assurance.
That isn’t enough in today’s volatile risk environment. Business leaders and boards urgently need Internal Audit’s assurance to help them identify, understand, and manage new and emerging risk areas. That means looking ahead toward ensuring future success — not looking back at what went wrong.
In 2027, a risk-focused audit plan must include forward-looking advisory work. This article breaks risk down into four buckets to help you identify the right audit project type and approach to use:
- Emerging risks unknown by the company
- Emerging risks known by the company
- Key risks beginning to be managed
- Key risks managed on an ongoing basis
What’s your ideal audit-advisory split? How will you ensure a better balance between traditional assurance and forward-looking advisory work in 2027?
Step 6: Plan 1-2 Go-to-Market (GTM) Audit Projects
How are you making sure your business is set up for success and resilience?
The first five steps helped you assess your 2027 plan in the context of your business. The last two steps, however, apply to ANY business.
As AI takes on more of Internal Audit’s traditional assurance work, our profession’s relevance and value are at stake. If we don’t show business leaders and boards that we’re focused on the risks that most impact business success and reliance, will they want us around?
That’s why every Internal Audit team should commit to at least one or two GTM audit projects in 2027. Here’s how to get started, including tips on finding points of entry, opening doors, getting buy-in, and running engagements that actually deliver value.
What GTM audit or advisory project(s) will your team tackle in 2027?
Step 7: Do an AI Governance Review
Haven’t done an AI governance review yet? Do one ASAP.
Already did one? Do another.
AI is the defining business topic of our time, and every organization has to prioritize AI governance. If you’re not looking at it, you’re not auditing your organization’s key risks.
That’s why AI governance should be on your audit plan in 2027 — and every year from now on.
Fortunately, Internal Auditors were made for this. Your business and risk acumen, change management experience, critical thinking skills, and process/controls expertise give you the foundations. The Internal Audit Collective's AI Governance Playbook has everything else you need to get moving, including lessons learned, example project scopes, and more from peers who’ve already done the work.
What AI governance area will you scope in for 2027?
THE LAST WORD: Plan for Impact in 2027
Feeling inspired? Time to translate that inspiration into action.
- Share this article with your direct reports. Assign out each step, delegating some and keeping some for yourself. The ask:
- Each person reads their article(s) and distills the 2–3 light bulbs that went off in their heads for each topic in the context of your team/organization.
- Have a pre-planning meeting in which everyone shares their light bulb moments. Then, agree on the specific additions or changes you’ll make to 2027’s audit plan.
- Don’t waste time reinventing the wheel. You don’t have to go it alone! Instead, check out the Internal Audit Collective’s Centers of Excellence (CoEs). Built by practitioners for practitioners, these centers are designed to help you quickly find relevant guidance, learn how peers approach common challenges, and apply proven solutions in your organization. Watch this 1-minute video to learn more. (Note: CoEs are available only to members.)
- As of October 2026, up-and-running Audit CoEs include: Accounts Payable/P2P; HR and Payroll; T&E; Third-Party Risk Management; Remote Access; SAP Control; SOC 1 and SOC 2 Report Review; Social Media; and AI Governance
- Audit CoEs currently in the works and coming soon: SOX ITGC Guide; Identity and Privileged Access Management; Disaster Recovery; Data Analytics Strategy and Benchmarking; AI Security; Cloud Security; System Integration Testing; Model Governance; Physical Inventory and Shrinkage; Treasury; IT Change Management (ITGC); AI Model Governance
- Future Audit CoEs in the backlog: Modern Audit Reporting and Issue Communication; SOX Testing, Walkthroughs & IPE Documentation; Risk-Based Audit Planning & Risk Assessment; Record-to-Report (R2R) / Journal Entry and Financial Close; Order-to-Cash / Revenue; Vulnerability and Threat Management; Workday; Unclaimed Property; Succession Planning; Onboarding/Offboarding of Contingent Workers

Recent Articles

Connected Risk Is Key to Elevating Audit’s Value: 4 Key Insights to Help Every Team Make Progress
Want to be updated as new blog posts are released? Subscribe to our newsletter.
Join 1K+ readers of The Enabling Positive Change Newsletter for tips, strategies, and resources to improve your approach to Internal Audit and SOX compliance.
